################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sat May 4 04:42:03 2024
Date Range Processed: yesterday
( 2024-May-03 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host:
h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [243:243]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
141.98.11.79 -> google.com:443: 1 Time(s)
87.121.69.52 -> google.com:443: 1 Time(s)
A total of 7 sites probed the server
107.170.253.9
139.162.251.90
181.214.166.113
198.199.104.58
205.210.31.96
207.90.244.4
45.95.169.184
Requests with error response codes
400 Bad Request
null: 11 Time(s)
google.com:443: 2 Time(s)
*: 1 Time(s)
/0bef: 1 Time(s)
/index.htm: 1 Time(s)
12.1.2: 1 Time(s)
2\x1Az\xB1\xC6I\x10\x05\xB4dC\xFD\x1DH\xBE ... x09\xC0\x13\xC0: 1 Time(s)
\x00\x00BBBB\xBA\x8C\xC1\xABDAAA: 1 Time(s)
\x02CV: 1 Time(s)
\x0F\x14G\xC7\xA2Na\xD8c\xFD$\xB3\x00u\x04 ... D\xC0$\xC0(\xC0: 1 Time(s)
\x84\x9B\x9Ft\xE1\xA3G$\x1E2:\xCB\xAE$T\xA ... x00\x01\x02\x00: 1 Time(s)
]#\xDE\xDD\x09\xEE\xF0\x96\xEE\x80_:\x80`# ... x00\x01\x02\x00: 1 Time(s)
mstshash=Administr: 1 Time(s)
v\x85+\xEF\x09'\xBF\xAAp\xE9\xFD\x1A\xA6\x ... x09\xC0\x13\xC0: 1 Time(s)
500 Internal Server Error
/: 9 Time(s)
/cgi-bin/luci/;stok=/locale?form=country&o ... 20.%2Ftenda.sh): 2 Time(s)
/favicon.ico: 2 Time(s)
/.env: 1 Time(s)
/.well-known/security.txt: 1 Time(s)
/Temporary_Listen_Addresses: 1 Time(s)
/autodiscove/: 1 Time(s)
/autodiscover/autodiscover%20/: 1 Time(s)
/autodiscover/autodiscoverrs/: 1 Time(s)
/autodiscover/autodiscovers/: 1 Time(s)
/ecp/Current/exporttool/microsoft.exchange ... ool.application: 1 Time(s)
/ews/%20/: 1 Time(s)
/ews/autodiscovers/: 1 Time(s)
/ews/ews/: 1 Time(s)
/ews/exchange%20/: 1 Time(s)
/ews/exchange/: 1 Time(s)
/ews/exchanges/: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/robots.txt: 1 Time(s)
/sitemap.xml: 1 Time(s)
502 Bad Gateway
/-S9MXoBxT0OMhDssROVsEg/pdf: 1 Time(s)
/LHl0Tj9sTpmYwPo9u-KOnA/pdf: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
root (183.81.169.238): 30 Time(s)
root (
leopolisjazz.com): 26 Time(s)
root (179.43.180.108): 19 Time(s)
unknown (154.117.199.12): 12 Time(s)
root (43.139.139.189): 11 Time(s)
root (104.250.50.2): 10 Time(s)
root (43.153.37.175): 10 Time(s)
unknown (103.186.161.19): 10 Time(s)
unknown (168.167.228.74): 10 Time(s)
unknown (185.29.121.105): 10 Time(s)
root (156.236.64.189): 9 Time(s)
root (220.86.29.35): 9 Time(s)
root (broadband-95-84-192-76.ip.moscow.rt.ru): 9 Time(s)
unknown (117.88.43.173): 9 Time(s)
unknown (190.188.241.93): 9 Time(s)
unknown (193.201.9.156): 9 Time(s)
unknown (43.153.194.186): 9 Time(s)
unknown (43.159.143.60): 9 Time(s)
root (154.92.17.137): 8 Time(s)
root (206.189.135.113): 8 Time(s)
root (43.130.16.178): 8 Time(s)
root (95.85.15.212): 8 Time(s)
unknown (103.144.245.127): 8 Time(s)
unknown (103.242.199.209): 8 Time(s)
unknown (115.166.142.18): 8 Time(s)
unknown (116.55.245.26): 8 Time(s)
unknown (124.223.16.247): 8 Time(s)
unknown (143.244.188.224): 8 Time(s)
unknown (
160.42.167.72.host.secureserver.net): 8 Time(s)
unknown (211.194.83.173): 8 Time(s)
unknown (223.197.151.55): 8 Time(s)
unknown (43.135.176.48): 8 Time(s)
unknown (43.153.17.152): 8 Time(s)
unknown (49.51.178.89): 8 Time(s)
unknown (49.51.189.248): 8 Time(s)
unknown (62.234.217.197): 8 Time(s)
unknown (81.68.110.60): 8 Time(s)
unknown (82.157.169.5): 8 Time(s)
root (106.104.69.212): 7 Time(s)
root (107.175.254.29): 7 Time(s)
root (14.18.45.2): 7 Time(s)
root (150.109.93.144): 7 Time(s)
root (154.117.199.12): 7 Time(s)
root (185.29.121.106): 7 Time(s)
root (27.72.62.222): 7 Time(s)
root (49.51.192.115): 7 Time(s)
root (5.42.85.242): 7 Time(s)
root (51.77.98.129): 7 Time(s)
root (82.157.166.180): 7 Time(s)
unknown (107.173.147.175): 7 Time(s)
unknown (118.26.37.77): 7 Time(s)
unknown (120.48.123.165): 7 Time(s)
unknown (14.18.45.2): 7 Time(s)
unknown (14.63.221.137): 7 Time(s)
unknown (162.62.126.85): 7 Time(s)
unknown (175.178.154.53): 7 Time(s)
unknown (185.43.108.11): 7 Time(s)
unknown (197.5.145.8): 7 Time(s)
unknown (212.70.149.150): 7 Time(s)
unknown (220.86.29.35): 7 Time(s)
unknown (43.128.73.126): 7 Time(s)
unknown (43.134.61.25): 7 Time(s)
unknown (43.153.178.198): 7 Time(s)
unknown (43.153.83.135): 7 Time(s)
unknown (43.155.132.150): 7 Time(s)
unknown (43.156.114.18): 7 Time(s)
unknown (43.156.241.167): 7 Time(s)
unknown (5.29.135.63): 7 Time(s)
unknown (59.61.82.66): 7 Time(s)
unknown (
6.201.169.192.host.secureserver.net): 7 Time(s)
unknown (
88.239.96.34.bc.googleusercontent.com): 7 Time(s)
root (1.116.45.166): 6 Time(s)
root (101.43.240.23): 6 Time(s)
root (103.186.161.19): 6 Time(s)
root (120.48.123.165): 6 Time(s)
root (124.152.5.117): 6 Time(s)
root (146.185.138.92): 6 Time(s)
root (171.217.93.19): 6 Time(s)
root (211.194.83.173): 6 Time(s)
root (212.70.149.150): 6 Time(s)
root (43.156.174.43): 6 Time(s)
root (62.234.217.197): 6 Time(s)
root (ip-095-222-091-210.um34.pools.vodafone-ip.de): 6 Time(s)
unknown (104.250.50.2): 6 Time(s)
unknown (106.104.69.212): 6 Time(s)
unknown (107.175.254.29): 6 Time(s)
unknown (111.231.32.122): 6 Time(s)
unknown (124.220.21.80): 6 Time(s)
unknown (14.34.248.108): 6 Time(s)
unknown (146.185.138.92): 6 Time(s)
unknown (150.109.93.144): 6 Time(s)
unknown (154.92.17.137): 6 Time(s)
unknown (156.236.64.189): 6 Time(s)
unknown (185.29.121.106): 6 Time(s)
unknown (27.72.62.222): 6 Time(s)
unknown (43.130.16.178): 6 Time(s)
unknown (43.135.157.137): 6 Time(s)
unknown (43.139.139.189): 6 Time(s)
unknown (43.153.195.114): 6 Time(s)
unknown (43.156.174.43): 6 Time(s)
unknown (49.51.192.115): 6 Time(s)
unknown (5.42.85.242): 6 Time(s)
unknown (51.77.98.129): 6 Time(s)
unknown (82.157.166.180): 6 Time(s)
unknown (85.209.11.227): 6 Time(s)
root (1.14.107.89): 5 Time(s)
root (103.242.199.209): 5 Time(s)
root (107.173.147.175): 5 Time(s)
root (118.26.37.77): 5 Time(s)
root (124.220.21.80): 5 Time(s)
root (185.29.121.105): 5 Time(s)
root (197.5.145.8): 5 Time(s)
root (43.134.61.25): 5 Time(s)
root (43.135.157.137): 5 Time(s)
root (43.153.178.198): 5 Time(s)
root (43.153.195.114): 5 Time(s)
root (43.155.132.150): 5 Time(s)
root (43.156.114.18): 5 Time(s)
root (5.29.135.63): 5 Time(s)
root (81.68.110.60): 5 Time(s)
root (
88.239.96.34.bc.googleusercontent.com): 5 Time(s)
unknown (1.116.45.166): 5 Time(s)
unknown (1.12.243.235): 5 Time(s)
unknown (101.35.19.119): 5 Time(s)
unknown (111.230.89.51): 5 Time(s)
unknown (206.189.135.113): 5 Time(s)
unknown (221.160.70.205): 5 Time(s)
unknown (95.85.15.212): 5 Time(s)
root (1.12.243.235): 4 Time(s)
root (101.89.215.129): 4 Time(s)
root (103.14.154.231): 4 Time(s)
root (111.231.32.122): 4 Time(s)
root (116.55.245.26): 4 Time(s)
root (117.88.43.173): 4 Time(s)
root (14.63.221.137): 4 Time(s)
root (152.136.12.92): 4 Time(s)
root (
160.42.167.72.host.secureserver.net): 4 Time(s)
root (162.62.126.85): 4 Time(s)
root (175.178.154.53): 4 Time(s)
root (185.43.108.11): 4 Time(s)
root (193.201.9.156): 4 Time(s)
root (43.128.73.126): 4 Time(s)
root (43.136.76.241): 4 Time(s)
root (43.153.17.152): 4 Time(s)
root (43.156.241.167): 4 Time(s)
root (43.159.143.60): 4 Time(s)
root (85.209.11.254): 4 Time(s)
unknown (1.14.107.89): 4 Time(s)
unknown (101.89.215.129): 4 Time(s)
unknown (112.184.135.67): 4 Time(s)
unknown (120.48.17.127): 4 Time(s)
unknown (152.136.12.92): 4 Time(s)
unknown (43.136.76.241): 4 Time(s)
unknown (43.153.37.175): 4 Time(s)
unknown (85.209.11.254): 4 Time(s)
unknown (broadband-95-84-192-76.ip.moscow.rt.ru): 4 Time(s)
root (101.35.19.119): 3 Time(s)
root (103.144.245.127): 3 Time(s)
root (115.166.142.18): 3 Time(s)
root (120.48.17.127): 3 Time(s)
root (124.223.16.247): 3 Time(s)
root (168.167.228.74): 3 Time(s)
root (190.188.241.93): 3 Time(s)
root (223.197.151.55): 3 Time(s)
root (43.153.83.135): 3 Time(s)
root (49.51.178.89): 3 Time(s)
root (49.51.189.248): 3 Time(s)
root (59.61.82.66): 3 Time(s)
root (
6.201.169.192.host.secureserver.net): 3 Time(s)
root (82.157.169.5): 3 Time(s)
unknown (101.43.240.23): 3 Time(s)
unknown (14.38.141.178): 3 Time(s)
unknown (185.246.130.20): 3 Time(s)
postgres (124.223.16.247): 2 Time(s)
postgres (
6.201.169.192.host.secureserver.net): 2 Time(s)
root (143.244.188.224): 2 Time(s)
root (43.135.176.48): 2 Time(s)
root (85.209.11.227): 2 Time(s)
unknown (103.14.154.231): 2 Time(s)
unknown (185.196.8.151): 2 Time(s)
unknown (31.184.198.71): 2 Time(s)
unknown (85.209.11.27): 2 Time(s)
backup (197.5.145.8): 1 Time(s)
backup (43.128.73.126): 1 Time(s)
bin (59.61.82.66): 1 Time(s)
lp (111.230.89.51): 1 Time(s)
lp (120.48.17.127): 1 Time(s)
lp (152.136.12.92): 1 Time(s)
lp (43.153.83.135): 1 Time(s)
lp (59.61.82.66): 1 Time(s)
mysql (104.250.50.2): 1 Time(s)
mysql (220.86.29.35): 1 Time(s)
postgres (1.116.45.166): 1 Time(s)
postgres (111.230.89.51): 1 Time(s)
postgres (117.88.43.173): 1 Time(s)
postgres (185.29.121.105): 1 Time(s)
postgres (197.5.145.8): 1 Time(s)
postgres (206.189.135.113): 1 Time(s)
postgres (212.70.149.150): 1 Time(s)
postgres (43.130.16.178): 1 Time(s)
postgres (43.135.157.137): 1 Time(s)
postgres (43.153.178.198): 1 Time(s)
postgres (43.153.195.114): 1 Time(s)
postgres (43.156.174.43): 1 Time(s)
postgres (59.61.82.66): 1 Time(s)
postgres (
88.239.96.34.bc.googleusercontent.com): 1 Time(s)
root (111.230.89.51): 1 Time(s)
root (185.246.130.20): 1 Time(s)
root (220.250.58.23): 1 Time(s)
root (31.184.198.71): 1 Time(s)
root (46.101.40.31): 1 Time(s)
temp (5.42.85.242): 1 Time(s)
unknown (14.56.193.140): 1 Time(s)
unknown (
156.red-80-24-99.staticip.rima-tde.net): 1 Time(s)
unknown (175.207.215.47): 1 Time(s)
unknown (220.250.58.23): 1 Time(s)
uucp (193.201.9.156): 1 Time(s)
Invalid Users:
Unknown Account: 601 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
8 Miscellaneous warnings
1 4xx Reject relay denied 100.00%
-------- --------------------------------------------------
1 Total 4xx Rejects 100.00%
======== ==================================================
93 Connections
16 Connections lost (inbound)
93 Disconnections
1 SMTP dialog errors
1 Hostname verification errors (FCRDNS)
---------------------- Postfix End -------------------------
--------------------- Connections (secure-log) Begin ------------------------
**Unmatched Entries**
systemd-logind: New seat seat0.: 1 Time(s)
---------------------- Connections (secure-log) End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin
------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End
-------------------------
--------------------- SSHD Begin ------------------------
SSHD Started: 2 Time(s)
Disconnecting after too many authentication failures for user:
invalid : 2 Time(s)
root : 1 Time(s)
Failed logins from:
1.12.243.235: 4 times
1.14.107.89: 5 times
1.116.45.166: 7 times
5.29.135.63: 5 times
5.42.85.242 (distinct-anger.aeza.network): 8 times
14.18.45.2: 7 times
14.63.221.137: 4 times
27.72.62.222: 7 times
31.184.198.71: 1 time
34.96.239.88 (
88.239.96.34.bc.googleusercontent.com): 6 times
43.128.73.126: 5 times
43.130.16.178: 9 times
43.134.61.25: 5 times
43.135.157.137: 6 times
43.135.176.48: 2 times
43.136.76.241: 4 times
43.139.139.189: 11 times
43.153.17.152: 4 times
43.153.37.175: 10 times
43.153.83.135: 4 times
43.153.178.198: 6 times
43.153.195.114: 6 times
43.155.132.150: 5 times
43.156.114.18: 5 times
43.156.174.43: 7 times
43.156.241.167: 4 times
43.159.143.60: 4 times
46.101.40.31: 1 time
49.51.178.89: 3 times
49.51.189.248: 3 times
49.51.192.115: 7 times
51.77.98.129: 7 times
59.61.82.66: 6 times
62.234.217.197: 6 times
72.167.42.160 (
160.42.167.72.host.secureserver.net): 4 times
81.68.110.60: 5 times
82.157.166.180: 7 times
82.157.169.5: 3 times
85.209.11.227: 2 times
85.209.11.254: 4 times
95.84.192.76 (broadband-95-84-192-76.ip.moscow.rt.ru): 9 times
95.85.15.212: 8 times
95.222.91.210 (ip-095-222-091-210.um34.pools.vodafone-ip.de): 6 times
101.35.19.119: 3 times
101.43.240.23: 6 times
101.89.215.129: 4 times
103.14.154.231: 4 times
103.144.245.127: 3 times
103.186.161.19: 6 times
103.242.199.209 (node-103-242-199-209.alliancebroadband.in): 5 times
104.250.50.2: 11 times
106.104.69.212 (106-104-69-212.adsl.static.seed.net.tw): 7 times
107.173.147.175 (
cerem1-75ony.latesteventmanage.com): 5 times
107.175.254.29 (
107-175-254-29-host.colocrossing.com): 7 times
111.230.89.51: 3 times
111.231.32.122: 4 times
115.166.142.18: 3 times
116.55.245.26: 4 times
117.88.43.173: 5 times
118.26.37.77: 5 times
120.48.17.127: 4 times
120.48.123.165: 6 times
124.152.5.117: 6 times
124.220.21.80: 5 times
124.223.16.247: 5 times
138.197.180.155 (
leopolisjazz.com): 26 times
143.244.188.224: 2 times
146.185.138.92: 6 times
150.109.93.144: 7 times
152.136.12.92: 5 times
154.92.17.137: 8 times
154.117.199.12: 7 times
156.236.64.189: 9 times
162.62.126.85: 4 times
168.167.228.74: 3 times
171.217.93.19: 6 times
175.178.154.53: 4 times
179.43.180.108 (
hostedby.privatelayer.com): 19 times
183.81.169.238: 30 times
185.29.121.105 (
host-185.29.121.105.routergate.com): 6 times
185.29.121.106 (
host-185.29.121.106.routergate.com): 7 times
185.43.108.11 (loantips.online): 4 times
185.246.130.20: 1 time
190.188.241.93 (93-241-188-190.cab.prima.net.ar): 3 times
192.169.201.6 (
6.201.169.192.host.secureserver.net): 5 times
193.201.9.156: 5 times
197.5.145.8: 7 times
206.189.135.113: 9 times
211.194.83.173: 6 times
212.70.149.150: 7 times
220.86.29.35: 10 times
220.250.58.23: 1 time
223.197.151.55 (
223-197-151-55.static.imsbiz.com): 3 times
Illegal users from:
2001:470:1:332::5 (
scan-39af.shadowserver.org): 1 time
undef: 259 times
1.12.243.235: 5 times
1.14.107.89: 4 times
1.116.45.166: 5 times
5.29.135.63: 7 times
5.42.85.242 (distinct-anger.aeza.network): 6 times
14.18.45.2: 7 times
14.34.248.108: 6 times
14.38.141.178: 3 times
14.56.193.140: 5 times
14.63.221.137: 7 times
27.72.62.222: 6 times
31.184.198.71: 3 times
34.96.239.88 (
88.239.96.34.bc.googleusercontent.com): 7 times
43.128.73.126: 7 times
43.130.16.178: 6 times
43.134.61.25: 7 times
43.135.157.137: 6 times
43.135.176.48: 8 times
43.136.76.241: 4 times
43.139.139.189: 6 times
43.153.17.152: 8 times
43.153.37.175: 4 times
43.153.83.135: 7 times
43.153.178.198: 7 times
43.153.194.186: 9 times
43.153.195.114: 6 times
43.155.132.150: 7 times
43.156.114.18: 7 times
43.156.174.43: 6 times
43.156.241.167: 7 times
43.159.143.60: 9 times
49.51.178.89: 8 times
49.51.189.248: 8 times
49.51.192.115: 6 times
51.77.98.129: 6 times
59.61.82.66: 7 times
62.234.217.197: 8 times
72.167.42.160 (
160.42.167.72.host.secureserver.net): 8 times
79.110.62.21: 1 time
80.24.99.156 (
156.red-80-24-99.staticip.rima-tde.net): 1 time
81.68.110.60: 8 times
82.157.59.178: 1 time
82.157.166.180: 6 times
82.157.169.5: 8 times
85.209.11.27: 2 times
85.209.11.227: 6 times
85.209.11.254: 4 times
95.84.192.76 (broadband-95-84-192-76.ip.moscow.rt.ru): 4 times
95.85.15.212: 5 times
101.35.19.119: 5 times
101.43.240.23: 3 times
101.89.215.129: 4 times
103.14.154.231: 2 times
103.144.245.127: 8 times
103.186.161.19: 10 times
103.242.199.209 (node-103-242-199-209.alliancebroadband.in): 8 times
104.250.50.2: 6 times
106.104.69.212 (106-104-69-212.adsl.static.seed.net.tw): 6 times
107.173.147.175 (
cerem1-75ony.latesteventmanage.com): 7 times
107.175.254.29 (
107-175-254-29-host.colocrossing.com): 6 times
111.230.89.51: 5 times
111.231.32.122: 6 times
112.184.135.67: 4 times
115.166.142.18: 8 times
116.55.245.26: 8 times
117.88.43.173: 9 times
118.26.37.77: 7 times
120.48.17.127: 4 times
120.48.123.165: 7 times
124.220.21.80: 6 times
124.223.16.247: 8 times
138.197.180.155 (
leopolisjazz.com): 16 times
143.244.188.224: 8 times
146.185.138.92: 6 times
150.109.93.144: 6 times
152.136.12.92: 4 times
154.92.17.137: 6 times
154.117.199.12: 12 times
156.236.64.189: 6 times
162.62.126.85: 7 times
168.167.228.74: 10 times
175.178.154.53: 7 times
175.207.215.47: 5 times
185.29.121.105 (
host-185.29.121.105.routergate.com): 10 times
185.29.121.106 (
host-185.29.121.106.routergate.com): 6 times
185.43.108.11 (loantips.online): 7 times
185.196.8.151: 2 times
185.246.130.20: 3 times
190.188.241.93 (93-241-188-190.cab.prima.net.ar): 9 times
192.169.201.6 (
6.201.169.192.host.secureserver.net): 7 times
193.201.9.156: 10 times
194.169.175.107: 3 times
197.5.145.8: 7 times
206.189.135.113: 5 times
211.194.83.173: 8 times
212.70.149.150: 8 times
220.86.29.35: 7 times
220.250.58.23: 1 time
221.160.70.205: 6 times
223.197.151.55 (
223-197-151-55.static.imsbiz.com): 8 times
**Unmatched Entries**
error: buffer_get_string_ret: incomplete message [preauth] : 1 time(s)
Disconnecting: Change of username or service not allowed: (root,ssh-connection) ->
(admin,ssh-connection) [preauth] : 2 time(s)
fatal: buffer_get_string: buffer error [preauth] : 1 time(s)
Disconnecting: Protocol error: expected packet type 21, got 20 [preauth] : 2 time(s)
Disconnecting: Change of username or service not allowed: (0,ssh-connection) ->
(root,ssh-connection) [preauth] : 2 time(s)
Disconnecting: Change of username or service not allowed: (admin,ssh-connection) ->
(ubnt,ssh-connection) [preauth] : 2 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop22185p1 394G 243G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################