Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.53.26
sshd[4796]: Failed password for invalid user test from 144.31.53.26 port 64868 ssh2
Count: 25 events in 417s | 14/May/2026:06:13:46 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.148.58
sshd[52943]: Failed password for invalid user ec2-user from 144.31.148.58 port 62701 ssh2
Count: 43 events in 539s | 16/May/2026:08:05:09 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.169.44
sshd[53182]: Failed password for invalid user www-data from 144.31.169.44 port 50310 ssh2
Count: 79 events in 442s | 15/May/2026:19:37:57 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 95.85.251.197
sshd[50622]: Failed password for invalid user bitbucket from 95.85.251.197 port 37839 ssh2
Count: 40 events in 382s | 16/May/2026:21:54:34 +0000
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 2.26.123.36
2.26.123.36 - - [15/May/2026:01:36:17 +0000] "GET /.htaccess HTTP/1.1" 400 2297 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
Count: 19 events
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.53.203
sshd[25331]: Failed password for invalid user ftpuser from 144.31.53.203 port 49328 ssh2
Count: 17 events in 498s | 15/May/2026:01:43:57 +0000
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 95.85.251.65
95.85.251.65 - - [14/May/2026:18:23:15 +0000] "GET /actuator/health HTTP/1.1" 404 5055 "-" "python-requests/2.31.0"
Count: 5 events
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 2.26.123.22
sshd[52556]: Failed password for invalid user pi from 2.26.123.22 port 52372 ssh2
Count: 10 events in 46s | 16/May/2026:04:59:32 +0000
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.238.83
144.31.238.83 - - [15/May/2026:17:17:21 +0000] "GET /solr/admin/info/system HTTP/1.1" 404 3109 "-" "python-requests/2.32.3"
Count: 15 events
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.238.88
sshd[46359]: Failed password for invalid user bitbucket from 144.31.238.88 port 36272 ssh2
Count: 11 events in 251s | 15/May/2026:12:02:50 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.169.54
sshd[9835]: Failed password for invalid user teamspeak from 144.31.169.54 port 40105 ssh2
Count: 28 events in 387s | 16/May/2026:17:28:04 +0000
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.238.201
144.31.238.201 - - [16/May/2026:06:07:53 +0000] "GET /.aws/credentials HTTP/1.1" 404 6975 "-" "python-requests/2.32.3"
Count: 35 events
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 2.26.123.155
2.26.123.155 - - [15/May/2026:11:10:08 +0000] "GET /wp-login.php HTTP/1.1" 403 969 "-" "python-requests/2.32.3"
Count: 49 events
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.148.140
144.31.148.140 - - [16/May/2026:07:45:22 +0000] "GET /backup.sql HTTP/1.1" 404 4198 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
Count: 13 events
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.169.170
144.31.169.170 - - [15/May/2026:18:28:59 +0000] "GET /wp-content/uploads/ HTTP/1.1" 403 3877 "-" "python-requests/2.32.3"
Count: 28 events
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 2.26.122.5
sshd[21245]: Failed password for invalid user info from 2.26.122.5 port 64113 ssh2
Count: 21 events in 436s | 16/May/2026:03:01:42 +0000
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.148.90
144.31.148.90 - - [14/May/2026:17:40:05 +0000] "GET /xmlrpc.php HTTP/1.1" 404 5587 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
Count: 18 events
show less
Wazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 ...
show moreWazuh Alert [Rule 31151 Level 7] - "Multiple web server errors from same source"
agent: webserver-02 | src_ip: 144.31.169.227
144.31.169.227 - - [16/May/2026:05:25:43 +0000] "GET /login.action HTTP/1.1" 400 671 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
Count: 30 events
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.53.210
sshd[31816]: Failed password for invalid user teamspeak from 144.31.53.210 port 53436 ssh2
Count: 9 events in 155s | 16/May/2026:14:53:33 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 95.85.251.132
sshd[15988]: Failed password for invalid user tomcat from 95.85.251.132 port 51548 ssh2
Count: 26 events in 267s | 15/May/2026:07:20:19 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 95.85.251.2
sshd[25560]: Failed password for invalid user minecraft from 95.85.251.2 port 53429 ssh2
Count: 52 events in 99s | 14/May/2026:04:23:20 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.238.151
sshd[4261]: Failed password for invalid user support from 144.31.238.151 port 59455 ssh2
Count: 100 events in 343s | 16/May/2026:05:00:19 +0000
show less
Wazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | s ...
show moreWazuh Alert [Rule 5763 Level 10] - "SSHD brute force trying to get access"
agent: server-prod-01 | src_ip: 144.31.53.42
sshd[28863]: Failed password for invalid user root from 144.31.53.42 port 51001 ssh2
Count: 17 events in 142s | 15/May/2026:14:45:06 +0000
show less