The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Server Sending Spam Problem

Discussion in 'E-mail Discussions' started by drupalin, Dec 30, 2016.

Tags:
  1. drupalin

    drupalin Registered

    Joined:
    Dec 30, 2016
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Madrid
    cPanel Access Level:
    Root Administrator
    Hi everyone, i´m kind of desesperate, my server sends spam from email acounts very similar to the real one.

    Real Mail Account: info@example.com

    Spammers:
    info115@example.com
    info116@example.com
    info117@example.com
    info118@example.com
    info119@example.com
    ....

    After of write this: grep cwd /var/log/exim_mainlog|grep -v /var/spool|awk -F"cwd=" '{print $2}'|awk '{print $1}'|sort|uniq -c|sort -n

    I get this details:
    Code:
    1 /home/biovidrio/public_html
    
    1 /home/meollo/public_html
    
    1 /home/tyd/public_html
    
    1 /home/webes/public_html/base
    
    1 /home/webes/public_html/clinicadental
    
    1 /home/webes/public_html/serviamb
    
    1 /var/log
    
    2 /home/adventurerooms/public_html
    
    2 /home/webes/public_html/tienda
    
    3 /home/enigmabohemia/public_html
    
    3 /home/legionella/public_html
    
    4 /home/ruraly/public_html
    
    4 /home/webes/public_html
    
    4 /home/webtematica/public_html
    
    5 /home/actormania/public_html
    
    5 /home/albertogorgojo/public_html
    
    5 /home/algodonmerlin/public_html
    
    5 /home/antonioaznar/public_html
    
    5 /home/elperiodismo/public_html
    
    5 /home/fisioterapia/public_html
    
    5 /home/fontanerosmadrid/public_html
    
    5 /home/inmobiliaria/public_html
    
    5 /home/kristianboys/public_html
    
    5 /home/serviamb/public_html
    
    6 /home/disenowebmadrid/public_html
    
    7 /home/costurasnontol/public_html
    
    7 /home/cursoderevit/public_html
    
    8 /tmp
    
    14 /home/portalclasico/public_html
    
    78 /
    
    110 /usr/local/apache/domlogs/portalclasico
    
    181 /home
    
    960 /root
    
    6748 /usr/local/cpanel/whostmgr/docroot
    
    
    So it seems its root user witch sends spam, but i can not find a way to get the spammer script


    Thanks very much
     
    #1 drupalin, Dec 30, 2016
    Last edited by a moderator: Dec 30, 2016
  2. SysSachin

    SysSachin Well-Known Member

    Joined:
    Aug 23, 2015
    Messages:
    542
    Likes Received:
    39
    Trophy Points:
    28
    Location:
    India
    cPanel Access Level:
    Root Administrator
    Twitter:
    Hello,

    It's seems the mail sending from account using php mail script. I think there is infected file under the account which is sending mails.

    Please try to check logs using below command so that you will get account account which is sending mail.

    Code:
    tail -n2000 /var/log/exim_mainlog|grep /home/
    
     
  3. drupalin

    drupalin Registered

    Joined:
    Dec 30, 2016
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Madrid
    cPanel Access Level:
    Root Administrator
    Thanks for the replay, i´m only get this details:

    Code:
    2016-12-30 11:42:37 [3507] cwd=/home/someusr/public_html 4 args: /usr/sbin/sendmail -t -i -finfo@example.com
     
    #3 drupalin, Dec 30, 2016
    Last edited by a moderator: Dec 30, 2016
  4. SysSachin

    SysSachin Well-Known Member

    Joined:
    Aug 23, 2015
    Messages:
    542
    Likes Received:
    39
    Trophy Points:
    28
    Location:
    India
    cPanel Access Level:
    Root Administrator
    Twitter:
  5. rpvw

    rpvw Well-Known Member

    Joined:
    Jul 18, 2013
    Messages:
    260
    Likes Received:
    76
    Trophy Points:
    28
    Location:
    Spain
    cPanel Access Level:
    Root Administrator
    Remember this may not be an infected script, and may not be detected by antivirus or malware detection software.

    Check for things like unpatched versions ( eg PHPMailer that has just had 2 critical updates in 3 days, and which may well be being actively exploited.) and any other php scripts that might be installed.
     
  6. drupalin

    drupalin Registered

    Joined:
    Dec 30, 2016
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Madrid
    cPanel Access Level:
    Root Administrator
    Thanks for the replay, i check with malded and clam, but not show results, about PHPMailer, not know what to do or update

    Any ideas, thanks very much in advance and happy new year
     
    #6 drupalin, Dec 30, 2016
    Last edited by a moderator: Dec 31, 2016
  7. drupalin

    drupalin Registered

    Joined:
    Dec 30, 2016
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Madrid
    cPanel Access Level:
    Root Administrator
    I repeat the grep cwd /var/log/exim_mainlog|grep -v /var/spool|awk -F"cwd=" '{print $2}'|awk '{print $1}'|sort|uniq -c|sort -n and this is the result

    Code:
    1
          1 /home/actormania/public_html
          1 /home/albertogorgojo/public_html
          1 /home/algodonmerlin/public_html
          1 /home/antonioaznar/public_html
          1 /home/costurasnontol/public_html
          1 /home/cursoderevit/public_html
          1 /home/disenowebmadrid/public_html
          1 /home/elperiodismo/public_html
          1 /home/enigmabohemia/public_html
          1 /home/fisioterapia/public_html
          1 /home/fontanerosmadrid/public_html
          1 /home/inmobiliaria/public_html
          1 /home/kristianboys/public_html
          1 /home/ruraly/public_html
          1 /home/serviamb/public_html
          1 /home/webes/public_html
          3 /home/webtematica/public_html
        164 /root
        318 /
       3700 /usr/local/cpanel/whostmgr/docroot
     
  8. NOC_Serverpoint

    NOC_Serverpoint Well-Known Member

    Joined:
    Jul 3, 2016
    Messages:
    102
    Likes Received:
    6
    Trophy Points:
    18
    cPanel Access Level:
    Website Owner
    Hi,

    Following command that will show you the script which is using script to send the email. If it is from php then use


    # egrep -R "X-PHP-Script" /var/spool/exim/input/*

    Thanks,
     
  9. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    37,064
    Likes Received:
    1,287
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    The following document is a good place to start:

    How to Prevent Email Abuse - cPanel Knowledge Base - cPanel Documentation

    In particular, review the section titled "Experimental: Rewrite From: header to match actual sender":

    Thank you.
     
Loading...

Share This Page