Strange mail message returns; compromised server?
Posted: Tue Aug 03, 2010 6:33 am
We have started to recieve complaints that emails sent through our server bounce back with a failure message saying that it could not send to various addresses:
Access logs show no access to qmal from outside and qmhandle doesn't show any source other than our server being responsible for these failure notices. After checking the maillog there are no records of any attempt by qmail to send to these addresses.
It looks like we may have some trojan script or something sending these out.
Any ideas what could be going on and how to fix it?
There are many more than this.From: <MAILER-DAEMON@plesk2.expat-email.co.uk>
Date: Tue, 3 Aug 2010 10:38:43 +0200
To: <customer name and email>
Subject: failure notice
Hi. This is the qmail-send program at plesk2.expat-email.co.uk.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<frankwick@sbcglobal.net>:
Connected to 207.115.36.22 but sender was rejected.
Remote host said: 553 5.3.0 nlpi149 - o0M2f7SA026683, DNSBL:ATTRBL 521<
82.197.79.4 >_is_blocked.__For_information_see_http://att.net/blocks
<frankwheeler@sbcglobal.net>:
Connected to 207.115.21.20 but sender was rejected.
Remote host said: 553 5.3.0 flpi181 - o0M2f7P2015145, DNSBL:ATTRBL 521<
82.197.79.4 >_is_blocked.__For_information_see_http://att.net/blocks
<frankwhite2@aol.com>:
205.188.155.72 does not like recipient.
Remote host said: 550 MAILBOX NOT FOUND
Giving up on 205.188.155.72.
Access logs show no access to qmal from outside and qmhandle doesn't show any source other than our server being responsible for these failure notices. After checking the maillog there are no records of any attempt by qmail to send to these addresses.
It looks like we may have some trojan script or something sending these out.
Any ideas what could be going on and how to fix it?