105 port 35463 Oct 5 19:46:15 ip-172-31-29-215 sshd[3924469]: Received disconnect from 103.153.190.105 port 35463:11: Bye Bye [preauth] Oct 5 19:46:15 ip-172-31-29-215 sshd[3924469]: Disconnected from invalid user penis 103.153.190.105 port 35463 [preauth] Oct 5 19:49:02 ip-172-31-29-215 sshd[3924473]: Invalid user aptuslegal from 142.93.73.173 port 40788 Oct 5 19:49:02 ip-172-31-29-215 sshd[3924473]: Connection closed by invalid user aptuslegal 142.93.73.173 port 40788 [preauth] Oct 5 19:49:48 ip-172-31-29-215 sshd[3924478]: Invalid user linda from 103.153.190.105 port 42009 Oct 5 19:49:49 ip-172-31-29-215 sshd[3924478]: Received disconnect from 103.153.190.105 port 42009:11: Bye Bye [preauth] Oct 5 19:49:49 ip-172-31-29-215 sshd[3924478]: Disconnected from invalid user linda 103.153.190.105 port 42009 [preauth] Oct 5 19:50:16 ip-172-31-29-215 sshd[3924480]: Connection closed by authenticating user root 34.72.109.56 port 39252 [preauth] Oct 5 19:53:20 ip-172-31-29-215 sshd[3924489]: Invalid user cantor from 103.153.190.105 port 45176 Oct 5 19:53:20 ip-172-31-29-215 sshd[3924489]: Received disconnect from 103.153.190.105 port 45176:11: Bye Bye [preauth] Oct 5 19:53:20 ip-172-31-29-215 sshd[3924489]: Disconnected from invalid user cantor 103.153.190.105 port 45176 [preauth] Oct 5 19:54:06 ip-172-31-29-215 sshd[3924495]: error: kex_exchange_identification: client sent invalid protocol identifier "GET / HTTP/1.1" Oct 5 19:56:49 ip-172-31-29-215 sshd[3924499]: Invalid user asm from 103.153.190.105 port 48473 Oct 5 19:56:49 ip-172-31-29-215 sshd[3924499]: Received disconnect from 103.153.190.105 port 48473:11: Bye Bye [preauth] Oct 5 19:56:49 ip-172-31-29-215 sshd[3924499]: Disconnected from invalid user asm 103.153.190.105 port 48473 [preauth] Oct 5 19:57:16 ip-172-31-29-215 sshd[3924501]: Invalid user aptuslegal from 162.240.61.39 port 37214 Oct 5 19:57:16 ip-172-31-29-215 sshd[3924501]: Connection closed by invalid user aptuslegal 162.240.61.39 port 37214 [preauth] Oct 5 20:00:01 ip-172-31-29-215 CRON[3924507]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 20:00:01 ip-172-31-29-215 CRON[3924507]: pam_unix(cron:session): session closed for user smmsp Oct 5 20:04:04 ip-172-31-29-215 sshd[3924530]: Invalid user admin from 103.188.167.170 port 34352 Oct 5 20:04:04 ip-172-31-29-215 sshd[3924530]: Connection closed by invalid user admin 103.188.167.170 port 34352 [preauth] Oct 5 20:09:01 ip-172-31-29-215 CRON[3924535]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 20:09:01 ip-172-31-29-215 CRON[3924535]: pam_unix(cron:session): session closed for user root Oct 5 20:16:38 ip-172-31-29-215 sshd[3924627]: Invalid user gouge from 45.78.226.118 port 60750 Oct 5 20:16:39 ip-172-31-29-215 sshd[3924627]: Received disconnect from 45.78.226.118 port 60750:11: Bye Bye [preauth] Oct 5 20:16:39 ip-172-31-29-215 sshd[3924627]: Disconnected from invalid user gouge 45.78.226.118 port 60750 [preauth] Oct 5 20:17:01 ip-172-31-29-215 CRON[3924629]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 20:17:01 ip-172-31-29-215 CRON[3924629]: pam_unix(cron:session): session closed for user root Oct 5 20:17:37 ip-172-31-29-215 sshd[3924632]: Invalid user random from 138.248.168.20 port 39060 Oct 5 20:17:38 ip-172-31-29-215 sshd[3924632]: Received disconnect from 138.248.168.20 port 39060:11: Bye Bye [preauth] Oct 5 20:17:38 ip-172-31-29-215 sshd[3924632]: Disconnected from invalid user random 138.248.168.20 port 39060 [preauth] Oct 5 20:19:37 ip-172-31-29-215 sshd[3924636]: Invalid user venus from 138.248.168.20 port 56140 Oct 5 20:19:37 ip-172-31-29-215 sshd[3924636]: Received disconnect from 138.248.168.20 port 56140:11: Bye Bye [preauth] Oct 5 20:19:37 ip-172-31-29-215 sshd[3924636]: Disconnected from invalid user venus 138.248.168.20 port 56140 [preauth] Oct 5 20:19:56 ip-172-31-29-215 sshd[3924639]: Invalid user charity from 45.78.226.118 port 57276 Oct 5 20:19:57 ip-172-31-29-215 sshd[3924639]: Received disconnect from 45.78.226.118 port 57276:11: Bye Bye [preauth] Oct 5 20:19:57 ip-172-31-29-215 sshd[3924639]: Disconnected from invalid user charity 45.78.226.118 port 57276 [preauth] Oct 5 20:20:01 ip-172-31-29-215 CRON[3924641]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 20:20:01 ip-172-31-29-215 CRON[3924641]: pam_unix(cron:session): session closed for user smmsp Oct 5 20:21:05 ip-172-31-29-215 sshd[3924664]: Invalid user kristi from 138.248.168.20 port 37784 Oct 5 20:21:05 ip-172-31-29-215 sshd[3924664]: Received disconnect from 138.248.168.20 port 37784:11: Bye Bye [preauth] Oct 5 20:21:05 ip-172-31-29-215 sshd[3924664]: Disconnected from invalid user kristi 138.248.168.20 port 37784 [preauth] Oct 5 20:21:14 ip-172-31-29-215 sshd[3924666]: Connection closed by authenticating user root 202.10.45.202 port 48058 [preauth] Oct 5 20:22:37 ip-172-31-29-215 sshd[3924668]: Received disconnect from 45.78.226.118 port 46842:11: Bye Bye [preauth] Oct 5 20:22:37 ip-172-31-29-215 sshd[3924668]: Disconnected from 45.78.226.118 port 46842 [preauth] Oct 5 20:22:46 ip-172-31-29-215 sshd[3924670]: Invalid user penelope from 138.248.168.20 port 47666 Oct 5 20:22:46 ip-172-31-29-215 sshd[3924670]: Received disconnect from 138.248.168.20 port 47666:11: Bye Bye [preauth] Oct 5 20:22:46 ip-172-31-29-215 sshd[3924670]: Disconnected from invalid user penelope 138.248.168.20 port 47666 [preauth] Oct 5 20:25:00 ip-172-31-29-215 sshd[3924673]: Invalid user egghead from 45.78.226.118 port 40510 Oct 5 20:25:00 ip-172-31-29-215 sshd[3924673]: Received disconnect from 45.78.226.118 port 40510:11: Bye Bye [preauth] Oct 5 20:25:00 ip-172-31-29-215 sshd[3924673]: Disconnected from invalid user egghead 45.78.226.118 port 40510 [preauth] Oct 5 20:26:51 ip-172-31-29-215 sshd[3924676]: Connection closed by authenticating user root 144.91.93.34 port 59236 [preauth] Oct 5 20:31:31 ip-172-31-29-215 sshd[3924682]: Connection closed by authenticating user root 161.97.186.240 port 58542 [preauth] Oct 5 20:39:01 ip-172-31-29-215 CRON[3924687]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 20:39:01 ip-172-31-29-215 CRON[3924687]: pam_unix(cron:session): session closed for user root Oct 5 20:39:31 ip-172-31-29-215 sshd[3924742]: Connection closed by authenticating user root 51.77.151.101 port 45600 [preauth] Oct 5 20:39:42 ip-172-31-29-215 sshd[3924745]: Invalid user admin from 34.72.109.56 port 39364 Oct 5 20:39:42 ip-172-31-29-215 sshd[3924745]: Connection closed by invalid user admin 34.72.109.56 port 39364 [preauth] Oct 5 20:40:01 ip-172-31-29-215 CRON[3924747]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 20:40:01 ip-172-31-29-215 CRON[3924747]: pam_unix(cron:session): session closed for user smmsp Oct 5 20:43:31 ip-172-31-29-215 sshd[3924769]: Invalid user aptuslegal from 162.240.61.39 port 54542 Oct 5 20:43:31 ip-172-31-29-215 sshd[3924769]: Connection closed by invalid user aptuslegal 162.240.61.39 port 54542 [preauth] Oct 5 20:44:40 ip-172-31-29-215 sshd[3924772]: Connection closed by authenticating user root 171.244.62.70 port 40820 [preauth] Oct 5 20:46:25 ip-172-31-29-215 sshd[3924774]: Invalid user aptuslegal from 59.24.133.197 port 46930 Oct 5 20:46:25 ip-172-31-29-215 sshd[3924774]: Connection closed by invalid user aptuslegal 59.24.133.197 port 46930 [preauth] Oct 5 21:00:01 ip-172-31-29-215 CRON[3924785]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 21:00:01 ip-172-31-29-215 CRON[3924785]: pam_unix(cron:session): session closed for user smmsp Oct 5 21:00:01 ip-172-31-29-215 sshd[3924783]: Invalid user teamspeak from 180.76.134.56 port 57980 Oct 5 21:00:02 ip-172-31-29-215 sshd[3924783]: Received disconnect from 180.76.134.56 port 57980:11: Bye Bye [preauth] Oct 5 21:00:02 ip-172-31-29-215 sshd[3924783]: Disconnected from invalid user teamspeak 180.76.134.56 port 57980 [preauth] Oct 5 21:00:27 ip-172-31-29-215 sshd[3924807]: error: kex_exchange_identification: Connection closed by remote host Oct 5 21:00:37 ip-172-31-29-215 sshd[3924808]: error: kex_exchange_identification: Connection closed by remote host Oct 5 21:00:52 ip-172-31-29-215 sshd[3924809]: error: kex_exchange_identification: banner line contains invalid characters Oct 5 21:00:55 ip-172-31-29-215 sshd[3924810]: error: kex_exchange_identification: Connection closed by remote host Oct 5 21:06:26 ip-172-31-29-215 sshd[3924813]: Invalid user steam from 180.76.134.56 port 47164 Oct 5 21:06:26 ip-172-31-29-215 sshd[3924813]: Received disconnect from 180.76.134.56 port 47164:11: Bye Bye [preauth] Oct 5 21:06:26 ip-172-31-29-215 sshd[3924813]: Disconnected from invalid user steam 180.76.134.56 port 47164 [preauth] Oct 5 21:07:16 ip-172-31-29-215 sshd[3924816]: Connection closed by 91.196.152.96 port 53241 [preauth] Oct 5 21:09:01 ip-172-31-29-215 CRON[3924821]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 21:09:01 ip-172-31-29-215 CRON[3924821]: pam_unix(cron:session): session closed for user root Oct 5 21:09:51 ip-172-31-29-215 sshd[3924877]: Invalid user melissa from 138.248.168.20 port 41032 Oct 5 21:09:51 ip-172-31-29-215 sshd[3924877]: Received disconnect from 138.248.168.20 port 41032:11: Bye Bye [preauth] Oct 5 21:09:51 ip-172-31-29-215 sshd[3924877]: Disconnected from invalid user melissa 138.248.168.20 port 41032 [preauth] Oct 5 21:11:31 ip-172-31-29-215 sshd[3924880]: Invalid user bananas from 138.248.168.20 port 50922 Oct 5 21:11:31 ip-172-31-29-215 sshd[3924880]: Received disconnect from 138.248.168.20 port 50922:11: Bye Bye [preauth] Oct 5 21:11:31 ip-172-31-29-215 sshd[3924880]: Disconnected from invalid user bananas 138.248.168.20 port 50922 [preauth] Oct 5 21:12:24 ip-172-31-29-215 sshd[3924883]: error: kex_exchange_identification: read: Connection reset by peer Oct 5 21:12:41 ip-172-31-29-215 sshd[3924884]: error: kex_exchange_identification: Connection closed by remote host Oct 5 21:17:01 ip-172-31-29-215 CRON[3924886]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 21:17:01 ip-172-31-29-215 CRON[3924886]: pam_unix(cron:session): session closed for user root Oct 5 21:20:01 ip-172-31-29-215 CRON[3924891]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 21:20:01 ip-172-31-29-215 CRON[3924891]: pam_unix(cron:session): session closed for user smmsp Oct 5 21:28:58 ip-172-31-29-215 sshd[3924916]: Connection closed by authenticating user root 34.72.109.56 port 52730 [preauth] Oct 5 21:39:01 ip-172-31-29-215 CRON[3924977]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 21:39:01 ip-172-31-29-215 CRON[3924977]: pam_unix(cron:session): session closed for user root Oct 5 21:40:01 ip-172-31-29-215 CRON[3924979]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 21:40:01 ip-172-31-29-215 CRON[3924979]: pam_unix(cron:session): session closed for user smmsp Oct 5 21:48:30 ip-172-31-29-215 sshd[3925004]: Connection closed by authenticating user root 171.244.62.70 port 46152 [preauth] Oct 5 21:49:08 ip-172-31-29-215 sshd[3925007]: error: kex_exchange_identification: client sent invalid protocol identifier "" Oct 5 21:51:01 ip-172-31-29-215 sshd[3925008]: Invalid user admin from 59.24.133.197 port 52620 Oct 5 21:51:02 ip-172-31-29-215 sshd[3925008]: Connection closed by invalid user admin 59.24.133.197 port 52620 [preauth] Oct 5 21:51:45 ip-172-31-29-215 sshd[3925011]: error: kex_exchange_identification: client sent invalid protocol identifier "GET / HTTP/1.1" Oct 5 21:53:59 ip-172-31-29-215 sshd[3925013]: error: kex_exchange_identification: client sent invalid protocol identifier "GET / HTTP/1.1" Oct 5 21:55:25 ip-172-31-29-215 sshd[3925014]: error: kex_exchange_identification: banner line contains invalid characters Oct 5 21:58:42 ip-172-31-29-215 sshd[3925017]: Connection closed by 3.132.23.201 port 50318 [preauth] Oct 5 21:59:42 ip-172-31-29-215 sshd[3925021]: error: kex_exchange_identification: banner line contains invalid characters Oct 5 22:00:01 ip-172-31-29-215 CRON[3925022]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 22:00:02 ip-172-31-29-215 CRON[3925022]: pam_unix(cron:session): session closed for user smmsp Oct 5 22:09:01 ip-172-31-29-215 CRON[3925048]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 22:09:01 ip-172-31-29-215 CRON[3925048]: pam_unix(cron:session): session closed for user root Oct 5 22:11:33 ip-172-31-29-215 sshd[3925105]: Connection closed by authenticating user root 103.188.167.170 port 35988 [preauth] Oct 5 22:17:01 ip-172-31-29-215 CRON[3925108]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 22:17:01 ip-172-31-29-215 CRON[3925108]: pam_unix(cron:session): session closed for user root Oct 5 22:17:20 ip-172-31-29-215 sshd[3925111]: Invalid user aptuslegal from 51.77.151.101 port 44144 Oct 5 22:17:20 ip-172-31-29-215 sshd[3925111]: Connection closed by invalid user aptuslegal 51.77.151.101 port 44144 [preauth] Oct 5 22:18:21 ip-172-31-29-215 sshd[3925115]: Invalid user aptuslegal from 34.72.109.56 port 50848 Oct 5 22:18:21 ip-172-31-29-215 sshd[3925115]: Connection closed by invalid user aptuslegal 34.72.109.56 port 50848 [preauth] Oct 5 22:20:01 ip-172-31-29-215 CRON[3925118]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 22:20:01 ip-172-31-29-215 CRON[3925118]: pam_unix(cron:session): session closed for user smmsp Oct 5 22:26:14 ip-172-31-29-215 sshd[3925141]: Connection closed by authenticating user root 142.93.73.173 port 60748 [preauth] Oct 5 22:39:01 ip-172-31-29-215 CRON[3925156]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 22:39:01 ip-172-31-29-215 CRON[3925156]: pam_unix(cron:session): session closed for user root Oct 5 22:40:01 ip-172-31-29-215 CRON[3925213]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 22:40:01 ip-172-31-29-215 CRON[3925213]: pam_unix(cron:session): session closed for user smmsp Oct 5 22:52:17 ip-172-31-29-215 sshd[3925243]: Connection closed by authenticating user root 171.244.62.70 port 46256 [preauth] Oct 5 22:55:42 ip-172-31-29-215 sshd[3925246]: Connection closed by authenticating user root 59.24.133.197 port 59042 [preauth] Oct 5 23:00:01 ip-172-31-29-215 CRON[3925252]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 23:00:01 ip-172-31-29-215 CRON[3925252]: pam_unix(cron:session): session closed for user smmsp Oct 5 23:04:48 ip-172-31-29-215 sshd[3925276]: Connection closed by authenticating user root 170.64.227.36 port 41606 [preauth] Oct 5 23:07:59 ip-172-31-29-215 sshd[3925279]: Connection closed by authenticating user root 34.72.109.56 port 39498 [preauth] Oct 5 23:09:01 ip-172-31-29-215 CRON[3925282]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 23:09:01 ip-172-31-29-215 CRON[3925282]: pam_unix(cron:session): session closed for user root Oct 5 23:09:02 ip-172-31-29-215 sshd[3925284]: Connection closed by authenticating user root 161.97.186.240 port 39536 [preauth] Oct 5 23:15:55 ip-172-31-29-215 sshd[3925342]: Connection closed by authenticating user root 103.188.167.170 port 42800 [preauth] Oct 5 23:17:01 ip-172-31-29-215 CRON[3925344]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 23:17:01 ip-172-31-29-215 CRON[3925344]: pam_unix(cron:session): session closed for user root Oct 5 23:20:01 ip-172-31-29-215 CRON[3925350]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 23:20:01 ip-172-31-29-215 CRON[3925350]: pam_unix(cron:session): session closed for user smmsp Oct 5 23:20:14 ip-172-31-29-215 sshd[3925372]: Invalid user teamspeak from 136.232.11.10 port 47008 Oct 5 23:20:15 ip-172-31-29-215 sshd[3925372]: Received disconnect from 136.232.11.10 port 47008:11: Bye Bye [preauth] Oct 5 23:20:15 ip-172-31-29-215 sshd[3925372]: Disconnected from invalid user teamspeak 136.232.11.10 port 47008 [preauth] Oct 5 23:25:27 ip-172-31-29-215 sshd[3925387]: Invalid user oracle from 136.232.11.10 port 50327 Oct 5 23:25:27 ip-172-31-29-215 sshd[3925387]: Received disconnect from 136.232.11.10 port 50327:11: Bye Bye [preauth] Oct 5 23:25:27 ip-172-31-29-215 sshd[3925387]: Disconnected from invalid user oracle 136.232.11.10 port 50327 [preauth] Oct 5 23:26:46 ip-172-31-29-215 sshd[3925390]: Invalid user teamspeak from 136.232.11.10 port 8612 Oct 5 23:26:47 ip-172-31-29-215 sshd[3925390]: Received disconnect from 136.232.11.10 port 8612:11: Bye Bye [preauth] Oct 5 23:26:47 ip-172-31-29-215 sshd[3925390]: Disconnected from invalid user teamspeak 136.232.11.10 port 8612 [preauth] Oct 5 23:29:27 ip-172-31-29-215 sshd[3925395]: Invalid user vpn from 136.232.11.10 port 36365 Oct 5 23:29:27 ip-172-31-29-215 sshd[3925395]: Received disconnect from 136.232.11.10 port 36365:11: Bye Bye [preauth] Oct 5 23:29:27 ip-172-31-29-215 sshd[3925395]: Disconnected from invalid user vpn 136.232.11.10 port 36365 [preauth] Oct 5 23:34:51 ip-172-31-29-215 sshd[3925398]: Invalid user oracle from 136.232.11.10 port 27788 Oct 5 23:34:52 ip-172-31-29-215 sshd[3925398]: Received disconnect from 136.232.11.10 port 27788:11: Bye Bye [preauth] Oct 5 23:34:52 ip-172-31-29-215 sshd[3925398]: Disconnected from invalid user oracle 136.232.11.10 port 27788 [preauth] Oct 5 23:39:01 ip-172-31-29-215 CRON[3925403]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 5 23:39:01 ip-172-31-29-215 CRON[3925403]: pam_unix(cron:session): session closed for user root Oct 5 23:40:01 ip-172-31-29-215 CRON[3925460]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 5 23:40:01 ip-172-31-29-215 CRON[3925460]: pam_unix(cron:session): session closed for user smmsp Oct 5 23:40:16 ip-172-31-29-215 sshd[3925483]: Invalid user test from 136.232.11.10 port 55318 Oct 5 23:40:17 ip-172-31-29-215 sshd[3925483]: Received disconnect from 136.232.11.10 port 55318:11: Bye Bye [preauth] Oct 5 23:40:17 ip-172-31-29-215 sshd[3925483]: Disconnected from invalid user test 136.232.11.10 port 55318 [preauth] Oct 5 23:41:37 ip-172-31-29-215 sshd[3925485]: Received disconnect from 136.232.11.10 port 49498:11: Bye Bye [preauth] Oct 5 23:41:37 ip-172-31-29-215 sshd[3925485]: Disconnected from authenticating user ubuntu 136.232.11.10 port 49498 [preauth] Oct 5 23:42:57 ip-172-31-29-215 sshd[3925487]: Invalid user adminuser from 136.232.11.10 port 58857 Oct 5 23:42:58 ip-172-31-29-215 sshd[3925487]: Received disconnect from 136.232.11.10 port 58857:11: Bye Bye [preauth] Oct 5 23:42:58 ip-172-31-29-215 sshd[3925487]: Disconnected from invalid user adminuser 136.232.11.10 port 58857 [preauth] Oct 5 23:44:20 ip-172-31-29-215 sshd[3925489]: Invalid user test from 136.232.11.10 port 12143 Oct 5 23:44:20 ip-172-31-29-215 sshd[3925489]: Received disconnect from 136.232.11.10 port 12143:11: Bye Bye [preauth] Oct 5 23:44:20 ip-172-31-29-215 sshd[3925489]: Disconnected from invalid user test 136.232.11.10 port 12143 [preauth] Oct 5 23:47:04 ip-172-31-29-215 sshd[3925501]: Invalid user test1 from 136.232.11.10 port 57692 Oct 5 23:47:04 ip-172-31-29-215 sshd[3925501]: Received disconnect from 136.232.11.10 port 57692:11: Bye Bye [preauth] Oct 5 23:47:04 ip-172-31-29-215 sshd[3925501]: Disconnected from invalid user test1 136.232.11.10 port 57692 [preauth] Oct 5 23:50:11 ip-172-31-29-215 sshd[3925505]: Connection closed by authenticating user root 144.91.93.34 port 59570 [preauth] Oct 5 23:51:09 ip-172-31-29-215 sshd[3925508]: Invalid user bot from 136.232.11.10 port 41878 Oct 5 23:51:09 ip-172-31-29-215 sshd[3925508]: Received disconnect from 136.232.11.10 port 41878:11: Bye Bye [preauth] Oct 5 23:51:09 ip-172-31-29-215 sshd[3925508]: Disconnected from invalid user bot 136.232.11.10 port 41878 [preauth] Oct 5 23:52:31 ip-172-31-29-215 sshd[3925511]: Invalid user john from 136.232.11.10 port 28136 Oct 5 23:52:32 ip-172-31-29-215 sshd[3925511]: Received disconnect from 136.232.11.10 port 28136:11: Bye Bye [preauth] Oct 5 23:52:32 ip-172-31-29-215 sshd[3925511]: Disconnected from invalid user john 136.232.11.10 port 28136 [preauth] Oct 5 23:55:16 ip-172-31-29-215 sshd[3925513]: Invalid user vpn from 136.232.11.10 port 10026 Oct 5 23:55:16 ip-172-31-29-215 sshd[3925513]: Received disconnect from 136.232.11.10 port 10026:11: Bye Bye [preauth] Oct 5 23:55:16 ip-172-31-29-215 sshd[3925513]: Disconnected from invalid user vpn 136.232.11.10 port 10026 [preauth] Oct 5 23:56:18 ip-172-31-29-215 sshd[3925516]: Connection closed by authenticating user root 171.244.62.70 port 59588 [preauth] Oct 5 23:58:18 ip-172-31-29-215 sshd[3925521]: Connection closed by authenticating user root 34.72.109.56 port 42824 [preauth] Oct 5 23:59:18 ip-172-31-29-215 sshd[3925524]: Invalid user adminuser from 136.232.11.10 port 2791 Oct 5 23:59:18 ip-172-31-29-215 sshd[3925524]: Received disconnect from 136.232.11.10 port 2791:11: Bye Bye [preauth] Oct 5 23:59:18 ip-172-31-29-215 sshd[3925524]: Disconnected from invalid user adminuser 136.232.11.10 port 2791 [preauth] Oct 6 00:00:00 ip-172-31-29-215 sshd[3925526]: Connection closed by authenticating user root 51.77.151.101 port 45894 [preauth] Oct 6 00:00:01 ip-172-31-29-215 CRON[3925569]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 00:00:01 ip-172-31-29-215 CRON[3925570]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 00:00:01 ip-172-31-29-215 CRON[3925569]: pam_unix(cron:session): session closed for user root Oct 6 00:00:01 ip-172-31-29-215 CRON[3925570]: pam_unix(cron:session): session closed for user smmsp Oct 6 00:00:27 ip-172-31-29-215 sshd[3925593]: Connection closed by authenticating user root 59.24.133.197 port 39234 [preauth] Oct 6 00:03:39 ip-172-31-29-215 sshd[3925596]: Connection closed by authenticating user root 161.97.186.240 port 56030 [preauth] Oct 6 00:09:01 ip-172-31-29-215 CRON[3925606]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 00:09:01 ip-172-31-29-215 CRON[3925606]: pam_unix(cron:session): session closed for user root Oct 6 00:15:33 ip-172-31-29-215 sshd[3925663]: Connection closed by authenticating user root 165.211.25.202 port 34010 [preauth] Oct 6 00:17:01 ip-172-31-29-215 CRON[3925665]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 00:17:01 ip-172-31-29-215 CRON[3925665]: pam_unix(cron:session): session closed for user root Oct 6 00:20:01 ip-172-31-29-215 CRON[3925670]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 00:20:01 ip-172-31-29-215 CRON[3925670]: pam_unix(cron:session): session closed for user smmsp Oct 6 00:39:01 ip-172-31-29-215 CRON[3925698]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 00:39:01 ip-172-31-29-215 CRON[3925698]: pam_unix(cron:session): session closed for user root Oct 6 00:40:01 ip-172-31-29-215 CRON[3925754]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 00:40:01 ip-172-31-29-215 CRON[3925754]: pam_unix(cron:session): session closed for user smmsp Oct 6 00:43:03 ip-172-31-29-215 sshd[3925776]: Connection closed by authenticating user root 64.227.136.122 port 35198 [preauth] Oct 6 00:51:31 ip-172-31-29-215 sshd[3925782]: Connection closed by authenticating user root 146.190.105.116 port 60032 [preauth] Oct 6 00:58:24 ip-172-31-29-215 sshd[3925787]: Connection closed by authenticating user root 161.97.186.240 port 33542 [preauth] Oct 6 01:00:01 ip-172-31-29-215 CRON[3925790]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 01:00:01 ip-172-31-29-215 CRON[3925790]: pam_unix(cron:session): session closed for user smmsp Oct 6 01:00:07 ip-172-31-29-215 sshd[3925812]: Connection closed by authenticating user root 171.244.62.70 port 51830 [preauth] Oct 6 01:01:01 ip-172-31-29-215 sshd[3925815]: Invalid user aptuslegal from 162.240.61.39 port 54206 Oct 6 01:01:01 ip-172-31-29-215 sshd[3925815]: Connection closed by invalid user aptuslegal 162.240.61.39 port 54206 [preauth] Oct 6 01:05:03 ip-172-31-29-215 sshd[3925818]: Invalid user aptuslegal from 59.24.133.197 port 45528 Oct 6 01:05:03 ip-172-31-29-215 sshd[3925818]: Connection closed by invalid user aptuslegal 59.24.133.197 port 45528 [preauth] Oct 6 01:08:00 ip-172-31-29-215 sshd[3926574]: Invalid user from 209.38.19.68 port 49188 Oct 6 01:08:08 ip-172-31-29-215 sshd[3926574]: Connection closed by invalid user 209.38.19.68 port 49188 [preauth] Oct 6 01:09:01 ip-172-31-29-215 CRON[3926578]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 01:09:01 ip-172-31-29-215 CRON[3926578]: pam_unix(cron:session): session closed for user root Oct 6 01:17:01 ip-172-31-29-215 CRON[3926637]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 01:17:01 ip-172-31-29-215 CRON[3926637]: pam_unix(cron:session): session closed for user root Oct 6 01:20:01 ip-172-31-29-215 CRON[3926643]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 01:20:01 ip-172-31-29-215 CRON[3926643]: pam_unix(cron:session): session closed for user smmsp Oct 6 01:25:32 ip-172-31-29-215 sshd[3926666]: Invalid user devuser from 103.81.86.208 port 35316 Oct 6 01:25:32 ip-172-31-29-215 sshd[3926666]: Received disconnect from 103.81.86.208 port 35316:11: Bye Bye [preauth] Oct 6 01:25:32 ip-172-31-29-215 sshd[3926666]: Disconnected from invalid user devuser 103.81.86.208 port 35316 [preauth] Oct 6 01:27:24 ip-172-31-29-215 sshd[3926669]: Invalid user administrator from 106.38.195.164 port 36426 Oct 6 01:27:24 ip-172-31-29-215 sshd[3926669]: Received disconnect from 106.38.195.164 port 36426:11: Bye Bye [preauth] Oct 6 01:27:24 ip-172-31-29-215 sshd[3926669]: Disconnected from invalid user administrator 106.38.195.164 port 36426 [preauth] Oct 6 01:28:42 ip-172-31-29-215 sshd[3926673]: Invalid user user from 103.81.86.208 port 60536 Oct 6 01:28:42 ip-172-31-29-215 sshd[3926673]: Received disconnect from 103.81.86.208 port 60536:11: Bye Bye [preauth] Oct 6 01:28:42 ip-172-31-29-215 sshd[3926673]: Disconnected from invalid user user 103.81.86.208 port 60536 [preauth] Oct 6 01:29:12 ip-172-31-29-215 sshd[3926676]: Received disconnect from 106.38.195.164 port 44336:11: Bye Bye [preauth] Oct 6 01:29:12 ip-172-31-29-215 sshd[3926676]: Disconnected from authenticating user mysql 106.38.195.164 port 44336 [preauth] Oct 6 01:30:29 ip-172-31-29-215 sshd[3926678]: Invalid user ec2-user from 103.81.86.208 port 36598 Oct 6 01:30:29 ip-172-31-29-215 sshd[3926678]: Received disconnect from 103.81.86.208 port 36598:11: Bye Bye [preauth] Oct 6 01:30:29 ip-172-31-29-215 sshd[3926678]: Disconnected from invalid user ec2-user 103.81.86.208 port 36598 [preauth] Oct 6 01:30:41 ip-172-31-29-215 sshd[3926681]: Invalid user vps from 106.38.195.164 port 38546 Oct 6 01:30:41 ip-172-31-29-215 sshd[3926681]: Received disconnect from 106.38.195.164 port 38546:11: Bye Bye [preauth] Oct 6 01:30:41 ip-172-31-29-215 sshd[3926681]: Disconnected from invalid user vps 106.38.195.164 port 38546 [preauth] Oct 6 01:30:52 ip-172-31-29-215 sshd[3926683]: Connection closed by authenticating user root 110.10.89.78 port 52558 [preauth] Oct 6 01:31:49 ip-172-31-29-215 sshd[3926685]: Connection closed by authenticating user root 144.91.93.34 port 39456 [preauth] Oct 6 01:32:12 ip-172-31-29-215 sshd[3926687]: Invalid user vps from 106.38.195.164 port 47098 Oct 6 01:32:12 ip-172-31-29-215 sshd[3926687]: Received disconnect from 106.38.195.164 port 47098:11: Bye Bye [preauth] Oct 6 01:32:12 ip-172-31-29-215 sshd[3926687]: Disconnected from invalid user vps 106.38.195.164 port 47098 [preauth] Oct 6 01:32:14 ip-172-31-29-215 sshd[3926689]: Invalid user devuser from 103.81.86.208 port 60366 Oct 6 01:32:14 ip-172-31-29-215 sshd[3926689]: Received disconnect from 103.81.86.208 port 60366:11: Bye Bye [preauth] Oct 6 01:32:14 ip-172-31-29-215 sshd[3926689]: Disconnected from invalid user devuser 103.81.86.208 port 60366 [preauth] Oct 6 01:33:52 ip-172-31-29-215 sshd[3926693]: Invalid user adminuser from 103.81.86.208 port 39502 Oct 6 01:33:53 ip-172-31-29-215 sshd[3926693]: Received disconnect from 103.81.86.208 port 39502:11: Bye Bye [preauth] Oct 6 01:33:53 ip-172-31-29-215 sshd[3926693]: Disconnected from invalid user adminuser 103.81.86.208 port 39502 [preauth] Oct 6 01:35:30 ip-172-31-29-215 sshd[3926695]: Invalid user vps from 103.81.86.208 port 56256 Oct 6 01:35:30 ip-172-31-29-215 sshd[3926695]: Received disconnect from 103.81.86.208 port 56256:11: Bye Bye [preauth] Oct 6 01:35:30 ip-172-31-29-215 sshd[3926695]: Disconnected from invalid user vps 103.81.86.208 port 56256 [preauth] Oct 6 01:37:05 ip-172-31-29-215 sshd[3926699]: Invalid user user1 from 103.81.86.208 port 45494 Oct 6 01:37:06 ip-172-31-29-215 sshd[3926699]: Received disconnect from 103.81.86.208 port 45494:11: Bye Bye [preauth] Oct 6 01:37:06 ip-172-31-29-215 sshd[3926699]: Disconnected from invalid user user1 103.81.86.208 port 45494 [preauth] Oct 6 01:38:39 ip-172-31-29-215 sshd[3926703]: Invalid user testuser from 103.81.86.208 port 39148 Oct 6 01:38:39 ip-172-31-29-215 sshd[3926703]: Received disconnect from 103.81.86.208 port 39148:11: Bye Bye [preauth] Oct 6 01:38:39 ip-172-31-29-215 sshd[3926703]: Disconnected from invalid user testuser 103.81.86.208 port 39148 [preauth] Oct 6 01:39:01 ip-172-31-29-215 CRON[3926706]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 01:39:01 ip-172-31-29-215 CRON[3926706]: pam_unix(cron:session): session closed for user root Oct 6 01:40:01 ip-172-31-29-215 CRON[3926762]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 01:40:01 ip-172-31-29-215 CRON[3926762]: pam_unix(cron:session): session closed for user smmsp Oct 6 01:40:15 ip-172-31-29-215 sshd[3926784]: Invalid user ftptest from 103.81.86.208 port 35166 Oct 6 01:40:15 ip-172-31-29-215 sshd[3926784]: Received disconnect from 103.81.86.208 port 35166:11: Bye Bye [preauth] Oct 6 01:40:15 ip-172-31-29-215 sshd[3926784]: Disconnected from invalid user ftptest 103.81.86.208 port 35166 [preauth] Oct 6 01:40:40 ip-172-31-29-215 sshd[3926786]: Connection closed by authenticating user root 51.77.151.101 port 52748 [preauth] Oct 6 01:42:04 ip-172-31-29-215 sshd[3926790]: Invalid user adminuser from 103.81.86.208 port 50526 Oct 6 01:42:04 ip-172-31-29-215 sshd[3926790]: Received disconnect from 103.81.86.208 port 50526:11: Bye Bye [preauth] Oct 6 01:42:04 ip-172-31-29-215 sshd[3926790]: Disconnected from invalid user adminuser 103.81.86.208 port 50526 [preauth] Oct 6 01:43:22 ip-172-31-29-215 sshd[3926796]: error: kex_exchange_identification: client sent invalid protocol identifier "MGLNDD_3.22.251.217_22" Oct 6 01:43:31 ip-172-31-29-215 sshd[3926794]: Connection closed by 4.227.180.232 port 39154 [preauth] Oct 6 01:43:41 ip-172-31-29-215 sshd[3926797]: Invalid user debian from 103.81.86.208 port 52900 Oct 6 01:43:41 ip-172-31-29-215 sshd[3926797]: Received disconnect from 103.81.86.208 port 52900:11: Bye Bye [preauth] Oct 6 01:43:41 ip-172-31-29-215 sshd[3926797]: Disconnected from invalid user debian 103.81.86.208 port 52900 [preauth] Oct 6 01:45:19 ip-172-31-29-215 sshd[3926799]: Invalid user teamspeak from 106.38.195.164 port 36980 Oct 6 01:45:19 ip-172-31-29-215 sshd[3926799]: Received disconnect from 106.38.195.164 port 36980:11: Bye Bye [preauth] Oct 6 01:45:19 ip-172-31-29-215 sshd[3926799]: Disconnected from invalid user teamspeak 106.38.195.164 port 36980 [preauth] Oct 6 01:45:32 ip-172-31-29-215 sshd[3926801]: Invalid user app from 103.81.86.208 port 45932 Oct 6 01:45:32 ip-172-31-29-215 sshd[3926801]: Received disconnect from 103.81.86.208 port 45932:11: Bye Bye [preauth] Oct 6 01:45:32 ip-172-31-29-215 sshd[3926801]: Disconnected from invalid user app 103.81.86.208 port 45932 [preauth] Oct 6 01:47:15 ip-172-31-29-215 sshd[3926804]: Invalid user teamspeak from 103.81.86.208 port 60986 Oct 6 01:47:16 ip-172-31-29-215 sshd[3926804]: Received disconnect from 103.81.86.208 port 60986:11: Bye Bye [preauth] Oct 6 01:47:16 ip-172-31-29-215 sshd[3926804]: Disconnected from invalid user teamspeak 103.81.86.208 port 60986 [preauth] Oct 6 01:47:58 ip-172-31-29-215 sshd[3926803]: Connection closed by 106.38.195.164 port 51404 [preauth] Oct 6 01:48:40 ip-172-31-29-215 sshd[3926809]: Invalid user aptuslegal from 162.240.61.39 port 36132 Oct 6 01:48:40 ip-172-31-29-215 sshd[3926809]: Connection closed by invalid user aptuslegal 162.240.61.39 port 36132 [preauth] Oct 6 01:48:55 ip-172-31-29-215 sshd[3926811]: Invalid user vps from 103.81.86.208 port 51132 Oct 6 01:48:55 ip-172-31-29-215 sshd[3926811]: Received disconnect from 103.81.86.208 port 51132:11: Bye Bye [preauth] Oct 6 01:48:55 ip-172-31-29-215 sshd[3926811]: Disconnected from invalid user vps 103.81.86.208 port 51132 [preauth] Oct 6 01:50:16 ip-172-31-29-215 sshd[3926815]: Connection closed by authenticating user root 64.227.136.122 port 49502 [preauth] Oct 6 01:50:45 ip-172-31-29-215 sshd[3926817]: Invalid user dev from 103.81.86.208 port 60032 Oct 6 01:50:45 ip-172-31-29-215 sshd[3926817]: Received disconnect from 103.81.86.208 port 60032:11: Bye Bye [preauth] Oct 6 01:50:45 ip-172-31-29-215 sshd[3926817]: Disconnected from invalid user dev 103.81.86.208 port 60032 [preauth] Oct 6 01:52:37 ip-172-31-29-215 sshd[3926820]: Invalid user administrator from 103.81.86.208 port 35550 Oct 6 01:52:37 ip-172-31-29-215 sshd[3926820]: Received disconnect from 103.81.86.208 port 35550:11: Bye Bye [preauth] Oct 6 01:52:37 ip-172-31-29-215 sshd[3926820]: Disconnected from invalid user administrator 103.81.86.208 port 35550 [preauth] Oct 6 01:52:55 ip-172-31-29-215 sshd[3926823]: Invalid user devuser from 106.38.195.164 port 40878 Oct 6 01:52:55 ip-172-31-29-215 sshd[3926823]: Received disconnect from 106.38.195.164 port 40878:11: Bye Bye [preauth] Oct 6 01:52:55 ip-172-31-29-215 sshd[3926823]: Disconnected from invalid user devuser 106.38.195.164 port 40878 [preauth] Oct 6 01:54:25 ip-172-31-29-215 sshd[3926826]: Invalid user user from 103.81.86.208 port 35396 Oct 6 01:54:25 ip-172-31-29-215 sshd[3926826]: Received disconnect from 103.81.86.208 port 35396:11: Bye Bye [preauth] Oct 6 01:54:25 ip-172-31-29-215 sshd[3926826]: Disconnected from invalid user user 103.81.86.208 port 35396 [preauth] Oct 6 01:54:51 ip-172-31-29-215 sshd[3926828]: Invalid user debian from 106.38.195.164 port 33464 Oct 6 01:54:52 ip-172-31-29-215 sshd[3926828]: Received disconnect from 106.38.195.164 port 33464:11: Bye Bye [preauth] Oct 6 01:54:52 ip-172-31-29-215 sshd[3926828]: Disconnected from invalid user debian 106.38.195.164 port 33464 [preauth] Oct 6 01:54:58 ip-172-31-29-215 sshd[3926830]: Invalid user nagel from 151.34.32.109 port 7316 Oct 6 01:54:59 ip-172-31-29-215 sshd[3926830]: Received disconnect from 151.34.32.109 port 7316:11: Bye Bye [preauth] Oct 6 01:54:59 ip-172-31-29-215 sshd[3926830]: Disconnected from invalid user nagel 151.34.32.109 port 7316 [preauth] Oct 6 01:55:44 ip-172-31-29-215 sshd[3926832]: Connection closed by authenticating user root 142.93.73.173 port 60552 [preauth] Oct 6 01:56:12 ip-172-31-29-215 sshd[3926834]: Invalid user john from 103.81.86.208 port 38626 Oct 6 01:56:13 ip-172-31-29-215 sshd[3926834]: Received disconnect from 103.81.86.208 port 38626:11: Bye Bye [preauth] Oct 6 01:56:13 ip-172-31-29-215 sshd[3926834]: Disconnected from invalid user john 103.81.86.208 port 38626 [preauth] Oct 6 01:57:07 ip-172-31-29-215 sshd[3926836]: Connection closed by 106.38.195.164 port 50210 [preauth] Oct 6 01:58:01 ip-172-31-29-215 sshd[3926839]: Received disconnect from 103.81.86.208 port 60276:11: Bye Bye [preauth] Oct 6 01:58:01 ip-172-31-29-215 sshd[3926839]: Disconnected from authenticating user ubuntu 103.81.86.208 port 60276 [preauth] Oct 6 01:59:06 ip-172-31-29-215 sshd[3926844]: Invalid user kristen from 151.34.32.109 port 7958 Oct 6 01:59:06 ip-172-31-29-215 sshd[3926844]: Received disconnect from 151.34.32.109 port 7958:11: Bye Bye [preauth] Oct 6 01:59:06 ip-172-31-29-215 sshd[3926844]: Disconnected from invalid user kristen 151.34.32.109 port 7958 [preauth] Oct 6 01:59:46 ip-172-31-29-215 sshd[3926847]: Invalid user dmdba from 103.81.86.208 port 35546 Oct 6 01:59:46 ip-172-31-29-215 sshd[3926847]: Received disconnect from 103.81.86.208 port 35546:11: Bye Bye [preauth] Oct 6 01:59:46 ip-172-31-29-215 sshd[3926847]: Disconnected from invalid user dmdba 103.81.86.208 port 35546 [preauth] Oct 6 02:00:01 ip-172-31-29-215 CRON[3926849]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 02:00:01 ip-172-31-29-215 CRON[3926849]: pam_unix(cron:session): session closed for user smmsp Oct 6 02:00:30 ip-172-31-29-215 sshd[3926872]: Invalid user venus from 151.34.32.109 port 7833 Oct 6 02:00:30 ip-172-31-29-215 sshd[3926872]: Received disconnect from 151.34.32.109 port 7833:11: Bye Bye [preauth] Oct 6 02:00:30 ip-172-31-29-215 sshd[3926872]: Disconnected from invalid user venus 151.34.32.109 port 7833 [preauth] Oct 6 02:00:36 ip-172-31-29-215 sshd[3926874]: Invalid user user from 106.38.195.164 port 47782 Oct 6 02:00:36 ip-172-31-29-215 sshd[3926874]: Received disconnect from 106.38.195.164 port 47782:11: Bye Bye [preauth] Oct 6 02:00:36 ip-172-31-29-215 sshd[3926874]: Disconnected from invalid user user 106.38.195.164 port 47782 [preauth] Oct 6 02:01:37 ip-172-31-29-215 sshd[3926876]: Invalid user administrator from 103.81.86.208 port 58768 Oct 6 02:01:38 ip-172-31-29-215 sshd[3926876]: Received disconnect from 103.81.86.208 port 58768:11: Bye Bye [preauth] Oct 6 02:01:38 ip-172-31-29-215 sshd[3926876]: Disconnected from invalid user administrator 103.81.86.208 port 58768 [preauth] Oct 6 02:04:07 ip-172-31-29-215 sshd[3926878]: Invalid user aptuslegal from 171.244.62.70 port 36176 Oct 6 02:04:07 ip-172-31-29-215 sshd[3926878]: Connection closed by invalid user aptuslegal 171.244.62.70 port 36176 [preauth] Oct 6 02:07:05 ip-172-31-29-215 sshd[3926881]: Invalid user tracy from 152.42.240.109 port 58252 Oct 6 02:07:05 ip-172-31-29-215 sshd[3926881]: Received disconnect from 152.42.240.109 port 58252:11: Bye Bye [preauth] Oct 6 02:07:05 ip-172-31-29-215 sshd[3926881]: Disconnected from invalid user tracy 152.42.240.109 port 58252 [preauth] Oct 6 02:09:01 ip-172-31-29-215 CRON[3926885]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 02:09:01 ip-172-31-29-215 CRON[3926885]: pam_unix(cron:session): session closed for user root Oct 6 02:09:11 ip-172-31-29-215 sshd[3926939]: Connection closed by authenticating user root 59.24.133.197 port 52782 [preauth] Oct 6 02:09:45 ip-172-31-29-215 sshd[3926942]: Invalid user foolproof from 152.42.240.109 port 39574 Oct 6 02:09:45 ip-172-31-29-215 sshd[3926942]: Received disconnect from 152.42.240.109 port 39574:11: Bye Bye [preauth] Oct 6 02:09:45 ip-172-31-29-215 sshd[3926942]: Disconnected from invalid user foolproof 152.42.240.109 port 39574 [preauth] Oct 6 02:17:01 ip-172-31-29-215 CRON[3926945]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 02:17:01 ip-172-31-29-215 CRON[3926945]: pam_unix(cron:session): session closed for user root Oct 6 02:20:01 ip-172-31-29-215 CRON[3926956]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 02:20:01 ip-172-31-29-215 CRON[3926956]: pam_unix(cron:session): session closed for user smmsp Oct 6 02:39:01 ip-172-31-29-215 CRON[3926987]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 02:39:01 ip-172-31-29-215 CRON[3926987]: pam_unix(cron:session): session closed for user root Oct 6 02:40:01 ip-172-31-29-215 CRON[3927042]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 02:40:01 ip-172-31-29-215 CRON[3927042]: pam_unix(cron:session): session closed for user smmsp Oct 6 02:41:12 ip-172-31-29-215 sshd[3927064]: Invalid user telephone from 151.36.129.198 port 1533 Oct 6 02:41:12 ip-172-31-29-215 sshd[3927064]: Received disconnect from 151.36.129.198 port 1533:11: Bye Bye [preauth] Oct 6 02:41:12 ip-172-31-29-215 sshd[3927064]: Disconnected from invalid user telephone 151.36.129.198 port 1533 [preauth] Oct 6 02:42:14 ip-172-31-29-215 sshd[3927066]: Invalid user mogul from 151.36.129.198 port 1604 Oct 6 02:42:14 ip-172-31-29-215 sshd[3927066]: Received disconnect from 151.36.129.198 port 1604:11: Bye Bye [preauth] Oct 6 02:42:14 ip-172-31-29-215 sshd[3927066]: Disconnected from invalid user mogul 151.36.129.198 port 1604 [preauth] Oct 6 02:43:19 ip-172-31-29-215 sshd[3927068]: Invalid user stacey from 151.36.129.198 port 1213 Oct 6 02:43:19 ip-172-31-29-215 sshd[3927068]: Received disconnect from 151.36.129.198 port 1213:11: Bye Bye [preauth] Oct 6 02:43:19 ip-172-31-29-215 sshd[3927068]: Disconnected from invalid user stacey 151.36.129.198 port 1213 [preauth] Oct 6 02:48:42 ip-172-31-29-215 sshd[3927072]: Connection closed by authenticating user root 142.93.73.173 port 56264 [preauth] Oct 6 02:59:57 ip-172-31-29-215 sshd[3927081]: Invalid user elephant from 152.42.240.109 port 47882 Oct 6 02:59:57 ip-172-31-29-215 sshd[3927081]: Received disconnect from 152.42.240.109 port 47882:11: Bye Bye [preauth] Oct 6 02:59:57 ip-172-31-29-215 sshd[3927081]: Disconnected from invalid user elephant 152.42.240.109 port 47882 [preauth] Oct 6 03:00:01 ip-172-31-29-215 CRON[3927083]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 03:00:01 ip-172-31-29-215 CRON[3927083]: pam_unix(cron:session): session closed for user smmsp Oct 6 03:02:38 ip-172-31-29-215 sshd[3927105]: Invalid user wombat from 152.42.240.109 port 49694 Oct 6 03:02:39 ip-172-31-29-215 sshd[3927105]: Received disconnect from 152.42.240.109 port 49694:11: Bye Bye [preauth] Oct 6 03:02:39 ip-172-31-29-215 sshd[3927105]: Disconnected from invalid user wombat 152.42.240.109 port 49694 [preauth] Oct 6 03:06:02 ip-172-31-29-215 sshd[3927108]: Invalid user wendy from 152.42.240.109 port 43744 Oct 6 03:06:02 ip-172-31-29-215 sshd[3927108]: Received disconnect from 152.42.240.109 port 43744:11: Bye Bye [preauth] Oct 6 03:06:02 ip-172-31-29-215 sshd[3927108]: Disconnected from invalid user wendy 152.42.240.109 port 43744 [preauth] Oct 6 03:08:08 ip-172-31-29-215 sshd[3927119]: Connection closed by authenticating user root 171.244.62.70 port 33218 [preauth] Oct 6 03:09:01 ip-172-31-29-215 CRON[3927122]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 03:09:01 ip-172-31-29-215 CRON[3927122]: pam_unix(cron:session): session closed for user root Oct 6 03:10:01 ip-172-31-29-215 CRON[3927178]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 03:10:01 ip-172-31-29-215 CRON[3927178]: pam_unix(cron:session): session closed for user root Oct 6 03:13:50 ip-172-31-29-215 sshd[3927181]: Invalid user aptuslegal from 59.24.133.197 port 34626 Oct 6 03:13:50 ip-172-31-29-215 sshd[3927181]: Connection closed by invalid user aptuslegal 59.24.133.197 port 34626 [preauth] Oct 6 03:17:01 ip-172-31-29-215 CRON[3927184]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 03:17:01 ip-172-31-29-215 CRON[3927184]: pam_unix(cron:session): session closed for user root Oct 6 03:20:01 ip-172-31-29-215 CRON[3927190]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 03:20:01 ip-172-31-29-215 CRON[3927190]: pam_unix(cron:session): session closed for user smmsp Oct 6 03:21:02 ip-172-31-29-215 sshd[3927212]: Invalid user aptuslegal from 51.77.151.101 port 45060 Oct 6 03:21:03 ip-172-31-29-215 sshd[3927212]: Connection closed by invalid user aptuslegal 51.77.151.101 port 45060 [preauth] Oct 6 03:31:08 ip-172-31-29-215 sshd[3927227]: Connection closed by authenticating user root 103.188.167.170 port 37576 [preauth] Oct 6 03:39:01 ip-172-31-29-215 CRON[3927232]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 03:39:01 ip-172-31-29-215 CRON[3927232]: pam_unix(cron:session): session closed for user root Oct 6 03:40:01 ip-172-31-29-215 CRON[3927289]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 03:40:01 ip-172-31-29-215 CRON[3927289]: pam_unix(cron:session): session closed for user smmsp Oct 6 04:00:01 ip-172-31-29-215 CRON[3927319]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 04:00:01 ip-172-31-29-215 CRON[3927319]: pam_unix(cron:session): session closed for user smmsp Oct 6 04:09:01 ip-172-31-29-215 CRON[3927346]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 04:09:01 ip-172-31-29-215 CRON[3927346]: pam_unix(cron:session): session closed for user root Oct 6 04:12:07 ip-172-31-29-215 sshd[3927402]: Connection closed by authenticating user root 171.244.62.70 port 36918 [preauth] Oct 6 04:17:01 ip-172-31-29-215 CRON[3927406]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 04:17:01 ip-172-31-29-215 CRON[3927406]: pam_unix(cron:session): session closed for user root Oct 6 04:18:34 ip-172-31-29-215 sshd[3927410]: Connection closed by authenticating user root 59.24.133.197 port 44882 [preauth] Oct 6 04:20:01 ip-172-31-29-215 CRON[3927413]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 04:20:01 ip-172-31-29-215 CRON[3927413]: pam_unix(cron:session): session closed for user smmsp Oct 6 04:26:40 ip-172-31-29-215 sshd[3927437]: Connection closed by 66.240.223.202 port 49298 [preauth] Oct 6 04:27:37 ip-172-31-29-215 sshd[3927439]: Invalid user zsq from 103.183.75.239 port 59426 Oct 6 04:27:37 ip-172-31-29-215 sshd[3927439]: Received disconnect from 103.183.75.239 port 59426:11: Bye Bye [preauth] Oct 6 04:27:37 ip-172-31-29-215 sshd[3927439]: Disconnected from invalid user zsq 103.183.75.239 port 59426 [preauth] Oct 6 04:28:03 ip-172-31-29-215 sshd[3927442]: error: kex_exchange_identification: Connection closed by remote host Oct 6 04:29:58 ip-172-31-29-215 sshd[3927448]: Invalid user s from 103.183.75.239 port 35664 Oct 6 04:29:58 ip-172-31-29-215 sshd[3927448]: Received disconnect from 103.183.75.239 port 35664:11: Bye Bye [preauth] Oct 6 04:29:58 ip-172-31-29-215 sshd[3927448]: Disconnected from invalid user s 103.183.75.239 port 35664 [preauth] Oct 6 04:31:54 ip-172-31-29-215 sshd[3927451]: Invalid user visco from 103.183.75.239 port 57110 Oct 6 04:31:54 ip-172-31-29-215 sshd[3927451]: Received disconnect from 103.183.75.239 port 57110:11: Bye Bye [preauth] Oct 6 04:31:54 ip-172-31-29-215 sshd[3927451]: Disconnected from invalid user visco 103.183.75.239 port 57110 [preauth] Oct 6 04:33:47 ip-172-31-29-215 sshd[3927453]: Invalid user lakshmi from 103.183.75.239 port 40030 Oct 6 04:33:47 ip-172-31-29-215 sshd[3927453]: Received disconnect from 103.183.75.239 port 40030:11: Bye Bye [preauth] Oct 6 04:33:47 ip-172-31-29-215 sshd[3927453]: Disconnected from invalid user lakshmi 103.183.75.239 port 40030 [preauth] Oct 6 04:35:13 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:13 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:17 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:17 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:21 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:21 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:28 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:28 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:31 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:31 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:33 ip-172-31-29-215 sshd[3927472]: Invalid user steven from 103.183.75.239 port 53970 Oct 6 04:35:33 ip-172-31-29-215 sshd[3927472]: Received disconnect from 103.183.75.239 port 53970:11: Bye Bye [preauth] Oct 6 04:35:33 ip-172-31-29-215 sshd[3927472]: Disconnected from invalid user steven 103.183.75.239 port 53970 [preauth] Oct 6 04:35:35 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:35 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:39 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:39 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:42 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:42 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:45 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:45 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:49 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:49 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:52 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:52 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:56 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:56 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:35:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:35:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:03 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:03 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:10 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:10 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:13 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:13 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:17 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:17 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:20 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:20 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:28 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:28 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:32 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:32 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:36 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:36 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:40 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:40 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:43 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:43 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:48 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:48 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:51 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:51 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:55 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:55 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:36:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:36:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:03 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:03 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:10 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:10 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:14 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:14 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:18 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:18 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:22 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:22 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:26 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:26 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:30 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:30 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:34 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:34 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:38 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:38 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:42 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:42 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:46 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:46 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:49 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:49 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:53 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:53 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:37:57 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:37:57 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:04 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:04 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:07 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:07 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:12 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:12 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:16 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:16 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:20 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:20 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:24 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:27 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:27 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:31 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:31 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:35 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:35 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:39 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:39 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:43 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:43 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:47 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:47 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:51 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:51 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:54 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:54 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:38:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:38:59 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:39:01 ip-172-31-29-215 CRON[3927587]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 04:39:01 ip-172-31-29-215 CRON[3927587]: pam_unix(cron:session): session closed for user root Oct 6 04:39:02 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:39:02 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:39:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): check pass; user unknown Oct 6 04:39:06 ip-172-31-29-215 vsftpd: pam_unix(vsftpd:auth): authentication failure; logname= uid=0 euid=0 tty=ftp ruser=www rhost=186.136.1.119 Oct 6 04:40:01 ip-172-31-29-215 CRON[3927649]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 04:40:01 ip-172-31-29-215 CRON[3927649]: pam_unix(cron:session): session closed for user smmsp Oct 6 04:40:57 ip-172-31-29-215 sshd[3927671]: Connection closed by authenticating user root 165.211.25.202 port 50316 [preauth] Oct 6 04:48:03 ip-172-31-29-215 sshd[3927689]: Invalid user aptuslegal from 110.10.89.78 port 45390 Oct 6 04:48:03 ip-172-31-29-215 sshd[3927689]: Connection closed by invalid user aptuslegal 110.10.89.78 port 45390 [preauth] Oct 6 04:56:00 ip-172-31-29-215 sshd[3927693]: Connection closed by authenticating user root 144.91.93.34 port 35996 [preauth] Oct 6 05:00:01 ip-172-31-29-215 CRON[3927698]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 05:00:01 ip-172-31-29-215 CRON[3927698]: pam_unix(cron:session): session closed for user smmsp Oct 6 05:03:49 ip-172-31-29-215 sshd[3927721]: Connection closed by authenticating user root 51.77.151.101 port 38946 [preauth] Oct 6 05:09:01 ip-172-31-29-215 CRON[3927727]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 05:09:01 ip-172-31-29-215 CRON[3927727]: pam_unix(cron:session): session closed for user root Oct 6 05:15:32 ip-172-31-29-215 sshd[3927784]: Connection closed by authenticating user root 171.244.62.70 port 36946 [preauth] Oct 6 05:17:01 ip-172-31-29-215 CRON[3927787]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 05:17:01 ip-172-31-29-215 CRON[3927787]: pam_unix(cron:session): session closed for user root Oct 6 05:20:01 ip-172-31-29-215 CRON[3927792]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 05:20:01 ip-172-31-29-215 CRON[3927792]: pam_unix(cron:session): session closed for user smmsp Oct 6 05:23:19 ip-172-31-29-215 sshd[3927815]: Invalid user aptuslegal from 59.24.133.197 port 54308 Oct 6 05:23:19 ip-172-31-29-215 sshd[3927815]: Connection closed by invalid user aptuslegal 59.24.133.197 port 54308 [preauth] Oct 6 05:24:46 ip-172-31-29-215 sshd[3927817]: Invalid user shiyang from 103.183.75.239 port 37416 Oct 6 05:24:46 ip-172-31-29-215 sshd[3927817]: Received disconnect from 103.183.75.239 port 37416:11: Bye Bye [preauth] Oct 6 05:24:46 ip-172-31-29-215 sshd[3927817]: Disconnected from invalid user shiyang 103.183.75.239 port 37416 [preauth] Oct 6 05:26:33 ip-172-31-29-215 sshd[3927820]: Invalid user shiyasong from 103.183.75.239 port 47532 Oct 6 05:26:33 ip-172-31-29-215 sshd[3927820]: Received disconnect from 103.183.75.239 port 47532:11: Bye Bye [preauth] Oct 6 05:26:33 ip-172-31-29-215 sshd[3927820]: Disconnected from invalid user shiyasong 103.183.75.239 port 47532 [preauth] Oct 6 05:27:07 ip-172-31-29-215 sshd[3927822]: error: kex_exchange_identification: Connection closed by remote host Oct 6 05:27:08 ip-172-31-29-215 sshd[3927823]: Connection closed by 185.247.137.12 port 37911 [preauth] Oct 6 05:34:59 ip-172-31-29-215 sshd[3927829]: error: kex_exchange_identification: Connection closed by remote host Oct 6 05:39:01 ip-172-31-29-215 CRON[3927832]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 05:39:01 ip-172-31-29-215 CRON[3927832]: pam_unix(cron:session): session closed for user root Oct 6 05:40:01 ip-172-31-29-215 CRON[3927890]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 05:40:02 ip-172-31-29-215 CRON[3927890]: pam_unix(cron:session): session closed for user smmsp Oct 6 06:00:01 ip-172-31-29-215 CRON[3927932]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 06:00:01 ip-172-31-29-215 CRON[3927932]: pam_unix(cron:session): session closed for user smmsp Oct 6 06:09:01 ip-172-31-29-215 CRON[3927961]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 06:09:01 ip-172-31-29-215 CRON[3927961]: pam_unix(cron:session): session closed for user root Oct 6 06:17:01 ip-172-31-29-215 CRON[3928019]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 06:17:01 ip-172-31-29-215 CRON[3928019]: pam_unix(cron:session): session closed for user root Oct 6 06:18:46 ip-172-31-29-215 sshd[3928023]: Connection closed by authenticating user root 171.244.62.70 port 45704 [preauth] Oct 6 06:19:16 ip-172-31-29-215 sshd[3928026]: Invalid user spit from 103.146.52.252 port 55022 Oct 6 06:19:16 ip-172-31-29-215 sshd[3928026]: Received disconnect from 103.146.52.252 port 55022:11: Bye Bye [preauth] Oct 6 06:19:16 ip-172-31-29-215 sshd[3928026]: Disconnected from invalid user spit 103.146.52.252 port 55022 [preauth] Oct 6 06:19:21 ip-172-31-29-215 sshd[3928028]: Invalid user denise from 163.44.173.168 port 41118 Oct 6 06:19:21 ip-172-31-29-215 sshd[3928028]: Received disconnect from 163.44.173.168 port 41118:11: Bye Bye [preauth] Oct 6 06:19:21 ip-172-31-29-215 sshd[3928028]: Disconnected from invalid user denise 163.44.173.168 port 41118 [preauth] Oct 6 06:20:01 ip-172-31-29-215 CRON[3928030]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 06:20:01 ip-172-31-29-215 CRON[3928030]: pam_unix(cron:session): session closed for user smmsp Oct 6 06:21:47 ip-172-31-29-215 sshd[3928053]: Invalid user support from 103.146.52.252 port 52840 Oct 6 06:21:47 ip-172-31-29-215 sshd[3928053]: Received disconnect from 103.146.52.252 port 52840:11: Bye Bye [preauth] Oct 6 06:21:47 ip-172-31-29-215 sshd[3928053]: Disconnected from invalid user support 103.146.52.252 port 52840 [preauth] Oct 6 06:22:19 ip-172-31-29-215 sshd[3928056]: Invalid user security from 163.44.173.168 port 37298 Oct 6 06:22:19 ip-172-31-29-215 sshd[3928056]: Received disconnect from 163.44.173.168 port 37298:11: Bye Bye [preauth] Oct 6 06:22:19 ip-172-31-29-215 sshd[3928056]: Disconnected from invalid user security 163.44.173.168 port 37298 [preauth] Oct 6 06:23:16 ip-172-31-29-215 sshd[3928058]: Invalid user ruth from 103.146.52.252 port 36138 Oct 6 06:23:16 ip-172-31-29-215 sshd[3928058]: Received disconnect from 103.146.52.252 port 36138:11: Bye Bye [preauth] Oct 6 06:23:16 ip-172-31-29-215 sshd[3928058]: Disconnected from invalid user ruth 103.146.52.252 port 36138 [preauth] Oct 6 06:24:13 ip-172-31-29-215 sshd[3928060]: Invalid user burgess from 163.44.173.168 port 47582 Oct 6 06:24:13 ip-172-31-29-215 sshd[3928060]: Received disconnect from 163.44.173.168 port 47582:11: Bye Bye [preauth] Oct 6 06:24:13 ip-172-31-29-215 sshd[3928060]: Disconnected from invalid user burgess 163.44.173.168 port 47582 [preauth] Oct 6 06:24:40 ip-172-31-29-215 sshd[3928062]: Invalid user file from 103.146.52.252 port 33388 Oct 6 06:24:40 ip-172-31-29-215 sshd[3928062]: Received disconnect from 103.146.52.252 port 33388:11: Bye Bye [preauth] Oct 6 06:24:40 ip-172-31-29-215 sshd[3928062]: Disconnected from invalid user file 103.146.52.252 port 33388 [preauth] Oct 6 06:25:01 ip-172-31-29-215 CRON[3928065]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 06:25:01 ip-172-31-29-215 CRON[3928065]: pam_unix(cron:session): session closed for user root Oct 6 06:25:56 ip-172-31-29-215 sshd[3928156]: Invalid user friend from 163.44.173.168 port 57852 Oct 6 06:25:57 ip-172-31-29-215 sshd[3928156]: Received disconnect from 163.44.173.168 port 57852:11: Bye Bye [preauth] Oct 6 06:25:57 ip-172-31-29-215 sshd[3928156]: Disconnected from invalid user friend 163.44.173.168 port 57852 [preauth] Oct 6 06:26:06 ip-172-31-29-215 sshd[3928158]: Invalid user ariadne from 103.146.52.252 port 40472 Oct 6 06:26:06 ip-172-31-29-215 sshd[3928158]: Received disconnect from 103.146.52.252 port 40472:11: Bye Bye [preauth] Oct 6 06:26:06 ip-172-31-29-215 sshd[3928158]: Disconnected from invalid user ariadne 103.146.52.252 port 40472 [preauth] Oct 6 06:28:21 ip-172-31-29-215 sshd[3928163]: Connection closed by authenticating user root 59.24.133.197 port 35316 [preauth] Oct 6 06:28:29 ip-172-31-29-215 sshd[3928165]: Connection closed by authenticating user root 110.10.89.78 port 53878 [preauth] Oct 6 06:39:01 ip-172-31-29-215 CRON[3928249]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 06:39:01 ip-172-31-29-215 CRON[3928249]: pam_unix(cron:session): session closed for user root Oct 6 06:40:00 ip-172-31-29-215 sshd[3928305]: Connection closed by 14.103.123.232 port 32774 [preauth] Oct 6 06:40:01 ip-172-31-29-215 CRON[3928307]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 06:40:01 ip-172-31-29-215 CRON[3928307]: pam_unix(cron:session): session closed for user smmsp Oct 6 06:44:04 ip-172-31-29-215 sshd[3928332]: Invalid user aptuslegal from 51.77.151.101 port 48174 Oct 6 06:44:04 ip-172-31-29-215 sshd[3928332]: Connection closed by invalid user aptuslegal 51.77.151.101 port 48174 [preauth] Oct 6 06:53:41 ip-172-31-29-215 sshd[3928337]: Invalid user liyan from 198.12.114.232 port 40894 Oct 6 06:53:41 ip-172-31-29-215 sshd[3928337]: Received disconnect from 198.12.114.232 port 40894:11: Bye Bye [preauth] Oct 6 06:53:41 ip-172-31-29-215 sshd[3928337]: Disconnected from invalid user liyan 198.12.114.232 port 40894 [preauth] Oct 6 06:55:59 ip-172-31-29-215 sshd[3928340]: Invalid user xiaoyu from 198.12.114.232 port 54954 Oct 6 06:55:59 ip-172-31-29-215 sshd[3928340]: Received disconnect from 198.12.114.232 port 54954:11: Bye Bye [preauth] Oct 6 06:55:59 ip-172-31-29-215 sshd[3928340]: Disconnected from invalid user xiaoyu 198.12.114.232 port 54954 [preauth] Oct 6 06:56:07 ip-172-31-29-215 sshd[3928342]: Invalid user servy from 121.229.5.171 port 40608 Oct 6 06:56:08 ip-172-31-29-215 sshd[3928342]: Received disconnect from 121.229.5.171 port 40608:11: Bye Bye [preauth] Oct 6 06:56:08 ip-172-31-29-215 sshd[3928342]: Disconnected from invalid user servy 121.229.5.171 port 40608 [preauth] Oct 6 06:57:29 ip-172-31-29-215 sshd[3928344]: Invalid user prabhjot from 198.12.114.232 port 39818 Oct 6 06:57:29 ip-172-31-29-215 sshd[3928344]: Received disconnect from 198.12.114.232 port 39818:11: Bye Bye [preauth] Oct 6 06:57:29 ip-172-31-29-215 sshd[3928344]: Disconnected from invalid user prabhjot 198.12.114.232 port 39818 [preauth] Oct 6 06:59:02 ip-172-31-29-215 sshd[3928352]: Invalid user josh from 198.12.114.232 port 50702 Oct 6 06:59:02 ip-172-31-29-215 sshd[3928352]: Received disconnect from 198.12.114.232 port 50702:11: Bye Bye [preauth] Oct 6 06:59:02 ip-172-31-29-215 sshd[3928352]: Disconnected from invalid user josh 198.12.114.232 port 50702 [preauth] Oct 6 07:00:01 ip-172-31-29-215 CRON[3928355]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 07:00:01 ip-172-31-29-215 CRON[3928355]: pam_unix(cron:session): session closed for user smmsp Oct 6 07:01:39 ip-172-31-29-215 sshd[3928377]: Invalid user aptuslegal from 162.240.61.39 port 60570 Oct 6 07:01:39 ip-172-31-29-215 sshd[3928377]: Connection closed by invalid user aptuslegal 162.240.61.39 port 60570 [preauth] Oct 6 07:03:52 ip-172-31-29-215 sshd[3928379]: Accepted publickey for ubuntu from 189.203.182.33 port 7217 ssh2: RSA SHA256:Zqk1VR7n9VKAJSML2oy4Swt5sm7d+ABJKnVgCDEu32k Oct 6 07:03:52 ip-172-31-29-215 sshd[3928379]: pam_unix(sshd:session): session opened for user ubuntu by (uid=0) Oct 6 07:03:52 ip-172-31-29-215 systemd-logind[500]: New session 53570 of user ubuntu. Oct 6 07:03:52 ip-172-31-29-215 systemd: pam_unix(systemd-user:session): session opened for user ubuntu by (uid=0) Oct 6 07:04:18 ip-172-31-29-215 dbus-daemon[475]: [system] Failed to activate service 'org.bluez': timed out (service_start_timeout=25000ms) Oct 6 07:09:01 ip-172-31-29-215 CRON[3928748]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 07:09:01 ip-172-31-29-215 CRON[3928748]: pam_unix(cron:session): session closed for user root Oct 6 07:14:47 ip-172-31-29-215 sshd[3928808]: Invalid user precious from 163.44.173.168 port 60966 Oct 6 07:14:47 ip-172-31-29-215 sshd[3928808]: Received disconnect from 163.44.173.168 port 60966:11: Bye Bye [preauth] Oct 6 07:14:47 ip-172-31-29-215 sshd[3928808]: Disconnected from invalid user precious 163.44.173.168 port 60966 [preauth] Oct 6 07:14:57 ip-172-31-29-215 sshd[3928810]: error: kex_exchange_identification: Connection closed by remote host Oct 6 07:16:31 ip-172-31-29-215 sshd[3928813]: Invalid user moguls from 163.44.173.168 port 43006 Oct 6 07:16:32 ip-172-31-29-215 sshd[3928813]: Received disconnect from 163.44.173.168 port 43006:11: Bye Bye [preauth] Oct 6 07:16:32 ip-172-31-29-215 sshd[3928813]: Disconnected from invalid user moguls 163.44.173.168 port 43006 [preauth] Oct 6 07:17:01 ip-172-31-29-215 CRON[3928815]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 07:17:01 ip-172-31-29-215 CRON[3928815]: pam_unix(cron:session): session closed for user root Oct 6 07:20:01 ip-172-31-29-215 CRON[3928822]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 07:20:01 ip-172-31-29-215 CRON[3928822]: pam_unix(cron:session): session closed for user smmsp Oct 6 07:23:37 ip-172-31-29-215 sshd[3928845]: Connection closed by authenticating user root 171.244.62.70 port 38954 [preauth] Oct 6 07:33:07 ip-172-31-29-215 sshd[3928855]: Connection closed by authenticating user root 59.24.133.197 port 44758 [preauth] Oct 6 07:38:24 ip-172-31-29-215 sshd[3928862]: Connection closed by authenticating user root 103.188.167.170 port 40766 [preauth] Oct 6 07:39:01 ip-172-31-29-215 CRON[3928865]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 07:39:01 ip-172-31-29-215 CRON[3928865]: pam_unix(cron:session): session closed for user root Oct 6 07:39:27 ip-172-31-29-215 sshd[3928920]: Connection closed by authenticating user root 1.15.90.110 port 49086 [preauth] Oct 6 07:40:01 ip-172-31-29-215 CRON[3928924]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 07:40:01 ip-172-31-29-215 CRON[3928924]: pam_unix(cron:session): session closed for user smmsp Oct 6 07:49:13 ip-172-31-29-215 sshd[3928998]: Invalid user aptuslegal from 162.240.61.39 port 50700 Oct 6 07:49:14 ip-172-31-29-215 sshd[3928998]: Connection closed by invalid user aptuslegal 162.240.61.39 port 50700 [preauth] Oct 6 08:00:01 ip-172-31-29-215 CRON[3929008]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 08:00:01 ip-172-31-29-215 CRON[3929008]: pam_unix(cron:session): session closed for user smmsp Oct 6 08:09:01 ip-172-31-29-215 CRON[3929038]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 08:09:01 ip-172-31-29-215 CRON[3929038]: pam_unix(cron:session): session closed for user root Oct 6 08:14:42 ip-172-31-29-215 sshd[3929102]: Invalid user aptuslegal from 146.190.105.116 port 46518 Oct 6 08:14:43 ip-172-31-29-215 sshd[3929102]: Connection closed by invalid user aptuslegal 146.190.105.116 port 46518 [preauth] Oct 6 08:17:01 ip-172-31-29-215 CRON[3929106]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 08:17:01 ip-172-31-29-215 CRON[3929106]: pam_unix(cron:session): session closed for user root Oct 6 08:20:01 ip-172-31-29-215 CRON[3929113]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 08:20:01 ip-172-31-29-215 CRON[3929113]: pam_unix(cron:session): session closed for user smmsp Oct 6 08:26:19 ip-172-31-29-215 sshd[3929139]: Connection closed by authenticating user root 51.77.151.101 port 33298 [preauth] Oct 6 08:28:26 ip-172-31-29-215 sshd[3929144]: Connection closed by authenticating user root 171.244.62.70 port 49616 [preauth] Oct 6 08:34:29 ip-172-31-29-215 sshd[3929150]: Invalid user alex from 180.76.145.111 port 47836 Oct 6 08:34:30 ip-172-31-29-215 sshd[3929150]: Received disconnect from 180.76.145.111 port 47836:11: Bye Bye [preauth] Oct 6 08:34:30 ip-172-31-29-215 sshd[3929150]: Disconnected from invalid user alex 180.76.145.111 port 47836 [preauth] Oct 6 08:35:02 ip-172-31-29-215 sshd[3929152]: Invalid user admin from 170.64.227.36 port 37502 Oct 6 08:35:03 ip-172-31-29-215 sshd[3929152]: Connection closed by invalid user admin 170.64.227.36 port 37502 [preauth] Oct 6 08:35:11 ip-172-31-29-215 sshd[3929155]: Invalid user admin from 64.227.136.122 port 46648 Oct 6 08:35:11 ip-172-31-29-215 sshd[3929155]: Connection closed by invalid user admin 64.227.136.122 port 46648 [preauth] Oct 6 08:38:01 ip-172-31-29-215 sshd[3929161]: Connection closed by authenticating user root 59.24.133.197 port 53838 [preauth] Oct 6 08:38:02 ip-172-31-29-215 sshd[3929159]: Received disconnect from 180.76.145.111 port 40578:11: Bye Bye [preauth] Oct 6 08:38:02 ip-172-31-29-215 sshd[3929159]: Disconnected from authenticating user ubuntu 180.76.145.111 port 40578 [preauth] Oct 6 08:39:01 ip-172-31-29-215 CRON[3929164]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 08:39:01 ip-172-31-29-215 CRON[3929164]: pam_unix(cron:session): session closed for user root Oct 6 08:39:31 ip-172-31-29-215 sshd[3929221]: Connection closed by authenticating user root 103.183.74.60 port 50074 [preauth] Oct 6 08:40:01 ip-172-31-29-215 CRON[3929224]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 08:40:01 ip-172-31-29-215 CRON[3929224]: pam_unix(cron:session): session closed for user smmsp Oct 6 09:00:01 ip-172-31-29-215 CRON[3929283]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 09:00:01 ip-172-31-29-215 CRON[3929283]: pam_unix(cron:session): session closed for user smmsp Oct 6 09:05:18 ip-172-31-29-215 sshd[3929309]: Connection closed by authenticating user root 161.97.186.240 port 43472 [preauth] Oct 6 09:09:01 ip-172-31-29-215 CRON[3929332]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 09:09:01 ip-172-31-29-215 CRON[3929332]: pam_unix(cron:session): session closed for user root Oct 6 09:17:01 ip-172-31-29-215 CRON[3929400]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 09:17:01 ip-172-31-29-215 CRON[3929400]: pam_unix(cron:session): session closed for user root Oct 6 09:20:01 ip-172-31-29-215 CRON[3929424]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 09:20:01 ip-172-31-29-215 CRON[3929424]: pam_unix(cron:session): session closed for user smmsp Oct 6 09:28:40 ip-172-31-29-215 sshd[3929571]: Invalid user steam from 180.76.145.111 port 47790 Oct 6 09:28:40 ip-172-31-29-215 sshd[3929571]: Received disconnect from 180.76.145.111 port 47790:11: Bye Bye [preauth] Oct 6 09:28:40 ip-172-31-29-215 sshd[3929571]: Disconnected from invalid user steam 180.76.145.111 port 47790 [preauth] Oct 6 09:33:35 ip-172-31-29-215 sshd[3929586]: Invalid user aptuslegal from 171.244.62.70 port 50726 Oct 6 09:33:35 ip-172-31-29-215 sshd[3929586]: Connection closed by invalid user aptuslegal 171.244.62.70 port 50726 [preauth] Oct 6 09:37:51 ip-172-31-29-215 sshd[3929590]: Received disconnect from 14.139.105.2 port 47256:11: Bye Bye [preauth] Oct 6 09:37:51 ip-172-31-29-215 sshd[3929590]: Disconnected from authenticating user ubuntu 14.139.105.2 port 47256 [preauth] Oct 6 09:39:01 ip-172-31-29-215 CRON[3929596]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 09:39:01 ip-172-31-29-215 CRON[3929596]: pam_unix(cron:session): session closed for user root Oct 6 09:40:01 ip-172-31-29-215 CRON[3929653]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 09:40:01 ip-172-31-29-215 CRON[3929653]: pam_unix(cron:session): session closed for user smmsp Oct 6 09:40:24 ip-172-31-29-215 sshd[3929679]: Received disconnect from 14.139.105.2 port 48100:11: Bye Bye [preauth] Oct 6 09:40:24 ip-172-31-29-215 sshd[3929679]: Disconnected from authenticating user ubuntu 14.139.105.2 port 48100 [preauth] Oct 6 09:40:49 ip-172-31-29-215 sshd[3929694]: Connection closed by authenticating user root 103.188.167.170 port 58230 [preauth] Oct 6 09:42:17 ip-172-31-29-215 sshd[3929696]: Received disconnect from 14.139.105.2 port 60380:11: Bye Bye [preauth] Oct 6 09:42:17 ip-172-31-29-215 sshd[3929696]: Disconnected from authenticating user ubuntu 14.139.105.2 port 60380 [preauth] Oct 6 09:43:14 ip-172-31-29-215 sshd[3929713]: Received disconnect from 206.189.131.246 port 43608:11: Bye Bye [preauth] Oct 6 09:43:14 ip-172-31-29-215 sshd[3929713]: Disconnected from authenticating user ubuntu 206.189.131.246 port 43608 [preauth] Oct 6 09:44:11 ip-172-31-29-215 sshd[3929717]: Received disconnect from 14.139.105.2 port 44078:11: Bye Bye [preauth] Oct 6 09:44:11 ip-172-31-29-215 sshd[3929717]: Disconnected from authenticating user ubuntu 14.139.105.2 port 44078 [preauth] Oct 6 09:45:14 ip-172-31-29-215 sshd[3929719]: Received disconnect from 206.189.131.246 port 43190:11: Bye Bye [preauth] Oct 6 09:45:14 ip-172-31-29-215 sshd[3929719]: Disconnected from authenticating user ubuntu 206.189.131.246 port 43190 [preauth] Oct 6 09:46:00 ip-172-31-29-215 sshd[3929722]: Received disconnect from 14.139.105.2 port 55006:11: Bye Bye [preauth] Oct 6 09:46:00 ip-172-31-29-215 sshd[3929722]: Disconnected from authenticating user ubuntu 14.139.105.2 port 55006 [preauth] Oct 6 09:47:02 ip-172-31-29-215 sshd[3929724]: Received disconnect from 206.189.131.246 port 34438:11: Bye Bye [preauth] Oct 6 09:47:02 ip-172-31-29-215 sshd[3929724]: Disconnected from authenticating user ubuntu 206.189.131.246 port 34438 [preauth] Oct 6 09:47:55 ip-172-31-29-215 sshd[3929726]: Received disconnect from 14.139.105.2 port 39300:11: Bye Bye [preauth] Oct 6 09:47:55 ip-172-31-29-215 sshd[3929726]: Disconnected from authenticating user ubuntu 14.139.105.2 port 39300 [preauth] Oct 6 09:48:46 ip-172-31-29-215 sshd[3929729]: Received disconnect from 206.189.131.246 port 56700:11: Bye Bye [preauth] Oct 6 09:48:46 ip-172-31-29-215 sshd[3929729]: Disconnected from authenticating user ubuntu 206.189.131.246 port 56700 [preauth] Oct 6 09:49:45 ip-172-31-29-215 sshd[3929734]: Received disconnect from 14.139.105.2 port 50266:11: Bye Bye [preauth] Oct 6 09:49:45 ip-172-31-29-215 sshd[3929734]: Disconnected from authenticating user ubuntu 14.139.105.2 port 50266 [preauth] Oct 6 09:49:47 ip-172-31-29-215 sshd[3929736]: Connection closed by authenticating user root 110.10.89.78 port 57038 [preauth] Oct 6 09:50:37 ip-172-31-29-215 sshd[3929752]: Received disconnect from 206.189.131.246 port 54794:11: Bye Bye [preauth] Oct 6 09:50:37 ip-172-31-29-215 sshd[3929752]: Disconnected from authenticating user ubuntu 206.189.131.246 port 54794 [preauth] Oct 6 09:51:35 ip-172-31-29-215 sshd[3929754]: Received disconnect from 14.139.105.2 port 33100:11: Bye Bye [preauth] Oct 6 09:51:35 ip-172-31-29-215 sshd[3929754]: Disconnected from authenticating user ubuntu 14.139.105.2 port 33100 [preauth] Oct 6 09:52:20 ip-172-31-29-215 sshd[3929757]: Received disconnect from 206.189.131.246 port 58684:11: Bye Bye [preauth] Oct 6 09:52:20 ip-172-31-29-215 sshd[3929757]: Disconnected from authenticating user ubuntu 206.189.131.246 port 58684 [preauth] Oct 6 09:53:25 ip-172-31-29-215 sshd[3929759]: Received disconnect from 14.139.105.2 port 44106:11: Bye Bye [preauth] Oct 6 09:53:25 ip-172-31-29-215 sshd[3929759]: Disconnected from authenticating user ubuntu 14.139.105.2 port 44106 [preauth] Oct 6 09:54:02 ip-172-31-29-215 sshd[3929761]: Received disconnect from 206.189.131.246 port 60156:11: Bye Bye [preauth] Oct 6 09:54:02 ip-172-31-29-215 sshd[3929761]: Disconnected from authenticating user ubuntu 206.189.131.246 port 60156 [preauth] Oct 6 09:55:14 ip-172-31-29-215 sshd[3929770]: Received disconnect from 14.139.105.2 port 55208:11: Bye Bye [preauth] Oct 6 09:55:14 ip-172-31-29-215 sshd[3929770]: Disconnected from authenticating user ubuntu 14.139.105.2 port 55208 [preauth] Oct 6 09:55:43 ip-172-31-29-215 sshd[3929780]: Received disconnect from 206.189.131.246 port 44110:11: Bye Bye [preauth] Oct 6 09:55:43 ip-172-31-29-215 sshd[3929780]: Disconnected from authenticating user ubuntu 206.189.131.246 port 44110 [preauth] Oct 6 09:57:09 ip-172-31-29-215 sshd[3929782]: Received disconnect from 14.139.105.2 port 39534:11: Bye Bye [preauth] Oct 6 09:57:09 ip-172-31-29-215 sshd[3929782]: Disconnected from authenticating user ubuntu 14.139.105.2 port 39534 [preauth] Oct 6 09:57:34 ip-172-31-29-215 sshd[3929784]: Received disconnect from 206.189.131.246 port 40238:11: Bye Bye [preauth] Oct 6 09:57:34 ip-172-31-29-215 sshd[3929784]: Disconnected from authenticating user ubuntu 206.189.131.246 port 40238 [preauth] Oct 6 09:59:00 ip-172-31-29-215 sshd[3929790]: Received disconnect from 14.139.105.2 port 50970:11: Bye Bye [preauth] Oct 6 09:59:00 ip-172-31-29-215 sshd[3929790]: Disconnected from authenticating user ubuntu 14.139.105.2 port 50970 [preauth] Oct 6 09:59:19 ip-172-31-29-215 sshd[3929793]: Received disconnect from 206.189.131.246 port 56594:11: Bye Bye [preauth] Oct 6 09:59:19 ip-172-31-29-215 sshd[3929793]: Disconnected from authenticating user ubuntu 206.189.131.246 port 56594 [preauth] Oct 6 10:00:01 ip-172-31-29-215 CRON[3929795]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 10:00:01 ip-172-31-29-215 CRON[3929795]: pam_unix(cron:session): session closed for user smmsp Oct 6 10:00:45 ip-172-31-29-215 sshd[3929818]: Received disconnect from 14.139.105.2 port 32840:11: Bye Bye [preauth] Oct 6 10:00:45 ip-172-31-29-215 sshd[3929818]: Disconnected from authenticating user ubuntu 14.139.105.2 port 32840 [preauth] Oct 6 10:01:02 ip-172-31-29-215 sshd[3929821]: Received disconnect from 206.189.131.246 port 38070:11: Bye Bye [preauth] Oct 6 10:01:02 ip-172-31-29-215 sshd[3929821]: Disconnected from authenticating user ubuntu 206.189.131.246 port 38070 [preauth] Oct 6 10:02:35 ip-172-31-29-215 sshd[3929823]: Received disconnect from 14.139.105.2 port 43852:11: Bye Bye [preauth] Oct 6 10:02:35 ip-172-31-29-215 sshd[3929823]: Disconnected from authenticating user ubuntu 14.139.105.2 port 43852 [preauth] Oct 6 10:02:53 ip-172-31-29-215 sshd[3929825]: Received disconnect from 206.189.131.246 port 59934:11: Bye Bye [preauth] Oct 6 10:02:53 ip-172-31-29-215 sshd[3929825]: Disconnected from authenticating user ubuntu 206.189.131.246 port 59934 [preauth] Oct 6 10:04:29 ip-172-31-29-215 sshd[3929829]: Received disconnect from 14.139.105.2 port 55958:11: Bye Bye [preauth] Oct 6 10:04:29 ip-172-31-29-215 sshd[3929829]: Disconnected from authenticating user ubuntu 14.139.105.2 port 55958 [preauth] Oct 6 10:06:21 ip-172-31-29-215 sshd[3929832]: Received disconnect from 14.139.105.2 port 39538:11: Bye Bye [preauth] Oct 6 10:06:21 ip-172-31-29-215 sshd[3929832]: Disconnected from authenticating user ubuntu 14.139.105.2 port 39538 [preauth] Oct 6 10:08:10 ip-172-31-29-215 sshd[3929836]: Received disconnect from 14.139.105.2 port 50552:11: Bye Bye [preauth] Oct 6 10:08:10 ip-172-31-29-215 sshd[3929836]: Disconnected from authenticating user ubuntu 14.139.105.2 port 50552 [preauth] Oct 6 10:09:01 ip-172-31-29-215 CRON[3929843]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 10:09:01 ip-172-31-29-215 CRON[3929843]: pam_unix(cron:session): session closed for user root Oct 6 10:10:05 ip-172-31-29-215 sshd[3929900]: Received disconnect from 14.139.105.2 port 34168:11: Bye Bye [preauth] Oct 6 10:10:05 ip-172-31-29-215 sshd[3929900]: Disconnected from authenticating user ubuntu 14.139.105.2 port 34168 [preauth] Oct 6 10:12:01 ip-172-31-29-215 sshd[3929916]: Received disconnect from 14.139.105.2 port 46610:11: Bye Bye [preauth] Oct 6 10:12:01 ip-172-31-29-215 sshd[3929916]: Disconnected from authenticating user ubuntu 14.139.105.2 port 46610 [preauth] Oct 6 10:13:52 ip-172-31-29-215 sshd[3929925]: Received disconnect from 14.139.105.2 port 57372:11: Bye Bye [preauth] Oct 6 10:13:52 ip-172-31-29-215 sshd[3929925]: Disconnected from authenticating user ubuntu 14.139.105.2 port 57372 [preauth] Oct 6 10:15:41 ip-172-31-29-215 sshd[3929940]: Received disconnect from 14.139.105.2 port 39654:11: Bye Bye [preauth] Oct 6 10:15:41 ip-172-31-29-215 sshd[3929940]: Disconnected from authenticating user ubuntu 14.139.105.2 port 39654 [preauth] Oct 6 10:17:01 ip-172-31-29-215 CRON[3929944]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 10:17:01 ip-172-31-29-215 CRON[3929944]: pam_unix(cron:session): session closed for user root Oct 6 10:17:34 ip-172-31-29-215 sshd[3929947]: Received disconnect from 14.139.105.2 port 50610:11: Bye Bye [preauth] Oct 6 10:17:34 ip-172-31-29-215 sshd[3929947]: Disconnected from authenticating user ubuntu 14.139.105.2 port 50610 [preauth] Oct 6 10:19:22 ip-172-31-29-215 sshd[3929952]: Received disconnect from 14.139.105.2 port 33336:11: Bye Bye [preauth] Oct 6 10:19:22 ip-172-31-29-215 sshd[3929952]: Disconnected from authenticating user ubuntu 14.139.105.2 port 33336 [preauth] Oct 6 10:20:01 ip-172-31-29-215 CRON[3929954]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 10:20:01 ip-172-31-29-215 CRON[3929954]: pam_unix(cron:session): session closed for user smmsp Oct 6 10:21:12 ip-172-31-29-215 sshd[3929989]: Received disconnect from 14.139.105.2 port 44444:11: Bye Bye [preauth] Oct 6 10:21:12 ip-172-31-29-215 sshd[3929989]: Disconnected from authenticating user ubuntu 14.139.105.2 port 44444 [preauth] Oct 6 10:23:07 ip-172-31-29-215 sshd[3929998]: Received disconnect from 14.139.105.2 port 56716:11: Bye Bye [preauth] Oct 6 10:23:07 ip-172-31-29-215 sshd[3929998]: Disconnected from authenticating user ubuntu 14.139.105.2 port 56716 [preauth] Oct 6 10:23:16 ip-172-31-29-215 sshd[3930004]: Invalid user aptuslegal from 162.240.61.39 port 53044 Oct 6 10:23:16 ip-172-31-29-215 sshd[3930004]: Connection closed by invalid user aptuslegal 162.240.61.39 port 53044 [preauth] Oct 6 10:24:23 ip-172-31-29-215 sshd[3930012]: Connection closed by 173.19.21.79 port 56904 [preauth] Oct 6 10:25:01 ip-172-31-29-215 sshd[3930015]: Received disconnect from 14.139.105.2 port 40772:11: Bye Bye [preauth] Oct 6 10:25:01 ip-172-31-29-215 sshd[3930015]: Disconnected from authenticating user ubuntu 14.139.105.2 port 40772 [preauth] Oct 6 10:26:47 ip-172-31-29-215 sshd[3930024]: Received disconnect from 14.139.105.2 port 35458:11: Bye Bye [preauth] Oct 6 10:26:47 ip-172-31-29-215 sshd[3930024]: Disconnected from authenticating user ubuntu 14.139.105.2 port 35458 [preauth] Oct 6 10:28:40 ip-172-31-29-215 sshd[3930039]: Received disconnect from 14.139.105.2 port 41070:11: Bye Bye [preauth] Oct 6 10:28:40 ip-172-31-29-215 sshd[3930039]: Disconnected from authenticating user ubuntu 14.139.105.2 port 41070 [preauth] Oct 6 10:30:32 ip-172-31-29-215 sshd[3930051]: Received disconnect from 14.139.105.2 port 55802:11: Bye Bye [preauth] Oct 6 10:30:32 ip-172-31-29-215 sshd[3930051]: Disconnected from authenticating user ubuntu 14.139.105.2 port 55802 [preauth] Oct 6 10:32:19 ip-172-31-29-215 sshd[3930066]: Received disconnect from 14.139.105.2 port 38134:11: Bye Bye [preauth] Oct 6 10:32:19 ip-172-31-29-215 sshd[3930066]: Disconnected from authenticating user ubuntu 14.139.105.2 port 38134 [preauth] Oct 6 10:38:20 ip-172-31-29-215 sshd[3930131]: Connection closed by authenticating user root 171.244.62.70 port 35586 [preauth] Oct 6 10:39:01 ip-172-31-29-215 CRON[3930134]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 10:39:01 ip-172-31-29-215 CRON[3930134]: pam_unix(cron:session): session closed for user root Oct 6 10:40:01 ip-172-31-29-215 CRON[3930190]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 10:40:01 ip-172-31-29-215 CRON[3930190]: pam_unix(cron:session): session closed for user smmsp Oct 6 11:00:01 ip-172-31-29-215 CRON[3930342]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 11:00:01 ip-172-31-29-215 CRON[3930342]: pam_unix(cron:session): session closed for user smmsp Oct 6 11:09:01 ip-172-31-29-215 CRON[3930454]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 11:09:01 ip-172-31-29-215 CRON[3930454]: pam_unix(cron:session): session closed for user root Oct 6 11:17:01 ip-172-31-29-215 CRON[3930553]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 11:17:01 ip-172-31-29-215 CRON[3930553]: pam_unix(cron:session): session closed for user root Oct 6 11:20:01 ip-172-31-29-215 CRON[3930589]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 11:20:02 ip-172-31-29-215 CRON[3930589]: pam_unix(cron:session): session closed for user smmsp Oct 6 11:23:07 ip-172-31-29-215 sshd[3930654]: Connection closed by 13.219.78.203 port 51670 [preauth] Oct 6 11:28:03 ip-172-31-29-215 sshd[3930683]: Invalid user ansible from 123.160.167.73 port 48392 Oct 6 11:28:03 ip-172-31-29-215 sshd[3930683]: Received disconnect from 123.160.167.73 port 48392:11: Bye Bye [preauth] Oct 6 11:28:03 ip-172-31-29-215 sshd[3930683]: Disconnected from invalid user ansible 123.160.167.73 port 48392 [preauth] Oct 6 11:33:01 ip-172-31-29-215 sshd[3930689]: Invalid user sol from 123.160.167.73 port 50556 Oct 6 11:33:01 ip-172-31-29-215 sshd[3930689]: Received disconnect from 123.160.167.73 port 50556:11: Bye Bye [preauth] Oct 6 11:33:01 ip-172-31-29-215 sshd[3930689]: Disconnected from invalid user sol 123.160.167.73 port 50556 [preauth] Oct 6 11:35:22 ip-172-31-29-215 sshd[3930723]: Invalid user postgres from 123.160.167.73 port 52190 Oct 6 11:35:22 ip-172-31-29-215 sshd[3930723]: Received disconnect from 123.160.167.73 port 52190:11: Bye Bye [preauth] Oct 6 11:35:22 ip-172-31-29-215 sshd[3930723]: Disconnected from invalid user postgres 123.160.167.73 port 52190 [preauth] Oct 6 11:39:01 ip-172-31-29-215 CRON[3930742]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 11:39:01 ip-172-31-29-215 CRON[3930742]: pam_unix(cron:session): session closed for user root Oct 6 11:40:01 ip-172-31-29-215 CRON[3930812]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 11:40:01 ip-172-31-29-215 CRON[3930812]: pam_unix(cron:session): session closed for user smmsp Oct 6 12:00:01 ip-172-31-29-215 CRON[3931106]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 12:00:01 ip-172-31-29-215 CRON[3931107]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 12:00:01 ip-172-31-29-215 CRON[3931106]: pam_unix(cron:session): session closed for user root Oct 6 12:00:01 ip-172-31-29-215 CRON[3931107]: pam_unix(cron:session): session closed for user smmsp Oct 6 12:04:15 ip-172-31-29-215 sshd[3931137]: Invalid user aptuslegal from 162.240.61.39 port 56704 Oct 6 12:04:16 ip-172-31-29-215 sshd[3931137]: Connection closed by invalid user aptuslegal 162.240.61.39 port 56704 [preauth] Oct 6 12:04:30 ip-172-31-29-215 sshd[3931139]: Invalid user from 170.64.164.172 port 40954 Oct 6 12:04:38 ip-172-31-29-215 sshd[3931139]: Connection closed by invalid user 170.64.164.172 port 40954 [preauth] Oct 6 12:09:01 ip-172-31-29-215 CRON[3931211]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 12:09:01 ip-172-31-29-215 CRON[3931211]: pam_unix(cron:session): session closed for user root Oct 6 12:09:37 ip-172-31-29-215 sshd[3931267]: Invalid user soporte from 47.247.99.155 port 34962 Oct 6 12:09:37 ip-172-31-29-215 sshd[3931267]: Received disconnect from 47.247.99.155 port 34962:11: Bye Bye [preauth] Oct 6 12:09:37 ip-172-31-29-215 sshd[3931267]: Disconnected from invalid user soporte 47.247.99.155 port 34962 [preauth] Oct 6 12:12:10 ip-172-31-29-215 sshd[3931285]: Invalid user soporte from 167.71.221.242 port 53992 Oct 6 12:12:11 ip-172-31-29-215 sshd[3931285]: Received disconnect from 167.71.221.242 port 53992:11: Bye Bye [preauth] Oct 6 12:12:11 ip-172-31-29-215 sshd[3931285]: Disconnected from invalid user soporte 167.71.221.242 port 53992 [preauth] Oct 6 12:12:12 ip-172-31-29-215 sshd[3931287]: Invalid user ali from 37.120.247.198 port 57216 Oct 6 12:12:12 ip-172-31-29-215 sshd[3931287]: Received disconnect from 37.120.247.198 port 57216:11: Bye Bye [preauth] Oct 6 12:12:12 ip-172-31-29-215 sshd[3931287]: Disconnected from invalid user ali 37.120.247.198 port 57216 [preauth] Oct 6 12:13:02 ip-172-31-29-215 sshd[3931302]: Invalid user teste from 47.247.99.155 port 41670 Oct 6 12:13:02 ip-172-31-29-215 sshd[3931302]: Received disconnect from 47.247.99.155 port 41670:11: Bye Bye [preauth] Oct 6 12:13:02 ip-172-31-29-215 sshd[3931302]: Disconnected from invalid user teste 47.247.99.155 port 41670 [preauth] Oct 6 12:13:49 ip-172-31-29-215 sshd[3931311]: Invalid user bitwarden from 37.120.247.198 port 52218 Oct 6 12:13:49 ip-172-31-29-215 sshd[3931311]: Received disconnect from 37.120.247.198 port 52218:11: Bye Bye [preauth] Oct 6 12:13:49 ip-172-31-29-215 sshd[3931311]: Disconnected from invalid user bitwarden 37.120.247.198 port 52218 [preauth] Oct 6 12:14:17 ip-172-31-29-215 sshd[3931313]: Invalid user soporte from 167.71.221.242 port 40300 Oct 6 12:14:17 ip-172-31-29-215 sshd[3931313]: Received disconnect from 167.71.221.242 port 40300:11: Bye Bye [preauth] Oct 6 12:14:17 ip-172-31-29-215 sshd[3931313]: Disconnected from invalid user soporte 167.71.221.242 port 40300 [preauth] Oct 6 12:15:01 ip-172-31-29-215 sshd[3931322]: Invalid user nexus from 47.247.99.155 port 33898 Oct 6 12:15:01 ip-172-31-29-215 sshd[3931322]: Received disconnect from 47.247.99.155 port 33898:11: Bye Bye [preauth] Oct 6 12:15:01 ip-172-31-29-215 sshd[3931322]: Disconnected from invalid user nexus 47.247.99.155 port 33898 [preauth] Oct 6 12:15:15 ip-172-31-29-215 sshd[3931328]: Invalid user me from 37.120.247.198 port 38904 Oct 6 12:15:16 ip-172-31-29-215 sshd[3931328]: Received disconnect from 37.120.247.198 port 38904:11: Bye Bye [preauth] Oct 6 12:15:16 ip-172-31-29-215 sshd[3931328]: Disconnected from invalid user me 37.120.247.198 port 38904 [preauth] Oct 6 12:16:11 ip-172-31-29-215 sshd[3931343]: Invalid user mc from 167.71.221.242 port 52476 Oct 6 12:16:11 ip-172-31-29-215 sshd[3931343]: Received disconnect from 167.71.221.242 port 52476:11: Bye Bye [preauth] Oct 6 12:16:11 ip-172-31-29-215 sshd[3931343]: Disconnected from invalid user mc 167.71.221.242 port 52476 [preauth] Oct 6 12:16:57 ip-172-31-29-215 sshd[3931350]: Invalid user adminuser from 37.120.247.198 port 41364 Oct 6 12:16:57 ip-172-31-29-215 sshd[3931350]: Received disconnect from 37.120.247.198 port 41364:11: Bye Bye [preauth] Oct 6 12:16:57 ip-172-31-29-215 sshd[3931350]: Disconnected from invalid user adminuser 37.120.247.198 port 41364 [preauth] Oct 6 12:17:01 ip-172-31-29-215 CRON[3931352]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 12:17:01 ip-172-31-29-215 CRON[3931352]: pam_unix(cron:session): session closed for user root Oct 6 12:17:07 ip-172-31-29-215 sshd[3931355]: Invalid user ali from 47.247.99.155 port 41616 Oct 6 12:17:07 ip-172-31-29-215 sshd[3931355]: Received disconnect from 47.247.99.155 port 41616:11: Bye Bye [preauth] Oct 6 12:17:07 ip-172-31-29-215 sshd[3931355]: Disconnected from invalid user ali 47.247.99.155 port 41616 [preauth] Oct 6 12:17:59 ip-172-31-29-215 sshd[3931361]: Invalid user adminuser from 167.71.221.242 port 36420 Oct 6 12:17:59 ip-172-31-29-215 sshd[3931361]: Received disconnect from 167.71.221.242 port 36420:11: Bye Bye [preauth] Oct 6 12:17:59 ip-172-31-29-215 sshd[3931361]: Disconnected from invalid user adminuser 167.71.221.242 port 36420 [preauth] Oct 6 12:18:16 ip-172-31-29-215 sshd[3931364]: Invalid user elasticsearch from 123.160.167.73 port 52398 Oct 6 12:18:16 ip-172-31-29-215 sshd[3931364]: Received disconnect from 123.160.167.73 port 52398:11: Bye Bye [preauth] Oct 6 12:18:16 ip-172-31-29-215 sshd[3931364]: Disconnected from invalid user elasticsearch 123.160.167.73 port 52398 [preauth] Oct 6 12:18:20 ip-172-31-29-215 sshd[3931366]: Invalid user github from 37.120.247.198 port 46646 Oct 6 12:18:20 ip-172-31-29-215 sshd[3931366]: Received disconnect from 37.120.247.198 port 46646:11: Bye Bye [preauth] Oct 6 12:18:20 ip-172-31-29-215 sshd[3931366]: Disconnected from invalid user github 37.120.247.198 port 46646 [preauth] Oct 6 12:19:09 ip-172-31-29-215 sshd[3931377]: Received disconnect from 47.247.99.155 port 57542:11: Bye Bye [preauth] Oct 6 12:19:09 ip-172-31-29-215 sshd[3931377]: Disconnected from authenticating user root 47.247.99.155 port 57542 [preauth] Oct 6 12:19:42 ip-172-31-29-215 sshd[3931384]: Invalid user github from 37.120.247.198 port 51336 Oct 6 12:19:43 ip-172-31-29-215 sshd[3931384]: Received disconnect from 37.120.247.198 port 51336:11: Bye Bye [preauth] Oct 6 12:19:43 ip-172-31-29-215 sshd[3931384]: Disconnected from invalid user github 37.120.247.198 port 51336 [preauth] Oct 6 12:19:47 ip-172-31-29-215 sshd[3931386]: Invalid user github from 167.71.221.242 port 48592 Oct 6 12:19:47 ip-172-31-29-215 sshd[3931386]: Received disconnect from 167.71.221.242 port 48592:11: Bye Bye [preauth] Oct 6 12:19:47 ip-172-31-29-215 sshd[3931386]: Disconnected from invalid user github 167.71.221.242 port 48592 [preauth] Oct 6 12:20:01 ip-172-31-29-215 CRON[3931388]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 12:20:01 ip-172-31-29-215 CRON[3931388]: pam_unix(cron:session): session closed for user smmsp Oct 6 12:20:57 ip-172-31-29-215 sshd[3931410]: Invalid user adminuser from 47.247.99.155 port 52246 Oct 6 12:20:57 ip-172-31-29-215 sshd[3931410]: Received disconnect from 47.247.99.155 port 52246:11: Bye Bye [preauth] Oct 6 12:20:57 ip-172-31-29-215 sshd[3931410]: Disconnected from invalid user adminuser 47.247.99.155 port 52246 [preauth] Oct 6 12:21:04 ip-172-31-29-215 sshd[3931412]: Invalid user teamspeak from 37.120.247.198 port 42764 Oct 6 12:21:04 ip-172-31-29-215 sshd[3931412]: Received disconnect from 37.120.247.198 port 42764:11: Bye Bye [preauth] Oct 6 12:21:04 ip-172-31-29-215 sshd[3931412]: Disconnected from invalid user teamspeak 37.120.247.198 port 42764 [preauth] Oct 6 12:22:27 ip-172-31-29-215 sshd[3931427]: Received disconnect from 37.120.247.198 port 42586:11: Bye Bye [preauth] Oct 6 12:22:27 ip-172-31-29-215 sshd[3931427]: Disconnected from authenticating user root 37.120.247.198 port 42586 [preauth] Oct 6 12:22:51 ip-172-31-29-215 sshd[3931429]: Invalid user mc from 47.247.99.155 port 43930 Oct 6 12:22:52 ip-172-31-29-215 sshd[3931429]: Received disconnect from 47.247.99.155 port 43930:11: Bye Bye [preauth] Oct 6 12:22:52 ip-172-31-29-215 sshd[3931429]: Disconnected from invalid user mc 47.247.99.155 port 43930 [preauth] Oct 6 12:24:43 ip-172-31-29-215 sshd[3931437]: Invalid user ansible from 47.247.99.155 port 34118 Oct 6 12:24:43 ip-172-31-29-215 sshd[3931437]: Received disconnect from 47.247.99.155 port 34118:11: Bye Bye [preauth] Oct 6 12:24:43 ip-172-31-29-215 sshd[3931437]: Disconnected from invalid user ansible 47.247.99.155 port 34118 [preauth] Oct 6 12:26:17 ip-172-31-29-215 sshd[3931443]: error: kex_exchange_identification: Connection closed by remote host Oct 6 12:26:31 ip-172-31-29-215 sshd[3931444]: Connection closed by 59.173.133.179 port 19745 [preauth] Oct 6 12:26:34 ip-172-31-29-215 sshd[3931446]: Invalid user proxyuser from 47.247.99.155 port 43320 Oct 6 12:26:34 ip-172-31-29-215 sshd[3931446]: Received disconnect from 47.247.99.155 port 43320:11: Bye Bye [preauth] Oct 6 12:26:34 ip-172-31-29-215 sshd[3931446]: Disconnected from invalid user proxyuser 47.247.99.155 port 43320 [preauth] Oct 6 12:28:02 ip-172-31-29-215 sshd[3931463]: Invalid user remoto from 123.59.50.202 port 10871 Oct 6 12:28:02 ip-172-31-29-215 sshd[3931463]: Received disconnect from 123.59.50.202 port 10871:11: Bye Bye [preauth] Oct 6 12:28:02 ip-172-31-29-215 sshd[3931463]: Disconnected from invalid user remoto 123.59.50.202 port 10871 [preauth] Oct 6 12:28:11 ip-172-31-29-215 sshd[3931465]: Invalid user odoo15 from 123.160.167.73 port 59056 Oct 6 12:28:11 ip-172-31-29-215 sshd[3931465]: Received disconnect from 123.160.167.73 port 59056:11: Bye Bye [preauth] Oct 6 12:28:11 ip-172-31-29-215 sshd[3931465]: Disconnected from invalid user odoo15 123.160.167.73 port 59056 [preauth] Oct 6 12:28:33 ip-172-31-29-215 sshd[3931469]: Invalid user lab from 47.247.99.155 port 41486 Oct 6 12:28:33 ip-172-31-29-215 sshd[3931469]: Received disconnect from 47.247.99.155 port 41486:11: Bye Bye [preauth] Oct 6 12:28:33 ip-172-31-29-215 sshd[3931469]: Disconnected from invalid user lab 47.247.99.155 port 41486 [preauth] Oct 6 12:30:08 ip-172-31-29-215 sshd[3931476]: Invalid user staging from 123.59.50.202 port 22756 Oct 6 12:30:08 ip-172-31-29-215 sshd[3931476]: Received disconnect from 123.59.50.202 port 22756:11: Bye Bye [preauth] Oct 6 12:30:08 ip-172-31-29-215 sshd[3931476]: Disconnected from invalid user staging 123.59.50.202 port 22756 [preauth] Oct 6 12:32:05 ip-172-31-29-215 sshd[3931494]: Invalid user frappe from 123.59.50.202 port 34292 Oct 6 12:32:05 ip-172-31-29-215 sshd[3931494]: Received disconnect from 123.59.50.202 port 34292:11: Bye Bye [preauth] Oct 6 12:32:05 ip-172-31-29-215 sshd[3931494]: Disconnected from invalid user frappe 123.59.50.202 port 34292 [preauth] Oct 6 12:32:53 ip-172-31-29-215 sshd[3931497]: Invalid user oracle from 123.59.50.202 port 40060 Oct 6 12:32:53 ip-172-31-29-215 sshd[3931497]: Received disconnect from 123.59.50.202 port 40060:11: Bye Bye [preauth] Oct 6 12:32:53 ip-172-31-29-215 sshd[3931497]: Disconnected from invalid user oracle 123.59.50.202 port 40060 [preauth] Oct 6 12:39:01 ip-172-31-29-215 CRON[3931533]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 12:39:01 ip-172-31-29-215 CRON[3931533]: pam_unix(cron:session): session closed for user root Oct 6 12:40:01 ip-172-31-29-215 CRON[3931590]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 12:40:01 ip-172-31-29-215 CRON[3931590]: pam_unix(cron:session): session closed for user smmsp Oct 6 12:40:39 ip-172-31-29-215 sshd[3931613]: Connection closed by 66.132.153.142 port 49622 [preauth] Oct 6 12:43:29 ip-172-31-29-215 sshd[3931628]: Invalid user odoo from 123.160.167.73 port 40960 Oct 6 12:43:29 ip-172-31-29-215 sshd[3931628]: Received disconnect from 123.160.167.73 port 40960:11: Bye Bye [preauth] Oct 6 12:43:29 ip-172-31-29-215 sshd[3931628]: Disconnected from invalid user odoo 123.160.167.73 port 40960 [preauth] Oct 6 12:55:47 ip-172-31-29-215 sshd[3931887]: Received disconnect from 187.110.238.50 port 60608:11: Bye Bye [preauth] Oct 6 12:55:47 ip-172-31-29-215 sshd[3931887]: Disconnected from authenticating user ubuntu 187.110.238.50 port 60608 [preauth] Oct 6 12:57:14 ip-172-31-29-215 sshd[3931891]: Invalid user aptuslegal from 162.240.61.39 port 42240 Oct 6 12:57:14 ip-172-31-29-215 sshd[3931891]: Connection closed by invalid user aptuslegal 162.240.61.39 port 42240 [preauth] Oct 6 12:58:01 ip-172-31-29-215 sshd[3931913]: Received disconnect from 187.110.238.50 port 49366:11: Bye Bye [preauth] Oct 6 12:58:01 ip-172-31-29-215 sshd[3931913]: Disconnected from authenticating user ubuntu 187.110.238.50 port 49366 [preauth] Oct 6 13:00:01 ip-172-31-29-215 CRON[3931928]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 13:00:01 ip-172-31-29-215 CRON[3931928]: pam_unix(cron:session): session closed for user smmsp Oct 6 13:00:05 ip-172-31-29-215 sshd[3931950]: Received disconnect from 187.110.238.50 port 60662:11: Bye Bye [preauth] Oct 6 13:00:05 ip-172-31-29-215 sshd[3931950]: Disconnected from authenticating user ubuntu 187.110.238.50 port 60662 [preauth] Oct 6 13:00:18 ip-172-31-29-215 sshd[3931952]: Invalid user nginx from 14.103.235.143 port 58520 Oct 6 13:00:18 ip-172-31-29-215 sshd[3931952]: Received disconnect from 14.103.235.143 port 58520:11: Bye Bye [preauth] Oct 6 13:00:18 ip-172-31-29-215 sshd[3931952]: Disconnected from invalid user nginx 14.103.235.143 port 58520 [preauth] Oct 6 13:05:05 ip-172-31-29-215 sshd[3931977]: Invalid user odoo from 14.103.235.143 port 26186 Oct 6 13:05:06 ip-172-31-29-215 sshd[3931977]: Received disconnect from 14.103.235.143 port 26186:11: Bye Bye [preauth] Oct 6 13:05:06 ip-172-31-29-215 sshd[3931977]: Disconnected from invalid user odoo 14.103.235.143 port 26186 [preauth] Oct 6 13:09:01 ip-172-31-29-215 CRON[3931998]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 13:09:01 ip-172-31-29-215 CRON[3931998]: pam_unix(cron:session): session closed for user root Oct 6 13:17:01 ip-172-31-29-215 CRON[3932094]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 13:17:01 ip-172-31-29-215 CRON[3932094]: pam_unix(cron:session): session closed for user root Oct 6 13:20:01 ip-172-31-29-215 CRON[3932109]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 13:20:01 ip-172-31-29-215 CRON[3932109]: pam_unix(cron:session): session closed for user smmsp Oct 6 13:39:01 ip-172-31-29-215 CRON[3932215]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 13:39:01 ip-172-31-29-215 CRON[3932215]: pam_unix(cron:session): session closed for user root Oct 6 13:40:01 ip-172-31-29-215 CRON[3932280]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 13:40:01 ip-172-31-29-215 CRON[3932280]: pam_unix(cron:session): session closed for user smmsp Oct 6 13:47:42 ip-172-31-29-215 sshd[3932359]: Received disconnect from 187.110.238.50 port 49338:11: Bye Bye [preauth] Oct 6 13:47:42 ip-172-31-29-215 sshd[3932359]: Disconnected from authenticating user ubuntu 187.110.238.50 port 49338 [preauth] Oct 6 13:49:27 ip-172-31-29-215 sshd[3932388]: Received disconnect from 187.110.238.50 port 60620:11: Bye Bye [preauth] Oct 6 13:49:27 ip-172-31-29-215 sshd[3932388]: Disconnected from authenticating user ubuntu 187.110.238.50 port 60620 [preauth] Oct 6 13:51:10 ip-172-31-29-215 sshd[3932403]: Received disconnect from 187.110.238.50 port 43668:11: Bye Bye [preauth] Oct 6 13:51:10 ip-172-31-29-215 sshd[3932403]: Disconnected from authenticating user ubuntu 187.110.238.50 port 43668 [preauth] Oct 6 13:52:53 ip-172-31-29-215 sshd[3932426]: Received disconnect from 187.110.238.50 port 54940:11: Bye Bye [preauth] Oct 6 13:52:53 ip-172-31-29-215 sshd[3932426]: Disconnected from authenticating user ubuntu 187.110.238.50 port 54940 [preauth] Oct 6 13:56:55 ip-172-31-29-215 sshd[3932485]: Invalid user nexus from 14.103.235.143 port 26518 Oct 6 13:56:56 ip-172-31-29-215 sshd[3932485]: Received disconnect from 14.103.235.143 port 26518:11: Bye Bye [preauth] Oct 6 13:56:56 ip-172-31-29-215 sshd[3932485]: Disconnected from invalid user nexus 14.103.235.143 port 26518 [preauth] Oct 6 14:00:01 ip-172-31-29-215 CRON[3932497]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 14:00:01 ip-172-31-29-215 CRON[3932497]: pam_unix(cron:session): session closed for user smmsp Oct 6 14:09:01 ip-172-31-29-215 CRON[3932636]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 14:09:01 ip-172-31-29-215 CRON[3932636]: pam_unix(cron:session): session closed for user root Oct 6 14:13:02 ip-172-31-29-215 sshd[3928492]: Received disconnect from 189.203.182.33 port 7217:11: disconnected by user Oct 6 14:13:02 ip-172-31-29-215 sshd[3928492]: Disconnected from user ubuntu 189.203.182.33 port 7217 Oct 6 14:13:02 ip-172-31-29-215 systemd-logind[500]: Session 53570 logged out. Waiting for processes to exit. Oct 6 14:13:02 ip-172-31-29-215 sshd[3928379]: pam_unix(sshd:session): session closed for user ubuntu Oct 6 14:17:01 ip-172-31-29-215 CRON[3932721]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 14:17:01 ip-172-31-29-215 CRON[3932721]: pam_unix(cron:session): session closed for user root Oct 6 14:18:02 ip-172-31-29-215 systemd-logind[500]: Removed session 53570. Oct 6 14:20:01 ip-172-31-29-215 CRON[3932746]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 14:20:01 ip-172-31-29-215 CRON[3932746]: pam_unix(cron:session): session closed for user smmsp Oct 6 14:39:01 ip-172-31-29-215 CRON[3932790]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 14:39:01 ip-172-31-29-215 CRON[3932790]: pam_unix(cron:session): session closed for user root Oct 6 14:40:01 ip-172-31-29-215 CRON[3932851]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 14:40:01 ip-172-31-29-215 CRON[3932851]: pam_unix(cron:session): session closed for user smmsp Oct 6 15:00:01 ip-172-31-29-215 CRON[3932930]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 15:00:01 ip-172-31-29-215 CRON[3932930]: pam_unix(cron:session): session closed for user smmsp Oct 6 15:02:05 ip-172-31-29-215 sshd[3932958]: Received disconnect from 157.10.52.61 port 48296:11: Bye Bye [preauth] Oct 6 15:02:05 ip-172-31-29-215 sshd[3932958]: Disconnected from authenticating user ubuntu 157.10.52.61 port 48296 [preauth] Oct 6 15:02:55 ip-172-31-29-215 sshd[3932960]: Received disconnect from 103.113.67.35 port 48096:11: Bye Bye [preauth] Oct 6 15:02:55 ip-172-31-29-215 sshd[3932960]: Disconnected from authenticating user ubuntu 103.113.67.35 port 48096 [preauth] Oct 6 15:03:38 ip-172-31-29-215 sshd[3932963]: Received disconnect from 147.45.212.166 port 47058:11: Bye Bye [preauth] Oct 6 15:03:38 ip-172-31-29-215 sshd[3932963]: Disconnected from authenticating user ubuntu 147.45.212.166 port 47058 [preauth] Oct 6 15:04:46 ip-172-31-29-215 sshd[3932965]: Connection closed by 14.103.118.79 port 23276 [preauth] Oct 6 15:05:34 ip-172-31-29-215 sshd[3932968]: Received disconnect from 147.45.212.166 port 44498:11: Bye Bye [preauth] Oct 6 15:05:34 ip-172-31-29-215 sshd[3932968]: Disconnected from authenticating user ubuntu 147.45.212.166 port 44498 [preauth] Oct 6 15:05:35 ip-172-31-29-215 sshd[3932970]: Received disconnect from 157.10.52.61 port 48612:11: Bye Bye [preauth] Oct 6 15:05:35 ip-172-31-29-215 sshd[3932970]: Disconnected from authenticating user ubuntu 157.10.52.61 port 48612 [preauth] Oct 6 15:05:45 ip-172-31-29-215 sshd[3932972]: Received disconnect from 103.113.67.35 port 58684:11: Bye Bye [preauth] Oct 6 15:05:45 ip-172-31-29-215 sshd[3932972]: Disconnected from authenticating user ubuntu 103.113.67.35 port 58684 [preauth] Oct 6 15:07:17 ip-172-31-29-215 sshd[3932974]: Received disconnect from 147.45.212.166 port 50716:11: Bye Bye [preauth] Oct 6 15:07:17 ip-172-31-29-215 sshd[3932974]: Disconnected from authenticating user ubuntu 147.45.212.166 port 50716 [preauth] Oct 6 15:07:32 ip-172-31-29-215 sshd[3932976]: Connection closed by 157.10.52.61 port 51382 [preauth] Oct 6 15:07:39 ip-172-31-29-215 sshd[3932978]: Received disconnect from 103.113.67.35 port 57500:11: Bye Bye [preauth] Oct 6 15:07:39 ip-172-31-29-215 sshd[3932978]: Disconnected from authenticating user ubuntu 103.113.67.35 port 57500 [preauth] Oct 6 15:08:58 ip-172-31-29-215 sshd[3932981]: Received disconnect from 147.45.212.166 port 43008:11: Bye Bye [preauth] Oct 6 15:08:58 ip-172-31-29-215 sshd[3932981]: Disconnected from authenticating user ubuntu 147.45.212.166 port 43008 [preauth] Oct 6 15:09:01 ip-172-31-29-215 CRON[3932984]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 15:09:01 ip-172-31-29-215 CRON[3932984]: pam_unix(cron:session): session closed for user root Oct 6 15:10:36 ip-172-31-29-215 sshd[3933046]: Received disconnect from 147.45.212.166 port 37282:11: Bye Bye [preauth] Oct 6 15:10:36 ip-172-31-29-215 sshd[3933046]: Disconnected from authenticating user ubuntu 147.45.212.166 port 37282 [preauth] Oct 6 15:17:01 ip-172-31-29-215 CRON[3933090]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 15:17:01 ip-172-31-29-215 CRON[3933090]: pam_unix(cron:session): session closed for user root Oct 6 15:20:01 ip-172-31-29-215 CRON[3933095]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 15:20:01 ip-172-31-29-215 CRON[3933095]: pam_unix(cron:session): session closed for user smmsp Oct 6 15:39:01 ip-172-31-29-215 CRON[3933146]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 15:39:01 ip-172-31-29-215 CRON[3933146]: pam_unix(cron:session): session closed for user root Oct 6 15:40:01 ip-172-31-29-215 CRON[3933203]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 15:40:01 ip-172-31-29-215 CRON[3933203]: pam_unix(cron:session): session closed for user smmsp Oct 6 16:00:01 ip-172-31-29-215 CRON[3933262]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 16:00:01 ip-172-31-29-215 CRON[3933262]: pam_unix(cron:session): session closed for user smmsp Oct 6 16:00:33 ip-172-31-29-215 sshd[3933284]: Received disconnect from 157.10.52.61 port 60898:11: Bye Bye [preauth] Oct 6 16:00:33 ip-172-31-29-215 sshd[3933284]: Disconnected from authenticating user ubuntu 157.10.52.61 port 60898 [preauth] Oct 6 16:09:01 ip-172-31-29-215 CRON[3933297]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 16:09:01 ip-172-31-29-215 CRON[3933297]: pam_unix(cron:session): session closed for user root Oct 6 16:17:01 ip-172-31-29-215 CRON[3933438]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 16:17:01 ip-172-31-29-215 CRON[3933438]: pam_unix(cron:session): session closed for user root Oct 6 16:20:01 ip-172-31-29-215 CRON[3933452]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 16:20:01 ip-172-31-29-215 CRON[3933452]: pam_unix(cron:session): session closed for user smmsp Oct 6 16:39:01 ip-172-31-29-215 CRON[3933567]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 16:39:01 ip-172-31-29-215 CRON[3933567]: pam_unix(cron:session): session closed for user root Oct 6 16:40:01 ip-172-31-29-215 CRON[3933622]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 16:40:01 ip-172-31-29-215 CRON[3933622]: pam_unix(cron:session): session closed for user smmsp Oct 6 16:54:01 ip-172-31-29-215 CRON[3933817]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 16:54:01 ip-172-31-29-215 CRON[3933817]: pam_unix(cron:session): session closed for user root Oct 6 17:00:01 ip-172-31-29-215 CRON[3933853]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Oct 6 17:00:01 ip-172-31-29-215 CRON[3933853]: pam_unix(cron:session): session closed for user smmsp Oct 6 17:09:01 ip-172-31-29-215 CRON[3933892]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 17:09:01 ip-172-31-29-215 CRON[3933892]: pam_unix(cron:session): session closed for user root Oct 6 17:17:01 ip-172-31-29-215 CRON[3934004]: pam_unix(cron:session): session opened for user root by (uid=0) Oct 6 17:17:01 ip-172-31-29-215 CRON[3934004]: pam_unix(cron:session): session closed for user root Oct 6 17:18:02 ip-172-31-29-215 sshd[3934008]: Connection closed by authenticating user root 163.172.12.133 port 41986 [preauth] Oct 6 17:18:02 ip-172-31-29-215 sshd[3934010]: Connection closed by authenticating user root 163.172.12.133 port 41992 [preauth] Oct 6 17:18:03 ip-172-31-29-215 sshd[3934012]: Connection closed by authenticating user root 163.172.12.133 port 41994 [preauth] Oct 6 17:18:03 ip-172-31-29-215 sshd[3934014]: Connection closed by authenticating user root 163.172.12.133 port 41998 [preauth] Oct 6 17:18:04 ip-172-31-29-215 sshd[3934016]: Connection closed by authenticating user root 163.172.12.133 port 42010 [preauth] Oct 6 17:18:05 ip-172-31-29-215 sshd[3934018]: Connection closed by authenticating user root 163.172.12.133 port 42018 [preauth] Oct 6 17:18:05 ip-172-31-29-215 sshd[3934020]: Connection closed by authenticating user root 163.172.12.133 port 42034 [preauth] Oct 6 17:18:06 ip-172-31-29-215 sshd[3934022]: Connection closed by authenticating user root 163.172.12.133 port 42040 [preauth] Oct 6 17:18:06 ip-172-31-29-215 sshd[3934024]: Connection closed by authenticating user root 163.172.12.133 port 42050 [preauth] Oct 6 17:18:07 ip-172-31-29-215 sshd[3934026]: Connection closed by authenticating user root 163.172.12.133 port 42060 [preauth] Oct 6 17:18:07 ip-172-31-29-215 sshd[3934028]: Connection closed by authenticating user root 163.172.12.133 port 42076 [preauth] Oct 6 17:18:08 ip-172-31-29-215 sshd[3934030]: Connection closed by authenticating user root 163.172.12.133 port 42092 [preauth] Oct 6 17:18:08 ip-172-31-29-215 sshd[3934032]: Connection closed by authenticating user root 163.172.12.133 port 42106 [preauth] Oct 6 17:18:09 ip-172-31-29-215 sshd[3934034]: Connection closed by authenticating user root 163.172.12.133 port 42108 [preauth] Oct 6 17:18:10 ip-172-31-29-215 sshd[3934036]: Connection closed by authenticating user root 163.172.12.133 port 42124 [preauth] Oct 6 17:18:10 ip-172-31-29-215 sshd[3934038]: Connection closed by authenticating user root 163.172.12.133 port 48238 [preauth] Oct 6 17:18:11 ip-172-31-29-215 sshd[3934040]: Connection closed by authenticating user root 163.172.12.133 port 48254 [preauth] Oct 6 17:18:11 ip-172-31-29-215 sshd[3934042]: Connection closed by authenticating user root 163.172.12.133 port 48270 [preauth] Oct 6 17:18:12 ip-172-31-29-215 sshd[3934044]: Connection closed by authenticating user root 163.172.12.133 port 48274 [preauth] Oct 6 17:18:12 ip-172-31-29-215 sshd[3934046]: Connection closed by authenticating user root 163.172.12.133 port 48290 [preauth] Oct 6 17:18:13 ip-172-31-29-215 sshd[3934048]: Connection closed by authenticating user root 163.172.12.133 port 48294 [preauth] Oct 6 17:18:14 ip-172-31-29-215 sshd[3934050]: Connection closed by authenticating user root 163.172.12.133 port 48302 [preauth] Oct 6 17:18:14 ip-172-31-29-215 sshd[3934052]: Connection closed by authenticating user root 163.172.12.133 port 48312 [preauth] Oct 6 17:18:15 ip-172-31-29-215 sshd[3934054]: Connection closed by authenticating user root 163.172.12.133 port 48328 [preauth] Oct 6 17:18:15 ip-172-31-29-215 sshd[3934056]: Connection closed by authenticating user root 163.172.12.133 port 48330 [preauth] Oct 6 17:18:16 ip-172-31-29-215 sshd[3934058]: Connection closed by authenticating user root 163.172.12.133 port 48334 [preauth] Oct 6 17:18:16 ip-172-31-29-215 sshd[3934060]: Connection closed by authenticating user root 163.172.12.133 port 48344 [preauth] Oct 6 17:18:17 ip-172-31-29-215 sshd[3934062]: Connection closed by authenticating user root 163.172.12.133 port 48346 [preauth] Oct 6 17:18:18 ip-172-31-29-215 sshd[3934064]: Connection closed by authenticating user root 163.172.12.133 port 48362 [preauth] Oct 6 17:18:18 ip-172-31-29-215 sshd[3934066]: Connection closed by authenticating user root 163.172.12.133 port 48364 [preauth] Oct 6 17:18:19 ip-172-31-29-215 sshd[3934068]: Connection closed by authenticating user root 163.172.12.133 port 48374 [preauth] Oct 6 17:18:19 ip-172-31-29-215 sshd[3934070]: Connection closed by authenticating user root 163.172.12.133 port 48388 [preauth] Oct 6 17:18:20 ip-172-31-29-215 sshd[3934072]: Connection closed by authenticating user root 163.172.12.133 port 59188 [preauth] Oct 6 17:18:20 ip-172-31-29-215 sshd[3934074]: Connection closed by authenticating user root 163.172.12.133 port 59204 [preauth] Oct 6 17:18:21 ip-172-31-29-215 sshd[3934076]: Connection closed by authenticating user root 163.172.12.133 port 59218 [preauth] Oct 6 17:18:22 ip-172-31-29-215 sshd[3934078]: Connection closed by authenticating user root 163.172.12.133 port 59230 [preauth] Oct 6 17:18:22 ip-172-31-29-215 sshd[3934080]: Connection closed by authenticating user root 163.172.12.133 port 59246 [preauth] Oct 6 17:18:23 ip-172-31-29-215 sshd[3934082]: Connection closed by authenticating user root 163.172.12.133 port 59254 [preauth] Oct 6 17:18:23 ip-172-31-29-215 sshd[3934084]: Connection closed by authenticating user root 163.172.12.133 port 59270 [preauth] Oct 6 17:18:24 ip-172-31-29-215 sshd[3934086]: Connection closed by authenticating user root 163.172.12.133 port 59272 [preauth] Oct 6 17:18:24 ip-172-31-29-215 sshd[3934088]: Connection closed by authenticating user root 163.172.12.133 port 59282 [preauth] Oct 6 17:18:25 ip-172-31-29-215 sshd[3934090]: Connection closed by authenticating user root 163.172.12.133 port 59286 [preauth] Oct 6 17:18:26 ip-172-31-29-215 sshd[3934092]: Connection closed by authenticating user root 163.172.12.133 port 59294 [preauth] Oct 6 17:18:26 ip-172-31-29-215 sshd[3934094]: Connection closed by authenticating user root 163.172.12.133 port 59306 [preauth] Oct 6 17:18:27 ip-172-31-29-215 sshd[3934096]: Connection closed by authenticating user root 163.172.12.133 port 59322 [preauth] Oct 6 17:18:27 ip-172-31-29-215 sshd[3934098]: Connection closed by authenticating user root 163.172.12.133 port 59328 [preauth] Oct 6 17:18:28 ip-172-31-29-215 sshd[3934100]: Connection closed by authenticating user root 163.172.12.133 port 59344 [preauth] Oct 6 17:18:28 ip-172-31-29-215 sshd[3934102]: Connection closed by authenticating user root 163.172.12.133 port 59356 [preauth] Oct 6 17:18:29 ip-172-31-29-215 sshd[3934104]: Connection closed by authenticating user root 163.172.12.133 port 59364 [preauth] Oct 6 17:18:30 ip-172-31-29-215 sshd[3934106]: Connection closed by authenticating user root 163.172.12.133 port 59372 [preauth] Oct 6 17:18:30 ip-172-31-29-215 sshd[3934108]: Connection closed by authenticating user root 163.172.12.133 port 43128 [preauth] Oct 6 17:18:31 ip-172-31-29-215 sshd[3934110]: Connection closed by authenticating user root 163.172.12.133 port 43136 [preauth] Oct 6 17:18:31 ip-172-31-29-215 sshd[3934112]: Connection closed by authenticating user root 163.172.12.133 port 43142 [preauth] Oct 6 17:18:32 ip-172-31-29-215 sshd[3934114]: Connection closed by authenticating user root 163.172.12.133 port 43146 [preauth] Oct 6 17:18:32 ip-172-31-29-215 sshd[3934116]: Connection closed by authenticating user root 163.172.12.133 port 43148 [preauth] Oct 6 17:18:33 ip-172-31-29-215 sshd[3934118]: Connection closed by authenticating user root 163.172.12.133 port 43160 [preauth] Oct 6 17:18:33 ip-172-31-29-215 sshd[3934120]: Connection closed by authenticating user root 163.172.12.133 port 43174 [preauth] Oct 6 17:18:34 ip-172-31-29-215 sshd[3934122]: Connection closed by authenticating user root 163.172.12.133 port 43182 [preauth] Oct 6 17:18:35 ip-172-31-29-215 sshd[3934124]: Connection closed by authenticating user root 163.172.12.133 port 43194 [preauth] Oct 6 17:18:35 ip-172-31-29-215 sshd[3934126]: Connection closed by authenticating user root 163.172.12.133 port 43210 [preauth] Oct 6 17:18:36 ip-172-31-29-215 sshd[3934128]: Connection closed by authenticating user root 163.172.12.133 port 43218 [preauth] Oct 6 17:18:36 ip-172-31-29-215 sshd[3934130]: Connection closed by authenticating user root 163.172.12.133 port 43226 [preauth] Oct 6 17:18:37 ip-172-31-29-215 sshd[3934132]: Connection closed by authenticating user root 163.172.12.133 port 43236 [preauth] Oct 6 17:18:37 ip-172-31-29-215 sshd[3934134]: Connection closed by authenticating user root 163.172.12.133 port 43240 [preauth] Oct 6 17:18:38 ip-172-31-29-215 sshd[3934137]: Connection closed by authenticating user root 163.172.12.133 port 43256 [preauth] Oct 6 17:18:39 ip-172-31-29-215 sshd[3934139]: Connection closed by authenticating user root 163.172.12.133 port 43264 [preauth] Oct 6 17:18:39 ip-172-31-29-215 sshd[3934141]: Connection closed by authenticating user root 163.172.12.133 port 43266 [preauth] Oct 6 17:18:40 ip-172-31-29-215 sshd[3934143]: Connection closed by authenticating user root 163.172.12.133 port 43268 [preauth] Oct 6 17:18:40 ip-172-31-29-215 sshd[3934145]: Connection closed by authenticating user root 163.172.12.133 port 53616 [preauth] Oct 6 17:18:41 ip-172-31-29-215 sshd[3934147]: Connection closed by authenticating user root 163.172.12.133 port 53628 [preauth] Oct 6 17:18:41 ip-172-31-29-215 sshd[3934149]: Connection closed by authenticating user root 163.172.12.133 port 53632 [preauth] Oct 6 17:18:42 ip-172-31-29-215 sshd[3934151]: Connection closed by authenticating user root 163.172.12.133 port 53634 [preauth] Oct 6 17:18:43 ip-172-31-29-215 sshd[3934153]: Connection closed by authenticating user root 163.172.12.133 port 53642 [preauth] Oct 6 17:18:43 ip-172-31-29-215 sshd[3934155]: Connection closed by authenticating user root 163.172.12.133 port 53644 [preauth] Oct 6 17:18:44 ip-172-31-29-215 sshd[3934157]: Connection closed by authenticating user root 163.172.12.133 port 53648 [preauth] Oct 6 cts parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989482 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP Stack trace: [Mon Jul 21 17:12:26.989487 2025] [php7:notice] [pid 2890659] [client 136.143.176.44:40186] PHP Stack trace: [Mon Jul 21 17:12:26.989491 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989491 2025] [php7:notice] [pid 2890659] [client 136.143.176.44:40186] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989495 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989501 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989504 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP Stack trace: [Mon Jul 21 17:12:26.989507 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989511 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989496 2025] [php7:notice] [pid 2890659] [client 136.143.176.44:40186] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989516 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989531 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP Stack trace: [Mon Jul 21 17:12:26.989534 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989538 2025] [php7:notice] [pid 2890108] [client 136.143.176.60:44114] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989617 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989624 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Stack trace: [Mon Jul 21 17:12:26.989629 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989633 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989641 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989646 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Stack trace: [Mon Jul 21 17:12:26.989650 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989654 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989659 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989662 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP Stack trace: [Mon Jul 21 17:12:26.989670 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989673 2025] [php7:notice] [pid 2887211] [client 136.143.177.62:38746] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989374 2025] [php7:notice] [pid 2890624] [client 136.143.177.44:52298] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989782 2025] [php7:notice] [pid 2890624] [client 136.143.177.44:52298] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989779 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989787 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Stack trace: [Mon Jul 21 17:12:26.989792 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989796 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989802 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989805 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Stack trace: [Mon Jul 21 17:12:26.989799 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Warning: fopen(./LogosArochi/MAR-130914.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989808 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989811 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Stack trace: [Mon Jul 21 17:12:26.989812 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989816 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989818 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989820 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989816 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989821 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP Stack trace: [Mon Jul 21 17:12:26.989826 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Stack trace: [Mon Jul 21 17:12:26.989827 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989828 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989831 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Stack trace: [Mon Jul 21 17:12:26.989832 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989833 2025] [php7:notice] [pid 2888105] [client 136.143.177.61:41580] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989835 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989843 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989846 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989851 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989851 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989855 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Stack trace: [Mon Jul 21 17:12:26.989856 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP Stack trace: [Mon Jul 21 17:12:26.989859 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989860 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989863 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989864 2025] [php7:notice] [pid 2885036] [client 136.143.177.62:60644] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989869 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989872 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP Stack trace: [Mon Jul 21 17:12:26.989875 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989878 2025] [php7:notice] [pid 2891128] [client 136.143.177.43:48100] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989924 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Warning: fopen(./LogosArochi/MAR-130916.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989931 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Stack trace: [Mon Jul 21 17:12:26.989936 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989939 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989945 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989948 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Stack trace: [Mon Jul 21 17:12:26.989933 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Warning: fopen(./LogosArochi/MAR-130913.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.989951 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989961 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Stack trace: [Mon Jul 21 17:12:26.989962 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989966 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989967 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989970 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.989971 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP Stack trace: [Mon Jul 21 17:12:26.989975 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989977 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.989978 2025] [php7:notice] [pid 2885380] [client 136.143.177.61:54892] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.989981 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Stack trace: [Mon Jul 21 17:12:26.989985 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.989988 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.989993 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.989996 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP Stack trace: [Mon Jul 21 17:12:26.989999 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990002 2025] [php7:notice] [pid 2885034] [client 136.143.177.61:58506] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.990006 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.990060 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.990068 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Stack trace: [Mon Jul 21 17:12:26.990072 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990075 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.990081 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.990090 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Stack trace: [Mon Jul 21 17:12:26.990014 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Stack trace: [Mon Jul 21 17:12:26.990093 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990099 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.990099 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990104 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.990104 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.990102 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.990109 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP Stack trace: [Mon Jul 21 17:12:26.990111 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Stack trace: [Mon Jul 21 17:12:26.990111 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.990112 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990116 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Stack trace: [Mon Jul 21 17:12:26.990116 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990117 2025] [php7:notice] [pid 2887282] [client 136.143.176.60:50878] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.990119 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990121 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.990124 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.990127 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.990129 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.990131 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Stack trace: [Mon Jul 21 17:12:26.990132 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP Stack trace: [Mon Jul 21 17:12:26.990135 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990136 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990138 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.990144 2025] [php7:notice] [pid 2891149] [client 136.143.177.43:56798] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.990148 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.990151 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP Stack trace: [Mon Jul 21 17:12:26.990154 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990157 2025] [php7:notice] [pid 2890694] [client 136.143.177.44:52780] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon Jul 21 17:12:26.990202 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.990211 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Stack trace: [Mon Jul 21 17:12:26.990215 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990219 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.990225 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.990228 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Stack trace: [Mon Jul 21 17:12:26.990226 2025] [php7:notice] [pid 2890380] [client 136.143.177.43:49112] PHP Warning: fopen(./LogosArochi/MAR-130925.png): failed to open stream: Permission denied in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 188 [Mon Jul 21 17:12:26.990232 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990234 2025] [php7:notice] [pid 2890380] [client 136.143.177.43:49112] PHP Stack trace: [Mon Jul 21 17:12:26.990236 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 2. fwrite() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:189 [Mon Jul 21 17:12:26.990239 2025] [php7:notice] [pid 2890380] [client 136.143.177.43:49112] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990241 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Warning: fclose() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 190 [Mon Jul 21 17:12:26.990243 2025] [php7:notice] [pid 2890380] [client 136.143.177.43:49112] PHP 2. fopen() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:188 [Mon Jul 21 17:12:26.990245 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP Stack trace: [Mon Jul 21 17:12:26.990248 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 1. {main}() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:0 [Mon Jul 21 17:12:26.990249 2025] [php7:notice] [pid 2890380] [client 136.143.177.43:49112] PHP Warning: fwrite() expects parameter 1 to be resource, bool given in /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php on line 189 [Mon Jul 21 17:12:26.990252 2025] [php7:notice] [pid 2890719] [client 136.143.176.44:53764] PHP 2. fclose() /var/www/html/imagenesAptusLegal/arochi/wsImageSave_v3.php:190 [Mon J "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan el Propoietario de la Aplicación"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bRecId == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan el ID del CFDI a actualizar"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bDatPAC == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan los Datos del PAC"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bDatGen == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan los Datos Generales"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bDatEmi == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan los Datos del Emisor"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bDatRec == "" or $bDatArt == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan los Datos del Receptor"); $Resultado = json_encode($j_array); echo $Resultado; return; } if($bDatArt == "") { $j_array = array('code' => "300", "message" => "ERROR - [wsInvoiceSF] Parametros incompletos para el Servicio Web, faltan los Datos de los Articulos"); $Resultado = json_encode($j_array); echo $Resultado; return; } ### 0. EXTRACCION DE PARAMETROS PARA EL CFDI ###################################################### #== Primero, extraemos el JSON del string en base 64 $bdDatPAC = base64_decode($bDatPAC); $bdDatGen = base64_decode($bDatGen); $bdDatEmi = base64_decode($bDatEmi); $bdDatRec = base64_decode($bDatRec); $bdDatArt = base64_decode($bDatArt); if($bDatRel <> "") { $bdDatRel = base64_decode($bDatRel); } if ($tipoTest == 1){ echo $bdDatPAC; echo '
'; echo '
'; echo $bdDatGen; echo '
'; echo '
'; echo $bdDatEmi; echo '
'; echo '
'; echo $bdDatRec; echo '
'; echo '
'; echo $bdDatArt; echo '
'; echo '
'; echo $bdDatRel; echo '
'; echo '
'; $array = json_encode(json_decode($bdDatRec), JSON_PRETTY_PRINT); echo $array; } #== Segundo, decodificamos el JSON a un arreglo $abdDatPAC = json_decode($bdDatPAC,true); $abdDatGen = json_decode($bdDatGen,true); $abdDatEmi = json_decode($bdDatEmi,true); $abdDatRec = json_decode($bdDatRec,true); $abdDatArt = json_decode($bdDatArt,true); if($bDatRel <> "") { $abdDatRel = json_decode($bdDatRel,true); } if ($tipoTest == 1){ echo '
'; echo 'AREGLOS DE DATOS DESPUES DE json_decode'; echo '
'; echo '
'; print_r($abdDatPAC); echo '
'; echo '
'; print_r($abdDatGen); echo '
'; echo '
'; print_r($abdDatEmi); echo '
'; echo '
'; print_r($abdDatRec); echo '
'; echo '
'; print_r($abdDatArt); echo '
'; echo '
'; } $dirBase = realpath("../"); ### CÓDIGO FUENTE, FACTURACIÓN ELECTRÓNICA CFDI VERSIÓN 3.2 ACORDE A LOS REQUIRIMIENTOS DEL SAT, ANEXO 20. ### 1. CONFIGURACIÓN INICIAL ###################################################### # 1.1 Configuración de zona horaria date_default_timezone_set('America/Mexico_City'); // if($tipoTest > 0){ # 1.2 Muestra la zona horaria predeterminada del servidor (opcional a mostrar) echo '
'; echo 'ZONA HORARIA PREDETERMINADA'; echo '
'; echo '
'; echo date_default_timezone_get(); echo '

'; } ### 2. DEFINICIÓN DE CONSTANTES ################################################### $SendaPEMS = "archs_pem/"; $SendaCFDI = "archs_cfdi/"; $SendaGRAFS = "archs_graf/"; $SendaXSD = "archs_xsd/"; // 2.1 Datos de acceso del usuario (proporcionados por el PAC). if($abdDatPAC["tipoTim"] == 1){ ## Timbrado en producción $urlPAC = "https://solucionfactible.com/ws/services/Timbrado?wsdl"; } else { ## Timbrado en pruebas $urlPAC = "https://testing.solucionfactible.com/ws/services/Timbrado?wsdl"; } $username = $abdDatPAC["username"]; $password = $abdDatPAC["password"]; if($tipoTest > 0){ $username = "testing@solucionfactible.com"; $password = "timbrado.SF.16672"; $urlPAC = "https://testing.solucionfactible.com/ws/services/Timbrado?wsdl"; } $valorNod = ''; $metodoDePago = ""; if ($tipoTest > 0){ ### MUESTRA LOS DATOS DEL USUARIO QUE ESTÁ TIMBRANDO (OPCIONAL A MOSTRAR) ###### echo '
'; echo 'DATOS DEL USUARIO QUE ESTÁ TIMBRANDO'; echo '
'; echo '
'; echo 'USUARIO: '.$username."
"; echo 'PASSWORD: '.$password."
"; echo 'URL: '.$urlPAC."
"; echo '

'; } ### 3. DEFINICIÓN DE VARIABLES INICIALES ########################################## #---------------------------------------------------------------- #== Llamado para generar el token para donatello #---------------------------------------------------------------- $curl = curl_init(); curl_setopt_array($curl, array( CURLOPT_URL => 'https://donatello.aptuslegal.app/oauth/token/'.$appOwner, CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => '', CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 0, CURLOPT_FOLLOWLOCATION => true, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => 'GET', CURLOPT_HTTPHEADER => array( 'Authorization: Token e68d5a079f937ea29ad2ec5a5b105b75491a0e0c' ), )); $response = curl_exec($curl); curl_close($curl); // Decodificamos la respuesta JSON $data = json_decode($response, true); // Accedemos al valor de 'access_token de donatello' $access_token = $data['access_token']; if($incAddenda == 1) { #== Conexión a Zoho Creator para el detalle del CFDI $request_url = 'https://creator.zoho.com/api/v2/'.$appOwner.'/'.$applnkname.'/report/cfdi_I_query/'.$bRecId; $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $request_url); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); curl_setopt($ch, CURLOPT_HTTPHEADER, array('Authorization: Zoho-oauthtoken ' . $access_token)); $r = curl_exec($ch); $array = json_decode($r); $folio_AdAs = $array->data->Folio_AdAs; $serie_AdAs = $array->data->Serie_AdAs; $no_Prov_AdAs = $array->data->No_Prov_AdAs; $ord_Com_AdAs = $array->data->Ord_Comp_AdAs; $tip_Pro_AdAs = $array->data->Tipo_Prov_AdAs; $jsonAddenda = $array->data->JSON_Addenda_ASO; $ajsonAddenda = json_decode($jsonAddenda,true); } ### 4. DESTINATARIOS DE E-MAILS, PERSONAS A QUIENES LES LLEGARÁ DE MANERA ADJUNTA LA FACTURA ELECTRÓNICA EN ARCHIVOS .XML Y .PDF $CadenaEmails = $abdDatGen["CadenaEmails"]; $CadenaEmails = "ffaccinetto@aptus-legal.com"; ### 5. DATOS GENERALES DE LA FACTURA ############################################## $fact_serie = $abdDatGen["fact_serie"]; $fact_folio = $abdDatGen["fact_folio"]; if ($bFolioN <> ""){ $fact_folio = $bFolioN; } $NoFac = $fact_serie.$fact_folio; $fact_tipcompr = $abdDatGen["fact_tipcompr"]; $fact_exportacion = $abdDatGen["fact_exportacion"]; $tasa_iva = $abdDatGen["tasa_iva"]; $subTotal = number_format($abdDatGen["subTotal"],2,'.',''); $descuento = number_format($abdDatGen["descuento"],2,'.',''); $IVA = number_format($abdDatGen["IVA"],2,'.',''); $total = number_format($abdDatGen["total"],2,'.',''); $fecha_fact = $abdDatGen["fecha_fact"]; $condicionesDePago = $abdDatGen["condicionesDePago"]; $formaDePago = utf8_decode($abdDatGen["formaDePago"]); $metodoDePago = utf8_decode($abdDatGen["metodoDePago"]); $TipoCambio = $abdDatGen["TipoCambio"]; $LugarExpedicion = utf8_decode($abdDatGen["LugarExpedicion"]); $moneda = $abdDatGen["moneda"]; $invoiceID = $abdDatGen["invoiceID"]; $invoiceNumber = $abdDatGen["invoiceNumber"]; $TipoRelacion = $abdDatGen["TipoRelacion"]; if($TipPDFGen == 1) { $sObservaciones = base64_encode(utf8_decode($abdDatGen["Observaciones"])); $sOrdenCobro = $abdDatGen["OrdenCobro"]; } $subTotal = 0; $subTotTraslados = 0; $totalImpuestosRetenidos = 0; // 5.24 Total de impuestos retenidos. $totalImpuestosTrasladados = 0; // 5.25 Total de impuestos trasladados. if ($tipoTest > 0){ ### 6. MUESTRA LA ZONA HORARIA PREDETERMINADA DEL SERVIDOR (OPCIONAL A MOSTRAR) ###### echo '
'; echo 'FECHA Y HORA DE SOLICITUD DE TIMBRADO'; echo '
'; echo '
'; echo $fecha_fact; // 6.1 Se muestra solo para consultar y confirmar que sea la correcta. echo '

'; } // Calculando subTotal, Impuestos Trasladados y Retenidos. for ($i = 0; $icreateElement("cfdi:Comprobante"); $root = $xml->appendChild($root); $cadena_original='||'; $noatt= array(); #== 10.2 Se crea e inserta el primer nodo donde se declaran los namespaces ====== cargaAtt($root, array("xsi:schemaLocation"=>"http://www.sat.gob.mx/cfd/4 http://www.sat.gob.mx/sitio_internet/cfd/4/cfdv40.xsd", "xmlns:cfdi"=>"http://www.sat.gob.mx/cfd/4", "xmlns:xsi"=>"http://www.w3.org/2001/XMLSchema-instance" ) ); #== 10.3 Rutina de integración de nodos ========================================= if($TipPDFGen == 1) { if ($appOwner == "arochiylindner.aptus") { cargaAtt($root, array( "Version"=>"4.0", "Serie"=>$fact_serie, "Folio"=>$invoiceNumber, "Fecha"=>$fecha_fact, "FormaPago"=>$formaDePago, "NoCertificado"=>$noCertificado, "CondicionesDePago"=>$condicionesDePago, "SubTotal"=>$subTotal, "Descuento"=>$descuento, "Moneda"=>$moneda, "TipoCambio"=>$TipoCambio, "Total"=>$total, "TipoDeComprobante"=>$fact_tipcompr, "Exportacion"=>$fact_exportacion, "MetodoPago"=>$metodoDePago, "LugarExpedicion"=>$LugarExpedicion ) ); } else { cargaAtt($root, array( "Version"=>"4.0", "Serie"=>$fact_serie, "Folio"=>$invoiceNumber, "Fecha"=>date("Y-m-d")."T".date("H:i:s"), "FormaPago"=>$formaDePago, "NoCertificado"=>$noCertificado, "CondicionesDePago"=>$condicionesDePago, "SubTotal"=>$subTotal, "Descuento"=>$descuento, "Moneda"=>$moneda, "TipoCambio"=>$TipoCambio, "Total"=>$total, "TipoDeComprobante"=>$fact_tipcompr, "Exportacion"=>$fact_exportacion, "MetodoPago"=>$metodoDePago, "LugarExpedicion"=>$LugarExpedicion ) ); } } else { cargaAtt($root, array( "Version"=>"4.0", "Serie"=>$fact_serie, "Folio"=>$fact_folio, "Fecha"=>date("Y-m-d")."T".date("H:i:s"), "FormaPago"=>$formaDePago, "NoCertificado"=>$noCertificado, "CondicionesDePago"=>$condicionesDePago, "SubTotal"=>$subTotal, "Descuento"=>$descuento, "Moneda"=>$moneda, "TipoCambio"=>$TipoCambio, "Total"=>$total, "TipoDeComprobante"=>$fact_tipcompr, "Exportacion"=>$fact_exportacion, "MetodoPago"=>$metodoDePago, "LugarExpedicion"=>$LugarExpedicion ) ); } // Adicionado por FFR en Marzo 30, 2019 // Para el manejo de los CFDI Relacionados if($bDatRel <> "") { $cfdiRelacionados = $xml->createElement("cfdi:CfdiRelacionados"); $cfdiRelacionados = $root->appendChild($cfdiRelacionados); cargaAtt($cfdiRelacionados, array("TipoRelacion"=>utf8_decode($TipoRelacion))); for ($i=0; $i < count($abdDatRel); $i++) { $cfdiRelacionado = $xml->createElement("cfdi:CfdiRelacionado"); $cfdiRelacionado = $cfdiRelacionados->appendChild($cfdiRelacionado); cargaAtt($cfdiRelacionado, array("UUID"=>utf8_decode($abdDatRel[$i]["UUID"]))); } } $emisor = $xml->createElement("cfdi:Emisor"); $emisor = $root->appendChild($emisor); cargaAtt($emisor, array("Rfc"=>$emisor_rfc, "Nombre"=>$emisor_rs, "RegimenFiscal"=>$emisor_regfis ) ); $receptor = $xml->createElement("cfdi:Receptor"); $receptor = $root->appendChild($receptor); cargaAtt($receptor, array("Rfc"=>$receptor_rfc, "Nombre"=>$receptor_rs, "DomicilioFiscalReceptor"=>$receptor_cp, "RegimenFiscalReceptor"=>$receptor_regfis, "UsoCFDI"=>$receptor_uso ) ); $conceptos = $xml->createElement("cfdi:Conceptos"); $conceptos = $root->appendChild($conceptos); $isrImpuesto = "001"; $ivaImpuesto = "002"; #== 10.4 Ciclo "for", recopilación de datos de artículos e integración de sus respectivos nodos == $ivaTasaOCuota = 0.160000; $isrTasaOCuota = 0.060000; for ($i=0; $icreateElement("cfdi:Concepto"); $concepto = $conceptos->appendChild($concepto); cargaAtt($concepto, array( "ClaveProdServ"=>utf8_decode($abdDatArt[$i]["claveProd"]), "Cantidad"=>$abdDatArt[$i]["cantidad"], "ClaveUnidad"=>utf8_decode($abdDatArt[$i]["unidad"]), "Unidad"=>trim(utf8_decode($abdDatArt[$i]["descUnidad"])), "Descripcion"=>trim(utf8_decode($abdDatArt[$i]["descripcion"])), "ValorUnitario"=>number_format($abdDatArt[$i]["valorUnitario"],2,'.',''), "Importe"=>number_format($abdDatArt[$i]["importe"],2,'.',''), "Descuento"=>number_format($abdDatArt[$i]["descuento"],2,'.',''), "ObjetoImp"=>utf8_decode($abdDatArt[$i]["ObjetoImp"]) ) ); if ($abdDatArt[$i]["ivaImporte"] > 0 || $abdDatArt[$i]["isrImporte"] > 0) //if($abdDatArt[$i]["ivaImpuesto"] == "002" || $abdDatArt[$i]["isrImpuesto"] == "001") { $impuestos = $xml->createElement("cfdi:Impuestos"); $impuestos = $concepto->appendChild($impuestos); if ($abdDatArt[$i]["ivaImporte"] > 0) //if($abdDatArt[$i]["ivaImpuesto"] == "002") { $Traslados = $xml->createElement("cfdi:Traslados"); $Traslados = $impuestos->appendChild($Traslados); $Traslado = $xml->createElement("cfdi:Traslado"); $Traslado = $Traslados->appendChild($Traslado); $ivaImpuesto = $abdDatArt[$i]["ivaImpuesto"]; cargaAtt($Traslado, array( "Base"=>number_format($abdDatArt[$i]["ivaBase"],2,'.',''), "Impuesto"=>$abdDatArt[$i]["ivaImpuesto"], "TipoFactor"=>$abdDatArt[$i]["ivaTipoFactor"], "TasaOCuota"=>number_format($abdDatArt[$i]["ivaTasaOCuota"],6,'.',''), "Importe"=>number_format($abdDatArt[$i]["ivaImporte"],2,'.','') ) ); $ivaTasaOCuota = $abdDatArt[$i]["ivaTasaOCuota"]; } if ($abdDatArt[$i]["isrImporte"] > 0) //if($abdDatArt[$i]["isrImpuesto"] == "001") { $Retenciones = $xml->createElement("cfdi:Retenciones"); $Retenciones = $impuestos->appendChild($Retenciones); $Retencion = $xml->createElement("cfdi:Retencion"); $Retencion = $Retenciones->appendChild($Retencion); $isrImpuesto = $abdDatArt[$i]["isrImpuesto"]; cargaAtt($Retencion, array( "Base"=>number_format($abdDatArt[$i]["isrBase"],2,'.',''), "Impuesto"=>$abdDatArt[$i]["isrImpuesto"], "TipoFactor"=>$abdDatArt[$i]["isrTipoFactor"], "TasaOCuota"=>number_format($abdDatArt[$i]["isrTasaOCuota"],6,'.',''), "Importe"=>number_format($abdDatArt[$i]["isrImporte"],2,'.','') ) ); $isrTasaOCuota = $abdDatArt[$i]["isrTasaOCuota"]; } } } if ($totalImpuestosTrasladados > 0 || $totalImpuestosRetenidos > 0) { $Impuestos = $xml->createElement("cfdi:Impuestos"); $Impuestos = $root->appendChild($Impuestos); if ($totalImpuestosRetenidos > 0) { $Retenciones = $xml->createElement("cfdi:Retenciones"); $Retenciones = $Impuestos->appendChild($Retenciones); $Retencion = $xml->createElement("cfdi:Retencion"); $Retencion = $Retenciones->appendChild($Retencion); cargaAtt($Retencion, array( "Impuesto"=>$isrImpuesto, "Importe"=>number_format($totalImpuestosRetenidos,2,'.','') ) ); cargaAtt($Impuestos, array( "TotalImpuestosRetenidos"=>number_format($totalImpuestosRetenidos,2,'.','') ) ); } if ($totalImpuestosTrasladados > 0) { $Traslados = $xml->createElement("cfdi:Traslados"); $Traslados = $Impuestos->appendChild($Traslados); $Traslado = $xml->createElement("cfdi:Traslado"); $Traslado = $Traslados->appendChild($Traslado); cargaAtt($Traslado, array( "Base"=>number_format($subTotTraslados,2,'.',''), "Impuesto"=>$ivaImpuesto, "TipoFactor"=>"Tasa", "TasaOCuota"=>number_format($ivaTasaOCuota,6,'.',''), "Importe"=>number_format($totalImpuestosTrasladados,2,'.','') ) ); cargaAtt($Impuestos, array( "TotalImpuestosTrasladados"=>number_format($totalImpuestosTrasladados,2,'.','') ) ); } } $complemento = $xml->createElement("cfdi:Complemento"); $complemento = $root->appendChild($complemento); #== 10.7 Termina de conformarse la "Cadena original" con doble || $cadena_original .= "|"; if ($tipoTest > 0){ #=== Muestra la cadena original (opcional a mostrar) ======================= echo '
'; echo 'CADENA ORIGINAL'; echo '
'; echo '
'; echo $cadena_original; echo '

'; } #== 10.8 Proceso para obtener el sello digital del archivo .pem.key ========= $keyid = openssl_get_privatekey(file_get_contents($SendaPEMS.$file_key)); openssl_sign($cadena_original, $crypttext, $keyid, OPENSSL_ALGO_SHA256); openssl_free_key($keyid); #== 10.9 Se convierte la cadena digital a Base 64 =========================== $sello = base64_encode($crypttext); if ($tipoTest > 0){ #=== Muestra el sello (opcional a mostrar) ================================= echo '
'; echo 'SELLO '.$SendaPEMS.$file_key; echo '
'; echo '
'; echo $sello; echo '

'; } #== 10.10 Proceso para extraer el certificado del sello digital ================== $file = $SendaPEMS.$file_cer; // Ruta al archivo $datos = file($file); $certificado = ""; $carga=false; for ($i=0; $i 0){ #=== Muestra el certificado del sello digital (opcional a mostrar) ========= echo '
'; echo 'CERTIFICADO DEL SELLO DIGITAL'; echo '
'; echo '
'; echo $certificado; echo '

'; } #== 10.11 Se continua con la integración de nodos =========================== $root->setAttribute("Sello",$sello); $root->setAttribute("Certificado",$certificado); # Certificado. #== Fin de la integración de nodos ========================================= #=== 10.12 Se guarda el archivo .XML antes de ser timbrado ======================= $cfdi = $xml->saveXML(); $xml->formatOutput = true; $xml->save($SendaCFDI."PreCFDI-33_".$NoFac.".xml"); unset($xml); #=== 10.13 Se dan permisos de escritura al archivo .xml. ========================= chmod($SendaCFDI."PreCFDI-33_".$NoFac.".xml", 0777); ### 11. PROCESO DE TIMBRADO ######################################################## if ($tipoTest > 0){ #=== Se muestra el .XML antes de ser timbrado (opcional a mostrar)========== echo '
'; echo 'FACTURA .XML A TIMBRAR'; echo '
'; echo '
'; echo htmlspecialchars($cfdi); echo '

'; } #== 11.1 Se crea una variable de tipo DOM y se le carga el CFDI ================================= $xml2 = new DOMDocument(); $xml2->loadXML($cfdi); #== 11.2 Proceso de validación de la variable de tipo DOM (estructura del CFDI a timbrar) contra el esquema cfdv32.xsd ========================== $fname = $SendaCFDI."PreCFDI-33_".$NoFac.".xml"; if(!file_exists($fname)){ die(PHP_EOL . "File not found" . PHP_EOL . PHP_EOL); } $handle = fopen($fname, "r"); $sData = ''; #== 11.3 Convirtiendo el contenido del CFDI a BASE 64 ====================== while(!feof($handle)) $sData .= fread($handle, filesize($fname)); fclose($handle); $b64 = base64_encode($sData); $response = ''; if($abdDatPAC["tipoTim"] == 1){ ## Timbrado en producción $urlLocation = 'https://solucionfactible.com/ws/services/Timbrado'; } else { ## Timbrado en pruebas $urlLocation = 'https://testing.solucionfactible.com/ws/services/Timbrado'; } #== 11.5 Se lleva a cabo el timbrado del XML ============================ try { $client = new SoapClient($urlPAC); $client->__setLocation($urlLocation); $params = array('usuario' => $username, 'password' => $password, 'cfdiBase64'=>$b64, 'zip'=>False); $response = $client->__soapCall('timbrarBase64', array('parameters' => $params)); } catch (SoapFault $fault) { $j_array = array('code' => "400", "message" => $fault->faultcode."-".$fault->faultstring); $Resultado = json_encode($j_array); echo $Resultado; return; } $ret = $response->return; if($ret->status != 200) { $j_array = array('code' => "500", "message" => "ERROR EN EL PROCESO DE TIMBRADO. ".$ret->status." - ".$ret->mensaje); $Resultado = json_encode($j_array); echo $Resultado; return; } /* if ($tipoTest > 0){ echo '
'; print_r($ret); echo '
'; return; } */ #=== 11.7 Muestra los resultados del timbrado del CFDI ========================= $RespServ = $ret->resultados->cfdiTimbrado; if($RespServ == NULL){ $j_array = array('code' => "600", "message" => "ERROR EN EL PROCESO DE TIMBRADO. status: ".$ret->status.", mensaje: ".$ret->mensaje.". ==> Resultado Timbrado: "." status: ".$ret->resultados->status.", mensaje: ".$ret->resultados->mensaje); $Resultado = json_encode($j_array); echo $Resultado; return; /* //echo $cadena_original; echo "status: ".$ret->resultados->status.", mensaje: ".$ret->resultados->mensaje; echo "
"; echo "
"; print_r($ret); echo "
"; echo "
"; die(PHP_EOL . "Error al timbrar el CFDI." . PHP_EOL . PHP_EOL); */ } if ($tipoTest > 0){ #== 12.5 Se muestra el .XML ya timbrado (CFDI V 3.2), opcional a mostrar ===== echo '
'; echo 'FACTURA .XML (CFDI) YA TIMBRADA'; echo '
'; echo '
'; echo htmlspecialchars($RespServ); echo '

'; } ## 12. PROCESOS POSTERIORES AL TIMBRADO ######################################## #== 12.1 Se asigna la respuesta del servidor a una variable de tipo DOM ==== $VarXML = new DOMDocument(); $VarXML->loadXML($RespServ); #== 12.2 Se graba la respuesta del servidor a un archivo .xml $VarXML->save($SendaCFDI."RespServ_".$NoFac.".xml"); chmod($SendaCFDI."RespServ_".$NoFac.".xml", 0777); if($TipPDFGen == 1) { $NomArchXML = "CFDI_".$fact_serie."_".$invoiceNumber.".xml"; $NomArchPDF = "CFDI_".$fact_serie."_".$invoiceNumber.".pdf"; } else { $NomArchXML = "CFDI_".$fact_serie.str_pad($fact_folio, 6, "0", STR_PAD_LEFT)."_".$invoiceNumber.".xml"; $NomArchPDF = "CFDI_".$fact_serie.str_pad($fact_folio, 6, "0", STR_PAD_LEFT)."_".$invoiceNumber.".pdf"; } //$NomArchXML = "CFDI_".$fact_serie.str_pad($fact_folio, 6, "0", STR_PAD_LEFT)."_".$invoiceNumber.".xml"; //$NomArchPDF = "CFDI_".$fact_serie.str_pad($fact_folio, 6, "0", STR_PAD_LEFT)."_".$invoiceNumber.".pdf"; $xmlt = new DOMDocument(); $xmlt->loadXML($RespServ); #== 12.1.1 Se valida si tiene addenda y se le agrega al CFDI ==== if($incAddenda == 1) { if ($tipoTest > 0){ echo '
'; echo 'DATOS DE LA ADDENDA'; echo '
'; echo '
'; echo 'tipoProveedor: '.$tip_Pro_AdAs.'
'; echo 'folio: '.$folio_AdAs.'
'; echo 'ordenCompra: '.$ord_Com_AdAs.'
'; echo 'noProveedor: '.$no_Prov_AdAs.'
'; echo 'serie: '.$serie_AdAs.'
'; echo 'cuantos: '.count($ajsonAddenda).'
'; for ($i = 0; $i'.$ajsonAddenda[$i]["ivaDevengado"].'
'; echo 'ivaAcreditable('.$i.'): '.$ajsonAddenda[$i]["ivaAcreditable"].'
'; echo 'noPartida('.$i.'): '.$ajsonAddenda[$i]["noPartida"].'
'; echo 'Otros('.$i.'): '.$ajsonAddenda[$i]["Otros"].'
'; }; echo '

'; } $Root = $xmlt->firstChild; $addenda = $xmlt->createElement("cfdi:Addenda"); $addenda = $Root->appendChild($addenda); $asonioscoc = $xmlt->createElement("ASONIOSCOC"); $asonioscoc = $addenda->appendChild($asonioscoc); cargaAttNodo($asonioscoc, array( "tipoProveedor"=>$tip_Pro_AdAs, "folio"=>$folio_AdAs, "ordenCompra"=>$ord_Com_AdAs, "noProveedor"=>$no_Prov_AdAs, "serie"=>$serie_AdAs ) ); $partidas = $xmlt->createElement("Partidas"); $partidas = $asonioscoc->appendChild($partidas); for ($i = 0; $icreateElement("Partida"); $partida = $partidas->appendChild($partida); cargaAttNodo($partida, array( "ivaDevengado"=>$ajsonAddenda[$i]["ivaDevengado"], "ivaAcreditable"=>$ajsonAddenda[$i]["ivaAcreditable"], "noPartida"=>$ajsonAddenda[$i]["noPartida"], "Otros"=>$ajsonAddenda[$i]["Otros"] ) ); }; } $xmlt->save($SendaCFDI.$NomArchXML); chmod($SendaCFDI.$NomArchXML, 0777); #== 12.7 Procesos para extraer datos del Timbre Fiscal del CFDI ========= $docXML = new DOMDocument(); //$docXML->load($SendaCFDI."Fact_CFDI_".$NoFac.".xml"); $docXML->load($SendaCFDI.$NomArchXML); $comprobante = $docXML->getElementsByTagName("TimbreFiscalDigital"); #== 12.8 Se obtienen contenidos de los atributos y se asignan a variables para ser mostrados ======= foreach($comprobante as $timFis){ $version_timbre = $timFis->getAttribute('Version'); $sello_SAT = $timFis->getAttribute('SelloSAT'); $cert_SAT = $timFis->getAttribute('NoCertificadoSAT'); $sello_CFD = $timFis->getAttribute('SelloCFD'); $tim_fecha = $timFis->getAttribute('FechaTimbrado'); $tim_uuid = $timFis->getAttribute('UUID'); $tim_RfcPac = $timFis->getAttribute('RfcProvCertif'); } if ($tipoTest > 0){ echo 'Versión del timbre: '.$version_timbre.'
'; echo 'Sello del SAT: '.$sello_SAT.'
'; echo 'Certificado del SAT: '.$cert_SAT.'
'; echo 'Sello del CFDI: '.$sello_CFD.'
'; echo 'Fecha de timbrado: '.$tim_fecha.'
'; echo 'Folio fiscal: '.$tim_uuid.'
'; echo 'RFC del PAC: '.$tim_RfcPac.'
'; echo 'No. de factura asignado por el sistema local: '.$NoFac.'

'; } #== 12.8.1 Se muestra el número de factura asignado por el sistema local (no asingado por el SAT). $params = $docXML->getElementsByTagName('Emisor'); foreach ($params as $param) { $Emisor_RFC = $param->getAttribute('Rfc'); } $params = $docXML->getElementsByTagName('Receptor'); foreach ($params as $param) { $Receptor_RFC = $param->getAttribute('Rfc'); } $params = $docXML->getElementsByTagName('Comprobante'); foreach ($params as $param) { $total = $param->getAttribute('Total'); } #== 12.9 Se crea el archivo .PNG con codigo bidimensional ================================= $filename = "archs_graf/Img_".$tim_uuid.".png"; ### 13. CREACION DE PDF ########################### # 13.1 Creación del Archivo PDF //$url = 'http://64.235.39.50/aptusCFDIRF/wsInvoicePDF_v33.php?NomArchXML='.$NomArchXML.'&NomArchPDF='.$NomArchPDF; if($TipPDFGen == 1) { $url = 'https://aptuslegal.app/aptusCFDIRF/'.$FormatoPDF.'.php?NomArchXML='.$NomArchXML.'&NomArchPDF='.$NomArchPDF.'&pInvNumb='.$invoiceNumber.'&pOrdCob='.$sOrdenCobro.'&pObserva='.$sObservaciones.'&pDirRecep='.$sDireRecep;; } else { $url = 'https://aptuslegal.app/aptusCFDIRF/'.$FormatoPDF.'.php?NomArchXML='.$NomArchXML.'&NomArchPDF='.$NomArchPDF; } $objCurl = curl_init(); curl_setopt($objCurl, CURLOPT_URL, $url); curl_setopt($objCurl, CURLOPT_HEADER, 0); curl_setopt($objCurl, CURLOPT_RETURNTRANSFER, true); curl_exec($objCurl); curl_close($objCurl); # 13.3 Envio del Archivos a Invoice de Zoho Books # Primero actualizamos el access_token de Books #== Datos y Variables para OAuth Token // $boa_ClientId = $abdDatGen["B_OAuth_client_id"]; // $boa_ClientSecret = $abdDatGen["B_OAuth_client_secret"]; // $boa_RefreshToken = $abdDatGen["B_OAuth_refresh_token"]; // $boa_GrantType = $abdDatGen["B_OAuth_grant_type"]; // $boa_RedirectUri = $abdDatGen["B_OAuth_redirect_uri"]; // $boa_AuthUrl = "https://accounts.zoho.com/oauth/v2/token"; #---------------------------------------------------------------- # JFA: 2021-06-12 # Obtenemos el access_token #---------------------------------------------------------------- // $Params = array( // "refresh_token" => $boa_RefreshToken, // "client_id" => $boa_ClientId, // "client_secret" => $boa_ClientSecret, // "redirect_uri" => $boa_RedirectUri, // "grant_type" => $boa_GrantType // ); // $curl = curl_init(); // curl_setopt($curl, CURLOPT_URL, $boa_AuthUrl); // curl_setopt($curl, CURLOPT_CUSTOMREQUEST, 'POST'); // curl_setopt($curl, CURLOPT_POSTFIELDS, $Params); // curl_setopt($curl, CURLOPT_RETURNTRANSFER, true); // curl_setopt($curl, CURLOPT_FOLLOWLOCATION, true); // $response = curl_exec($curl); // $array = json_decode($response); // $boa_access_token = $array->access_token; // $boa_access_token = oauth($appOwner, 'ZBooks', $boa_RefreshToken, $boa_ClientId, $boa_ClientSecret, $boa_RedirectUri, $boa_GrantType, $boa_AuthUrl); $curl = curl_init(); curl_setopt_array($curl, array( CURLOPT_URL => 'https://donatello.aptuslegal.app/oauth/token/'.$organi_id_ZB, CURLOPT_RETURNTRANSFER => true, CURLOPT_ENCODING => '', CURLOPT_MAXREDIRS => 10, CURLOPT_TIMEOUT => 0, CURLOPT_FOLLOWLOCATION => true, CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1, CURLOPT_CUSTOMREQUEST => 'GET', CURLOPT_HTTPHEADER => array('Authorization: Token e68d5a079f937ea29ad2ec5a5b105b75491a0e0c'),)); $response = curl_exec($curl); curl_close($curl); $ra = json_decode($response); $boa_access_token = $ra->access_token; //echo $access_token; if($organi_id_ZB != "673221150") { # Primero el PDF $file_name_with_full_path = '/var/www/html/aptusCFDIRF/archs_cfdi/'.$NomArchPDF; $request_url = 'https://www.zohoapis.com/books/v3/invoices/'.$invoiceID.'/attachment'; if (function_exists('curl_file_create')) { // php 5.6+ $cFile = curl_file_create($file_name_with_full_path); } else { $cFile = '@' . realpath($file_name_with_full_path); } $post = array( // 'authtoken' => $authtoken_ZB, 'organization_id' => $organi_id_ZB, 'can_send_in_mail' => 'true', 'attachment'=> $cFile); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $request_url); //curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); #JFA: Cambiamos el método de Autenticación a OAuth curl_setopt($ch, CURLOPT_HTTPHEADER, array('Authorization: Zoho-oauthtoken ' . $boa_access_token)); $r = curl_exec($ch); $resultPDF = $r; $httpcode = curl_getinfo($ch, CURLINFO_HTTP_CODE); curl_close ($ch); $ra = json_decode($r); $resultPDF = $ra->code.' - '.$ra->message; if($ra->code != 0) { $NomArchHttp = '/var/www/html/aptusCFDIRF/archs_txt/'."CFDI_".$fact_serie."_".$invoiceNumber.".txt"; $variable = fopen($NomArchHttp,"w"); fwrite($variable,$httpcode . PHP_EOL); fwrite($variable,$ra->code.' - '.$ra->message); fclose($variable); } } //print_r($r); # Segundo el XML $file_name_with_full_path = '/var/www/html/aptusCFDIRF/archs_cfdi/'.$NomArchXML; $request_url = 'https://www.zohoapis.com/books/v3/invoices/'.$invoiceID.'/attachment'; if (function_exists('curl_file_create')) { // php 5.6+ $cFile = curl_file_create($file_name_with_full_path); } else { $cFile = '@' . realpath($file_name_with_full_path); } $post = array( // 'authtoken' => $authtoken_ZB, 'organization_id' => $organi_id_ZB, // 'can_send_in_mail' => 'true', 'attachment'=> $cFile); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $request_url); //curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); #JFA: Cambiamos el método de Autenticación a OAuth curl_setopt($ch, CURLOPT_HTTPHEADER, array('Authorization: Zoho-oauthtoken ' . $boa_access_token)); $r = curl_exec($ch); //print_r($r); $resultXML = $r; curl_close ($ch); $ra = json_decode($r); $resultXML = $ra->code.' - '.$ra->message; # 13.4 Envio del Archivos a Invoice de Zoho Creator # Primero el PDF $file_name_with_full_path = '/var/www/html/aptusCFDIRF/archs_cfdi/'.$NomArchPDF; //$request_url = 'https://creator.zoho.com/api/xml/fileupload/scope=creatorapi'; # Actualización a API V2 y OAuth JFA y FFR 2021-06-18 $request_url = 'https://creator.zoho.com/api/v2/'.$appOwner.'/'.$applnkname.'/report/cfdi_I_query/'.$bRecId.'/File_CFDI_PDF/upload'; if (function_exists('curl_file_create')) { // php 5.6+ $cFile = curl_file_create($file_name_with_full_path); } else { $cFile = '@' . realpath($file_name_with_full_path); } $post = array( // 'authtoken' => $authtoken_ZC, // 'applinkname' => $applnkname, // 'formname' => 'CreacionCFDIv33', // 'fieldname' => 'File_CFDI_PDF', // 'recordId' => $bRecId, // 'filename' => $NomArchPDF, 'file'=> $cFile); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $request_url); //curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); #JFA: Cambiamos el método de Autenticación a OAuth curl_setopt($ch, CURLOPT_HTTPHEADER, array('Authorization: Zoho-oauthtoken ' . $access_token)); $r = curl_exec($ch); curl_close ($ch); # Segundo el XML $file_name_with_full_path = '/var/www/html/aptusCFDIRF/archs_cfdi/'.$NomArchXML; //$request_url = 'https://creator.zoho.com/api/xml/fileupload/scope=creatorapi'; # Actualización a API V2 y OAuth JFA y FFR 2021-06-18 $request_url = 'https://creator.zoho.com/api/v2/'.$appOwner.'/'.$applnkname.'/report/cfdi_I_query/'.$bRecId.'/File_CFDI_XML/upload'; if (function_exists('curl_file_create')) { // php 5.6+ $cFile = curl_file_create($file_name_with_full_path); } else { $cFile = '@' . realpath($file_name_with_full_path); } $post = array( // 'authtoken' => $authtoken_ZC, // 'applinkname' => $applnkname, // 'formname' => 'CreacionCFDIv33', // 'fieldname' => 'File_CFDI_XML', // 'recordId' => $bRecId, // 'filename' => $NomArchXML, 'file'=> $cFile); $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $request_url); //curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, $post); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true); #JFA: Cambiamos el método de Autenticación a OAuth curl_setopt($ch, CURLOPT_HTTPHEADER, array('Authorization: Zoho-oauthtoken ' . $access_token)); $r = curl_exec($ch); curl_close ($ch); #== Se elimina los archivos de trabajo unlink($SendaCFDI."PreCFDI-33_".$NoFac.".xml"); unlink($SendaCFDI."RespServ_".$NoFac.".xml"); unlink($filename); $j_array = array('code' => "200", 'message' => "Proceso de creacion de CFDI fue exitoso", 'version_timbre' => $version_timbre, 'cert_SAT' => $cert_SAT, 'tim_fecha' => $tim_fecha, 'tim_uuid' => $tim_uuid, 'tim_RfcPac' => $tim_RfcPac, 'sello_SAT' => $sello_SAT, 'sello_CFD' => $sello_CFD, 'RespBooks_FileXML' => $resultXML, 'RespBooks_FilePDF' => $resultPDF); $Resultado = json_encode($j_array); echo $Resultado; return; ### 14. FUNCIONES DEL MÓDULO ######################################################### # 14.1 Función que integra los nodos al archivo .XML y forma la "Cadena original". function cargaAtt(&$nodo, $attr){ global $xml, $cadena_original; $quitar = array('sello'=>1,'noCertificado'=>1,'certificado'=>1); foreach ($attr as $key => $val){ $val = preg_replace('/\s\s+/', ' ', $val); $val = trim($val); if (strlen($val)>0){ $val = utf8_encode(str_replace("|","/",$val)); $nodo->setAttribute($key,$val); if (!isset($quitar[$key])) if (substr($key,0,3) != "xml" && substr($key,0,4) != "xsi:") $cadena_original .= $val . "|"; } } } # 14.2 Funciónes que da formato al "Importe total" como lo requiere el SAT para ser integrado al código QR. function ProcesImpTot($ImpTot){ $ImpTot = number_format($ImpTot, 4); // <== Se agregó el 30 de abril de 2017. $ArrayImpTot = explode(".", $ImpTot); $NumEnt = $ArrayImpTot[0]; $NumDec = ProcesDecFac($ArrayImpTot[1]); return $NumEnt.".".$NumDec; } function ProcesDecFac($Num){ $FolDec = ""; if ($Num < 10){$FolDec = "00000".$Num;} if ($Num > 9 and $Num < 100){$FolDec = $Num."0000";} if ($Num > 99 and $Num < 1000){$FolDec = $Num."000";} if ($Num > 999 and $Num < 10000){$FolDec = $Num."00";} if ($Num > 9999 and $Num < 100000){$FolDec = $Num."0";} return $FolDec; } function limpioCaracteresXML($cadena){ $search = array("<", ">", "&", "'"); $replace = array("<", ">", "&", "&apos"); $final = str_replace($search, $replace, $cadena); return $final; }