Good day all,
what do you think about this scenario on my network:
My LOG is reporting some login failures:
12:25:12 system,error,critical login failure for user root from 61.174.51.209 via ssh
12:25:13 system,error,critical login failure for user root from 61.174.51.209 via ssh
11:35:49 system,error,critical login failure for user zabbix from 101.227.246.74 via ssh
11:35:56 system,error,critical login failure for user zabbix from 101.227.246.74 via ssh
11:36:02 system,error,critical login failure for user zabbix from 101.227.246.74 via ssh
The same IP's are showing different names for login attempts
My connect tracking shows a lot of syn-sent :
this is just an example:
1674 S tcp 222.186.21.43:65265 197.235.8.114:8080 syn-recv 2m36s
1675 udp 128.195.65.13:10503 197.235.8.114:53 2m28s
1676 SA udp 24.192.180.233:3414 197.235.8.114:53 22s
1677 tcp 111.74.238.172:11850 197.235.8.114:8080 syn-sent 2m33s
1678 udp 128.195.65.13:56387 197.235.8.114:53 2m28s
1679 SA tcp 111.73.45.56:55207 197.235.8.114:8080 established 23h57m26s
1680 SA udp 128.195.65.13:37582 197.235.8.114:53 25s
1681 tcp 61.160.212.165:36455 197.235.8.114:8080 syn-sent 2m30s
1682 tcp 58.218.199.67:50017 197.235.8.114:8080 syn-sent 2m29s
1683 S tcp 60.169.77.202:51534 197.235.8.114:8080 syn-recv 2m28s
1684 udp 128.195.65.13:14278 197.235.8.114:53 2m22s
1685 SA udp 84.118.240.21:44624 197.235.8.114:53 29s
1686 SA udp 186.223.47.27:55770 197.235.8.114:53 31s
1687 S tcp 115.239.231.76:14941 197.235.8.114:8080 syn-recv 2m24s
1688 tcp 222.186.21.43:6307 197.235.8.114:8080 syn-sent 2m22s
1689 tcp 197.235.8.114:43998 221.228.209.164:801 syn-sent 2m22s
1690 udp 128.195.65.13:24974 197.235.8.114:53 2m17s
1691 tcp 61.160.207.163:9003 197.235.8.114:8080 syn-sent 2m20s
1692 tcp 183.136.214.125:20905 197.235.8.114:8080 syn-sent 2m19s
1693 udp 128.195.65.13:46960 197.235.8.114:53 2m14s
1694 SA udp 84.118.240.21:2375 197.235.8.114:53 37s
1695 SA tcp 58.218.204.37:54974 197.235.8.114:8080 established 23h57m38s
1696 SA tcp 111.73.46.94:18844 197.235.8.114:8080 established 23h57m38s
1697 SA udp 77.181.125.194:19154 197.235.8.114:53 39s
1698 SA udp 128.195.65.13:30442 197.235.8.114:53 40s
1699 udp 24.192.180.233:26163 197.235.8.114:53 2m10s
1700 SA tcp 197.235.8.114:53515 2.20.49.194:443 established 23h57m26s
1701 S tcp 23.245.116.37:24003 197.235.8.114:8080 syn-recv 2m30s
1702 udp 128.195.65.13:50726 197.235.8.114:53 2m25s
1703 tcp 79.129.32.29:63507 197.235.8.114:8080 syn-sent 2m30s
1704 S tcp 108.46.235.84:55524 197.235.8.114:8080 syn-recv 2m29s
And i have a lot of data drops as invalid as you can see on the screenshot
is this anything to worry about or it is normal?