Options:

Whois scanning my machine???

wadaw!!!
mesin ku kena scan!!!!
:(( huwaaaaaaaaaaaaaaaa

Mar 5 21:12:01 serv-slack01 sshd[954]: Did not receive identification string from 222.90.73.206
Mar 5 21:16:00 serv-slack01 sshd[956]: Invalid user 64studio from 222.90.73.206
Mar 5 21:16:00 serv-slack01 sshd[956]: Failed password for invalid user 64studio from 222.90.73.206 port 54991 ssh2
Mar 5 21:16:01 serv-slack01 sshd[959]: Invalid user 64studio from 222.90.73.206
Mar 5 21:16:02 serv-slack01 sshd[959]: Failed password for invalid user 64studio from 222.90.73.206 port 55307 ssh2
Mar 5 21:16:03 serv-slack01 sshd[962]: Invalid user aaliyah from 222.90.73.206
Mar 5 21:16:03 serv-slack01 sshd[962]: Failed password for invalid user aaliyah from 222.90.73.206 port 55511 ssh2
Mar 5 21:16:04 serv-slack01 sshd[965]: Invalid user aaliyah from 222.90.73.206
Mar 5 21:16:04 serv-slack01 sshd[965]: Failed password for invalid user aaliyah from 222.90.73.206 port 55664 ssh2
Mar 5 21:16:06 serv-slack01 sshd[968]: Invalid user aaliyah from 222.90.73.206
Mar 5 21:16:06 serv-slack01 sshd[968]: Failed password for invalid user aaliyah from 222.90.73.206 port 55824 ssh2
Mar 5 21:16:07 serv-slack01 sshd[971]: Invalid user aaliyah from 222.90.73.206
… … …

Mar 5 21:21:45 serv-slack01 sshd[1692]: Failed password for invalid user sales from 61.78.36.229 port 38280 ssh2
Mar 5 21:21:46 serv-slack01 sshd[1695]: Invalid user admin from 222.90.73.206
Mar 5 21:21:46 serv-slack01 sshd[1695]: Failed password for invalid user admin from 222.90.73.206 port 57210 ssh2
Mar 5 21:21:47 serv-slack01 sshd[1698]: Invalid user admin from 61.78.36.229
Mar 5 21:21:47 serv-slack01 sshd[1698]: Failed password for invalid user admin from 61.78.36.229 port 38412 ssh2
Mar 5 21:21:48 serv-slack01 sshd[1701]: Invalid user admin from 222.90.73.206
Mar 5 21:21:48 serv-slack01 sshd[1701]: Failed password for invalid user admin from 222.90.73.206 port 57697 ssh2
Mar 5 21:21:49 serv-slack01 sshd[1704]: Invalid user andrea from 61.78.36.229
Mar 5 21:21:49 serv-slack01 sshd[1704]: Failed password for invalid user andrea from 61.78.36.229 port 38493 ssh2
Mar 5 21:21:51 serv-slack01 sshd[1708]: Invalid user admin from 222.90.73.206
Mar 5 21:21:51 serv-slack01 sshd[1708]: Failed password for invalid user admin from 222.90.73.206 port 57999 ssh2
Mar 5 21:21:51 serv-slack01 sshd[1710]: Invalid user backup from 61.78.36.229
Mar 5 21:21:51 serv-slack01 sshd[1710]: Failed password for invalid user backup from 61.78.36.229 port 38608 ssh2
Mar 5 21:21:53 serv-slack01 sshd[1714]: Invalid user admin from 222.90.73.206
Mar 5 21:21:53 serv-slack01 sshd[1714]: Failed password for invalid user admin from 222.90.73.206 port 58562 ssh2
Mar 5 21:21:53 serv-slack01 sshd[1715]: Invalid user guest from 61.78.36.229
Mar 5 21:21:53 serv-slack01 sshd[1715]: Failed password for invalid user guest from 61.78.36.229 port 38713 ssh2
Mar 5 21:21:55 serv-slack01 sshd[1723]: Invalid user guest1 from 61.78.36.229
Mar 5 21:21:55 serv-slack01 sshd[1721]: Invalid user admin from 222.90.73.206
… … …

ada 2 IP yang scanning, 222.90.73.206 + 61.78.36.229

root@serv-slack01:~# whois 222.90.73.206
% [whois.apnic.net node-1]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

inetnum: 222.90.0.0 - 222.91.255.255
netname: CHINANET-SN
descr: CHINANET shanxi(SN) province network
descr: China Telecom
descr: A12,Xin-Jie-Kou-Wai Street
descr: Beijing 100088
country: CN
admin-c: CH93-AP
tech-c: XC10-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-CHINANET-SHAANXI
mnt-routes: MAINT-CHINANET-SHAANXI
remarks: This object can only modify by APNIC hostmaster
remarks: If you wish to modify this object details please
remarks: send email to hostmaster@apnic.net with your
remarks: organisation account name in the subject line.
changed: hm-changed@apnic.net 20040224
status: ALLOCATED PORTABLE
source: APNIC

person: Chinanet Hostmaster
nic-hdl: CH93-AP
e-mail: anti-spam@ns.chinanet.cn.net
address: No.31 ,jingrong street,beijing
address: 100032
phone: +86-10-58501724
fax-no: +86-10-58501724
country: CN
changed: lqing@chinatelecom.com.cn 20051212
mnt-by: MAINT-CHINANET
source: APNIC

person: Xianghong Cao
address: Shaanxi province data communication Bureau
address: 8# guangde Road west development zone
address: Xi’an city, Shanxi province 710075
address: CN
phone: +8629-837-1049
fax-no: +8629-837-1049
e-mail: IPADM@PUBLIC.XA.SN.CN
nic-hdl: XC10-AP
mnt-by: MAINT-CHINANET-SHAANXI
changed: IPADM@PUBLIC.XA.SN.CN 20011203
source: APNIC
root@serv-slack01:~# whois 61.78.36.229
Çѱ¹ÀÎÅͳÝÁøÈï¿ø(NIDA)ÀÇ ÀÎÅͳÝÁ¤º¸¼¾ÅÍ(KRNIC)°¡ Á¦°øÇÏ´Â Whois ¼­ºñ½º ÀÔ´Ï´Ù.

query: 61.78.36.229

# KOREAN

Á¶È¸°á°ú´Â ¾Æ·¡¿Í °°À¸¸ç, ½ÇÁ¦ Á¤º¸¿Í »óÀÌÇÒ ¼ö ÀÖ½À´Ï´Ù.

IPv4 ÁÖ¼Ò : 61.78.36.0-61.78.36.255
³×Æ®¿öÅ© À̸§ : KORNET-INFRA000001
¿¬°á ISP¸í : KORNET
ÇÒ´ç³»¿ª µî·ÏÀÏ : 20060405
ÇÒ´çÁ¤º¸°ø°³¿©ºÎ : N

[ IPv4 »ç¿ë ±â°ü Á¤º¸ ]
±â°ü°íÀ¯¹øÈ£ : ORG1600
±â°ü¸í : (ÁÖ)ÄÉÀÌÆ¼
ÁÖ¼Ò : ¼º³²½Ã ºÐ´ç±¸ Á¤ÀÚµ¿
¿ìÆí ¹øÈ£ : 463-711

[ ³×Æ®¿öÅ© ´ã´çÀÚ Àι° Á¤º¸ ]
±â°ü¸í : KORNET
ÁÖ¼Ò : ¼º³²½Ã ºÐ´ç±¸ Á¤ÀÚµ¿
¿ìÆí ¹øÈ£ : 463-711
ÀüÀÚ ¿ìÆí : ip@krnic.kornet.net

——————————————————————————–

¸¸¾à À§ÀÇ IPv4ÁÖ¼Ò »ç¿ë±â°ü Á¤º¸°¡ ¿Ã¹Ù¸£Áö ¾ÊÀ» °æ¿ì
¾Æ·¡ÀÇ ÇØ´ç ¿¬°á ISP ´ç´çÀÚ¿¡°Ô ¹®ÀÇÇϽñ⠹ٶø´Ï´Ù.

[ ¿¬°áISPÀÇ IPv4ÁÖ¼Ò Ã¥ÀÓÀÚ Á¤º¸ ]
À̸§ : IPÁÖ¼Ò°ü¸®ÀÚ
ÀüÈ­ ¹øÈ£ : +82-2-3674-5708
ÀüÀÚ ¿ìÆí : ip@krnic.kornet.net

[ ¿¬°áISPÀÇ IPv4ÁÖ¼Ò °ü¸®ÀÚ Á¤º¸ ]
À̸§ : IPÁÖ¼Ò´ã´çÀÚ
ÀüÈ­ ¹øÈ£ : +82-2-3674-5708
ÀüÀÚ ¿ìÆí : ip@krnic.kornet.net

[ ¿¬°áISPÀÇ Network Abuse ´ã´çÀÚ Á¤º¸ ]
À̸§ : ½ºÆÔ/ÇØÅ·´ã´ç
ÀüÈ­ ¹øÈ£ : +82-2-100-0000
ÀüÀÚ ¿ìÆí : abuse@kornet.net

# ENGLISH

KRNIC is not an ISP but a National Internet Registry similar to APNIC.
The followings is organization information that is using the IPv4 address.

IPv4 Address : 61.78.36.0-61.78.36.255
Network Name : KORNET-INFRA000001
Connect ISP Name : KORNET
Registration Date : 20060405
Publishes : N

[ Organization Information ]
Organization ID : ORG1600
Org Name : Korea Telecom
Address : Jungja-dong, Bundang-gu, Sungnam-ci
Zip Code : 463-711

[ Technical Contact Information ]
Org Name : Korea Telecom
Address : Jungja-dong, Bundang-gu, Sungnam-ci
Zip Code : 463-711
E-Mail : ip@krnic.kornet.net

——————————————————————————–

If the above contacts are not reachable, please contact following ISP
for further information.

[ ISP IPv4 Admin Contact Information ]
Name : IP Administrator
Phone : +82-2-3674-5708
E-Mail : ip@krnic.kornet.net

[ ISP IPv4 Tech Contact Information ]
Name : IP Manager
Phone : +82-2-3674-5708
E-Mail : ip@krnic.kornet.net

[ ISP Network Abuse Contact Information ]
Name : Network Abuse
Phone : +82-2-100-0000
E-Mail : abuse@kornet.net

Asem asem asem!!!
Kopeds!!!
Asuw!!!
Anjeeeeng!!!

Leave a Reply