Boa noite, hoje eu comprei uma vps para fins de estudo, então desculpe-me pela leiguice aushdfa. Eu estava dando uma olhada nos logs do ssh e vi que tem alguns Ips da Rússia, China e California, a maioria são de lugares aleatórios, tinha um da Rússia que dava em um cemitério, nem morto os bixo deixa a gente em paz, brincadeiras a parte :D. Queria saber se esses logs indicam alguma coisa, qual o significado e etc, acho que qualquer leigo como eu olharia esses logs e ficaria com medo ou algo do tipo kkkk.
Obs.: Alguns logs eu tive que cortar, pois tinha o meu IP Público.
Sep 6 18:10:50 srv417565 sshd[614]: error: kex_exchange_identification: banner line contains invalid characters
Sep 6 18:10:50 srv417565 sshd[614]: banner exchange: Connection from 59.120.224.187 port 16085: invalid format
Sep 6 18:10:58 srv417565 sshd[615]: Received disconnect from 59.120.224.187 port 59247:11: Bye Bye [preauth]
Sep 6 18:10:58 srv417565 sshd[615]: Disconnected from 59.120.224.187 port 59247 [preauth]
Sep 6 18:17:01 srv417565 CRON[621]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0)
Sep 6 18:17:01 srv417565 CRON[621]: pam_unix(cron:session): session closed for user root
Sep 6 18:20:54 srv417565 sshd[626]: error: kex_exchange_identification: banner line contains invalid characters
Sep 6 18:20:54 srv417565 sshd[626]: banner exchange: Connection from 177.201.193.33 port 47408: invalid format
Sep 6 18:21:05 srv417565 sshd[627]: Invalid user NL5xUDpV2xRa from 177.201.193.33 port 36124
Sep 6 18:21:05 srv417565 sshd[627]: fatal: userauth_pubkey: parse request failed: incomplete message [preauth]
Sep 6 19:22:56 srv417565 sshd[14583]: Connection closed by 195.112.113.205 port 42220
Sep 6 20:17:01 srv417565 CRON[14992]: pam_unix(cron:session): session opened for user root(uid=0) by (uid=0)
Sep 6 20:17:01 srv417565 CRON[14992]: pam_unix(cron:session): session closed for user root
Sep 6 20:23:03 srv417565 su: pam_unix(su:session): session closed for user root
Sep 6 21:42:51 srv417565 sshd[15027]: Connection closed by authenticating user root 157.230.143.105 port 48726 [preauth]
Sep 6 21:42:53 srv417565 sshd[15029]: Connection closed by authenticating user root 157.230.143.105 port 48732 [preauth]
Sep 6 21:42:54 srv417565 sshd[15031]: Connection closed by authenticating user root 157.230.143.105 port 39768 [preauth]
Sep 6 21:42:56 srv417565 sshd[15033]: Connection closed by authenticating user root 157.230.143.105 port 39774 [preauth]
Sep 6 21:42:57 srv417565 sshd[15035]: Connection closed by authenticating user root 157.230.143.105 port 39788 [preauth]
Sep 6 21:42:58 srv417565 sshd[15037]: Connection closed by authenticating user root 157.230.143.105 port 39796 [preauth]
Sep 6 21:43:00 srv417565 sshd[15039]: Connection closed by authenticating user root 157.230.143.105 port 39812 [preauth]
Sep 6 21:43:01 srv417565 sshd[15041]: Connection closed by authenticating user root 157.230.143.105 port 39824 [preauth]
Sep 6 21:43:03 srv417565 sshd[15043]: Connection closed by authenticating user root 157.230.143.105 port 39838 [preauth]
Sep 6 21:43:04 srv417565 sshd[15045]: Connection closed by authenticating user root 157.230.143.105 port 37630 [preauth]