Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sun Nov 14 04:42:04 2021
Date Range Processed: yesterday
( 2021-Nov-13 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 64:64 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 7 sites probed the server
178.239.21.162
198.98.56.220
34.96.130.11
36.100.141.196
45.61.184.37
66.240.192.138
66.240.205.34
Requests with error response codes
400 Bad Request
null: 12 Time(s)
mstshash=Administr: 4 Time(s)
/: 1 Time(s)
/.env: 1 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
500 Internal Server Error
/: 53 Time(s)
/robots.txt: 4 Time(s)
/.env: 2 Time(s)
///remote/fgt_lang?lang=/../../../..//////////dev/: 2 Time(s)
/favicon.ico: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
/.well-known/security.txt: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/admin: 1 Time(s)
/api/jsonws/invoke: 1 Time(s)
/console/: 1 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 1 Time(s)
/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f: 1 Time(s)
/sitemap.xml: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (8.225.226.100): 78 Time(s)
root (117.247.176.211): 39 Time(s)
root (93-47-3-47.ip110.fastwebnet.it): 36 Time(s)
root (111.44.140.229): 32 Time(s)
root (134.209.236.191): 31 Time(s)
root (49.232.221.113): 31 Time(s)
root (37.61.176.231): 28 Time(s)
unknown (176.111.173.237): 24 Time(s)
root (156.241.132.29): 22 Time(s)
root (181.23.75.134): 20 Time(s)
unknown (111.44.140.229): 18 Time(s)
unknown (209.141.49.147): 18 Time(s)
root (103.167.53.253): 16 Time(s)
root (106.13.74.61): 16 Time(s)
unknown (134.209.236.191): 16 Time(s)
unknown (37.61.176.231): 16 Time(s)
unknown (111.125.70.22): 14 Time(s)
unknown (49.232.221.113): 13 Time(s)
root (125.18.107.242): 12 Time(s)
unknown (125.18.107.242): 12 Time(s)
unknown (209.141.62.185): 12 Time(s)
unknown (117.247.176.211): 11 Time(s)
root (111.125.70.22): 9 Time(s)
unknown (103.167.53.253): 9 Time(s)
root (158.101.157.248): 8 Time(s)
root (5.181.80.180): 8 Time(s)
unknown (156.241.132.29): 7 Time(s)
unknown (205.185.119.112): 7 Time(s)
unknown (93-47-3-47.ip110.fastwebnet.it): 7 Time(s)
root (120.78.0.229): 6 Time(s)
root (36.110.228.254): 6 Time(s)
unknown (106.13.74.61): 6 Time(s)
unknown (136.144.41.36): 5 Time(s)
unknown (45.135.232.159): 5 Time(s)
root (179.147.84.188): 4 Time(s)
unknown (181.23.75.134): 4 Time(s)
unknown (195.133.18.210): 4 Time(s)
unknown (2.56.59.39): 4 Time(s)
unknown (smtp17.mib360realestate.com): 4 Time(s)
root (176.111.173.237): 3 Time(s)
unknown (117.7.122.163): 3 Time(s)
unknown (158.101.157.248): 3 Time(s)
unknown (195.54.166.135): 3 Time(s)
unknown (205.185.114.87): 3 Time(s)
unknown (31.184.198.71): 3 Time(s)
unknown (38.143.137.90): 3 Time(s)
unknown (45.155.204.39): 3 Time(s)
unknown (8.225.226.100): 3 Time(s)
unknown (smtp4.achtungumbedingt.de): 3 Time(s)
root (38.143.137.90): 2 Time(s)
unknown (116.110.209.193): 2 Time(s)
unknown (141.98.10.142): 2 Time(s)
unknown (189.174.48.108): 2 Time(s)
unknown (199.19.224.157): 2 Time(s)
unknown (199.19.225.172): 2 Time(s)
unknown (37.0.10.28): 2 Time(s)
unknown (88.162.54.93): 2 Time(s)
unknown (90.74.133.157): 2 Time(s)
unknown (cpe-76-177-197-140.natcky.res.rr.com): 2 Time(s)
unknown (slot0.epaperitaliait.com): 2 Time(s)
irc (156.241.132.29): 1 Time(s)
mysql (176.111.173.237): 1 Time(s)
postgres (176.111.173.237): 1 Time(s)
root (103.133.57.250): 1 Time(s)
root (116.110.209.193): 1 Time(s)
root (36.80.48.9): 1 Time(s)
root (onion.xor.sc): 1 Time(s)
unknown (116.110.14.239): 1 Time(s)
unknown (179.147.84.188): 1 Time(s)
unknown (185.31.175.231): 1 Time(s)
unknown (185.31.175.247): 1 Time(s)
unknown (187.32.84.234): 1 Time(s)
unknown (205.185.113.226): 1 Time(s)
unknown (209.141.43.8): 1 Time(s)
unknown (41.137.137.92): 1 Time(s)
Invalid Users:
Unknown Account: 271 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
48 Miscellaneous warnings
11.897K Bytes accepted 12,183
11.897K Bytes sent via SMTP 12,183
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
2 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
2 Total 4xx Rejects 100.00%
======== ==================================================
309 Connections
71 Connections lost (inbound)
309 Disconnections
1 Removed from queue
1 Sent via SMTP
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
Failed logins from:
5.181.80.180 (ip-80-180-bullethost.net): 8 times
8.225.226.100: 78 times
36.80.48.9: 1 time
36.110.228.254: 6 times
37.61.176.231 (37.61.176.231.svttk.ru): 28 times
38.143.137.90: 2 times
49.232.221.113: 31 times
93.47.3.47 (93-47-3-47.ip110.fastwebnet.it): 36 times
103.133.57.250: 1 time
103.167.53.253: 16 times
106.13.74.61: 16 times
111.44.140.229: 32 times
111.125.70.22: 9 times
116.110.209.193: 1 time
117.247.176.211: 39 times
120.78.0.229: 6 times
125.18.107.242: 12 times
134.209.236.191: 31 times
156.241.132.29: 23 times
158.101.157.248: 8 times
176.111.173.237: 5 times
179.147.84.188 (179-147-84-188.user.vivozap.com.br): 4 times
181.23.75.134 (181-23-75-134.speedy.com.ar): 20 times
185.56.80.65 (onion.xor.sc): 1 time
Illegal users from:
2001:470:1:c84::12: 1 time
undef: 158 times
2.56.59.39 (branewsinfos.ddns.net): 4 times
8.225.226.100: 3 times
31.184.198.71: 3 times
37.0.10.28 (aggiornamento.xyz): 2 times
37.61.176.231 (37.61.176.231.svttk.ru): 16 times
38.143.137.90: 3 times
41.137.137.92: 1 time
45.135.232.159: 5 times
45.155.204.39: 3 times
49.232.221.113: 13 times
65.49.20.66 (scan-17.shadowserver.org): 1 time
76.177.197.140 (cpe-76-177-197-140.natcky.res.rr.com): 2 times
82.156.167.244: 1 time
88.162.54.93 (chy02-2_migr-88-162-54-93.fbx.proxad.net): 2 times
90.74.133.157 (157.pool90-74-133.dynamic.orange.es): 2 times
93.47.3.47 (93-47-3-47.ip110.fastwebnet.it): 7 times
103.167.53.253: 9 times
106.13.74.61: 6 times
107.189.30.134 (smtp4.achtungumbedingt.de): 3 times
111.44.140.229: 18 times
111.125.70.22: 14 times
116.110.14.239: 1 time
116.110.209.193: 2 times
117.7.122.163 (localhost): 3 times
117.247.176.211: 11 times
125.18.107.242: 12 times
134.209.236.191: 16 times
136.144.41.36: 5 times
141.98.10.142 (rectum-bounders.oinkhow.net): 2 times
156.241.132.29: 7 times
158.101.157.248: 3 times
176.111.173.237: 24 times
179.147.84.188 (179-147-84-188.user.vivozap.com.br): 1 time
181.23.75.134 (181-23-75-134.speedy.com.ar): 4 times
185.31.175.231: 1 time
185.31.175.247: 1 time
187.32.84.234 (187-032-084-234.static.ctbctelecom.com.br): 1 time
189.174.48.108 (dsl-189-174-48-108-dyn.prod-infinitum.com.mx): 2 times
195.54.166.135: 3 times
195.133.18.24 (slot0.epaperitaliait.com): 2 times
195.133.18.210: 4 times
199.19.224.157: 2 times
199.19.225.172: 2 times
205.185.113.226 (admin.applr.top): 1 time
205.185.114.87: 3 times
205.185.119.40 (smtp17.mib360realestate.com): 4 times
205.185.119.112: 7 times
209.141.43.8 (mx09.hcx8.top): 1 time
209.141.49.147: 18 times
209.141.62.185: 12 times
**Unmatched Entries**
Disconnecting: Change of username or service not allowed: (0,ssh-connection) -> (!root,ssh-connection) [preauth] : 1 time(s)
Disconnecting: Change of username or service not allowed: (admin,ssh-connection) -> (0,ssh-connection) [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop33257p1 394G 242G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from bgreven@smail.uni-koeln.de requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: bgreven(a)smail.uni-koeln.de
Subject: Fwd: Reso Versammlungsgesetz
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from bgreven@smail.uni-koeln.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: bgreven(a)smail.uni-koeln.de
Subject: Unterst?tzung B?ndnis Vers Gesetz NRW stoppen
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from andreas.drotloff@stud-mail.uni-wuerzburg.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: andreas.drotloff(a)stud-mail.uni-wuerzburg.de
Subject: Fwd: [Winter21-teilnehmika] Aktualisierte Fassung MRVO-Antrag f?r die Postersession
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from zigzag@uni-goettingen.de requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: zigzag(a)uni-goettingen.de
Subject: Antrag an das Plenum
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from zigzag@uni-goettingen.de requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: zigzag(a)uni-goettingen.de
Subject: Resolution zur Schaffung von Anrechnungsm?glichkeiten f?r b?rgerschaftliches Engagement
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from bgreven@smail.uni-koeln.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: bgreven(a)smail.uni-koeln.de
Subject: Reso Versammlungsgesetz
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from soenbeier@uni-potsdam.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: soenbeier(a)uni-potsdam.de
Subject: Resolution zur Schaffung von Anrechnungsm?glichkeiten f?r b?rgerschaftliches Engagement
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
winter21-teilnehmika@zapf.in post from andreas.drotloff@stud-mail.uni-wuerzburg.de requires approval
by winter21-teilnehmika-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: winter21-teilnehmika(a)zapf.in
From: andreas.drotloff(a)stud-mail.uni-wuerzburg.de
Subject: Aktualisierte Fassung MRVO-Antrag f?r die Postersession
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate
reso@zapf.in post from haendscr@physik.hu-berlin.de requires approval
by reso-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: reso(a)zapf.in
From: haendscr(a)physik.hu-berlin.de
Subject: Handreichung Vertrauenspersonen f?r die Postersession
The message is being held because:
The message is larger than the 40 KB maximum size
At your convenience, visit your dashboard to approve or deny the
request.
3 Jahre, 11 Monate