Report for IP: 159.112.138.47

Threat LevelCRITICAL72/1002 rule types across 2 attack categories
2 incidents on record · 2 rule types · active attack detected · persistent 74-day campaign · last seen 3d ago
PTR N/A
Org / ASN Oracle Cloud Infrastructure (sa-santiago-1)
Country 🇨🇱 Chile
City Santiago, Santiago Metropolitan
Timezone America/Santiago

Attack Analysis

Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.
SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).

Reports (2)

Date Severity Description
26 Sep 2026 - 23:39 high SSH: Login attempt using non-existent user
14 Jul 2026 - 16:04 high IDS: Suricata alert