Home >

Scoundrels

D --> f001ish attempts at misuse of resources


D --> via http

259 requests from 190.254.11.125
257 requests from 211.159.179.174
250 requests from 176.98.41.100
250 requests from 200.48.214.19
246 requests from 192.144.170.248
244 requests from 182.61.54.213
243 requests from 119.1.96.157
241 requests from 103.73.161.251
240 requests from 114.116.43.85
240 requests from 119.29.113.69
108 requests from 72.79.117.32
40 requests from 92.233.215.55
15 requests from 94.102.57.141
11 requests from 212.237.45.125
3 requests from 212.67.214.96
... 87 items truncated ...
36 requests for/
17 requests for/wp-login.php
10 requests for/l7.php
10 requests for/admin/mysql/index.php
10 requests for/cacti/plugins/weathermap/editor.php
10 requests for/aotu.php
10 requests for/phpmyadmin/index.php
10 requests for/wshell.php
10 requests for/typo3/phpmyadmin/index.php
10 requests for/admin/phpmyadmin/index.php
10 requests for/muhstik-dpr.php
10 requests for/qaz.php
10 requests for/cmv.php
10 requests for/help-e.php
10 requests for/123.php
... 419 items truncated ...

D --> via ssh

25attempts from  159.65.64.0/20
19attempts from  73.0.0.0/8
12attempts from  80.26.0.0/16
12attempts from  207.244.144.0/20
12attempts from  176.31.0.0/16
12attempts from  122.167.160.0/20
12attempts from  118.40.0.0/13
10attempts from  91.121.0.0/16
9attempts from  167.114.0.0/17
9attempts from  112.198.56.0/21
9attempts from  109.87.224.0/24
8attempts from  5.188.10.0/24
7attempts from  51.254.0.0/15
6attempts from  83.228.128.0/17
6attempts from  59.144.0.0/15
6attempts from  37.59.0.0/16
6attempts from  37.195.0.0/16
6attempts from  37.187.0.0/16
6attempts from  27.96.91.0/24
6attempts from  24.134.0.0/18
... 23 items truncated ...
72attempts on admin
45attempts on root
34attempts on test
14attempts on www-data
12attempts on postgres
11attempts on user
11attempts on pi
8attempts on ubuntu
8attempts on oracle
8attempts on nagios
7attempts on squid
7attempts on ftpuser
6attempts on tomcat
6attempts on support
6attempts on setup
6attempts on compta
5attempts on guest
5attempts on castis
5attempts on administrator
4attempts on wpyan
... 113 items truncated ..

D --> via smtp

4 attempts from 2.83.118.254
4 attempts from 2.86.11.136
4 attempts from 5.204.221.96
4 attempts from 14.164.47.83
4 attempts from 14.185.47.74
4 attempts from 23.254.166.221
494 attempts from 23.254.211.210
4 attempts from 27.78.21.233
4 attempts from 27.114.165.150
4 attempts from 31.167.101.246
4 attempts from 37.119.243.42
4 attempts from 37.134.150.0
4 attempts from 39.48.69.250
4 attempts from 41.33.56.225
4 attempts from 41.89.195.2
... 58 items truncated ..
588 of reject: RCPT from [...]: 554 5.7.1
194 of reject: RCPT from [...]: 550 5.7.1
80 of Client host [...] blocked using bl.spamcop.net;
30 of warning: unknown[185.222.209.84]: SASL PLAIN authentication failed:
9 of Client host [...] blocked using cbl.abuseat.org;
8 of reject: RCPT from [...]: 450 4.1.8
6 of warning: unknown[185.222.209.83]: SASL PLAIN authentication failed:
5 of Received-SPF: permerror
4 of warning: numeric domain name in resource data of MX record for [...]
3 of warning: ns515505.ip-198-27-64.net[198.27.64.162]: SASL PLAIN authentication failed:

D --> blacklisted

The first set are ranges blacklisted by hand
pkts bytes target prot opt in out source destination
135 6787 REFUSE all -- * * 222.176.0.0/12 0.0.0.0/0
2026 128K REFUSE all -- * *  58.192.0.0/11 *
31 1252 REFUSE all -- * *  111.72.0.0/13 *
1437 88891 REFUSE all -- * *  111.192.0.0/12 *
29 1404 REFUSE all -- * *  118.24.0.0/15 *
257 10764 REFUSE all -- * *  125.64.0.0/11 *
916 59980 REFUSE all -- * *  221.224.0.0/13 *
18 860 REFUSE all -- * *  222.128.0.0/12 *

These were blacklisted automatically by triggering a trap
1 40 REFUSE all -- * *  1.186.113.74 *
1 60 REFUSE all -- * *  1.234.63.185 *
0 0 REFUSE all -- * *  2.87.13.186 *
1 40 REFUSE all -- * *  5.34.1.193 *
7 412 REFUSE all -- * *  5.151.0.118 *
0 0 REFUSE all -- * *  14.118.54.202 *
1 40 REFUSE all -- * *  24.43.146.118 *
0 0 REFUSE all -- * *  27.0.254.177 *
6 304 REFUSE all -- * *  37.115.188.53 *
0 0 REFUSE all -- * *  37.134.216.64 *
0 0 REFUSE all -- * *  37.202.95.53 *
1 40 REFUSE all -- * *  37.252.83.38 *
0 0 REFUSE all -- * *  39.43.171.70 *
0 0 REFUSE all -- * *  39.57.255.155 *
0 0 REFUSE all -- * *  42.112.28.157 *
0 0 REFUSE all -- * *  43.252.100.28 *
0 0 REFUSE all -- * *  45.18.11.97 *
0 0 REFUSE all -- * *  45.40.165.6 *
0 0 REFUSE all -- * *  45.40.165.15 *
0 0 REFUSE all -- * *  45.77.91.134 *
0 0 REFUSE all -- * *  46.41.144.26 *
9 424 REFUSE all -- * *  47.51.74.186 *
0 0 REFUSE all -- * *  49.144.198.195 *
9 360 REFUSE all -- * *  49.146.251.15 *
4 160 REFUSE all -- * *  49.148.9.156 *
0 0 REFUSE all -- * *  49.206.7.41 *
0 0 REFUSE all -- * *  50.63.197.202 *
8 344 REFUSE all -- * *  50.87.144.167 *
0 0 REFUSE all -- * *  50.87.248.64 *
6 240 REFUSE all -- * *  58.27.219.115 *
14 716 REFUSE all -- * *  59.152.92.110 *
0 0 REFUSE all -- * *  60.53.11.90 *
0 0 REFUSE all -- * *  62.102.148.160 *
0 0 REFUSE all -- * *  62.150.199.201 *
5 244 REFUSE all -- * *  64.231.253.196 *
0 0 REFUSE all -- * *  65.182.101.66 *
7 280 REFUSE all -- * *  65.182.101.71 *
0 0 REFUSE all -- * *  66.135.63.227 *
0 0 REFUSE all -- * *  67.180.10.215 *
0 0 REFUSE all -- * *  67.205.10.101 *
2 80 REFUSE all -- * *  67.205.13.248 *
108 6480 REFUSE all -- * *  69.27.124.170 *
9 372 REFUSE all -- * *  69.57.235.78 *
0 0 REFUSE all -- * *  69.195.124.206 *
8 344 REFUSE all -- * *  69.195.124.244 *
3 120 REFUSE all -- * *  70.45.128.6 *
0 0 REFUSE all -- * *  70.64.207.98 *
0 0 REFUSE all -- * *  70.179.5.62 *
0 0 REFUSE all -- * *  72.29.127.15 *
1 52 REFUSE all -- * *  73.184.73.233 *
0 0 REFUSE all -- * *  75.161.12.182 *
0 0 REFUSE all -- * *  76.69.169.162 *
0 0 REFUSE all -- * *  77.126.1.134 *
1 40 REFUSE all -- * *  78.87.97.40 *
13 648 REFUSE all -- * *  78.190.229.25 *
0 0 REFUSE all -- * *  78.250.204.161 *
8 344 REFUSE all -- * *  79.170.40.242 *
13 596 REFUSE all -- * *  79.185.152.145 *
0 0 REFUSE all -- * *  80.88.86.23 *
0 0 REFUSE all -- * *  80.107.88.127 *
1 60 REFUSE all -- * *  81.169.144.135 *
0 0 REFUSE all -- * *  82.46.211.252 *
0 0 REFUSE all -- * *  82.84.7.211 *
7 304 REFUSE all -- * *  82.116.32.74 *
11 1128 REFUSE all -- * *  82.165.81.63 *
13 592 REFUSE all -- * *  83.44.103.82 *
0 0 REFUSE all -- * *  83.45.145.208 *
0 0 REFUSE all -- * *  83.53.164.186 *
0 0 REFUSE all -- * *  83.132.22.22 *
4 160 REFUSE all -- * *  84.20.83.36 *
0 0 REFUSE all -- * *  84.46.255.164 *
0 0 REFUSE all -- * *  84.236.115.24 *
0 0 REFUSE all -- * *  85.96.152.56 *
0 0 REFUSE all -- * *  85.101.185.177 *
8 396 REFUSE all -- * *  85.146.191.153 *
0 0 REFUSE all -- * *  87.7.229.251 *
13 648 REFUSE all -- * *  87.116.176.105 *
1 40 REFUSE all -- * *  88.5.153.122 *
7 352 REFUSE all -- * *  89.64.58.58 *
0 0 REFUSE all -- * *  89.100.168.72 *
0 0 REFUSE all -- * *  89.143.136.208 *
1 40 REFUSE all -- * *  89.164.243.72 *
0 0 REFUSE all -- * *  89.253.232.124 *
16 1086 REFUSE all -- * *  91.208.99.2 *
7 312 REFUSE all -- * *  93.185.26.206 *
25 1160 REFUSE all -- * *  94.19.172.76 *
0 0 REFUSE all -- * *  94.43.130.37 *
1 40 REFUSE all -- * *  94.60.69.221 *
2 92 REFUSE all -- * *  94.73.55.58 *
1 40 REFUSE all -- * *  94.140.83.45 *
0 0 REFUSE all -- * *  94.177.14.48 *
0 0 REFUSE all -- * *  95.40.149.45 *
0 0 REFUSE all -- * *  95.63.95.145 *
0 0 REFUSE all -- * *  96.127.220.236 *
0 0 REFUSE all -- * *  103.10.120.154 *
0 0 REFUSE all -- * *  103.18.109.163 *
0 0 REFUSE all -- * *  103.53.166.145 *
1 40 REFUSE all -- * *  103.66.79.77 *
0 0 REFUSE all -- * *  103.66.212.228 *
1 40 REFUSE all -- * *  103.199.234.107 *
0 0 REFUSE all -- * *  103.255.31.84 *
7 344 REFUSE all -- * *  105.108.139.101 *
0 0 REFUSE all -- * *  107.174.86.179 *
0 0 REFUSE all -- * *  109.78.176.190 *
0 0 REFUSE all -- * *  109.148.112.36 *
0 0 REFUSE all -- * *  109.175.98.197 *
9 432 REFUSE all -- * *  109.242.108.176 *
0 0 REFUSE all -- * *  111.92.24.179 *
0 0 REFUSE all -- * *  112.201.167.71 *
0 0 REFUSE all -- * *  113.12.99.160 *
0 0 REFUSE all -- * *  113.66.34.43 *
4 160 REFUSE all -- * *  115.28.111.201 *
0 0 REFUSE all -- * *  115.28.229.143 *
0 0 REFUSE all -- * *  115.164.87.98 *
1 40 REFUSE all -- * *  117.98.198.159 *
0 0 REFUSE all -- * *  117.102.0.96 *
7 508 REFUSE all -- * *  117.196.231.151 *
0 0 REFUSE all -- * *  119.23.220.191 *
1 40 REFUSE all -- * *  119.29.4.85 *
0 0 REFUSE all -- * *  119.159.144.46 *
5 200 REFUSE all -- * *  120.24.60.115 *
3 120 REFUSE all -- * *  120.27.37.74 *
6 240 REFUSE all -- * *  120.27.103.132 *
0 0 REFUSE all -- * *  121.32.193.10 *
0 0 REFUSE all -- * *  121.42.13.194 *
0 0 REFUSE all -- * *  121.42.54.54 *
0 0 REFUSE all -- * *  122.167.209.179 *
7 344 REFUSE all -- * *  123.100.177.89 *
0 0 REFUSE all -- * *  125.162.79.187 *
17 909 REFUSE all -- * *  125.162.192.119 *
4 192 REFUSE all -- * *  130.105.10.37 *
0 0 REFUSE all -- * *  130.105.243.52 *
7 344 REFUSE all -- * *  131.213.187.77 *
0 0 REFUSE all -- * *  134.90.130.109 *
32 1612 REFUSE all -- * *  134.249.49.211 *
7 280 REFUSE all -- * *  143.255.154.200 *
0 0 REFUSE all -- * *  143.255.155.72 *
0 0 REFUSE all -- * *  143.255.155.173 *
1 40 REFUSE all -- * *  153.168.127.29 *
0 0 REFUSE all -- * *  154.73.10.91 *
10 424 REFUSE all -- * *  158.69.221.182 *
0 0 REFUSE all -- * *  160.119.122.28 *
0 0 REFUSE all -- * *  160.120.55.192 *
8 344 REFUSE all -- * *  162.208.49.151 *
8 344 REFUSE all -- * *  162.215.248.51 *
0 0 REFUSE all -- * *  162.215.248.87 *
0 0 REFUSE all -- * *  169.0.111.55 *
7 344 REFUSE all -- * *  174.110.77.110 *
7 328 REFUSE all -- * *  175.112.191.190 *
4 192 REFUSE all -- * *  175.143.138.186 *
7 352 REFUSE all -- * *  175.156.17.179 *
0 0 REFUSE all -- * *  175.158.201.9 *
0 0 REFUSE all -- * *  176.9.146.157 *
4 192 REFUSE all -- * *  177.97.42.18 *
0 0 REFUSE all -- * *  177.223.86.111 *
0 0 REFUSE all -- * *  177.247.99.95 *
19 952 REFUSE all -- * *  178.137.89.28 *
0 0 REFUSE all -- * *  178.149.8.44 *
0 0 REFUSE all -- * *  179.96.147.117 *
4 192 REFUSE all -- * *  180.204.51.33 *
7 352 REFUSE all -- * *  181.45.97.81 *
0 0 REFUSE all -- * *  181.64.4.234 *
0 0 REFUSE all -- * *  182.176.222.130 *
0 0 REFUSE all -- * *  182.185.242.85 *
13 584 REFUSE all -- * *  183.87.146.68 *
0 0 REFUSE all -- * *  184.162.229.19 *
0 0 REFUSE all -- * *  184.168.152.149 *
0 0 REFUSE all -- * *  185.180.198.27 *
0 0 REFUSE all -- * *  185.220.101.30 *
0 0 REFUSE all -- * *  186.6.204.101 *
6 264 REFUSE all -- * *  186.202.153.99 *
0 0 REFUSE all -- * *  188.250.220.37 *
4 192 REFUSE all -- * *  189.32.160.208 *
7 280 REFUSE all -- * *  189.112.148.73 *
0 0 REFUSE all -- * *  190.172.165.140 *
0 0 REFUSE all -- * *  190.245.221.225 *
0 0 REFUSE all -- * *  191.223.120.127 *
8 344 REFUSE all -- * *  192.185.2.179 *
8 480 REFUSE all -- * *  193.106.30.98 *
8 384 REFUSE all -- * *  193.169.252.189 *
12 608 REFUSE all -- * *  193.201.224.225 *
7 304 REFUSE all -- * *  193.226.34.72 *
0 0 REFUSE all -- * *  194.228.152.55 *
0 0 REFUSE all -- * *  196.188.12.47 *
2 92 REFUSE all -- * *  197.28.23.47 *
13 664 REFUSE all -- * *  201.6.229.55 *
13 648 REFUSE all -- * *  201.81.70.96 *
0 0 REFUSE all -- * *  201.131.241.81 *
6 240 REFUSE all -- * *  202.137.155.111 *
7 344 REFUSE all -- * *  202.142.107.61 *
0 0 REFUSE all -- * *  203.189.234.88 *
0 0 REFUSE all -- * *  208.114.128.18 *
0 0 REFUSE all -- * *  208.114.128.63 *
0 0 REFUSE all -- * *  209.59.71.122 *
7 344 REFUSE all -- * *  210.18.173.72 *
1 40 REFUSE all -- * *  212.58.112.165 *
0 0 REFUSE all -- * *  212.181.51.162 *
0 0 REFUSE all -- * *  213.251.182.115 *
0 0 REFUSE all -- * *  216.120.252.102 *
7 352 REFUSE all -- * *  216.126.201.170 *
1 40 REFUSE all -- * *  218.215.146.214 *
7 344 REFUSE all -- * *  219.90.101.202 *
0 0 REFUSE all -- * *  219.92.198.222 *
0 0 REFUSE all -- * *  223.130.27.201 *

Last updated Thu Nov 15 11:51:39 2018