Beware! Coordinated SSH brute force campaign

By Eric John Emberda

Explore my NLP research and published research.

Beware! Coordinated SSH brute force campaign

There have been sustained, multi-source credential stuffing and dictionary attacks against my SSH daemon across 4 consecutive days, as shown in my Fail2Ban logs. Several patterns stand out.


77.83.39.153 is the primary threat. This single IP from a Netherlands hosting provider (Serverius) accounts for roughly 60% of all attempts. What makes it particularly concerning is its behavior after each fail2ban unban, it resumes immediately without any cool-down. This suggests an automated botnet script that monitors connectivity rather than an opportunistic scanner. It was banned 9 times across 4 days, meaning the 30-minute ban window is not deterring it at all.


2.57.122.162 is deliberately slow-scanning to avoid bans. This LeaseWeb IP never triggered a ban despite appearing across all 4 days. The attacker is pacing attempts at intervals just below your maxretry threshold. This is a classic evasion technique. This is arguably more dangerous than the noisy 77.83.39.153 because it's operating below the usual detection floor indefinitely.


The coordinated multi-IP clusters are botnet signatures. Between 07:00–07:30 on March 15, around a dozen IPs from Japan, Korea, Brazil, and the Philippines all hit my server simultaneously with ~2-minute intervals between each. This is a distributed botnet working a shared target list, not independent actors.


Cloud provider IPs (Azure, DigitalOcean, Alibaba Cloud, DigitalOcean) appear throughout, suggesting compromised VMs are being used as attack relays. This is a common tactic to evade IP reputation blocklists.


I have already done the following recommended hardening steps, and I'm posting it here to help others as well:

  1. Change SSH to a non-standard port to eliminate the bulk of automated scans
  2. Enforce key-only authentication (PasswordAuthentication no in sshd_config)
  3. Increase fail2ban bantime to at least 24 hours, or use permanent bans with bantime = -1 for repeat offenders
  4. Add 77.83.39.153 and 2.57.122.162 to UFW as permanent denies immediately
  5. Consider maxretry = 3 if it isn't already. Most logs show 10+ attempts before a ban triggers


Related Articles

A Study Shows Schools Need Better AI Policies, Not Better AI Detectors (Here Are 5)

We talk a lot about human-centered AI in education today. We tell students to use AI responsibly and keep their critical thinking sharp. But here is the ironic reality on …

Read More →

Practical use case of Vibe-coding for Parents

For parents, one practical use of Vibe-coding is when your children need a review for their summative exams. You can create an interactive webpage for them.

Read More →

Free Agentic Coding

Let's face it. Not all developers can afford to continuously pay for AI subscriptions. Even a $20 per month can be expensive for many in the Philippines. GitHub Copilot may …

Read More →

Subscribe to Updates

Get notified about new blog posts, AI insights, and digital transformation strategies.

We respect your privacy. Unsubscribe at any time.