Skip to main content

Primary Hostname Sending spam

Comments

7 comments

  • quietFinn
    That shows 2 accounts, gmorone & csad, sending spam.
    0
  • philwebservices
    Hi @quietFinn, Yep but I can say that these accounts are non-existent and keeps changing all the time, in fact ns1.wizkidhosting.com is the primary domain and does not have a default mailbox
    0
  • quietFinn
    There is no such a thing as "primary domain", in the exim log you can see the usernames where the mails are sent from (i.e. form USERNAME@HOSTNAME). If those users are not cPanel users I'd think that your server is compromised. Check what users you have in /home directory.
    0
  • Spirogg
    @philwebservices when I tried to access your site I got this in my browser. Website blocked due to a Trojan Your Malwarebytes Premium blocked this website because it may contain a Trojan. We strongly recommend you do not continue. @quietFinn seems to be correct, you are compromised unfortunately
    0
  • philwebservices
    Thanks for the input, will have this scanned entirely
    0
  • philwebservices
    Scanned the server and found the php file culprit :) Thank you all!
    0
  • Spirogg
    Scanned the server and found the php file culprit :) Thank you all!

    I"m Glad you found it and hopefully all is well and resolved.
    0

Please sign in to leave a comment.