one of my domain get hundreds spam each minutes, here is the report of the Brute Force
The remote system 59.37.80.127 was found to have exceeded acceptable login failures on quicktrack.techscape.co.id; there was 66 events to the service exim. As such the attacking host has been banned from further accessing this system. For the integrity of your host you should investigate this event as soon as possible.
Executed ban command:
/etc/apf/apf -d 59.37.80.127 {bfd.exim}
The following are event logs from 59.37.80.127 on service exim (all time stamps are GMT +0700):
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:16 no host name found for IP address 59.37.80.127
2006-05-23 03:08:16 no host name found for IP address 59.37.80.127
2006-05-23 03:08:20 H=(lop10a.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (lop10a.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(qon.lao.net) [59.37.80.127] F=<r[email protected]> rejected RCPT <[email protected]>: Message rejected (qon.lao.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(sahkoposti.zzn.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (sahkoposti.zzn.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(chathamnc.every1.net) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (chathamnc.every1.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(pokemates.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (pokemates.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(pokemates.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (pokemates.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(sahkoposti.zzn.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (sahkoposti.zzn.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(lop10a.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (lop10a.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(chathamnc.every1.net) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (chathamnc.every1.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
Here is the another one, what should I do
F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:03 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:03 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:04 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:05 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:07 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:07 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:11 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:12 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:12 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:13 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:14 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:15 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:16 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:19 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:19 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:20 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:22 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:24 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:26 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:27 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:28 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
The remote system 59.37.80.127 was found to have exceeded acceptable login failures on quicktrack.techscape.co.id; there was 66 events to the service exim. As such the attacking host has been banned from further accessing this system. For the integrity of your host you should investigate this event as soon as possible.
Executed ban command:
/etc/apf/apf -d 59.37.80.127 {bfd.exim}
The following are event logs from 59.37.80.127 on service exim (all time stamps are GMT +0700):
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:13 no host name found for IP address 59.37.80.127
2006-05-23 03:08:16 no host name found for IP address 59.37.80.127
2006-05-23 03:08:16 no host name found for IP address 59.37.80.127
2006-05-23 03:08:20 H=(lop10a.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (lop10a.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(qon.lao.net) [59.37.80.127] F=<r[email protected]> rejected RCPT <[email protected]>: Message rejected (qon.lao.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(sahkoposti.zzn.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (sahkoposti.zzn.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(chathamnc.every1.net) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (chathamnc.every1.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:20 H=(pokemates.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (pokemates.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(pokemates.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (pokemates.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(sahkoposti.zzn.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (sahkoposti.zzn.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(lop10a.com) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (lop10a.com) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
2006-05-23 03:08:21 H=(chathamnc.every1.net) [59.37.80.127] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (chathamnc.every1.net) [59.37.80.127] is blacklisted at cbl.abuseat.org see dnslist_text
Here is the another one, what should I do
F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:03 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:03 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:04 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:05 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:07 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:07 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:11 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:12 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:12 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:13 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:14 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:15 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:16 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:19 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:19 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:20 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:22 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:24 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:26 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:27 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text
2006-05-23 03:05:28 H=(4D169008) [80.73.221.149] F=<[email protected]> rejected RCPT <[email protected]>: Message rejected (4D169008) [80.73.221.149] is blacklisted at bl.spamcop.net see dnslist_text