Unwanted traffic detected by honeypot on February 01, 2024: port scans (105 port 22 scans), and brut ...
show moreUnwanted traffic detected by honeypot on February 01, 2024: port scans (105 port 22 scans), and brute force and hacking attacks (18 over ssh).
show less
DATE:2024-02-01 23:16:44, IP:167.99.176.79, PORT:ssh SSH brute force auth on honeypot server (epe-ho ...
show moreDATE:2024-02-01 23:16:44, IP:167.99.176.79, PORT:ssh SSH brute force auth on honeypot server (epe-honey1-hq)
show less
Feb 1 23:01:09 petr-testing sshd[18903]: Failed password for invalid user elasticsearch from 167.99 ...
show moreFeb 1 23:01:09 petr-testing sshd[18903]: Failed password for invalid user elasticsearch from 167.99.176.79 port 50340 ssh2
Feb 1 23:11:12 petr-testing sshd[27255]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
Feb 1 23:11:14 petr-testing sshd[27255]: Failed password for invalid user server from 167.99.176.79 port 51188 ssh2
Feb 1 23:11:26 petr-testing sshd[27852]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
...
show less
Feb 1 22:50:34 petr-testing sshd[8531]: pam_unix(sshd:auth): authentication failure; logname= uid=0 ...
show moreFeb 1 22:50:34 petr-testing sshd[8531]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
Feb 1 22:50:36 petr-testing sshd[8531]: Failed password for invalid user \357\273\277root from 167.99.176.79 port 48578 ssh2
Feb 1 22:50:42 petr-testing sshd[9128]: Failed password for root from 167.99.176.79 port 48784 ssh2
...
show less
Fail2Ban automatic report:
SSH brute-force:
Feb 1 21:26:27 serw sshd[2530552]: Unable to negotiate ...
show moreFail2Ban automatic report:
SSH brute-force:
Feb 1 21:26:27 serw sshd[2530552]: Unable to negotiate with 167.99.176.79 port 57104: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]
Feb 1 21:26:32 serw sshd[2530554]: Unable to negotiate with 167.99.176.79 port 56622: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]
Feb 1 21:26:37 serw sshd[2530560]: Unable to negotiate with 167.99.176.79 port 55998: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]
show less
Report 979907 with IP 2027453 for SSH brute-force attack by source 2022132 via ssh-honeypot/0.2.0+ht ...
show moreReport 979907 with IP 2027453 for SSH brute-force attack by source 2022132 via ssh-honeypot/0.2.0+http
show less
2024-02-01T20:35:54.102376+01:00 srv1.renaudna.fr sshd[26019]: Connection closed by 167.99.176.79 po ...
show more2024-02-01T20:35:54.102376+01:00 srv1.renaudna.fr sshd[26019]: Connection closed by 167.99.176.79 port 49338
2024-02-01T20:36:05.368805+01:00 srv1.renaudna.fr sshd[26020]: Unable to negotiate with 167.99.176.79 port 49510: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]
2024-02-01T20:36:11.080122+01:00 srv1.renaudna.fr sshd[26024]: Unable to negotiate with 167.99.176.79 port 49534: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1,diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1 [preauth]
...
show less
fail2ban/Feb 1 19:55:59 h1962932 sshd[18920]: Invalid user \357\273\277root from 167.99.176.79 port ...
show morefail2ban/Feb 1 19:55:59 h1962932 sshd[18920]: Invalid user \357\273\277root from 167.99.176.79 port 51198
Feb 1 19:55:59 h1962932 sshd[18920]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
Feb 1 19:56:01 h1962932 sshd[18920]: Failed password for invalid user \357\273\277root from 167.99.176.79 port 51198 ssh2
Feb 1 19:56:06 h1962932 sshd[18957]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79 user=root
Feb 1 19:56:08 h1962932 sshd[18957]: Failed password for root from 167.99.176.79 port 50788 ssh2
show less
Feb 1 17:48:12 rm sshd[202961]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 ...
show moreFeb 1 17:48:12 rm sshd[202961]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
Feb 1 17:48:14 rm sshd[202961]: Failed password for invalid user \357\273\277root from 167.99.176.79 port 50480 ssh2
Feb 1 17:48:20 rm sshd[202965]: Failed password for root from 167.99.176.79 port 50066 ssh2
...
show less
Feb 1 18:23:02 dev0-dcde-rnet sshd[3637]: pam_unix(sshd:auth): authentication failure; logname= uid ...
show moreFeb 1 18:23:02 dev0-dcde-rnet sshd[3637]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.176.79
Feb 1 18:23:04 dev0-dcde-rnet sshd[3637]: Failed password for invalid user \357\273\277root from 167.99.176.79 port 36084 ssh2
Feb 1 18:23:10 dev0-dcde-rnet sshd[3639]: Failed password for root from 167.99.176.79 port 35570 ssh2
show less