Hi,
I have a question. Few days ago I checked rejectlog (because has a strange big size - about 100MB) of exim and I saw this.
Many differents IP are trying to connect via SMTP and every IP sending this in input.
I listed top o 50 rejected IPs and blocked in firewall.
I have question. Anyone has a idea what is this?
It's looks like this IPs want to connect via encrypted channel?
Any other ideas? It's a brute force attack?
Thanks!
Michael
I have a question. Few days ago I checked rejectlog (because has a strange big size - about 100MB) of exim and I saw this.
Many differents IP are trying to connect via SMTP and every IP sending this in input.
I listed top o 50 rejected IPs and blocked in firewall.
I have question. Anyone has a idea what is this?
It's looks like this IPs want to connect via encrypted channel?
Any other ideas? It's a brute force attack?
Thanks!
Michael
Code:
2013-08-25 03:32:18 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=host86-136-168-91.range86-136.btcentralplus.com [86.136.168.91] input="mÍ^ä/6óŽ—(>ç=›18>ŘÖ‰Uč˛Ůň%©\034\034\031W'x»Ťl\b[Jż‰ýż7 ŃfÁ/Y׬u÷*\020é\177´{Ó\rx‰BżcU\nÚcÖP* ¦Ŕm75Řžv\fŕ©Qxk¦\007A¦ÂÂ>‰˘¬\033‡O^ć\004@HĆ\003ă8ňŘL\024ˇ\017AÔá˛ĺ´\032đ™şĆ˘¬bPbĺ ?Đz©\003‚,A\022T o"
2013-08-25 03:32:37 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=host-92-29-208-175.as13285.net [92.29.208.175] input="\022÷HqŮ8wţąŞ¦’\035.\004;e4fVÉ˝·un7\002ą"\n˛\026\005–É<É"é¬řK\007„X@&[*Br\037-b]ۆ}Řě^ś¶ó|ÁNü(޲iŹűÚŽ\005—sŤ;d”rUR![vO‚Ą””††°zOrDEÖˇę?XX\006Ř\032·*g\b™ą\025ĚČâ\b°"€É”óŁtm\vľL¨zŘ*Đ5öďŰu\024ĚŐ"
2013-08-25 03:32:38 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=111-241-253-205.dynamic.hinet.net [111.241.253.205] input="t\027˙n_ľwäf©¸ä\030ŕ/p3\037çmsŞápůŁ5ćŁÚ¬q§s\022r*˛[ĺ\031L×ç„7\030č®{úpâ\023ňć!E¬q•Ď¦th\fu\025\001ruą±Őę(Řźs\n\v“é€\bZt´*QęŰŇťę\177ˇ™uűťuëw›<vÎż\035yŢXyQ‹Ďy\002˘Lď3áµz†úQxw”_đ\017†ÖôéTĽ}młů}˛¤"
2013-08-25 03:32:42 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=s0106c8be19630369.vc.shawcable.net [96.49.44.19] input="™;ÉѧC‹ \v*`*\034X_MoÎŹt\003ĺjś‹3Ŕ˝\001Ę\020â™;\006\004Mç„*(ĹOQ¤ßluŃf&\177Qůş&hćÝa,ë˙çŰr#tm"G&…™Ŕ\032\022F[Aó#\007¦A\016+¦‰™O#éčoź\003\006”\006Nf.Y—'Ü$+\027ý\vRŞ—\005\030@Âë\022"ĺę\021z„Äţ«2\033íÍH7AńČ)č\0261ô;ĺµ"
2013-08-25 03:32:47 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=[86.98.20.107] input="Š\020™‚4bĽ˘ş¤ź\030dµÄąľQ:3jXŞČĄD\026Y?wßţhpMyŢč\f\032¬*Aš-|i-*jşZK„M)‘[Đb\031¤lIJěáŔ=Ń|XgU\b±‚ngqR&‡ĄYľOoŰT§\b\034îyÓśu‰\021Ü żó¤›#`/‘¨BµŽú*PÁ\022cŘĘFĄiř(nűř•Z"
2013-08-25 03:32:48 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=141-105-194-82.ipgate.co.uk [141.105.194.82] input="cţť1 –h\002Ąj‰ďş\036Z«†XşH\023˛ËTŚ‰.§t'ę—=\007úp"
2013-08-25 03:33:04 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=[89.148.9.45] input="wűP2ŕ\ăö»Ű÷ŐŇäią<Ć•™Ôđˇ°EI*šÂč”wÖ\nČLŁ›7\030ÚR˝ŘămŠ¨őč\016]h.®Ôˇ*#•(\032}z9gŰ\037éĚFL„w©Ľ\004EZ¤µ\bÔ÷ů´8:‰:¦5ËÂ\016釥\025ŢjĽ)DŘ\0164şBE>ł•ČV”1éwa\033\vr"
2013-08-25 03:33:08 SMTP protocol synchronization error (input sent without waiting for greeting): rejected connection from H=199-192-80-54.static.wiline.com [199.192.80.54] input="lD´\vŇ?Ş\035ęöď#íV2*\006$"