Someone or some process from the 95.xx.xx.xx server is connecting to this server and doing a partial SMTP transaction but ending it with a quit.
That's what I thought too...... someone or some process on the 95.* server must be trying this. Problem is, I can't find any proof of it in the 95.* server, not in exim logs and neither in php-mail.log files of users. And that is the problem I'm having with this, that I can't find where it's coming from.
Even Maldetect has not found anything yet.
Sender callouts... if that is not enabled by default then no I don't have it on any server.
There's nothing inherently malicious with any of this. Unless you consider checking for the existence of the
[email protected] email address to be malicious.
Yes it is malicious because it shouldn't come from a non existing mail address on the 95.* server anyway. Next to that, it's not 1 address of customerdomain.nl but things like
[email protected] [email protected] and so on, like 50 of them at 1 time. To me that is malicous.
It's normal that spammer try this, but then they directly login or try to send to the vps were customerdomain.nl resides and then I wouldn't be worried.
But in this case, my own 95.* servers is trying to send mail from non-local addresses to my external vps on the 173.* ip. That is relaying and should not be possible. Or it's something from my own 95.* server, and then it's malicious too.
Is that server configured to relay mail through the server you caught the log on?
Not that I know of. It's a default exim.conf. No relaying customisations.
The server I cought the log on is a VPS we are temporarily using with a 173 ip address.
That botnet list is interesting, you can add 46.148.40.* to that list.
Code:
2023-08-27 00:45:58 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=netops)
2023-08-27 00:50:46 login authenticator failed for ([185.36.81.16]) [185.36.81.16]: 535 Incorrect authentication data (set_id=bank)
2023-08-27 00:51:05 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=metabase)
2023-08-27 00:56:19 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=katalog)
2023-08-27 01:00:08 login authenticator failed for (User) [79.110.62.182]: 535 Incorrect authentication data (set_id=user)
2023-08-27 01:01:09 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=manage-vps)
2023-08-27 01:06:15 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=mvp)
2023-08-27 01:06:35 login authenticator failed for (localhost) [46.148.40.77]: 535 Incorrect authentication data (set_id=5555)
2023-08-27 01:10:54 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=myriam)
2023-08-27 01:11:01 login authenticator failed for (localhost) [46.148.40.94]: 535 Incorrect authentication data (set_id=ky)
2023-08-27 01:12:01 login authenticator failed for (localhost) [46.148.40.77]: 535 Incorrect authentication data (set_id=esf)
2023-08-27 01:16:09 login authenticator failed for (localhost) [46.148.40.94]: 535 Incorrect authentication data (set_id=rekrutacja)
2023-08-27 01:16:22 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=page_options)
2023-08-27 01:16:58 login authenticator failed for (localhost) [46.148.40.77]: 535 Incorrect authentication data (set_id=columbia)
2023-08-27 01:21:07 login authenticator failed for (localhost) [46.148.40.94]: 535 Incorrect authentication data (set_id=pos)
2023-08-27 01:21:29 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=miffy)
2023-08-27 01:21:56 login authenticator failed for (localhost) [46.148.40.77]: 535 Incorrect authentication data (set_id=pannello)
2023-08-27 01:26:16 login authenticator failed for (localhost) [46.148.40.94]: 535 Incorrect authentication data (set_id=Aries)
2023-08-27 01:26:26 login authenticator failed for (localhost) [46.148.40.195]: 535 Incorrect authentication data (set_id=nizhnevartovsk)
etc..
Got a couple of hundreds of them in the log. But these are "normal" attacks.
As for my issue, I did notice that they were trying the same customerdomain.nl every time. Also with .ru mail address like this:
So same as the .cz but now with .ru from address.