Unwanted traffic detected by honeypot on February 27, 2026: port scans (1 port 22 scan), and brute f ...
show moreUnwanted traffic detected by honeypot on February 27, 2026: port scans (1 port 22 scan), and brute force and hacking attacks (54 over ssh).
show less
Feb 27 15:35:19 kamergaz sshd[2488959]: Failed password for root from 167.99.244.34 port 59132 ssh2
...
show moreFeb 27 15:35:19 kamergaz sshd[2488959]: Failed password for root from 167.99.244.34 port 59132 ssh2
Feb 27 15:36:45 kamergaz sshd[2489691]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.244.34 user=root
Feb 27 15:36:48 kamergaz sshd[2489691]: Failed password for root from 167.99.244.34 port 55934 ssh2
Feb 27 15:38:11 kamergaz sshd[2490335]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.244.34 user=root
Feb 27 15:38:12 kamergaz sshd[2490335]: Failed password for root from 167.99.244.34 port 39060 ssh2
show less
2026-02-27T15:32:05.428209+01:00 server sshd[336351]: User root from 167.99.244.34 not allowed becau ...
show more2026-02-27T15:32:05.428209+01:00 server sshd[336351]: User root from 167.99.244.34 not allowed because listed in DenyUsers
2026-02-27T15:33:36.765581+01:00 server sshd[336583]: User root from 167.99.244.34 not allowed because listed in DenyUsers
2026-02-27T15:35:03.854354+01:00 server sshd[336824]: User root from 167.99.244.34 not allowed because listed in DenyUsers
2026-02-27T15:36:30.138939+01:00 server sshd[337015]: User root from 167.99.244.34 not allowed because listed in DenyUsers
2026-02-27T15:37:58.168904+01:00 server sshd[337247]: User root from 167.99.244.34 not allowed because listed in DenyUsers
...
show less
2026-02-27T15:35:04.282842+01:00 frank sshd-session[3739835]: Failed password for root from 167.99.2 ...
show more2026-02-27T15:35:04.282842+01:00 frank sshd-session[3739835]: Failed password for root from 167.99.244.34 port 38556 ssh2
2026-02-27T15:36:28.683724+01:00 frank sshd-session[3741633]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.244.34 user=root
2026-02-27T15:36:31.041324+01:00 frank sshd-session[3741633]: Failed password for root from 167.99.244.34 port 39410 ssh2
2026-02-27T15:37:56.860127+01:00 frank sshd-session[3743270]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=167.99.244.34 user=root
2026-02-27T15:37:58.698343+01:00 frank sshd-session[3743270]: Failed password for root from 167.99.244.34 port 37936 ssh2
...
show less
2026-02-27T22:31:37.548621+08:00 dh sshd[3237710]: Connection closed by authenticating user root 167 ...
show more2026-02-27T22:31:37.548621+08:00 dh sshd[3237710]: Connection closed by authenticating user root 167.99.244.34 port 55996 [preauth]
2026-02-27T22:33:08.126174+08:00 dh sshd[3237836]: Connection closed by authenticating user root 167.99.244.34 port 58246 [preauth]
2026-02-27T22:34:35.445951+08:00 dh sshd[3237948]: Connection closed by authenticating user root 167.99.244.34 port 39634 [preauth]
2026-02-27T22:36:01.496318+08:00 dh sshd[3238453]: Connection closed by authenticating user root 167.99.244.34 port 55694 [preauth]
2026-02-27T22:37:30.412274+08:00 dh sshd[3238923]: Connection closed by authenticating user root 167.99.244.34 port 49706 [preauth]
show less
2026-02-27T14:31:43.176079+00:00 sg-jumphost-server sshd[1845829]: Connection closed by authenticati ...
show more2026-02-27T14:31:43.176079+00:00 sg-jumphost-server sshd[1845829]: Connection closed by authenticating user root 167.99.244.34 port 38578 [preauth]
2026-02-27T14:33:13.531214+00:00 sg-jumphost-server sshd[1845860]: Connection closed by authenticating user root 167.99.244.34 port 59240 [preauth]
2026-02-27T14:34:40.336056+00:00 sg-jumphost-server sshd[1845890]: Connection closed by authenticating user root 167.99.244.34 port 44352 [preauth]
...
show less
SSH brute-force attempt detected from IP 167.99.244.34: 2026-02-27T14:31:09.725225+00:00 [redacted-h ...
show moreSSH brute-force attempt detected from IP 167.99.244.34: 2026-02-27T14:31:09.725225+00:00 [redacted-hostname] sshd[1693960]: Failed password for invalid user root from 167.99.244.34 port 44888 ssh2 on 1772202846.
show less