SYSTEM INFORMATION | |
---|---|
OS type and version | Ubuntu 20.04 |
Virtualmin version | 7.5 |
I seem to have gotten into a similar situation to this from last year - Spam being sent from an email account - Virtualmin - Virtualmin Community
I disabled the server, changed the email password, restarted apache and postfix but the spam is not stopping. The only thing I can do to stop it is to stop postfix itself. Checkout some of the maillog
Apr 15 11:36:53 primary dovecot: imap-login: Login: user=<sales@tooneywheels.in>, method=PLAIN, rip=185.30.176.169, lip=139.162.61.248, mpid=2378171, TLS, session=<FN2pw1n5wJG5HrCp>
Apr 15 11:36:53 primary postfix/smtp[2378114]: 5295384843: to=<cheyne156@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=21562, delays=21553/4.1/4.1/0.26, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:53 primary postfix/smtp[2378114]: 5295384843: to=<mattdave1@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=21562, delays=21553/4.1/4.1/0.26, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378124]: 5577C834E4: to=<niguy@videotron.ca>, relay=mx.videotron.ca[24.201.245.37]:25, delay=536, delays=527/0.11/2.2/6.4, dsn=4.1.0, status=deferred (host mx.videotron.ca[24.201.245.37] said: 452 4.1.0 nZ3epdvBA0Aa7nZ3fp19q9 service temporarily unavailable AUP#EML-041 (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378165]: A0D7B8241E: to=<acy2731@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=29807, delays=29798/4.1/4.5/0.32, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378159]: B7AF984B48: to=<liam.madison@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=17167, delays=17158/4.8/3.9/0.25, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378155]: 1581484A84: host mta7.am0.yahoodns.net[67.195.228.94] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378155]: 1581484A84: lost connection with mta7.am0.yahoodns.net[67.195.228.94] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378116]: F2B7084860: host mta6.am0.yahoodns.net[67.195.228.111] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378116]: F2B7084860: lost connection with mta6.am0.yahoodns.net[67.195.228.111] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378115]: F375C84982: host mta5.am0.yahoodns.net[67.195.204.79] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378115]: F375C84982: lost connection with mta5.am0.yahoodns.net[67.195.204.79] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378156]: 5B0C8837BB: to=<john_smit@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=27950, delays=27941/4.6/4.4/0.26, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378122]: 5AC3E837B9: to=<nialldfitzpatrick@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=27950, delays=27941/4.7/4.3/0.24, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378118]: 602EC82521: host mta6.am0.yahoodns.net[67.195.228.110] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378118]: 602EC82521: lost connection with mta6.am0.yahoodns.net[67.195.228.110] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378149]: 2F37D8341F: host mta7.am0.yahoodns.net[67.195.204.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378149]: 2F37D8341F: lost connection with mta7.am0.yahoodns.net[67.195.204.73] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378138]: 5AC6E837BA: to=<gmanfife@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=27951, delays=27941/4.7/4.4/0.34, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378144]: 619A984857: host mta6.am0.yahoodns.net[98.136.96.91] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378150]: 1DB1084B12: host mta7.am0.yahoodns.net[67.195.204.77] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378150]: 1DB1084B12: lost connection with mta7.am0.yahoodns.net[67.195.204.77] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378144]: 619A984857: lost connection with mta6.am0.yahoodns.net[98.136.96.91] while sending RCPT TO
Apr 15 11:36:54 primary postfix/smtp[2378153]: 58D6283365: to=<smurfy_uk_81@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.74]:25, delay=30306, delays=30296/4.6/4.6/0.33, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.74] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378119]: 533B882519: to=<kafimd@yahoo.co.uk>, relay=mx-eu.mail.am0.yahoodns.net[188.125.72.73]:25, delay=32126, delays=32116/4.1/5.1/0.32, dsn=4.7.0, status=deferred (host mx-eu.mail.am0.yahoodns.net[188.125.72.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command))
Apr 15 11:36:54 primary postfix/smtp[2378152]: 0F0B783641: host mta6.am0.yahoodns.net[67.195.204.73] said: 421 4.7.0 [TSS04] Messages from 139.162.61.248 temporarily deferred due to unexpected volume or user complaints - 4.16.55.1; see https://postmaster.yahooinc.com/error-codes (in reply to MAIL FROM command)
Apr 15 11:36:54 primary postfix/smtp[2378152]: 0F0B783641: lost connection with mta6.am0.yahoodns.net[67.195.204.73] while sending RCPT TO
I’m curious about the login this time. Does that session part mean that the user is logged in via their session? Is this a case of session hijacking?