ip.dilenatech.com
08 Dec 2021
2021-12-09 03:46:34,248 fail2ban.actions [1101]: NOTICE [asterisk-challenge] Ban 137.74.23.2 ... show more 2021-12-09 03:46:34,248 fail2ban.actions [1101]: NOTICE [asterisk-challenge] Ban 137.74.23.249
... show less
Brute-Force
SSH
Rentel Telecom
08 Dec 2021
SIP Brute Force
Fraud VoIP
Brute-Force
sgofferj
08 Dec 2021
Attack attempt on SIP server
Fraud VoIP
Hacking
Brute-Force
6GNet.pl
08 Dec 2021
\[2021-12-09 02:24:32\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventT ... show more \[2021-12-09 02:24:32\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-09T02:24:32.155+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="144",SessionID="0x7ff07c0f62f8",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5155",Challenge="51ecdb0a",ReceivedChallenge="51ecdb0a",ReceivedHash="3565e618ad9c6e2f640c76e49ffa2f86"
\[2021-12-09 02:24:32\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-09T02:24:32.244+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="144",SessionID="0x7ff07c1607c8",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5155",Challenge="4121cb8f",ReceivedChallenge="4121cb8f",ReceivedHash="f8d1f67eeda5c9fcfbf49678014ba2f1"
\[2021-12-09 02:24:32\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-09T02:24:32.270+0100",Severity="Error",Service="SIP",EventVersion="2",Acc
... show less
Fraud VoIP
Brute-Force
giant.rocks
07 Dec 2021
[Dec 7 20:34:08] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021- ... show more [Dec 7 20:34:08] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-07T20:34:08.819-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="10000",SessionID="71550dd10a09aafd28abc3551a51f1c5",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/40118"
[Dec 7 20:34:22] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-07T20:34:22.256-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="10000",SessionID="1818355871",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5714"
[Dec 7 20:34:22] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-07T20:34:22.528-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="10000",SessionID="1818355871",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5714"
[Dec 7 20:34:22] SECURITY[4826] res_security_log.c: SecurityEvent="Challe
... show less
Fraud VoIP
Hacking
Brute-Force
ingentar
07 Dec 2021
\[2021-12-07 19:46:38\] NOTICE\[16370\] chan_sip.c: Registration from \'"10000" \<sip:[email protected] ... show more \[2021-12-07 19:46:38\] NOTICE\[16370\] chan_sip.c: Registration from \'"10000" \<sip:[email protected] \>\' failed for \'137.74.23.249:5392\' - Wrong password\[2021-12-07 19:46:38\] SECURITY\[16484\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-07T19:46:38.004-0500",Severity="Error",Service="SIP",EventVersion="2",AccountID="10000",SessionID="0x7f68d02ab328",LocalAddress="IPV4/UDP/181.143.117.59/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5392",Challenge="512d89bc",ReceivedChallenge="512d89bc",ReceivedHash="1c403778c2ab97d1fa051d9228c5afd7"\[2021-12-07 19:46:38\] NOTICE\[16370\] chan_sip.c: Registration from \'"10000" \<sip:[email protected] \>\' failed for \'137.74.23.249:5392\' - Wrong password\[2021-12-07 19:46:38\] SECURITY\[16484\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-07T19:46:38.213-0500",Severity="Error",Service="SIP",EventVersion="2",AccountID="10000",SessionID="0x7f68d0246c68",LocalAddress="IPV4/UDP/181.143.117.59/506
... show less
Fraud VoIP
Brute-Force
Rentel Telecom
07 Dec 2021
SIP Brute Force
Fraud VoIP
Brute-Force
6GNet.pl
07 Dec 2021
\[2021-12-07 23:55:58\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventT ... show more \[2021-12-07 23:55:58\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-07T23:55:58.730+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="10000",SessionID="0x7ff07c090798",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5390",Challenge="185ac88b",ReceivedChallenge="185ac88b",ReceivedHash="2adc2e50679787ea6126530f00ba77a8"
\[2021-12-07 23:55:58\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-07T23:55:58.792+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="10000",SessionID="0x7ff07c0ee958",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5390",Challenge="7a98d785",ReceivedChallenge="7a98d785",ReceivedHash="a4c5980ff540295b5c36c3fcd4591876"
\[2021-12-07 23:55:58\] SECURITY\[32659\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-07T23:55:58.842+0100",Severity="Error",Service="SIP",EventVersion="2"
... show less
Fraud VoIP
Brute-Force
giant.rocks
05 Dec 2021
[Dec 5 06:05:04] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021- ... show more [Dec 5 06:05:04] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-05T06:05:04.900-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="203",SessionID="7ad0da56129c27a139158f0faca66173",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/33185"
[Dec 5 06:05:09] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-05T06:05:09.649-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="203",SessionID="2748184146",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5389"
[Dec 5 06:05:09] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-05T06:05:09.731-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="203",SessionID="2748184146",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5389"
[Dec 5 06:05:09] SECURITY[4826] res_security_log.c: SecurityEvent="ChallengeRes
... show less
Fraud VoIP
Hacking
Brute-Force
ipoac.nl
04 Dec 2021
[Dec 5 04:46:41] SECURITY[5624] res_security_log.c: SecurityEvent="FailedACL",EventTV="2021-12-05T0 ... show more [Dec 5 04:46:41] SECURITY[5624] res_security_log.c: SecurityEvent="FailedACL",EventTV="2021-12-05T04:46:41.583+0100",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="anonymous",SessionID="a1157b77dea62f945672623f9fb96dcb",LocalAddress="IPV4/UDP/45.95.239.192/5060",RemoteAddress="IPV4/UDP/137.74.23.249/56046",ACLName="registrar_attempt_without_configured_aors"
[Dec 5 04:46:49] SECURITY[5624] res_security_log.c: SecurityEvent="FailedACL",EventTV="2021-12-05T04:46:49.065+0100",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="anonymous",SessionID="2968157617",LocalAddress="IPV4/UDP/45.95.239.192/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5273",ACLName="registrar_attempt_without_configured_aors"
[Dec 5 04:46:49] SECURITY[5624] res_security_log.c: SecurityEvent="FailedACL",EventTV="2021-12-05T04:46:49.065+0100",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="anonymous",SessionID="2968157617",LocalAddress="IPV4/UDP/45.95.239.192/5060",RemoteAddress="IPV4/UDP/137.74.23.[...] show less
Fraud VoIP
Brute-Force
Rentel Telecom
04 Dec 2021
SIP Brute Force
Fraud VoIP
Brute-Force
6GNet.pl
04 Dec 2021
\[2021-12-04 16:29:14\] SECURITY\[3161\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV ... show more \[2021-12-04 16:29:14\] SECURITY\[3161\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-04T16:29:14.374+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="2222",SessionID="0x3e40ba8",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5341",Challenge="25c8b4ca",ReceivedChallenge="25c8b4ca",ReceivedHash="30292a84296ec8a2c57cfc5ce0b67016"
\[2021-12-04 16:29:14\] SECURITY\[3161\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-04T16:29:14.462+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="2222",SessionID="0x40385f8",LocalAddress="IPV4/UDP/204.8.216.89/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5341",Challenge="37bb89c0",ReceivedChallenge="37bb89c0",ReceivedHash="01e254400355be77364033d387dadd91"
\[2021-12-04 16:29:14\] SECURITY\[3161\] res_security_log.c: SecurityEvent="InvalidPassword",EventTV="2021-12-04T16:29:14.476+0100",Severity="Error",Service="SIP",EventVersion="2",AccountID="222
... show less
Fraud VoIP
Brute-Force
giant.rocks
04 Dec 2021
[Dec 4 04:19:09] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021- ... show more [Dec 4 04:19:09] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-04T04:19:09.116-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="1111",SessionID="718549194758bb28406cf3f4a1cc1785",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/32954"
[Dec 4 04:19:14] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-04T04:19:14.318-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="1111",SessionID="2172591278",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5390"
[Dec 4 04:19:14] SECURITY[4826] res_security_log.c: SecurityEvent="InvalidAccountID",EventTV="2021-12-04T04:19:14.403-0500",Severity="Error",Service="PJSIP",EventVersion="1",AccountID="1111",SessionID="2172591278",LocalAddress="IPV4/UDP/206.81.5.45/5060",RemoteAddress="IPV4/UDP/137.74.23.249/5390"
[Dec 4 04:19:14] SECURITY[4826] res_security_log.c: SecurityEvent="Challenge
... show less
Fraud VoIP
Hacking
Brute-Force
ip.dilenatech.com
04 Dec 2021
2021-12-01 21:54:11,403 fail2ban.actions [1063]: NOTICE [asterisk] Ban 137.74.23.249
2 ... show more 2021-12-01 21:54:11,403 fail2ban.actions [1063]: NOTICE [asterisk] Ban 137.74.23.249
2021-12-03 05:55:46,264 fail2ban.actions [1063]: NOTICE [asterisk-challenge] Ban 137.74.23.249
2021-12-04 06:31:52,286 fail2ban.actions [1063]: NOTICE [asterisk-challenge] Ban 137.74.23.249
... show less
Brute-Force
SSH
Rentel Telecom
03 Dec 2021
SIP Brute Force
Fraud VoIP
Brute-Force