Nov 1 17:42:32 localhost postfix/smtpd[576692]: lost connection after AUTH from unknown[20.222.28.1 ... show moreNov 1 17:42:32 localhost postfix/smtpd[576692]: lost connection after AUTH from unknown[20.222.28.195]
Nov 1 17:42:34 localhost postfix/smtpd[576692]: lost connection after AUTH from unknown[20.222.28.195]
Nov 1 17:42:38 localhost postfix/smtpd[576692]: lost connection after AUTH from unknown[20.222.28.195]
... show less
Brute-ForceSSH
Anonymous
Nov 1 17:46:19 localhost postfix/smtpd[3743249]: warning: unknown[20.222.28.195]: SASL LOGIN authen ... show moreNov 1 17:46:19 localhost postfix/smtpd[3743249]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 17:46:24 localhost postfix/smtpd[3743249]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 17:46:30 localhost postfix/smtpd[3743249]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
... show less
Brute-Force
Anonymous
Nov 1 15:30:37 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authenticatio ... show moreNov 1 15:30:37 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 15:30:43 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 15:30:48 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 15:30:53 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
Nov 1 15:30:59 wm1 postfix/smtpd[470447]: warning: unknown[20.222.28.195]: SASL LOGIN authentication failed: authentication failure
... show less
lfd: (smtpauth) Failed SMTP AUTH login from 20.222.28.195 (US/United States/-): 5 in the last 3600 s ... show morelfd: (smtpauth) Failed SMTP AUTH login from 20.222.28.195 (US/United States/-): 5 in the last 3600 secs - Wed Nov 1 14:42:33 2023 show less
Nov 1 07:10:29 mailman postfix/smtpd[11558]: lost connection after UNKNOWN from unknown[20.222.28.1 ... show moreNov 1 07:10:29 mailman postfix/smtpd[11558]: lost connection after UNKNOWN from unknown[20.222.28.195]
Nov 1 07:10:29 mailman postfix/smtpd[11558]: lost connection after UNKNOWN from unknown[20.222.28.195] show less
Nov 1 11:42:11 mx1 sshd[110961]: User root from 20.222.28.195 not allowed because not listed in All ... show moreNov 1 11:42:11 mx1 sshd[110961]: User root from 20.222.28.195 not allowed because not listed in AllowUsers show less
20.222.28.195 (US/United States/-), 6 distributed sshd attacks on account [root] in the last 3600 se ... show more20.222.28.195 (US/United States/-), 6 distributed sshd attacks on account [root] in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: Nov 1 06:18:48 server2 sshd[6733]: Failed password for root from 43.154.151.93 port 48418 ssh2
Nov 1 06:23:11 server2 sshd[7878]: Failed password for root from 20.222.28.195 port 60400 ssh2
Nov 1 06:01:36 server2 sshd[2067]: Failed password for root from 203.138.147.67 port 33452 ssh2
Nov 1 06:01:37 server2 sshd[2067]: Failed password for root from 203.138.147.67 port 33452 ssh2
Nov 1 06:01:37 server2 sshd[2067]: Failed password for root from 203.138.147.67 port 33452 ssh2
Nov 1 06:20:59 server2 sshd[7240]: Failed password for root from 118.70.48.219 port 37542 ssh2