################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sun Jun 16 04:42:10 2019
Date Range Processed: yesterday
( 2019-Jun-15 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host:
h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [202:201]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
A total of 4 sites probed the server
108.178.16.154
188.166.77.35
61.219.11.153
69.164.221.31
Requests with error response codes
400 Bad Request
null: 4 Time(s)
\xE8@j\xC1R|>\xFB+\x86: 1 Time(s)
http://172.247.32.25/ddd.html: 1 Time(s)
mstshash=Administr: 1 Time(s)
404 Not Found
/robots.txt: 41 Time(s)
/wp-login.php: 3 Time(s)
/berlin/apple-touch-icon.png: 2 Time(s)
/downloader/index.php: 1 Time(s)
/errors/503.php: 1 Time(s)
/index.php/admin/: 1 Time(s)
/magento/downloader/index.php: 1 Time(s)
/magento/errors/503.php: 1 Time(s)
/magento/index.php/admin/: 1 Time(s)
/reader/1994-wi-reader_hb94.pdf: 1 Time(s)
/reader/2016_SoSe_Konstanz_kurz.pdf%7CReader: 1 Time(s)
/reader/2016_sose_konstanz_lang.pdf: 1 Time(s)
/resolutionen/sose14/reso_sose14_zusammenarbeitzapf-che.pdf: 1 Time(s)
/shop/downloader/index.php: 1 Time(s)
/shop/errors/503.php: 1 Time(s)
/shop/index.php/admin/: 1 Time(s)
/store/downloader/index.php: 1 Time(s)
/store/errors/503.php: 1 Time(s)
/store/index.php/admin/: 1 Time(s)
/verein/satzung/%7CSatzung: 1 Time(s)
500 Internal Server Error
/: 38 Time(s)
/downloader/index.php: 3 Time(s)
/errors/503.php: 3 Time(s)
/index.php/admin/: 3 Time(s)
/.env: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
unknown (168.128.86.35): 47 Time(s)
unknown (175.143.5.126): 47 Time(s)
unknown (36.108.172.39): 44 Time(s)
unknown (192.144.132.172): 40 Time(s)
unknown (222.231.33.233): 38 Time(s)
unknown (164.ip-54-38-189.eu): 35 Time(s)
unknown (165.227.79.50): 35 Time(s)
unknown (167.99.232.88): 35 Time(s)
unknown (174.138.58.149): 35 Time(s)
unknown (30.ip-51-38-128.eu): 34 Time(s)
unknown (5.196.52.173): 32 Time(s)
unknown (106.13.9.153): 31 Time(s)
unknown (
fixed-187-189-109-138.totalplay.net): 26 Time(s)
unknown (129.204.58.180): 25 Time(s)
unknown (165.227.9.145): 18 Time(s)
unknown (157.230.91.45): 13 Time(s)
unknown (
c-71-234-228-136.hsd1.ct.comcast.net): 11 Time(s)
unknown (118.89.26.58): 10 Time(s)
root (5.196.52.173): 9 Time(s)
root (164.ip-54-38-189.eu): 7 Time(s)
root (168.128.86.35): 7 Time(s)
root (222.231.33.233): 7 Time(s)
root (30.ip-51-38-128.eu): 7 Time(s)
root (112.85.42.176): 6 Time(s)
root (117.57.35.254): 6 Time(s)
root (175.143.5.126): 6 Time(s)
root (183.157.185.147): 6 Time(s)
root (49.83.32.77): 6 Time(s)
root (58.23.194.250): 6 Time(s)
root (58.242.82.11): 6 Time(s)
unknown (118.24.11.71): 6 Time(s)
root (106.13.9.153): 5 Time(s)
root (157.230.91.45): 5 Time(s)
root (174.138.58.149): 5 Time(s)
root (
fixed-187-189-109-138.totalplay.net): 5 Time(s)
unknown (148.70.166.52): 5 Time(s)
unknown (175.6.77.235): 5 Time(s)
root (129.204.58.180): 4 Time(s)
root (165.227.79.50): 4 Time(s)
root (167.99.232.88): 4 Time(s)
root (192.144.132.172): 4 Time(s)
unknown (66.115.168.210): 4 Time(s)
root (165.227.9.145): 3 Time(s)
unknown (106.12.87.149): 3 Time(s)
unknown (123.206.41.40): 3 Time(s)
root (36.108.172.39): 2 Time(s)
unknown (46.101.206.205): 2 Time(s)
unknown (93.84.111.7): 2 Time(s)
unknown (
cpe-104-34-155-90.socal.res.rr.com): 2 Time(s)
backup (118.89.26.58): 1 Time(s)
games (222.231.33.233): 1 Time(s)
gnats (175.6.77.235): 1 Time(s)
irc (192.144.132.172): 1 Time(s)
irc (36.108.172.39): 1 Time(s)
lp (106.13.9.153): 1 Time(s)
mail (164.ip-54-38-189.eu): 1 Time(s)
mail (192.144.132.172): 1 Time(s)
mailman (175.143.5.126): 1 Time(s)
man (165.227.79.50): 1 Time(s)
man (175.143.5.126): 1 Time(s)
man (5.196.52.173): 1 Time(s)
mysql (118.89.26.58): 1 Time(s)
mysql (36.108.172.39): 1 Time(s)
nobody (168.128.86.35): 1 Time(s)
postfix (222.231.33.233): 1 Time(s)
root (123.206.41.40): 1 Time(s)
root (142.4.204.122): 1 Time(s)
root (148.70.166.52): 1 Time(s)
root (178.128.126.222): 1 Time(s)
root (218.92.0.170): 1 Time(s)
root (66.115.168.210): 1 Time(s)
smmsp (192.144.132.172): 1 Time(s)
sshd (167.99.232.88): 1 Time(s)
sshd (222.231.33.233): 1 Time(s)
temp (30.ip-51-38-128.eu): 1 Time(s)
unknown (103.60.220.73): 1 Time(s)
unknown (103.94.130.4): 1 Time(s)
unknown (114.108.177.34): 1 Time(s)
unknown (118.144.82.74): 1 Time(s)
unknown (14.169.222.139): 1 Time(s)
unknown (142.4.204.122): 1 Time(s)
unknown (163-172-16-65.rev.poneytelecom.eu): 1 Time(s)
unknown (167.99.85.247): 1 Time(s)
unknown (178.128.126.222): 1 Time(s)
unknown (183.196.107.144): 1 Time(s)
unknown (185.208.64.6): 1 Time(s)
unknown (197.46.72.16): 1 Time(s)
unknown (219.239.47.66): 1 Time(s)
unknown (222.214.237.144): 1 Time(s)
unknown (222.237.78.73): 1 Time(s)
unknown (58.59.2.26): 1 Time(s)
unknown (
60-251-229-67.hinet-ip.hinet.net): 1 Time(s)
unknown (83.red-185-190-100.static.citelia.es): 1 Time(s)
unknown (85.38.164.51): 1 Time(s)
unknown (
d-66-212-192-81.ct.cpe.atlanticbb.net): 1 Time(s)
unknown (
host81-142-80-97.in-addr.btopenworld.com): 1 Time(s)
unknown (mail.aslbenevento1.it): 1 Time(s)
unknown (mail.coosanca.coop.py): 1 Time(s)
unknown (
mail.inboxnorth.com): 1 Time(s)
unknown (
server.ocimumscience.org): 1 Time(s)
Invalid Users:
Unknown Account: 617 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
1 Miscellaneous warnings
14.171K Bytes accepted 14,511
14.171K Bytes sent via SMTP 14,511
======== ==================================================
1 Accepted 100.00%
-------- --------------------------------------------------
1 Total 100.00%
======== ==================================================
1 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
1 Total 4xx Rejects 100.00%
======== ==================================================
24 Connections
19 Connections lost (inbound)
24 Disconnections
1 Removed from queue
1 Sent via SMTP
2 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin
------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End
-------------------------
--------------------- SSHD Begin ------------------------
Disconnecting after too many authentication failures for user:
root : 6 Time(s)
Failed logins from:
5.196.52.173: 10 times
36.108.172.39: 4 times
49.83.32.77: 6 times
51.38.128.30 (30.ip-51-38-128.eu): 8 times
54.38.189.164 (164.ip-54-38-189.eu): 8 times
58.23.194.250: 6 times
58.242.82.11: 6 times
66.115.168.210 (
bilz4.2012londonbad.com): 1 time
106.13.9.153: 6 times
112.85.42.176: 6 times
117.57.35.254: 6 times
118.89.26.58: 2 times
123.206.41.40: 1 time
129.204.58.180: 4 times
142.4.204.122: 1 time
148.70.166.52: 1 time
157.230.91.45 (
252407.cloudwaysapps.com): 5 times
165.227.9.145: 3 times
165.227.79.50: 5 times
167.99.232.88: 5 times
168.128.86.35 (
168-128-86-35-af1.mcp-services.net): 8 times
174.138.58.149: 5 times
175.6.77.235: 1 time
175.143.5.126: 8 times
178.128.126.222: 1 time
183.157.185.147: 6 times
187.189.109.138 (
fixed-187-189-109-138.totalplay.net): 5 times
192.144.132.172: 7 times
218.92.0.170: 2 times
222.231.33.233: 10 times
Illegal users from:
undef: 500 times
5.196.52.173: 32 times
14.169.222.139 (static.vnpt.vn): 1 time
36.108.172.39: 44 times
46.101.206.205: 2 times
51.38.128.30 (30.ip-51-38-128.eu): 34 times
54.38.189.164 (164.ip-54-38-189.eu): 35 times
58.59.2.26: 1 time
60.251.229.67 (
60-251-229-67.HINET-IP.hinet.net): 1 time
66.115.168.210 (
bilz4.2012londonbad.com): 4 times
66.212.192.81 (
d-66-212-192-81.ct.cpe.atlanticbb.net): 1 time
71.234.228.136 (
c-71-234-228-136.hsd1.ct.comcast.net): 11 times
81.142.80.97 (
host81-142-80-97.in-addr.btopenworld.com): 1 time
85.38.164.51: 1 time
93.51.173.134 (mail.aslbenevento1.it): 1 time
93.84.111.7 (mm-7-111-84-93.static.minsktelecom.by): 2 times
103.60.220.73: 1 time
103.94.130.4: 1 time
104.34.155.90 (
cpe-104-34-155-90.socal.res.rr.com): 2 times
106.12.87.149: 3 times
106.13.9.153: 31 times
114.108.177.34: 1 time
118.24.11.71: 6 times
118.89.26.58: 10 times
118.144.82.74: 1 time
123.206.41.40: 3 times
129.204.58.180: 25 times
139.162.122.110 (
scan-8.security.ipip.net): 1 time
142.4.204.122: 1 time
142.93.188.233 (
mail.inboxnorth.com): 1 time
148.70.166.52: 5 times
157.230.91.45 (
252407.cloudwaysapps.com): 13 times
163.172.16.65 (163-172-16-65.rev.poneytelecom.eu): 1 time
165.227.9.145: 18 times
165.227.79.50: 35 times
167.99.85.247: 1 time
167.99.232.88: 35 times
168.128.86.35 (
168-128-86-35-af1.mcp-services.net): 47 times
174.138.58.149: 35 times
175.6.77.235: 5 times
175.143.5.126: 47 times
178.128.126.222: 1 time
181.40.89.90 (mail.coosanca.coop.py): 1 time
182.18.157.223 (
server.ocimumscience.org): 1 time
183.196.107.144: 1 time
185.190.100.83 (83.red-185-190-100.static.citelia.es): 1 time
185.208.64.6: 1 time
187.189.109.138 (
fixed-187-189-109-138.totalplay.net): 26 times
192.144.132.172: 40 times
197.46.72.16 (
host-197.46.72.16.tedata.net): 1 time
219.239.47.66: 1 time
222.214.237.144: 1 time
222.231.33.233: 38 times
222.237.78.73 (222-237-78-73.tongkni.co.kr): 5 times
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/vzfs 400G 242G 159G 61% /
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################