|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-11-08 time=08:44:39 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="cn_admin" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-11-08 time=08:34:29 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="medicamenta" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-10-24 time=09:03:56 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="farma1" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-10-18 time=12:49:21 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="switch" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-10-05 time=08:21:41 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="mcafee" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-09-29 time=10:09:46 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="siemens" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-09-26 time=07:45:53 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="siemens" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
Anonymous
|
|
Attempting to obtain SSL VPN access (multiple attempts in a row)
|
VPN IP
|
|
|
Anonymous
|
|
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2023-07-17 time=05:26:29 devname=FG200E4Q16901016 devid=FG200E4Q16901016 logid=0101039426 type=event subtype=vpn level=alert vd=root logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="crew" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
|
VPN IP
|
|
|
๐น๐ผ
James Chen
|
|
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206 ...
show more
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="terminal"
show less
|
Hacking
Brute-Force
|
|
|
Anonymous
|
|
SSL login attempts, usernames tried:
onedrive
Hyperv
konica
login
Hyper
|
Hacking
Brute-Force
|
|
|
๐น๐ผ
James Chen
|
|
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206 ...
show more
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="warehouse"
show less
|
Hacking
Brute-Force
|
|
|
๐น๐ผ
James Chen
|
|
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206 ...
show more
logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=5.188.206.92 user="warehouse"
show less
|
Port Scan
Hacking
Brute-Force
|
|
|
๐บ๐ธ
WhiteFireOCN1
|
|
4 failed SSL-VPN logins.
UN: 'install', PW: 'install', observed 2023-06-19T22:45:09Z, Firewall ID: ...
show more
4 failed SSL-VPN logins.
UN: 'install', PW: 'install', observed 2023-06-19T22:45:09Z, Firewall ID: 654.
UN: 'install', PW: '1234***' (trunc, len 6), observed 2023-06-19T22:45:09Z, Firewall ID: 654.
UN: 'install', PW: 'install', observed 2023-06-19T22:46:46Z, Firewall ID: b8c.
UN: 'install', PW: '1234***' (trunc, len 6), observed 2023-06-19T22:46:46Z, Firewall ID: b8c.
show less
|
VPN IP
Hacking
Brute-Force
|
|
|
๐น๐ท
CTI-Beholder
|
|
VPN Bruteforce
|
Hacking
Brute-Force
|
|