This IP address has been reported a total of
540
times from
267 distinct
sources.
85.121.48.247 was first reported on
, and the most recent report was
.
Old Reports:
The most recent abuse report for this IP address is from
. It is possible that this IP is no longer involved in abusive activities.
This IP address carried out 210 port scanning attempts on 18-11-2025. For more information or to rep ...
show moreThis IP address carried out 210 port scanning attempts on 18-11-2025. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
This IP address carried out 38 SSH credential attack (attempts) on 18-11-2025. For more information ...
show moreThis IP address carried out 38 SSH credential attack (attempts) on 18-11-2025. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
This IP address carried out 70 SSH credential attack (attempts) on 17-11-2025. For more information ...
show moreThis IP address carried out 70 SSH credential attack (attempts) on 17-11-2025. For more information or to report interesting / incorrect findings, give me a shoutout @parthmaniar on Twitter.
show less
2025-11-18T11:09:38.549839+01:00 axisverse sshd-session[3544154]: Invalid user ubuntu from 85.121.48 ...
show more2025-11-18T11:09:38.549839+01:00 axisverse sshd-session[3544154]: Invalid user ubuntu from 85.121.48.247 port 36156
2025-11-18T11:09:51.159945+01:00 axisverse sshd-session[3544624]: Invalid user ubuntu from 85.121.48.247 port 49426
2025-11-18T11:12:10.186504+01:00 axisverse sshd-session[3550174]: Invalid user ftp_user from 85.121.48.247 port 35262
...
show less
2025-11-18T10:07:41.185376+00:00 mailtommygod sshd[2920848]: pam_unix(sshd:auth): authentication fai ...
show more2025-11-18T10:07:41.185376+00:00 mailtommygod sshd[2920848]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247
2025-11-18T10:07:43.202201+00:00 mailtommygod sshd[2920848]: Failed password for invalid user david from 85.121.48.247 port 40684 ssh2
2025-11-18T10:08:50.217325+00:00 mailtommygod sshd[2921062]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247 user=root
2025-11-18T10:08:52.375806+00:00 mailtommygod sshd[2921062]: Failed password for root from 85.121.48.247 port 40248 ssh2
2025-11-18T10:10:01.146696+00:00 mailtommygod sshd[2921419]: Invalid user ubuntu from 85.121.48.247 port 39812
show less
2025-11-18T13:07:26.992177+03:00 deltachat.me sshd[2615425]: pam_unix(sshd:auth): authentication fai ...
show more2025-11-18T13:07:26.992177+03:00 deltachat.me sshd[2615425]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247
2025-11-18T13:07:28.616723+03:00 deltachat.me sshd[2615425]: Failed password for invalid user david from 85.121.48.247 port 58496 ssh2
2025-11-18T13:08:37.417260+03:00 deltachat.me sshd[2620526]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247 user=root
2025-11-18T13:08:39.454142+03:00 deltachat.me sshd[2620526]: Failed password for root from 85.121.48.247 port 58060 ssh2
2025-11-18T13:09:54.226833+03:00 deltachat.me sshd[2626066]: Invalid user ubuntu from 85.121.48.247 port 57624
...
show less
2025-11-18T12:06:00.944553+02:00 zrh02-ch-pop.as202427.net sshd[350589]: User root from 85.121.48.24 ...
show more2025-11-18T12:06:00.944553+02:00 zrh02-ch-pop.as202427.net sshd[350589]: User root from 85.121.48.247 not allowed because not listed in AllowUsers
2025-11-18T12:07:32.939707+02:00 zrh02-ch-pop.as202427.net sshd[350616]: Invalid user david from 85.121.48.247 port 58276
2025-11-18T12:08:42.377893+02:00 zrh02-ch-pop.as202427.net sshd[350649]: User root from 85.121.48.247 not allowed because not listed in AllowUsers
...
show less
(sshd) Failed SSH login from 85.121.48.247 (RO/Romania/dhhhst.pw): 5 in the last 3600 secs; Ports: * ...
show more(sshd) Failed SSH login from 85.121.48.247 (RO/Romania/dhhhst.pw): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Nov 18 04:03:34 14902 sshd[553]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247 user=root
Nov 18 04:03:36 14902 sshd[553]: Failed password for root from 85.121.48.247 port 58386 ssh2
Nov 18 04:06:53 14902 sshd[779]: Invalid user david from 85.121.48.247 port 53394
Nov 18 04:06:56 14902 sshd[779]: Failed password for invalid user david from 85.121.48.247 port 53394 ssh2
Nov 18 04:08:05 14902 sshd[910]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247 user=root
show less
(sshd) Failed SSH login from 85.121.48.247 (RO/Romania/dhhhst.pw): 5 in the last 3600 secs; Ports: * ...
show more(sshd) Failed SSH login from 85.121.48.247 (RO/Romania/dhhhst.pw): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Nov 18 03:14:57 13966 sshd[22881]: Invalid user amber from 85.121.48.247 port 49906
Nov 18 03:14:59 13966 sshd[22881]: Failed password for invalid user amber from 85.121.48.247 port 49906 ssh2
Nov 18 03:18:18 13966 sshd[23197]: Invalid user ubuntu from 85.121.48.247 port 48356
Nov 18 03:18:20 13966 sshd[23197]: Failed password for invalid user ubuntu from 85.121.48.247 port 48356 ssh2
Nov 18 03:19:30 13966 sshd[23273]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.121.48.247 user=root
show less
2025-11-18T09:37:14.802517+01:00 lw-dedi-hdz-10g2480-ams sshd[721085]: Invalid user mysftp from 85.1 ...
show more2025-11-18T09:37:14.802517+01:00 lw-dedi-hdz-10g2480-ams sshd[721085]: Invalid user mysftp from 85.121.48.247 port 53972
2025-11-18T09:38:25.689265+01:00 lw-dedi-hdz-10g2480-ams sshd[721190]: Invalid user foundry from 85.121.48.247 port 53434
2025-11-18T09:40:37.459009+01:00 lw-dedi-hdz-10g2480-ams sshd[721369]: Invalid user centos from 85.121.48.247 port 52340
...
show less
Brute-Force
SSH
Showing 1 to
15
of 540 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ