Unwanted traffic detected by honeypot on February 05, 2026: port scans (1 port 22 scan), and brute f ...
show moreUnwanted traffic detected by honeypot on February 05, 2026: port scans (1 port 22 scan), and brute force and hacking attacks (16 over ssh).
show less
2026-02-05T16:38:58.510756-05:00 main-nyc3 sshd[95187]: Invalid user postgres from 152.42.136.58 por ...
show more2026-02-05T16:38:58.510756-05:00 main-nyc3 sshd[95187]: Invalid user postgres from 152.42.136.58 port 37598
2026-02-05T16:41:09.668319-05:00 main-nyc3 sshd[95305]: Invalid user oracle from 152.42.136.58 port 51390
2026-02-05T16:43:06.548124-05:00 main-nyc3 sshd[95368]: Invalid user user from 152.42.136.58 port 46750
2026-02-05T16:45:03.381520-05:00 main-nyc3 sshd[95418]: Invalid user vps from 152.42.136.58 port 33752
2026-02-05T16:47:00.888228-05:00 main-nyc3 sshd[95466]: Invalid user testuser from 152.42.136.58 port 58322
...
show less
[Automated F2B Report] 2026-02-05T21:39:07.005052webserver sshd[780414]: Invalid user postgres from ...
show more[Automated F2B Report] 2026-02-05T21:39:07.005052webserver sshd[780414]: Invalid user postgres from 152.42.136.58 port 33896
2026-02-05T21:41:17.091553webserver sshd[780522]: Invalid user oracle from 152.42.136.58 port 48802
2026-02-05T21:43:19.247539webserver sshd[780555]: Invalid user user from 152.42.136.58 port 33366
...
show less
2026-02-06T08:20:36.796695+11:00 m sshd-session[241026]: Failed password for root from 152.42.136.58 ...
show more2026-02-06T08:20:36.796695+11:00 m sshd-session[241026]: Failed password for root from 152.42.136.58 port 43774 ssh2
2026-02-06T08:23:25.394110+11:00 m sshd-session[241057]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=152.42.136.58 user=root
2026-02-06T08:23:27.440544+11:00 m sshd-session[241057]: Failed password for root from 152.42.136.58 port 36404 ssh2
...
show less
2026-02-05T21:18:52.576979+00:00 sg-jumphost-server sshd[1008113]: Connection closed by authenticati ...
show more2026-02-05T21:18:52.576979+00:00 sg-jumphost-server sshd[1008113]: Connection closed by authenticating user root 152.42.136.58 port 57322 [preauth]
2026-02-05T21:20:19.768428+00:00 sg-jumphost-server sshd[1008252]: Connection closed by authenticating user root 152.42.136.58 port 48188 [preauth]
2026-02-05T21:22:37.893867+00:00 sg-jumphost-server sshd[1008329]: Connection closed by authenticating user root 152.42.136.58 port 40644 [preauth]
...
show less