Возвращаясь к вчерашнему моему посту
Вот лог с удаленного роутера на который ломились пока не отрубил порт наружу
00:01:43 14-05-2017 (warning|authpriv|dropbear) dropbear[1144]: Bad password attempt for \'root\' from 94.248.7.206:41568
00:01:43 14-05-2017 (warning|authpriv|dropbear) dropbear[1144]: Bad password attempt for \'root\' from 94.248.7.206:41568
Вот лог с домашнего роутера
May 14 14:34:27 atom sshd[16110]: pam_winbind(sshd:auth): pam_get_item returned a password
May 14 14:34:27 atom sshd[16110]: pam_winbind(sshd:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
May 14 14:34:30 atom sshd[16110]: Failed password for root from 61.177.172.60 port 10443 ssh2
May 14 14:34:30 atom sshd[16110]: Received disconnect from 61.177.172.60: 11: [preauth]
May 14 14:34:30 atom sshd[16110]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.177.172.60 user=root
May 14 14:34:51 atom sshd[16125]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=61.177.172.60 user=root
May 14 14:34:51 atom sshd[16125]: pam_winbind(sshd:auth): getting password (0x00000388)
May 14 14:34:51 atom sshd[16125]: pam_winbind(sshd:auth): pam_get_item returned a password
May 14 14:34:51 atom sshd[16125]: pam_winbind(sshd:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
May 14 14:34:53 atom sshd[16125]: Failed password for root from 61.177.172.60 port 33498 ssh2
May 14 14:34:54 atom sshd[16125]: pam_winbind(sshd:auth): getting password (0x00000388)
May 14 14:34:54 atom sshd[16125]: pam_winbind(sshd:auth): pam_get_item returned a password
May 14 14:34:54 atom sshd[16125]: pam_winbind(sshd:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
May 14 14:34:55 atom sshd[16125]: Failed password for root from 61.177.172.60 port 33498 ssh2
May 14 14:34:56 atom sshd[16125]: pam_winbind(sshd:auth): getting password (0x00000388)
May 14 14:34:56 atom sshd[16125]: pam_winbind(sshd:auth): pam_get_item returned a password
May 14 14:34:56 atom sshd[16125]: pam_winbind(sshd:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_USER_UNKNOWN (10), NTSTATUS: NT_STATUS_NO_SUCH_USER, Error message was: No such user
May 14 14:34:58 atom sshd[16125]: Failed password for root from 61.177.172.60 port 33498 ssh2
May 14 14:34:59 atom sshd[16125]: Received disconnect from 61.177.172.60: 11: [preauth]
Айпишники аццкие, напоминают сборник левых проксей по всему миру.
Долбят прямо сейчас, благо там антибрут везде и перебирать будут до седьмого пришествия. Чисто интересно активность пошла синхронно с распространением заразы. Может шифровальщик это лишь верхушка айсберга.