Hack Attempts Stats
Some stats on the latest hack attempts of my own server hosting various community online services.
TOP Per Country
- 🇨🇳 CN - China (243 IPs)
- 🇩🇪 DE - Germany (140 IPs)
- 🇺🇸 US - United States of America (87 IPs)
- 🇷🇺 RU - Russian Federation (67 IPs)
- 🇬🇧 GB - United Kingdom of Great Britain and Northern Ireland (41 IPs)
- 🇳🇱 NL - Netherlands (40 IPs)
- 🇻🇳 VN - Viet Nam (35 IPs)
- 🇫🇷 FR - France (33 IPs)
- 🇭🇰 HK - Hong Kong (32 IPs)
- 🇧🇷 BR - Brazil (29 IPs)
- 🇮🇩 ID - Indonesia (25 IPs)
- 🇺🇦 UA - Ukraine (22 IPs)
- 🇰🇷 KR - Korea (Republic of) (21 IPs)
- 🇮🇳 IN - India (20 IPs)
- 🇸🇬 SG - Singapore (18 IPs)
- 🇲🇽 MX - Mexico (17 IPs)
- 🇲🇦 MA - Morocco (17 IPs)
- 🇮🇷 IR - Iran (Islamic Republic of) (17 IPs)
- 🇵🇰 PK - Pakistan (14 IPs)
- 🇵🇱 PL - Poland (14 IPs)
- ... 67 more
TOP Per Country + ISP
- 🇩🇪 Contabo GmbH - DE - Germany (63 IPs)
- 🇨🇳 China Mobile Communications Corporation - CN - China (26 IPs)
- 🇨🇳 Tencent Cloud Computing (Beijing) Co. Ltd. - CN - China (24 IPs)
- 🇫🇷 OVH SAS - FR - France (19 IPs)
- 🇨🇳 Tencent Cloud Computing (Beijing) Co. Ltd - CN - China (19 IPs)
- 🇲🇦 Maroc Telecom - MA - Morocco (17 IPs)
- 🇷🇺 LIR Limited - RU - Russian Federation (17 IPs)
- 🇨🇳 ChinaNet Guangdong Province Network - CN - China (17 IPs)
- 🇮🇩 PT Telkom Indonesia - ID - Indonesia (17 IPs)
- 🇨🇳 ChinaNet Yunnan Province Network - CN - China (16 IPs)
- 🇨🇳 ChinaNet Shandong Province Network - CN - China (14 IPs)
- 🇺🇸 rdpdaddy.com - US - United States of America (14 IPs)
- 🇭🇰 Contabo GmbH - HK - Hong Kong (14 IPs)
- 🇰🇷 KT Corporation - KR - Korea (Republic of) (14 IPs)
- 🇳🇱 Alexander Valerevich Mokhonko - NL - Netherlands (14 IPs)
- 🇨🇳 Shanghai UCloud Information Technology Company Limited - CN - China (10 IPs)
- 🇪🇬 TE Data - EG - Egypt (9 IPs)
- 🇩🇪 Tube Hosting - DE - Germany (9 IPs)
- 🇻🇳 Vietnam Posts and Telecommunications Group - VN - Viet Nam (8 IPs)
- 🇬🇧 Contabo GmbH - GB - United Kingdom of Great Britain and Northern Ireland (8 IPs)
- 🇹🇼 Chunghwa Telecom Co. Ltd. - TW - Taiwan (Province of China) (8 IPs)
- 🇺🇸 Google LLC - US - United States of America (8 IPs)
- 🇬🇧 British Telecommunications PLC - GB - United Kingdom of Great Britain and Northern Ireland (8 IPs)
- 🇧🇪 FlyServers S.A. - BE - Belgium (7 IPs)
- 🇨🇳 ChinaNet Zhejiang Province Network - CN - China (7 IPs)
- 🇨🇳 ChinaNet Jiangsu Province Network - CN - China (7 IPs)
- 🇩🇪 SC Lithuanian Radio and TV Center - DE - Germany (7 IPs)
- 🇷🇺 Express Courier LLC - RU - Russian Federation (6 IPs)
- 🇨🇳 ChinaNet Fujian Province Network - CN - China (6 IPs)
- 🇵🇭 Philippine Long Distance Telephone Company - PH - Philippines (6 IPs)
- 🇨🇳 Aliyun Computing Co. Ltd - CN - China (6 IPs)
- 🇩🇪 Privax Ltd - DE - Germany (6 IPs)
- 🇩🇪 AVAST Slovakia s.r.o. - DE - Germany (5 IPs)
- 🇳🇱 Veraton Projects Ltd. - NL - Netherlands (5 IPs)
- 🇲🇽 Uninet - MX - Mexico (5 IPs)
- 🇨🇳 ChinaNet Jiangxi Province Network - CN - China (5 IPs)
- 🇧🇿 FlyServers S.A. - BZ - Belize (5 IPs)
- 🇷🇺 IPX - FZCO - RU - Russian Federation (5 IPs)
- 🇨🇳 ChinaNet Shanghai Province Network - CN - China (5 IPs)
- 🇮🇳 Bharti Airtel Ltd. - IN - India (5 IPs)
- 🇬🇧 Information & Computing Center Ltd. - GB - United Kingdom of Great Britain and Northern Ireland (5 IPs)
- 🇨🇳 Shenzhen Qianhai bird cloud computing Co. Ltd. - CN - China (4 IPs)
- 🇩🇪 Hetzner Online GmbH - DE - Germany (4 IPs)
- 🇨🇳 ChinaNet Hubei Province Network - CN - China (4 IPs)
- 🇩🇪 DataDelivery s.r.o. - DE - Germany (4 IPs)
- 🇲🇽 Gestion de Direccionamiento Uninet - MX - Mexico (4 IPs)
- 🇺🇸 ColoCrossing - US - United States of America (4 IPs)
- 🇨🇳 China Unicom Henan Province Network - CN - China (4 IPs)
- 🇷🇺 OOO Network of Data-Centers Selectel - RU - Russian Federation (4 IPs)
- 🇺🇸 OVH US LLC - US - United States of America (4 IPs)
- ... 499 more
Some Context
- Hack Attempt Logs are from the last two months (Mid-November '23 to Mid-January '24).
- IP geographic location details acquired via https://www.iplocation.net/.
- My attacked server's data center is located 📍 in Germany, Europe 🇩🇪.
- Some traffic was most likely routed through legit countries and ISPs even though it originated from sketch ones 🇷🇺🔀🇺🇸. Even more so since I progressively blocked malicious IP ranges. This would explain high traffic from such countries, especially from Germany since that's the location of my server.
- Attempts were of brute-force kind (credentials trial-and-error). Targeting server login (ssh, mstsc), database login (sqlserver, mysql, oracle, postgres, etc.) and such.