This IP address has been reported a total of
63
times from
52 distinct
sources.
92.38.49.180 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
denied traffic to a non-approved destination port. destination port 2375.
SSH Brute force: 1 attempts were recorded from 92.38.49.180
2026-07-14T11:31:46+02:00 Disconnected f ...
show moreSSH Brute force: 1 attempts were recorded from 92.38.49.180
2026-07-14T11:31:46+02:00 Disconnected from authenticating user root 92.38.49.180 port 49618 [preauth]
show less
Honeypot [uk-production01]: HTTP/1.1 request on 2375
GET /v1.16/version
User-Agent: Mozilla/5.0 zgr ...
show moreHoneypot [uk-production01]: HTTP/1.1 request on 2375
GET /v1.16/version
User-Agent: Mozilla/5.0 zgrab/0.x
Accept: */*
Accept-Encoding: gzip; 2375 [1] TCP
show less
92.38.49.180 (KZ/Kazakhstan/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; ...
show more92.38.49.180 (KZ/Kazakhstan/-), 5 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Mar 26 15:37:29 14069 sshd[2133]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=92.38.49.180 user=root
Mar 26 15:37:31 14069 sshd[2133]: Failed password for root from 92.38.49.180 port 49686 ssh2
Mar 26 16:07:13 14069 sshd[4975]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=160.187.240.90 user=root
Mar 26 16:07:15 14069 sshd[4975]: Failed password for root from 160.187.240.90 port 37428 ssh2
Mar 26 16:07:28 14069 sshd[4980]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=50.35.168.148 user=root
IP Addresses Blocked:
show less
Honeypot hit: Brute-force attack detected on 22/SSH
โข Credentials: dan:12345678, root:123456, root:P ...
show moreHoneypot hit: Brute-force attack detected on 22/SSH
โข Credentials: dan:12345678, root:123456, root:P@ssw0rd05, 345gs5662d34:345gs5662d34, root:3245gs5662d34
โข Number of login attempts: 5
โข 19 command(s) were executed during the session
โข Client: SSH-2.0-libssh_0.11.1
show less
(sshd) Failed SSH login from 92.38.49.180 (KZ/Kazakhstan/-): 5 in the last 3600 secs; Ports: *; Dire ...
show more(sshd) Failed SSH login from 92.38.49.180 (KZ/Kazakhstan/-): 5 in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_SSHD; Logs: Mar 26 05:32:49 14995 sshd[952]: Invalid user dan from 92.38.49.180 port 46728
Mar 26 05:32:50 14995 sshd[952]: Failed password for invalid user dan from 92.38.49.180 port 46728 ssh2
Mar 26 05:38:03 14995 sshd[1461]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=92.38.49.180 user=root
Mar 26 05:38:05 14995 sshd[1461]: Failed password for root from 92.38.49.180 port 34320 ssh2
Mar 26 05:40:09 14995 sshd[1656]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=92.38.49.180 user=root
show less
2026-03-26T11:37:39.831785+01:00 ieyasu.moretrix.com sshd-session[1468088]: User root from 92.38.49. ...
show more2026-03-26T11:37:39.831785+01:00 ieyasu.moretrix.com sshd-session[1468088]: User root from 92.38.49.180 not allowed because none of user's groups are listed in AllowGroups
2026-03-26T11:39:45.507345+01:00 ieyasu.moretrix.com sshd-session[1468284]: Connection from 92.38.49.180 port 40360 on 176.9.64.17 port 22 rdomain ""
2026-03-26T11:39:46.121399+01:00 ieyasu.moretrix.com sshd-session[1468284]: User root from 92.38.49.180 not allowed because none of user's groups are listed in AllowGroups
...
show less
SSH brute force attack detected: 5 failed attempts
Brute-Force
Anonymous
Mar 26 10:13:27 conf sshd[277316]: Disconnected from invalid user emma 92.38.49.180 port 40506 [prea ...
show moreMar 26 10:13:27 conf sshd[277316]: Disconnected from invalid user emma 92.38.49.180 port 40506 [preauth]
Mar 26 10:19:47 conf sshd[278452]: Connection from 92.38.49.180 port 54998 on 79.137.33.6 port 22 rdomain ""
Mar 26 10:19:48 conf sshd[278452]: Invalid user frappeuser from 92.38.49.180 port 54998
...
show less