Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Thu Nov 18 04:42:04 2021
Date Range Processed: yesterday
( 2021-Nov-17 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 49:48 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
60.191.125.35 -> zapf.wiki:443: 1 Time(s)
60.216.134.51 -> zapf.wiki:443: 1 Time(s)
A total of 10 sites probed the server
159.223.44.222
172.104.131.24
194.67.205.181
219.139.40.10
23.23.6.16
37.0.8.133
45.86.74.235
5.188.210.227
87.251.64.122
91.134.146.186
Requests with error response codes
400 Bad Request
null: 14 Time(s)
mstshash=Administr: 2 Time(s)
zapf.wiki:443: 2 Time(s)
/: 1 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 1 Time(s)
/config/getuser?index=0: 1 Time(s)
/index.php?s=/index/\x09hink\x07pp/invokef ... exec&vars[1][]=: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... VVse6cDq_3VAAAS: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... kH9lxVZ5wkRAAAU: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... llpgPHcNjaiAAAT: 1 Time(s)
http://5.188.210.227/echo.php: 1 Time(s)
404 Not Found
//2018/wp-includes/wlwmanifest.xml: 1 Time(s)
//2019/wp-includes/wlwmanifest.xml: 1 Time(s)
//blog/wp-includes/wlwmanifest.xml: 1 Time(s)
//cms/wp-includes/wlwmanifest.xml: 1 Time(s)
//media/wp-includes/wlwmanifest.xml: 1 Time(s)
//news/wp-includes/wlwmanifest.xml: 1 Time(s)
//shop/wp-includes/wlwmanifest.xml: 1 Time(s)
//site/wp-includes/wlwmanifest.xml: 1 Time(s)
//sito/wp-includes/wlwmanifest.xml: 1 Time(s)
//test/wp-includes/wlwmanifest.xml: 1 Time(s)
//web/wp-includes/wlwmanifest.xml: 1 Time(s)
//website/wp-includes/wlwmanifest.xml: 1 Time(s)
//wordpress/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp-includes/wlwmanifest.xml: 1 Time(s)
//wp/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp1/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp2/wp-includes/wlwmanifest.xml: 1 Time(s)
//xmlrpc.php?rsd: 1 Time(s)
499 (undefined)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... 769gATVvhkxAAAV: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... VVse6cDq_3VAAAS: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... kH9lxVZ5wkRAAAU: 1 Time(s)
/socket.io/?noteId=D1lk7Eb3Squ7uGiIXiErNg& ... llpgPHcNjaiAAAT: 1 Time(s)
500 Internal Server Error
/: 37 Time(s)
/.env: 4 Time(s)
/robots.txt: 3 Time(s)
/console/: 2 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/ReportServer: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/cgi-bin: 1 Time(s)
/favicon.ico: 1 Time(s)
/login: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/servlets/com.adventnet.tools.sum.transpor ... nicationServlet: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (gurlstalk.com): 60 Time(s)
root (209.14.131.233): 39 Time(s)
root (152.136.181.121): 36 Time(s)
root (102.223.75.234): 32 Time(s)
root (1.15.106.44): 31 Time(s)
root (81.70.163.61): 29 Time(s)
root (115.246.73.210): 27 Time(s)
root (183.134.78.94): 27 Time(s)
root (186.67.248.5): 26 Time(s)
unknown (209.14.131.233): 22 Time(s)
root (143.244.136.52): 17 Time(s)
unknown (1.15.106.44): 17 Time(s)
unknown (115.246.73.210): 17 Time(s)
unknown (102.223.75.234): 16 Time(s)
root (171.39.0.3): 14 Time(s)
root (176.111.173.238): 13 Time(s)
root (210.25.189.14): 13 Time(s)
unknown (152.136.181.121): 13 Time(s)
root (114.67.179.239): 12 Time(s)
unknown (183.134.78.94): 12 Time(s)
unknown (186.67.248.5): 12 Time(s)
root (112.33.16.34): 11 Time(s)
unknown (81.70.163.61): 11 Time(s)
root (40.73.119.184): 8 Time(s)
unknown (143.244.136.52): 8 Time(s)
root (202.83.16.8): 7 Time(s)
unknown (212.192.241.37): 7 Time(s)
unknown (40.73.119.184): 7 Time(s)
root (128.187.26.211.sta.commander.net.au): 6 Time(s)
root (bras-base-mtrlpq02xew-grc-14-64-229-166-89.dsl.bell.ca): 6 Time(s)
unknown (171.39.0.3): 6 Time(s)
unknown (slot0.epaperitaliait.com): 6 Time(s)
unknown (202.83.16.8): 5 Time(s)
unknown (209.141.32.141): 5 Time(s)
root (183.157.169.245): 4 Time(s)
unknown (112.33.16.34): 4 Time(s)
unknown (128.187.26.211.sta.commander.net.au): 4 Time(s)
unknown (210.25.189.14): 4 Time(s)
unknown (212.192.241.124): 4 Time(s)
root (176.111.173.237): 3 Time(s)
unknown (114.67.179.239): 3 Time(s)
unknown (141.98.10.92): 3 Time(s)
unknown (205.185.114.87): 3 Time(s)
unknown (205.185.120.71): 3 Time(s)
unknown (209.141.62.185): 3 Time(s)
unknown (45.155.204.39): 3 Time(s)
unknown (097-097-177-058.res.spectrum.com): 2 Time(s)
unknown (121.166.68.59): 2 Time(s)
unknown (199.19.225.172): 2 Time(s)
unknown (200.73.129.37): 2 Time(s)
unknown (58.124.118.121): 2 Time(s)
unknown (81.68.212.201): 2 Time(s)
unknown (c-73-115-100-136.hsd1.tx.comcast.net): 2 Time(s)
root (139.198.109.155): 1 Time(s)
root (212.192.241.124): 1 Time(s)
root (39.170.80.185): 1 Time(s)
root (45.153.160.139): 1 Time(s)
root (81.68.212.201): 1 Time(s)
root (tor-exit1-readme.dfri.se): 1 Time(s)
unknown (103.98.79.46): 1 Time(s)
unknown (111.67.193.133): 1 Time(s)
unknown (175.209.89.234): 1 Time(s)
unknown (183.157.169.245): 1 Time(s)
unknown (198.98.62.88): 1 Time(s)
unknown (205.185.115.39): 1 Time(s)
unknown (209.141.43.8): 1 Time(s)
unknown (smtp17.mib360realestate.com): 1 Time(s)
Invalid Users:
Unknown Account: 220 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
43 Miscellaneous warnings
10.325K Bytes accepted 10,573
10.325K Bytes sent via SMTP 10,573
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
1 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
1 Total 4xx Rejects 100.00%
======== ==================================================
262 Connections
45 Connections lost (inbound)
262 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
root : 1 Time(s)
Failed logins from:
1.15.106.44: 31 times
39.170.80.185: 1 time
40.73.119.184: 8 times
45.153.160.139: 1 time
64.229.166.89 (bras-base-mtrlpq02xew-grc-14-64-229-166-89.dsl.bell.ca): 6 times
81.68.212.201: 1 time
81.70.163.61: 29 times
102.223.75.234: 32 times
104.248.168.195 (gurlstalk.com): 60 times
112.33.16.34: 11 times
114.67.179.239: 12 times
115.246.73.210 (115.246.73.210.static.jio.com): 27 times
139.198.109.155: 1 time
143.244.136.52: 17 times
152.136.181.121: 36 times
171.25.193.77 (tor-exit1-readme.dfri.se): 1 time
171.39.0.3: 14 times
176.111.173.237: 3 times
176.111.173.238: 13 times
183.134.78.94: 27 times
183.157.169.245: 4 times
186.67.248.5: 26 times
202.83.16.8 (act20283168.broadband.actcorp.in): 7 times
209.14.131.233 (209-14-131-233.as270353.com.br): 39 times
210.25.189.14: 13 times
211.26.187.128 (128.187.26.211.sta.commander.net.au): 6 times
212.192.241.124: 1 time
Illegal users from:
2001:470:1:c84::13: 1 time
undef: 122 times
1.15.106.44: 17 times
40.73.119.184: 7 times
45.155.204.39: 3 times
58.124.118.121: 2 times
65.49.20.67 (scan-18.shadowserver.org): 1 time
73.115.100.136 (c-73-115-100-136.hsd1.tx.comcast.net): 2 times
81.68.212.201: 2 times
81.70.163.61: 11 times
97.97.177.58 (097-097-177-058.res.spectrum.com): 2 times
102.223.75.234: 16 times
103.98.79.46: 1 time
111.67.193.133: 1 time
112.33.16.34: 4 times
114.67.179.239: 3 times
115.246.73.210 (115.246.73.210.static.jio.com): 17 times
121.166.68.59: 2 times
141.98.10.92: 3 times
143.244.136.52: 8 times
152.136.181.121: 13 times
171.39.0.3: 6 times
175.209.89.234: 1 time
183.134.78.94: 12 times
183.157.169.245: 1 time
186.67.248.5: 12 times
195.133.18.24 (slot0.epaperitaliait.com): 6 times
198.98.62.88: 1 time
199.19.225.172: 2 times
200.73.129.37 (37.129.73.200.cab.prima.net.ar): 2 times
202.83.16.8 (act20283168.broadband.actcorp.in): 5 times
205.185.114.87: 3 times
205.185.115.39 (mx.learnmorefun.org): 1 time
205.185.119.40 (smtp17.mib360realestate.com): 1 time
205.185.120.71: 3 times
209.14.131.233 (209-14-131-233.as270353.com.br): 22 times
209.141.32.141 (smtp9.dfsfasfasf.xyz): 5 times
209.141.43.8 (mx09.hcx8.top): 1 time
209.141.62.185: 3 times
210.25.189.14: 4 times
211.26.187.128 (128.187.26.211.sta.commander.net.au): 4 times
212.192.241.37: 7 times
212.192.241.124: 4 times
**Unmatched Entries**
fatal: Unable to negotiate a key exchange method [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
3 Jahre, 11 Monate
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Wed Nov 17 04:42:05 2021
Date Range Processed: yesterday
( 2021-Nov-16 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 60:60 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 10 sites probed the server
125.127.149.159
164.92.66.113
178.239.21.102
178.239.21.162
195.15.226.153
34.77.162.25
64.227.97.195
64.227.99.233
66.240.205.34
80.82.65.247
Requests with error response codes
400 Bad Request
null: 9 Time(s)
mstshash=Administr: 2 Time(s)
/: 1 Time(s)
/.env: 1 Time(s)
/bag2: 1 Time(s)
/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/: 1 Time(s)
7: 1 Time(s)
G\xE8\x94(O\x9B\xFCY\xB1I\xBD\xE5cf\xE4\xC ... x09\xC0\x14\xC0: 1 Time(s)
\x88\xC1`\xE8\xBC\xB6F\xC4\x12\x0BAx\xD8\x ... (\xC0#\xC0'\xC0: 1 Time(s)
500 Internal Server Error
/: 72 Time(s)
/.env: 5 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 3 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 2 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/users/sign_in: 2 Time(s)
/.git/config: 1 Time(s)
///remote/fgt_lang?lang=/../../../..//////////dev/: 1 Time(s)
/?s=/Index/\x5Cthink\x5Capp/invokefunction ... s[1][]=otwksbpu: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/_profiler/phpinfo: 1 Time(s)
/actuator/health: 1 Time(s)
/debug/default/view?panel=config: 1 Time(s)
/index.php?s=/Index/\x5Cthink\x5Capp/invok ... HelloThinkPHP21: 1 Time(s)
/jenkins/login: 1 Time(s)
/login: 1 Time(s)
/manager/html: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/remote/fgt_lang?lang=/../../../..//////// ... lvpn_websession: 1 Time(s)
/robots.txt: 1 Time(s)
/script: 1 Time(s)
/wp-login.php: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (93-47-3-47.ip110.fastwebnet.it): 46 Time(s)
root (pppoe-static-209-91-178-224.vianet.ca): 35 Time(s)
root (61.148.90.118): 26 Time(s)
root (42.248.78.142): 23 Time(s)
root (5.181.80.180): 23 Time(s)
unknown (93-47-3-47.ip110.fastwebnet.it): 23 Time(s)
root (69.49.228.198): 22 Time(s)
root (40.115.79.44): 20 Time(s)
unknown (167.172.207.139): 20 Time(s)
unknown (120.92.34.203): 19 Time(s)
root (43.129.93.101): 18 Time(s)
root (222.90.82.234): 15 Time(s)
unknown (pppoe-static-209-91-178-224.vianet.ca): 15 Time(s)
unknown (40.115.79.44): 14 Time(s)
unknown (61.148.90.118): 12 Time(s)
root (167.172.207.139): 10 Time(s)
unknown (69.49.228.198): 10 Time(s)
unknown (176.111.173.237): 9 Time(s)
unknown (slot0.epaperitaliait.com): 9 Time(s)
root (123.231.90.100): 8 Time(s)
unknown (222.90.82.234): 8 Time(s)
unknown (43.129.93.101): 7 Time(s)
root (175.11.202.102): 6 Time(s)
root (d204-191-196-151.abhsia.telus.net): 6 Time(s)
unknown (42.248.78.142): 6 Time(s)
unknown (123.231.90.100): 5 Time(s)
unknown (45.144.225.69): 5 Time(s)
root (112.194.208.93): 4 Time(s)
unknown (188.164.175.126): 4 Time(s)
unknown (212.192.241.124): 4 Time(s)
unknown (2.56.59.198): 3 Time(s)
unknown (205.185.114.87): 3 Time(s)
unknown (205.185.119.112): 3 Time(s)
unknown (209.141.33.193): 3 Time(s)
unknown (209.141.62.185): 3 Time(s)
unknown (smtp4.achtungumbedingt.de): 3 Time(s)
root (120.92.34.203): 2 Time(s)
unknown (195.133.18.210): 2 Time(s)
unknown (199.19.225.172): 2 Time(s)
unknown (205.185.115.39): 2 Time(s)
unknown (209.141.32.141): 2 Time(s)
unknown (209.141.44.165): 2 Time(s)
unknown (5.181.80.180): 2 Time(s)
unknown (93-43-223-61.ip94.fastwebnet.it): 2 Time(s)
unknown (ip5f5a3cd1.dynamic.kabel-deutschland.de): 2 Time(s)
unknown (smtp17.mib360realestate.com): 2 Time(s)
postgres (69.49.228.198): 1 Time(s)
root (129.146.188.246): 1 Time(s)
root (152.136.18.77): 1 Time(s)
root (185.235.146.29): 1 Time(s)
root (212.192.241.124): 1 Time(s)
root (h-37-123-163-58.a785.priv.bahnhof.se): 1 Time(s)
unknown (112.194.208.93): 1 Time(s)
unknown (141.98.10.92): 1 Time(s)
unknown (209.141.62.233): 1 Time(s)
unknown (220.241.80.114): 1 Time(s)
unknown (41.137.137.92): 1 Time(s)
Invalid Users:
Unknown Account: 211 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
51 Miscellaneous warnings
9.230K Bytes accepted 9,452
9.230K Bytes sent via SMTP 9,452
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
2 4xx Reject relay denied 66.67%
1 4xx Reject VRFY 33.33%
-------- --------------------------------------------------
3 Total 4xx Rejects 100.00%
======== ==================================================
369 Connections
72 Connections lost (inbound)
369 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
root : 1 Time(s)
Failed logins from:
5.181.80.180 (ip-80-180-bullethost.net): 23 times
37.123.163.58 (h-37-123-163-58.A785.priv.bahnhof.se): 1 time
40.115.79.44: 20 times
42.248.78.142: 23 times
43.129.93.101: 18 times
61.148.90.118: 26 times
69.49.228.198 (69-49-228-198.unifiedlayer.com): 23 times
93.47.3.47 (93-47-3-47.ip110.fastwebnet.it): 46 times
112.194.208.93: 4 times
120.92.34.203: 2 times
123.231.90.100: 8 times
129.146.188.246: 1 time
152.136.18.77: 1 time
167.172.207.139: 10 times
175.11.202.102: 6 times
185.235.146.29: 1 time
204.191.196.151 (d204-191-196-151.abhsia.telus.net): 6 times
209.91.178.224 (pppoe-static-209-91-178-224.vianet.ca): 35 times
212.192.241.124: 1 time
222.90.82.234: 15 times
Illegal users from:
2001:470:1:332::7: 1 time
undef: 127 times
2.56.59.198: 3 times
5.181.80.180 (ip-80-180-bullethost.net): 2 times
40.115.79.44: 14 times
41.137.137.92: 1 time
42.248.78.142: 6 times
43.129.93.101: 7 times
45.144.225.69: 5 times
61.148.90.118: 12 times
69.49.228.198 (69-49-228-198.unifiedlayer.com): 10 times
93.43.223.61 (93-43-223-61.ip94.fastwebnet.it): 2 times
93.47.3.47 (93-47-3-47.ip110.fastwebnet.it): 23 times
95.90.60.209 (ip5f5a3cd1.dynamic.kabel-deutschland.de): 2 times
107.189.30.134 (smtp4.achtungumbedingt.de): 3 times
112.194.208.93: 1 time
120.92.34.203: 19 times
123.231.90.100: 5 times
141.98.10.92: 1 time
167.172.207.139: 20 times
176.111.173.237: 9 times
188.164.175.126: 4 times
195.133.18.24 (slot0.epaperitaliait.com): 9 times
195.133.18.210: 2 times
199.19.225.172: 2 times
205.185.114.87: 3 times
205.185.115.39 (mx.learnmorefun.org): 2 times
205.185.119.40 (smtp17.mib360realestate.com): 2 times
205.185.119.112: 3 times
209.91.178.224 (pppoe-static-209-91-178-224.vianet.ca): 15 times
209.141.32.141 (smtp9.dfsfasfasf.xyz): 2 times
209.141.33.193 (mx.chinadomainregistry.org): 3 times
209.141.44.165: 2 times
209.141.62.185: 3 times
209.141.62.233 (hhb8.cn): 1 time
212.192.241.124: 4 times
220.241.80.114 (mx2.hkucs.org): 1 time
222.90.82.234: 8 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
3 Jahre, 11 Monate
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Tue Nov 16 04:42:04 2021
Date Range Processed: yesterday
( 2021-Nov-15 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 53:53 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
222.186.19.235 -> zapf.wiki:443: 1 Time(s)
A total of 5 sites probed the server
178.239.21.102
212.193.30.245
222.186.19.235
45.146.164.160
45.86.74.235
Requests with error response codes
400 Bad Request
null: 3 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 2 Time(s)
/.env: 1 Time(s)
/manager/html: 1 Time(s)
HTTP/1.0: 1 Time(s)
\x1D3QA\x8C\x18\xB21\xF47)\xC3\xF3J\xC3\xB ... x09\xC0\x14\xC0: 1 Time(s)
zapf.wiki:443: 1 Time(s)
500 Internal Server Error
/: 42 Time(s)
/robots.txt: 4 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/favicon.ico: 2 Time(s)
/tmui/login.jsp/..;/tmui/locallb/workspace ... ame=/etc/passwd: 2 Time(s)
/.env: 1 Time(s)
/.well-known/security.txt: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/actuator/health: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/autodiscover/autodiscover.json?(a)evil.corp ... on%3F(a)evil.corp: 1 Time(s)
/bag2: 1 Time(s)
/mgmt/tm/util/bash: 1 Time(s)
/owa/auth/logon.aspx: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/wp-content/plugins/wp-file-manager/readme.txt: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (81.68.84.91): 38 Time(s)
root (134.209.241.15): 33 Time(s)
root (113.57.109.73): 30 Time(s)
unknown (net-2-45-185-2.cust.vodafonedsl.it): 30 Time(s)
unknown (121.5.107.215): 29 Time(s)
root (101.69.200.162): 27 Time(s)
root (59.29.227.55): 23 Time(s)
root (81.70.160.99): 21 Time(s)
root (117.50.119.185): 20 Time(s)
root (165.227.196.43): 20 Time(s)
unknown (113.57.109.73): 18 Time(s)
unknown (134.209.241.15): 17 Time(s)
root (143.244.136.52): 16 Time(s)
root (49.233.203.30): 16 Time(s)
root (178.62.78.193): 14 Time(s)
root (90.189.182.30): 13 Time(s)
unknown (81.68.84.91): 11 Time(s)
unknown (143.244.136.52): 9 Time(s)
unknown (101.69.200.162): 8 Time(s)
unknown (178.62.78.193): 8 Time(s)
unknown (81.70.160.99): 8 Time(s)
unknown (90.189.182.30): 8 Time(s)
root (176.111.173.237): 7 Time(s)
unknown (49.233.203.30): 7 Time(s)
unknown (59.29.227.55): 7 Time(s)
unknown (117.50.119.185): 6 Time(s)
unknown (165.227.196.43): 6 Time(s)
unknown (smtp4.achtungumbedingt.de): 6 Time(s)
unknown (141.98.10.142): 4 Time(s)
unknown (slot0.epaperitaliait.com): 4 Time(s)
root (121.5.107.215): 3 Time(s)
unknown (199.19.225.172): 3 Time(s)
unknown (209.141.32.141): 3 Time(s)
unknown (209.141.33.193): 3 Time(s)
unknown (smtp17.mib360realestate.com): 3 Time(s)
root (net-2-45-185-2.cust.vodafonedsl.it): 2 Time(s)
unknown (205.185.114.87): 2 Time(s)
unknown (205.185.119.112): 2 Time(s)
unknown (host-94-109-136-83.retail.pianetafibra.it): 2 Time(s)
unknown (i59f4cc80.versanet.de): 2 Time(s)
unknown (ip-176-198-213-74.hsi05.unitymediagroup.de): 2 Time(s)
root (211.220.27.191): 1 Time(s)
root (38.130.243.175): 1 Time(s)
root (jpn2-exit.privateinternetaccess.com): 1 Time(s)
unknown (141.98.10.63): 1 Time(s)
unknown (186.179.100.86): 1 Time(s)
unknown (205.185.115.39): 1 Time(s)
unknown (209.141.43.8): 1 Time(s)
unknown (211.45.247.122): 1 Time(s)
unknown (61.148.90.118): 1 Time(s)
unknown (adsl-186-159-1-121.edatel.net.co): 1 Time(s)
unknown (torexit.orwell.syndicateguys.com): 1 Time(s)
Invalid Users:
Unknown Account: 216 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
51 Miscellaneous warnings
12.744K Bytes accepted 13,050
12.744K Bytes sent via SMTP 13,050
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
354 Connections
53 Connections lost (inbound)
354 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
2.45.185.2 (net-2-45-185-2.cust.vodafonedsl.it): 2 times
38.130.243.175: 1 time
49.233.203.30: 16 times
59.29.227.55: 23 times
81.68.84.91: 38 times
81.70.160.99: 21 times
90.189.182.30 (b-internet.90.189.182.30.snt.ru): 13 times
101.69.200.162: 27 times
113.57.109.73: 30 times
117.50.119.185: 20 times
121.5.107.215: 3 times
134.209.241.15: 33 times
143.244.136.52: 16 times
156.146.34.193 (jpn2-exit.privateinternetaccess.com): 1 time
165.227.196.43: 20 times
176.111.173.237: 7 times
178.62.78.193: 14 times
211.220.27.191: 1 time
Illegal users from:
undef: 146 times
2.45.185.2 (net-2-45-185-2.cust.vodafonedsl.it): 30 times
49.233.203.30: 7 times
59.29.227.55: 7 times
61.148.90.118: 1 time
65.49.20.67 (scan-18.shadowserver.org): 1 time
81.68.84.91: 11 times
81.70.160.99: 8 times
83.136.109.94 (host-94-109-136-83.retail.pianetafibra.it): 2 times
89.244.204.128 (i59F4CC80.versanet.de): 2 times
90.189.182.30 (b-internet.90.189.182.30.snt.ru): 8 times
101.69.200.162: 8 times
107.189.30.134 (smtp4.achtungumbedingt.de): 6 times
113.57.109.73: 18 times
117.50.119.185: 6 times
121.5.107.215: 29 times
134.209.241.15: 17 times
141.98.10.63: 1 time
141.98.10.142 (rectum-bounders.oinkhow.net): 4 times
143.244.136.52: 9 times
165.227.196.43: 6 times
176.198.213.74 (ip-176-198-213-74.hsi05.unitymediagroup.de): 2 times
178.62.78.193: 8 times
185.112.146.73 (torexit.orwell.syndicateguys.com): 1 time
186.159.1.121 (adsl-186-159-1-121.edatel.net.co): 1 time
186.179.100.86 (azteca-comunicaciones.com): 1 time
195.133.18.24 (slot0.epaperitaliait.com): 4 times
199.19.225.172: 3 times
205.185.114.87: 2 times
205.185.115.39 (mx.learnmorefun.org): 1 time
205.185.119.40 (smtp17.mib360realestate.com): 3 times
205.185.119.112: 2 times
209.141.32.141 (smtp9.dfsfasfasf.xyz): 3 times
209.141.33.193 (mx.chinadomainregistry.org): 3 times
209.141.43.8 (mx09.hcx8.top): 1 time
211.45.247.122: 1 time
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
3 Jahre, 11 Monate
Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Mon Nov 15 04:42:04 2021
Date Range Processed: yesterday
( 2021-Nov-14 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 44:44 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
222.186.19.235 -> zapf.wiki:443: 2 Time(s)
45.81.234.73 -> 84.153.66.200:4444: 1 Time(s)
A total of 11 sites probed the server
161.35.230.3
167.71.102.181
185.254.31.134
188.166.151.235
188.166.235.173
195.133.18.100
198.20.69.98
20.83.148.119
209.141.53.177
222.186.19.235
64.227.97.195
Requests with error response codes
400 Bad Request
null: 18 Time(s)
/: 2 Time(s)
/w00tw00t.at.ISC.SANS.DFind:): 2 Time(s)
zapf.wiki:443: 2 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/ ... 2e%2e/etc/hosts: 1 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh: 1 Time(s)
/login: 1 Time(s)
/manager/text/list: 1 Time(s)
/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/: 1 Time(s)
84.153.66.200:4444: 1 Time(s)
K\xC1k\x9F\xC1\x9D\x0C\xCF\xC9\xD7\xA8\xBA ... C0$\xC0\x14\xC0: 1 Time(s)
\x04B!^\x85\xC2x\x98H\xFEG\xCF\xE6\x0B\xEE ... x09\xC0\x14\xC0: 1 Time(s)
mstshash=Administr: 1 Time(s)
404 Not Found
//2018/wp-includes/wlwmanifest.xml: 1 Time(s)
//2019/wp-includes/wlwmanifest.xml: 1 Time(s)
//blog/wp-includes/wlwmanifest.xml: 1 Time(s)
//cms/wp-includes/wlwmanifest.xml: 1 Time(s)
//media/wp-includes/wlwmanifest.xml: 1 Time(s)
//news/wp-includes/wlwmanifest.xml: 1 Time(s)
//shop/wp-includes/wlwmanifest.xml: 1 Time(s)
//site/wp-includes/wlwmanifest.xml: 1 Time(s)
//sito/wp-includes/wlwmanifest.xml: 1 Time(s)
//test/wp-includes/wlwmanifest.xml: 1 Time(s)
//web/wp-includes/wlwmanifest.xml: 1 Time(s)
//website/wp-includes/wlwmanifest.xml: 1 Time(s)
//wordpress/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp-includes/wlwmanifest.xml: 1 Time(s)
//wp/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp1/wp-includes/wlwmanifest.xml: 1 Time(s)
//wp2/wp-includes/wlwmanifest.xml: 1 Time(s)
//xmlrpc.php?rsd: 1 Time(s)
500 Internal Server Error
/: 65 Time(s)
/.env: 3 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 2 Time(s)
/favicon.ico: 2 Time(s)
/.DS_Store: 1 Time(s)
/.git/config: 1 Time(s)
/.json: 1 Time(s)
/HNAP1: 1 Time(s)
/actuator/health: 1 Time(s)
/api/search?folderIds=0: 1 Time(s)
/config.json: 1 Time(s)
/debug/default/view?panel=config: 1 Time(s)
/evox/about: 1 Time(s)
/frontend_dev.php/$: 1 Time(s)
/idx_config/: 1 Time(s)
/info.php: 1 Time(s)
/login.action: 1 Time(s)
/nmaplowercheck1636865864: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/s/lkx/_/;/META-INF/maven/com.atlassian.ji ... /pom.properties: 1 Time(s)
/sdk: 1 Time(s)
/server-status: 1 Time(s)
/telescope/requests: 1 Time(s)
/v2/_catalog: 1 Time(s)
502 Bad Gateway
/HZorDIqkSuaId6RfPo7k1w/pdf: 1 Time(s)
/build/constant.js: 1 Time(s)
/build/emojify.js/dist/css/basic/emojify.min.css: 1 Time(s)
/js/mathjax-config-extra.js: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGo-D: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGokb: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGpDv: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGpTX: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGpj9: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGpyp: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGqCR: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGqS5: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGqhj: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGqxM: 1 Time(s)
/socket.io/?noteId=HZorDIqkSuaId6RfPo7k1w& ... lling&t=NqUGrB0: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (5.181.80.180): 39 Time(s)
root (103.219.112.1): 35 Time(s)
root (210-71-232-236.hinet-ip.hinet.net): 27 Time(s)
root (90.189.182.30): 23 Time(s)
root (116.117.157.69): 20 Time(s)
unknown (210-71-232-236.hinet-ip.hinet.net): 19 Time(s)
root (138.197.203.168): 18 Time(s)
root (176.111.173.237): 16 Time(s)
root (175.209.89.234): 15 Time(s)
unknown (103.219.112.1): 15 Time(s)
unknown (128.199.247.40): 15 Time(s)
root (81.70.160.99): 14 Time(s)
root (106.12.140.168): 13 Time(s)
root (mail.wooree42.com): 13 Time(s)
unknown (mail.wooree42.com): 10 Time(s)
unknown (106.12.140.168): 9 Time(s)
unknown (138.197.203.168): 9 Time(s)
unknown (175.209.89.234): 8 Time(s)
unknown (209.141.43.8): 8 Time(s)
root (101.69.200.162): 7 Time(s)
root (159.223.16.53): 7 Time(s)
unknown (101.69.200.162): 7 Time(s)
unknown (106.12.179.113): 7 Time(s)
unknown (116.117.157.69): 7 Time(s)
unknown (209.141.62.233): 7 Time(s)
unknown (81.70.160.99): 7 Time(s)
root (106.12.179.113): 6 Time(s)
unknown (195.133.18.210): 6 Time(s)
unknown (209.141.33.193): 6 Time(s)
unknown (90.189.182.30): 6 Time(s)
root (128.199.247.40): 5 Time(s)
root (123.9.235.229): 4 Time(s)
root (124-145-74-224.rev.home.ne.jp): 4 Time(s)
root (166.90.116.107): 4 Time(s)
unknown (199.19.224.157): 4 Time(s)
unknown (141.98.10.63): 3 Time(s)
unknown (171.227.203.183): 3 Time(s)
unknown (205.185.120.71): 3 Time(s)
unknown (38.143.137.90): 3 Time(s)
unknown (5.181.80.180): 3 Time(s)
unknown (116.110.213.215): 2 Time(s)
unknown (116.121.174.213): 2 Time(s)
unknown (136.144.41.68): 2 Time(s)
unknown (136.37.6.214): 2 Time(s)
unknown (141.98.10.142): 2 Time(s)
unknown (82.66.59.170): 2 Time(s)
root (117.7.122.163): 1 Time(s)
root (175.186.0.161): 1 Time(s)
root (23.247.33.61): 1 Time(s)
root (36.133.45.135): 1 Time(s)
unknown (103.254.198.67): 1 Time(s)
unknown (116.110.121.105): 1 Time(s)
unknown (117.7.122.163): 1 Time(s)
unknown (123.9.235.229): 1 Time(s)
unknown (124-145-74-224.rev.home.ne.jp): 1 Time(s)
unknown (136.144.41.36): 1 Time(s)
unknown (166.90.116.107): 1 Time(s)
unknown (177.53.70.205): 1 Time(s)
unknown (186.179.100.61): 1 Time(s)
unknown (199.19.225.172): 1 Time(s)
unknown (smtp17.mib360realestate.com): 1 Time(s)
Invalid Users:
Unknown Account: 188 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
39 Miscellaneous warnings
10.949K Bytes accepted 11,212
10.949K Bytes sent via SMTP 11,212
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
4 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
4 Total 4xx Rejects 100.00%
======== ==================================================
233 Connections
52 Connections lost (inbound)
233 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Illegal address syntax in SMTP command
2 SMTP dialog errors
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
5.181.80.180 (ip-80-180-bullethost.net): 39 times
23.247.33.61: 1 time
36.133.45.135: 1 time
81.70.160.99: 14 times
90.189.182.30 (b-internet.90.189.182.30.snt.ru): 23 times
101.69.200.162: 7 times
103.219.112.1: 35 times
106.12.140.168: 13 times
106.12.179.113: 6 times
116.117.157.69: 20 times
117.7.122.163 (localhost): 1 time
123.9.235.229 (hn.kd.ny.adsl): 4 times
124.145.74.224 (124-145-74-224.rev.home.ne.jp): 4 times
128.199.247.40: 5 times
138.197.203.168: 18 times
159.223.16.53: 7 times
166.90.116.107 (unknown.Level3.net): 4 times
175.186.0.161: 1 time
175.209.89.234: 15 times
176.111.173.237: 16 times
210.71.232.236 (210-71-232-236.hinet-ip.hinet.net): 27 times
211.238.111.61 (mail.wooree42.com): 13 times
Illegal users from:
2001:470:1:332::5: 1 time
undef: 106 times
5.181.80.180 (ip-80-180-bullethost.net): 3 times
38.143.137.90: 3 times
81.70.160.99: 7 times
82.66.59.170 (mar92-2_migr-82-66-59-170.fbx.proxad.net): 2 times
90.189.182.30 (b-internet.90.189.182.30.snt.ru): 6 times
101.69.200.162: 7 times
103.219.112.1: 15 times
103.254.198.67: 1 time
106.12.140.168: 9 times
106.12.179.113: 7 times
116.110.121.105: 1 time
116.110.213.215: 2 times
116.117.157.69: 7 times
116.121.174.213: 2 times
117.7.122.163 (localhost): 1 time
123.9.235.229 (hn.kd.ny.adsl): 1 time
124.145.74.224 (124-145-74-224.rev.home.ne.jp): 1 time
128.199.247.40: 15 times
136.37.6.214 (136-37-6-214.googlefiber.net): 2 times
136.144.41.36: 1 time
136.144.41.68: 2 times
138.197.203.168: 9 times
141.98.10.63: 3 times
141.98.10.142 (rectum-bounders.oinkhow.net): 2 times
166.90.116.107 (unknown.Level3.net): 1 time
171.227.203.183 (dynamic-ip-adsl.viettel.vn): 3 times
175.209.89.234: 8 times
177.53.70.205: 1 time
186.179.100.61 (azteca-comunicaciones.com): 1 time
195.133.18.210: 6 times
199.19.224.157: 4 times
199.19.225.172: 1 time
205.185.119.40 (smtp17.mib360realestate.com): 1 time
205.185.120.71: 3 times
209.141.33.193 (mx.chinadomainregistry.org): 6 times
209.141.43.8 (mx09.hcx8.top): 8 times
209.141.62.233 (hhb8.cn): 7 times
210.71.232.236 (210-71-232-236.hinet-ip.hinet.net): 19 times
211.238.111.61 (mail.wooree42.com): 10 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from zigzag@uni-goettingen.de requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: zigzag(a)uni-goettingen.de
Subject: Initiativantrag an das Plenum
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from t.brackertz@gmx.net requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: t.brackertz(a)gmx.net
Subject: Re: Fwd: Unterst?tzung B?ndnis Vers Gesetz NRW stoppen
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from t.brackertz@gmx.net requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: t.brackertz(a)gmx.net
Subject: Re: Fwd: Unterst?tzung B?ndnis Vers Gesetz NRW stoppen
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from bgreven@smail.uni-koeln.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: bgreven(a)smail.uni-koeln.de
Subject: Fwd: Unterst?tzung B?ndnis Vers Gesetz NRW stoppen
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate