This IP address has been reported a total of
157
times from
79 distinct
sources.
59.97.138.76 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-06-04T05:45:39.254973+03:00 ns1 sshd-session[207073]: User root not allowed because account is ...
show more2026-06-04T05:45:39.254973+03:00 ns1 sshd-session[207073]: User root not allowed because account is locked
2026-06-04T05:45:39.445330+03:00 ns1 sshd-session[207073]: Connection closed by invalid user root 59.97.138.76 port 52310 [preauth]
2026-06-04T05:46:01.056008+03:00 ns1 sshd-session[207075]: User root not allowed because account is locked
2026-06-04T05:46:01.249768+03:00 ns1 sshd-session[207075]: Connection closed by invalid user root 59.97.138.76 port 54340 [preauth]
2026-06-04T05:46:25.010988+03:00 ns1 sshd-session[207118]: Invalid user chenyiyuan from 59.97.138.76 port 36862
...
show less
Coordinated attack against 84.46.253.134. Webshell scanning + credential harvesting. Active May-Jun ...
show moreCoordinated attack against 84.46.253.134. Webshell scanning + credential harvesting. Active May-Jun 2026. ZAC Bayern ref BY0257-500359-26/8.
show less
2026-05-30T09:53:04.607568-03:00 vmi2819241 sshd-session[1847859]: Failed password for invalid user ...
show more2026-05-30T09:53:04.607568-03:00 vmi2819241 sshd-session[1847859]: Failed password for invalid user root from 59.97.138.76 port 56138 ssh2
2026-05-30T09:53:21.565619-03:00 vmi2819241 sshd-session[1847886]: Invalid user cleo from 59.97.138.76 port 39246
2026-05-30T09:53:21.746191-03:00 vmi2819241 sshd-session[1847886]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=59.97.138.76
2026-05-30T09:53:23.837551-03:00 vmi2819241 sshd-session[1847886]: Failed password for invalid user cleo from 59.97.138.76 port 39246 ssh2
...
show less
May 29 07:18:56 59.97.138.76 TCP SPT=58540 DPT=222 SYN
May 29 07:18:57 59.97.138.76 TCP SPT=58540 DP ...
show moreMay 29 07:18:56 59.97.138.76 TCP SPT=58540 DPT=222 SYN
May 29 07:18:57 59.97.138.76 TCP SPT=58540 DPT=222 SYN
May 29 07:18:59 59.97.138.76 TCP SPT=58540 DPT=222
...
show less
May 28 06:33:47 Torux sshd[203487]: Failed password for root from 59.97.138.76 port 34044 ssh2
May 2 ...
show moreMay 28 06:33:47 Torux sshd[203487]: Failed password for root from 59.97.138.76 port 34044 ssh2
May 28 06:34:04 Torux sshd[203636]: Invalid user oracle from 59.97.138.76 port 47832
May 28 06:34:04 Torux sshd[203636]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=59.97.138.76
May 28 06:34:05 Torux sshd[203636]: Failed password for invalid user oracle from 59.97.138.76 port 47832 ssh2
May 28 06:34:25 Torux sshd[203807]: Invalid user magento from 59.97.138.76 port 40308
...
show less
2026-05-28T06:33:46.598839+02:00 **** sshd-session[47220]: Failed password for root from 59.97.138.7 ...
show more2026-05-28T06:33:46.598839+02:00 **** sshd-session[47220]: Failed password for root from 59.97.138.76 port 55670 ssh2
2026-05-28T06:34:03.473357+02:00 **** sshd-session[47785]: Invalid user **** from 59.97.138.76 port 42520
2026-05-28T06:34:03.634277+02:00 **** sshd-session[47785]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=59.97.138.76
2026-05-28T06:34:05.364352+02:00 **** sshd-session[47785]: Failed password for invalid user **** from 59.97.138.76 port 42520 ssh2
2026-05-28T06:34:23.743473+02:00 **** sshd-session[48394]: Invalid user **** from 59.97.138.76 port 45874
show less
2026-05-28T06:31:43.689905+02:00 thelists sshd[984729]: Connection closed by 59.97.138.76 port 33802 ...
show more2026-05-28T06:31:43.689905+02:00 thelists sshd[984729]: Connection closed by 59.97.138.76 port 33802 [preauth]
2026-05-28T06:33:23.107307+02:00 thelists sshd[985676]: Connection closed by authenticating user root 59.97.138.76 port 43246 [preauth]
2026-05-28T06:33:42.176119+02:00 thelists sshd[985722]: Connection closed by authenticating user root 59.97.138.76 port 59378 [preauth]
2026-05-28T06:34:00.718623+02:00 thelists sshd[985945]: Invalid user oracle from 59.97.138.76 port 45824
2026-05-28T06:34:00.892738+02:00 thelists sshd[985945]: Connection closed by invalid user oracle 59.97.138.76 port 45824 [preauth]
...
show less
Brute-Force
SSH
Showing 1 to
15
of 157 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ