Доброго время суток. Помогите разобраться, есть подозрения на взлом. Как это можно понять и где и что посмотреть.
Feb 7 08:06:10 p kernel: [203720.307763] SYN/FININ=eth1 OUT= MAC=64:70:02:10:22:c3:00:08:e2:0a:f8:19:08:00 SRC=31.180.143.85 DST=мой ip LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=15115 DF PROTO=TCP SPT=0 DPT=20480 WINDOW=64903 RES$
Feb 7 08:59:52 p kernel: [206942.286817] SYN/FININ=eth1 OUT= MAC=64:70:02:10:22:c3:00:08:e2:0a:f8:19:08:00 SRC=178.35.142.34 DST=мой ip LEN=52 TOS=0x00 PREC=0x00 TTL=120 ID=20209 DF PROTO=TCP SPT=0 DPT=20480 WINDOW=1344 RES=$
Feb 7 15:23:38 p kernel: [229968.215078] SSH_brute_forceIN=eth1 OUT= MAC=64:70:02:10:22:c3:00:08:e2:0a:f8:19:08:00 SRC=94.154.72.213 DST=мой ip LEN=60 TOS=0x00 PREC=0x00 TTL=60 ID=62113 DF PROTO=TCP SPT=51513 DPT=22 WINDOW=6$
Feb 7 15:23:54 p kernel: [229984.269041] SSH_brute_forceIN=eth1 OUT= MAC=64:70:02:10:22:c3:00:08:e2:0a:f8:19:08:00 SRC=94.154.72.213 DST=мой ip LEN=60 TOS=0x00 PREC=0x00 TTL=60 ID=62114 DF PROTO=TCP SPT=51513 DPT=22 WINDOW=6$
Feb 7 15:24:43 p kernel: [230032.523765] PPP BSD Compression module registered
Feb 7 15:24:43 p kernel: [230032.526771] PPP Deflate Compression module registered
Feb 7 15:24:43 p kernel: [230032.523765] PPP BSD Compression module registered
Feb 7 15:24:43 p kernel: [230032.526771] PPP Deflate Compression module registered
Feb 7 15:34:15 p kernel: [ 0.000000] Initializing cgroup subsys cpuset
Feb 7 15:34:15 p kernel: [ 0.000000] Initializing cgroup subsys cpu
Feb 7 15:34:15 p kernel: [ 0.000000] Initializing cgroup subsys cpuacct
Feb 7 15:34:15 p kernel: [ 0.000000] Linux version 3.13.0-77-generic (buildd@lcy01-30) (gcc version 4.8.2 (Ubuntu 4.8.2-19ubuntu1) ) #121-Ubuntu SMP Wed Jan 20 10:50:42 UTC 2016 (Ubuntu 3.13.0-77.121-generic 3.13.11-ckt32)
Feb 7 15:34:15 p kernel: [ 0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-3.13.0-77-generic root=UUID=638c68db-a5a7-479d-b434-bec5376f9e0c ro selinux=0 nomdmonddf nomdmonisw
Feb 7 15:34:15 p kernel: [ 0.000000] KERNEL supported cpus:
Feb 7 15:34:15 p kernel: [ 0.000000] Intel GenuineIntel
Feb 7 15:34:15 p kernel: [ 0.000000] AMD AuthenticAMD
Feb 7 15:34:15 p kernel: [ 0.000000] Centaur CentaurHauls
Feb 7 15:34:15 p kernel: [ 0.000000] e820: BIOS-provided physical RAM map:
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009f7ff] usable
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x000000000009f800-0x000000000009ffff] reserved
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000000f0000-0x00000000000fffff] reserved
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000cfedffff] usable
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000cfee0000-0x00000000cfee2fff] ACPI NVS
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000cfee3000-0x00000000cfeeffff] ACPI data
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000cfef0000-0x00000000cfefffff] reserved
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000f4000000-0x00000000f7ffffff] reserved
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x00000000fec00000-0x00000000ffffffff] reserved
Feb 7 15:34:15 p kernel: [ 0.000000] BIOS-e820: [mem 0x0000000100000000-0x000000022fffffff] usable
Feb 7 15:34:15 p kernel: [ 0.000000] NX (Execute Disable) protection: active
Feb 7 15:34:15 p kernel: [ 0.000000] SMBIOS 2.4 present.
Feb 7 15:34:15 p kernel: [ 0.000000] DMI: Gigabyte Technology Co., Ltd. P43T-ES3G/P43T-ES3G, BIOS F7 08/20/2010
Feb 7 15:34:15 p kernel: [ 0.000000] e820: update [mem 0x00000000-0x00000fff] usable ==> reserved
Feb 7 15:34:15 p kernel: [ 0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
Feb 7 15:34:15 p kernel: [ 0.000000] No AGP bridge found
Feb 7 15:34:15 p kernel: [ 0.000000] e820: last_pfn = 0x230000 max_arch_pfn = 0x400000000
Feb 7 15:34:15 p kernel: [ 0.000000] MTRR default type: uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] MTRR fixed ranges enabled:
Feb 7 15:34:15 p kernel: [ 0.000000] 00000-9FFFF write-back
Feb 7 15:34:15 p kernel: [ 0.000000] A0000-BFFFF uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] C0000-CDFFF write-protect
Feb 7 15:34:15 p kernel: [ 0.000000] CE000-EFFFF uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] F0000-FFFFF write-through
Feb 7 15:34:15 p kernel: [ 0.000000] MTRR variable ranges enabled:
Feb 7 15:34:15 p kernel: [ 0.000000] 0 base 000000000 mask F00000000 write-back
Feb 7 15:34:15 p kernel: [ 0.000000] 1 base 0E0000000 mask FE0000000 uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] 2 base 0D0000000 mask FF0000000 uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] 3 base 100000000 mask F00000000 write-back
Feb 7 15:34:15 p kernel: [ 0.000000] 4 base 200000000 mask FC0000000 write-back
Feb 7 15:34:15 p kernel: [ 0.000000] 5 base 230000000 mask FF0000000 uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] 6 base 0CFF00000 mask FFFF00000 uncachable
Feb 7 15:34:15 p kernel: [ 0.000000] 7 disabled
Feb 7 15:34:15 p kernel: [ 0.000000] x86 PAT enabled: cpu 0, old 0x7040600070406, new 0x7010600070106
Feb 7 15:34:15 p kernel: [ 0.000000] original variable MTRRs
Feb 7 15:34:15 p kernel: [ 0.000000] reg 0, base: 0GB, range: 4GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 1, base: 3584MB, range: 512MB, type UC
Feb 7 15:34:15 p kernel: [ 0.000000] reg 2, base: 3328MB, range: 256MB, type UC
Feb 7 15:34:15 p kernel: [ 0.000000] reg 3, base: 4GB, range: 4GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 4, base: 8GB, range: 1GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 5, base: 8960MB, range: 256MB, type UC
Feb 7 15:34:15 p kernel: [ 0.000000] reg 6, base: 3327MB, range: 1MB, type UC
Feb 7 15:34:15 p kernel: [ 0.000000] total RAM covered: 8191M
Feb 7 15:34:15 p kernel: [ 0.000000] Found optimal setting for mtrr clean up
Feb 7 15:34:15 p kernel: [ 0.000000] gran_size: 64K chunk_size: 2M num_reg: 7 lose cover RAM: 0G
Feb 7 15:34:15 p kernel: [ 0.000000] New variable MTRRs
Feb 7 15:34:15 p kernel: [ 0.000000] reg 0, base: 0GB, range: 2GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 1, base: 2GB, range: 1GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 2, base: 3GB, range: 256MB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 3, base: 3327MB, range: 1MB, type UC
Feb 7 15:34:15 p kernel: [ 0.000000] reg 4, base: 4GB, range: 4GB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 5, base: 8GB, range: 512MB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] reg 6, base: 8704MB, range: 256MB, type WB
Feb 7 15:34:15 p kernel: [ 0.000000] e820: update [mem 0xcff00000-0xffffffff] usable ==> reserved
Feb 7 15:34:15 p kernel: [ 0.000000] e820: last_pfn = 0xcfee0 max_arch_pfn = 0x400000000
Feb 7 15:34:15 p kernel: [ 0.000000] found SMP MP-table at [mem 0x000f5380-0x000f538f] mapped at [ffff8800000f5380]
Feb 7 15:34:15 p kernel: [ 0.000000] Scanning 1 areas for low memory corruption