This IP address has been reported a total of
39
times from
31 distinct
sources.
58.11.120.150 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
58.11.120.150 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale ...
show more58.11.120.150 is one of many (potentially hijacked) hosts in a botnet. This attack is a large scale industrial operation attempting unrelenting brute-force login attempts for months on end - between all CIDR ranges in the botnet, our servers receive over 800 authentication attempts per minute on smtp, imap and relative mail ports, as well as ssh, and other protocols.
IP INFO:
- IP 58.11.120.150
- Anycast false
- City N/A
- Region N/A
- Region Code N/A
- Country N/A (N/A)
- Continent N/A (N/A)
- Range N/A
- Provider N/A
- Organisation N/A
- Proxy N/A
- Type N/A
show less
2026-06-05T06:34:25.824324-05:00 plex sshd-session[10755]: Invalid user ibrahim from 58.11.120.150 p ...
show more2026-06-05T06:34:25.824324-05:00 plex sshd-session[10755]: Invalid user ibrahim from 58.11.120.150 port 45020
2026-06-05T06:50:46.270769-05:00 plex sshd-session[11031]: Invalid user prometheus from 58.11.120.150 port 56564
...
show less
(sshd) Failed SSH login from 58.11.120.150 (TH/Thailand/ppp-58-11-120-150.revip2.asianet.co.th): 5 i ...
show more(sshd) Failed SSH login from 58.11.120.150 (TH/Thailand/ppp-58-11-120-150.revip2.asianet.co.th): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 5 06:47:34 14977 sshd[7798]: Invalid user debian from 58.11.120.150 port 58922
Jun 5 06:47:36 14977 sshd[7798]: Failed password for invalid user debian from 58.11.120.150 port 58922 ssh2
Jun 5 06:48:49 14977 sshd[8392]: Invalid user ali from 58.11.120.150 port 45076
Jun 5 06:48:51 14977 sshd[8392]: Failed password for invalid user ali from 58.11.120.150 port 45076 ssh2
Jun 5 06:50:05 14977 sshd[9212]: Invalid user prometheus from 58.11.120.150 port 48750
show less
CSF/LFD blocked 58.11.120.150 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH ...
show moreCSF/LFD blocked 58.11.120.150 after LF_SSHD on * (inout, perm=1, ttl=1s). Reason: (sshd) Failed SSH login from 58.11.120.150 (TH/Thailand/ppp-58-11-120-150.revip2.asianet.co.th): 5 in the last 3600 secs. Evidence: Jun 5 05:29:24 paladin sshd[2299125]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58.11.120.150 user=root
show less
2026-06-05T13:36:37.985427+03:00 gogo-server sshd-session[2747746]: pam_unix(sshd:auth): authenticat ...
show more2026-06-05T13:36:37.985427+03:00 gogo-server sshd-session[2747746]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58.11.120.150
2026-06-05T13:36:39.459487+03:00 gogo-server sshd-session[2747746]: Failed password for invalid user krishna from 58.11.120.150 port 43028 ssh2
2026-06-05T13:47:49.639916+03:00 gogo-server sshd-session[2755823]: Invalid user celeryuser from 58.11.120.150 port 52718
...
show less
(sshd) Failed SSH login from 58.11.120.150 (TH/Thailand/ppp-58-11-120-150.revip2.asianet.co.th): 5 i ...
show more(sshd) Failed SSH login from 58.11.120.150 (TH/Thailand/ppp-58-11-120-150.revip2.asianet.co.th): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Jun 5 05:18:40 14967 sshd[8209]: Invalid user tidb from 58.11.120.150 port 45968
Jun 5 05:18:43 14967 sshd[8209]: Failed password for invalid user tidb from 58.11.120.150 port 45968 ssh2
Jun 5 05:26:04 14967 sshd[8993]: Invalid user junior from 58.11.120.150 port 49416
Jun 5 05:26:06 14967 sshd[8993]: Failed password for invalid user junior from 58.11.120.150 port 49416 ssh2
Jun 5 05:32:04 14967 sshd[9614]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=58.11.120.150 user=root
show less
Brute-Force
SSH
Showing 1 to
15
of 39 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ