Code: Select all
Nov 25 01:32:00 XXXX-XX-XX-XX-XX-XX-XX sshd[12574]: Address 198.XX.XXX.XX164 maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:00 XXXX-XX-XX-XX-XX-XX-XX sshd[12574]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:00 XXXX-XX-XX-XX-XX-XX-XX sshd[12576]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:00 XXXX-XX-XX-XX-XX-XX-XX sshd[12576]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12578]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12578]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12580]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12580]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12582]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:01 XXXX-XX-XX-XX-XX-XX-XX sshd[12582]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12584]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12584]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12586]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12586]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12588]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:02 XXXX-XX-XX-XX-XX-XX-XX sshd[12588]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12590]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12590]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12592]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12592]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12594]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:03 XXXX-XX-XX-XX-XX-XX-XX sshd[12594]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12596]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12596]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12598]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12598]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12600]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12600]: Invalid user oracle from 198.XX.XXX.
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12600]: input_userauth_request: invalid user oracle [preauth]
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12600]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12602]: Address 198.XX.XXX. maps to mav11.chev.4p.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT!
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12602]: Invalid user oracle from 198.XX.XXX.
Nov 25 01:32:04 XXXX-XX-XX-XX-XX-XX-XX sshd[12602]: input_userauth_request: invalid user oracle [preauth]
Nov 25 01:32:05 XXXX-XX-XX-XX-XX-XX-XX sshd[12602]: Received disconnect from 198.XX.XXX.: 11: Bye Bye [preauth]
I should also add that the IP maps back to two specific domains, one of which was registered the day of the "attacks" and the other three days prior.
Can anyone shed any additional light on this?
Thanks!