HideMyAss.com

Friday, 22 November 2013

[Fail2Ban] SSH: banned 175.198.158.210

Hi,

The IP 175.198.158.210 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 175.198.158.210:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[Redirected to whois.nic.or.kr]
[Querying whois.nic.or.kr]
[whois.nic.or.kr]
query : 175.198.158.210


# KOREAN(UTF8)

조회하ì&lsqauo;  IPv4주소ëŠ" 한국인터넷진흥원으로부터 아래의 관리대행자에게 í• ë&lsqauo;¹ë˜ì—ˆìœ¼ë©°, í• ë&lsqauo;¹ ì •ë³´ëŠ" ë&lsqauo;¤ìŒê³¼ 같습ë&lsqauo;ˆë&lsqauo;¤.

[ 네트워크 í• ë&lsqauo;¹ ì •ë³´ ]
IPv4주소 : 175.192.0.0 - 175.215.255.255 (/12+/13)
서비스명 : KORNET
기관명 : 주ì&lsqauo;íšŒì‚¬ 케이í&lsqauo;°
기관고유번호 : ORG1600
주소 : 경기도 성남ì&lsqauo;œ 분ë&lsqauo;¹êµ¬ 불정로 90 (정자동) 한국통ì&lsqauo;  e-Biz본부 기획팀
우편번호 : 463-711
í• ë&lsqauo;¹ì¼ìž : 20100211

[ IPv4주소 책임자 정보 ]
이름 : IP주소관리자
ì „í™"번호 : +82-2-500-6630
전자우편 : kornet_ip@kt.com

[ IPv4주소 ë&lsqauo;´ë&lsqauo;¹ìž ì •ë³´ ]
이름 : IP주소ë&lsqauo;´ë&lsqauo;¹ìž
ì „í™"번호 : +82-2-500-6630
전자우편 : kornet_ip@kt.com

[ 스팸 해킹 ë&lsqauo;´ë&lsqauo;¹ìž ì •ë³´ ]
이름 : 스팸/해킹ë&lsqauo;´ë&lsqauo;¹
ì „í™"번호 : +82-2-100-0000
전자우편 : abuse@kornet.net

--------------------------------------------------------------------------------

조회하ì&lsqauo;  IPv4주소에 대한 위 관리대행자의 사용자 í• ë&lsqauo;¹ì •ë³´ê°€ 존재하지 않습ë&lsqauo;ˆë&lsqauo;¤.


# ENGLISH

KRNIC is not an ISP but a National Internet Registry similar to APNIC.

[ Network Information ]
IPv4 Address : 175.192.0.0 - 175.215.255.255 (/12+/13)
Service Name : KORNET
Organization Name : Korea Telecom
Organization ID : ORG1600
Address : 206, Gyeonggi-do Bundang-gu, Seongnam-si Buljeong-ro
Zip Code : 463-711
Registration Date : 20100211

[ Admin Contact Information ]
Name : IP Administrator
Phone : +82-2-500-6630
E-Mail : kornet_ip@kt.com

[ Tech Contact Information ]
Name : IP Manager
Phone : +82-2-500-6630
E-Mail : kornet_ip@kt.com

[ Network Abuse Contact Information ]
Name : Network Abuse
Phone : +82-2-100-0000
E-Mail : abuse@kornet.net


- KISA/KRNIC Whois Service -

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 132.248.59.129

Hi,

The IP 132.248.59.129 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 132.248.59.129:

[Querying whois.arin.net]
[Redirected to whois.lacnic.net]
[Querying whois.lacnic.net]
[whois.lacnic.net]

% Joint Whois - whois.lacnic.net
% This server accepts single ASN, IPv4 or IPv6 queries

% LACNIC resource: whois.lacnic.net


% Copyright LACNIC lacnic.net
% The data below is provided for information purposes
% and to assist persons in obtaining information about or
% related to AS and IP numbers registrations
% By submitting a whois query, you agree to use this data
% only for lawful purposes.
% 2013-11-22 17:47:43 (BRST -02:00)

inetnum: 132.248/16
status: assigned
aut-num: N/A
owner: Universidad Nacional Autonoma de Mexico
ownerid: MX-UNAM1-LACNIC
responsible: DGTIC - NICUNAM
address: Ciudad Universitaria, circuito exterior, s/n,
address: 04510 - Mexico - DF
country: MX
phone: +52 55 56228884 []
owner-c: CIR
tech-c: CIR
abuse-c: CIR
inetrev: 132.248/16
nserver: NS3.UNAM.MX
nsstat: 20131120 AA
nslastaa: 20131120
nserver: NS4.UNAM.MX
nsstat: 20131120 AA
nslastaa: 20131120
created: 19890331
changed: 20030206

nic-hdl: CIR
person: ALEJANDRO CRUZ SANTOS
e-mail: nic@UNAM.MX
address: DGTIC Ciudad Universitaria, circuito exterior, s/n, NICUNAM
address: 04510 - Mexico - DF
country: MX
phone: +52 55 56228884 []
created: 20041202
changed: 20110217

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 118.97.221.60

Hi,

The IP 118.97.221.60 has just been banned by Fail2Ban after
6 attempts against SSH.


Here are more information about 118.97.221.60:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '118.97.208.0 - 118.97.223.255'

inetnum: 118.97.208.0 - 118.97.223.255
netname: TLKM_NAS_AST_CUSTOMER
country: ID
descr: PT TELKOM INDONESIA
descr: Menara Multimedia Lt. 7
descr: Jl. Kebonsirih No.12
descr: JAKARTA
admin-c: AR165-AP
tech-c: HM444-AP
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-TELKOMNET
mnt-irt: IRT-IDTELKOM-ID
changed: hostmaster@telkom.net.id 20101202
source: APNIC

irt: IRT-IDTELKOM-ID
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebon sirih No.12
address: JAKARTA
e-mail: abuse@telkom.net.id
abuse-mailbox: abuse@telkom.net.id
admin-c: DF99-AP
tech-c: AR165-AP
auth: # Filtered
mnt-by: MAINT-TELKOMNET
changed: abuse@telkom.net.id 20120420
changed: hm-changed@apnic.net 20120420
source: APNIC

role: PT Telkom Indonesia APNIC Resources Management
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
country: ID
phone: +62-21-3860500
fax-no: +62-21-3861215
e-mail: ip-admin@telkom.net.id
admin-c: HM444-AP
tech-c: HM444-AP
nic-hdl: AR165-AP
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060105
source: APNIC

person: PT Telkom Indonesia Hostmaster
nic-hdl: HM444-AP
e-mail: hostmaster@telkom.net.id
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
phone: +62-21-3860500
fax-no: +62-21-3861215
country: ID
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060105
source: APNIC

% Information related to '118.97.208.0/20AS17974'

route: 118.97.208.0/20
descr: PT. TELKOM INDONESIA
descr: Menara Multimedia Lt. 7
descr: Jln. Kebonsirih No.12
descr: JAKARTA
country: ID
origin: AS17974
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20130612
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 210.21.110.54

Hi,

The IP 210.21.110.54 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 210.21.110.54:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '210.21.0.0 - 210.21.127.255'

inetnum: 210.21.0.0 - 210.21.127.255
netname: UNICOM-GD
descr: China Unicom Guangdong province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: RP181-AP
remarks: service provider
mnt-by: MAINT-CNCGROUP
mnt-lower: MAINT-CNCGROUP-GD
mnt-routes: MAINT-CNCGROUP-RR
mnt-irt: IRT-CU-CN
changed: abuse@cnc-noc.net 20050118
status: ALLOCATED NON-PORTABLE
changed: hm-changed@apnic.net 20050616
changed: hm-changed@apnic.net 20060126
changed: hm-changed@apnic.net 20090507
changed: hm-changed@apnic.net 20090508
source: APNIC

irt: IRT-CU-CN
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
e-mail: zhouxm@chinaunicom.cn
abuse-mailbox: zhouxm@chinaunicom.cn
admin-c: CH1302-AP
tech-c: CH1302-AP
auth: # Filtered
mnt-by: MAINT-CNCGROUP
changed: zhouxm@chinaunicom.cn 20101110
changed: hm-changed@apnic.net 20101116
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@cnc-noc.net
address: No.21,Jin-Rong Street
address: Beijing,100033
address: P.R.China
phone: +86-10-66259764
fax-no: +86-10-66259764
country: CN
changed: abuse@cnc-noc.net 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: runkeng pan
nic-hdl: RP181-AP
e-mail: wangjj238@chinaunicom.cn
address: XinShiKong Plaza,No 666 Huangpu Rd. Guangzhou 510627,China
phone: +86-20-22214174
fax-no: +86-20-22212266-4174
country: CN
changed: wangjj238@chinaunicom.cn 20071221
mnt-by: MAINT-CNCGROUP-GD
source: APNIC

% Information related to '210.21.0.0/17AS17816'

route: 210.21.0.0/17
descr: CNC Group CHINA169 Guangdong Province Network
country: CN
origin: AS17816
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060118
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 206.53.51.16

Hi,

The IP 206.53.51.16 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 206.53.51.16:

[Querying whois.arin.net]
[Redirected to rwhois.velcom.com:4321]
[Querying rwhois.velcom.com]
[rwhois.velcom.com]
%rwhois V-1.5:003eff:00 rwhois.velcom.com (by Network Solutions, Inc. V-1.5.9.5)
network:Auth-Area:206.53.48.0/20
network:Class-Name:network
network:ID:NET-206-53-51-0-24
network:Network-Name:Velcom.com
Virtual Hosting
network:IP-Network:206.53.51.0/24
network:Org-Name:VELCOM
network:Street-Address:50
Delta Park Blvd., Unit 4
network:City:Brampton
network:State:ON
network:Postal-Code:L6T-5E8
network:Country-Code:CA
network:Tech-Contact:support@velcom.com
network:Updated:2011-04-26
network:Updated-By:roman@velcom.com

network:Auth-Area:206.53.48.0/20
network:Class-Name:network
network:ID:NET-206-53-48-0-20
network:Network-Name:Velcom.com
IP Pool
network:IP-Network:206.53.48.0/20
network:Org-Name:VELCOM
network:Street-Address:50
Delta Park Blvd., Unit 4
network:City:Brampton
network:State:ON
network:Postal-Code:L6T-5E8
network:Country-Code:CA
network:Tech-Contact:support@velcom.com
network:Updated:2011-04-26
network:Updated-By:roman@velcom.com

%referral rwhois://root.rwhois.net:4321/auth-area=.
%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 213.165.80.81

Hi,

The IP 213.165.80.81 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 213.165.80.81:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '213.165.80.0 - 213.165.95.255'

% Abuse contact for '213.165.80.0 - 213.165.95.255' is 'abuse@oneandone.net'

inetnum: 213.165.80.0 - 213.165.95.255
netname: SCHLUND-CUSTOMERS
descr: 1&1 Internet AG
country: DE
admin-c: IPAD-RIPE
tech-c: IPOP-RIPE
remarks: INFRA-AW
remarks: in case of abuse or spam, please mailto: abuse@oneandone.net
status: ASSIGNED PA
mnt-by: AS8560-MNT
source: RIPE # Filtered

role: IP Administration
address: 1&1 Internet AG
admin-c: AFI5-RIPE
admin-c: RME9-RIPE
admin-c: JR2342-RIPE
admin-c: LTO3-RIPE
admin-c: ZIG-RIPE
admin-c: MI-RIPE
admin-c: MINK-RIPE
admin-c: VR-RIPE
tech-c: AFI5-RIPE
tech-c: RME9-RIPE
tech-c: JR2342-RIPE
tech-c: LTO3-RIPE
nic-hdl: IPAD-RIPE
abuse-mailbox: abuse@oneandone.net
mnt-by: AS8560-MNT
source: RIPE # Filtered

role: IP Operations
address: 1&1 Internet AG
admin-c: AFI5-RIPE
admin-c: RME9-RIPE
admin-c: JR2342-RIPE
admin-c: LTO3-RIPE
tech-c: AFI5-RIPE
tech-c: RME9-RIPE
tech-c: JR2342-RIPE
tech-c: LTO3-RIPE
nic-hdl: IPOP-RIPE
abuse-mailbox: abuse@oneandone.net
mnt-by: AS8560-MNT
source: RIPE # Filtered

% Information related to '213.165.64.0/19AS8560'

route: 213.165.64.0/19
descr: SCHLUND-GMX-213-165-64-0
origin: AS8560
mnt-by: AS8560-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70.1 (WHOIS2)

Regards,

Fail2Ban

Thursday, 21 November 2013

[Fail2Ban] SSH: banned 219.232.231.208

Hi,

The IP 219.232.231.208 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 219.232.231.208:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '219.232.224.0 - 219.232.231.255'

inetnum: 219.232.224.0 - 219.232.231.255
netname: KuanjieNet
descr: Beijing KuanjieNet Technology Co.,Ltd.
descr: 420,Exacutive Tower, No.83 Fuxing Road,
descr: Haidian District, Beijing China ,100856
country: CN
admin-c: YF999-AP
tech-c: YF999-AP
status: allocated non-portable
mnt-by: MAINT-AP-CNISP
mnt-irt: IRT-CNISP-CN
changed: ip@cnisp.org.cn 20130802
source: APNIC

irt: IRT-CNISP-CN
address: CNISP-Union Technology (Beijing) Co., Ltd
e-mail: ip@cnisp.org.cn
abuse-mailbox: ip@cnisp.org.cn
admin-c: DY1-AUTO
tech-c: WF1-AUTO
auth: # Filtered
mnt-by: MAINT-AP-CNISP
changed: ip@cnisp.org.cn 20101109
changed: hm-changed@apnic.net 20101111
source: APNIC

person: Yijiang Feng
address: 420,Exacutive Tower,No.83fu xing Road,
address: Haidian District,Beijing
country: CN
phone: +86-10-51606076
e-mail: fengyijiang@cncitynet.net
nic-hdl: YF999-AP
mnt-by: MAINT-NET-AP
changed: ip@sslchina.cn 20130601
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 36.72.229.51

Hi,

The IP 36.72.229.51 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 36.72.229.51:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '36.72.224.0 - 36.72.239.255'

inetnum: 36.72.224.0 - 36.72.239.255
netname: TLKM_BB_SERVICE_36_72_DIVRE3-4
country: ID
descr: PT TELKOM INDONESIA
descr: STO Gambir 3rd Floor
descr: Jl. Medan Merdeka Selatan No. 12
descr: Jakarta 10110
admin-c: AR165-AP
tech-c: HM444-AP
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-TELKOMNET
mnt-irt: IRT-IDTELKOM-ID
changed: hostmaster@telkom.net.id 20120509
source: APNIC

irt: IRT-IDTELKOM-ID
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebon sirih No.12
address: JAKARTA
e-mail: abuse@telkom.net.id
abuse-mailbox: abuse@telkom.net.id
admin-c: DF99-AP
tech-c: AR165-AP
auth: # Filtered
mnt-by: MAINT-TELKOMNET
changed: abuse@telkom.net.id 20120420
changed: hm-changed@apnic.net 20120420
source: APNIC

role: PT Telkom Indonesia APNIC Resources Management
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
country: ID
phone: +62-21-3860500
fax-no: +62-21-3861215
e-mail: ip-admin@telkom.net.id
admin-c: HM444-AP
tech-c: HM444-AP
nic-hdl: AR165-AP
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060105
source: APNIC

person: PT Telkom Indonesia Hostmaster
nic-hdl: HM444-AP
e-mail: hostmaster@telkom.net.id
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
phone: +62-21-3860500
fax-no: +62-21-3861215
country: ID
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060105
source: APNIC

% Information related to '36.72.228.0/22AS17974'

route: 36.72.228.0/22
descr: PT. TELKOM INDONESIA
country: ID
origin: AS17974
mnt-by: MAINT-TELKOMNET
changed: djimie@telin.co.id 20130818
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 199.168.140.242

Hi,

The IP 199.168.140.242 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 199.168.140.242:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 199.168.140.242"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=199.168.140.242?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 199.168.136.0 - 199.168.143.255
CIDR: 199.168.136.0/21
OriginAS: AS46664
NetName: VOLUMEDRIVE
NetHandle: NET-199-168-136-0-1
Parent: NET-199-0-0-0-0
NetType: Direct Allocation
RegDate: 2011-06-17
Updated: 2012-03-02
Ref: http://whois.arin.net/rest/net/NET-199-168-136-0-1

OrgName: VolumeDrive
OrgId: VOLUM-2
Address: 1143 Northern Blvd
City: Clarks Summit
StateProv: PA
PostalCode: 18411
Country: US
RegDate: 2008-08-26
Updated: 2011-09-24
Ref: http://whois.arin.net/rest/org/VOLUM-2

OrgTechHandle: VOLUM1-ARIN
OrgTechName: VolumeDrive POC
OrgTechPhone: +1-862-266-1083
OrgTechEmail: info@volumedrive.com
OrgTechRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN

OrgAbuseHandle: VOLUM1-ARIN
OrgAbuseName: VolumeDrive POC
OrgAbusePhone: +1-862-266-1083
OrgAbuseEmail: info@volumedrive.com
OrgAbuseRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 222.43.96.226

Hi,

The IP 222.43.96.226 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 222.43.96.226:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '222.32.0.0 - 222.63.255.255'

inetnum: 222.32.0.0 - 222.63.255.255
netname: CTTNET
descr: China TieTong Telecommunications Corporation
descr: Jinze Mansion, 2 Guangningbo Street,
descr: Xicheng District, Beijing, China, 100032
country: CN
admin-c: WP188-AP
tech-c: LM273-AP
status: ALLOCATED PORTABLE
mnt-by: MAINT-CNNIC-AP
mnt-lower: MAINT-CN-CRTC
mnt-routes: MAINT-CNNIC-AP
mnt-irt: IRT-CNNIC-CN
changed: hm-changed@apnic.net 20090430
source: APNIC

irt: IRT-CNNIC-CN
address: Beijing, China
e-mail: ipas@cnnic.cn
abuse-mailbox: ipas@cnnic.cn
admin-c: IP50-AP
tech-c: IP50-AP
auth: # Filtered
remarks: Please note that CNNIC is not an ISP and is not
remarks: empowered to investigate complaints of network abuse.
remarks: Please contact the tech-c or admin-c of the network.
mnt-by: MAINT-CNNIC-AP
changed: ipas@cnnic.cn 20110428
source: APNIC

person: liu min
nic-hdl: LM273-AP
e-mail: crnet_mgr@chinatietong.com
address: 22F Yuetan Mansion, Xicheng District, Beijing, P.R.China
phone: +86-10-51848796
fax-no: +86-10-51842426
country: CN
changed: ipas@cnnic.net.cn 20120320
mnt-by: MAINT-CNNIC-AP
source: APNIC

person: Wang Pei
nic-hdl: WP188-AP
e-mail: crnet_mgr@chinatietong.com
address: Jinze Mansion, 2 Guangningbo Street,
address: Xicheng District, Beijing, China, 100032
phone: +21-51892106
fax-no: +21-51847802
country: CN
changed: ipas@cnnic.net.cn 20060926
mnt-by: MAINT-CNNIC-AP
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 199.168.140.242

Hi,

The IP 199.168.140.242 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 199.168.140.242:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 199.168.140.242"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=199.168.140.242?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 199.168.136.0 - 199.168.143.255
CIDR: 199.168.136.0/21
OriginAS: AS46664
NetName: VOLUMEDRIVE
NetHandle: NET-199-168-136-0-1
Parent: NET-199-0-0-0-0
NetType: Direct Allocation
RegDate: 2011-06-17
Updated: 2012-03-02
Ref: http://whois.arin.net/rest/net/NET-199-168-136-0-1

OrgName: VolumeDrive
OrgId: VOLUM-2
Address: 1143 Northern Blvd
City: Clarks Summit
StateProv: PA
PostalCode: 18411
Country: US
RegDate: 2008-08-26
Updated: 2011-09-24
Ref: http://whois.arin.net/rest/org/VOLUM-2

OrgAbuseHandle: VOLUM1-ARIN
OrgAbuseName: VolumeDrive POC
OrgAbusePhone: +1-862-266-1083
OrgAbuseEmail: info@volumedrive.com
OrgAbuseRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN

OrgTechHandle: VOLUM1-ARIN
OrgTechName: VolumeDrive POC
OrgTechPhone: +1-862-266-1083
OrgTechEmail: info@volumedrive.com
OrgTechRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 199.168.140.242

Hi,

The IP 199.168.140.242 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 199.168.140.242:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 199.168.140.242"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=199.168.140.242?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 199.168.136.0 - 199.168.143.255
CIDR: 199.168.136.0/21
OriginAS: AS46664
NetName: VOLUMEDRIVE
NetHandle: NET-199-168-136-0-1
Parent: NET-199-0-0-0-0
NetType: Direct Allocation
RegDate: 2011-06-17
Updated: 2012-03-02
Ref: http://whois.arin.net/rest/net/NET-199-168-136-0-1

OrgName: VolumeDrive
OrgId: VOLUM-2
Address: 1143 Northern Blvd
City: Clarks Summit
StateProv: PA
PostalCode: 18411
Country: US
RegDate: 2008-08-26
Updated: 2011-09-24
Ref: http://whois.arin.net/rest/org/VOLUM-2

OrgTechHandle: VOLUM1-ARIN
OrgTechName: VolumeDrive POC
OrgTechPhone: +1-862-266-1083
OrgTechEmail: info@volumedrive.com
OrgTechRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN

OrgAbuseHandle: VOLUM1-ARIN
OrgAbuseName: VolumeDrive POC
OrgAbusePhone: +1-862-266-1083
OrgAbuseEmail: info@volumedrive.com
OrgAbuseRef: http://whois.arin.net/rest/poc/VOLUM1-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 49.212.96.241

Hi,

The IP 49.212.96.241 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 49.212.96.241:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '49.212.0.0 - 49.212.255.255'

inetnum: 49.212.0.0 - 49.212.255.255
netname: SAKURA-OSAKA
descr: SAKURA Internet Inc.
descr: 1-8-14, Minami Honmachi, Chuo-ku, Osaka 541-0054, Japan
country: JP
admin-c: JNIC1-AP
tech-c: JNIC1-AP
status: ALLOCATED PORTABLE
remarks: Email address for spam or abuse complaints : abuse@sakura.ad.jp
changed: hm-changed@apnic.net 20101207
mnt-irt: IRT-JPNIC-JP
mnt-by: MAINT-JPNIC
mnt-lower: MAINT-JPNIC
source: APNIC

irt: IRT-JPNIC-JP
address: Urbannet-Kanda Bldg 4F, 3-6-2 Uchi-Kanda
address: Chiyoda-ku, Tokyo 101-0047, Japan
e-mail: abuse@apnic.net
abuse-mailbox: abuse@apnic.net
admin-c: JNIC1-AP
tech-c: JNIC1-AP
auth: # Filtered
mnt-by: MAINT-JPNIC
changed: abuse@apnic.net 20101108
changed: hm-changed@apnic.net 20101111
source: APNIC

role: Japan Network Information Center
address: Urbannet-Kanda Bldg 4F
address: 3-6-2 Uchi-Kanda
address: Chiyoda-ku, Tokyo 101-0047,Japan
country: JP
phone: +81-3-5297-2311
fax-no: +81-3-5297-2312
e-mail: hostmaster@nic.ad.jp
admin-c: JI13-AP
tech-c: JE53-AP
nic-hdl: JNIC1-AP
mnt-by: MAINT-JPNIC
changed: hm-changed@apnic.net 20041222
changed: hm-changed@apnic.net 20050324
changed: ip-apnic@nic.ad.jp 20051027
changed: ip-apnic@nic.ad.jp 20120828
source: APNIC

% Information related to '49.212.96.0 - 49.212.96.255'

inetnum: 49.212.96.0 - 49.212.96.255
netname: SAKURA-NET
descr: SAKURA Internet Inc.
country: JP
admin-c: KT749JP
tech-c: KW419JP
remarks: This information has been partially mirrored by APNIC from
remarks: JPNIC. To obtain more specific information, please use the
remarks: JPNIC WHOIS Gateway at
remarks: http://www.nic.ad.jp/en/db/whois/en-gateway.html or
remarks: whois.nic.ad.jp for WHOIS client. (The WHOIS client
remarks: defaults to Japanese output, use the /e switch for English
remarks: output)
changed: apnic-ftp@nic.ad.jp 20110602
source: JPNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS4)

Regards,

Fail2Ban

Wednesday, 20 November 2013

[Fail2Ban] SSH: banned 88.150.229.252

Hi,

The IP 88.150.229.252 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 88.150.229.252:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '88.150.229.224 - 88.150.229.255'

% Abuse contact for '88.150.229.224 - 88.150.229.255' is 'abuse@redstation.com'

inetnum: 88.150.229.224 - 88.150.229.255
netname: RSDEDI-KHJMBPBN
descr: Dedicated Server Hosting
country: GB
admin-c: RA1415-RIPE
tech-c: RA1415-RIPE
status: ASSIGNED PA
remarks: ABUSE REPORTS: abuse@redstation.com
mnt-by: REDSTATION-MNT
mnt-domains: REDSTATION-MNT
mnt-routes: REDSTATION-MNT
source: RIPE # Filtered

role: Redstation Admin Role
address: Redstation Limited
address: 2 Frater Gate Business Park
address: Aerodrome Road
address: Gosport
address: Hampshire
address: PO13 0GW
address: UNITED KINGDOM
abuse-mailbox: abuse@redstation.com
admin-c: KMAC-RIPE
tech-c: PA5242-RIPE
nic-hdl: RA1415-RIPE
mnt-by: REDSTATION-MNT
source: RIPE # Filtered

% Information related to '88.150.128.0/17AS35662'

route: 88.150.128.0/17
descr: Redstation Limited
origin: AS35662
mnt-by: REDSTATION-MNT
mnt-lower: GB10488-RIPE-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 176.31.107.136

Hi,

The IP 176.31.107.136 has just been banned by Fail2Ban after
11 attempts against SSH.


Here are more information about 176.31.107.136:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '176.31.96.0 - 176.31.127.255'

% No abuse contact registered for 176.31.96.0 - 176.31.127.255

inetnum: 176.31.96.0 - 176.31.127.255
netname: OVH
descr: OVH SAS
descr: Dedicated servers
descr: http://www.ovh.com
country: FR
admin-c: OK217-RIPE
tech-c: OTC2-RIPE
status: ASSIGNED PA
mnt-by: OVH-MNT
source: RIPE # Filtered

role: OVH Technical Contact
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
admin-c: OK217-RIPE
tech-c: GM84-RIPE
nic-hdl: OTC2-RIPE
abuse-mailbox: abuse@ovh.net
mnt-by: OVH-MNT
source: RIPE # Filtered

person: Octave Klaba
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
phone: +33 9 74 53 13 23
nic-hdl: OK217-RIPE
abuse-mailbox: abuse@ovh.net
mnt-by: OVH-MNT
source: RIPE # Filtered

% Information related to '176.31.0.0/16AS16276'

route: 176.31.0.0/16
descr: OVH ISP
descr: Paris, France
origin: AS16276
mnt-by: OVH-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 123.200.129.218

Hi,

The IP 123.200.129.218 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 123.200.129.218:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '123.200.128.0 - 123.200.255.255'

inetnum: 123.200.128.0 - 123.200.255.255
netname: ISEEK
descr: iseek Communications
descr: 46 Logan Rd
descr: Woolloongabba QLD 4102
country: AU
admin-c: IH161-AP
tech-c: IH161-AP
status: ALLOCATED PORTABLE
mnt-by: APNIC-HM
mnt-lower: MAINT-AU-ISEEK
mnt-irt: IRT-INFOPRO-AU
remarks: ---
remarks: For spam/security issues email abuse@iseek.com.au
remarks: ---
changed: hm-changed@apnic.net 20070315
changed: hm-changed@apnic.net 20090226
changed: hm-changed@apnic.net 20090302
changed: hm-changed@apnic.net 20110627
source: APNIC

irt: IRT-INFOPRO-AU
address: 46 Logan Road
address: Woolloongabba, QLD, 4102
address: Australia
e-mail: abuse@iseek.com.au
abuse-mailbox: abuse@iseek.com.au
admin-c: IB7-AP
tech-c: IH161-AP
auth: # Filtered
mnt-by: MAINT-AU-ISEEK
changed: technical@iseek.com.au 20101108
source: APNIC

role: iseek hostmaster
remarks: ---
remarks: For spam/security issues email abuse@iseek.com.au
remarks: ---
address: 46 Logan Rd
address: Woolloongabba QLD 4102
country: AU
phone: +61-1300-661-668
fax-no: +61-1300-661-540
e-mail: hostmaster@iseek.com.au
remarks: ---
remarks: For spam/security issues email abuse@iseek.com.au
remarks: ---
admin-c: IH161-AP
tech-c: IH161-AP
nic-hdl: IH161-AP
mnt-by: MAINT-AU-ISEEK
changed: hm-changed@apnic.net 20090226
changed: hm-changed@apnic.net 20110622
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS4)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 64.5.53.243

Hi,

The IP 64.5.53.243 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 64.5.53.243:

[Querying whois.arin.net]
[Redirected to rwhois.theplanet.com:4321]
[Querying rwhois.theplanet.com]
[rwhois.theplanet.com]
%rwhois V-1.5:003fff:00 rwhois.softlayer.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:NETBLK-SOFTLAYER.64.5.32.0/19
network:Auth-Area:64.5.32.0/19
network:Network-Name:SOFTLAYER-64.5.32.0
network:IP-Network:64.5.53.0/24
network:IP-Network-Block:64.5.53.0-64.5.53.255

network:Organization;I:SoftLayer
network:Street-Address:4849 Alpha Road
network:City:Dallas
network:State:TX
network:Postal-Code:75244
network:Country-Code:US
network:Tech-Contact;I:sysadmins@softlayer.com
network:Abuse-Contact;I:abuse@softlayer.com
network:Admin-Contact;I:IPADM258-ARIN
network:Created:2011-02-17 15:12:46
network:Updated-By:ipadmin@softlayer.com

network:Class-Name:network
network:ID:NETBLK-THEPLANET-BLK-5
network:Auth-Area:64.5.32.0/19
network:Network-Name:TPIS-BLK-64-5-53-0
network:IP-Network:64.5.53.0/24
network:IP-Network-Block:64.5.53.0
- 64.5.53.255
network:Organization;I:Linode.com
network:Street-Address:N/A
network:City:Galloway
network:State:NJ
network:Postal-Code:08205
network:Country-Code:USA
network:Tech-Contact;I:abuse@theplanet.com
network:Admin-Contact;I:abuse@theplanet.com
network:Created:20030403
network:Updated:20130619

%referral rwhois://root.rwhois.net:4321/auth-area=.
%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 62.26.12.244

Hi,

The IP 62.26.12.244 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 62.26.12.244:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '62.26.12.0 - 62.26.12.255'

% Abuse contact for '62.26.12.0 - 62.26.12.255' is 'abuse@ecotel.net'

inetnum: 62.26.12.0 - 62.26.12.255
netname: TIS-D400707-NET
descr: Dauer
country: DE
admin-c: NET12312-RIPE
tech-c: NET12312-RIPE
status: ASSIGNED PA
mnt-by: AS12312-MNT
source: RIPE # Filtered

role: AS12312 Network Management
address: ecotel communication ag
address: Hanauer Landstrasse 300
address: 60314 Frankfurt
address: Germany
phone: +49 69 40801 0
fax-no: +49 69 40801 161
abuse-mailbox: abuse@ecotel.net
remarks:
remarks: --------------------------------------------------------
remarks: ---( Network & Operational Issues )---------------------
remarks: --------------------------------------------------------
remarks:
remarks: Send mail to: ................ noc [at] ecotel [dot] net
remarks: Call (24/7): .......................... +49 69 40801 530
remarks:
remarks: --------------------------------------------------------
remarks: ---( Abuse & Spam Reports )-----------------------------
remarks: --------------------------------------------------------
remarks:
remarks: Send mail to: .............. abuse [at] ecotel [dot] net
remarks:
admin-c: CU20-RIPE
tech-c: CU20-RIPE
tech-c: PW1632-RIPE
tech-c: RN901-RIPE
nic-hdl: NET12312-RIPE
mnt-by: AS12312-MNT
source: RIPE # Filtered

% Information related to '62.26.0.0/15AS12312'

route: 62.26.0.0/15
descr: ecotel communication ag
origin: AS12312
mnt-by: AS12312-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 129.21.208.60

Hi,

The IP 129.21.208.60 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 129.21.208.60:

[Querying whois.arin.net]
[whois.arin.net]

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous. The query is assumed to be:
# "n 129.21.208.60"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=129.21.208.60?showDetails=true&showARIN=false&ext=netref2
#

NetRange: 129.21.0.0 - 129.21.255.255
CIDR: 129.21.0.0/16
OriginAS:
NetName: RIT
NetHandle: NET-129-21-0-0-1
Parent: NET-129-0-0-0-0
NetType: Direct Assignment
Comment: http://www.rit.edu
RegDate: 1987-07-14
Updated: 2002-10-30
Ref: http://whois.arin.net/rest/net/NET-129-21-0-0-1

OrgName: Rochester Institute of Technology
OrgId: RIT-3
Address: 103 Lomb Memorial Drive
City: Rochester
StateProv: NY
PostalCode: 14623-5608
Country: US
RegDate: 1987-07-14
Updated: 2002-11-04
Ref: http://whois.arin.net/rest/org/RIT-3

OrgTechHandle: NETWO58-ARIN
OrgTechName: Network Administration
OrgTechPhone: +1-585-475-5306
OrgTechEmail: networks@rit.edu
OrgTechRef: http://whois.arin.net/rest/poc/NETWO58-ARIN

OrgAbuseHandle: ABUSE87-ARIN
OrgAbuseName: Abuse Reporting
OrgAbusePhone: +1-585-475-7860
OrgAbuseEmail: abuse@rit.edu
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE87-ARIN

OrgNOCHandle: NETWO57-ARIN
OrgNOCName: Network Support
OrgNOCPhone: +1-585-475-5306
OrgNOCEmail: networks@rit.edu
OrgNOCRef: http://whois.arin.net/rest/poc/NETWO57-ARIN

RNOCHandle: NETWO57-ARIN
RNOCName: Network Support
RNOCPhone: +1-585-475-5306
RNOCEmail: networks@rit.edu
RNOCRef: http://whois.arin.net/rest/poc/NETWO57-ARIN

RAbuseHandle: ABUSE87-ARIN
RAbuseName: Abuse Reporting
RAbusePhone: +1-585-475-7860
RAbuseEmail: abuse@rit.edu
RAbuseRef: http://whois.arin.net/rest/poc/ABUSE87-ARIN

RTechHandle: NETWO58-ARIN
RTechName: Network Administration
RTechPhone: +1-585-475-5306
RTechEmail: networks@rit.edu
RTechRef: http://whois.arin.net/rest/poc/NETWO58-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 162.13.151.5

Hi,

The IP 162.13.151.5 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 162.13.151.5:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '162.13.144.0 - 162.13.159.255'

% Abuse contact for '162.13.144.0 - 162.13.159.255' is 'abuse@rackspace.com'

inetnum: 162.13.144.0 - 162.13.159.255
netname: RSPC-UK-Cloud-Servers-UK
descr: Cloud Servers UK IP Space
country: GB
admin-c: IA247-RIPE
tech-c: IA247-RIPE
status: ASSIGNED PA
mnt-by: RSPC-MNT
source: RIPE # Filtered

person: IP Admin
address: Rackspace Hosting 5000 Walzem, San Antonio, Texas 78218
phone: +1 210 312 4000
fax-no: +1 210 312 4000
nic-hdl: IA247-RIPE
remarks: ### Rackspace Abuse Department
remarks: ### Please send any complaints to the following:
remarks: ### abuse@rackspace.com
mnt-by: RSPC-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 202.134.5.130

Hi,

The IP 202.134.5.130 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 202.134.5.130:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '202.134.5.0 - 202.134.5.255'

inetnum: 202.134.5.0 - 202.134.5.255
netname: TLKM_D2_IDC_COLO_KARET_2
country: ID
descr: PT TELKOM DIVISI MULTIMEDIA
descr: TELECOMMUNICATIONS/COMMUNICATIONS
descr: JL. KEBON SIRIH No.12 - 6th FLOOR
descr: JAKARTA
admin-c: AR165-AP
tech-c: NA182-AP
status: ASSIGNED NON-PORTABLE
remarks: ------------------------------------------------------------------
remarks: Send ABUSE and SPAM reports with plain ASCII text only to
remarks: datacenter@telkom.co.id and cc to abuse@telkom.net.id
remarks: The netname enclosed in square bracket is included in the subject.
remarks: ------------------------------------------------------------------
changed: hostmaster@telkom.net.id 20070620
changed: hostmaster@telkom.net.id 20080101
mnt-by: MAINT-TELKOMNET
source: APNIC

role: PT Telkom Indonesia APNIC Resources Management
address: PT. TELKOM INDONESIA
address: Menara Multimedia Lt. 7
address: Jl. Kebonsirih No.12
address: JAKARTA
country: ID
phone: +62-21-3860500
fax-no: +62-21-3861215
e-mail: ip-admin@telkom.net.id
admin-c: HM444-AP
tech-c: HM444-AP
nic-hdl: AR165-AP
notify: hostmaster@telkom.net.id
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060105
source: APNIC

person: Network Admin Server Farm
address: PT. TELKOM INDONESIA
address: Service Operation Data Center
address: Grha Citra Caraka Building
address: Jl. Gatot Subroto Kav 52
address: JAKARTA
country: ID
phone: +62-21-52920400
fax-no: +62-21-52907111
e-mail: net-admin@telkom.net.id
nic-hdl: NA182-AP
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20080101
source: APNIC

% Information related to '202.134.5.0/24AS17974'

route: 202.134.5.0/24
descr: PT. TELKOM INDONESIA
descr: Menara Multimedia Lt. 7
descr: Jl. Kebonsirih No.12
descr: JAKARTA
country: ID
origin: AS17974
mnt-by: MAINT-TELKOMNET
changed: hostmaster@telkom.net.id 20060601
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS1)

Regards,

Fail2Ban

Tuesday, 19 November 2013

[Fail2Ban] SSH: banned 83.226.80.45

Hi,

The IP 83.226.80.45 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 83.226.80.45:

[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '83.226.80.0 - 83.226.81.255'

% Abuse contact for '83.226.80.0 - 83.226.81.255' is 'abuse@telenor.se'

inetnum: 83.226.80.0 - 83.226.81.255
netname: B2-BISP
descr: B2 customers in sto43.se
country: SE
admin-c: BR3045-RIPE
tech-c: BR3045-RIPE
status: ASSIGNED PA
mnt-by: B2-MNT
mnt-routes: B2-MNT
source: RIPE # Filtered

role: Bredbandsbolaget Routing Registry
address: Box 4247
address: 102 65 Stockholm
address: Sweden
remarks: trouble: *********************************
remarks: trouble: Abuse related issues is reported
remarks: trouble: to abuse@bredband.com
remarks: trouble: Abuse issues sent to other e-mail
remarks: trouble: adresses will be discarded
remarks: trouble: *********************************
admin-c: JN1883-RIPE
admin-c: EB78-RIPE
admin-c: NE102-RIPE
admin-c: ARL1-RIPE
admin-c: CPE1-RIPE
tech-c: JN1883-RIPE
tech-c: EB78-RIPE
tech-c: NE102-RIPE
tech-c: ARL1-RIPE
tech-c: CPE1-RIPE
nic-hdl: BR3045-RIPE
mnt-by: B2-MNT
abuse-mailbox: abuse@bredband.com
source: RIPE # Filtered

% Information related to '83.226.0.0/15AS2119'

route: 83.226.0.0/15
descr: Broadband customers in Scandinavia
descr: Please report improper use to abuse@bredband.com
origin: AS2119
member-of: AS2119:RS-SE-B2
mnt-by: AS2119-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS2)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 201.22.58.155

Hi,

The IP 201.22.58.155 has just been banned by Fail2Ban after
7 attempts against SSH.


Here are more information about 201.22.58.155:

[Querying whois.lacnic.net]
[Redirected to whois.registro.br]
[Querying whois.registro.br]
[whois.registro.br]

% Copyright (c) Nic.br
% The use of the data below is only permitted as described in
% full by the terms of use (http://registro.br/termo/en.html),
% being prohibited its distribution, comercialization or
% reproduction, in particular, to use it for advertising or
% any similar purpose.
% 2013-11-20 01:17:42 (BRST -02:00)

inetnum: 201.22/16
aut-num: AS18881
abuse-c: GOI
owner: Global Village Telecom
ownerid: 003.420.926/0002-05
responsible: Eng&Op Dados
country: BR
owner-c: GEI26
tech-c: GVO6
inetrev: 201.22.32/19
nserver: dns1.gvt.net.br
nsstat: 20131118 AA
nslastaa: 20131118
nserver: dns2.gvt.net.br
nsstat: 20131118 AA
nslastaa: 20131118
nserver: dns3.gvt.net.br
nsstat: 20131118 AA
nslastaa: 20131118
created: 20041118
changed: 20041119

nic-hdl-br: GEI26
person: GVT - Equipe de redes IT
e-mail: registro@gvt.com.br
created: 20021107
changed: 20120627

nic-hdl-br: GOI
person: GVT - Operacoes Internet
e-mail: abuse@gvt.com.br
created: 20050112
changed: 20110222

nic-hdl-br: GVO6
person: GVT Operacao
e-mail: operacao@gvt.com.br
created: 20010613
changed: 20100713

% Security and mail abuse issues should also be addressed to
% cert.br, http://www.cert.br/, respectivelly to cert@cert.br
% and mail-abuse@cert.br
%
% whois.registro.br accepts only direct match queries. Types
% of queries are: domain (.br), registrant (tax ID), ticket,
% provider, contact handle (ID), CIDR block, IP and ASN.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 119.84.63.30

Hi,

The IP 119.84.63.30 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 119.84.63.30:

[Querying whois.arin.net]
[Redirected to whois.apnic.net]
[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '119.84.0.0 - 119.87.255.255'

inetnum: 119.84.0.0 - 119.87.255.255
netname: CHINANET-CQ
descr: CHINANET Chongqing Province Network
descr: Data Communication Division
descr: China Telecom
country: CN
admin-c: CH93-AP
tech-c: CQ235-AP
remarks: service provider
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation's account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20080129
status: ALLOCATED PORTABLE
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-CQ
mnt-routes: MAINT-CHINANET-CQ
source: APNIC

role: CHINANET CQ
address: The mainstreet 3 daping ,chongqing data communication bureau
country: CN
phone: +862368614888
fax-no: +862368602314
e-mail: abuse@cta.cq.cn
remarks: send spam reports to abuse@cta.cq.cn
remarks: and abuse reports to abuse@cta.cq.cn
admin-c: ZL235-AP
tech-c: ZL235-AP
nic-hdl: CQ235-AP
remarks: http://www.cta.cq.cn
notify: abuse@cta.cq.cn
mnt-by: MAINT-CHINANET-CQ
changed: abuse@cta.cq.cn 20030917
source: APNIC
changed: hm-changed@apnic.net 20111114

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: dingsy@cndata.com 20070416
mnt-by: MAINT-CHINANET
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 31.199.3.178

Hi,

The IP 31.199.3.178 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 31.199.3.178:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '31.199.3.160 - 31.199.3.191'

% Abuse contact for '31.199.3.160 - 31.199.3.191' is 'abuse@business.telecomitalia.it'

inetnum: 31.199.3.160 - 31.199.3.191
netname: ERICSSON-TELECOMUNICAZIONI
descr: ERICSSON TELECOMUNICAZIONI S.P.A.
country: IT
admin-c: PT6067-RIPE
tech-c: PT6067-RIPE
status: ASSIGNED PA
mnt-by: INTERB-MNT
source: RIPE # Filtered

person: PIERO TOLLIS
address: ERICSSON TELECOMUNICAZIONI S.P.A.
address: VIA ANAGNINA 203
address: 00100 ROMA
address: IT
phone: +39 0672582887
nic-hdl: PT6067-RIPE
mnt-by: INTERB-MNT
source: RIPE # Filtered

% Information related to '31.198.0.0/15AS3269'

route: 31.198.0.0/15
descr: INTERBUSINESS
origin: AS3269
remarks: ************************************************
remarks: * Pay attention *
remarks: * Any communication sent to email different *
remarks: * from the following will be ignored! *
remarks: * Any abuse reports, please send them to *
remarks: * abuse@business.telecomitalia.it *
remarks: ************************************************
mnt-by: INTERB-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS3)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 222.187.126.134

Hi,

The IP 222.187.126.134 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 222.187.126.134:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '222.187.126.128 - 222.187.126.143'

inetnum: 222.187.126.128 - 222.187.126.143
netname: XUZHOU-TIANNENG-CORP
descr: XuZhou TianNeng CORP
descr: Xuzhou City
descr: Jiangsu Province
country: CN
admin-c: CH482-AP
tech-c: ZJ1344-AP
changed: ip@jsinfo.net 20070319
status: ASSIGNED NON-PORTABLE
mnt-by: MAINT-CHINANET-JS
mnt-lower: MAINT-CHINANET-JS-XZ
source: APNIC

person: CHINANET-JS-XZ Hostmaster
address: No.116,Huaihai East Road,Xuzhou 221000
country: CN
phone: +86-516-5806352
fax-no: +86-516-3712480
e-mail: ipxz@pub.xz.jsinfo.net
nic-hdl: CH482-AP
remarks: send anti-spam or abuse reports to abuse@public.xz.js.cn
remarks: or abuse@pub.xz.jsinfo.net
remarks: times in GMT+8
mnt-by: MAINT-CHINANET-JS-XZ
changed: ip@jsinfo.net 20030428
source: APNIC

person: Zhong Jiansheng
nic-hdl: ZJ1344-AP
e-mail: zhongjiansheng@pub.xz.jsinfo.net
address: HuaiHaiRoad XuZhou City
phone: +86-516-82213273
country: CN
changed: ip@jsinfo.net 20070319
mnt-by: MAINT-CHINANET-JS
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS4)

Regards,

Fail2Ban

Monday, 18 November 2013

[Fail2Ban] SSH: banned 201.57.75.254

Hi,

The IP 201.57.75.254 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 201.57.75.254:

[Querying whois.lacnic.net]
[Redirected to whois.registro.br]
[Querying whois.registro.br]
[whois.registro.br]

% Copyright (c) Nic.br
% The use of the data below is only permitted as described in
% full by the terms of use (http://registro.br/termo/en.html),
% being prohibited its distribution, comercialization or
% reproduction, in particular, to use it for advertising or
% any similar purpose.
% 2013-11-18 22:34:19 (BRST -02:00)

inetnum: 201.57.75.240/28
aut-num
: AS4230
abuse-c: GSE6
owner: Serviço Nacional de Aprendizagem Industrial-SENAI
ownerid: 003.795.071/0001-16
responsible: Gustavo Leal Sales Filho
country: BR
owner-c: FFA66
tech-c: MMP269
created: 20071114
changed: 20081210
inetnum-up: 201.56/15

nic-hdl-br: FFA66
person: France Ferreira de Souza Arnaut
e-mail: arnaut@bol.com.br
created: 20020109
changed: 20020109

nic-hdl-br: GSE6
person: Grupo de Segurança Internet da Embratel
e-mail: abuse@embratel.net.br
created: 20001005
changed: 20001005

nic-hdl-br: MMP269
person: Marcelo Machado de Pinheiro
e-mail: marcelo.mpinheiro@gmail.com
created: 20041018
changed: 20080107

% Security and mail abuse issues should also be addressed to
% cert.br, http://www.cert.br/, respectivelly to cert@cert.br
% and mail-abuse@cert.br
%
% whois.registro.br accepts only direct match queries. Types
% of queries are: domain (.br), registrant (tax ID), ticket,
% provider, contact handle (ID), CIDR block, IP and ASN.


Regards,

Fail2Ban

[Fail2Ban] SSH: banned 211.95.76.242

Hi,

The IP 211.95.76.242 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 211.95.76.242:

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

% Information related to '211.94.0.0 - 211.103.255.255'

inetnum: 211.94.0.0 - 211.103.255.255
netname: CNNIC
descr: China Internet Network Information Center
country: CN
admin-c: HQ1-CN
tech-c: MW1-AP
tech-c: WZ2-AP
remarks: confederation CNNIC
mnt-by: MAINT-CNNIC-AP
changed: hostmaster@apnic.net 19991214
status: ALLOCATED PORTABLE
source: APNIC

person: Hualin Qian
address: Chinese Academy of Sciences
address: Computer Network Center
address: P.O.Box 2418-26
address: Beijing, 100081
address: CN
country: CN
phone: +86 1 2569960
e-mail: hlqian@ns.cnc.ac.cn
nic-hdl: HQ1-CN
notify: dbmon@apnic.net
mnt-by: MAINT-NULL
changed: hostmaster@apnic.net 19950419
source: APNIC
changed: hm-changed@apnic.net 20111122

person: Mao Wei
address: China Internet Information Center(CNNIC)No. 4 of South street,
address: Zhongguancun, Beijing, P.R.China 100080
country: CN
phone: +86-10-58813000
fax-no: +86-10-62559892
e-mail: ipas@cnnic.net.cn
nic-hdl: MW1-AP
mnt-by: MAINT-CNNIC-AP
changed: ipas@cnnic.net.cn 20010319
changed: ipas@cnnic.net.cn 20060222
source: APNIC

person: Wenhui Zhang
address: China Internet Information Center(CNNIC)
address: No.4,South Fourth street,Zhongguancun,Haidian
address: Beijing,100080
address: P.R.China
country: CN
phone: +86-10-62553604
fax-no: +86-10-62559892
e-mail: whzhang@cnnic.net.cn
nic-hdl: WZ2-AP
mnt-by: MAINT-CNNIC-AP
changed: ipas@cnnic.net.cn 20020408
source: APNIC

% This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS1)

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 108.168.143.122

Hi,

The IP 108.168.143.122 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 108.168.143.122:

[Querying whois.arin.net]
[Redirected to rwhois.softlayer.com:4321]
[Querying rwhois.softlayer.com]
[rwhois.softlayer.com]
%rwhois V-1.5:003fff:00 rwhois.softlayer.com (by Network Solutions, Inc. V-1.5.9.5)
network:Class-Name:network
network:ID:NETBLK-SOFTLAYER.108.168.128.0/19
network:Auth-Area:108.168.128.0/19
network:Network-Name:SOFTLAYER-108.168.128.0
network:IP-Network:108.168.143.120/29
network:IP-Network-Block:108.168.143.120-108.168.143.127

network:Organization;I:Bridge Base, Inc.
network:Street-Address:10550 Hope Mills Drive
network:City:Las Vegas
network:State:NV
network:Postal-Code:89135
network:Country-Code:US
network:Tech-Contact;I:sysadmins@softlayer.com
network:Abuse-Contact;I:uday@bridgebase.com
network:Admin-Contact;I:IPADM258-ARIN
network:Created:2010-11-19 14:55:43
network:Updated:2013-03-29 12:17:03
network:Updated-By:ipadmin@softlayer.com

%ok

Regards,

Fail2Ban

[Fail2Ban] SSH: banned 46.149.115.109

Hi,

The IP 46.149.115.109 has just been banned by Fail2Ban after
5 attempts against SSH.


Here are more information about 46.149.115.109:

[Querying whois.arin.net]
[Redirected to whois.ripe.net:43]
[Querying whois.ripe.net]
[whois.ripe.net]
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.

% Information related to '46.149.112.0 - 46.149.127.255'

% No abuse contact registered for 46.149.112.0 - 46.149.127.255

inetnum: 46.149.112.0 - 46.149.127.255
netname: ALFSERVIS-NET
descr: Alf Servis s.r.o.
country: CZ
org: ORG-ALFS1-RIPE
admin-c: SEBE1-RIPE
tech-c: SEBE1-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-lower: RIPE-NCC-END-MNT
mnt-by: ALFSERVIS-MNT
mnt-routes: ALFSERVIS-MNT
mnt-domains: ALFSERVIS-MNT
source: RIPE # Filtered

organisation: ORG-ALFS1-RIPE
org-name: Alf servis, s.r.o.
org-type: OTHER
address: Okruzni 17,678 01 Blansko, Czech Republic
mnt-ref: ALFSERVIS-MNT
mnt-by: ALFSERVIS-MNT
source: RIPE # Filtered

person: Jaromir Sebela
address: Okruzni 17,678 01 Blansko, Czech Republic
phone: +420603259683
nic-hdl: SEBE1-RIPE
mnt-by: ALFSERVIS-MNT
source: RIPE # Filtered

% Information related to '46.149.112.0/20AS52092'

route: 46.149.112.0/20
descr: Route object #1 AlfServis s.r.o.
origin: AS52092
mnt-by: ALFSERVIS-MNT
source: RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.70 (WHOIS1)

Regards,

Fail2Ban