Daily report for 02.05.2004

Summary
Topic Value
Network Report 68.2M
Traffic via iptables 29.7M
CPU Usage 0.00
Web-Server 39.8M
FTP-Server 210.0K
FTP-Logs 10
Postfix 233.9K
Warnings 16
Last logins 3
Check for Rootkit 1
System information-
Network Report
249.2K bytes 974.3K bytes 159.3K bytes 1.1M bytes 313.4K bytes 931.1K bytes 168.4K bytes 705.1K bytes 84.5K bytes 312.2K bytes 120.4K bytes 629.4K bytes 329.2K bytes 13.0M bytes 344.1K bytes 986.8K bytes 525.8K bytes 1.5M bytes 418.5K bytes 1004.1K bytes 281.9K bytes 1.7M bytes 399.4K bytes 2.0M bytes 332.0K bytes 1.6M bytes 630.1K bytes 4.2M bytes 283.4K bytes 1.6M bytes 466.7K bytes 1.3M bytes 903.2K bytes 7.4M bytes 760.1K bytes 7.1M bytes 560.4K bytes 1.9M bytes 301.9K bytes 1.5M bytes 276.2K bytes 2.1M bytes 271.2K bytes 1.4M bytes 668.2K bytes 3.9M bytes 138.6K bytes 723.7K bytes
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
Hour In Out Sum
0 249.2K 974.3K 1.2M
1 159.3K 1.1M 1.3M
2 313.4K 931.1K 1.2M
3 168.4K 705.1K 873.5K
4 84.5K 312.2K 396.7K
5 120.4K 629.4K 749.8K
6 329.2K 13.0M 13.3M
7 344.1K 986.8K 1.3M
8 525.8K 1.5M 2.0M
9 418.5K 1004.1K 1.4M
10 281.9K 1.7M 2.0M
11 399.4K 2.0M 2.4M
Hour In Out Sum
12 332.0K 1.6M 2.0M
13 630.1K 4.2M 4.8M
14 283.4K 1.6M 1.9M
15 466.7K 1.3M 1.7M
16 903.2K 7.4M 8.3M
17 760.1K 7.1M 7.8M
18 560.4K 1.9M 2.5M
19 301.9K 1.5M 1.8M
20 276.2K 2.1M 2.3M
21 271.2K 1.4M 1.7M
22 668.2K 3.9M 4.6M
23 138.6K 723.7K 862.3K
Hour In Out Sum
Sum 8.8M 59.5M 68.2M
Traffic via iptables
Target Bytes IN Bytes OUT Bytes Sum
www 1.2M 26.3M 27.5M
ftp 13.6K 16.2K 29.8K
ssh 231.7K 416.2K 647.9K
mail 41.8K 55.0K 96.9K
cvs 0 0 0
Andere 907.7K 575.2K 1.4M
Summe1.5M 26.8M 28.3M
CPU Usage
0.01
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.00
0.02
0.00
0.00
0.00
0.03
0.00
0.00
0.00
0.01
0.00
0.01
0.00
0.01
0.01
0.01
0.00
0.02
0.00
0.01
0.01
0.01
0.00
0.01
0.00
0.01
0.01
0.01
0.01
0.01
0.00
0.01
0.01
0.01
0.00
0.01
0.01
0.00
0.01
0.00
0.01
0.01
0.00
0.01
0.01
0.00
0.01
0.01
0.01
0.00
0.01
0.00
0.00
0.00
0.00
0.00
0.01
0.00
0.00
0.00
0.00
0.00
0.01
0.00
0.00
0.02
0.00
0.00
0.00
0.00
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
Hour 1st quater 2nd quater 3rd quater 4th quater Average
0 0.01 0.00 0.00 0.00 0.00
1 0.00 0.00 0.00 0.00 0.00
2 0.00 0.00 0.00 0.00 0.00
3 0.00 0.00 0.00 0.00 0.00
4 0.00 0.00 0.00 0.00 0.00
5 0.00 0.00 0.00 0.00 0.00
6 0.00 0.00 0.00 0.02 0.01
7 0.00 0.00 0.00 0.03 0.01
8 0.00 0.00 0.00 0.01 0.00
9 0.00 0.01 0.00 0.01 0.01
10 0.01 0.01 0.00 0.02 0.01
11 0.00 0.01 0.01 0.01 0.01
12 0.00 0.01 0.00 0.01 0.01
13 0.01 0.01 0.01 0.01 0.01
14 0.00 0.01 0.01 0.01 0.01
15 0.00 0.01 0.01 0.00 0.01
16 0.01 0.00 0.01 0.01 0.01
17 0.00 0.01 0.01 0.00 0.01
18 0.01 0.01 0.01 0.00 0.01
19 0.01 0.00 0.00 0.00 0.00
20 0.00 0.00 0.01 0.00 0.00
21 0.00 0.00 0.00 0.00 0.00
22 0.01 0.00 0.00 0.02 0.01
23 0.00 0.00 0.00 0.00 0.00
Web-Server
9.8M 2587 3.5M 124 3.4M 822 3.0M 213 2.9M 312 2.2M 273 2.1M 639 2.0M 201 1.9M 213 1.8M 309 1.5M 104 1.4M 1012 1.1M 243 896.6K 114 458.3K 22 356.0K 95 350.0K 103 349.9K 7 171.6K 54 115.9K 178 107.3K 29 84.2K 61 82.2K 15 81.8K 16 79.7K 56 64.5K 5 40.3K 5 9.6K 2 8.0K 3 4.2K 1 4.2K 1 1.4K 4 1.1K 7 1014 1 852 1 535 2 5 1
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37
VHost # bytes # Requests Status 2xx Status 3xx Status 4xx
1. domain1.de 9.8M 2587 1678 885 24
2. domain2.de 3.5M 124 84 40 0
3. www.domain3.de 3.4M 822 605 203 14
4. domain4.de 3.0M 213 165 41 7
5. www.domain5.de 2.9M 312 305 5 2
6. www.domain4.de 2.2M 273 209 54 10
7. www.domain6.de 2.1M 639 460 170 9
8. www.domain7.de 2.0M 201 195 3 3
9. domain3.de 1.9M 213 135 64 14
10. www.domain8.de 1.8M 309 246 43 20
11. srvreport.domain6.de 1.5M 104 87 5 12
12. www.web20.domain5.de 1.4M 1012 347 662 3
13. domain9.de 1.1M 243 241 0 2
14. jeremy.domain5.de 896.6K 114 84 4 26
15. domain10.de 458.3K 22 16 2 4
16. tobi.domain5.de 356.0K 95 7 88 0
17. domain8.de 350.0K 103 49 48 6
18. www.domain11.de 349.9K 7 5 0 2
19. www.domain12.de 171.6K 54 53 0 1
20. www.domain13.de 115.9K 178 24 153 1
21. www.domain14.de 107.3K 29 29 0 0
22. domain15.de 84.2K 61 5 0 56
23. www.domain16.de 82.2K 15 15 0 0
24. www.domain17.de 81.8K 16 15 1 0
25. markus.domain5.de 79.7K 56 52 4 0
26. forum.domain18.de 64.5K 5 3 1 1
27. domain5.de 40.3K 5 4 0 1
28. domain11.de 9.6K 2 1 0 1
29. domain6.de 8.0K 3 2 1 0
30. goi.domain8.de 4.2K 1 1 0 0
31. www.goi.domain8.de 4.2K 1 1 0 0
32. - 1.4K 4 0 0 4
33. www.domain15.de 1.1K 7 2 3 2
34. www.domain19.de 1014 1 1 0 0
35. %s 852 1 1 0 0
36. www.domain20.de 535 2 1 0 1
37. www.domain18.de 5 1 0 1 0
Summe 39.8M 7835 5128 2481 226
FTP-Server
187.4K 5 22.6K 5
1 2
VHost # bytes # Anfragen
1. web36 187.4K 5
2. web27 22.6K 5
Summe 210.0K 10
FTP-Logs

Sun May 02 08:32:02 2004 1 127.0.0.1 1069 /html/baustelle.gif b _ o r web36 ftp 0 * c
Sun May 02 08:33:15 2004 1 127.0.0.1 62720 /html/haupseite.jpg b _ i r web36 ftp 0 * c
Sun May 02 08:36:34 2004 1 127.0.0.1 62720 /html/haupseite.jpg b _ o r web36 ftp 0 * c
Sun May 02 08:36:42 2004 1 127.0.0.1 62720 /html/haupseite.jpg b _ o r web36 ftp 0 * c
Sun May 02 08:38:33 2004 1 127.0.0.1 2676 /html/hauptseite.html b _ i r web36 ftp 0 * c
Sun May 02 18:17:28 2004 1 62.246.131.191 3052 /html/Gebetsstunde.htm b _ i r web27 ftp 0 * c
Sun May 02 18:17:29 2004 1 62.246.131.191 767 /html/index.htm b _ i r web27 ftp 0 * c
Sun May 02 18:17:32 2004 2 62.246.131.191 3810 /html/Kontakt.htm b _ i r web27 ftp 0 * c
Sun May 02 18:17:34 2004 2 62.246.131.191 7717 /html/Termine.htm b _ i r web27 ftp 0 * c
Sun May 02 18:17:36 2004 1 62.246.131.191 7751 /html/Veranstaltungen.htm b _ i r web27 ftp 0 * c

Postfix
# IN # OUT Bytes IN Bytes OUT # Sum Bytes Sum
16 27 126.3K 107.6K 43 233.9K
To From # bytes Relay

webmaster@domain1.de(4x)

root@pxxxxxxxx.pureserver.info(4x) 75.2K mx01.schlund.de[212.227.126.211], mx01.schlund.de[212.227.126.164], mx01.schlund.de[212.227.126.140], REJECTED

root@pxxxxxxxx.pureserver.info

48.0K local

web11p1@pxxxxxxxx.pureserver.info(14x)

martin@domain3.de(14x)
hortenciacham@bigramp.com, Caleb@ameritech.net, tghgaxugl@email.com, 95g4@yyhmail.com, wjzcdu@f6.dion.ne.jp, on2hxibq@mail.dux.ru, fqlps@yahoo.com, ornaments@earthlink.net, MadgeHardy@up-to.net, behavior@rdominicana.com, lorenarushingjo@staminerboy.freeserve.co.uk, kndqh@yahoo.com, yjopwdx@yahoo.com.hk, patriarchybecalm@attbi.com 41.5K local(14x)

web30p3@pxxxxxxxx.pureserver.info

name.surename@domain11.de
root@extdom1.net 36.8K local

967323@gmx.de(2x)

friedy@domain3.de
fk@domain3.de
some_prov.87371217.191255.0@reply.some_prov.com, Dionys5475@wongfaye.com 26.8K mx0.gmx.de[213.165.64.100], mx0.gmx.net[213.165.64.100]

some-comp@t-online.de(2x)

martin@domain22.de(2x)
Robert@abc.de, Alexis@efgcom 5.6K mailin07.sul.t-online.de[194.25.134.75], mailin01.sul.t-online.de[194.25.134.72]

Passwort@domain3.de

0 REJECTED

n.sn@domain8.de

sk@my-wgt.de 0 REJECTED

martin@domain3.de(15x)

_Geiger@, vrsqcd@168.com, Beatty@, Gospelchor@domain3.de, _Marks@, Webmaster@vs.com, Kirk@, Passwort@lz.org, .Wynn@, VGKERSAHZG@hush.com, Beasley@, @, Crockett@, Leslie@, Khan@ 0 REJECTED(15x)

info@domain19.de

qfnavkcm@valudeal.com 0 REJECTED

talente@ok45mall.com

79gy9j79@sedtfse.com 0 REJECTED
Summe   233.9K  
To From Reject reason
martin@domain3.de Leslie@ RCPT from S010600402b2b 2044.cg.shawcable.net[6 8.146.114.180]: 504 <Leslie@>: Sender address rejected: need fully-qualified address;
martin@domain3.de Beatty@ RCPT from c3eea56e4.ca ble.wanadoo.nl[62.234.8 6.228]: 504 <Beatty@>: Sender address rejected: need fully-qualified address;
martin@domain3.de VGKERSAHZG@hush.com header Subject: Valium, Cialis, Phentermine, Xanax, Soma - All here from bzq-179-150-83.pop .bezeqint.net[212.179. 150.83];
webmaster@domain1.de root@pxxxxxxxx.pureserver.info body <td> header Subject: Generic Phentermine and other Weight Loss Drugs Prescribed for FREE from c-67-163- 4-208.client.comcast.n et[67.163.4.208];</td></ tr><tr class="mailRow2 "><td>name.surename@l gv-dink from local;
martin@domain3.de Webmaster@valvesoftware.com header Content-Type: application/octet-str eam; name=AMD-System.t xt.pif from pD95E9BB9. dip.t-dialin.net[217.9 4.155.185];
martin@domain3.de Passwort@liebenzell.org header Content-Type: application/octet-str eam; name=Benutzer-Dat en.pif from pD95E9BB9. dip.t-dialin.net[217.9 4.155.185];
info@domain19.de qfnavkcm@valudeal.com RCPT from pcp03118394p cs.elkton01.md.comcast .net[68.33.5.215]: 550 <info@ettlingen.or g>: User unknown in virtual alias table;
martin@domain3.de Beasley@ RCPT from pcp01378323p cs.selrsv01.pa.comcast .net[68.81.96.74]: 504 <Beasley@>: Sender address rejected: need fully-qualified address;
martin@domain3.de Khan@ RCPT from c-24-1-246-13 6.client.comcast.net[2 4.1.246.136]: 504 <Khan@>: Sender address rejected: need fully-qualified address;
martin@domain3.de _Geiger@ RCPT from 178.54-136-21 7.adsl.skynet.be[217.1 36.54.178]: 504 <_Geiger@>: Sender address rejected: need fully-qualified address;
martin@domain3.de Crockett@ RCPT from 215.007.dsl. nsw.iprimus.net.au[210 .50.160.215]: 504 <Crockett@>: Sender address rejected: need fully-qualified address;
martin@domain3.de vrsqcd@168.com RCPT from S010600207810 b988.cg.shawcable.net[6 8.145.166.134]: 450 <vrsqcd@168.com>: Sender address rejected: Domain not found;
talente@ok45mall.com 79gy9j79@sedtfse.com RCPT from unknown[221 .155.192.247]: 554 <talente@ok45mall.com> : Relay access denied;
martin@domain3.de _Marks@ RCPT from c-24-3-119-10 9.client.comcast.net[2 4.3.119.109]: 504 <_Marks@>: Sender address rejected: need fully-qualified address;
n.sn@domain8.de sk@my-wgt.de header Content-Type: application/octet-str eam; name=Passwoerter. txt.pif from dialin-2 12-144-174-039.arcor-ip .net[212.144.174.39];
Passwort@domain3.de RCPT from relay1.tisc ali.de[62.26.116.129]: 550 <Passwort@ec-altbu lach.de>: User unknown in virtual alias table;
martin@domain3.de @ RCPT from pcp03418803p cs.eorang01.nj.comcast .net[68.36.43.9]: 504 <@>: Sender address rejected: need fully-qualified address;
martin@domain3.de Kirk@ RCPT from user-0cal5ku .cable.mindspring.com[ 24.170.150.158]: 504 <Kirk@>: Sender address rejected: need fully-qualified address;
martin@domain3.de .Wynn@ RCPT from c-24-126-10-1 60.we.client2.attbi.co m[24.126.10.160]: 504 <.Wynn@>: Sender address rejected: need fully-qualified address;
martin@domain3.de Gospelchor@domain3.de header Content-Type: application/octet-str eam; name=Dokument.pif from pD95E9BB9.dip.t-d ialin.net[217.94.155.18 5];
Username # Checks Check-Time
web14p1 3 04:05 09:05 21:03
web1p1 282 07:23-09:32 (65x) 13:54-17:13 (98x) 17:58-21:34 (107x) 22:08-22:32 (12x)
web24p1 23 07:45 07:53 08:04-08:05 (2x) 09:34 09:42 13:44-13:49 (2x) 15:32 15:43 15:50 17:12-17:17 (2x) 17:23 17:30-17:33 (2x) 17:43-17:44 (2x) 18:03 18:13 18:19 22:48-22:51 (2x)
web30p3 1 22:21
web7p1 281 07:23-09:32 (65x) 13:54-17:13 (98x) 17:58-21:34 (106x) 22:08-22:32 (12x)
Warnings

May 2 01:31:46 pxxxxxxxx postfix/smtpd[3180]: warning: 200.170.138.131: hostname prs-rawnet-131.ctbctelecom.com.br verification failed: Host not found
May 2 08:27:11 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:27:36 pxxxxxxxx last message repeated 2 times
May 2 08:28:16 pxxxxxxxx last message repeated 2 times
May 2 08:31:18 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:32:21 pxxxxxxxx last message repeated 4 times
May 2 08:33:15 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:34:14 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:34:29 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:36:18 pxxxxxxxx last message repeated 3 times
May 2 08:36:57 pxxxxxxxx last message repeated 5 times
May 2 08:38:14 pxxxxxxxx last message repeated 4 times
May 2 08:38:33 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 08:40:13 pxxxxxxxx last message repeated 4 times
May 2 18:16:57 pxxxxxxxx vsftpd: PAM-listfile: Couldn't open /etc/ftpusers
May 2 18:17:25 pxxxxxxxx last message repeated 3 times

Last logins

root pts/0 Sun May 2 08:00 - 08:01 (00:00) p508356eb.dip0.t-ipconnect.de
root pts/0 Sun May 2 07:56 - 08:00 (00:03) p508356eb.dip0.t-ipconnect.de
root pts/0 Sun May 2 07:41 - 07:42 (00:00) p508356eb.dip0.t-ipconnect.de

Check for Rootkit

Checking `bindshell'... INFECTED (PORTS: 465)

System information
Mounted Filesystems
Mount Typ Partition Percent Capacity Free Used Size
/ ext3 /dev/hda3 16% 16% 29.3G 6.1G 37.2G
/boot ext3 /dev/hda1 9% 9% 210.8M 24.2M 248.0M
/dev/shm shm shmfs 0% 0% 121.1M 0 121.1M
Sum     16% 16% 29.6G 6.1G 37.6G
Memory usage
Typ Percent Capacity Free Used Size
Mem 95% 95% 10.7M 231.5M 242.2M
Swap 8% 8% 235.7M 23.2M 258.9M

SrvReport Version 0.65