Skip to content

Instantly share code, notes, and snippets.

@HauptJ
Created November 18, 2017 03:29
Show Gist options
  • Save HauptJ/4267f85a751ad481cea9b36fd5504785 to your computer and use it in GitHub Desktop.
Save HauptJ/4267f85a751ad481cea9b36fd5504785 to your computer and use it in GitHub Desktop.
IP ban-list for failed SSH logins and attacks
Take note of the times.
212.159.139.204 # lfd: 212.159.139.204 (GB/United Kingdom/host-212-159-139-204.static.as13285.net), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Mon Sep 4 01:40:03 2017
221.232.143.219 # lfd: 221.232.143.219 (CN/China/219.143.232.221.broad.wh.hb.dynamic.163data.com.cn), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Mon Sep 4 01:40:04 2017
213.32.69.137 # lfd: 213.32.69.137 (FR/France/137.ip-213-32-69.eu), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Thu Sep 14 06:41:45 2017
110.45.145.187 # lfd: 110.45.145.187 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Thu Sep 14 06:41:47 2017
210.245.8.79 # lfd: 210.245.8.79 (VN/Vietnam/-), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Thu Sep 14 12:30:26 2017
79.171.75.25 # lfd: 79.171.75.25 (IE/Ireland/-), 5 distributed sshd attacks on account [oracle] in the last 3600 secs - Thu Sep 14 12:30:28 2017
60.248.187.251 # lfd: 60.248.187.251 (TW/Taiwan/www2.hcchurch.org.tw), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Fri Sep 29 15:07:47 2017
211.24.114.151 # lfd: 211.24.114.151 (MY/Malaysia/test.dcatalyst.biz), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Fri Sep 29 15:07:48 2017
92.222.45.136 # lfd: 92.222.45.136 (FR/France/136.ip-92-222-45.eu), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Fri Sep 29 17:08:27 2017
177.22.37.50 # lfd: 177.22.37.50 (BR/Brazil/-), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Fri Sep 29 17:08:28 2017
109.207.159.151 # lfd: 109.207.159.151 (PL/Poland/cpe-109-207-159-151.docsis.tczew.net.pl), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Thu Sep 28 15:48:46 2017
123.207.8.206 # lfd: 123.207.8.206 (CN/China/-), 5 distributed sshd attacks on account [admin] in the last 3600 secs - Thu Sep 28 15:48:48 2017
Raspberry PIs are a very common target.
124.92.196.12 # lfd: 124.92.196.12 (CN/China/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Jul 20 20:29:08 2017
60.225.11.3 # lfd: 60.225.11.3 (AU/Australia/CPE-60-225-11-3.nsw.bigpond.net.au), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Jul 20 20:29:10 2017
108.18.106.181 # lfd: 108.18.106.181 (US/United States/pool-108-18-106-181.washdc.fios.verizon.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Jul 22 07:00:58 2017
117.149.30.106 # lfd: 117.149.30.106 (CN/China/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Jul 22 07:01:08 2017
95.237.149.201 # lfd: 95.237.149.201 (IT/Italy/host201-149-dynamic.237-95-r.retail.telecomitalia.it), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Jul 23 19:33:47 2017
119.207.21.229 # lfd: 119.207.21.229 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Jul 23 19:33:48 2017
186.86.165.201 # lfd: 186.86.165.201 (CO/Colombia/dynamic-ip-18686165201.cable.net.co), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Jul 27 13:07:06 2017
90.142.153.26 # lfd: 90.142.153.26 (SE/Sweden/d90-142-153-26.cust.tele2.se), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Jul 27 13:07:07 2017
125.64.209.11 # lfd: 125.64.209.11 (CN/China/11.209.64.125.broad.yb.sc.dynamic.163data.com.cn), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Aug 1 13:53:26 2017
89.181.239.37 # lfd: 89.181.239.37 (PT/Portugal/89-181-239-37.net.novis.pt), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Aug 1 13:53:27 2017
82.154.54.48 # lfd: 82.154.54.48 (PT/Portugal/bl5-54-48.dsl.telepac.pt), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Wed Aug 9 16:01:06 2017
121.129.186.183 # lfd: 121.129.186.183 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Aug 10 05:08:04 2017
82.253.111.241 # lfd: 82.253.111.241 (FR/France/lns-bzn-38-82-253-111-241.adsl.proxad.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Aug 10 05:08:06 2017
84.230.6.193 # lfd: 84.230.6.193 (FI/Finland/84-230-6-193.elisa-mobile.fi), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Aug 20 16:09:26 2017
121.161.77.161 # lfd: 121.161.77.161 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Aug 20 16:09:27 2017
189.172.43.167 # lfd: 189.172.43.167 (MX/Mexico/dsl-189-172-43-167-dyn.prod-infinitum.com.mx), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Aug 26 10:47:25 2017
183.103.204.37 # lfd: 183.103.204.37 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Aug 26 10:47:26 2017
103.24.49.230 # lfd: 103.24.49.230 (ID/Indonesia/ip-49-230.ppns.ac.id), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Aug 26 20:08:07 2017
85.184.164.136 # lfd: 85.184.164.136 (DK/Denmark/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sat Aug 26 20:08:08 2017
88.121.95.17 # lfd: 88.121.95.17 (FR/France/cau84-1-88-121-95-17.fbx.proxad.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Sep 5 08:00:05 2017
148.101.159.154 # lfd: 148.101.159.154 (DO/Dominican Republic/154.159.101.148.d.dyn.claro.net.do), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Sep 5 08:00:06 2017
197.245.104.44 # lfd: 197.245.104.44 (ZA/South Africa/dsl-197-245-104-44.voxdsl.co.za), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Sep 21 14:54:06 2017
78.212.58.124 # lfd: 78.212.58.124 (FR/France/rou13-2-78-212-58-124.fbx.proxad.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Thu Sep 21 14:54:08 2017
118.32.27.85 # lfd: 118.32.27.85 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Sep 22 12:50:07 2017
109.101.153.162 # lfd: 109.101.153.162 (RO/Romania/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Sep 22 12:50:08 2017
190.166.157.167 # lfd: 190.166.157.167 (DO/Dominican Republic/167.157.166.190.f.sta.codetel.net.do), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Sep 22 13:14:27 2017
219.137.61.7 # lfd: 219.137.61.7 (CN/China/7.61.137.219.broad.gz.gd.dynamic.163data.com.cn), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Sep 22 13:14:28 2017
182.68.238.205 # lfd: 182.68.238.205 (IN/India/abts-north-dynamic-205.238.68.182.airtelbroadband.in), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 1 00:58:03 2017
79.164.85.135 # lfd: 79.164.85.135 (RU/Russian Federation/host-79-164-85-135.qwerty.ru), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 1 00:58:05 2017
68.63.59.8 # lfd: 68.63.59.8 (US/United States/c-68-63-59-8.hsd1.al.comcast.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Oct 6 13:21:26 2017
188.60.216.149 # lfd: 188.60.216.149 (CH/Switzerland/149.216.60.188.dynamic.wline.res.cust.swisscom.ch), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Fri Oct 6 13:21:28 2017
14.58.118.69 # lfd: 14.58.118.69 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 15 18:34:47 2017
195.225.116.21 # lfd: 195.225.116.21 (CH/Switzerland/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 15 18:34:49 2017
109.96.148.62 # lfd: 109.96.148.62 (RO/Romania/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 22 12:58:25 2017
113.252.222.19 # lfd: 113.252.222.19 (HK/Hong Kong/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Sun Oct 22 12:58:27 2017
211.87.226.165 # lfd: 211.87.226.165 (CN/China/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Oct 24 05:19:04 2017
104.7.206.3 # lfd: 104.7.206.3 (US/United States/104-7-206-3.lightspeed.irvnca.sbcglobal.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Tue Oct 24 05:19:06 2017
180.70.170.34 # lfd: 180.70.170.34 (KR/Korea, Republic of/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Wed Nov 1 02:03:23 2017
217.112.105.157 # lfd: 217.112.105.157 (IT/Italy/-), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Wed Nov 1 02:03:25 2017
173.61.183.188 # lfd: 173.61.183.188 (US/United States/pool-173-61-183-188.cmdnnj.fios.verizon.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Wed Nov 8 21:09:07 2017
174.52.249.84 # lfd: 174.52.249.84 (US/United States/c-174-52-249-84.hsd1.ut.comcast.net), 5 distributed sshd attacks on account [pi] in the last 3600 secs - Wed Nov 8 21:09:09 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment