Skip to main content

Suspicious process running under user mailnull

Comments

4 comments

  • GOT
    The process you have included appears to be mailscanner which by itself is fine and worth of an exception I your csf ignore file. That doesn't necessarily mean that you were not hacked though, but if so the evidence would be elsewhere.
    0
  • brock41
    Would mailscanner consistently try to connect to IP address 5.9.xxx.xx through port 24441? I have 18 emails from today of that same log. The same IP address and same port number.
    0
  • GOT
    I never use mailscanner, so I can't really comment for sure, but is that port open in your firewall for outbound connections? It may be checking some list, blocklist, abuse list, etc, I really don't know.
    0
  • cPanelLauren
    @brock41 The IP it's connecting to belongs to the Spam Filtering service SpamExperts. This is normal behavior and none of this looks suspicious from what's been provided thus far. As suggested by @GOT I'd add the mailnull process to the csf ignore list to stop notifications for this specific issue.
    0

Please sign in to leave a comment.