112.213.98.94 (HK/Hong Kong/-), 6 distributed sshd attacks on account [root] in the last 3600 secs; ...
show more112.213.98.94 (HK/Hong Kong/-), 6 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: 1; Trigger: LF_DISTATTACK; Logs: Jun 6 18:34:46 15216 sshd[3547]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=112.213.98.94 user=root
Jun 6 18:23:47 15216 sshd[1577]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=138.124.242.66 user=root
Jun 6 18:23:49 15216 sshd[1577]: Failed password for root from 138.124.242.66 port 43232 ssh2
Jun 6 18:23:51 15216 sshd[1577]: Failed password for root from 138.124.242.66 port 43232 ssh2
Jun 6 18:23:53 15216 sshd[1577]: Failed password for root from 138.124.242.66 port 43232 ssh2
Jun 6 18:23:55 15216 sshd[1577]: Failed password for root from 138.124.242.66 port 43232 ssh2
IP Addresses Blocked:
show less
Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: ME ...
show moreHoneypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud
show less
2026-06-05T21:04:47.403398+02:00 router01.dui.de.mersrv.de sshd[3702855]: Connection closed by authe ...
show more2026-06-05T21:04:47.403398+02:00 router01.dui.de.mersrv.de sshd[3702855]: Connection closed by authenticating user admin 112.213.98.94 port 34766 [preauth]
2026-06-05T21:05:22.057544+02:00 router01.dui.de.mersrv.de sshd[3703076]: Invalid user orangepi from 112.213.98.94 port 54252
2026-06-05T21:05:23.059668+02:00 router01.dui.de.mersrv.de sshd[3703076]: Connection closed by invalid user orangepi 112.213.98.94 port 54252 [preauth]
2026-06-05T21:05:59.112206+02:00 router01.dui.de.mersrv.de sshd[3703171]: Connection closed by authenticating user root 112.213.98.94 port 45780 [preauth]
2026-06-05T21:06:35.431497+02:00 router01.dui.de.mersrv.de sshd[3703356]: Connection closed by authenticating user root 112.213.98.94 port 36946 [preauth]
show less
Brute-Force
Anonymous
2026-06-04T23:23:44.397903+02:00 mail sshd[2180925]: Invalid user orangepi from 112.213.98.94 port 4 ...
show more2026-06-04T23:23:44.397903+02:00 mail sshd[2180925]: Invalid user orangepi from 112.213.98.94 port 42040
2026-06-04T23:23:44.402138+02:00 mail sshd[2180925]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=112.213.98.94
2026-06-04T23:23:46.288740+02:00 mail sshd[2180925]: Failed password for invalid user orangepi from 112.213.98.94 port 42040 ssh2
2026-06-04T23:24:25.118623+02:00 mail sshd[2180970]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=112.213.98.94 user=root
2026-06-04T23:24:27.300575+02:00 mail sshd[2180970]: Failed password for root from 112.213.98.94 port 35316 ssh2
...
show less