WARNING
The
SMF forum hosting software is vulnerable to a nasty breach that acts like a
Trojan Horse using your site's resources as a spamming server and possibly a proxy. If you're running on default SMF installation
permissions you are likely to be already affected. Compare your
Themes/default directory contents with the virgin SMF distribution to tell.
The attack seems to be carried out by fake Google and Bing bots. It seems Wordpress and MediaWiki are other packages the breach is targeting. Fortunately WP and Mediawiki isn't installed on any of the sites I host.
I'm amazed by how much of the traffic to your website is bots.
I have spent a couple days tracking down the cause and effect and building a security model that will hopefully prevent it from happening again.
Good luck with this!
On a side note I was please to learn that Gitlab-ce installs
OWASP ModSecurity by default.