HideMyAss.com

Monday 28 May 2018

[Fail2Ban] SSH: banned 41.59.225.121 from natural-breast-active.com

Hi,

The IP 41.59.225.121 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 41.59.225.121:

[Querying whois.afrinic.net]
[whois.afrinic.net]
% This is the AfriNIC Whois server.

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '41.59.0.0 - 41.59.255.255'

% No abuse contact registered for 41.59.0.0 - 41.59.255.255

inetnum: 41.59.0.0 - 41.59.255.255
netname: TTCL-20100413
descr: TANZANIA TELECOMMUNICATIONS CO. LTD
country: TZ
org: ORG-TTCL1-AFRINIC
admin-c: ALM1-AFRINIC
tech-c: ALM1-AFRINIC
status: ALLOCATED PA
mnt-by: AFRINIC-HM-MNT
mnt-lower: TTCLDATA-MNT
mnt-routes: TTCLDATA-MNT
source: AFRINIC # Filtered
parent: 41.0.0.0 - 41.255.255.255

organisation: ORG-TTCL1-AFRINIC
org-name: TANZANIA TELECOMMUNICATIONS CO. LTD
org-type: LIR
country: TZ
address: 4th Floor,
address: Extelecomms Building, Samora Avenue
address: Dar Es Salaam PO Box 9070
phone: tel:+255-738-261-212
fax-no: tel:+255-22213488
admin-c: ALM1-AFRINIC
tech-c: ALM1-AFRINIC
mnt-ref: AFRINIC-HM-MNT
mnt-ref: TTCLDATA-MNT
mnt-by: AFRINIC-HM-MNT
source: AFRINIC # Filtered

person: Adam L Mwaipungu
address: Data Networks Operations
address: Tanzania Telecommunications Co Ltd
address: +255-22-2142250
address: +255-732526699
address: Telephone Hse
address: Kaluta Street
address: Dar Es Salaam
address: Dar es salaam
address: Tanzania
phone: tel:+255-732-526-699
fax-no: tel:+255-22-213-3488
nic-hdl: ALM1-AFRINIC
remarks: Empowering Tanzania through ICT
mnt-by: GENERATED-JRSLVBWKTFMJBCFFEOZVE9BE9XPRZVUA-MNT
source: AFRINIC # Filtered

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 52.231.32.54 from natural-breast-active.com

Hi,

The IP 52.231.32.54 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 52.231.32.54:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 52.231.32.54"
#
# Use "?" to get help.
#

NetRange: 52.224.0.0 - 52.255.255.255
CIDR: 52.224.0.0/11
NetName: MSFT
NetHandle: NET-52-224-0-0-1
Parent: NET52 (NET-52-0-0-0-0)
NetType: Direct Assignment
OriginAS:
Organization: Microsoft Corporation (MSFT)
RegDate: 2015-11-24
Updated: 2015-11-24
Ref: https://whois.arin.net/rest/net/NET-52-224-0-0-1



OrgName: Microsoft Corporation
OrgId: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
RegDate: 1998-07-09
Updated: 2017-01-28
Comment: To report suspected security issues specific to traffic emanating from Microsoft online services, including the distribution of malicious content or other illicit or illegal material through a Microsoft online service, please submit reports to:
Comment: * https://cert.microsoft.com.
Comment:
Comment: For SPAM and other abuse issues, such as Microsoft Accounts, please contact:
Comment: * abuse@microsoft.com.
Comment:
Comment: To report security vulnerabilities in Microsoft products and services, please contact:
Comment: * secure@microsoft.com.
Comment:
Comment: For legal and law enforcement-related requests, please contact:
Comment: * msndcc@microsoft.com
Comment:
Comment: For routing, peering or DNS issues, please
Comment: contact:
Comment: * IOC@microsoft.com
Ref: https://whois.arin.net/rest/org/MSFT


OrgAbuseHandle: MAC74-ARIN
OrgAbuseName: Microsoft Abuse Contact
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@microsoft.com
OrgAbuseRef: https://whois.arin.net/rest/poc/MAC74-ARIN

OrgTechHandle: MRPD-ARIN
OrgTechName: Microsoft Routing, Peering, and DNS
OrgTechPhone: +1-425-882-8080
OrgTechEmail: IOC@microsoft.com
OrgTechRef: https://whois.arin.net/rest/poc/MRPD-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 198.50.179.83 from natural-breast-active.com

Hi,

The IP 198.50.179.83 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 198.50.179.83:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 198.50.179.83"
#
# Use "?" to get help.
#

Private Customer OVH-CUST-4449571 (NET-198-50-179-80-1) 198.50.179.80 - 198.50.179.95
OVH Hosting, Inc. OVH-ARIN-6 (NET-198-50-128-0-1) 198.50.128.0 - 198.50.255.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 139.99.149.86 from natural-breast-active.com

Hi,

The IP 139.99.149.86 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 139.99.149.86:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 139.99.149.86"
#
# Use "?" to get help.
#

OVH Hosting, Inc. HO-2 (NET-139-99-0-0-1) 139.99.0.0 - 139.99.255.255
OVH Australia PTY LTD OVH-AU-1 (NET-139-99-128-0-1) 139.99.128.0 - 139.99.255.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 105.96.12.53 from natural-breast-active.com

Hi,

The IP 105.96.12.53 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 105.96.12.53:

[Querying whois.arin.net]
[Redirected to whois.afrinic.net]
[Querying whois.afrinic.net]
[whois.afrinic.net]
% This is the AfriNIC Whois server.

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '105.96.0.0 - 105.96.255.255'

% No abuse contact registered for 105.96.0.0 - 105.96.255.255

inetnum: 105.96.0.0 - 105.96.255.255
netname: PLS-POOLS
descr: IP fixe 105.96.0.0/17
descr: 105.96.192.0/19 easy CA1
descr: 105.96.224.0/20 CA1 EASY
descr: 105.96.240.0/20 BEK EASY
country: DZ
admin-c: SD6-AFRINIC
tech-c: SD6-AFRINIC
status: ASSIGNED PA
remarks: Send abuse request to abuse(AT)djaweb.dz
mnt-by: DJAWEB-MNT
source: AFRINIC # Filtered
parent: 105.96.0.0 - 105.111.255.255

person: Security Departement
address: Alger
phone: tel:+213-21-91-12-24
fax-no: tel:+213-21-91-12-08
nic-hdl: SD6-AFRINIC
mnt-by: GENERATED-IRIXFFLWUREDGEB9HMRODGUJH3OJCIPE-MNT
source: AFRINIC # Filtered

% Information related to '105.96.0.0/12AS36947'

route: 105.96.0.0/12
descr: Algerie Telecom
origin: AS36947
mnt-by: DJAWEB-MNT
source: AFRINIC # Filtered

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 37.113.134.110 from natural-breast-active.com

Hi,

The IP 37.113.134.110 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 37.113.134.110:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '37.113.128.0 - 37.113.135.255'

% Abuse contact for '37.113.128.0 - 37.113.135.255' is 'abuse@domru.ru'

inetnum: 37.113.128.0 - 37.113.135.255
netname: ERTH-CHEL-PPPOE-26-NET
descr: CJSC "ER-Telecom Holding" Chelyabinsk branch
descr: Chelyabinsk, Russia
descr: PPPoE individual customers
country: RU
admin-c: ERTH74-RIPE
org: ORG-CHCB1-RIPE
tech-c: ERTH74-RIPE
remarks: INFRA-AW
status: ASSIGNED PA
mnt-by: RAID-MNT
created: 2012-02-14T03:47:09Z
last-modified: 2012-02-14T03:47:09Z
source: RIPE

organisation: ORG-CHCB1-RIPE
org-name: JSC "ER-Telecom Holding" Chelyabinsk Branch
org-type: OTHER
descr: TM DOM.RU, Chelyabinsk ISP
address: Voroshilova, 10
address: Chelyabinsk, Russia, 454014
phone: +7 (351) 217-17-17
fax-no: +7 (351) 217-17-17
admin-c: ERTH74-RIPE
tech-c: ERTH74-RIPE
mnt-ref: RAID-MNT
mnt-by: RAID-MNT
created: 2011-01-13T10:54:47Z
last-modified: 2016-01-11T11:46:44Z
source: RIPE # Filtered

role: Network Operation Center CJSC ER-Telecom Company Chelyabinsk branch
address: 54, Kashirinyh st.
address: 454106 Chelyabinsk
address: Russian Federation
phone: +7 351 2471100
fax-no: +7 351 2471177
admin-c: YIV74-RIPE
admin-c: SDR666-RIPE
tech-c: SDR666-RIPE
tech-c: YIV74-RIPE
nic-hdl: ERTH74-RIPE
created: 2007-01-23T04:05:58Z
last-modified: 2008-10-28T11:04:08Z
source: RIPE # Filtered
mnt-by: MNT-ERTHOLDING

% Information related to '37.113.134.0/24AS41661'

route: 37.113.134.0/24
origin: AS41661
org: ORG-CHCB1-RIPE
descr: CJSC "ER-Telecom Holding" Chelyabinsk branch
descr: Chelyabinsk, Russia
mnt-by: RAID-MNT
created: 2015-08-27T10:53:25Z
last-modified: 2015-08-27T10:53:25Z
source: RIPE # Filtered

organisation: ORG-CHCB1-RIPE
org-name: JSC "ER-Telecom Holding" Chelyabinsk Branch
org-type: OTHER
descr: TM DOM.RU, Chelyabinsk ISP
address: Voroshilova, 10
address: Chelyabinsk, Russia, 454014
phone: +7 (351) 217-17-17
fax-no: +7 (351) 217-17-17
admin-c: ERTH74-RIPE
tech-c: ERTH74-RIPE
mnt-ref: RAID-MNT
mnt-by: RAID-MNT
created: 2011-01-13T10:54:47Z
last-modified: 2016-01-11T11:46:44Z
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.91.2 (HEREFORD)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 51.15.253.164 from natural-breast-active.com

Hi,

The IP 51.15.253.164 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 51.15.253.164:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '51.15.0.0 - 51.15.255.255'

% Abuse contact for '51.15.0.0 - 51.15.255.255' is 'abuse@online.net'

inetnum: 51.15.0.0 - 51.15.255.255
org: ORG-ONLI1-RIPE
netname: ONLINE_NET_DEDICATED_SERVERS
descr: Dedicated Servers and cloud assignment, abuse reports : http://abuse.online.net
country: FR
admin-c: MM42047-RIPE
tech-c: MM42047-RIPE
status: LEGACY
mnt-by: ONLINESAS-MNT
created: 2016-02-22T15:25:27Z
last-modified: 2018-03-27T19:55:46Z
source: RIPE

organisation: ORG-ONLI1-RIPE
mnt-ref: MNT-TISCALIFR-B2B
org-name: ONLINE SAS
org-type: OTHER
address: 8 rue de la ville l'eveque 75008 PARIS
abuse-c: AR32851-RIPE
mnt-ref: ONLINESAS-MNT
mnt-by: ONLINESAS-MNT
created: 2015-07-10T15:20:41Z
last-modified: 2017-10-30T14:40:53Z
source: RIPE # Filtered

person: Mickael Marchand
address: 8 rue de la ville l'eveque 75008 PARIS
phone: +33173502000
nic-hdl: MM42047-RIPE
mnt-by: MMA-MNT
created: 2015-07-10T15:02:32Z
last-modified: 2016-02-23T12:43:25Z
source: RIPE # Filtered

% Information related to '51.15.0.0/16AS12876'

route: 51.15.0.0/16
origin: AS12876
mnt-by: MNT-TISCALIFR
created: 2018-03-28T18:01:19Z
last-modified: 2018-03-28T18:01:19Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (WAGYU)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 203.109.110.223 from natural-breast-active.com

Hi,

The IP 203.109.110.223 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 203.109.110.223:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '203.109.96.0 - 203.109.111.255'

% Abuse contact for '203.109.96.0 - 203.109.111.255' is 'abuse@youbroadband.co.in'

inetnum: 203.109.96.0 - 203.109.111.255
netname: YOUTELE
descr: YOU Telecom India Pvt Ltd
country: IN
admin-c: SG135-AP
tech-c: NI23-AP
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-IN-YOU
last-modified: 2009-12-10T05:33:22Z
source: APNIC

person: NOC IQARA
nic-hdl: NI23-AP
e-mail: network@youtele.com
address: YOU Broadband & Cable India Ltd.
address: Iqara Center
address: Adajan-Hazira Rd
address: Surat-9
phone: +91-261-2789500
fax-no: +91-261-2789501
country: IN
mnt-by: MAINT-IN-YOU
last-modified: 2010-04-07T10:10:28Z
source: APNIC

person: SRIDHAR G
nic-hdl: SG135-AP
e-mail: gr.sridhar@youbroadband.co.in
remarks: -----------------------------------------
remarks: send abuse and spam report to
remarks: abuse@youbroadband.in or spamlog@youbroadband.in
remarks: -----------------------------------------
address: YOU Broadband & Cable India Ltd.
address: Millenium Arcade, 2nd floor
address: Adajan-Hazira Road
address: Surat -395009,Gujarat
address: India
phone: +91-261-2789500
fax-no: +91-261-2789501
country: IN
mnt-by: MAINT-IN-YOU
last-modified: 2010-05-13T04:40:07Z
source: APNIC

% Information related to '203.109.110.0/24AS18207'

route: 203.109.110.0/24
descr: YOU Broadband & Cable India Ltd.
country: IN
origin: AS18207
mnt-lower: MAINT-IN-YOU
mnt-routes: MAINT-IN-YOU
mnt-by: MAINT-IN-YOU
last-modified: 2015-11-02T10:15:41Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 202.92.4.131 from natural-breast-active.com

Hi,

The IP 202.92.4.131 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 202.92.4.131:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '202.92.4.0 - 202.92.7.255'

% Abuse contact for '202.92.4.0 - 202.92.7.255' is 'hm-changed@vnnic.vn'

inetnum: 202.92.4.0 - 202.92.7.255
netname: INET-VNNIC-VN
descr: iNET Media Company Limited
descr: 247 Cau Giay Str, Cau Giay Dist, Ha Noi
country: VN
admin-c: TK664-AP
tech-c: LVV1-AP
status: ASSIGNED PORTABLE
remarks: send spam and abuse report to contact@inet.com.vn
mnt-by: MAINT-VN-VNNIC
mnt-routes: MAINT-VN-INET
mnt-irt: IRT-VNNIC-AP
last-modified: 2015-04-08T09:25:20Z
source: APNIC

irt: IRT-VNNIC-AP
address: Ha Noi, VietNam
phone: +84-24-35564944
fax-no: +84-24-37821462
e-mail: hm-changed@vnnic.vn
abuse-mailbox: hm-changed@vnnic.vn
admin-c: NTTT1-AP
tech-c: NTTT1-AP
auth: # Filtered
mnt-by: MAINT-VN-VNNIC
last-modified: 2017-11-08T09:40:06Z
source: APNIC

person: Luu Van Vuong
address: iNET Corporation Company
address: No 247 Cau Giay, Dich Vong ward, Cau Giay district, Ha Noi City
country: VN
phone: +84-24-38385588
e-mail: vuonglv@inet.vn
nic-hdl: LVV1-AP
mnt-by: MAINT-VN-VNNIC
last-modified: 2017-11-02T09:11:21Z
source: APNIC

person: Tran Kien
address: iNET Corporation Company
address: No 247 Cau Giay, Dich Vong ward, Cau Giay district, Ha Noi City
country: VN
phone: +84-24-38385588
e-mail: kien@inet.vn
nic-hdl: TK664-AP
mnt-by: MAINT-VN-VNNIC
last-modified: 2017-11-02T09:09:12Z
source: APNIC

% Information related to '202.92.4.0/22AS7643'

route: 202.92.4.0/22
descr: INET-VN
origin: AS7643
mnt-by: MAINT-VN-VNNIC
last-modified: 2015-04-10T08:15:47Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 94.198.78.42 from natural-breast-active.com

Hi,

The IP 94.198.78.42 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 94.198.78.42:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '94.198.78.40 - 94.198.78.47'

% Abuse contact for '94.198.78.40 - 94.198.78.47' is 'info@logostech.it'

inetnum: 94.198.78.40 - 94.198.78.47
netname: Poletto-Net
descr: Poletto Network
country: IT
admin-c: PS9029-RIPE
tech-c: PS9029-RIPE
status: ASSIGNED PA
mnt-by: MNT-HORIZON
created: 2009-04-02T06:40:35Z
last-modified: 2014-04-11T09:28:56Z
source: RIPE

person: Poletto Srl
address: Quartiere dell'Industria - prima strada 30032 Fiesso d'Artico (PD)
phone: +39
nic-hdl: PS9029-RIPE
created: 2009-01-20T12:21:39Z
last-modified: 2016-04-06T20:30:11Z
mnt-by: RIPE-NCC-LOCKED-MNT
source: RIPE

% Information related to '94.198.72.0/21AS48191'

route: 94.198.72.0/21
descr: 4ISP Main route
origin: AS48191
mnt-by: MNT-HORIZON
created: 2008-10-23T14:04:54Z
last-modified: 2014-04-11T09:32:10Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (HEREFORD)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 140.143.247.241 from natural-breast-active.com

Hi,

The IP 140.143.247.241 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 140.143.247.241:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '140.143.0.0 - 140.143.255.255'

% Abuse contact for '140.143.0.0 - 140.143.255.255' is 'ipas@cnnic.cn'

inetnum: 140.143.0.0 - 140.143.255.255
netname: TencentCloud
descr: Tencent cloud computing (Beijing) Co., Ltd.
descr: Floor 6, Yinke Building,38 Haidian St,
descr: Haidian District Beijing
country: CN
admin-c: JT1125-AP
tech-c: JX1747-AP
mnt-by: MAINT-CNNIC-AP
mnt-irt: IRT-CNNIC-CN
mnt-lower: MAINT-CNNIC-AP
mnt-routes: MAINT-CNNIC-AP
status: ALLOCATED PORTABLE
last-modified: 2016-08-29T02:48:01Z
source: APNIC

irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-11-01T08:57:39Z
source: APNIC

person: James Tian
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-84952
e-mail: harveyduan@tencent.com
nic-hdl: JT1125-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-10-31T07:10:47Z
source: APNIC

person: Jimmy Xiao
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-80224
e-mail: harveyduan@tencent.com
nic-hdl: JX1747-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-11-04T05:51:38Z
source: APNIC

% Information related to '140.143.0.0/16AS45090'

route: 140.143.0.0/16
descr: TencentCloud
country: CN
origin: AS45090
notify: jimmyxiao@tencent.com
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-10-19T03:16:02Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 42.61.24.202 from natural-breast-active.com

Hi,

The IP 42.61.24.202 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 42.61.24.202:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '42.60.0.0 - 42.61.255.255'

% Abuse contact for '42.60.0.0 - 42.61.255.255' is 'abuse@singnet.com.sg'

inetnum: 42.60.0.0 - 42.61.255.255
netname: SINGNET-SG
descr: SingNet Pte Ltd
descr: 2 Stirling Road
descr: #03-00 Queenstown Exchange
descr: Singapore 148943
country: SG
org: ORG-SPL1-AP
admin-c: SH9-AP
tech-c: SH9-AP
status: ALLOCATED PORTABLE
remarks: --------------------------------------------------------
remarks: To report network abuse, please contact mnt-irt
remarks: For troubleshooting, please contact tech-c and admin-c
remarks: Report invalid contact via www.apnic.net/invalidcontact
remarks: --------------------------------------------------------
mnt-by: APNIC-HM
mnt-lower: MAINT-SG-SINGNET
mnt-routes: MAINT-SG-SINGNET
mnt-irt: IRT-SINGNET-SG
last-modified: 2017-08-29T22:58:25Z
source: APNIC

irt: IRT-SINGNET-SG
address: SingNet Engineering & Operations
address: 2 Stirling Road
address: #03-00 Queenstown Exchange
address: Singapore 148943
e-mail: hostmaster@singnet.com.sg
abuse-mailbox: abuse@singnet.com.sg
admin-c: SH9-AP
tech-c: SH9-AP
auth: # Filtered
mnt-by: MAINT-SG-SINGNET
last-modified: 2011-01-14T03:36:00Z
source: APNIC

organisation: ORG-SPL1-AP
org-name: SingNet Pte Ltd
country: SG
address: c/o Singapore Telecommunications
address: Accounts Payable Department
address: 31 Exeter Road, # 16-00 Comcent
phone: +65-6472-2580
fax-no: +65-6471-9812
e-mail: hostmaster@singnet.com.sg
mnt-ref: APNIC-HM
mnt-by: APNIC-HM
last-modified: 2017-10-11T01:28:39Z
source: APNIC

person: SingNet Hostmaster
address: SingNet Engineering & Operations
address: 2 Stirling Road
address: #03-00 Queenstown Exchange
address: Singapore 148943
country: SG
phone: +65 7845922
fax-no: +65 4753273
e-mail: hostmaster@singnet.com.sg
nic-hdl: SH9-AP
notify: hostmaster@singnet.com.sg
mnt-by: MAINT-SG-SINGNET
last-modified: 2011-12-22T05:14:44Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 81.42.199.7 from natural-breast-active.com

Hi,

The IP 81.42.199.7 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 81.42.199.7:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '81.42.192.0 - 81.42.223.255'

% Abuse contact for '81.42.192.0 - 81.42.223.255' is 'nemesys@telefonica.com'

inetnum: 81.42.192.0 - 81.42.223.255
netname: RIMA
descr: Red de servicios IP
country: ES
admin-c: ATDE1-RIPE
tech-c: TTdE1-RIPE
status: ASSIGNED PA
mnt-by: MAINT-AS3352
created: 2017-05-09T14:35:33Z
last-modified: 2017-05-09T14:35:33Z
source: RIPE # Filtered

role: Administradores Telefonica de Espana
address: Ronda de la Comunicacion s/n
address: Edificio Norte 1, planta 6
address: 28050 Madrid
address: SPAIN
org: ORG-TDE1-RIPE
admin-c: KIX1-RIPE
tech-c: TTDE1-RIPE
nic-hdl: ATDE1-RIPE
mnt-by: MAINT-AS3352
abuse-mailbox: nemesys@telefonica.com
created: 2006-01-18T12:24:41Z
last-modified: 2018-04-09T09:42:47Z
source: RIPE # Filtered

role: Tecnicos Telefonica de Espana
address: Ronda de la Comunicacion S/N
address: 28050-MADRID
address: SPAIN
org: ORG-TDE1-RIPE
admin-c: TTE2-RIPE
tech-c: TTE2-RIPE
nic-hdl: TTdE1-RIPE
mnt-by: MAINT-AS3352
abuse-mailbox: nemesys@telefonica.com
created: 2006-01-18T12:39:59Z
last-modified: 2018-04-09T09:43:13Z
source: RIPE # Filtered

% Information related to '81.42.0.0/16AS3352'

route: 81.42.0.0/16
descr: RIMA (Red IP Multi Acceso)
origin: AS3352
mnt-by: MAINT-AS3352
created: 2002-03-26T11:55:21Z
last-modified: 2009-08-19T06:59:18Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (BLAARKOP)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 98.164.34.90 from natural-breast-active.com

Hi,

The IP 98.164.34.90 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 98.164.34.90:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 98.164.34.90"
#
# Use "?" to get help.
#

Cox Communications Inc. NETBLK-OKC-COI-98-164-32-0 (NET-98-164-32-0-1) 98.164.32.0 - 98.164.47.255
Cox Communications Inc. CXA (NET-98-160-0-0-1) 98.160.0.0 - 98.191.255.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 189.146.251.89 from natural-breast-active.com

Hi,

The IP 189.146.251.89 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 189.146.251.89:

[Querying whois.lacnic.net]
[whois.lacnic.net]

% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries

% LACNIC resource: whois.lacnic.net


% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2018-05-28 22:30:40 (BRT -03:00)

inetnum: 189.146.251/24
status: reassigned
owner: Gestión de direccionamiento UniNet
ownerid: MX-GDUN-LACNIC
responsible: Gestión de cambios y configuraciones
address: Periferico Sur, 3190,
address: 01900 - México DF - CX
country: MX
phone: +52 55 56244400 []
owner-c: DCA
tech-c: DCA
abuse-c: SRU
created: 20070914
changed: 20120901
inetnum-up: 189.128/11

nic-hdl: DCA
person: GESTION DE CAMBIOS
e-mail: gccips1@REDUNO.COM.MX
address: PERIFERICO SUR, 3190, ALVARO OBREG
address: 01900 - MEXICO DF - CX
country: MX
phone: +52 5 556244400 []
created: 20021210
changed: 20170107

nic-hdl: SRU
person: SEGURIDAD DE RED UNINET
e-mail: abuse@UNINET.NET.MX
address: PERIFERICO SUR, 3190, ALVARO OBREG
address: 01900 - MEXICO - CX
country: MX
phone: +52 55 52237234 []
created: 20030701
changed: 20170107

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 193.52.13.61 from natural-breast-active.com

Hi,

The IP 193.52.13.61 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 193.52.13.61:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '193.52.13.0 - 193.52.13.63'

% Abuse contact for '193.52.13.0 - 193.52.13.63' is 'certsvp@renater.fr'

inetnum: 193.52.13.0 - 193.52.13.63
netname: FR-LSBB-RUSTREL
descr: Laboratoire Sous Terrain a Bas Bruit
country: FR
admin-c: DB9307-RIPE
admin-c: AC16248-RIPE
tech-c: JM4147-RIPE
tech-c: MM9545-RIPE
status: ASSIGNED PA
mnt-by: RENATER-MNT
remarks: changed: rensvp@renater.fr 20100816
created: 2002-09-27T10:17:03Z
last-modified: 2015-08-06T14:16:05Z
source: RIPE

person: Alain CAVAILLOU
address: Laboratoire Sous Terrain à Bas Bruit
address: La Grande Combe, 84400 Rustrel, France
phone: +33 4 90 04 99 00
fax-no: +33 4 90 04 99 01
nic-hdl: AC16248-RIPE
mnt-by: RENATER-MNT
remarks: changed: rensvp@renater.fr 20100816
created: 2010-08-16T16:22:17Z
last-modified: 2015-08-07T13:55:43Z
source: RIPE # Filtered

person: Daniel BOYER
address: Laboratoire Sous Terrain à Bas Bruit
address: La Grande Combe, 84400 Rustrel, France
phone: +33 4 90 04 99 00
fax-no: +33 4 90 04 99 01
nic-hdl: DB9307-RIPE
mnt-by: RENATER-MNT
remarks: changed: rensvp@renater.fr 20100816
created: 2010-08-16T16:22:17Z
last-modified: 2015-08-07T14:11:15Z
source: RIPE # Filtered

person: Jean-Michel MERCIER
address: Observatoire de la Cote d'Azur
address: BP4229, F-06304 Nice CEDEX 4, France
phone: +33 4 92 00 30 10
fax-no: +33 4 92 00 31 18
nic-hdl: JM4147-RIPE
mnt-by: RENATER-MNT
remarks: changed: rensvp@renater.fr 20050112
remarks: changed: rensvp@renater.fr 20100816
created: 2005-01-12T16:46:43Z
last-modified: 2015-08-07T14:14:37Z
source: RIPE # Filtered

person: Marie-Laure MINIUSSI
address: Observatoire de la Cote d'Azur
address: CS 34229, F-06304 Nice CEDEX 4, France
phone: +33 4 92 00 19 42
fax-no: +33 4 92 00 31 18
nic-hdl: MM9545-RIPE
mnt-by: RENATER-MNT
remarks: changed: rensvp@renater.fr 20050112
remarks: changed: rensvp@renater.fr 20150512
created: 2005-01-12T16:46:39Z
last-modified: 2015-08-07T14:26:05Z
source: RIPE # Filtered

% Information related to '193.52.0.0/16AS2200'

route: 193.52.0.0/16
descr: RENATER
descr: FRANCE
origin: AS2200
mnt-by: RENATER-MNT
remarks: changed: RenSVP@Renater.fr 19991008
remarks: changed: rensvp@renater.fr 20100915
created: 1970-01-01T00:00:00Z
last-modified: 2015-08-07T13:36:18Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (BLAARKOP)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 118.97.55.104 from natural-breast-active.com

Hi,

The IP 118.97.55.104 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 118.97.55.104:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '118.97.53.88 - 118.97.97.95'

% Abuse contact for '118.97.53.88 - 118.97.97.95' is 'abuse@telkom.co.id'

inetnum: 118.97.53.88 - 118.97.97.95
netname: TLKM_D2_AST_CUSTOMER
country: ID
descr: PT Telkom Indonesia's customer.
admin-c: HM444-AP
tech-c: AI64-AP
remarks: ------------------------------------------------------------------
remarks: Send ABUSE and SPAM reports with plain ASCII text only to
remarks: to abuse@telkom.net.id.
remarks: The netname enclosed in square bracket is included in the subject.
remarks: ------------------------------------------------------------------
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-TELKOMNET
last-modified: 2009-02-18T04:25:59Z
source: APNIC

role: PT Telkom Indonesia ABUSE INTERNET Response Team
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
country: ID
phone: +62-21-3860500
fax-no: +62-21-3861215
e-mail: abuse@telkom.net.id
admin-c: HM444-AP
tech-c: HM444-AP
nic-hdl: AI64-AP
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
last-modified: 2008-09-04T07:54:17Z
source: APNIC

person: PT Telkom Indonesia Hostmaster
nic-hdl: HM444-AP
e-mail: hostmaster@telkom.net.id
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
phone: +62-21-3860500
fax-no: +62-21-3861215
country: ID
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
last-modified: 2008-09-04T07:29:40Z
source: APNIC

% Information related to '118.97.55.0/24AS17974'

route: 118.97.55.0/24
descr: PT. TELKOM INDONESIA
descr: JAKARTA
country: ID
origin: AS17974
mnt-by: MAINT-TELKOMNET
last-modified: 2015-05-27T03:32:56Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 177.73.136.228 from natural-breast-active.com

Hi,

The IP 177.73.136.228 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 177.73.136.228:

[Querying whois.arin.net]
[Redirected to whois.lacnic.net]
[Querying whois.lacnic.net]
[Redirected to whois.registro.br]
[Querying whois.registro.br]
[whois.registro.br]

% Copyright (c) Nic.br
% The use of the data below is only permitted as described in
% full by the terms of use at https://registro.br/termo/en.html ,
% being prohibited its distribution, commercialization or
% reproduction, in particular, to use it for advertising or
% any similar purpose.
% 2018-05-28T21:49:35-03:00

% Permission denied. For more information, contact abuse@registro.br

% Security and mail abuse issues should also be addressed to
% cert.br, http://www.cert.br/ , respectivelly to cert@cert.br
% and mail-abuse@cert.br
%
% whois.registro.br accepts only direct match queries. Types
% of queries are: domain (.br), registrant (tax ID), ticket,
% provider, contact handle (ID), CIDR block, IP and ASN.

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 206.189.196.193 from natural-breast-active.com

Hi,

The IP 206.189.196.193 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 206.189.196.193:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 206.189.196.193"
#
# Use "?" to get help.
#

NetRange: 206.189.0.0 - 206.189.255.255
CIDR: 206.189.0.0/16
NetName: DIGITALOCEAN-30
NetHandle: NET-206-189-0-0-1
Parent: NET206 (NET-206-0-0-0-0)
NetType: Direct Allocation
OriginAS:
Organization: DigitalOcean, LLC (DO-13)
RegDate: 1995-11-15
Updated: 2018-03-26
Ref: https://whois.arin.net/rest/net/NET-206-189-0-0-1



OrgName: DigitalOcean, LLC
OrgId: DO-13
Address: 101 Ave of the Americas
Address: 10th Floor
City: New York
StateProv: NY
PostalCode: 10013
Country: US
RegDate: 2012-05-14
Updated: 2017-07-03
Comment: http://www.digitalocean.com
Comment: Simple Cloud Hosting
Ref: https://whois.arin.net/rest/org/DO-13


OrgTechHandle: NOC32014-ARIN
OrgTechName: Network Operations Center
OrgTechPhone: +1-347-875-6044
OrgTechEmail: noc@digitalocean.com
OrgTechRef: https://whois.arin.net/rest/poc/NOC32014-ARIN

OrgAbuseHandle: ABUSE5232-ARIN
OrgAbuseName: Abuse, DigitalOcean
OrgAbusePhone: +1-347-875-6044
OrgAbuseEmail: abuse@digitalocean.com
OrgAbuseRef: https://whois.arin.net/rest/poc/ABUSE5232-ARIN

OrgNOCHandle: NOC32014-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-347-875-6044
OrgNOCEmail: noc@digitalocean.com
OrgNOCRef: https://whois.arin.net/rest/poc/NOC32014-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 118.24.157.66 from natural-breast-active.com

Hi,

The IP 118.24.157.66 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 118.24.157.66:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '118.24.0.0 - 118.25.255.255'

% Abuse contact for '118.24.0.0 - 118.25.255.255' is 'tencent_idc@tencent.com'

inetnum: 118.24.0.0 - 118.25.255.255
netname: TENCENT-CN
descr: Tencent Cloud Computing (Beijing) Co., Ltd
descr: Floor 6, Yinke Building, 38 Haidian St, Haidian District
country: CN
org: ORG-TCCC1-AP
admin-c: TCA15-AP
tech-c: TCA15-AP
mnt-by: APNIC-HM
mnt-routes: MAINT-TENCENT-CN
mnt-lower: MAINT-TENCENT-CN
mnt-irt: IRT-TENCENT-CN
status: ALLOCATED PORTABLE
remarks: --------------------------------------------------------
remarks: To report network abuse, please contact mnt-irt
remarks: For troubleshooting, please contact tech-c and admin-c
remarks: Report invalid contact via www.apnic.net/invalidcontact
remarks: --------------------------------------------------------
last-modified: 2017-08-29T23:00:21Z
source: APNIC

irt: IRT-TENCENT-CN
address: Floor 6, Yinke Building, 38 Haidian St, Haidian District, Beijing Beijing 100080
e-mail: tencent_idc@tencent.com
abuse-mailbox: tencent_idc@tencent.com
admin-c: TCA15-AP
tech-c: TCA15-AP
auth: # Filtered
mnt-by: MAINT-COMSENZ1-CN
last-modified: 2017-06-28T03:13:15Z
source: APNIC

organisation: ORG-TCCC1-AP
org-name: Tencent Cloud Computing (Beijing) Co., Ltd
country: CN
address: 309 West Zone, 3F. 49 Zhichun Road. Haidian District.
phone: +86-10-62671299
fax-no: +86-10-82602088-41299
e-mail: tencent_idc@tencent.com
mnt-ref: APNIC-HM
mnt-by: APNIC-HM
last-modified: 2017-08-20T22:54:05Z
source: APNIC

role: Tencent Cloud administrator
address: Floor 6, Yinke Building, 38 Haidian St, Haidian District, Beijing Beijing 100080
country: CN
phone: +86-10-62671299
e-mail: tencent_idc@tencent.com
admin-c: TCA15-AP
tech-c: TCA15-AP
nic-hdl: TCA15-AP
mnt-by: MAINT-AP-DIALPAD
fax-no: +86-10-62671299
last-modified: 2017-04-04T10:34:03Z
source: APNIC

% Information related to '118.24.0.0/15AS45090'

route: 118.24.0.0/15
descr: TENCENT-CN routes
origin: AS45090
mnt-by: MAINT-COMSENZ1-CN
mnt-lower: MAINT-COMSENZ1-CN
mnt-routes: MAINT-COMSENZ1-CN
last-modified: 2017-07-07T07:13:59Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 106.12.8.207 from natural-breast-active.com

Hi,

The IP 106.12.8.207 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 106.12.8.207:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '106.12.0.0 - 106.13.255.255'

% Abuse contact for '106.12.0.0 - 106.13.255.255' is 'ipas@cnnic.cn'

inetnum: 106.12.0.0 - 106.13.255.255
netname: Baidu
descr: Beijing Baidu Netcom Science and Technology Co., Ltd.
descr: Baidu Plaza, No.10, Shangdi 10th street,
descr: Haidian District Beijing,100080
admin-c: SD753-AP
tech-c: SD753-AP
country: CN
mnt-by: MAINT-CNNIC-AP
mnt-lower: MAINT-CNNIC-AP
mnt-irt: IRT-CNNIC-CN
mnt-routes: MAINT-CNNIC-AP
status: ALLOCATED PORTABLE
last-modified: 2015-01-28T09:58:01Z
source: APNIC

irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-11-01T08:57:39Z
source: APNIC

person: Supeng Deng
nic-hdl: SD753-AP
address: No.6 2nd North Street Haidian District Beijing
country: CN
phone: +86-10-58003402
fax-no: +86-10-58003402
e-mail: zhangyukun@baidu.com
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-11-01T08:04:01Z
source: APNIC

% Information related to '106.12.0.0/18AS38365'

route: 106.12.0.0/18
descr: Baidu
country: CN
origin: AS38365
notify: zhangyukun@baidu.com
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-12-21T02:20:17Z
source: APNIC

% Information related to '106.12.0.0/18AS55967'

route: 106.12.0.0/18
descr: Baidu
country: CN
origin: AS55967
notify: zhangyukun@baidu.com
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-12-21T02:20:23Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 119.28.74.248 from natural-breast-active.com

Hi,

The IP 119.28.74.248 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 119.28.74.248:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '119.28.0.0 - 119.29.255.255'

% Abuse contact for '119.28.0.0 - 119.29.255.255' is 'ipas@cnnic.cn'

inetnum: 119.28.0.0 - 119.29.255.255
netname: TencentCloud
descr: Tencent cloud computing (Beijing) Co., Ltd.
descr: Floor 6, Yinke Building,38 Haidian St,
descr: Haidian District Beijing
country: CN
admin-c: JT1125-AP
tech-c: JX1747-AP
mnt-by: MAINT-CNNIC-AP
mnt-irt: IRT-CNNIC-CN
mnt-routes: MAINT-TENCENT-NET-AP-CN
status: ALLOCATED PORTABLE
last-modified: 2017-05-16T07:44:01Z
source: APNIC

irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-11-01T08:57:39Z
source: APNIC

person: James Tian
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-84952
e-mail: harveyduan@tencent.com
nic-hdl: JT1125-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-10-31T07:10:47Z
source: APNIC

person: Jimmy Xiao
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-80224
e-mail: harveyduan@tencent.com
nic-hdl: JX1747-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-11-04T05:51:38Z
source: APNIC

% Information related to '119.28.64.0/19AS133478'

route: 119.28.64.0/19
descr: ComsenzNet routes
origin: AS133478
mnt-by: MAINT-COMSENZ1-CN
last-modified: 2015-12-14T12:36:14Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 54.36.126.178 from natural-breast-active.com

Hi,

The IP 54.36.126.178 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 54.36.126.178:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '54.36.0.0 - 54.38.255.255'

% Abuse contact for '54.36.0.0 - 54.38.255.255' is 'abuse@ovh.net'

inetnum: 54.36.0.0 - 54.38.255.255
org: ORG-OS3-RIPE
status: LEGACY
netname: FR-OVH
country: FR
admin-c: OTC2-RIPE
tech-c: OTC2-RIPE
mnt-by: RIPE-NCC-LEGACY-MNT
mnt-by: OVH-MNT
created: 2017-10-16T15:27:48Z
last-modified: 2017-10-16T15:27:48Z
source: RIPE

organisation: ORG-OS3-RIPE
org-name: OVH SAS
org-type: LIR
address: 2 rue Kellermann
address: 59100
address: Roubaix
address: FRANCE
phone: +33972101007
abuse-c: AR15333-RIPE
admin-c: OTC2-RIPE
admin-c: OK217-RIPE
admin-c: GM84-RIPE
mnt-ref: OVH-MNT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
mnt-by: OVH-MNT
created: 2004-04-17T11:23:17Z
last-modified: 2017-10-30T14:40:06Z
source: RIPE # Filtered

role: OVH Technical Contact
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
admin-c: OK217-RIPE
tech-c: GM84-RIPE
tech-c: SL10162-RIPE
nic-hdl: OTC2-RIPE
abuse-mailbox: abuse@ovh.net
mnt-by: OVH-MNT
created: 2004-01-28T17:42:29Z
last-modified: 2014-09-05T10:47:15Z
source: RIPE # Filtered

% Information related to '54.36.0.0/16AS16276'

route: 54.36.0.0/16
origin: AS16276
mnt-by: OVH-MNT
created: 2017-10-06T07:57:47Z
last-modified: 2017-10-06T07:57:47Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (ANGUS)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 77.22.56.68 from natural-breast-active.com

Hi,

The IP 77.22.56.68 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 77.22.56.68:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '77.22.0.0 - 77.23.255.255'

% Abuse contact for '77.22.0.0 - 77.23.255.255' is 'abuse@vodafone.com'

inetnum: 77.22.0.0 - 77.23.255.255
netname: KABEL-DEUTSCHLAND-CUSTOMER-SERVICES-17
descr: Kabel Deutschland Breitband Customer 17
country: DE
admin-c: KDG40-RIPE
tech-c: KDG40-RIPE
status: ASSIGNED PA
mnt-by: MNT-KABELDEUTSCHLAND
mnt-lower: MNT-KABELDEUTSCHLAND
mnt-routes: MNT-KABELDEUTSCHLAND
created: 2008-09-22T13:44:14Z
last-modified: 2015-06-09T14:48:54Z
source: RIPE

role: Kabel Deutschland RIPE
address: Vodafone Kabel Deutschland GmbH
address: Germaniastr. 14-17
address: 12099 Berlin
address: Germany
admin-c: FM464-RIPE
admin-c: MM45323-RIPE
tech-c: MM45323-RIPE
abuse-mailbox: abuse@vodafone.com
nic-hdl: KDG40-RIPE
mnt-by: MNT-KABELDEUTSCHLAND
created: 2015-06-06T09:42:03Z
last-modified: 2018-01-08T13:49:13Z
source: RIPE # Filtered

% Information related to '77.22.0.0/17AS31334'

route: 77.22.0.0/17
descr: Kabeldeutschland Route
origin: AS31334
mnt-by: MNT-KABELDEUTSCHLAND
created: 2009-04-20T13:15:25Z
last-modified: 2009-04-20T13:15:25Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (ANGUS)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 181.48.14.50 from natural-breast-active.com

Hi,

The IP 181.48.14.50 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 181.48.14.50:

[Querying whois.arin.net]
[Redirected to whois.lacnic.net]
[Querying whois.lacnic.net]
[whois.lacnic.net]

% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries

% LACNIC resource: whois.lacnic.net


% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2018-05-28 20:58:07 (BRT -03:00)

inetnum: 181.48/13
status: allocated
aut-num: N/A
owner: Telmex Colombia S.A.
ownerid: CO-ACSA-LACNIC
responsible: Operaciones Core IP
address: CLARO FIJO COLOMBIA - Cra 68A No. 24B-10, 11111,
address: 11111 - Bogota - DC
country: CO
phone: +57 01 7480000 []
owner-c: ATI
tech-c: ATI
abuse-c: ATI
inetrev: 181.48/16
nserver: NS3.TELMEXLA.NET.CO
nsstat: 20180527 AA
nslastaa: 20180527
nserver: NS2.TELMEXLA.NET.CO
nsstat: 20180527 AA
nslastaa: 20180527
created: 20110502
changed: 20110502

nic-hdl: ATI
person: Network Security Team
e-mail: abuse@TELMEXLA.NET.CO
address: Carrera 68a #24b-10, 00, Plaza Claro
address: 111321 - Bogota - DC
country: CO
phone: +57 017480456 [81966]
created: 20020909
changed: 20180302

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 170.210.136.3 from natural-breast-active.com

Hi,

The IP 170.210.136.3 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 170.210.136.3:

[Querying whois.arin.net]
[Redirected to whois.lacnic.net]
[Querying whois.lacnic.net]
[whois.lacnic.net]

% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries

% LACNIC resource: whois.lacnic.net


% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2018-05-28 20:14:39 (BRT -03:00)

inetnum: 170.210/16
status: assigned
aut-num: AS4270
abuse-c: ADR6
owner: Red de Interconexion Universitaria
ownerid: AR-RIUN-LACNIC
responsible: Carlos Frank
address: Maipu, 645, Piso 4to - Of 10
address: C1006ACG - Ciudad de Buenos Aires - BA
country: AR
phone: +54 1143227027 [0000]
owner-c: ADR6
tech-c: ADR6
abuse-c: ADR6
inetrev: 170.210/16
nserver: NS2.RIU.EDU.AR
nsstat: 20180526 AA
nslastaa: 20180526
nserver: NS4.RIU.EDU.AR
nsstat: 20180526 AA
nslastaa: 20180526
dsinetrev: 170.210/16
dsrecord: 38392 RSA/SHA-256 069D4E72295EFA904F9C38C843BDEAD248D2831C1A6EB9CC120DF7C3A526D5A1
dsstatus: 20180526 OK
dslastok: 20180526
dsinetrev: 170.210/16
dsrecord: 38392 RSA/SHA-256 6FC92A8A9CA5119EFE4C128948281D1DA73B40C2
dsstatus: 20180526 OK
dslastok: 20180526
created: 19950124
changed: 20040405

nic-hdl: ADR6
person: Administracion RIU
e-mail: noc@RIU.EDU.AR
address: Maipu, 645, Piso 4 Of. 10
address: C1006ACG - Buenos Aires - CF
country: AR
phone: +54 11 43227027 []
created: 20040315
changed: 20170109

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 139.199.121.254 from natural-breast-active.com

Hi,

The IP 139.199.121.254 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 139.199.121.254:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '139.199.0.0 - 139.199.255.255'

% Abuse contact for '139.199.0.0 - 139.199.255.255' is 'ipas@cnnic.cn'

inetnum: 139.199.0.0 - 139.199.255.255
netname: TencentCloud
descr: Tencent cloud computing (Beijing) Co., Ltd.
descr: Floor 6, Yinke Building,38 Haidian St,
descr: Haidian District Beijing
admin-c: JT1125-AP
tech-c: JX1747-AP
country: CN
mnt-by: MAINT-CNNIC-AP
mnt-lower: MAINT-CNNIC-AP
mnt-routes: MAINT-CNNIC-AP
mnt-irt: IRT-CNNIC-CN
status: ALLOCATED PORTABLE
last-modified: 2015-01-29T06:14:02Z
source: APNIC

irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
last-modified: 2017-11-01T08:57:39Z
source: APNIC

person: James Tian
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-84952
e-mail: harveyduan@tencent.com
nic-hdl: JT1125-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-10-31T07:10:47Z
source: APNIC

person: Jimmy Xiao
address: 9F, FIYTA Building, Gaoxinnanyi Road,Southern
address: District of Hi-tech Park, Shenzhen
country: CN
phone: +86-755-86013388-80224
e-mail: harveyduan@tencent.com
nic-hdl: JX1747-AP
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-11-04T05:51:38Z
source: APNIC

% Information related to '139.199.0.0/16AS45090'

route: 139.199.0.0/16
descr: TencentCloud
descr: Tencent cloud computing (Beijing) Co., Ltd.
country: CN
origin: AS45090
notify: jimmyxiao@tencent.com
mnt-by: MAINT-CNNIC-AP
last-modified: 2016-01-21T09:24:01Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 185.154.14.238 from natural-breast-active.com

Hi,

The IP 185.154.14.238 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 185.154.14.238:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '185.154.14.128 - 185.154.14.255'

% Abuse contact for '185.154.14.128 - 185.154.14.255' is 'abuse@server-panel.net'

inetnum: 185.154.14.128 - 185.154.14.255
netname: NET-9-2
org: ORG-ODL5-RIPE
country: NL
remarks: Server location - Netherlands, Dronten
geoloc: 52.718151 6.199986
remarks: abuse mailbox - abuse@server-panel.net
admin-c: MC31466-RIPE
tech-c: MC31466-RIPE
mnt-routes: ITL-MNT
status: ASSIGNED PA
mnt-by: XX0220
created: 2018-04-23T09:58:54Z
last-modified: 2018-04-23T09:58:54Z
source: RIPE

organisation: ORG-ODL5-RIPE
org-name: ON-LINE DATA LTD
org-type: OTHER
address: Suite 1, Second Floor, Sound & Vision House, Francis Rachel Str.
address: Victoria, Mahe, Seychelles
abuse-c: AR36511-RIPE
mnt-ref: XX0220
mnt-ref: ua-online-324-1-mnt
mnt-ref: new-microweb
mnt-ref: ua-tele-web-1-mnt
mnt-ref: ua-noter-klav-1-mnt
mnt-ref: ua-linux-com-1-mnt
mnt-ref: ua-capital-d-1-mnt
mnt-ref: ua-bilzard-1-mnt
mnt-ref: ua-site-trast-1-mnt
mnt-ref: ua-torat-1-mnt
mnt-ref: ua-td-server-1-mnt
mnt-ref: ua-snab-inform-1-mnt
mnt-by: XX0220
created: 2017-02-08T15:13:39Z
last-modified: 2018-04-23T16:03:44Z
source: RIPE # Filtered

person: Michel Clarisse
address: Suite 1, Second Floor, Sound & Vision House, Francis Rachel Str.
address: Victoria, Mahe, Seychelles
phone: +248 063-71-35
nic-hdl: MC31466-RIPE
mnt-by: XX0220
created: 2017-02-08T15:24:29Z
last-modified: 2018-04-23T09:01:26Z
source: RIPE

% Information related to '185.154.14.0/24AS21100'

route: 185.154.14.0/24
origin: AS21100
mnt-by: ITL-MNT
created: 2016-06-27T06:43:01Z
last-modified: 2018-04-23T16:10:45Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (HEREFORD)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 80.211.48.187 from natural-breast-active.com

Hi,

The IP 80.211.48.187 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 80.211.48.187:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '80.211.48.0 - 80.211.48.255'

% Abuse contact for '80.211.48.0 - 80.211.48.255' is 'abuse@staff.aruba.it'

inetnum: 80.211.48.0 - 80.211.48.255
geoloc: 43.45997095884493 11.837875843048096
netname: ARUBA-NET
descr: Aruba S.p.A. - Cloud Services DC1
country: IT
admin-c: SS936-RIPE
tech-c: AN3450-RIPE
mnt-by: ARUBA-MNT
status: ASSIGNED PA
created: 2018-04-30T07:11:42Z
last-modified: 2018-04-30T07:11:42Z
source: RIPE

role: ARUBA NOC
address: Aruba S.p.A.
address: via S.Clemente 53
address: 24036 Ponte San Pietro (BG)
address: Italy
abuse-mailbox: abuse@staff.aruba.it
admin-c: SS936-RIPE
tech-c: SC279-RIPE
nic-hdl: AN3450-RIPE
mnt-by: ARUBA-MNT
created: 2008-11-19T19:02:34Z
last-modified: 2017-11-15T08:13:57Z
source: RIPE # Filtered

person: Susanna Santini
address: Aruba S.p.A.
address: Via S.Clemente, 53
address: 24036 Ponte San Pietro (BG)
phone: +39 0575 0505
fax-no: +39 0575 862000
nic-hdl: SS936-RIPE
mnt-by: ARUBA-MNT
created: 1970-01-01T00:00:00Z
last-modified: 2017-11-15T08:14:40Z
source: RIPE # Filtered

% Information related to '80.211.0.0/17AS31034'

route: 80.211.0.0/17
descr: Aruba S.p.A. Network
origin: AS31034
mnt-by: ARUBA-MNT
created: 2017-06-16T10:10:03Z
last-modified: 2017-06-16T10:10:03Z
source: RIPE

% This query was served by the RIPE Database Query Service version 1.91.2 (BLAARKOP)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 45.125.117.178 from natural-breast-active.com

Hi,

The IP 45.125.117.178 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 45.125.117.178:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '45.125.116.0 - 45.125.119.255'

% Abuse contact for '45.125.116.0 - 45.125.119.255' is 'limrasbroadband@gmail.com'

inetnum: 45.125.116.0 - 45.125.119.255
netname: LIMRASERONET
descr: limras eronet broadband service private limited
admin-c: VM164-AP
tech-c: MD670-AP
country: IN
mnt-by: MAINT-IN-IRINN
mnt-lower: MAINT-IN-LIMRASERONET
mnt-irt: IRT-LIMRASERONET-IN
mnt-routes: MAINT-IN-LIMRASERONET
status: ALLOCATED PORTABLE
last-modified: 2015-08-03T11:51:15Z
source: APNIC

irt: IRT-LIMRASERONET-IN
address: no:4,valluvar kottam high road
e-mail: limrasbroadband@gmail.com
abuse-mailbox: limrasbroadband@gmail.com
admin-c: MD670-AP
tech-c: VM164-AP
auth: # Filtered
remarks: send spam and abuse report to limrasbroadband@gmail.com
irt-nfy: limrasbroadband@gmail.com
notify: limrasbroadband@gmail.com
mnt-by: MAINT-IN-LIMRASERONET
last-modified: 2014-05-19T11:04:27Z
source: APNIC

role: Managing Director
address: no:4,valluvar kottam high road
country: IN
phone: +91 04430461450
fax-no: +91 04430461450
e-mail: venkatesh.trm@gmail.com
admin-c: VM164-AP
tech-c: VM164-AP
nic-hdl: MD670-AP
remarks: send spam and abuse report to limrasbroadband@gmail.com
notify: limrasbroadband@gmail.com
abuse-mailbox: limrasbroadband@gmail.com
mnt-by: MAINT-IN-LIMRASERONET
last-modified: 2014-05-19T11:04:00Z
source: APNIC

person: Venkatesh Meganathan
address: no4valluvar kottam high road
country: IN
phone: +91 04430461450
fax-no: +91 04430461450
e-mail: limrasbroadband@gmail.com
nic-hdl: VM164-AP
remarks: send spam and abuse report to limrasbroadband@gmail.com
notify: limrasbroadband@gmail.com
abuse-mailbox: limrasbroadband@gmail.com
mnt-by: MAINT-IN-LIMRASERONET
last-modified: 2014-05-19T11:03:34Z
source: APNIC

% Information related to '45.125.117.0/24AS132556'

route: 45.125.117.0/24
descr: Limras Eronet Broadband Service Private limited
origin: AS132556
country: IN
remarks: send spam and abuse report to limrasbroadband@gmail.com
notify: limrasbroadband@gmail.com
mnt-routes: MAINT-IN-BLUELOTUS
mnt-by: MAINT-IN-BLUELOTUS
last-modified: 2015-08-25T05:22:12Z
source: APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 76.247.31.173 from natural-breast-active.com

Hi,

The IP 76.247.31.173 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 76.247.31.173:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 76.247.31.173"
#
# Use "?" to get help.
#

NetRange: 76.241.128.0 - 76.251.255.255
CIDR: 76.241.128.0/17, 76.244.0.0/14, 76.248.0.0/14, 76.242.0.0/15
NetName: SBCIS-SBIS-6BLK
NetHandle: NET-76-241-128-0-1
Parent: NET76 (NET-76-0-0-0-0)
NetType: Direct Allocation
OriginAS:
Organization: AT&T Internet Services (SIS-80)
RegDate: 2006-09-15
Updated: 2018-01-10
Comment: Contact ipadmin@att.com for general IP
Comment: Administration support.
Ref: https://whois.arin.net/rest/net/NET-76-241-128-0-1



OrgName: AT&T Internet Services
OrgId: SIS-80
Address: 3300 E Renner Rd
Address: Mailroom B2139
Address: Attn:IP Management
City: Richardson
StateProv: TX
PostalCode: 75082
Country: US
RegDate: 2000-06-19
Updated: 2017-05-30
Comment: For policy abuse issues contact abuse@att.net
Comment: For all subpoena, Internet, court order related matters and emergency requests contact
Comment: 11760 US Highway 1
Comment: North Palm Beach, FL 33408
Comment: Main Number: 800-635-6840
Comment: Fax: 888-938-4715
Ref: https://whois.arin.net/rest/org/SIS-80


OrgAbuseHandle: ABUSE6-ARIN
OrgAbuseName: Abuse ATT Internet Services
OrgAbusePhone: +1-919-319-8167
OrgAbuseEmail: abuse@att.net
OrgAbuseRef: https://whois.arin.net/rest/poc/ABUSE6-ARIN

OrgTechHandle: IPADM2-ARIN
OrgTechName: IPAdmin ATT Internet Services
OrgTechPhone: +1-888-510-5545
OrgTechEmail: ipadmin@att.com
OrgTechRef: https://whois.arin.net/rest/poc/IPADM2-ARIN

OrgNOCHandle: SUPPO-ARIN
OrgNOCName: Support ATT Internet Services
OrgNOCPhone: +1-888-510-5545
OrgNOCEmail: ipadmin@sbc.com
OrgNOCRef: https://whois.arin.net/rest/poc/SUPPO-ARIN

RTechHandle: IPADM2-ARIN
RTechName: IPAdmin ATT Internet Services
RTechPhone: +1-888-510-5545
RTechEmail: ipadmin@att.com
RTechRef: https://whois.arin.net/rest/poc/IPADM2-ARIN

RAbuseHandle: ABUSE6-ARIN
RAbuseName: Abuse ATT Internet Services
RAbusePhone: +1-919-319-8167
RAbuseEmail: abuse@att.net
RAbuseRef: https://whois.arin.net/rest/poc/ABUSE6-ARIN

RNOCHandle: SUPPO-ARIN
RNOCName: Support ATT Internet Services
RNOCPhone: +1-888-510-5545
RNOCEmail: ipadmin@sbc.com
RNOCRef: https://whois.arin.net/rest/poc/SUPPO-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#
# If you see inaccuracies in the results, please report at
# https://www.arin.net/resources/whois_reporting/index.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 136.243.126.99 from natural-breast-active.com

Hi,

The IP 136.243.126.99 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 136.243.126.99:

[Querying whois.arin.net]
[Redirected to whois.ripe.net]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '136.243.126.96 - 136.243.126.127'

% No abuse contact registered for 136.243.126.96 - 136.243.126.127

inetnum: 136.243.126.96 - 136.243.126.127
netname: OOO-VESTA
descr: OOO "Vesta"
country: DE
admin-c: MS39426-RIPE
tech-c: MS39426-RIPE
status: LEGACY
mnt-by: HOS-GUN
created: 2015-11-24T02:13:02Z
last-modified: 2015-11-24T02:13:02Z
source: RIPE # Filtered

person: Maxim Shchelokov
address: Just-Hosting
address: str.krasnykh 11-12
address: 654000 Zelenogorsk
address: RUSSIAN FEDERATION
phone: +79089474007
nic-hdl: MS39426-RIPE
remarks: **************************************
remarks: * For spamming or other abuse issues *
remarks: * please send your requests to *
remarks: * abuse@just-hosting.ru *
remarks: **************************************
mnt-by: HOS-GUN
created: 2015-11-22T16:24:13Z
last-modified: 2017-10-20T02:31:17Z
source: RIPE # Filtered

% Information related to '136.243.0.0/16AS24940'

route: 136.243.0.0/16
descr: HETZNER-RZ-BLK-ERX3
origin: AS24940
org: ORG-HOA1-RIPE
mnt-by: HOS-GUN
created: 2012-12-24T09:10:23Z
last-modified: 2012-12-24T09:10:23Z
source: RIPE

organisation: ORG-HOA1-RIPE
org-name: Hetzner Online GmbH
org-type: LIR
address: Industriestrasse 25
address: D-91710
address: Gunzenhausen
address: GERMANY
phone: +49 9831 5050
fax-no: +49 9831 5053
admin-c: TF2013-RIPE
admin-c: MF1400-RIPE
admin-c: GM834-RIPE
admin-c: HOAC1-RIPE
admin-c: MH375-RIPE
admin-c: SK2374-RIPE
admin-c: SK8441-RIPE
abuse-c: HOAC1-RIPE
mnt-ref: RIPE-NCC-HM-MNT
mnt-ref: HOS-GUN
mnt-by: RIPE-NCC-HM-MNT
mnt-by: HOS-GUN
created: 2004-04-17T11:07:58Z
last-modified: 2016-08-25T13:26:09Z
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.91.2 (WAGYU)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 202.59.168.36 from natural-breast-active.com

Hi,

The IP 202.59.168.36 has just been banned by Fail2Ban after
2 attempts against SSH.


Here is more information about 202.59.168.36:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '202.59.160.0 - 202.59.175.255'

% Abuse contact for '202.59.160.0 - 202.59.175.255' is 'abuse@nap.net.id'

inetnum: 202.59.160.0 - 202.59.175.255
netname: NAPINFO
descr: PT. NAP Info Lintas Nusa
descr: NAP.Net.id - Network Access Point
country: ID
admin-c: HNIL1-AP
tech-c: GW8177-AP
mnt-by: MNT-APJII-ID
mnt-lower: MAINT-ID-NAPINFO
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: spam and abuse report : abuse@apjii.or.id, abuse@nap.net.id
status: ALLOCATED PORTABLE
mnt-irt: IRT-NAPNET-ID
last-modified: 2016-08-22T09:07:35Z
source: APNIC

irt: IRT-NAPNET-ID
address: PT. NAP Info Lintas Nusa
address: Suite 101 AB Annex Building, Plaza Kuningan
address: H.R. Rasuna Said, Kav. C 11-14.
address: Jakarta Selatan, DKI 12940
e-mail: abuse@nap.net.id
abuse-mailbox: abuse@nap.net.id
admin-c: HNIL1-AP
tech-c: HNIL1-AP
auth: # Filtered
mnt-by: MAINT-ID-NAPINFO
last-modified: 2016-08-22T09:12:06Z
source: APNIC

person: Gunawan Wicaksono
nic-hdl: GW8177-AP
e-mail: gunawan@nap.net.id
address: PT. NAP Info Lintas Nusa
address: Suite 101 AB Annex Building, Plaza Kuningan.
address: Jalan. H.R. Rasuna Said, Kav. C 11-14.
address: Jakarta Selatan, DKI 12940
phone: +62-(21)-252-8888
fax-no: +62-(21)-252-5555
country: ID
mnt-by: MAINT-ID-NAPINFO
last-modified: 2008-09-04T07:29:17Z
source: APNIC

person: hostmaster nap info lintas nusa
address: PT. NAP INFO LINTAS NUSA
country: ID
phone: +62-(21)-2528888
fax-no: +62-(21)-2525555
e-mail: hostmaster@nap.net.id
nic-hdl: HNIL1-AP
notify: hostmaster@nap.net.id
abuse-mailbox: hostmaster@nap.net.id
mnt-by: MAINT-ID-NAPINFO
last-modified: 2013-08-02T07:49:29Z
source: APNIC

% Information related to '202.59.168.0/24AS17727'

route: 202.59.168.0/24
descr: Route Object of NAP.Net.id - Network Access Point
origin: AS17727
mnt-by: MAINT-ID-NAPINFO
mnt-lower: MAINT-ID-NAPINFO
mnt-routes: MAINT-ID-NAPINFO
last-modified: 2015-10-20T10:39:14Z
source: APNIC

% Information related to '202.59.168.32 - 202.59.168.47'

inetnum: 202.59.168.32 - 202.59.168.47
netname: McDermott
descr: PT. McDermott Indonesia
country: ID
admin-c: SH144-AP
tech-c: GW8177-AP
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-ID-NAPINFO
last-modified: 2009-01-20T10:02:40Z
source: IDNIC

person: Gunawan Wicaksono
nic-hdl: GW8177-AP
e-mail: gunawan@nap.net.id
address: PT. NAP Info Lintas Nusa
address: Suite 101 AB Annex Building, Plaza Kuningan.
address: Jalan. H.R. Rasuna Said, Kav. C 11-14.
address: Jakarta Selatan, DKI 12940
phone: +62-(21)-252-8888
fax-no: +62-(21)-252-5555
country: ID
mnt-by: MAINT-ID-NAPINFO
last-modified: 2008-09-04T07:29:17Z
source: IDNIC

person: Sandi Gunawan Ho
nic-hdl: SH144-AP
e-mail: sandy@nap.net.id
address: PT. NAP Info Lintas Nusa
address: Suite 101 AB Annex Building, Plaza Kuningan
address: H.R. Rasuna Said, Kav. C 11-14.
address: Jakarta Selatan, DKI 12940
phone: +62-(21)-252-8888
fax-no: +62-(21)-252-5555
country: ID
mnt-by: MAINT-ID-INTER
last-modified: 2008-09-04T07:29:17Z
source: IDNIC

% Information related to '202.59.168.0/24AS17727'

route: 202.59.168.0/24
descr: Route Object of NAP.Net.id - Network Access Point
origin: AS17727
mnt-by: MAINT-ID-NAPINFO
mnt-lower: MAINT-ID-NAPINFO
mnt-routes: MAINT-ID-NAPINFO
last-modified: 2015-10-20T10:39:14Z
source: IDNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

Regards,

Fail2Ban