Merkwürdige Mails an nur eine Domain im Queue und merkwürdige Einträge in der Maillog

juser

Member
Hallo,

ich habe seit gestern Abend in der Maillog folgende Einträge und gleichzeitig im Mailqueue viele Mails die nur an eine einzige Domain,z.B. 2235948548@qq.com, versendet werden.

Hat jemand von Euch schon mal solch einen Fall gehabt?
Ich werde aus den Maillog Einträgen nicht schlau, kann mir da evtl. jemand auf die Sprünge helfen?

Schon mal vielen Dank im Voraus für Eure Mühe.


Aug 27 11:14:20 z3-host postfix/pickup[3339]: 96C9A503BB9: uid=5042 from=<info@domain-xxxx.com>
Aug 27 11:14:20 z3-host postfix/qmgr[3340]: 96C9A503BB9: from=<info@domain-xxxx.com>, size=942, nrcpt=1 (queue active)
Aug 27 11:14:20 z3-host postfix/pickup[3339]: AF59E503BA0: uid=5042 from=<info@domain-xxxx.com>
Aug 27 11:14:20 z3-host postfix/qmgr[3340]: AF59E503BA0: from=<info@domain-xxxx.com>, size=1017, nrcpt=1 (queue active)
Aug 27 11:14:28 z3-host postfix/qmgr[3340]: 45826504FD2: from=<info@domain-xxxx.com>, size=1702, nrcpt=1 (queue active)
Aug 27 11:14:28 z3-host amavis[2319]: (02319-04) Passed SPAMMY {RelayedTaggedInternal}, <info@domain-xxxx.com> -> <info@domain-xxxx.com>, Message-ID: <00f69fa8411482c8b57118cdb05b2729@www.domain-xxxx.com>, mail_id: PmSAoyK-vtEZ, Hits: 5.445, size: 941, queued_as: 45826504FD2, 7702 ms
Aug 27 11:14:28 z3-host postfix/smtp[3765]: 96C9A503BB9: to=<info@domain-xxxx.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=7.9, delays=0.19/0/0/7.7, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 45826504FD2)
Aug 27 11:14:28 z3-host postfix/pickup[3339]: CEAC4505477: uid=5000 from=<info@domain-xxxx.com>
Aug 27 11:14:28 z3-host dovecot: lda(info@domain-xxxx.com): sieve: msgid=<00f69fa8411482c8b57118cdb05b2729@www.domain-xxxx.com>: forwarded to <backup@domain-xxxx.com>
Aug 27 11:14:28 z3-host postfix/qmgr[3340]: CEAC4505477: from=<info@domain-xxxx.com>, size=1983, nrcpt=1 (queue active)
Aug 27 11:14:29 z3-host dovecot: lda(info@domain-xxxx.com): sieve: msgid=<00f69fa8411482c8b57118cdb05b2729@www.domain-xxxx.com>: stored mail into mailbox 'INBOX'
Aug 27 11:14:29 z3-host postfix/pipe[3818]: 45826504FD2: to=<info@domain-xxxx.com>, relay=dovecot, delay=0.83, delays=0.13/0/0/0.7, dsn=2.0.0, status=sent (delivered via dovecot service)
Aug 27 11:14:33 z3-host postfix/pickup[3339]: C7526504FD2: uid=5042 from=<info@domain-xxxx.com>
Aug 27 11:14:33 z3-host postfix/qmgr[3340]: C7526504FD2: from=<info@domain-xxxx.com>, size=953, nrcpt=1 (queue active)
Aug 27 11:14:33 z3-host postfix/pickup[3339]: E04C7503BB9: uid=5042 from=<info@domain-xxxx.com>
Aug 27 11:14:34 z3-host postfix/qmgr[3340]: E04C7503BB9: from=<info@domain-xxxx.com>, size=1027, nrcpt=1 (queue active)
Aug 27 11:14:35 z3-host postfix/qmgr[3340]: 0E4E15054D6: from=<info@domain-xxxx.com>, size=1436, nrcpt=1 (queue active)
Aug 27 11:14:35 z3-host amavis[2320]: (02320-05) Passed CLEAN {RelayedOutbound}, <info@domain-xxxx.com> -> <450429313@qq.com>, Message-ID: <50a689ebee28e79808674c4cf87852a3@www.domain-xxxx.com>, mail_id: RcvOJfxHG7Et, Hits: 5.445, size: 1016, queued_as: 0E4E15054D6, 14312 ms
Aug 27 11:14:41 z3-host postfix/qmgr[3340]: AB229505697: from=<info@domain-xxxx.com>, size=2116, nrcpt=1 (queue active)
Aug 27 11:14:41 z3-host amavis[2319]: (02319-05) Passed CLEAN {RelayedOutbound}, <info@domain-xxxx.com> -> <backup@domain-xxxx.com>, Message-ID: <00f69fa8411482c8b57118cdb05b2729@www.domain-xxxx.com>, mail_id: lY2vo8CsjVz2, Hits: 4.446, size: 1982, queued_as: AB229505697, 12964 ms
Aug 27 11:14:49 z3-host postfix/qmgr[3340]: D6D78505939: from=<info@domain-xxxx.com>, size=1778, nrcpt=1 (queue active)
Aug 27 11:14:49 z3-host amavis[2320]: (02320-06) Passed SPAMMY {RelayedTaggedInternal}, <info@domain-xxxx.com> -> <info@domain-xxxx.com>, Message-ID: <8fe641a10a132461f01a16c2d5c7aced@www.domain-xxxx.com>, mail_id: eKrrgk8EqnuE, Hits: 9.201, size: 952, queued_as: D6D78505939, 13799 ms
Aug 27 11:14:49 z3-host postfix/smtp[3768]: C7526504FD2: to=<info@domain-xxxx.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=15, delays=0.17/1.3/0/14, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as D6D78505939)
Aug 27 11:14:49 z3-host dovecot: lda(info@domain-xxxx.com): sieve: msgid=<8fe641a10a132461f01a16c2d5c7aced@www.domain-xxxx.com>: forwarded to <backup@domain-xxxx.com>
 

thommy

Member
ja, qq.com ist bei mir auch so ein thema...

ich nehme an, dass ein kontaktformular in einem wordpress und/oder joomla da gehackt wurde. bei mir sinds leider / zum glück nur einige wenige mails pro woche, sodass ich das nicht ernsthaft suche. der eine bounce wg. unzustellbar pro woche ist mir letztlich egal; die mxtoolbox meint dazu, dass der server kein spammer ist...
 

Werbung

Top