Hi .. I recently received an email from The Planet stating that my server was the origin of a Phishing Abuse email spam. I've temporarily stopped my sendmail service and am currently going through the log files. My server is on a linux machine using Ensim Pro 4.0.3-22.rhel.3ES to administrate the server.
Here are a couple of things I've found.
from /var/log/maillog
Mar 13 20:14:43 ensim sendmail[6259]: l2CICs3l018565: to=<crisscross9031@yahoo.com>, ctladdr=<apache@ensim.ev1servers.net> (48/48), delay=1+08:01:49, xdelay=00:00:01, mailer=esmtp, pri=124675, relay=d.mx.mail.yahoo.com. [216.39.53.2], dsn=5.0.0, stat=Service unavailable
Mar 13 20:14:43 ensim sendmail[6259]: l2CICs3l018565: l2E24iNi006259: DSN: Service unavailable
Mar 13 20:14:43 ensim sendmail[6259]: l2E24iNi006259: to=root, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=30000, dsn=2.0.0, stat=Sent
Mar 13 20:14:43 ensim sendmail[6259]: l2CIBLnU015630: to=<angelheart04967@yahoo.com>, ctladdr=<apache@ensim.ev1servers.net> (48/48), delay=1+08:03:22, xdelay=00:00:00, mailer=esmtp, pri=124676, relay=c.mx.mail.yahoo.com., dsn=4.0.0, stat=Deferred: 451 Message temporarily deferred - [170]
Mar 13 20:14:43 ensim sendmail[6259]: l2CIBLnU015630: l2E24iNj006259: sender notify: Warning: could not send message for past 4 hours
Mar 13 20:14:43 ensim sendmail[6259]: l2E24iNj006259: to=root, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=30000, dsn=2.0.0, stat=Sent
Mar 13 20:14:47 ensim sendmail[6259]: l2CIBKQ1015607: to=<angelhayes12345@yahoo.com>, ctladdr=<apache@ensim.ev1servers.net> (48/48), delay=1+08:03:27, xdelay=00:00:04, mailer=esmtp, pri=124676, relay=c.mx.mail.yahoo.com., dsn=4.0.0, stat=Deferred: 451 Message temporarily deferred - [70]
Mar 13 20:14:47 ensim sendmail[6259]: l2CIBKQ1015607: l2E24iNk006259: sender notify: Warning: could not send message for past 4 hours
Mar 13 20:14:47 ensim sendmail[6259]: l2E24iNk006259: to=root, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=30000, dsn=2.0.0, stat=Sent
Mar 13 20:14:48 ensim sendmail[6259]: l2CIBf3I016268: to=<angelkisses99_us@yahoo.com>, ctladdr=<apache@ensim.ev1servers.net> (48/48), delay=1+08:03:06, xdelay=00:00:01, mailer=esmtp, pri=124677, relay=c.mx.mail.yahoo.com., dsn=4.0.0, stat=Deferred: 451 Message temporarily deferred - [70]
Mar 13 20:14:48 ensim sendmail[6259]: l2CIBf3I016268: l2E24iNl006259: sender notify: Warning: could not send message for past 4 hours
Mar 13 20:14:48 ensim sendmail[6259]: l2E24iNl006259: to=root, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=30000, dsn=2.0.0, stat=Sent
Mar 13 20:14:48 ensim sendmail[6259]: l2CIB8cJ015258: to=<angeleyeslibra_85@yahoo.com>, ctladdr=<apache@ensim.ev1servers.net> (48/48), delay=1+08:03:40, xdelay=00:00:00, mailer=esmtp, pri=124678, relay=g.mx.mail.yahoo.com., dsn=4.0.0, stat=Deferred: 451 Message temporarily deferred - [70]
Mar 13 20:14:48 ensim sendmail[6259]: l2CIB8cJ015258: l2E24iNm006259: sender notify: Warning: could not send message for past 4 hours
Mar 13 20:14:48 ensim sendmail[6259]: l2E24iNm006259: to=root, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=30000, dsn=2.0.0, stat=Sent
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<jah@creativepeopleskills.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<sue.patton@cstratinc.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<jobs@devries-pr.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<dkaufman@fischerhealth.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<hoggs@fleishman.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<careers@gymr.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<Heidi.Crane@hassmsl.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<msilveremail@msilver-pr.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<barry@peterbellassociates.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<joyce.fratturo@piercepromotions.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<bayareacareers@porternovelli.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<hr@rfbinder.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<noha.sahyoun@rlpublicrelations.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<duane@tcpr.net>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sm-acceptingconnections[7752]: l2E2ws3D007752: to=<lauren@teamworksmedia.com>, delay=00:00:01, mailer=esmtp, pri=811714, stat=queued
Mar 13 20:58:56 ensim sendmail[7750]: l2E2wpa2007750: to=wkrampf@coneinc.com,hr@coneinc.com,jessica@amies.com.,careers@alantaylor.com.
,hoggs@fleishman.com,careers@gymr.com,jobs@devries-pr.com,duane@tcpr.net,dkaufman@fischerhealth.com,careers@cmgrp.cpm,DRenella@cmgr
p.com,careers@cmgrp.com,hr@rfbinder.com,lauren@teamworksmedia.com,msilveremail@ms
ilver-pr.com,jennifer.logullo@corecubed.com.,sue.patton@cstratinc.com,dgabriel@cisny.c
om,jah@creativepeopleskills.com,Kathy@adrecruiters.com,noha.sahyoun@rlpublicrelat
ions.com,lspackman@bremerpr.com,barry@peterbellassociates.com,jobs@berkmanpr.com.
,joyce.fratturo@piercepromotions.com,Heidi.Crane@hassmsl.com,bayareacareers@porte
rnovelli.com, ctladdr=apache (48/48), delay=00:00:05, xdelay=00:00:02, mailer=relay, pri=811356, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (l2E2ws3D007752 Message accepted for delivery)
Mar 13 20:58:56 ensim sendmail[7755]: l2E2wug7007755: from=apache, size=657, class=0, nrcpts=1, msgid=<200703140258.l2E2wug7007755@ensim.ev1servers.net>, relay=apache@localhost
Mar 13 20:58:56 ensim sm-acceptingconnections[7757]: l2E2wuNA007757: from=<apache@ensim.ev1servers.net>, size=892, class=0, nrcpts=1, msgid=<200703140258.l2E2wug7007755@ensim.ev1servers.net>, proto=ESMTP, daemon=MTA, relay=localhost.localdomain [127.0.0.1]
Mar 13 20:58:56 ensim sm-acceptingconnections[7757]: l2E2wuNA007757: to=<camaraloans@yahoo.com>, delay=00:00:00, mailer=esmtp, pri=30892, stat=queued
Mar 13 20:58:56 ensim sendmail[7755]: l2E2wug7007755: to=camaraloans@yahoo.com, ctladdr=apache (48/48), delay=00:00:00, xdelay=00:00:00, mailer=relay, pri=30657, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (l2E2wuNA007757 Message accepted for delivery)
Mar 13 20:59:11 ensim sm-acceptingconnections[7758]: l2E2x9GI007758: from=<qktn@hetnet.nl>, size=18180, class=0, nrcpts=1, msgid=<45F762BF.5070104@hetnet.nl>, proto=SMTP, daemon=MTA, relay=[210.221.220.11]
Mar 13 20:59:11 ensim sm-acceptingconnections[7758]: l2E2x9GI007758: to=<petgord34truew@funnyclipcentral.com>, delay=00:00:01, mailer=virthostmail, pri=48180, stat=queued
Mar 13 21:00:12 ensim sm-acceptingconnections[7764]: l2E2xw3u007764: from=<gwfp@yam.com>, size=30399, class=0, nrcpts=1, msgid=<000d01c765e3$7bf3b820$badd5d7d@ylu>, proto=SMTP, daemon=MTA, relay=20129031077.user.veloxzone.com.br [201.29.31.77] (may be forged)
Mar 13 21:00:12 ensim sm-acceptingconnections[7764]: l2E2xw3u007764: to=<petgord34truew@findadonor.com>, delay=00:00:10, mailer=virthostmail, pri=60399, stat=queued
from /var/spool/mail/root
--l2E24iNm006259.1173838488/ensim.ev1servers.net
**********************************************
** THIS IS A WARNING MESSAGE ONLY **
** YOU DO NOT NEED TO RESEND YOUR MESSAGE **
**********************************************
The original message was received at Mon, 12 Mar 2007 12:11:08 -0600
from localhost.localdomain [127.0.0.1]
----- Transcript of session follows -----
... while talking to d.mx.mail.yahoo.com.:
>>> DATA
<<< 451 Message temporarily deferred - [70]
<angeleyeslibra_85@yahoo.com>... Deferred: 451 Message temporarily deferred - [70]
Warning: message still undelivered after 4 hours
Will keep trying until message is 5 days old
--l2E24iNm006259.1173838488/ensim.ev1servers.net
Content-Type: message/delivery-status
Reporting-MTA: dns; ensim.ev1servers.net
Arrival-Date: Mon, 12 Mar 2007 12:11:08 -0600
Final-Recipient: RFC822; angeleyeslibra_85@yahoo.com
Action: delayed
Status: 4.2.0
Remote-MTA: DNS; g.mx.mail.yahoo.com
Last-Attempt-Date: Tue, 13 Mar 2007 20:14:48 -0600
Will-Retry-Until: Sat, 17 Mar 2007 12:11:08 -0600
--l2E24iNm006259.1173838488/ensim.ev1servers.net
Content-Type: text/rfc822-headers
Content-Transfer-Encoding: 8bit
X-ClientAddr: 127.0.0.1
Return-Path: <apache@ensim.ev1servers.net>
Received: from ensim.ev1servers.net (localhost.localdomain [127.0.0.1])
by ensim.ev1servers.net (8.12.11/8.12.11) with ESMTP id l2CIB8cJ015258
for <angeleyeslibra_85@yahoo.com>; Mon, 12 Mar 2007 12:11:08 -0600
Received: (from apache@localhost)
by ensim.ev1servers.net (8.12.11/8.12.11/Submit) id l2CIB845015248;
Mon, 12 Mar 2007 12:11:08 -0600
Date: Mon, 12 Mar 2007 12:11:08 -0600
Message-Id: <200703121811.l2CIB845015248@ensim.ev1servers.net>
To: angeleyeslibra_85@yahoo.com
Subject: Security.Alert(Upgrade Your Online Banking Information
From: WellsFargo® Online Banking® <customerservice@wellsfargo.com>
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
X-MediaRail-MailScanner-Information: Please contact the ISP for more information
X-MediaRail-MailScanner: Found to be clean
X-MailScanner-From: apache@ensim.ev1servers.net
--l2E24iNm006259.1173838488/ensim.ev1servers.net--
Are there any other log files I can check to try and find how exactly sending all these mail requests? Any suggestions on how to block these emails?
