This IP address has been reported a total of
167
times from
145 distinct
sources.
80.99.216.230 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
2026-09-24T14:19:28.119198 orion-monitor sshd[1985296]: Invalid user ansible from 80.99.216.230 port ...
show more2026-09-24T14:19:28.119198 orion-monitor sshd[1985296]: Invalid user ansible from 80.99.216.230 port 38418
2026-09-24T14:20:58.102333 orion-monitor sshd[1985304]: Invalid user hibiki from 80.99.216.230 port 57276
2026-09-24T14:23:46.902569 orion-monitor sshd[1985316]: Invalid user vendas from 80.99.216.230 port 38314
2026-09-24T14:27:48.670075 orion-monitor sshd[1985348]: Invalid user sebastian from 80.99.216.230 port 33890
2026-09-24T14:31:47.464233 orion-monitor sshd[1985386]: Invalid user test from 80.99.216.230 port 44470
...
show less
Report 2702391 with IP 3749959 for SSH brute-force attack by source 3744616 via ssh-honeypot/0.2.0+h ...
show moreReport 2702391 with IP 3749959 for SSH brute-force attack by source 3744616 via ssh-honeypot/0.2.0+http
show less
2026-09-24T12:52:38.304661+00:00 helium sshd-session[296750]: Disconnected from authenticating user ...
show more2026-09-24T12:52:38.304661+00:00 helium sshd-session[296750]: Disconnected from authenticating user root 80.99.216.230 port 36172 [preauth]
2026-09-24T12:56:59.882917+00:00 helium sshd-session[298051]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.99.216.230 user=root
2026-09-24T12:57:01.925862+00:00 helium sshd-session[298051]: Failed password for root from 80.99.216.230 port 57668 ssh2
...
show less
Sep 24 12:51:13 sshd[3465517]: Disconnected from authenticating user XXXX 80.99.216.230 port 34764 [ ...
show moreSep 24 12:51:13 sshd[3465517]: Disconnected from authenticating user XXXX 80.99.216.230 port 34764 [preauth]
Sep 24 12:56:46 sshd[3465535]: Disconnected from authenticating user XXXX 80.99.216.230 port 41568 [preauth]
show less
Brute-Force
SSH
Anonymous
2026-09-24T15:50:27.067556+03:00 2426447-on24665.twc1.net sshd[310867]: pam_unix(sshd:auth): authent ...
show more2026-09-24T15:50:27.067556+03:00 2426447-on24665.twc1.net sshd[310867]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=80.99.216.230 user=root
2026-09-24T15:50:29.498124+03:00 2426447-on24665.twc1.net sshd[310867]: Failed password for root from 80.99.216.230 port 55880 ssh2
...
show less
Cowrie SSH honeypot detected unauthorized SSH activity. Username: test. Failed SSH login attempts fr ...
show moreCowrie SSH honeypot detected unauthorized SSH activity. Username: test. Failed SSH login attempts from this IP in the last 24 hours: 11. New failed login attempts since the previous report: 10. Reason: Failed SSH login attempt. Target: SSH honeypot.
show less
2026-09-24T14:23:59.495764+02:00 nc-vm-rs4kg95-vie sshd-session[642904]: Invalid user filip from 80. ...
show more2026-09-24T14:23:59.495764+02:00 nc-vm-rs4kg95-vie sshd-session[642904]: Invalid user filip from 80.99.216.230 port 36808
2026-09-24T14:25:40.846077+02:00 nc-vm-rs4kg95-vie sshd-session[643566]: Invalid user root1 from 80.99.216.230 port 59318
2026-09-24T14:27:05.466769+02:00 nc-vm-rs4kg95-vie sshd-session[644534]: Invalid user ahmad from 80.99.216.230 port 48672
...
show less
Cowrie SSH honeypot detected unauthorized SSH activity. Username: root. Failed SSH login attempts fr ...
show moreCowrie SSH honeypot detected unauthorized SSH activity. Username: root. Failed SSH login attempts from this IP in the last 24 hours: 1. New failed login attempts since the previous report: 1. Reason: Failed SSH login attempt. Target: SSH honeypot.
show less
Brute-Force
SSH
Anonymous
80.99.216.230 (HU/Hungary/-), 7 distributed sshd attacks on account [root] in the last 3600 secs; Po ...
show more80.99.216.230 (HU/Hungary/-), 7 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: Sep 24 08:18:08 server5 sshd[23346]: Failed password for root from 80.99.216.230 port 43538 ssh2
Sep 24 08:15:17 server5 sshd[21799]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.196.191.58 user=root
Sep 24 08:15:19 server5 sshd[21799]: Failed password for root from 220.196.191.58 port 58226 ssh2
Sep 24 08:18:53 server5 sshd[23811]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=115.190.185.14 user=root
Sep 24 08:17:35 server5 sshd[23003]: Failed password for root from 46.10.201.90 port 58374 ssh2
Sep 24 08:09:56 server5 sshd[17563]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=220.196.191.58 user=root
Sep 24 08:09:58 server5 sshd[17563]: Failed password for root from 220.196.191.58 port 54200 ssh2
IP Addresses Blocked:
show less
Brute-Force
Showing 1 to
15
of 167 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ