castris
Verified User
Last night I had a spam attack where a user is sending spam.
After analyzing the issue:
After analyzing the issue:
- The email accounts do not exist on the server.
- The email is not authenticated.
- I can't understand this method of access and sending (understand how it is possible) as it is the first time in my life that I see something like this.
Is there any solution?
Bash:
cat /var/log/exim/mainlog| grep ":25:0:127.0.0.1:1080:socks5:25:"
2025-05-11 23:19:31 1uEFxC-0000000CHzy-3bCH <= [email protected] H=(mail.customer-domain.tld) [165.154.242.35] P=esmtp S=1079 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-11 23:19:31 1uEFxC-0000000CI00-3poo <= [email protected] H=(smtp.customer-domain.tld) [165.154.242.35] P=esmtp S=966 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 17:50:36 1uFcj5-00000004BwS-4BTn <= [email protected] H=(mail.customer-domain.tld) [165.154.233.184] P=esmtp S=914 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 17:50:36 1uFcj6-00000004BwQ-01DG <= [email protected] H=(smtp.customer-domain.tld) [165.154.233.184] P=esmtp S=888 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 21:44:10 1uFgN8-00000006otG-2Gzf <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=971 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 21:45:54 1uFgOo-00000006peY-1KkR <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=761 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:06 1uFhRq-00000009qGH-22N5 <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=827 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:06 1uFhRq-00000009qGw-2Jcp <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=961 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:06 1uFhRq-00000009qGg-2Lac <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=841 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:07 1uFhRr-00000009qIr-16lU <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=969 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:09 1uFhRt-00000009qMV-0r2s <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=926 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:09 1uFhRt-00000009qMX-1XYg <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=761 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:10 1uFhRu-00000009qPO-0PEK <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=1055 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:17 1uFhS1-00000009qif-24RQ <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=998 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:37 1uFhSK-00000009rYU-3xdE <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=864 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:37 1uFhSL-00000009raR-1GlC <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=715 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:39 1uFhSN-00000009rfU-2b3i <= [email protected] H=(smtp.customer-domain.tld) [172.111.9.180] P=esmtp S=806 T="smtp.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]
2025-05-15 22:53:40 1uFhSO-00000009rjO-3HGA <= [email protected] H=(mail.customer-domain.tld) [172.111.9.180] P=esmtp S=936 T="mail.customer-domain.tld:25:0:127.0.0.1:1080:socks5:25:" from <[email protected]> for [email protected]