################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Wed Jan 3 04:42:03 2024
Date Range Processed: yesterday
( 2024-Jan-02 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host:
h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [222:222]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 9 sites probed the server
107.170.240.25
157.230.8.75
161.35.238.241
162.243.135.40
162.243.147.5
31.220.88.155
66.240.205.34
78.153.140.221
89.190.156.10
Requests with error response codes
400 Bad Request
null: 8 Time(s)
*: 3 Time(s)
mstshash=Administr: 3 Time(s)
../../proc/: 2 Time(s)
/: 2 Time(s)
/admin/config.php: 1 Time(s)
/manager/text/list: 1 Time(s)
/query?q=SHOW+DIAGNOSTICS: 1 Time(s)
/solr/admin/cores?action=STATUS&wt=json: 1 Time(s)
/solr/admin/info/system: 1 Time(s)
/v2/_catalog: 1 Time(s)
I\x1E4\xD4\x065&\x1F\xE2\xE7\xED\xE8\x13\x ... x09\xC0\x14\xC0: 1 Time(s)
\x0C<\xEA\xE6F\xAE\xBC\xF4+\xBB\xAC\xAE\x0 ... 00l\x00\xBF\xC0: 1 Time(s)
\x9A\x9C\xCF:\xA1\x9D\x9E\x13w\xED\x80\x98 ... C0$\xC0\x14\xC0: 1 Time(s)
\xBF\xAF\xF7\x99=\xDE\xDC5\x08\xE8'P\xF4^\ ... x09\xC0\x13\xC0: 1 Time(s)
404 Not Found
//cdnjs.cloudflare.com/ajax/libs/es5-shim/ ... es5-shim.min.js: 1 Time(s)
//cdnjs.cloudflare.com/ajax/libs/html5shiv ... tml5shiv.min.js: 1 Time(s)
//cdnjs.cloudflare.com/ajax/libs/respond.j ... /respond.min.js: 1 Time(s)
//protokolle.zapf.in/build/8.common.fef3ca2736298be630a4.js: 1 Time(s)
//protokolle.zapf.in/build/constant.js: 1 Time(s)
500 Internal Server Error
/: 29 Time(s)
/favicon.ico: 2 Time(s)
/robots.txt: 2 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 2 Time(s)
/.git/config: 1 Time(s)
/?XDEBUG_SESSION_START=phpstorm: 1 Time(s)
/Autodiscover/Autodiscover.xml: 1 Time(s)
/HNAP1: 1 Time(s)
/Public/home/js/check.js: 1 Time(s)
/_ignition/execute-solution: 1 Time(s)
/ab2g: 1 Time(s)
/ab2h: 1 Time(s)
/actuator/gateway/routes: 1 Time(s)
/admin/.git/config: 1 Time(s)
/alive.php: 1 Time(s)
/api/.git/config: 1 Time(s)
/app/.git/config: 1 Time(s)
/assets/.git/config: 1 Time(s)
/autodiscover/autodiscover.json?@zdi/Powershell: 1 Time(s)
/console/: 1 Time(s)
/evox/about: 1 Time(s)
/geoserver: 1 Time(s)
/includes/.git/config: 1 Time(s)
/nmaplowercheck1704227990: 1 Time(s)
/node_modules/.git/config: 1 Time(s)
/sdk: 1 Time(s)
/static/admin/javascript/hetong.js: 1 Time(s)
/t4: 1 Time(s)
/teorema505?t=1: 1 Time(s)
/version: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
unknown (89.190.156.41): 91 Time(s)
root (37.113.26.6): 30 Time(s)
root (89.190.156.41): 30 Time(s)
root (80.71.157.129): 25 Time(s)
root (181.115.145.34): 21 Time(s)
root (209.38.220.224): 21 Time(s)
root (43.156.42.38): 21 Time(s)
root (167.172.182.99): 20 Time(s)
root (182.253.47.126): 20 Time(s)
root (188.166.245.43): 20 Time(s)
root (159.223.45.100): 19 Time(s)
root (165.154.183.177): 19 Time(s)
root (182.18.161.165): 19 Time(s)
root (43.136.84.236): 19 Time(s)
root (101.32.141.93): 18 Time(s)
root (24.144.80.196): 18 Time(s)
root (43.153.18.40): 18 Time(s)
root (
static-47-180-212-134.lsan.ca.frontiernet.net): 18 Time(s)
root (119.28.111.112): 17 Time(s)
root (142.93.76.36): 17 Time(s)
root (150.109.93.69): 17 Time(s)
root (171.244.62.232): 17 Time(s)
root (190.52.39.248): 17 Time(s)
root (27.71.26.177): 17 Time(s)
root (103.140.194.87): 16 Time(s)
root (106.250.187.83): 16 Time(s)
root (110.45.145.182): 16 Time(s)
root (12.232.158.130): 16 Time(s)
root (131.14.174.178.static.wline.lns.sme.cust.swisscom.ch): 16 Time(s)
root (146.190.122.209): 16 Time(s)
root (197.5.145.68): 16 Time(s)
root (
211-21-113-128.hinet-ip.hinet.net): 16 Time(s)
root (27.254.235.2): 16 Time(s)
root (37.152.183.187): 16 Time(s)
root (43.163.217.125): 16 Time(s)
root (80.253.31.232): 16 Time(s)
root (91.220.109.149): 16 Time(s)
root (ip-037-024-043-066.um08.pools.vodafone-ip.de): 16 Time(s)
root (ip121.ip-51-89-162.eu): 16 Time(s)
root (124.222.102.83): 15 Time(s)
root (77.91.78.115): 15 Time(s)
root (103.212.34.105): 14 Time(s)
root (119.202.128.28): 14 Time(s)
root (150.109.204.150): 14 Time(s)
root (150.158.148.149): 14 Time(s)
root (175.203.23.6): 14 Time(s)
root (180.76.183.123): 14 Time(s)
root (183.83.222.24): 14 Time(s)
root (202.51.74.123): 14 Time(s)
root (27.254.151.32): 14 Time(s)
root (43.159.139.131): 14 Time(s)
root (59.98.83.57): 14 Time(s)
root (82.207.8.202): 14 Time(s)
root (103.170.86.86): 13 Time(s)
root (104.248.50.109): 13 Time(s)
root (112.133.247.44): 13 Time(s)
root (124.223.45.97): 13 Time(s)
root (154.221.25.18): 13 Time(s)
root (20.141.43.88): 13 Time(s)
root (201.149.49.146): 13 Time(s)
root (165.22.230.101): 12 Time(s)
root (43.159.135.77): 12 Time(s)
root (80.66.75.106): 12 Time(s)
root (
mail.synhsgroup.com): 12 Time(s)
root (207.154.245.38): 11 Time(s)
root (213.74.115.162): 11 Time(s)
root (43.134.136.188): 11 Time(s)
root (43.154.211.73): 11 Time(s)
root (43.156.149.50): 11 Time(s)
root (
61-222-211-114.hinet-ip.hinet.net): 11 Time(s)
root (v150-95-64-112.a009.g.bkk2.static.cnode.io): 11 Time(s)
root (111.47.15.165): 10 Time(s)
root (113.31.104.225): 10 Time(s)
root (209.38.248.13): 10 Time(s)
root (79.175.189.19): 10 Time(s)
root (111.229.98.54): 9 Time(s)
root (137.184.118.88): 9 Time(s)
root (206.189.59.169): 9 Time(s)
unknown (143.110.245.172): 9 Time(s)
unknown (210.114.22.126): 9 Time(s)
root (117.50.162.133): 8 Time(s)
root (117.50.210.148): 8 Time(s)
root (139.150.69.244): 8 Time(s)
root (110.182.85.114): 6 Time(s)
root (164.92.100.116): 6 Time(s)
root (164.92.180.158): 6 Time(s)
root (165.227.162.21): 6 Time(s)
root (175.31.224.14): 6 Time(s)
root (218.201.57.130): 6 Time(s)
root (42.159.80.91): 6 Time(s)
root (82.246.56.190.static.intelnet.net.gt): 6 Time(s)
root (112.186.166.148): 5 Time(s)
root (182.72.56.30): 5 Time(s)
root (210.114.22.126): 5 Time(s)
unknown (175.206.96.66): 5 Time(s)
unknown (182.253.47.126): 5 Time(s)
unknown (121.178.230.152): 4 Time(s)
unknown (197.5.145.68): 4 Time(s)
unknown (20.141.43.88): 4 Time(s)
unknown (43.163.217.125): 4 Time(s)
unknown (79.175.189.19): 4 Time(s)
postgres (89.190.156.41): 3 Time(s)
unknown (142.93.76.36): 3 Time(s)
unknown (165.22.230.101): 3 Time(s)
unknown (171.244.62.232): 3 Time(s)
unknown (175.203.23.6): 3 Time(s)
unknown (190.52.39.248): 3 Time(s)
unknown (201.149.49.146): 3 Time(s)
unknown (213.74.115.162): 3 Time(s)
unknown (37.113.26.6): 3 Time(s)
unknown (43.134.136.188): 3 Time(s)
unknown (43.159.135.77): 3 Time(s)
unknown (80.66.75.106): 3 Time(s)
unknown (
mail.synhsgroup.com): 3 Time(s)
unknown (v150-95-64-112.a009.g.bkk2.static.cnode.io): 3 Time(s)
mysql (143.110.245.172): 2 Time(s)
root (106.13.208.8): 2 Time(s)
root (143.110.245.172): 2 Time(s)
unknown (103.170.86.86): 2 Time(s)
unknown (104.248.50.109): 2 Time(s)
unknown (111.229.98.54): 2 Time(s)
unknown (119.202.128.28): 2 Time(s)
unknown (124.223.45.97): 2 Time(s)
unknown (131.14.174.178.static.wline.lns.sme.cust.swisscom.ch): 2 Time(s)
unknown (137.184.118.88): 2 Time(s)
unknown (139.150.69.244): 2 Time(s)
unknown (146.190.122.209): 2 Time(s)
unknown (150.109.204.150): 2 Time(s)
unknown (154.221.25.18): 2 Time(s)
unknown (164.92.180.158): 2 Time(s)
unknown (165.154.183.177): 2 Time(s)
unknown (167.172.182.99): 2 Time(s)
unknown (182.18.161.165): 2 Time(s)
unknown (183.83.222.24): 2 Time(s)
unknown (188.166.245.43): 2 Time(s)
unknown (202.51.74.123): 2 Time(s)
unknown (
211-21-113-128.hinet-ip.hinet.net): 2 Time(s)
unknown (24.144.80.196): 2 Time(s)
unknown (27.254.151.32): 2 Time(s)
unknown (43.153.18.40): 2 Time(s)
unknown (43.154.211.73): 2 Time(s)
unknown (43.159.139.131): 2 Time(s)
unknown (59.98.83.57): 2 Time(s)
unknown (77.91.78.115): 2 Time(s)
unknown (80.71.157.129): 2 Time(s)
unknown (82.207.8.202): 2 Time(s)
unknown (ip-037-024-043-066.um08.pools.vodafone-ip.de): 2 Time(s)
unknown (lfbn-orl-1-1610-168.w90-107.abo.wanadoo.fr): 2 Time(s)
unknown (
static-47-180-212-134.lsan.ca.frontiernet.net): 2 Time(s)
mysql (43.153.18.40): 1 Time(s)
mysql (ip-037-024-043-066.um08.pools.vodafone-ip.de): 1 Time(s)
postgres (119.28.111.112): 1 Time(s)
postgres (143.110.245.172): 1 Time(s)
postgres (154.221.25.18): 1 Time(s)
postgres (159.223.45.100): 1 Time(s)
postgres (181.115.145.34): 1 Time(s)
postgres (206.189.59.169): 1 Time(s)
postgres (43.153.18.40): 1 Time(s)
postgres (43.156.42.38): 1 Time(s)
postgres (
static-47-180-212-134.lsan.ca.frontiernet.net): 1 Time(s)
proxy (210.114.22.126): 1 Time(s)
root (223.197.175.91): 1 Time(s)
unknown (103.140.194.87): 1 Time(s)
unknown (106.13.208.8): 1 Time(s)
unknown (106.250.187.83): 1 Time(s)
unknown (110.45.145.182): 1 Time(s)
unknown (111.47.15.165): 1 Time(s)
unknown (112.133.247.44): 1 Time(s)
unknown (112.187.18.4): 1 Time(s)
unknown (113.31.104.225): 1 Time(s)
unknown (117.50.162.133): 1 Time(s)
unknown (12.232.158.130): 1 Time(s)
unknown (150.158.148.149): 1 Time(s)
unknown (159.223.45.100): 1 Time(s)
unknown (171.227.27.171): 1 Time(s)
unknown (180.76.183.123): 1 Time(s)
unknown (181.115.145.34): 1 Time(s)
unknown (182.72.56.30): 1 Time(s)
unknown (206.189.59.169): 1 Time(s)
unknown (207.154.245.38): 1 Time(s)
unknown (209.38.220.224): 1 Time(s)
unknown (209.38.248.13): 1 Time(s)
unknown (37.152.183.187): 1 Time(s)
unknown (42.159.80.91): 1 Time(s)
unknown (43.156.149.50): 1 Time(s)
unknown (
61-222-211-114.hinet-ip.hinet.net): 1 Time(s)
unknown (91.220.109.149): 1 Time(s)
unknown (ip121.ip-51-89-162.eu): 1 Time(s)
Invalid Users:
Unknown Account: 270 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
20 Connections
15 Connections lost (inbound)
20 Disconnections
---------------------- Postfix End -------------------------
--------------------- rsyslogd Begin ------------------------
**** Unmatched entries ****
[origin software="rsyslogd" swVersion="8.4.2"
x-pid="154" x-info="http://www.rsyslog.com"] exiting on signal 15. : 1
Times
---------------------- rsyslogd End -------------------------
--------------------- Connections (secure-log) Begin ------------------------
**Unmatched Entries**
systemd-logind: New seat seat0.: 1 Time(s)
---------------------- Connections (secure-log) End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin
------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End
-------------------------
--------------------- SSHD Begin ------------------------
SSHD Started: 2 Time(s)
Disconnecting after too many authentication failures for user:
invalid : 1 Time(s)
root : 3 Time(s)
Failed logins from:
12.232.158.130: 16 times
20.141.43.88: 13 times
24.144.80.196: 18 times
27.71.26.177: 17 times
27.254.151.32 (
27-254-151-32-static-idc-assigned.csloxinfo.com): 14 times
27.254.235.2: 16 times
37.24.43.66 (ip-037-024-043-066.um08.pools.vodafone-ip.de): 17 times
37.113.26.6: 30 times
37.152.183.187: 16 times
42.159.80.91: 6 times
43.134.136.188: 11 times
43.136.84.236: 19 times
43.153.18.40: 20 times
43.154.211.73: 11 times
43.156.42.38: 22 times
43.156.149.50: 11 times
43.159.135.77: 12 times
43.159.139.131: 14 times
43.163.217.125: 16 times
47.180.212.134 (
static-47-180-212-134.lsan.ca.frontiernet.net): 19 times
51.89.162.121 (ip121.ip-51-89-162.eu): 16 times
59.98.83.57: 14 times
61.222.211.114 (
61-222-211-114.hinet-ip.hinet.net): 11 times
77.91.78.115 (test.aeza.network): 15 times
79.175.189.19: 10 times
80.66.75.106: 12 times
80.71.157.129 (vm1964710.stark-industries.solutions): 25 times
80.253.31.232: 16 times
82.207.8.202 (
202-8-207-82.pool.ukrtel.net): 14 times
89.190.156.41 (smtp-10.goinbox.in): 33 times
91.220.109.149: 16 times
101.32.141.93: 18 times
103.140.194.87: 16 times
103.170.86.86: 13 times
103.212.34.105: 14 times
104.248.50.109: 13 times
106.13.208.8: 2 times
106.250.187.83: 16 times
110.45.145.182: 16 times
110.182.85.114: 6 times
111.47.15.165: 10 times
111.229.98.54: 9 times
112.133.247.44: 13 times
112.186.166.148: 6 times
112.199.113.42 (
mail.synhsgroup.com): 12 times
113.31.104.225: 10 times
117.50.162.133 (hangluckpaper.com.cn): 8 times
117.50.210.148: 8 times
119.28.111.112: 18 times
119.202.128.28: 14 times
124.222.102.83: 15 times
124.223.45.97: 13 times
137.184.118.88: 9 times
139.150.69.244: 8 times
142.93.76.36 (starwifi-11.28.2023-s-1vcpu-2gb-nyc3-01): 17 times
143.110.245.172: 5 times
146.190.122.209: 16 times
150.95.64.112 (v150-95-64-112.a009.g.bkk2.static.cnode.io): 11 times
150.109.93.69: 17 times
150.109.204.150: 14 times
150.158.148.149: 14 times
154.221.25.18: 14 times
159.223.45.100: 20 times
164.92.100.116: 6 times
164.92.180.158: 6 times
165.22.230.101: 12 times
165.154.183.177: 19 times
165.227.162.21: 6 times
167.172.182.99: 20 times
171.244.62.232: 17 times
175.31.224.14: 6 times
175.203.23.6: 14 times
178.174.14.131 (131.14.174.178.static.wline.lns.sme.cust.swisscom.ch): 16 times
180.76.183.123: 14 times
181.115.145.34: 22 times
182.18.161.165 (static-182-18-161-165.ctrls.in): 19 times
182.72.56.30 (nsg-static-030.56.72.182.airtel.in): 5 times
182.253.47.126: 20 times
183.83.222.24 (broadband.actcorp.in): 14 times
188.166.245.43: 20 times
190.52.39.248: 17 times
190.56.246.82 (82.246.56.190.static.intelnet.net.gt): 6 times
197.5.145.68: 16 times
201.149.49.146 (
cuallix.com): 13 times
202.51.74.123: 14 times
206.189.59.169: 10 times
207.154.245.38: 11 times
209.38.220.224: 21 times
209.38.248.13: 10 times
210.114.22.126: 6 times
211.21.113.128 (
211-21-113-128.hinet-ip.hinet.net): 16 times
213.74.115.162 (
host-213-74-115-162.superonline.net): 11 times
218.201.57.130: 6 times
223.197.175.91 (
223-197-175-91.static.imsbiz.com): 1 time
Illegal users from:
2001:470:1:332::9 (
scan-43af.shadowserver.org): 1 time
undef: 77 times
12.232.158.130: 1 time
20.141.43.88: 4 times
24.144.80.196: 2 times
27.254.151.32 (
27-254-151-32-static-idc-assigned.csloxinfo.com): 2 times
37.24.43.66 (ip-037-024-043-066.um08.pools.vodafone-ip.de): 2 times
37.113.26.6: 3 times
37.152.183.187: 1 time
42.159.80.91: 1 time
43.134.136.188: 3 times
43.153.18.40: 2 times
43.154.211.73: 2 times
43.156.149.50: 1 time
43.159.135.77: 3 times
43.159.139.131: 2 times
43.163.217.125: 4 times
47.180.212.134 (
static-47-180-212-134.lsan.ca.frontiernet.net): 2 times
51.89.162.121 (ip121.ip-51-89-162.eu): 1 time
59.98.83.57: 2 times
61.222.211.114 (
61-222-211-114.hinet-ip.hinet.net): 1 time
64.62.197.196 (
scan-42o.shadowserver.org): 1 time
77.91.78.115 (test.aeza.network): 2 times
79.175.189.19: 4 times
80.66.75.106: 3 times
80.71.157.129 (vm1964710.stark-industries.solutions): 2 times
82.207.8.202 (
202-8-207-82.pool.ukrtel.net): 2 times
89.190.156.41 (smtp-10.goinbox.in): 92 times
90.107.164.168 (lfbn-orl-1-1610-168.w90-107.abo.wanadoo.fr): 2 times
91.220.109.149: 1 time
103.140.194.87: 1 time
103.170.86.86: 2 times
104.248.50.109: 2 times
106.13.208.8: 1 time
106.250.187.83: 1 time
110.45.145.182: 1 time
111.47.15.165: 1 time
111.229.98.54: 2 times
112.133.247.44: 1 time
112.187.18.4: 5 times
112.199.113.42 (
mail.synhsgroup.com): 3 times
113.31.104.225: 1 time
117.50.162.133 (hangluckpaper.com.cn): 1 time
119.202.128.28: 2 times
121.178.230.152: 5 times
124.223.45.97: 2 times
137.184.118.88: 2 times
139.150.69.244: 2 times
142.93.76.36 (starwifi-11.28.2023-s-1vcpu-2gb-nyc3-01): 3 times
143.110.245.172: 9 times
146.190.122.209: 2 times
150.95.64.112 (v150-95-64-112.a009.g.bkk2.static.cnode.io): 3 times
150.109.204.150: 2 times
150.158.148.149: 1 time
154.221.25.18: 2 times
159.223.45.100: 1 time
164.92.180.158: 2 times
165.22.230.101: 3 times
165.154.183.177: 2 times
167.172.182.99: 2 times
171.227.27.171 (dynamic-adsl.viettel.vn): 1 time
171.244.62.232: 3 times
175.203.23.6: 3 times
175.206.96.66: 6 times
178.174.14.131 (131.14.174.178.static.wline.lns.sme.cust.swisscom.ch): 2 times
180.76.183.123: 1 time
181.115.145.34: 1 time
182.18.161.165 (static-182-18-161-165.ctrls.in): 2 times
182.72.56.30 (nsg-static-030.56.72.182.airtel.in): 1 time
182.253.47.126: 5 times
183.83.222.24 (broadband.actcorp.in): 2 times
188.166.245.43: 2 times
190.52.39.248: 3 times
197.5.145.68: 4 times
201.149.49.146 (
cuallix.com): 3 times
202.51.74.123: 2 times
206.189.59.169: 1 time
207.154.245.38: 1 time
209.38.220.224: 1 time
209.38.248.13: 1 time
210.114.22.126: 9 times
211.21.113.128 (
211-21-113-128.hinet-ip.hinet.net): 2 times
213.74.115.162 (
host-213-74-115-162.superonline.net): 3 times
**Unmatched Entries**
Disconnecting: Protocol error: expected packet type 21, got 20 [preauth] : 3 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop65010p1 394G 243G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################