"Hacking" attempts on this site
Tags: Random ShitThis server receives many brute force ssh login attempts per day. Many use common linux system user names like root, postgres, www and pi. A lot are also common surnames like Peter, Alex, Jack and Kim. This post is an attempt to make a midly interessting statistic from the data gathered. It shows that bots exist on the internet and that they try to find insufficiently secured servers. The accessing IPs are logged and their location was queried via geolocation-db.com (seems to be down now). This is of course not representative, because the location can be easily spoofed using a VPN and it is even very likely that malicious actors would use one to increase their anonymity on the internet. This has been done out of curiosity more than anything else and to test out the following tools:
Usernames
Username | Count |
---|---|
root | 1800 |
user | 326 |
test | 302 |
ubuntu | 295 |
postgres | 264 |
steam | 260 |
oracle | 253 |
guest | 201 |
ftpuser | 191 |
centos | 184 |
pi | 145 |
testuser | 112 |
es | 105 |
devops | 95 |
ansadmin | 95 |
ansible | 86 |
vagrant | 85 |
ftp | 81 |
hadoop | 79 |
www | 79 |
zjw | 79 |
halo | 79 |
tester | 77 |
esuser | 75 |
dmdba | 73 |
emqx | 66 |
dockeradmin | 64 |
posiflex | 62 |
jenkins | 50 |
dev | 50 |
elastic | 46 |
web | 40 |
33 | |
student | 32 |
ubnt | 32 |
teamspeak | 31 |
minecraft | 28 |
deploy | 27 |
mc | 23 |
support | 23 |
deployer | 22 |
casadiagnosis | 22 |
ts3 | 22 |
a | 21 |
bot | 21 |
discord | 20 |
debian | 20 |
blank | 17 |
1 | 16 |
linux | 16 |
dspace | 16 |
linaro | 15 |
ts3server | 15 |
systems | 15 |
notes | 15 |
carlos | 15 |
q | 14 |
mcserver | 14 |
fa | 14 |
bitrix | 13 |
mailadmin | 12 |
discordbot | 12 |
Test | 11 |
openhabian | 10 |
server | 10 |
Root | 10 |
alex | 10 |
moxa | 10 |
hello | 9 |
config | 9 |
unknown | 9 |
odoo15 | 9 |
tomcat | 8 |
test1 | 8 |
teamspeak3 | 8 |
User | 8 |
testuser2 | 7 |
subbu | 7 |
nvidia | 6 |
ops | 6 |
nagios | 6 |
sonar | 6 |
prueba | 6 |
teste | 5 |
admin1 | 5 |
hduser | 5 |
ankush | 5 |
default | 5 |
ftptest | 5 |
account3 | 5 |
sammy | 5 |
weblogic | 5 |
daenon | 5 |
administrator | 5 |
ftpuser2 | 5 |
user1 | 5 |
python | 4 |
gitlab | 4 |
vm | 4 |
craft | 4 |
odoo | 4 |
account | 4 |
hari | 4 |
sysadmin | 4 |
hd16x05 | 4 |
mike | 4 |
cloud | 4 |
vion | 4 |
hans | 4 |
vnc | 4 |
info | 4 |
naveen | 4 |
work | 4 |
data | 3 |
lisi | 3 |
beta | 3 |
kim | 3 |
ben | 3 |
acserver | 3 |
elk | 3 |
dashboard | 3 |
Admin | 3 |
ftpadmin | 3 |
azureuser | 3 |
Alex | 3 |
igor | 3 |
usuario | 3 |
db | 3 |
jeus | 3 |
andrek | 3 |
daniel | 3 |
sinusbot | 3 |
zabbix | 3 |
tim | 3 |
administrador | 3 |
account2 | 3 |
username | 3 |
pub | 3 |
jack | 3 |
hd16pt07 | 3 |
jessica | 3 |
newuser | 3 |
manager | 3 |
testing | 3 |
devuser | 2 |
marcelo | 2 |
cs | 2 |
sofia | 2 |
yy | 2 |
mqm | 2 |
station3 | 2 |
usr | 2 |
moises | 2 |
bharat | 2 |
tir | 2 |
ww | 2 |
polaris | 2 |
james | 2 |
ventas | 2 |
nginx | 2 |
karen | 2 |
admin123 | 2 |
edge | 2 |
kk | 2 |
ftp_test | 2 |
soa | 2 |
ana | 2 |
make | 2 |
builder | 2 |
online | 2 |
splunk | 2 |
service | 2 |
process | 2 |
kiosk | 2 |
export | 2 |
jason | 2 |
tina | 2 |
rustserver | 2 |
hpcadmin | 2 |
webadmin | 2 |
dummy | 2 |
help | 2 |
rahul | 2 |
boss | 2 |
henry | 2 |
musikbot | 2 |
vbox | 2 |
pramod | 2 |
english | 2 |
insightvm | 2 |
ts | 2 |
sinus | 2 |
gokul | 2 |
jimmy | 2 |
portal | 2 |
start | 2 |
toor | 2 |
peuser | 2 |
ly | 2 |
Administrator | 2 |
king | 2 |
gtekautomation | 2 |
g | 2 |
hostinger | 2 |
jupyter | 2 |
samir | 2 |
sam | 2 |
joseph | 2 |
li | 2 |
dpu | 2 |
wyl | 2 |
ghost | 2 |
frappe | 2 |
maestro | 2 |
eng | 2 |
sherry | 2 |
user2 | 2 |
sybase | 2 |
dvd | 2 |
developer | 2 |
spotlight | 2 |
delta | 2 |
chimsen | 2 |
chris | 2 |
m1 | 2 |
conta | 2 |
build | 2 |
julio | 2 |
workflow | 2 |
dalia | 2 |
sample | 2 |
master | 2 |
john | 2 |
casa | 2 |
rob | 2 |
ansuser | 2 |
x | 2 |
neo4j | 2 |
wke | 2 |
grid | 2 |
bill | 2 |
orangepi | 2 |
network | 2 |
Guest | 2 |
webmaster | 2 |
account1 | 2 |
tom | 2 |
peter | 2 |
thomas | 2 |
user7 | 2 |
vpn | 2 |
eagle | 2 |
uftp | 2 |
usuario1 | 2 |
deamon | 2 |
abc | 2 |
iii | 2 |
jboss | 2 |
kevin | 2 |
calendar | 2 |
anthony | 2 |
eirik | 2 |
marek | 2 |
station6 | 2 |
afp | 2 |
mapr | 2 |
temp | 2 |
gordon | 2 |
2 | |
teacher1 | 2 |
ahmed | 2 |
James | 2 |
martine | 2 |
jump | 2 |
hermann | 2 |
user02 | 2 |
incoming | 2 |
felins | 2 |
userftp | 2 |
moodle | 2 |
erika | 2 |
test123 | 2 |
edward | 2 |
michael | 2 |
marin | 2 |
eddie | 2 |
amit | 2 |
t | 2 |
osm | 2 |
mohammad | 2 |
arkserver | 2 |
wordpress | 2 |
demo | 2 |
docker | 2 |
csgoserver | 2 |
lls | 2 |
lisa | 2 |
yg | 1 |
hywang | 1 |
utils | 1 |
csserver | 1 |
sme | 1 |
webster | 1 |
imobilis | 1 |
hd15pt05 | 1 |
knp | 1 |
lorenzo | 1 |
wc | 1 |
valli | 1 |
agata | 1 |
mysql_admin | 1 |
sampath | 1 |
hy | 1 |
ebf | 1 |
sadegh | 1 |
nominatim | 1 |
gts | 1 |
hsi | 1 |
student04 | 1 |
me | 1 |
netgear | 1 |
java | 1 |
mongodb | 1 |
drone | 1 |
grq | 1 |
ds | 1 |
sso | 1 |
ark | 1 |
salman | 1 |
aan | 1 |
spr | 1 |
sansforensics | 1 |
winer | 1 |
cheryl | 1 |
royal | 1 |
root01 | 1 |
tmhttpd | 1 |
uwsgi | 1 |
aa | 1 |
u | 1 |
loguser | 1 |
uploader | 1 |
dasusr1 | 1 |
wp | 1 |
manal | 1 |
melissa | 1 |
zengzheni | 1 |
dave | 1 |
zhu | 1 |
med | 1 |
impala | 1 |
exx | 1 |
camera | 1 |
chia | 1 |
wjz | 1 |
argo | 1 |
tally | 1 |
wetserver | 1 |
wsx | 1 |
wesley | 1 |
adi | 1 |
kenny | 1 |
patrick | 1 |
mxintadm | 1 |
aziz | 1 |
cc | 1 |
citrixuser | 1 |
njk | 1 |
vitor | 1 |
user13 | 1 |
zimbra | 1 |
stu | 1 |
asd | 1 |
odoo8 | 1 |
jean | 1 |
testtest | 1 |
itu | 1 |
nz | 1 |
fuzihao | 1 |
vps | 1 |
botuser | 1 |
jay | 1 |
leo | 1 |
tomcat2 | 1 |
comercial | 1 |
juan | 1 |
sandra | 1 |
javed | 1 |
hq | 1 |
pab | 1 |
xsw | 1 |
ot2022g | 1 |
Pamela | 1 |
sjj | 1 |
ts2 | 1 |
tiago | 1 |
lanou | 1 |
flora | 1 |
apple | 1 |
zyx | 1 |
zr | 1 |
tmf | 1 |
liying | 1 |
xunjian | 1 |
burninuser | 1 |
tdc | 1 |
yangjun | 1 |
ucp | 1 |
maxime | 1 |
linuxtest | 1 |
thj | 1 |
kubernetes | 1 |
pavan | 1 |
vfi | 1 |
raj | 1 |
dbadmin | 1 |
aud | 1 |
song | 1 |
austin | 1 |
lft | 1 |
olv | 1 |
north | 1 |
sarah | 1 |
hxeadm | 1 |
jember | 1 |
transfer | 1 |
neeraj | 1 |
socket | 1 |
zxin10 | 1 |
public | 1 |
angelica | 1 |
spread | 1 |
dpt | 1 |
robo | 1 |
mwb | 1 |
qy | 1 |
forge | 1 |
vk | 1 |
fleet | 1 |
yiling | 1 |
apollo | 1 |
pradeep | 1 |
tr | 1 |
hd15pw01 | 1 |
ovhuser | 1 |
yarn | 1 |
lbs | 1 |
1111 | 1 |
rancher | 1 |
balaji | 1 |
jan | 1 |
dhn | 1 |
pop | 1 |
nils | 1 |
le | 1 |
bea | 1 |
users | 1 |
init | 1 |
bmf | 1 |
tileserver | 1 |
user22 | 1 |
plano | 1 |
big | 1 |
svn | 1 |
ira | 1 |
indra | 1 |
celia | 1 |
canal | 1 |
jira | 1 |
ctrls | 1 |
marcio | 1 |
laurent | 1 |
oleg | 1 |
albert | 1 |
linz1114 | 1 |
yosa | 1 |
gabriel | 1 |
uzivatel | 1 |
alberto | 1 |
123 | 1 |
fmaster | 1 |
pty | 1 |
chester | 1 |
yan | 1 |
alfonso | 1 |
dbseller | 1 |
fujita | 1 |
valeria | 1 |
juliana | 1 |
lfs | 1 |
media | 1 |
cpanel | 1 |
orlando | 1 |
sudo | 1 |
fastuser | 1 |
bh | 1 |
milton | 1 |
nifi | 1 |
alfa | 1 |
cesar | 1 |
cat | 1 |
lry | 1 |
henk | 1 |
light | 1 |
zhouh | 1 |
hugo | 1 |
xufang | 1 |
px | 1 |
intel | 1 |
tiger | 1 |
tomcat8 | 1 |
niv | 1 |
elasticsearch | 1 |
mcserv | 1 |
student8 | 1 |
registry | 1 |
browser | 1 |
app | 1 |
wizard | 1 |
sunday | 1 |
syslog | 1 |
ts3sv | 1 |
VM | 1 |
lin | 1 |
kelvin | 1 |
ob | 1 |
fff | 1 |
markus | 1 |
anirudh | 1 |
elasticuser | 1 |
ps | 1 |
bm3871 | 1 |
pip | 1 |
zlg | 1 |
sdtdserver | 1 |
sispac | 1 |
baum | 1 |
pbe | 1 |
contact | 1 |
sophia | 1 |
ts3server1 | 1 |
tommy | 1 |
pwrchute | 1 |
svnroot | 1 |
gamemaster | 1 |
wasadmin | 1 |
kg | 1 |
pruebasfe | 1 |
user01 | 1 |
ada | 1 |
lucia | 1 |
xavier | 1 |
mathew | 1 |
Redistoor | 1 |
ctf | 1 |
max | 1 |
hf | 1 |
silver | 1 |
ac | 1 |
bso | 1 |
webhost | 1 |
wfp | 1 |
pio | 1 |
mailroom | 1 |
johnson | 1 |
rohan | 1 |
fiscal | 1 |
owncloud | 1 |
fgt | 1 |
zhangjinyang | 1 |
Alex1 | 1 |
noa | 1 |
webadm | 1 |
andy | 1 |
pig | 1 |
red | 1 |
sunny | 1 |
jj | 1 |
nrg | 1 |
rock | 1 |
stefan | 1 |
servis | 1 |
adminstrator | 1 |
rebecca | 1 |
pyy | 1 |
jlopez | 1 |
kub | 1 |
bootcamp | 1 |
hd19x05 | 1 |
kelly | 1 |
sapaccount | 1 |
profe | 1 |
composer | 1 |
suraj | 1 |
platform | 1 |
erp | 1 |
user100 | 1 |
debora | 1 |
space | 1 |
george | 1 |
zhongfu | 1 |
mihai | 1 |
stack | 1 |
lib | 1 |
sip | 1 |
lw | 1 |
adam | 1 |
aiden | 1 |
user8 | 1 |
macintosh | 1 |
tqm | 1 |
osboxes | 1 |
alvin | 1 |
operador | 1 |
terrariaserver | 1 |
otto | 1 |
mine | 1 |
ld | 1 |
hdfs | 1 |
sara | 1 |
dsadm | 1 |
oc | 1 |
jinzhenj | 1 |
rf | 1 |
ncc | 1 |
tryton | 1 |
guest2 | 1 |
tuser | 1 |
cynthia | 1 |
frp | 1 |
philip | 1 |
gbase | 1 |
mangesh | 1 |
lucas | 1 |
reza | 1 |
dst | 1 |
ljw | 1 |
barbara | 1 |
dp | 1 |
cv | 1 |
da1adm | 1 |
amssys | 1 |
supervisor | 1 |
qdx | 1 |
dreamer | 1 |
redis | 1 |
isha | 1 |
ego | 1 |
ako | 1 |
sklad | 1 |
mycat | 1 |
orion | 1 |
22 | 1 |
1234 | 1 |
vilma | 1 |
claudio | 1 |
kana | 1 |
zz | 1 |
idc | 1 |
xd | 1 |
ode | 1 |
carbon | 1 |
hexing | 1 |
vladimir | 1 |
sawada | 1 |
marcela | 1 |
tigergraph | 1 |
sky | 1 |
cptuser | 1 |
jenny | 1 |
test2 | 1 |
user15 | 1 |
md | 1 |
hanna | 1 |
html | 1 |
radioserver | 1 |
gaurav | 1 |
ilog | 1 |
steve | 1 |
auser | 1 |
alt | 1 |
cyril | 1 |
mcguitaruser | 1 |
benjamin | 1 |
gb | 1 |
sftp | 1 |
zw | 1 |
apache | 1 |
gerencia | 1 |
isaac | 1 |
lukas | 1 |
ddd | 1 |
zav | 1 |
william | 1 |
Christopher | 1 |
bitnami | 1 |
spider | 1 |
training | 1 |
mysql_public | 1 |
lsh | 1 |
lois | 1 |
hooman | 1 |
hospital | 1 |
demos | 1 |
ll | 1 |
rolf | 1 |
dino | 1 |
joao | 1 |
jp | 1 |
zqy | 1 |
techuser | 1 |
ktw | 1 |
logout | 1 |
anna | 1 |
asterisk | 1 |
vikram | 1 |
rn | 1 |
rundeck | 1 |
sml | 1 |
pwn | 1 |
leonard | 1 |
jqu | 1 |
miller | 1 |
hh | 1 |
sdr | 1 |
gpadmin | 1 |
xia | 1 |
webapps | 1 |
marge | 1 |
haldaemon | 1 |
giovanni | 1 |
student9 | 1 |
tomas | 1 |
flow | 1 |
upload | 1 |
nn | 1 |
harold | 1 |
mailuser | 1 |
chendong | 1 |
adminuser | 1 |
postgresadm | 1 |
kernel | 1 |
lxd | 1 |
rlk | 1 |
zhan | 1 |
pal | 1 |
films | 1 |
cloud_user | 1 |
vegeta | 1 |
bert | 1 |
meeting | 1 |
tech | 1 |
yamamoto | 1 |
anand | 1 |
jperez | 1 |
water | 1 |
raspberrypi | 1 |
vic | 1 |
potato | 1 |
syn | 1 |
fyc | 1 |
pam | 1 |
jb | 1 |
line | 1 |
acs | 1 |
factorio | 1 |
wolfgang | 1 |
nikhil | 1 |
sqoop | 1 |
xuh | 1 |
nodeproxy | 1 |
r | 1 |
ftp1 | 1 |
alfred | 1 |
wl | 1 |
ircd | 1 |
rtc | 1 |
fabian | 1 |
ebs | 1 |
hg | 1 |
mmm | 1 |
aris | 1 |
techadmin | 1 |
richard | 1 |
pto | 1 |
iot | 1 |
magento | 1 |
gambaa | 1 |
micha | 1 |
cib | 1 |
chenyusheng | 1 |
anais | 1 |
pratik | 1 |
ent | 1 |
ftptest1 | 1 |
bvm | 1 |
zsy | 1 |
t7adm | 1 |
petra | 1 |
siteadmin | 1 |
dss | 1 |
adm | 1 |
suresh | 1 |
marcin | 1 |
quantum | 1 |
martin | 1 |
taiwan | 1 |
kali | 1 |
clovis | 1 |
acme | 1 |
test01 | 1 |
newuser1 | 1 |
bluecat | 1 |
fno | 1 |
demon | 1 |
stream | 1 |
xh | 1 |
zhou | 1 |
2 | 1 |
chn | 1 |
virl | 1 |
vmc | 1 |
nexus | 1 |
glen | 1 |
harry | 1 |
sun | 1 |
yzf | 1 |
reuniao | 1 |
ksw | 1 |
kvg | 1 |
ssld | 1 |
sts | 1 |
jm | 1 |
adminrig | 1 |
ppps | 1 |
ankur | 1 |
gis | 1 |
manish | 1 |
m | 1 |
invitado | 1 |
tsh | 1 |
vdc | 1 |
cubrid | 1 |
database | 1 |
sandeep | 1 |
ares | 1 |
cathy | 1 |
hjb | 1 |
geral | 1 |
student07 | 1 |
blog | 1 |
rpc | 1 |
sx | 1 |
ela | 1 |
krishna | 1 |
tavi | 1 |
olga | 1 |
yoshiaki | 1 |
AHMEDYA | 1 |
oscar | 1 |
huangwei | 1 |
multimedia | 1 |
myftp | 1 |
kang | 1 |
ncs | 1 |
dell | 1 |
js | 1 |
bungee | 1 |
zzh | 1 |
vpnuser | 1 |
dolly | 1 |
bob | 1 |
user05 | 1 |
marlon | 1 |
beginner | 1 |
adis | 1 |
joe | 1 |
sonarqube | 1 |
maxim | 1 |
xpp | 1 |
vsftpd | 1 |
csxm | 1 |
hps | 1 |
siva | 1 |
eg | 1 |
zf | 1 |
jht | 1 |
helpdesk | 1 |
kopp | 1 |
etserver | 1 |
yhuser | 1 |
LKepler | 1 |
panel | 1 |
baidu | 1 |
sham | 1 |
mgm | 1 |
gj | 1 |
daniela | 1 |
easy | 1 |
password | 1 |
thiago | 1 |
lxj | 1 |
administrateur | 1 |
ryder | 1 |
toni | 1 |
ed | 1 |
guest01 | 1 |
kv | 1 |
shaman | 1 |
osmc | 1 |
diandra | 1 |
rforlu | 1 |
hybris | 1 |
gast | 1 |
oms | 1 |
erica | 1 |
recepcja | 1 |
amir | 1 |
zzr | 1 |
shinken | 1 |
isabelle | 1 |
kalista | 1 |
phpmyadmin | 1 |
broadcast | 1 |
sistema | 1 |
de | 1 |
fuho | 1 |
user6 | 1 |
liuhao | 1 |
mc1 | 1 |
mob | 1 |
eric | 1 |
aperez | 1 |
mark | 1 |
reginaldo | 1 |
michel | 1 |
tanya | 1 |
prueba1 | 1 |
sftpuser | 1 |
onkar | 1 |
felix | 1 |
user5 | 1 |
laptop | 1 |
xiang | 1 |
ftpUser | 1 |
ning | 1 |
dm | 1 |
uk | 1 |
chenj | 1 |
z | 1 |
megha | 1 |
olx | 1 |
otrs | 1 |
minecraftserver | 1 |
signa | 1 |
ix | 1 |
RPM | 1 |
robson | 1 |
dqq | 1 |
dd | 1 |
christine | 1 |
wilma | 1 |
sFTPUser | 1 |
delgado | 1 |
zheng | 1 |
localadmin | 1 |
cxl | 1 |
xxs | 1 |
fmy | 1 |
external | 1 |
lan | 1 |
wei | 1 |
wlb | 1 |
arnaud | 1 |
02 | 1 |
arun | 1 |
owner | 1 |
camille | 1 |
httpfs | 1 |
pyramid | 1 |
xc | 1 |
mitzi | 1 |
kiran | 1 |
mysqladmin | 1 |
kobayashi | 1 |
eh | 1 |
yoon | 1 |
sunil | 1 |
ram | 1 |
nas | 1 |
idea | 1 |
silvia | 1 |
andrey | 1 |
pvserver | 1 |
fileshare | 1 |
ms | 1 |
sda | 1 |
rocco | 1 |
chan | 1 |
chimistry | 1 |
globe | 1 |
ppp | 1 |
cliente | 1 |
ur | 1 |
zhouying | 1 |
praveen | 1 |
oota | 1 |
caja2 | 1 |
kinder | 1 |
qt | 1 |
video | 1 |
takamatsu | 1 |
react | 1 |
login | 1 |
mj | 1 |
s | 1 |
skynet | 1 |
bun | 1 |
elisa | 1 |
shiyu | 1 |
biqu | 1 |
fast | 1 |
keller | 1 |
liu | 1 |
orca | 1 |
jesus | 1 |
dice | 1 |
lara | 1 |
comunica | 1 |
ali | 1 |
csgo | 1 |
ph | 1 |
fpf | 1 |
client | 1 |
lxh | 1 |
gmodserver | 1 |
david | 1 |
lgx | 1 |
kirk | 1 |
teste1 | 1 |
wangli | 1 |
share | 1 |
bk | 1 |
CISCO | 1 |
imc | 1 |
flex | 1 |
julia | 1 |
bbs | 1 |
wlh | 1 |
next | 1 |
cristian | 1 |
vod | 1 |
vendas | 1 |
rkb | 1 |
itadmin | 1 |
admins | 1 |
testsftp | 1 |
dani | 1 |
natalie | 1 |
sbo | 1 |
dietpi | 1 |
drake | 1 |
az | 1 |
uzi | 1 |
yuchen | 1 |
agenda | 1 |
zero | 1 |
hl | 1 |
informix | 1 |
labor | 1 |
csx | 1 |
csp | 1 |
gdb | 1 |
dcmtk | 1 |
yuzhen | 1 |
a8 | 1 |
xujun | 1 |
pp | 1 |
jsu | 1 |
vmware | 1 |
rnc | 1 |
ns | 1 |
soporte | 1 |
redmine | 1 |
marketing | 1 |
alg | 1 |
user002 | 1 |
juliet | 1 |
samba | 1 |
images | 1 |
liwei | 1 |
pentaho | 1 |
monique | 1 |
django | 1 |
lab5 | 1 |
interview | 1 |
antoine | 1 |
zhangbo | 1 |
quange | 1 |
mali | 1 |
r1soft | 1 |
ping | 1 |
sidney | 1 |
1 | |
ken | 1 |
mac | 1 |
front | 1 |
vmuser | 1 |
odl | 1 |
marconi | 1 |
swapnil | 1 |
zzy | 1 |
ptj | 1 |
jesse | 1 |
nadir | 1 |
platinum | 1 |
id | 1 |
cperez | 1 |
memcached | 1 |
hynexus | 1 |
nti | 1 |
patricia | 1 |
bala | 1 |
peng | 1 |
best | 1 |
wkx | 1 |
7days | 1 |
shen | 1 |
icinga | 1 |
zan | 1 |
linuxadmin | 1 |
nitin | 1 |
abel | 1 |
rhea | 1 |
vivek | 1 |
tst | 1 |
mobile | 1 |
prashant | 1 |
odoo11 | 1 |
suser | 1 |
ajeet | 1 |
test7 | 1 |
andrei | 1 |
acct | 1 |
test9 | 1 |
noaccess | 1 |
zj | 1 |
store | 1 |
linkxess | 1 |
aaron | 1 |
paramita | 1 |
ht | 1 |
mos | 1 |
miguel | 1 |
user21 | 1 |
wt | 1 |
worker | 1 |
priv_user | 1 |
aravind | 1 |
wink | 1 |
zy | 1 |
cvs | 1 |
diz | 1 |
vv | 1 |
yuk | 1 |
rex | 1 |
pc | 1 |
infra | 1 |
mailman | 1 |
raul | 1 |
visitante | 1 |
otsmanager | 1 |
xo | 1 |
gisela | 1 |
user03 | 1 |
ankit | 1 |
hr | 1 |
cstrike | 1 |
contabilidad | 1 |
hostmaster | 1 |
pbb | 1 |
ts3bot | 1 |
pokemon | 1 |
xiaowei | 1 |
openstack | 1 |
vodafone | 1 |
xxx | 1 |
lyc | 1 |
tmax | 1 |
rvw | 1 |
suporte | 1 |
sav | 1 |
wcc | 1 |
ludo | 1 |
idempiere | 1 |
teste2 | 1 |
chad | 1 |
johan | 1 |
mani | 1 |
zhl | 1 |
wialon | 1 |
lixiao | 1 |
center | 1 |
postgres1 | 1 |
aml | 1 |
beyndtrust_adm | 1 |
yhlee | 1 |
dan | 1 |
root1 | 1 |
leonardo | 1 |
polycom | 1 |
nelson | 1 |
site | 1 |
kafka | 1 |
sa | 1 |
market | 1 |
princess | 1 |
plm | 1 |
zxc | 1 |
hasan | 1 |
amano | 1 |
shane | 1 |
ar | 1 |
marius | 1 |
bsnl | 1 |
mahesh | 1 |
yassine | 1 |
cma | 1 |
magento_user | 1 |
bhd | 1 |
mis | 1 |
Minecraft | 1 |
christian | 1 |
piotr | 1 |
ymx | 1 |
scv | 1 |
homes | 1 |
cm | 1 |
ibk | 1 |
archiver | 1 |
dockerman | 1 |
robin | 1 |
yzy | 1 |
bcdig | 1 |
mahendra | 1 |
atom | 1 |
edison | 1 |
eswar | 1 |
ijq | 1 |
miner | 1 |
tool | 1 |
liming | 1 |
mickey | 1 |
shop | 1 |
wmf | 1 |
zyb | 1 |
trading | 1 |
n | 1 |
tams | 1 |
escaner | 1 |
mary | 1 |
ec2user | 1 |
fb | 1 |
core | 1 |
asi | 1 |
zhaoxu | 1 |
aef | 1 |
teacher | 1 |
xfy | 1 |
craig | 1 |
demouser | 1 |
edu01 | 1 |
liferay | 1 |
vada | 1 |
gc | 1 |
faberj | 1 |
urbackup | 1 |
kgd | 1 |
zg | 1 |
jaw | 1 |
joey | 1 |
dylan | 1 |
h | 1 |
aldo | 1 |
oper | 1 |
khalesi | 1 |
remote | 1 |
vijay | 1 |
mne | 1 |
esadm1 | 1 |
nux | 1 |
masha | 1 |
titan | 1 |
fabio | 1 |
szw | 1 |
sshproxy | 1 |
mingdong | 1 |
jake | 1 |
local | 1 |
telegram | 1 |
jacky | 1 |
ika | 1 |
ccc | 1 |
nigger | 1 |
wing | 1 |
operation | 1 |
vaibhav | 1 |
viewer | 1 |
francesco | 1 |
gerrit2 | 1 |
cardpro | 1 |
cy | 1 |
ins | 1 |
drm | 1 |
yangningxin | 1 |
juntasi | 1 |
ethos | 1 |
mdb | 1 |
nat | 1 |
bb | 1 |
luke | 1 |
ccook | 1 |
laboratory | 1 |
joneill | 1 |
aura | 1 |
abi | 1 |
darrell | 1 |
vyatta | 1 |
vsx | 1 |
liwen | 1 |
dash | 1 |
oozie | 1 |
sonic | 1 |
mosquitto | 1 |
tsserver | 1 |
sysop | 1 |
paul | 1 |
Countries of Origin
Country | Count |
---|---|
United States | 281 |
China | 185 |
Russia | 176 |
Singapore | 62 |
Japan | 58 |
Germany | 48 |
India | 41 |
South Korea | 40 |
Brazil | 38 |
United Kingdom | 34 |
Not found | 31 |
Hong Kong | 30 |
Vietnam | 28 |
Indonesia | 22 |
Netherlands | 20 |
France | 19 |
Colombia | 19 |
Argentina | 15 |
Mexico | 14 |
Thailand | 10 |
Italy | 9 |
Tunisia | 9 |
Malaysia | 7 |
Canada | 7 |
Poland | 6 |
Taiwan | 6 |
Israel | 6 |
Ukraine | 5 |
Uruguay | 5 |
Belarus | 5 |
Peru | 5 |
Philippines | 5 |
Bulgaria | 4 |
Uzbekistan | 4 |
Iran | 4 |
Ethiopia | 4 |
Greece | 4 |
Bolivia | 4 |
Hungary | 4 |
Portugal | 3 |
Kazakhstan | 3 |
Uganda | 3 |
Venezuela | 3 |
South Africa | 3 |
Spain | 3 |
Pakistan | 3 |
Ecuador | 3 |
Australia | 3 |
Egypt | 2 |
Slovakia | 2 |
Bahrain | 2 |
Bangladesh | 2 |
Croatia | 2 |
Switzerland | 2 |
Ireland | 2 |
Republic of Lithuania | 2 |
Chile | 2 |
Turkey | 2 |
Guatemala | 2 |
Paraguay | 2 |
Sri Lanka | 2 |
Myanmar | 1 |
Latvia | 1 |
Finland | 1 |
Czechia | 1 |
United Arab Emirates | 1 |
Oman | 1 |
Mauritius | 1 |
Macao | 1 |
Namibia | 1 |
Ivory Coast | 1 |
Kyrgyzstan | 1 |
Zimbabwe | 1 |
Nepal | 1 |
Romania | 1 |
Réunion | 1 |
Hashemite Kingdom of Jordan | 1 |
Niger | 1 |
Kenya | 1 |
Luxembourg | 1 |
None | 1 |
Sweden | 1 |
Mongolia | 1 |
Port Distribution
Standard port for ssh is 22 for incoming connections. Outbound the ssh client chooses an ephemeral port, but these do not seem to be equally distributed. The graphic below shows the port distribution for outbound connections used by attackers.
Synopsis:
- Total number of ports logged: 7689.
- Ports below 1024 were not used at all. This is expected behaviour for ephemeral ports.
- Ports above 32768 (=215) and below 61002 were used more often. This is also expected, because many linux kernels do not use 1024-65535port range, but 32768–60999.
- There are gaps between 14664-15512 and 21449-22372. Could be a coincidence, or could be another service already reserving ports in that range.