how to deal with port scan and brute force attack from AS 8075 ?
Bacon Zombie
baconzombie at gmail.com
Thu Mar 31 09:36:51 UTC 2016
I would ignore the portscans since there is nothing wrong with portscanning
the Internet.
Install fail2ban {don't forgot to whitelist your management static IPs}.
You may want to increase the default bantime and findtime {how far back to
search logs}.
On 31 Mar 2016 11:06, "Todd Crane" <todd.crane at n5tech.com> wrote:
> >>>>
> >>>> We are facing a lot of port scan and brute force attack on port 22
> (but
> >>>> not limited to) from Microsoft AS 8075 range toward our own infra, or
> >>>> toward our customers.
> >>>> We have sent email to abuse at microsoft.com, but no answer.
> >>>> source ip are:
> >>>> NetRange: 40.74.0.0 - 40.125.127.255
> >>>> CIDR: 40.74.0.0/15, 40.112.0.0/13, 40.124.0.0/16,
> >>>> 40.76.0.0/14, 40.80.0.0/12, 40.125.0.0/17, 40.96.0.0/12,
> 40.120.0.0/14
> >>>> NetName: MSFT
> >>>> He are some examples (we have more than 3000 such packets per day just
> >>>> from them, probably Azure), and source ip is always differents of
> course:
> >>>> Date_first_seen Duration Proto _IP_Addr:Port
> >>>> Dst_IP_Addr:Port Flags Packets
> >>>> 2016-02-29 14:55:20.108 0.000 6 104.45.210.69:1160 ->
> >>>> x.x.231:22 ...... 1
> >>>> 2016-02-29 14:55:20.611 0.000 6 104.45.210.69:1161 ->
> >>>> x.x.231:22 ...... 1
> >>>> 2016-02-29 14:56:41.004 0.000 6 40.76.55.204:1090 ->
> >>>> x.x..14:22 ...... 1
> >>>> 2016-02-29 14:56:41.324 0.000 6 40.76.55.204:1091 ->
> >>>> x.x..14:22 ...... 1
> >>>> 2016-02-29 15:00:05.670 0.000 6 40.76.55.204:1088 ->
> >>>> x.x.125:22 ...... 1
> >>>> 2016-02-29 15:00:06.003 0.000 6 40.76.55.204:1089 ->
> >>>> x.x.125:22 ...... 1
> >>>> 2016-02-29 15:01:17.358 0.000 6 40.76.70.58:1168 ->
> >>>> x.x..80:22 ...... 1
> >>>> 2016-02-29 15:01:17.676 0.000 6 40.76.70.58:1169 ->
> >>>> x.x..80:22 ...... 1
> >>>> 2016-02-29 15:02:42.637 0.000 6 40.76.55.204:1176 ->
> >>>> x.x.193:22 ...... 1
> >>>> 2016-02-29 15:02:42.878 0.000 6 40.76.55.204:1177 ->
> >>>> x.x.193:22 ...... 1
