This IP address has been reported a total of
5,737
times from
1,217 distinct
sources.
85.240.193.104 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
2026-03-25T17:27:00.271113+00:00 sg-jumphost-server sshd[2896401]: Invalid user nikita from 85.240.1 ...
show more2026-03-25T17:27:00.271113+00:00 sg-jumphost-server sshd[2896401]: Invalid user nikita from 85.240.193.104 port 58442
2026-03-25T17:27:00.482297+00:00 sg-jumphost-server sshd[2896401]: Disconnected from invalid user nikita 85.240.193.104 port 58442 [preauth]
...
show less
Mar 25 18:03:30 proxy sshd[410714]: Invalid user solr from 85.240.193.104 port 39318
Mar 25 18:09:57 ...
show moreMar 25 18:03:30 proxy sshd[410714]: Invalid user solr from 85.240.193.104 port 39318
Mar 25 18:09:57 proxy sshd[410810]: Invalid user jason1 from 85.240.193.104 port 60754
Mar 25 18:12:30 proxy sshd[410844]: Invalid user jason from 85.240.193.104 port 42640
...
show less
2026-03-25T10:08:28.195676-07:00 goldcrest sshd[71945]: Failed password for invalid user solr from 8 ...
show more2026-03-25T10:08:28.195676-07:00 goldcrest sshd[71945]: Failed password for invalid user solr from 85.240.193.104 port 34920 ssh2
2026-03-25T10:11:44.273611-07:00 goldcrest sshd[72120]: Invalid user jason1 from 85.240.193.104 port 53494
2026-03-25T10:11:44.280842-07:00 goldcrest sshd[72120]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.240.193.104
2026-03-25T10:11:46.510568-07:00 goldcrest sshd[72120]: Failed password for invalid user jason1 from 85.240.193.104 port 53494 ssh2
...
show less
2026-03-25T17:05:36.280825+00:00 sg-jumphost-server sshd[2895695]: Invalid user solr from 85.240.193 ...
show more2026-03-25T17:05:36.280825+00:00 sg-jumphost-server sshd[2895695]: Invalid user solr from 85.240.193.104 port 36400
2026-03-25T17:05:36.491540+00:00 sg-jumphost-server sshd[2895695]: Disconnected from invalid user solr 85.240.193.104 port 36400 [preauth]
2026-03-25T17:10:41.283402+00:00 sg-jumphost-server sshd[2895917]: Invalid user jason1 from 85.240.193.104 port 44400
...
show less
85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt), 5 distributed sshd attacks on account [solr ...
show more85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt), 5 distributed sshd attacks on account [solr] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Mar 25 12:10:00 17913 sshd[22990]: Invalid user solr from 209.14.88.118 port 59544
Mar 25 12:04:22 17913 sshd[22592]: Invalid user solr from 85.240.193.104 port 39202
Mar 25 12:04:25 17913 sshd[22592]: Failed password for invalid user solr from 85.240.193.104 port 39202 ssh2
Mar 25 12:05:07 17913 sshd[22669]: Invalid user solr from 187.183.59.64 port 19773
Mar 25 12:05:09 17913 sshd[22669]: Failed password for invalid user solr from 187.183.59.64 port 19773 ssh2
IP Addresses Blocked:
209.14.88.118 (BR/Brazil/gru-209-14-88-118.ip4.99.network)
show less
2026-03-25T17:05:50.910435+00:00 Node1-Xeon sshd-session[387996]: Invalid user solr from 85.240.193. ...
show more2026-03-25T17:05:50.910435+00:00 Node1-Xeon sshd-session[387996]: Invalid user solr from 85.240.193.104 port 47082
...
show less
(sshd) Failed SSH login from 85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt): 5 in the last ...
show more(sshd) Failed SSH login from 85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SSHD; Logs: Mar 25 17:40:53 da057 sshd[2163157]: Invalid user in from 85.240.193.104 port 53290
Mar 25 17:43:58 da057 sshd[2166170]: Invalid user zhy from 85.240.193.104 port 40934
Mar 25 17:46:20 da057 sshd[2168528]: Invalid user monitoring from 85.240.193.104 port 50086
Mar 25 17:50:51 da057 sshd[2172250]: Invalid user zabbix from 85.240.193.104 port 40218
Mar 25 17:53:04 da057 sshd[2174129]: Invalid user wei from 85.240.193.104 port 49404
show less
85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt), 5 distributed sshd attacks on account [zhy] ...
show more85.240.193.104 (PT/Portugal/bl7-193-104.dsl.telepac.pt), 5 distributed sshd attacks on account [zhy] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Mar 25 11:42:13 13545 sshd[7375]: Invalid user zhy from 213.167.43.130 port 41262
Mar 25 11:35:43 13545 sshd[6863]: Invalid user zhy from 23.226.133.133 port 38880
Mar 25 11:35:45 13545 sshd[6863]: Failed password for invalid user zhy from 23.226.133.133 port 38880 ssh2
Mar 25 11:42:08 13545 sshd[7373]: Invalid user zhy from 85.240.193.104 port 40436
Mar 25 11:42:10 13545 sshd[7373]: Failed password for invalid user zhy from 85.240.193.104 port 40436 ssh2
IP Addresses Blocked:
213.167.43.130 (RU/Russia/mx3.volgaltd.ru)
23.226.133.133 (US/United States/-)
show less
2026-03-25T19:13:37.360309openvpn sshd[1126219]: Invalid user wei from 85.240.193.104 port 56592
202 ...
show more2026-03-25T19:13:37.360309openvpn sshd[1126219]: Invalid user wei from 85.240.193.104 port 56592
2026-03-25T19:13:39.551606openvpn sshd[1126219]: Failed password for invalid user wei from 85.240.193.104 port 56592 ssh2
2026-03-25T19:16:08.656203openvpn sshd[1126265]: Invalid user iksi from 85.240.193.104 port 40286
2026-03-25T19:16:08.659159openvpn sshd[1126265]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.240.193.104
2026-03-25T19:16:08.656203openvpn sshd[1126265]: Invalid user iksi from 85.240.193.104 port 40286
2026-03-25T19:16:10.245850openvpn sshd[1126265]: Failed password for invalid user iksi from 85.240.193.104 port 40286 ssh2
2026-03-25T19:18:35.069307openvpn sshd[1126293]: Invalid user bbb from 85.240.193.104 port 52212
...
show less
2026-03-25T17:09:42.473397+01:00 monitoring.infra.crazycraftland.net sshd-session[1677047]: Invalid ...
show more2026-03-25T17:09:42.473397+01:00 monitoring.infra.crazycraftland.net sshd-session[1677047]: Invalid user vnc from 85.240.193.104 port 52188
2026-03-25T17:13:55.497044+01:00 monitoring.infra.crazycraftland.net sshd-session[1677919]: Invalid user wei from 85.240.193.104 port 51848
2026-03-25T17:16:26.695962+01:00 monitoring.infra.crazycraftland.net sshd-session[1678411]: Invalid user iksi from 85.240.193.104 port 35542
...
show less
2026-03-25T17:11:10.154524 dc-eu-ger-fra-001.aki-solutions.local sshd[591128]: pam_unix(sshd:auth): ...
show more2026-03-25T17:11:10.154524 dc-eu-ger-fra-001.aki-solutions.local sshd[591128]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=85.240.193.104
2026-03-25T17:11:12.499345 dc-eu-ger-fra-001.aki-solutions.local sshd[591128]: Failed password for invalid user vnc from 85.240.193.104 port 47240 ssh2
2026-03-25T17:14:28.023475 dc-eu-ger-fra-001.aki-solutions.local sshd[593887]: Invalid user wei from 85.240.193.104 port 37686
...
show less
Brute-Force
SSH
Showing 5716 to
5730
of 5737 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ