I'm including a section of the fail2ban logs the day it seems like fail2ban went down if anyone wants to analyze it. It may show evidence of a malicious script taking down my firewall but I'm not sure. Also in the Auth logs during the same time I see these two lines:
Oct 18 06:33:57 jello useradd[3800320]: new group: name=csf, GID=10001
Oct 18 06:33:57 jello useradd[3800320]: new user: name=csf, UID=10001, GID=10001, home=/home/csf, shell=/bin/false, from=none
Which GPT thinks is related to Config Server Firewall but I don't remember installing that, or doing any work on the server on that day.
What could it mean?
OH I guess I can't attach text files... ok here is the fail2ban log file snippet:
First 10 or so lines are normal operation (la de da de da..) :
2024-10-18 04:57:50,239 fail2ban.filter [933]: INFO [ssh] Found 217.170.194.48 - 2024-10-18 04:57:50
2024-10-18 04:57:50,339 fail2ban.actions [933]: NOTICE [ssh] Ban 217.170.194.48
2024-10-18 04:57:50,343 fail2ban.filter [933]: INFO [recidive] Found 217.170.194.48 - 2024-10-18 04:57:50
2024-10-18 05:39:34,255 fail2ban.filter [933]: INFO [ssh] Found 58.96.88.213 - 2024-10-18 05:39:34
2024-10-18 05:39:35,398 fail2ban.filter [933]: INFO [ssh] Found 58.96.88.213 - 2024-10-18 05:39:35
2024-10-18 05:39:35,488 fail2ban.actions [933]: NOTICE [ssh] Ban 58.96.88.213
2024-10-18 05:39:35,495 fail2ban.filter [933]: INFO [recidive] Found 58.96.88.213 - 2024-10-18 05:39:35
2024-10-18 06:12:50,657 fail2ban.filter [933]: INFO [ssh] Found 13.64.193.117 - 2024-10-18 06:12:50
2024-10-18 06:33:07,414 fail2ban.server [933]: INFO Shutdown in progress...
2024-10-18 06:33:07,416 fail2ban.observer [933]: INFO Observer stop ... try to end queue 5 seconds
2024-10-18 06:33:07,437 fail2ban.observer [933]: INFO Observer stopped, 0 events remaining.
2024-10-18 06:33:07,478 fail2ban.server [933]: INFO Stopping all jails
2024-10-18 06:33:07,481 fail2ban.filter [933]: INFO Removed logfile: '/var/log/auth.log'
2024-10-18 06:33:07,481 fail2ban.filter [933]: INFO Removed logfile: '/var/log/fail2ban.log'
2024-10-18 06:33:07,482 fail2ban.filter [933]: ERROR Unable to get failures in /var/log/fail2ban.log
2024-10-18 06:33:07,482 fail2ban.filter [933]: INFO Removed logfile: '/var/log/auth.log'
2024-10-18 06:33:07,496 fail2ban.filter [933]: INFO Removed logfile: '/var/log/maillog'
2024-10-18 06:33:07,496 fail2ban.filter [933]: INFO Removed logfile: '/var/log/maillog'
2024-10-18 06:33:07,496 fail2ban.filter [933]: INFO Removed logfile: '/var/log/plesk-roundcube/errors'
2024-10-18 06:33:07,497 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/error_log'
2024-10-18 06:33:07,497 fail2ban.filter [933]: INFO Removed logfile: '/var/log/apache2/error.log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/proxy_access_ssl_log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/access_ssl_log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/access_log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/proxy_access_log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/log/apache2/access.log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/log/apache2/other_vhosts_access.log'
2024-10-18 06:33:07,512 fail2ban.filter [933]: INFO Removed logfile: '/var/log/plesk/panel.log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/log/modsec_audit.log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/proxy_access_ssl_log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/access_ssl_log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/access_log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/www/vhosts/system/woundxed.com/logs/proxy_access_log'
2024-10-18 06:33:07,513 fail2ban.filter [933]: INFO Removed logfile: '/var/log/apache2/access.log'
2024-10-18 06:33:07,514 fail2ban.filter [933]: INFO Removed logfile: '/var/log/apache2/other_vhosts_access.log'
2024-10-18 06:33:07,537 fail2ban.actions [933]: NOTICE [plesk-postfix] Flush ticket(s) with iptables-multiport
2024-10-18 06:33:07,537 fail2ban.actions [933]: NOTICE [plesk-one-week-ban] Flush ticket(s) with iptables-allports
2024-10-18 06:33:07,538 fail2ban.actions [933]: NOTICE [plesk-permanent-ban] Flush ticket(s) with iptables-allports
2024-10-18 06:33:07,556 fail2ban.actions [933]: NOTICE [plesk-permanent-ban] Unban 183.81.169.238
2024-10-18 06:33:07,557 fail2ban.actions [933]: NOTICE [plesk-permanent-ban] Unban 64.227.156.104
2024-10-18 06:33:07,557 fail2ban.actions [933]: NOTICE [plesk-permanent-ban] Unban 60.191.20.210
2024-10-18 06:33:07,618 fail2ban.actions [933]: NOTICE [plesk-dovecot] Flush ticket(s) with iptables-multiport
2024-10-18 06:33:07,620 fail2ban.actions [933]: NOTICE [plesk-apache-badbot] Flush ticket(s) with iptables-multiport-BadBots
2024-10-18 06:33:07,621 fail2ban.actions [933]: NOTICE [plesk-roundcube] Flush ticket(s) with iptables-multiport
2024-10-18 06:33:07,621 fail2ban.actions [933]: NOTICE [plesk-wordpress] Flush ticket(s) with iptables-multiport
2024-10-18 06:33:07,622 fail2ban.actions [933]: NOTICE [plesk-apache] Flush ticket(s) with iptables-multiport-apache
2024-10-18 06:33:07,624 fail2ban.actions [933]: NOTICE [plesk-panel] Flush ticket(s) with iptables-multiport-plesk-login
2024-10-18 06:33:07,680 fail2ban.actions [933]: NOTICE [ssh] Flush ticket(s) with iptables
2024-10-18 06:33:07,701 fail2ban.actions [933]: NOTICE [ssh] Unban 85.221.48.115
2024-10-18 06:33:07,702 fail2ban.actions [933]: NOTICE [ssh] Unban 167.172.190.187
2024-10-18 06:33:07,702 fail2ban.actions [933]: NOTICE [ssh] Unban 64.23.178.20
2024-10-18 06:33:07,703 fail2ban.actions [933]: NOTICE [ssh] Unban 221.229.218.50
2024-10-18 06:33:07,703 fail2ban.actions [933]: NOTICE [ssh] Unban 122.179.128.202
2024-10-18 06:33:07,703 fail2ban.actions [933]: NOTICE [ssh] Unban 206.189.61.144
2024-10-18 06:33:07,703 fail2ban.actions [933]: NOTICE [ssh] Unban 182.70.119.240
. . . and it goes on unbanning every bot