Ga naar de hoofdnavigatie Ga naar de hoofdinhoud Ga naar de voettekst van de pagina
fail2ban banned IP addresses; Hostname=server
unban#removeidIPjailcountryrdnsloglinestimestampportsprotocolhostnamefailures
39942039942180.94.74.122postfix-saslAF, Afghanistan2026-02-16T05:46:25.424104+01:00 server postfix/smtps/smtpd[3090170]: warning: unknown[180.94.74.122]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 04:46:26smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
3994103994162.220.236.203postfix-saslFI, Finland2026-02-16T05:46:13.455937+01:00 server postfix/smtps/smtpd[3090130]: warning: unknown[62.220.236.203]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 04:46:14smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
3994003994060.172.41.103postfix-saslCN, China2026-02-16T05:34:49.451216+01:00 server postfix/smtps/smtpd[3089711]: warning: unknown[60.172.41.103]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 04:34:50smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39939039939128.185.187.2postfix-saslIN, India2026-02-16T05:34:35.138929+01:00 server postfix/smtps/smtpd[3089713]: warning: unknown[128.185.187.2]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 04:34:36smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
3993803993858.222.72.182postfix-saslCN, China2026-02-16T01:26:02.191899+01:00 server postfix/smtps/smtpd[3083354]: warning: unknown[58.222.72.182]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 00:26:03smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39937039937218.15.224.102postfix-saslCN, China2026-02-16T01:25:38.152432+01:00 server postfix/smtps/smtpd[3083278]: warning: unknown[218.15.224.102]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-16 00:25:42smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39936039936149.54.62.166postfix-saslAF, Afghanistan2026-02-16T00:06:18.149842+01:00 server postfix/smtps/smtpd[2967866]: warning: unknown[149.54.62.166]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 23:06:19smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39935039935103.186.114.73postfix-saslPK, Pakistan2026-02-16T00:05:48.237189+01:00 server postfix/smtps/smtpd[2967824]: warning: unknown[103.186.114.73]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 23:05:49smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39934039934103.160.26.152postfix-saslIN, India2026-02-15T21:58:49.280035+01:00 server postfix/submission/smtpd[2964768]: warning: unknown[103.160.26.152]: SASL PLAIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 20:58:50smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39933039933220.246.47.169postfix-saslHK, Hong Kong169.47.246.220.static.netvigator.com2026-02-15T20:19:22.321956+01:00 server postfix/smtps/smtpd[2961970]: warning: 169.47.246.220.static.netvigator.com[220.246.47.169]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 19:19:23smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39932039932194.237.70.114postfix-saslSE, Sweden2026-02-15T20:19:07.085197+01:00 server postfix/smtps/smtpd[2961918]: warning: unknown[194.237.70.114]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 19:19:07smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39931039931122.187.231.57postfix-saslIN, Indiansg-corporate-57.231.187.122.airtel.in2026-02-15T19:10:31.248301+01:00 server postfix/smtps/smtpd[2960452]: warning: unknown[122.187.231.57]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=theo@langstraatonline.nl2026-02-15 18:10:32smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39930039930195.178.110.199apache-authBG, Bulgaria[Sun Feb 15 11:02:49.483908 2026] [authz_core:error] [pid 2925405:tid 2925481] [client 195.178.110.199:59216] AH01630: client denied by server configuration: /var/www/Pure-FTPd/.htaccess2026-02-15 10:02:50http,httpstcpserver1
39926039926185.177.72.52apache-authGB, United Kingdom[Sat Feb 14 23:12:27.187417 2026] [authz_core:error] [pid 2803128:tid 2803214] [client 185.177.72.52:34304] AH01630: client denied by server configuration: /var/www/mail/.htaccess2026-02-14 22:12:27http,httpstcpserver1
3990003990045.148.10.238apache-authNL, Netherlands[Thu Feb 12 15:49:52.383605 2026] [authz_core:error] [pid 2445808:tid 2445896] [client 45.148.10.238:38098] AH01630: client denied by server configuration: /var/www/html/v13/.git2026-02-12 14:49:56http,httpstcpserver1
3989703989791.92.240.214postfix-saslBG, Bulgaria2026-02-11T21:45:36.078596+01:00 server postfix/smtps/smtpd[2328363]: warning: unknown[91.92.240.214]: SASL LOGIN authentication failed: (reason unavailable), sasl_username=admin@langstraatonline.nl2026-02-11 20:45:36smtp,465,submission,imap,imaps,pop3,pop3stcpserver1
39882039882195.178.110.108apache-authBG, Bulgaria[Tue Feb 10 22:24:02.286131 2026] [authz_core:error] [pid 2095488:tid 2095581] [client 195.178.110.108:55454] AH01630: client denied by server configuration: /var/www/Pure-FTPd/.htaccess2026-02-10 21:24:03http,httpstcpserver1
3985203985294.102.49.155apache-authNL, Netherlandsno-reverse-dns-configured.com[Sun Feb 08 08:25:58.719214 2026] [authz_core:error] [pid 1816923:tid 1816997] [client 94.102.49.155:49572] AH01630: client denied by server configuration: /var/www/Pure-FTPd/server-status2026-02-08 07:26:00http,httpstcpserver1
39789039789195.178.110.132apache-authBG, Bulgaria[Wed Feb 04 11:18:20.485895 2026] [authz_core:error] [pid 1090732:tid 1090789] [client 195.178.110.132:54542] AH01630: client denied by server configuration: /var/www/html/v13/.env.bak2026-02-04 10:18:21http,httpstcpserver1
3956703956745.91.64.6apache-authES, Spain[Tue Jan 27 07:48:31.606595 2026] [authz_core:error] [pid 163632:tid 163707] [client 45.91.64.6:50950] AH01630: client denied by server configuration: /var/www/Pure-FTPd/server-status2026-01-27 06:48:32http,httpstcpserver1

Analyse

Na drie dagen 399 sshd aanvallen geregistreerd. Reden om hier een ander poort nummer voor in te stellen. Port 22 is blijkbaar erg geliefd onder hackers. Opvallend, United States met 94 op nummer één en China met 86 op nummer twee maken samen bijna de helft van de aanvallen uit. Rusland komt op de 8st plaats met 14 aanvallen.

Apache en Dovecot aanvallen werden "slechts" 16 respectievelijk 9 keer geregistreerd in deze periode.