PULSE NAME
SSH Brute-Force IPs from fail2ban 2026-04-14
WHITE jinghua_dream 2026-04-15 Modified: 2026-04-22
0
IOCs
LOW VOLUME
SUMMARY: The VPS is located in DigitalOcean's Clifton data center. UTC+1:00 updates previous day's records. CC, ASN, latitude, longitude, based on GeoLite2-related data. | WARNING: Since 2026-03-27, attackers switched from brute-force to PROTOCOL PROBING (TCP Resets/Malformed Packets). This bypasses default SSH filters. | ACTION: Switch Fail2Ban to 'sshd[mode=aggressive]' to mitigate. | CONTEXT: Potential CVE-2024-6387 activity.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
SSH Brute-Force
Indicators of Compromise (0)
All
No indicators.