Good day.
About three days ago, i noticed spam messages were sent through two email accounts i have in my server. When i checked the logs in WHM one of them displayed:
and in the exim logs this was found:
I change the email account password then and it stopped but i get many log messages every day saying authentication failed.
Maybe some of our computer users have been hacked or something. Is there any way i can prevent this from happening again? I tried to find out what computer was infected but no luck. The logs shows differente ip address but the same domain (our domain isacol.com) on every time spam is trying to be sent.
Can i run anything or change anything in my configuration to prevent this?.
Thanks in advance.
Reginaldo.
About three days ago, i noticed spam messages were sent through two email accounts i have in my server. When i checked the logs in WHM one of them displayed:
Code:
User: admin
Domain: isacol.com
Sender: [email protected]
Sent Time: Apr 15, 2013 9:33:09 AM
Sender Host: isacol.com
Sender IP: 60.244.205.92
Authentication: courier_login
Spam Score:
Recipient: [email protected]
Delivered To: [email protected]
Delivery User: -remote-
Delivery Domain:
Router: lookuphost
Transport: remote_smtp
Out Time: Apr 15, 2013 9:33:09 AM
ID: 1URkSq-0004xk-Or
Delivery Host: mx1.emailsrvr.com
Delivery IP: 98.129.185.131
Size: 2.37 KB
Result: Message accepted
Code:
2013-04-15 09:33:01 1URkSq-0004xk-Or <= [email protected] H=(isacol.com) [60.244.205.92]:3129 P=esmtpa A=courier_login:[email protected] S=2423 [email protected] T="Quitting love game? Get necessary recommendations delivered worldwide!" for [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]
2013-04-15 09:33:01 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1URkSq-0004xk-Or
I change the email account password then and it stopped but i get many log messages every day saying authentication failed.
Maybe some of our computer users have been hacked or something. Is there any way i can prevent this from happening again? I tried to find out what computer was infected but no luck. The logs shows differente ip address but the same domain (our domain isacol.com) on every time spam is trying to be sent.
Can i run anything or change anything in my configuration to prevent this?.
Thanks in advance.
Reginaldo.