Skip to main content

Spam issue - lmtp(15774): Connect from local

Comments

6 comments

  • cPRex Jurassic Moderator
    Hey there! That entry looks like it is from /var/log/maillog. Can you check the /var/log/exim_mainlog file around the same time to see if there is anything interesting there?
    0
  • Kennybe
    2022-06-02 12:51:44 SMTP connection from [165.227.206.111]:38100 (TCP/IP connection count = 3) 2022-06-02 12:51:44 no host name found for IP address 165.227.206.111 2022-06-02 12:51:46 H=(mail.asticom.com) [165.227.206.111]:38100 Warning: Sender rate 1.0 / 1h 2022-06-02 12:51:48 1nwiQe-00048B-6G <= xxx@xxx.com H=(mail.asticom.com) [165.227.206.111]:38100 P=esmtpsa X=TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256 CV=no A=dovecot_plain:xxx@xxx.com S=1175 id=45BE855A-8614-4C82-B718-AC93BCAF7DC0@xxx.com T="\357\273\277" for desjourspatrick@hotmail.fr jean-claude.ouamrane@orange.fr claude.ouamrane@orange.fr jpl.jpl.mail@gmail.com bernard.souchon30@orange.fr alain.brigoulet@libertysurf.fr thierry.bernardet0826@orange.fr alifak@hotmail.fr jpbremond@wanadoo.fr hermes04@orange.fr 2022-06-02 12:51:48 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1nwiQe-00048B-6G 2022-06-02 12:51:48 1nwiQe-00048B-6G Sender identification U=asticom D=asticom.com S=xxx@xxx.com 2022-06-02 12:51:48 1nwiQe-00048B-6G SMTP connection outbound 1654167108 1nwiQe-00048B-6G xxx.com hermes04@orange.fr 2022-06-02 12:51:48 1nwiQe-00048B-6G Sender identification U=asticom D=asticom.com S=xxx@xxx.com 2022-06-02 12:51:48 1nwiQe-00048B-6G SMTP connection outbound 1654167108 1nwiQe-00048B-6G xxx.com jpbremond@wanadoo.fr 2022-06-02 12:51:48 1nwiQe-00048B-6G Sender identification U=asticom D=asticom.com S=xxx@xxx.com and more lines like the last one ...
    0
  • cPRex Jurassic Moderator
    Do any of those messages match up to the one you're looking for? I'm not going to recognize anything useful on my end, but the 12:51:48 timestamp line seems to be sending a group of messages at once.
    0
  • Kennybe
    It is the spammer ... each time when I receive a mail that the mail limit is exceeded, the same pattern occurs in mainlog and exim maillog. Today I had 5 mails ...
    0
  • cPRex Jurassic Moderator
    When the log shows "Connect from local" that would mean a webmail connection, or access to webmail through cPanel. I wonder if that user has malware on their local system that is contributing to password changes not working. It would be worth having any users with access to that cPanel account scan their local system for viruses or key loggers.
    0
  • Kennybe
    Strange ... I changed the password on an iOs device, Mac and a Windows PC from the army (I think the last one would be very strange if there was a keylogger). Noticed two times that the Facebook account registered with the same email address is hacked ... (password recovery via mail). Now scanning my two Macs on viruses and other stuff ...
    0

Please sign in to leave a comment.