SMTP connection from (TCP/IP connection count = 100)

Operating System & Version
CloudLinux v7.9.0 STANDARD standard
cPanel & WHM Version
106.0.11

jlucho

Well-Known Member
Aug 5, 2006
110
1
168
hi guys


i am getting this kind of activity
it is seen that it is a high consumption of emails, possibly email attack (view image)


2023-02-01 11:04:25 SMTP connection from [1.6.7.120]:6480 (TCP/IP connection count = 107)
2023-02-01 11:04:25 SMTP connection from [1.66.17.82]:14243 (TCP/IP connection count = 108)

Do you know how to stop this type of attack?
what could be happening on the server

thank
 

Attachments

Last edited by a moderator:

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
14,425
2,259
363
cPanel Access Level
Root Administrator
Hey there! As long as a service is open to the internet, it is always at risk of being abused.

If those entries are from /var/log/maillog, do you see that they actually sent messages in corresponding timestamps in /var/log/exim_mainlog? If not, it seems like most of the connections are from 190.x.x.x and 179.x.x.x so you could consider blocking those ranges in the server's firewall.