Report for IP: 170.0.62.165

Threat LevelHIGH59/1002 rule types
24 incidents · 2 rule types · active attack detected · 24 attacks/day · last seen 84d ago
PTR N/A
Org / ASN T.I Connect LTDA
Country 🇧🇷 Brazil
City Surubim, Pernambuco
Timezone America/Recife

Attack Analysis

SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).
SSH: Invalid User Flood
This IP attempted SSH logins using 5 or more invalid usernames within 2 minutes — a credential-stuffing attack cycling through common account names (admin, root, ubuntu, deploy, pi). This indicates an automated tool probing for default or common accounts.

Reports (24)

Date Severity Description
7 Jul 2026 - 22:16 high SSH: Invalid user flood — 5+ attempts in 120s
7 Jul 2026 - 22:15 medium SSH: Login attempt using non-existent user
7 Jul 2026 - 22:14 medium SSH: Login attempt using non-existent user
7 Jul 2026 - 22:09 medium SSH: Login attempt using non-existent user