Home >

Scoundrels

D --> f001ish attempts at misuse of resources


D --> via http

179 requests from 198.44.226.49
55 requests from 123.206.52.144
55 requests from 144.48.111.222
54 requests from 39.107.249.61
17 requests from 94.102.49.122
4 requests from 194.99.106.147
4 requests from 185.216.34.230
4 requests from 207.89.22.102
2 requests from 119.23.40.168
2 requests from 136.243.89.157
2 requests from 220.243.135.187
2 requests from 220.243.136.88
2 requests from 220.243.135.235
2 requests from 220.243.135.70
2 requests from 220.243.136.7
... 141 items truncated ...
39 requests for/
19 requests for/wp-login.php
5 requests for/...
4 requests for/phpMyAdmin/phpMyAdmin/index.php
4 requests for/index.php
4 requests for/admin/phpmyadmin2/index.php
4 requests for/webdav/
4 requests for/phpmyadmin0/index.php
4 requests for/phpmyadm1n/index.php
4 requests for/myadmin/index.php
4 requests for/phpmyadmin/index.php
4 requests for/admin/mysql2/index.php
4 requests for/phpMyadmin_bak/index.php
4 requests for/admin/phpMyAdmin/index.php
4 requests for/pmamy2/index.php
... 256 items truncated ...

D --> via ssh

36attempts from  51.254.0.0/15
29attempts from  91.121.0.0/16
29attempts from  59.44.0.0/14
28attempts from  106.51.64.0/19
21attempts from  73.0.0.0/8
21attempts from  213.55.89.0/24
21attempts from  188.165.0.0/16
19attempts from  178.32.0.0/15
18attempts from  94.23.0.0/16
17attempts from  164.132.0.0/16
16attempts from  37.187.0.0/16
16attempts from  139.59.0.0/18
15attempts from  54.36.0.0/16
14attempts from  81.174.128.0/17
14attempts from  77.55.0.0/16
14attempts from  217.80.0.0/12
14attempts from  183.82.96.0/19
14attempts from  180.250.159.0/24
14attempts from  112.198.56.0/21
13attempts from  81.128.0.0/12
... 152 items truncated ...
191attempts on root
112attempts on admin
46attempts on test
26attempts on ubuntu
24attempts on pi
23attempts on ftpuser
22attempts on user
16attempts on git
15attempts on support
14attempts on postgres
14attempts on oracle
13attempts on ftp
12attempts on deploy
11attempts on dev
10attempts on user1
10attempts on tomcat
10attempts on minecraft
10attempts on guest
10attempts on demo
9attempts on student
... 290 items truncated ..

D --> via smtp

4 attempts from 1.52.144.253
4 attempts from 2.44.62.201
4 attempts from 2.88.130.198
4 attempts from 2.127.111.245
4 attempts from 5.41.136.81
4 attempts from 5.236.28.24
4 attempts from 5.238.203.106
4 attempts from 14.171.183.148
4 attempts from 14.182.220.17
4 attempts from 14.185.76.83
4 attempts from 14.187.31.111
4 attempts from 14.237.29.29
4 attempts from 24.27.81.63
4 attempts from 27.67.179.246
4 attempts from 27.71.131.224
... 175 items truncated ..
468 of reject: RCPT from [...]: 550 5.7.1
326 of reject: RCPT from [...]: 554 5.7.1
188 of warning: unknown[185.222.209.55]: SASL PLAIN authentication failed:
88 of warning: unknown[185.255.31.122]: SASL PLAIN authentication failed:
79 of Client host [...] blocked using bl.spamcop.net;
16 of reject: RCPT from [...]: 450 4.1.8
8 of Received-SPF: softfail
7 of Client host [...] blocked using cbl.abuseat.org;
2 of warning: non-SMTP command from [...]: GET / HTTP/1.0
2 of warning: TLS library problem: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number:s3_srvr.c:960:
2 of warning: TLS library problem: error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol:s23_srvr.c:640:

D --> blacklisted

The first set are ranges blacklisted by hand
pkts bytes target prot opt in out source destination
0 0 REFUSE all -- * * 222.176.0.0/12 0.0.0.0/0
7 300 REFUSE all -- * *  58.192.0.0/11 *
0 0 REFUSE all -- * *  111.72.0.0/13 *
62 3864 REFUSE all -- * *  111.192.0.0/12 *
2 236 REFUSE all -- * *  118.24.0.0/15 *
6 240 REFUSE all -- * *  125.64.0.0/11 *
2 80 REFUSE all -- * *  221.224.0.0/13 *
0 0 REFUSE all -- * *  222.128.0.0/12 *

These were blacklisted automatically by triggering a trap
0 0 REFUSE all -- * *  1.234.63.185 *
0 0 REFUSE all -- * *  2.220.86.154 *
0 0 REFUSE all -- * *  5.29.35.51 *
0 0 REFUSE all -- * *  14.161.41.167 *
0 0 REFUSE all -- * *  24.19.184.187 *
0 0 REFUSE all -- * *  24.128.139.211 *
0 0 REFUSE all -- * *  31.133.86.79 *
0 0 REFUSE all -- * *  31.192.213.66 *
0 0 REFUSE all -- * *  35.0.127.52 *
0 0 REFUSE all -- * *  36.75.190.68 *
0 0 REFUSE all -- * *  36.84.230.174 *
0 0 REFUSE all -- * *  41.50.3.251 *
0 0 REFUSE all -- * *  41.140.39.135 *
0 0 REFUSE all -- * *  41.189.42.128 *
0 0 REFUSE all -- * *  41.207.1.46 *
0 0 REFUSE all -- * *  41.238.53.8 *
0 0 REFUSE all -- * *  42.201.183.210 *
0 0 REFUSE all -- * *  43.251.172.40 *
0 0 REFUSE all -- * *  45.53.88.99 *
0 0 REFUSE all -- * *  45.116.77.187 *
0 0 REFUSE all -- * *  45.116.237.218 *
0 0 REFUSE all -- * *  46.41.144.26 *
0 0 REFUSE all -- * *  46.118.155.165 *
0 0 REFUSE all -- * *  46.165.10.147 *
0 0 REFUSE all -- * *  46.197.193.231 *
0 0 REFUSE all -- * *  46.208.66.36 *
0 0 REFUSE all -- * *  47.98.176.76 *
0 0 REFUSE all -- * *  47.105.50.212 *
0 0 REFUSE all -- * *  49.148.147.14 *
0 0 REFUSE all -- * *  50.63.197.33 *
0 0 REFUSE all -- * *  50.87.144.137 *
0 0 REFUSE all -- * *  50.116.69.120 *
0 0 REFUSE all -- * *  50.194.92.44 *
0 0 REFUSE all -- * *  60.52.43.63 *
0 0 REFUSE all -- * *  61.19.247.164 *
0 0 REFUSE all -- * *  61.69.144.163 *
0 0 REFUSE all -- * *  62.102.148.166 *
0 0 REFUSE all -- * *  62.121.118.154 *
0 0 REFUSE all -- * *  62.193.157.124 *
0 0 REFUSE all -- * *  66.148.162.102 *
0 0 REFUSE all -- * *  67.83.130.82 *
0 0 REFUSE all -- * *  67.205.10.101 *
0 0 REFUSE all -- * *  69.27.124.170 *
0 0 REFUSE all -- * *  73.54.213.75 *
0 0 REFUSE all -- * *  73.128.187.151 *
0 0 REFUSE all -- * *  74.220.215.240 *
0 0 REFUSE all -- * *  78.146.137.2 *
0 0 REFUSE all -- * *  78.188.146.113 *
0 0 REFUSE all -- * *  78.207.81.252 *
0 0 REFUSE all -- * *  79.101.138.198 *
0 0 REFUSE all -- * *  80.12.80.200 *
0 0 REFUSE all -- * *  80.203.96.32 *
0 0 REFUSE all -- * *  84.244.34.177 *
0 0 REFUSE all -- * *  86.110.118.172 *
0 0 REFUSE all -- * *  86.121.23.144 *
0 0 REFUSE all -- * *  92.53.59.27 *
0 0 REFUSE all -- * *  94.21.252.5 *
6 304 REFUSE all -- * *  94.23.156.20 *
0 0 REFUSE all -- * *  98.139.190.55 *
0 0 REFUSE all -- * *  98.198.160.117 *
0 0 REFUSE all -- * *  103.24.86.73 *
0 0 REFUSE all -- * *  105.105.53.244 *
0 0 REFUSE all -- * *  107.199.177.74 *
0 0 REFUSE all -- * *  109.96.185.135 *
0 0 REFUSE all -- * *  109.166.137.195 *
0 0 REFUSE all -- * *  112.135.44.40 *
0 0 REFUSE all -- * *  112.147.22.54 *
0 0 REFUSE all -- * *  112.200.89.213 *
0 0 REFUSE all -- * *  112.201.56.232 *
0 0 REFUSE all -- * *  117.197.214.78 *
0 0 REFUSE all -- * *  120.24.60.115 *
0 0 REFUSE all -- * *  120.27.114.224 *
0 0 REFUSE all -- * *  122.171.172.64 *
0 0 REFUSE all -- * *  123.249.50.163 *
0 0 REFUSE all -- * *  134.249.141.24 *
0 0 REFUSE all -- * *  140.143.93.167 *
0 0 REFUSE all -- * *  143.238.192.93 *
0 0 REFUSE all -- * *  148.66.70.148 *
0 0 REFUSE all -- * *  149.255.62.4 *
0 0 REFUSE all -- * *  165.49.3.214 *
0 0 REFUSE all -- * *  168.197.209.20 *
0 0 REFUSE all -- * *  172.221.9.243 *
0 0 REFUSE all -- * *  174.55.137.164 *
0 0 REFUSE all -- * *  180.111.238.136 *
0 0 REFUSE all -- * *  180.190.55.219 *
0 0 REFUSE all -- * *  181.31.3.92 *
0 0 REFUSE all -- * *  181.169.254.11 *
0 0 REFUSE all -- * *  181.188.36.163 *
0 0 REFUSE all -- * *  182.1.161.43 *
0 0 REFUSE all -- * *  183.82.217.77 *
0 0 REFUSE all -- * *  183.83.79.139 *
0 0 REFUSE all -- * *  184.89.59.225 *
0 0 REFUSE all -- * *  186.148.134.9 *
0 0 REFUSE all -- * *  187.45.193.171 *
0 0 REFUSE all -- * *  187.58.124.30 *
0 0 REFUSE all -- * *  188.165.197.221 *
0 0 REFUSE all -- * *  188.165.254.65 *
16 800 REFUSE all -- * *  188.165.254.127 *
0 0 REFUSE all -- * *  189.211.78.137 *
0 0 REFUSE all -- * *  192.3.160.105 *
0 0 REFUSE all -- * *  192.99.1.38 *
0 0 REFUSE all -- * *  192.185.4.157 *
0 0 REFUSE all -- * *  192.185.82.183 *
0 0 REFUSE all -- * *  193.106.129.147 *
0 0 REFUSE all -- * *  193.169.252.96 *
0 0 REFUSE all -- * *  193.201.224.17 *
0 0 REFUSE all -- * *  193.201.224.225 *
0 0 REFUSE all -- * *  196.20.253.76 *
0 0 REFUSE all -- * *  197.200.20.176 *
0 0 REFUSE all -- * *  198.27.69.191 *
0 0 REFUSE all -- * *  200.17.160.117 *
0 0 REFUSE all -- * *  201.81.161.220 *
0 0 REFUSE all -- * *  203.112.223.126 *
0 0 REFUSE all -- * *  212.83.188.121 *
0 0 REFUSE all -- * *  213.97.42.29 *
0 0 REFUSE all -- * *  213.251.182.110 *
0 0 REFUSE all -- * *  217.55.208.32 *
0 0 REFUSE all -- * *  217.72.198.198 *
0 0 REFUSE all -- * *  223.74.157.114 *

Last updated Fri Oct 19 23:59:21 2018