HideMyAss.com

Monday, 14 October 2013

[Fail2Ban] SSH: banned 50.197.191.93

Hi,

The IP 50.197.191.93 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 50.197.191.93:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 50.197.191.93"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=50.197.191.93?showDetails=true&showARIN=false&ext=netref2
#

Comcast Cable Communications Holdings, Inc CCCH3-4 (NET-50-128-0-0-1) 50.128.0.0 - 50.255.255.255
Comcast Business Communications, LLC CBC-SFBA-24 (NET-50-197-128-0-1) 50.197.128.0 - 50.197.191.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

Sunday, 13 October 2013

[Fail2Ban] SSH: banned 200.107.121.50

Hi,

The IP 200.107.121.50 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 200.107.121.50:

[Querying whois.lacnic.net]
[whois.lacnic.net]

% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries

% LACNIC resource: whois.lacnic.net


% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2013-10-13 23:42:05 (BRT -03:00)

inetnum: 200.107.120/21
status: allocated
aut-num: N/A
owner: SERCOM de Honduras
ownerid: HN-SEHO1-LACNIC
responsible: Marco Peña
address: Av. República de Colombia, --, Edificio Aló
address: -- - Tegucigalpa - FM
country: HN
phone: +708 504 2054486 []
owner-c: MAP16
tech-c: MAP16
abuse-c: MAP16
inetrev: 200.107.120/21
nserver: NS1.TURBONETT.COM.HN
nsstat: 20131012 AA
nslastaa: 20131012
nserver: NS2.TURBONETT.COM.HN
nsstat: 20131012 AA
nslastaa: 20131012
nserver: NS3.TURBONETT.COM.HN
nsstat: 20131012 NOT SYNC ZONE
nslastaa: 20130925
nserver: NS4.TURBONETT.COM.HN
nsstat: 20131012 NOT SYNC ZONE
nslastaa: 20130925
created: 20060905
changed: 20080729

nic-hdl: MAP16
person: Joel Silva
e-mail: joel.silva@CLARO.COM.HN
address: Col. San Carlos, Ave, Colombia Edificio Claro, 1,
address: 001 - Tegucigalpa - Mo
country: HN
phone: +708 504 22054458 [4458]
created: 20070821
changed: 20130902

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 180.96.71.228

Hi,

The IP 180.96.71.228 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 180.96.71.228:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '180.96.0.0 - 180.127.255.255'

inetnum: 180.96.0.0 - 180.127.255.255
netname: CHINANET-JS
descr: Chinanet Jiangsu Province Network
descr: China Telecom
descr: No.31,jingrong street
descr: Beijing 100032
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
remarks: service provider
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20090723
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-JS
source: APNIC

role: CHINANET JIANGSU
address: 260 Zhongyang Road,Nanjing 210037
country: CN
phone: +86-25-86588231
phone: +86-25-86588745
fax-no: +86-25-86588104
e-mail: ip@jsinfo.net
remarks: send anti-spam reports to spam@jsinfo.net
remarks: send abuse reports to abuse@jsinfo.net
remarks: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@jsinfo.net 20090831
changed: ip@jsinfo.net 20090831
changed: hm-changed@apnic.net 20090901
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 61.160.200.54

Hi,

The IP 61.160.200.54 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 61.160.200.54:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '61.160.0.0 - 61.160.255.255'

inetnum: 61.160.0.0 - 61.160.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINANET-JS
mnt-routes: maint-chinanet-js
changed: hostmaster@ns.chinanet.cn.net 20020209
changed: hostmaster@ns.chinanet.cn.net 20030306
status: ALLOCATED non-PORTABLE
source: APNIC

role: CHINANET JIANGSU
address: 260 Zhongyang Road,Nanjing 210037
country: CN
phone: +86-25-86588231
phone: +86-25-86588745
fax-no: +86-25-86588104
e-mail: ip@jsinfo.net
remarks: send anti-spam reports to spam@jsinfo.net
remarks: send abuse reports to abuse@jsinfo.net
remarks: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@jsinfo.net 20090831
changed: ip@jsinfo.net 20090831
changed: hm-changed@apnic.net 20090901
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

% Information related to '61.160.0.0/16AS23650'

route: 61.160.0.0/16
descr: CHINANET jiangsu province network
country: CN
origin: AS23650
mnt-by: MAINT-CHINANET-JS
changed: ip@jsinfo.net 20030414
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 173.193.188.83

Hi,

The IP 173.193.188.83 has just been banned by Fail2Ban after
6 attempts against SSH.


Here are more information about 173.193.188.83:

[Querying whois.arin.net]
[Redirected to rwhois.softlayer.com:4321]
[Querying rwhois.softlayer.com]
[rwhois.softlayer.com]
%rwhois V-1.5:003fff:00 rwhois.softlayer.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:NETBLK-SOFTLAYER.173.193.128.0/18
network:Auth-Area:173.193.128.0/18
network:Network-Name:SOFTLAYER-173.193.128.0
network:IP-Network:173.193.188.80/28
network:IP-Network-Block:173.193.188.80-173.193.188.95

network:Organization;I:IBM - SmartCloud Application Services - Internal Dev
network:Street-Address:IBM Building 136, Floor 10
network:City:Montreal
network:State:QC
network:Postal-Code:00000
network:Country-Code:CA
network:Tech-Contact;I:sysadmins@softlayer.com
network:Abuse-Contact;I:denisd@ca.ibm.com
network:Admin-Contact;I:IPADM258-ARIN
network:Created:2013-07-22 17:15:01
network:Updated:2013-09-26 08:52:56
network:Updated-By:ipadmin@softlayer.com

%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 188.212.106.74

Hi,

The IP 188.212.106.74 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 188.212.106.74:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '188.212.104.0 - 188.212.107.255'

% Abuse contact for '188.212.104.0 - 188.212.107.255' is 'abuse@ip.ro'

inetnum: 188.212.104.0 - 188.212.107.255
netname: SC-HOSTINGBIT-SRL
descr: SC HOSTINGBIT SRL
descr: B-dul Dacia Nr. 65 Bl. 18, Sc. 1, Ap. 3
descr: Craiova Dolj 200588
country: ro
admin-c: SDA185-RIPE
tech-c: SDA185-RIPE
status: ASSIGNED PA
remarks: Registered through http://www.ip.ro/ip.html
mnt-by: RO-MNT
mnt-lower: RO-MNT
mnt-routes: HOSTINGBIT-MNT
source: RIPE # Filtered

person: STAN DANIEL ALEXANDRU
address: HOSTINGBIT SRL
address: B-dul Dacia nr. 65 Bl. 18, Sc. 1, Ap. 3
address: Craiova Dolj Romania 200588
phone: +40-770852615
nic-hdl: SDA185-RIPE
mnt-by: HOSTINGBIT-MNT
source: RIPE # Filtered

% Information related to '188.212.104.0/22AS57773'

route: 188.212.104.0/22
descr: HOSTINGBIT SRL
remarks: http://toolz.ro
origin: AS57773
mnt-by: HOSTINGBIT-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 60.191.232.54

Hi,

The IP 60.191.232.54 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 60.191.232.54:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '60.191.232.0 - 60.191.232.127'

inetnum: 60.191.232.0 - 60.191.232.127
netname: JINHUA-TELECOM-COMPANY
country: CN
descr: Jinhua Telecom Company IDC Center
descr:
admin-c: LW1591-AP
tech-c: CJ54-AP
mnt-irt: IRT-CHINANET-ZJ
status: ASSIGNED NON-PORTABLE
changed: zjnoc_ip_5@163.com 20130617
mnt-by: MAINT-CN-CHINANET-ZJ-JH
source: APNIC

irt: IRT-CHINANET-ZJ
address: Hangzhou, 288 fucun Road, China
e-mail: lfliu@pubinfo.com.cn
abuse-mailbox: antispam@dcb.hz.zj.cn
admin-c: CZ61-AP
tech-c: CZ61-AP
auth: # Filtered
mnt-by: MAINT-CHINANET-ZJ
changed: auto-dbm@dcb.hz.zj.cn 20101129
source: APNIC

role: CHINANET-ZJ Jinhua
address: No.155 Xishi street,Jinhua,Zhejiang.321000
country: CN
phone: +86-579-2300779
fax-no: +86-579-2330035
e-mail: anti_spam@mail.jhptt.zj.cn
remarks: send spam reports to anti_spam@mail.jhptt.zj.cn
remarks: and abuse reports to anti_spam@mail.jhptt.zj.cn
remarks: Please include detailed information and times in UTC
admin-c: CH55-AP
tech-c: CH55-AP
nic-hdl: CJ54-AP
mnt-by: MAINT-CHINANET-ZJ
changed: master@dcb.hz.zj.cn 20031204
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Lujiang Wang
nic-hdl: LW1591-AP
e-mail: anti_spam@mail.jhptt.zj.cn
address: NO.155 Xishi Street,Jinhua,Zhejiang.Postcode:321000
phone: +86-15305790379
country: CN
changed: zjnoc_ip_4@163.com 20130617
mnt-by: MAINT-CN-CHINANET-ZJ-JH
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 58.211.82.197

Hi,

The IP 58.211.82.197 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 58.211.82.197:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '58.208.0.0 - 58.223.255.255'

inetnum: 58.208.0.0 - 58.223.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-JS
mnt-routes: MAINT-CHINANET-JS
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
status: ALLOCATED PORTABLE
changed: hm-changed@apnic.net 20050624
source: APNIC

role: CHINANET JIANGSU
address: 260 Zhongyang Road,Nanjing 210037
country: CN
phone: +86-25-86588231
phone: +86-25-86588745
fax-no: +86-25-86588104
e-mail: ip@jsinfo.net
remarks: send anti-spam reports to spam@jsinfo.net
remarks: send abuse reports to abuse@jsinfo.net
remarks: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@jsinfo.net 20090831
changed: ip@jsinfo.net 20090831
changed: hm-changed@apnic.net 20090901
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 71.9.44.11

Hi,

The IP 71.9.44.11 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 71.9.44.11:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 71.9.44.11"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=71.9.44.11?showDetails=true&showARIN=false&ext=netref2
#

Charter Communications CC04 (NET-71-8-0-0-1) 71.8.0.0 - 71.15.255.255
Charter Communications MNT-CA-71-9-32 (NET-71-9-32-0-1) 71.9.32.0 - 71.9.47.255
STARLOGIC ONLINE STAR-71-9-44-0 (NET-71-9-44-0-1) 71.9.44.0 - 71.9.44.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 94.23.176.59

Hi,

The IP 94.23.176.59 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 94.23.176.59:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '94.23.176.32 - 94.23.176.63'

inetnum: 94.23.176.32 - 94.23.176.63
netname: OVH-PCC-646
descr: PrivateCloud id 646
country: FR
admin-c: OTC2-RIPE
tech-c: OTC2-RIPE
status: ASSIGNED PA
mnt-by: OVH-MNT
source: RIPE # Filtered

role: OVH Technical Contact
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
admin-c: OK217-RIPE
tech-c: GM84-RIPE
nic-hdl: OTC2-RIPE
abuse-mailbox: abuse@ovh.net
mnt-by: OVH-MNT
source: RIPE # Filtered

% Information related to '94.23.0.0/16AS16276'

route: 94.23.0.0/16
descr: OVH ISP
descr: Paris, France
origin: AS16276
mnt-by: OVH-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 66.175.221.151

Hi,

The IP 66.175.221.151 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 66.175.221.151:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 66.175.221.151"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=66.175.221.151?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 66.175.208.0 - 66.175.223.255
CIDR: 66.175.208.0/20
OriginAS:
NetName: LINODE-US
NetHandle: NET-66-175-208-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
Comment: This block is used for static customer allocations.
RegDate: 2012-06-25
Updated: 2012-06-26
Ref: http://whois.arin.net/rest/net/NET-66-175-208-0-1

OrgName: Linode
OrgId: LINOD
Address: 329 E. Jimmie Leeds Road
Address: Suite A
City: Galloway
StateProv: NJ
PostalCode: 08205
Country: US
RegDate: 2008-04-24
Updated: 2010-08-31
Comment: http://www.linode.com
Ref: http://whois.arin.net/rest/org/LINOD

OrgAbuseHandle: LAS12-ARIN
OrgAbuseName: Linode Abuse Support
OrgAbusePhone: +1-609-593-7103
OrgAbuseEmail: abuse@linode.com
OrgAbuseRef: http://whois.arin.net/rest/poc/LAS12-ARIN

OrgTechHandle: LNO21-ARIN
OrgTechName: Linode Network Operations
OrgTechPhone: +1-609-593-7103
OrgTechEmail: support@linode.com
OrgTechRef: http://whois.arin.net/rest/poc/LNO21-ARIN

OrgNOCHandle: LNO21-ARIN
OrgNOCName: Linode Network Operations
OrgNOCPhone: +1-609-593-7103
OrgNOCEmail: support@linode.com
OrgNOCRef: http://whois.arin.net/rest/poc/LNO21-ARIN

RNOCHandle: LNO21-ARIN
RNOCName: Linode Network Operations
RNOCPhone: +1-609-593-7103
RNOCEmail: support@linode.com
RNOCRef: http://whois.arin.net/rest/poc/LNO21-ARIN

RTechHandle: LNO21-ARIN
RTechName: Linode Network Operations
RTechPhone: +1-609-593-7103
RTechEmail: support@linode.com
RTechRef: http://whois.arin.net/rest/poc/LNO21-ARIN

RAbuseHandle: LAS12-ARIN
RAbuseName: Linode Abuse Support
RAbusePhone: +1-609-593-7103
RAbuseEmail: abuse@linode.com
RAbuseRef: http://whois.arin.net/rest/poc/LAS12-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 58.17.36.115

Hi,

The IP 58.17.36.115 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 58.17.36.115:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '58.17.36.0 - 58.17.37.255'

inetnum: 58.17.36.0 - 58.17.37.255
netname: SHLIANSE-COM
country: CN
descr: ShangHai Shelian commpany
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

person: CNCGroup Hostmaster
nic-hdl: CH444-AP
e-mail: abuse@cnc-noc.net
address: No.156,Fu-Xing-Men-Nei Street,
address: Beijing,100031,P.R.China
phone: +86-10-82993155
fax-no: +86-10-82993144
country: CN
changed: abuse@cnc-noc.net 20041220
mnt-by: MAINT-CNCGROUP
source: APNIC

% Information related to '58.17.0.0/17AS4837'

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

% Information related to '58.17.0.0/17AS9929'

route: 58.17.0.0/17
descr: CNCGroup JiangXi province network
country: CN
origin: AS9929
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20050218
changed: hm-changed@apnic.net 20050331
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 58.97.254.52

Hi,

The IP 58.97.254.52 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 58.97.254.52:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '58.97.128.0 - 58.97.255.255'

inetnum: 58.97.128.0 - 58.97.255.255
netname: BANGLALION-WIMAX-BD
descr: Silver Tower (16 & 18th Floor)
country: BD
admin-c: BCLn1-AP
tech-c: BCLn1-AP
status: ALLOCATED PORTABLE
remarks: Used for WiMAX
mnt-by: APNIC-HM
mnt-lower: MAINT-BANGLALION-WIMAX-BD
mnt-routes: MAINT-BANGLALION-WIMAX-BD
mnt-irt: IRT-BANGLALION-WIMAX-BD
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20110107
source: APNIC

irt: IRT-BANGLALION-WIMAX-BD
address: Silver Tower (16 & 18th Floor)
address: 52 Gulshan Avenue, Gulshan-1
address: Dhaka-1212
address: Bangladesh
e-mail: abuse-report@banglalionwimax.com
abuse-mailbox: abuse-report@banglalionwimax.com
admin-c: BCLn1-AP
tech-c: BCLn1-AP
auth: # Filtered
mnt-by: MAINT-BANGLALION-WIMAX-BD
changed: abuse-report@banglalionwimax.com 20101202
source: APNIC

role: BANGLALION COMMUNICATIONS LTD - network administr
address: Silver Tower (16 & 18th Floor), 52 Gulshan Avenue, Gulshan, Dhaka-1212. Bangladesh.
country: BD
phone: +88028816349
fax-no: +8802-9885647
e-mail: azhar.chowdhury@banglalionwimax.com
admin-c: BCLn1-AP
tech-c: AHC2-AP
nic-hdl: BCLn1-AP
mnt-by: MAINT-BANGLALION-WIMAX-BD
changed: hm-changed@apnic.net 20090831
source: APNIC
changed: hm-changed@apnic.net 20100825

% Information related to '58.97.128.0/17AS45904'

route: 58.97.128.0/17
descr: Route Object for 58.97.128.0.0/17
origin: AS45904
country: BD
remarks: New /17 block of Banglalion WiMAX
mnt-lower: MAINT-BANGLALION-WIMAX-BD
mnt-routes: MAINT-BANGLALION-WIMAX-BD
mnt-by: MAINT-BANGLALION-WIMAX-BD
changed: hm-changed@apnic.net 20110117
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS2)

Regards,

Fail2Ban

Saturday, 12 October 2013

[Fail2Ban] SSH: banned 211.141.34.111

Hi,

The IP 211.141.34.111 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 211.141.34.111:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '211.141.0.0 - 211.141.79.255'

inetnum: 211.141.0.0 - 211.141.79.255
netname: CMNET-jilin
descr: China Mobile Communications Corporation - jilin company
country: CN
admin-c: CH350-AP
tech-c: CH350-AP
mnt-by: MAINT-CN-CMCC
mnt-lower: MAINT-CN-CMCC-jilin
remarks: ------------------------------
remarks: Please send abuse e-mail to
remarks: huangchenwei@jl.chinamobilecom
remarks: Please send probe e-mail to
remarks: huangchenwei@jl.chinamobilecom
remarks: -------------------------------
changed: weichenguang@chinamobile.com 20040629
status: ALLOCATED NON-PORTABLE
source: APNIC

person: chenwei huang
nic-hdl: CH350-AP
e-mail: huangchenwei@jl.chinamobile.com
address: Liberation Road No.2899, Changchun,China,130061
phone: +86-0431-8980146
fax-no: +86-13578641267
country: cn
changed: huangchenwei@jl.chinamobile.com 20040806
mnt-by: MAINT-CN-CMCC-JILIN
source: APNIC

% Information related to '211.140.0.0/15AS9808'

route: 211.140.0.0/15
descr: China Mobile communications corporation
origin: AS9808
mnt-by: MAINT-CN-CMCC
changed: hostmaster@chinamobile.com 20120215
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS4)

Regards,

Fail2Ban

Friday, 11 October 2013

[Fail2Ban] SSH: banned 110.172.52.37

Hi,

The IP 110.172.52.37 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 110.172.52.37:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '110.172.52.0 - 110.172.55.255'

inetnum: 110.172.52.0 - 110.172.55.255
netname: WISHNET-IN
descr: 86, GOLAGHATA ROAD
country: IN
admin-c: AP284-AP
tech-c: AP284-AP
status: ALLOCATED PORTABLE
remarks: Used for broadband
mnt-by: APNIC-HM
mnt-lower: MAINT-WISHNET-IN
mnt-routes: MAINT-WISHNET-IN
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
mnt-irt: IRT-WISHNET-IN
changed: hm-changed@apnic.net 20090506
source: APNIC

irt: IRT-WISHNET-IN
address: 86,GOLAGHATA ROAD,JAMUNA APARTMENTS,GROUND FLOOR, KOLKATA 700048
e-mail: abuse-wishnet@wishnet.co.in
abuse-mailbox: abuse-wishnet@wishnet.co.in
admin-c: AP284-AP
tech-c: AP284-AP
auth: # Filtered
mnt-by: MAINT-WISHNET-IN
changed: abhishek.pal@wishnet.co.in 20110704
source: APNIC

role: ABHISHEK PAL
address: 86,GOLAGHATA ROAD, KOLKATA 700048
country: IN
phone: +91-033-2534 0326
fax-no: +91-033-2534 0343
e-mail: abuse-wishnet@wishnet.co.in
admin-c: AP284-AP
tech-c: AP284-AP
nic-hdl: AP284-AP
mnt-by: MAINT-WISHNET-IN
changed: hm-changed@apnic.net 20090506
changed: hm-changed@apnic.net 20090506
source: APNIC

% Information related to '110.172.52.0/22AS45775'

route: 110.172.52.0/22
descr: WISH NET - Broadband ISP, India
origin: AS45775
country: IN
notify: abuse-wishnet@wishnet.co.in
mnt-routes: MAINT-WISHNET-IN
mnt-by: MAINT-WISHNET-IN
changed: hm-changed@apnic.net 20100802
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 137.117.99.38

Hi,

The IP 137.117.99.38 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 137.117.99.38:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 137.117.99.38"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=137.117.99.38?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 137.117.0.0 - 137.117.255.255
CIDR: 137.117.0.0/16
OriginAS:
NetName: MICROSOFT
NetHandle: NET-137-117-0-0-1
Parent: NET-137-0-0-0-0
NetType: Direct Assignment
RegDate: 2011-08-02
Updated: 2013-08-20
Ref: http://whois.arin.net/rest/net/NET-137-117-0-0-1

OrgName: Microsoft Corp
OrgId: MSFT-Z
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US
RegDate: 2011-06-22
Updated: 2013-10-03
Comment: To report suspected security issues specific to
Comment: traffic emanating from Microsoft online services,
Comment: including the distribution of malicious content
Comment: or other illicit or illegal material through a
Comment: Microsoft online service, please submit reports
Comment: to:
Comment: * https://cert.microsoft.com.
Comment:
Comment: For SPAM and other abuse issues, such as Microsoft
Comment: Accounts, please contact:
Comment: * abuse@microsoft.com.
Comment:
Comment: To report security vulnerabilities in Microsoft
Comment: products and services, please contact:
Comment: * secure@microsoft.com.
Comment:
Comment: For legal and law enforcement-related requests,
Comment: please contact:
Comment: * msndcc@microsoft.com
Comment:
Comment: For routing, peering or DNS issues, please
Comment: contact:
Comment: * IOC@microsoft.com
Ref: http://whois.arin.net/rest/org/MSFT-Z

OrgAbuseHandle: MAC74-ARIN
OrgAbuseName: Microsoft Abuse Contact
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@microsoft.com
OrgAbuseRef: http://whois.arin.net/rest/poc/MAC74-ARIN

OrgTechHandle: MRPD-ARIN
OrgTechName: Microsoft Routing, Peering, and DNS
OrgTechPhone: +1-425-882-8080
OrgTechEmail: IOC@microsoft.com
OrgTechRef: http://whois.arin.net/rest/poc/MRPD-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 108.171.219.55

Hi,

The IP 108.171.219.55 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 108.171.219.55:

[Querying whois.arin.net]
[Redirected to clients.webnx.com:4321]
[Querying clients.webnx.com]
[clients.webnx.com]
%rwhois V-1.0,V-1.5:00090h:00 clients.webnx.com (Ubersmith RWhois Server V-2.3.0)
autharea=108.171.192.0/19
xautharea=108.171.192.0/19
network:Class-Name:network
network:Auth-Area:108.171.192.0/19
network:ID:NET-3224.108.171.219.32/27
network:Network-Name:108.171.219.33/27
network:IP-Network:108.171.219.32/27
network:IP-Network-Block:108.171.219.32
- 108.171.219.63
network:Org-Name:China Regional LLC Corp.
network:Street-Address:
network:City:
network:State:
network:Postal-Code:
network:Country-Code:US
network:Tech-Contact:MAINT-3224.108.171.219.32/27
network:Created:20120503093040000
network:Updated:20130604190858000
network:Updated-By:abuse@webnx.com
contact:POC-Name:WebNX Inc.
contact:POC-Email:abuse@webnx.com
contact:POC-Phone:800.840.5996 x3
contact:Tech-Name:WebNX Inc.
contact:Tech-Email:abuse@webnx.com
contact:Tech-Phone:800.840.5996 x3
contact:Abuse-Name:Abuse Department
contact:Abuse-Email:abuse@webnx.com
%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 198.136.59.143

Hi,

The IP 198.136.59.143 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 198.136.59.143:

[Querying whois.arin.net]
[Redirected to rwhois.dimenoc.com:4321]
[Querying rwhois.dimenoc.com]
[rwhois.dimenoc.com]
%rwhois V-1.5:0000a0:00 rwhois.dimenoc.com (by HostDime.com, Inc. v0.1)
network:id:DIMENOC-289008
network:ip-network:198.136.59.136/29
network:network-name:DIMENOC-289008
network:org-name:LoveVPS
network:street-address:440 West Kennedy Blvd Suite #1
network:city:Orlando
network:state:FL
network:postal-code:32810
network:country-code:US
network:tech-contact:abuse@lovevps.com
network:updated:2013-10-11 16:33:38
network:updated-by:network@dimenoc.com

%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 5.178.66.189

Hi,

The IP 5.178.66.189 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 5.178.66.189:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '5.178.66.160 - 5.178.66.191'

% Abuse contact for '5.178.66.160 - 5.178.66.191' is 'abuse@serverius.nl'

inetnum: 5.178.66.160 - 5.178.66.191
netname: CUST914
descr: Customer IP range
remarks: Please send email to "abuse@serverius.com" for complaints
remarks: regarding portscans, DoS attacks and spam.
country: NL
admin-c: GVG18-RIPE
tech-c: GVG18-RIPE
status: ASSIGNED PA
mnt-by: serverius-mnt
source: RIPE # Filtered

person: Gijs van Gemert
address: www.serverius.com
address: De Linge 26
address: 8253 PJ Dronten
address: The Netherlands
phone: +31 (0)88 73 78 374
nic-hdl: GVG18-RIPE
abuse-mailbox: abuse@serverius.com
remarks: Contact for customer IP space ranges
remarks: Please send email to "abuse@serverius.com" for complaints
remarks: regarding portscans, DoS attacks and spam.
mnt-by: SERVERIUS-MNT
source: RIPE # Filtered

% Information related to '5.178.64.0/21AS50673'

route: 5.178.64.0/21
descr: Serverius Route Object
origin: AS50673
mnt-by: SERVERIUS-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS2)

Regards,

Fail2Ban

Thursday, 10 October 2013

[Fail2Ban] SSH: banned 212.92.216.131

Hi,

The IP 212.92.216.131 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 212.92.216.131:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '212.92.192.0 - 212.92.223.255'

% Abuse contact for '212.92.192.0 - 212.92.223.255' is 'abuse@metronet.hr'

inetnum: 212.92.192.0 - 212.92.223.255
netname: HR-METRONET-20080827
descr: Metronet telekomunikacije d.d.
country: HR
org: ORG-Mtd1-RIPE
admin-c: Mc14212-RIPE
tech-c: Mc14212-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-lower: METRONET
mnt-routes: METRONET
source: RIPE # Filtered

organisation: ORG-Mtd1-RIPE
org-name: Metronet telekomunikacije d.d.
org-type: LIR
address: Metronet telekomunikacije d.d.
address: Ulica grada Vukovara 269d
address: 10000 Zagreb
address: CROATIA
phone: +38516327000
fax-no: +38516327011
mnt-ref: METRONET
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
admin-c: VK1159-RIPE
admin-c: TM2641-RIPE
admin-c: DK812-RIPE
admin-c: NV1519-RIPE
admin-c: BK1882-RIPE
abuse-c: MTDD-RIPE
source: RIPE # Filtered

role: Metronet contact
address: Metronet telekomunikacije d.d.
address: Ulica grada Vukovara 269d
address: 10000 Zagreb
address: Croatia
phone: +385 1 6327 077
fax-no: +385 1 6327 095
remarks: trouble: ******************************
remarks: trouble: * In case of abuse please *
remarks: trouble: * contact: abuse@metronet.hr *
remarks: trouble: ******************************
admin-c: NV1519-RIPE
admin-c: TM2641-RIPE
admin-c: VK1159-RIPE
tech-c: BK1882-RIPE
tech-c: DK812-RIPE
nic-hdl: Mc14212-RIPE
mnt-by: METRONET
source: RIPE # Filtered
abuse-mailbox: abuse@metronet.hr

% Information related to '212.92.192.0/19AS35549'

route: 212.92.192.0/19
descr: METRONET
origin: AS35549
mnt-by: METRONET
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 61.155.177.58

Hi,

The IP 61.155.177.58 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 61.155.177.58:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '61.155.0.0 - 61.155.255.255'

inetnum: 61.155.0.0 - 61.155.255.255
netname: CHINANET-JS
descr: CHINANET jiangsu province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: CJ186-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINANET-JS
mnt-routes: maint-chinanet-js
changed: hostmaster@ns.chinanet.cn.net 20020209
changed: hostmaster@ns.chinanet.cn.net 20030306
status: ALLOCATED non-PORTABLE
source: APNIC

role: CHINANET JIANGSU
address: 260 Zhongyang Road,Nanjing 210037
country: CN
phone: +86-25-86588231
phone: +86-25-86588745
fax-no: +86-25-86588104
e-mail: ip@jsinfo.net
remarks: send anti-spam reports to spam@jsinfo.net
remarks: send abuse reports to abuse@jsinfo.net
remarks: times in GMT+8
admin-c: CH360-AP
tech-c: CS306-AP
tech-c: CN142-AP
nic-hdl: CJ186-AP
remarks: www.jsinfo.net
notify: ip@jsinfo.net
mnt-by: MAINT-CHINANET-JS
changed: dns@jsinfo.net 20090831
changed: ip@jsinfo.net 20090831
changed: hm-changed@apnic.net 20090901
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

% Information related to '61.155.0.0/16AS23650'

route: 61.155.0.0/16
descr: CHINANET jiangsu province network
country: CN
origin: AS23650
mnt-by: MAINT-CHINANET-JS
changed: ip@jsinfo.net 20030414
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 211.103.11.244

Hi,

The IP 211.103.11.244 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 211.103.11.244:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '211.103.0.0 - 211.103.127.255'

inetnum: 211.103.0.0 - 211.103.127.255
netname: CMNET
descr: China Mobile Communications Corporation
descr: Mobile Communications Network Operator in China
descr: Internet Service Provider in China
country: CN
admin-c: JS686-AP
tech-c: CT74-AP
status: ALLOCATED PORTABLE
mnt-by: APNIC-HM
mnt-lower: MAINT-CN-CMCC
mnt-routes: MAINT-CN-CMCC
remarks: Transfer form CNNIC
changed: ipas@cnnic.net.cn 20031121
changed: hm-changed@apnic.net 20050513
changed: hm-changed@apnic.net 20050812
source: APNIC

role: chinamobile tech
address: 29, Jinrong Ave.,Xicheng district
address: Beijing
country: CN
phone: +86 6600 6688
fax-no: +86 6600 6187
e-mail: hostmaster@chinamobile.com
remarks: send spam reports to spam@chinamobile.com
remarks: and abuse reports to abuse@chinamobile.com
remarks: Please include detailed information and
remarks: times in UTC
admin-c: HL1318-AP
tech-c: JS686-AP
nic-hdl: ct74-AP
notify: hostmaster@chinamobile.com
mnt-by: MAINT-cn-cmcc
changed: hostmaster@chinamobile.com 20091019
source: APNIC

person: Jinxia Sun
address: China Mobile Communications Corporation
address: 29, Jinrong Ave., Xicheng District, Beijing, 100032
country: CN
phone: +86-10-66006688-1755
fax-no: +86-10-66006012
e-mail: sunjinxia@chinamobile.com
nic-hdl: JS686-AP
remarks: ------------------------------
remarks: Please send abuse e-mail to
remarks: abuse@chinamobile.com
remarks: Please send probe e-mail to
remarks: security@chinamobile.com
remarks: -------------------------------
mnt-by: MAINT-CN-CMCC
changed: hostmaster@chinamobile.com 20030130
source: APNIC

% Information related to '211.103.0.0/17AS9808'

route: 211.103.0.0/17
descr: China Mobile communications corporation
origin: AS9808
mnt-by: MAINT-CN-CMCC
changed: hostmaster@chinamobile.com 20120215
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 112.111.142.170

Hi,

The IP 112.111.142.170 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 112.111.142.170:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '112.111.142.169 - 112.111.142.176'

inetnum: 112.111.142.169 - 112.111.142.176
netname: CNC-FJLY-longjingxiaoqu-CORP
country: CN
descr: longjingxiaoqu-CORP
admin-c: LY987-AP
tech-c: LY987-AP
status: ASSIGNED NON-PORTABLE
changed: laibn1@chinaunicom.cn 20091207
mnt-by: MAINT-CN-LY28
source: APNIC

person: LONG YAN
nic-hdl: LY987-AP
e-mail: laibn1@chinaunicom.cn
address: Longyan city, Fujian province, China
phone: +86-597-5250000
fax-no: +86-597-5250000
country: cn
changed: chenmin_deletethispart_@chinaunicom.cn 20091106
mnt-by: MAINT-CNCGROUP-FJ
source: APNIC

% Information related to '112.111.0.0/16AS4837'

route: 112.111.0.0/16
descr: China Unicom CHINA169 Fujian Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20090119
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

Wednesday, 9 October 2013

[Fail2Ban] SSH: banned 216.155.147.121

Hi,

The IP 216.155.147.121 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 216.155.147.121:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 216.155.147.121"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=216.155.147.121?showDetails=true&showARIN=false&ext=netref2
#

ISS Ltd NET-216-155-147-64-26 (NET-216-155-147-64-1) 216.155.147.64 - 216.155.147.127
Choopa, LLC CHOOPA-NETBLK04 (NET-216-155-128-0-1) 216.155.128.0 - 216.155.159.255



#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 59.37.66.139

Hi,

The IP 59.37.66.139 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 59.37.66.139:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '59.32.0.0 - 59.42.255.255'

inetnum: 59.32.0.0 - 59.42.255.255
netname: CHINANET-GD
descr: CHINANET Guangdong province network
descr: China Telecom
descr: No.31,jingrong street
descr: Beijing 100032
country: CN
admin-c: CH93-AP
tech-c: IC83-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-GD
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20040802
changed: hm-changed@apnic.net 20041123
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

person: IPMASTER CHINANET-GD
nic-hdl: IC83-AP
e-mail: ipadm@189.cn
address: NO.1,RO.DONGYUANHENG,YUEXIUNAN,GUANGZHOU
phone: +86-20-83877223
fax-no: +86-20-83877223
country: CN
changed: ipadm@189.cn 20110418
mnt-by: MAINT-CHINANET-GD
remarks: IPMASTER is not for spam complaint,please send spam complaint to abuse_gdnoc@189.cn
abuse-mailbox: abuse_gdnoc@189.cn
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

Tuesday, 8 October 2013

[Fail2Ban] SSH: banned 222.73.218.113

Hi,

The IP 222.73.218.113 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 222.73.218.113:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '222.64.0.0 - 222.73.255.255'

inetnum: 222.64.0.0 - 222.73.255.255
netname: CHINANET-SH
descr: CHINANET shanghai province network
descr: China Telecom
descr: No1,jin-rong Street
descr: Beijing 100032
country: CN
admin-c: CH93-AP
tech-c: XI5-AP
changed: hm-changed@apnic.net 20031024
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-SH
mnt-routes: MAINT-CHINANET-SH
remarks: This object can only modify by APNIC hostmaster
remarks: If you wish to modify this object details please
remarks: send email to hostmaster@apnic.net with your
remarks: organisation account name in the subject line.
status: ALLOCATED PORTABLE
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

person: Wu Xiao Li
address: Room 805,61 North Si Chuan Road,Shanghai,200085,PRC
country: CN
phone: +86-21-63630562
fax-no: +86-21-63630566
e-mail: ip-admin@mail.online.sh.cn
nic-hdl: XI5-AP
mnt-by: MAINT-CHINANET-SH
changed: ip-admin@mail.online.sh.cn 20010510
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 36.39.246.121

Hi,

The IP 36.39.246.121 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 36.39.246.121:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[Redirected to whois.nic.or.kr]
[Querying whois.nic.or.kr]
[whois.nic.or.kr]
query : 36.39.246.121


# KOREAN(UTF8)

조회하ì&lsqauo;  IPv4주소ëŠ" 한국인터넷진흥원으로부터 아래의 관리대행자에게 í• ë&lsqauo;¹ë˜ì—ˆìœ¼ë©°, í• ë&lsqauo;¹ ì •ë³´ëŠ" ë&lsqauo;¤ìŒê³¼ 같습ë&lsqauo;ˆë&lsqauo;¤.

[ 네트워크 í• ë&lsqauo;¹ ì •ë³´ ]
IPv4주소 : 36.38.0.0 - 36.39.255.255 (/15)
서비스명 : CJ-HELLOVISION
기관명 : 주ì&lsqauo;íšŒì‚¬ ì"¨ì œì´í—¬ë¡œë¹„ì „
기관고유번호 : ORG809949
주소 : 서울 ì–'천구 ì&lsqauo; ì •ë™ 1254
우편번호 : 158-070
í• ë&lsqauo;¹ì¼ìž : 20110210

[ IPv4주소 책임자 정보 ]
이름 : 김창선
ì „í™"번호 : +82-2-2600-2941
전자우편 : leo4u@cj.net

[ IPv4주소 ë&lsqauo;´ë&lsqauo;¹ìž ì •ë³´ ]
이름 : 김창선
ì „í™"번호 : +82-70-8130-1751
전자우편 : leo4u@cj.net

[ 스팸 해킹 ë&lsqauo;´ë&lsqauo;¹ìž ì •ë³´ ]
이름 : 김창선
ì „í™"번호 : +82-70-8130-2212
전자우편 : leo4u@cj.net

--------------------------------------------------------------------------------

조회하ì&lsqauo;  IPv4주소에 대한 위 관리대행자의 사용자 í• ë&lsqauo;¹ì •ë³´ê°€ 존재하지 않습ë&lsqauo;ˆë&lsqauo;¤.


# ENGLISH

KRNIC is not an ISP but a National Internet Registry similar to APNIC.

[ Network Information ]
IPv4 Address : 36.38.0.0 - 36.39.255.255 (/15)
Service Name : CJ-HELLOVISION
Organization Name : CJ-HELLOVISION
Organization ID : ORG809949
Address : 1254, Sinjeong-dong Yangcheon-gu Seoul
Zip Code : 158-070
Registration Date : 20110210

[ Admin Contact Information ]
Name : Kim chang sun
Phone : +82-2-2600-2941
E-Mail : leo4u@cj.net

[ Tech Contact Information ]
Name : Kim chang sun
Phone : +82-70-8130-1751
E-Mail : leo4u@cj.net

[ Network Abuse Contact Information ]
Name : YOUNGCHAN LEE
Phone : +82-70-8130-2212
E-Mail : leo4u@cj.net


- KISA/KRNIC Whois Service -

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 211.152.52.50

Hi,

The IP 211.152.52.50 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 211.152.52.50:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '211.152.32.0 - 211.152.63.255'

inetnum: 211.152.32.0 - 211.152.63.255
netname: SH-21VIANET
descr: 21vianet (shanghai), Inc.
descr: 129 Yan An Rd(W.) Shanghai, China
country: CN
admin-c: XL442-AP
tech-c: YZ2222-AP
mnt-by: MAINT-CNNIC-AP
mnt-lower: MAINT-CNNIC-AP
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
changed: ipas@cnnic.cn 20090927
source: APNIC

person: Xiaoqiu Liu
nic-hdl: XL442-AP
e-mail: liu.xiaoqiu@21vianet.com.cn
address: 129 Yan An Rd(W.) Shanghai, China
phone: +86-021-62498848
fax-no: +86-021-62499901
country: CN
changed: ipas@cnnic.net.cn 20090927
mnt-by: MAINT-CNNIC-AP
source: APNIC

person: Yu Zhou
nic-hdl: YZ2222-AP
e-mail: zhou.yu@21vianet.com.cn
address: 129 Yan An Rd(W.) Shanghai, China
phone: +86-021-62499933-5199
fax-no: +86-021-62499901
country: CN
changed: ipas@cnnic.net.cn 20090927
mnt-by: MAINT-CNNIC-AP
source: APNIC

% This query was served by the APNIC Whois Service version 1.68.5 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 212.234.66.108

Hi,

The IP 212.234.66.108 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 212.234.66.108:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '212.234.66.0 - 212.234.66.127'

% Abuse contact for '212.234.66.0 - 212.234.66.127' is 'gestionip.ft@orange.com'

inetnum: 212.234.66.0 - 212.234.66.127
netname: FR-ONLINE-FORMAPRO
country: FR
descr: OBS Customer
admin-c: MG11632-RIPE
tech-c: MG11632-RIPE
status: ASSIGNED PA
mnt-by: PC80199-MNT
source: RIPE # Filtered

person: Michele GUERRIN
address: ONLINE FORMAPRO
address: ESPACE DE LA MOTTE
address: 70000 VESOUL
phone: +33 3 84 76 92 44
fax-no: +33 3 84 75 09 57
nic-hdl: MG11632-RIPE
mnt-by: RAIN-TRANSPAC
source: RIPE # Filtered

% Information related to '212.234.0.0/16AS3215'

route: 212.234.0.0/16
descr: RAIN
descr: Reseaux d'Acces a l'INternet
remarks: -------------------------------------------
remarks: For Hacking, Spamming or Security problems
remarks: send mail to abuse@orange-business.com
remarks: -------------------------------------------
origin: AS3215
mnt-by: RAIN-TRANSPAC
org: ORG-OBS3-RIPE
source: RIPE # Filtered

organisation: ORG-OBS3-RIPE
org-name: Orange Business Services
org-type: Other
address: 6 avenue Albert Durand
address: 31700 Blagnac France
remarks: **************************************
remarks: * Pour les obligations legale *
remarks: * Contacter uniquement les poles OL *
remarks: * de France Telecom/Orange *
remarks: * *
remarks: * For legal issus joint only *
remarks: * France telecom/orange legal team *
remarks: **************************************
abuse-mailbox: abuse@orange-business.com
admin-c: AA2914-RIPE
tech-c: AA2914-RIPE
abuse-c: AA2914-RIPE
mnt-ref: OLEANE-NOC
mnt-ref: FT-BRX
mnt-ref: RAIN-TRANSPAC
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RAIN-TRANSPAC
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS3)

Regards,

Fail2Ban

Monday, 7 October 2013

[Fail2Ban] SSH: banned 188.190.98.6

Hi,

The IP 188.190.98.6 has just been banned by Fail2Ban after
6 attempts against SSH.


Here are more information about 188.190.98.6:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '188.190.96.0 - 188.190.127.255'

inetnum: 188.190.96.0 - 188.190.127.255
netname: INFIUM
descr: Infium LTD
descr: Datacenter Kharkov
country: UA
org: ORG-INFI1-RIPE
admin-c: INF20-RIPE
tech-c: INF20-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-lower: RIPE-NCC-END-MNT
mnt-by: INFIUM-MNT
mnt-routes: INFIUM-MNT
mnt-domains: INFIUM-MNT
source: RIPE # Filtered

organisation: ORG-INFI1-RIPE
org-name: Infium Ltd.
descr: Datacenter in Ukraine, Kharkov
org-type: OTHER
address: 61129, Ukraine, Kharkov
address: Traktorostroiteley 156/41 ave, office 301
phone: +380-931-700-701
abuse-mailbox: abusemail@infiumhost.com
remarks:
remarks: *************************************************
remarks: * For spam/abuse/security issues please contact *
remarks: * abusemail@infiumhost.com, not this address *
remarks: *************************************************
remarks:
mnt-ref: INFIUM-MNT
mnt-by: INFIUM-MNT
source: RIPE # Filtered

person: Infium Ltd
address: 61129, Kharkov, Ukraine
address: Traktorostroiteley 156/41, office 301
phone: +380-931-700-701
abuse-mailbox: abusemail@infiumhost.com
remarks:
remarks: *************************************************
remarks: * For spam/abuse/security issues please contact *
remarks: * abusemail@infiumhost.com, not this address *
remarks: *************************************************
remarks:
nic-hdl: INF20-RIPE
mnt-by: INFIUM-MNT
source: RIPE # Filtered

% Information related to '188.190.98.0/24AS197145'

route: 188.190.98.0/24
descr: Infium LTD
origin: AS197145
mnt-by: INFIUM-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.69 (WHOIS1)

Regards,

Fail2Ban