################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sun Jan 27 04:42:04 2019
Date Range Processed: yesterday
( 2019-Jan-26 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host:
h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [131:131]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
59.36.132.222 ->
www.baidu.com:443: 1 Time(s)
A total of 1 sites probed the server
104.131.68.41
Requests with error response codes
400 Bad Request
/: 2 Time(s)
null: 2 Time(s)
/css/font-awesome.min.css: 1 Time(s)
/css/font-merriweather.css: 1 Time(s)
/css/highlight/default.css: 1 Time(s)
/css/style.css: 1 Time(s)
www.baidu.com:443: 1 Time(s)
404 Not Found
/robots.txt: 53 Time(s)
/berlin/apple-touch-icon.png: 2 Time(s)
/wp-login.php: 2 Time(s)
/.well-known/apple-app-site-association: 1 Time(s)
/apple-app-site-association: 1 Time(s)
/neuigkeiten/2010-11-30_Pressemitteilung-ZaPF-Berlin: 1 Time(s)
/reader/1995-so-reader_ha95.pdf: 1 Time(s)
/resolutionen/sose15/Netzneutralitaet_in_U ... %A4tsnetzen.pdf: 1 Time(s)
/sites/all/libraries/elfinder/connectors/php/connector.php: 1 Time(s)
/sites/all/libraries/elfinder/elfinder.html: 1 Time(s)
/sites/all/libraries/elfinder/src/connecto ... p/connector.php: 1 Time(s)
/sites/default/files/1981_SoSe_Mainz.pdf: 1 Time(s)
/sites/default/files/1982_WiSe_Stuttgart.pdf: 1 Time(s)
/sites/default/files/2005_SoSe_Erlangen.pdf: 1 Time(s)
/sites/default/files/2009_SoSe_G%C3%B6ttingen.pdf: 1 Time(s)
/user/password: 1 Time(s)
/wp/wp-login.php: 1 Time(s)
/zapf/berichte/ausgestaltung-studiengaenge ... _zapf-sose-2010: 1 Time(s)
/zapf/berichte/zapf-wise-2011: 1 Time(s)
/zapf/berichte/zapf-wise-2013: 1 Time(s)
499 (undefined)
/reader/1982-wi-Stuttgart_Wi82.pdf: 2 Time(s)
500 Internal Server Error
/: 3 Time(s)
//libs/js/iframe.js: 1 Time(s)
502 Bad Gateway
/: 26 Time(s)
/robots.txt: 2 Time(s)
/sitemap.xml: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (118.72.79.30): 6 Time(s)
root (120.224.101.134): 6 Time(s)
root (125.111.119.46): 6 Time(s)
root (2.190.147.104): 6 Time(s)
root (8ef02a575c.rev.snt.net.pl): 6 Time(s)
unknown (112.115.192.194): 6 Time(s)
unknown (117.11.70.154): 6 Time(s)
unknown (119.92.174.170): 6 Time(s)
unknown (122.194.143.219): 6 Time(s)
unknown (152.204.10.83): 6 Time(s)
unknown (200.233.228.113): 6 Time(s)
unknown (27.15.195.201): 6 Time(s)
unknown (ip217.ip-91-134-203.eu): 6 Time(s)
unknown (110-175-57-53.static.tpgi.com.au): 5 Time(s)
unknown (89.218.14.61): 5 Time(s)
unknown (
cpe-184-58-139-187.wi.res.rr.com): 5 Time(s)
unknown (112.171.152.12): 4 Time(s)
unknown (119.205.233.15): 4 Time(s)
unknown (134.208.23.110): 4 Time(s)
unknown (188.131.132.70): 4 Time(s)
unknown (218.5.112.6): 4 Time(s)
unknown (221.192.142.58): 4 Time(s)
unknown (host185.186-109-81.telecom.net.ar): 4 Time(s)
unknown (101.231.252.98): 3 Time(s)
unknown (103.36.121.213): 3 Time(s)
unknown (104.236.2.45): 3 Time(s)
unknown (106.12.208.162): 3 Time(s)
unknown (106.13.45.22): 3 Time(s)
unknown (106.51.54.198): 3 Time(s)
unknown (106.75.141.202): 3 Time(s)
unknown (110-170-252-164.static.asianet.co.th): 3 Time(s)
unknown (111.230.58.110): 3 Time(s)
unknown (112.176.71.202.sta.prodatanet.com.ph): 3 Time(s)
unknown (112.64.34.171): 3 Time(s)
unknown (114.112.104.13): 3 Time(s)
unknown (114.6.197.82): 3 Time(s)
unknown (116.0.54.226): 3 Time(s)
unknown (116.30.196.41): 3 Time(s)
unknown (117.50.0.146): 3 Time(s)
unknown (118.24.173.104): 3 Time(s)
unknown (118.24.83.41): 3 Time(s)
unknown (118.25.20.213): 3 Time(s)
unknown (118.25.96.30): 3 Time(s)
unknown (118.97.140.237): 3 Time(s)
unknown (119.29.65.240): 3 Time(s)
unknown (121.201.110.60): 3 Time(s)
unknown (121.67.246.139): 3 Time(s)
unknown (
122-117-36-247.hinet-ip.hinet.net): 3 Time(s)
unknown (125.124.32.11): 3 Time(s)
unknown (128.106.195.126): 3 Time(s)
unknown (129.204.46.170): 3 Time(s)
unknown (130.ip-54-37-19.eu): 3 Time(s)
unknown (132.232.11.31): 3 Time(s)
unknown (132.232.69.133): 3 Time(s)
unknown (138.68.31.105): 3 Time(s)
unknown (139.219.188.97): 3 Time(s)
unknown (140.143.134.86): 3 Time(s)
unknown (142.93.126.84): 3 Time(s)
unknown (
143.64.199.35.bc.googleusercontent.com): 3 Time(s)
unknown (146.ip-217-182-68.eu): 3 Time(s)
unknown (150.129.69.113): 3 Time(s)
unknown (159.89.194.103): 3 Time(s)
unknown (165.227.93.58): 3 Time(s)
unknown (171.110.123.41): 3 Time(s)
unknown (178.128.162.10): 3 Time(s)
unknown (178.22.122.234): 3 Time(s)
unknown (178.62.199.240): 3 Time(s)
unknown (178.62.201.159): 3 Time(s)
unknown (178.62.60.225): 3 Time(s)
unknown (181.231.63.190): 3 Time(s)
unknown (181.29.14.32): 3 Time(s)
unknown (182.71.127.226): 3 Time(s)
unknown (182.76.7.171): 3 Time(s)
unknown (182.ip-37-187-60.eu): 3 Time(s)
unknown (183.136.239.206): 3 Time(s)
unknown (185.54.152.230): 3 Time(s)
unknown (187.191.114.79): 3 Time(s)
unknown (188.131.234.186): 3 Time(s)
unknown (188.166.161.117): 3 Time(s)
unknown (189.124.93.10): 3 Time(s)
unknown (189.7.121.28): 3 Time(s)
unknown (190.145.55.90): 3 Time(s)
unknown (192.95.37.229): 3 Time(s)
unknown (193.ip-54-37-67.eu): 3 Time(s)
unknown (195.22.141.33): 3 Time(s)
unknown (200.108.139.242): 3 Time(s)
unknown (206.189.239.156): 3 Time(s)
unknown (206.81.24.64): 3 Time(s)
unknown (207.154.193.178): 3 Time(s)
unknown (218.18.101.84): 3 Time(s)
unknown (219.147.168.103): 3 Time(s)
unknown (219.65.51.21): 3 Time(s)
unknown (220.120.109.166): 3 Time(s)
unknown (221.131.28.146): 3 Time(s)
unknown (222.128.9.20): 3 Time(s)
unknown (238.123.146.82.ipv4.evonet.be): 3 Time(s)
unknown (250.ip-54-38-240.eu): 3 Time(s)
unknown (27.115.15.8): 3 Time(s)
unknown (40.113.194.12): 3 Time(s)
unknown (41.214.20.60): 3 Time(s)
unknown (41.77.199.28): 3 Time(s)
unknown (43.243.128.213): 3 Time(s)
unknown (45.55.243.106): 3 Time(s)
unknown (47.196.36.205): 3 Time(s)
unknown (51.15.183.198): 3 Time(s)
unknown (52.172.55.21): 3 Time(s)
unknown (59.145.221.103): 3 Time(s)
unknown (64.ip-51-254-201.eu): 3 Time(s)
unknown (67.205.135.127): 3 Time(s)
unknown (77.81.230.10): 3 Time(s)
unknown (80.211.236.160): 3 Time(s)
unknown (82.131.209.179): 3 Time(s)
unknown (
83.223.158.77.rev.sfr.net): 3 Time(s)
unknown (88.214.26.49): 3 Time(s)
unknown (93-43-39-56.ip90.fastwebnet.it): 3 Time(s)
unknown (93.ip-151-80-61.eu): 3 Time(s)
unknown (94.230.136.33): 3 Time(s)
unknown (95.245.211.11): 3 Time(s)
unknown (abi-hosting.onsite.hosting.co.za): 3 Time(s)
unknown (
c-24-125-234-230.hsd1.ga.comcast.net): 3 Time(s)
unknown (
c-73-15-91-251.hsd1.ca.comcast.net): 3 Time(s)
unknown (
cpe-74-130-22-36.kya.res.rr.com): 3 Time(s)
unknown (human.unsa.edu.ar): 3 Time(s)
unknown (
hwsrv-294917.hostwindsdns.com): 3 Time(s)
unknown (l246124.ppp.asahi-net.or.jp): 3 Time(s)
unknown (mik.esm.one): 3 Time(s)
unknown (net-93-144-155-137.cust.vodafonedsl.it): 3 Time(s)
unknown (ns3070189.ip-149-202-214.eu): 3 Time(s)
unknown (
play.euphalys.net): 3 Time(s)
unknown (profforma.it): 3 Time(s)
unknown (promoroom.ru): 3 Time(s)
unknown (
s72-38-90-230.static.comm.cgocable.net): 3 Time(s)
unknown (
sanyaade.plus.com): 3 Time(s)
unknown (
sd.two-notes.net): 3 Time(s)
unknown (server1.startsl.com.br): 3 Time(s)
unknown (static-186-31-25-22.static.etb.net.co): 3 Time(s)
unknown (static-82-85-143-181.clienti.tiscali.it): 3 Time(s)
unknown (
102.185.71.37.rev.sfr.net): 2 Time(s)
unknown (103.37.150.170): 2 Time(s)
unknown (177.206.128.131): 2 Time(s)
unknown (owa.iran.ahk.de): 2 Time(s)
gnats (134.208.23.110): 1 Time(s)
mysql (
102.185.71.37.rev.sfr.net): 1 Time(s)
mysql (104.236.2.45): 1 Time(s)
mysql (218.5.112.6): 1 Time(s)
mysql (89.218.14.61): 1 Time(s)
openproject (119.205.233.15): 1 Time(s)
openproject (188.131.132.70): 1 Time(s)
openproject (
83.223.158.77.rev.sfr.net): 1 Time(s)
postgres (210.183.236.30): 1 Time(s)
postgres (221.192.142.58): 1 Time(s)
root (125.124.30.186): 1 Time(s)
root (
ip-50-63-165-214.ip.secureserver.net): 1 Time(s)
unknown (1.236.151.31): 1 Time(s)
unknown (106.12.125.212): 1 Time(s)
unknown (106.12.205.171): 1 Time(s)
unknown (114.67.72.212): 1 Time(s)
unknown (116.196.101.227): 1 Time(s)
unknown (123.20.225.46): 1 Time(s)
unknown (123.206.45.16): 1 Time(s)
unknown (123.207.16.164): 1 Time(s)
unknown (177.19.165.26): 1 Time(s)
unknown (182.73.124.10): 1 Time(s)
unknown (206.189.167.33): 1 Time(s)
unknown (210.183.236.30): 1 Time(s)
unknown (211.24.126.238): 1 Time(s)
unknown (217.61.106.117): 1 Time(s)
unknown (217.66.212.66): 1 Time(s)
unknown (221.221.138.218): 1 Time(s)
unknown (46.209.21.220): 1 Time(s)
unknown (46.209.73.195): 1 Time(s)
unknown (61.148.194.162): 1 Time(s)
unknown (64.76.6.126): 1 Time(s)
unknown (80.211.244.130): 1 Time(s)
unknown (lfbn-1-12666-251.w90-90.abo.wanadoo.fr): 1 Time(s)
unknown (ns3016508.ip-51-254-47.eu): 1 Time(s)
unknown (p4fefc40c.dip0.t-ipconnect.de): 1 Time(s)
unknown (p5b3d2dba.dip0.t-ipconnect.de): 1 Time(s)
www-data (112.171.152.12): 1 Time(s)
Invalid Users:
Unknown Account: 466 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
1 Miscellaneous warnings
34.898K Bytes accepted 35,736
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
2 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
2 Total 4xx Rejects 100.00%
======== ==================================================
125 Connections
118 Connections lost (inbound)
125 Disconnections
3 Deferred
61 Deferrals
61 Connection failures (outbound)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin
------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End
-------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
invalid : 5 Time(s)
root : 5 Time(s)
Failed logins from:
2.190.147.104: 6 times
37.71.185.102 (
102.185.71.37.rev.sfr.net): 1 time
37.157.202.122 (8ef02a575c.rev.snt.net.pl): 6 times
50.63.165.214 (
ip-50-63-165-214.ip.secureserver.net): 1 time
77.158.223.83 (
83.223.158.77.rev.sfr.net): 1 time
89.218.14.61: 1 time
104.236.2.45: 1 time
112.171.152.12: 1 time
118.72.79.30 (30.79.72.118.adsl-pool.sx.cn): 6 times
119.205.233.15: 1 time
120.224.101.134: 6 times
125.111.119.46: 6 times
125.124.30.186: 1 time
134.208.23.110 (134-208-23-110.ndhu.edu.tw): 1 time
188.131.132.70: 1 time
210.183.236.30: 1 time
218.5.112.6: 1 time
221.192.142.58: 1 time
Illegal users from:
undef: 330 times
1.236.151.31: 1 time
24.125.234.230 (
c-24-125-234-230.hsd1.ga.comcast.net): 3 times
27.15.195.201: 6 times
27.115.15.8: 3 times
35.199.64.143 (
143.64.199.35.bc.googleusercontent.com): 3 times
37.71.185.102 (
102.185.71.37.rev.sfr.net): 2 times
37.187.60.182 (182.ip-37-187-60.eu): 3 times
40.113.194.12: 3 times
41.77.199.28: 3 times
41.214.20.60: 3 times
43.243.128.213: 3 times
45.55.243.106: 3 times
46.209.21.220: 1 time
46.209.73.195: 1 time
47.196.36.205: 3 times
51.15.183.198 (51-15-183-198.rev.poneytelecom.eu): 3 times
51.254.47.198 (ns3016508.ip-51-254-47.eu): 1 time
51.254.201.64 (64.ip-51-254-201.eu): 3 times
52.172.55.21: 3 times
54.36.165.129 (
play.euphalys.net): 3 times
54.37.19.130 (130.ip-54-37-19.eu): 3 times
54.37.67.193 (193.ip-54-37-67.eu): 3 times
54.38.240.250 (250.ip-54-38-240.eu): 3 times
59.145.221.103 (www1.jbvnl.co.in): 3 times
61.148.194.162: 1 time
64.76.6.126 (64-76-6-126.dynamic.impsat.net.ar): 1 time
67.205.135.127 (vook2.ubuntu-s-2vcpu-4gb-nyc1-01): 3 times
72.38.90.230 (
s72-38-90-230.static.comm.cgocable.net): 3 times
73.15.91.251 (
c-73-15-91-251.hsd1.ca.comcast.net): 3 times
74.130.22.36 (
cpe-74-130-22-36.kya.res.rr.com): 3 times
77.81.230.10 (host10-230-81-77.serverdedicati.aruba.it): 3 times
77.158.223.83 (
83.223.158.77.rev.sfr.net): 3 times
79.239.196.12 (p4FEFC40C.dip0.t-ipconnect.de): 1 time
80.211.236.160 (host160-236-211-80.serverdedicati.aruba.it): 3 times
80.211.244.130 (host130-244-211-80.static.arubacloud.pl): 1 time
80.253.145.66 (OWA.IRAN.AHK.DE): 2 times
81.174.227.27 (
sanyaade.plus.com): 3 times
82.85.143.181 (static-82-85-143-181.clienti.tiscali.it): 3 times
82.131.209.179 (charon.city-screen.hu): 3 times
82.146.123.238 (238.123.146.82.ipv4.evonet.be): 3 times
85.93.145.134 (promoroom.ru): 3 times
88.214.26.49: 3 times
89.218.14.61: 5 times
90.90.207.251 (lfbn-1-12666-251.w90-90.abo.wanadoo.fr): 1 time
91.61.45.186 (p5B3D2DBA.dip0.t-ipconnect.de): 1 time
91.134.203.217 (ip217.ip-91-134-203.eu): 6 times
91.199.144.23 (mik.esm.one): 3 times
93.43.39.56 (93-43-39-56.ip90.fastwebnet.it): 3 times
93.144.155.137 (net-93-144-155-137.cust.dsl.teletu.it): 3 times
94.230.136.33 (94-230-136-33.vi-line.ru): 3 times
95.245.211.11 (host11-211-dynamic.245-95-r.retail.telecomitalia.it): 3 times
101.231.252.98: 3 times
103.36.121.213: 3 times
103.37.150.170: 2 times
104.168.143.252 (
hwsrv-294917.hostwindsdns.com): 3 times
104.236.2.45: 3 times
106.12.125.212: 1 time
106.12.205.171: 1 time
106.12.208.162: 3 times
106.13.45.22: 3 times
106.51.54.198 (broadband.actcorp.in): 3 times
106.75.141.202: 3 times
110.170.252.164 (110-170-252-164.static.asianet.co.th): 3 times
110.175.57.53 (110-175-57-53.static.tpgi.com.au): 5 times
111.230.58.110: 3 times
112.64.34.171: 3 times
112.115.192.194: 6 times
112.171.152.12: 4 times
114.6.197.82 (
114-6-197-82.resources.indosat.com): 3 times
114.67.72.212: 1 time
114.112.104.13: 3 times
116.0.54.226: 3 times
116.30.196.41: 3 times
116.196.101.227: 1 time
117.11.70.154 (dns154.online.tj.cn): 6 times
117.50.0.146: 3 times
118.24.83.41: 3 times
118.24.173.104: 3 times
118.25.20.213: 3 times
118.25.96.30: 3 times
118.97.140.237 (237.subnet118-97-140.static.astinet.telkom.net.id): 3 times
119.29.65.240: 3 times
119.92.174.170 (
119.92.174.170.static.pldt.net): 6 times
119.205.233.15: 4 times
121.67.246.139: 3 times
121.201.110.60: 3 times
122.117.36.247 (
122-117-36-247.HINET-IP.hinet.net): 3 times
122.194.143.219: 6 times
123.20.225.46: 1 time
123.206.45.16: 1 time
123.207.16.164: 1 time
125.124.32.11: 3 times
128.106.195.126 (bb128-106-195-126.singnet.com.sg): 3 times
129.204.46.170: 3 times
132.232.11.31: 3 times
132.232.69.133: 3 times
134.208.23.110 (134-208-23-110.ndhu.edu.tw): 4 times
138.68.31.105: 3 times
139.162.122.110 (
scan-8.security.ipip.net): 1 time
139.219.188.97: 3 times
140.143.134.86: 3 times
142.44.194.54 (server1.startsl.com.br): 3 times
142.93.126.84: 3 times
149.202.214.11 (ns3070189.ip-149-202-214.eu): 3 times
150.129.69.113: 3 times
151.80.61.93 (93.ip-151-80-61.eu): 3 times
152.204.10.83: 6 times
159.89.194.103: 3 times
163.172.93.131 (
sd.two-notes.net): 3 times
165.227.93.58: 3 times
170.210.200.9 (human.unsa.edu.ar): 3 times
171.110.123.41: 3 times
177.19.165.26 (ciriex-abus.pae.gvt.net.br): 1 time
177.206.128.131 (177.206.128.131.static.gvt.net.br): 2 times
178.22.122.234: 3 times
178.62.60.225: 3 times
178.62.199.240: 3 times
178.62.201.159: 3 times
178.128.162.10: 3 times
181.29.14.32 (32-14-29-181.fibertel.com.ar): 3 times
181.231.63.190 (190-63-231-181.cab.prima.com.ar): 3 times
182.71.127.226 (nsg-static-226.127.71.182.airtel.in): 3 times
182.73.124.10: 1 time
182.76.7.171 (
nsg-static-171.7.76.182-airtel.com): 3 times
183.136.239.206: 3 times
184.58.139.187 (
cpe-184-58-139-187.wi.res.rr.com): 5 times
185.54.152.230 (185.54.152-230.link.cs.it): 3 times
186.31.25.22 (static-186-31-25-22.static.etb.net.co): 3 times
186.109.81.185 (host185.186-109-81.telecom.net.ar): 4 times
187.191.114.79: 3 times
188.131.132.70: 4 times
188.131.234.186: 3 times
188.166.161.117: 3 times
188.213.168.243 (profforma.it): 3 times
189.7.121.28 (bd07791c.virtua.com.br): 3 times
189.124.93.10 (
10.93.124.189.assim.net): 3 times
190.145.55.90: 3 times
192.95.37.229: 3 times
195.22.141.33 (195.22.141.33.users.bel.com.ua): 3 times
196.35.41.86 (abi-hosting.onsite.hosting.co.za): 3 times
200.108.139.242: 3 times
200.233.228.113 (200-233-228-113.xd-dynamic.ctbcnetsuper.com.br): 6 times
202.71.176.112 (112.176.71.202.sta.prodatanet.com.ph): 3 times
206.81.24.64: 3 times
206.189.167.33: 1 time
206.189.239.156: 3 times
207.154.193.178: 3 times
210.183.236.30: 1 time
211.24.126.238 (cgw-211-24-126-238.bbrtl.time.net.my): 1 time
217.61.106.117 (
host117-106-61-217.static.arubacloud.com): 1 time
217.66.212.66 (
int0.client.access.fanaptelecom.net): 1 time
217.182.68.146 (146.ip-217-182-68.eu): 3 times
218.5.112.6: 4 times
218.18.101.84: 3 times
218.219.246.124 (l246124.ppp.asahi-net.or.jp): 3 times
219.65.51.21 (219.65.51.21.static-chennai.vsnl.net.in): 3 times
219.147.168.103: 3 times
220.120.109.166: 3 times
221.131.28.146: 3 times
221.192.142.58: 4 times
221.221.138.218: 1 time
222.128.9.20: 3 times
**Unmatched Entries**
Disconnecting: Change of username or service not allowed: (admin,ssh-connection) ->
(user,ssh-connection) [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/vzfs 400G 241G 160G 61% /
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################