Let's take a look at this log snippet, breaking it into logical segments:
>20010512 143324 127.0.0.1 SMTPD (109E00FA) [205.178.180.13] EHLO
>whnt931.webhosting.com
>20010512 143324 127.0.0.1 SMTPD (109E00FA) [205.178.180.13] MAIL
>FROM:<[EMAIL PROTECTED]>
>20010512 143324 127.0.0.1 SMTPD (109E00FA) [205.178.180.13] RCPT
>To:<[EMAIL PROTECTED]>
>20010512 143324 127.0.0.1 SMTPD (109E00FA) [205.178.180.13] ERR
>igive.com invalid user <[EMAIL PROTECTED]
This is the only one coming from 205.178.180.13. The "mail4you" domain
does seem a bit suspicious, along with the letters-and-numbers
username. But, no indication of any problems here. The IP address does
match the HELO name, which make it appear legitimate. But...
>20010512 143341 127.0.0.1 SMTPD (109F00FA) [64.27.153.253] connect
>202.181.176.130 port 4075
> 20010512 143349 127.0.0.1 SMTPD (109F00FA) [202.181.176.130] EHLO
>www.compulink.com.hk
>20010512 143349 127.0.0.1 SMTPD (109F00FA) [202.181.176.130] MAIL
>From:<[EMAIL PROTECTED]>
>20010512 143349 127.0.0.1 SMTPD (109F00FA) [202.181.176.130] RCPT
>To:<[EMAIL PROTECTED]>
>20010512 143349 127.0.0.1 SMTPD (109F00FA) [202.181.176.130] ERR
>igive.com invalid user <[EMAIL PROTECTED]
This, from another mail server, that appears to be legitimate, since the
HELO name matches the IP. But, it's from another numbers-and-letters
username at a suspicious domain, to the same user. They definitely seem
connected.
>20010512 143324 127.0.0.1 SMTPD (06810104) [64.27.153.253] connect
>64.27.153.253 port 3438
>20010512 143425 127.0.0.1 SMTPD (10A000FA) [64.27.153.253] connect
>64.27.153.253 port 3451
I'm guessing this is your server, checking to make sure the SMTP port is
still responding.
>20010512 143505 127.0.0.1 SMTPD (10A100FA) [64.27.153.253] connect
>61.128.234.167 port 4226
>20010512 143505 127.0.0.1 SMTPD (10A100FA) [61.128.234.167] HELO
>smtp.igive.com
>20010512 143506 127.0.0.1 SMTPD (10A100FA) [61.128.234.167] mail
>from:<[EMAIL PROTECTED]>
>20010512 143508 127.0.0.1 SMTPD (10A100FA) [61.128.234.167] rcpt
>to:<[EMAIL PROTECTED]>
>20010512 143508 127.0.0.1 SMTPD (10A100FA) [61.128.234.167] ERR
>igive.com invalid user <[EMAIL PROTECTED]
Unless this is a server of yours, it shouldn't be claiming to be
smtp.igive.com. This is very likely a spammer; we see a number of them use
a HELO that is the same as what they know our mail server as (one of the
virtual domains). The fact that they are using the same From/To means that
either it is someone from your domain, or they are violating Internet
protocol and almost certainly a spammer.
>Doesn't look like I'm relaying, but want to make sure I'm "kosher".
I don't know what to make of these logs. The three transactions are all
*to* users in your domain, so they aren't trying to relay. And it doesn't
look like a dictionary attack, where they are trying to guess names at your
site. And, coming from 3 different IPs, it's hard to know what is going
on. It's possible that it's a distributed DoS attack, but if they were
doing that, it's unlikely they would use such a variety of methods of
sending (using different return addresses and the bogus HELO).
-Scott
Declude: Anti-spam and Anti-virus solutions for IMail. http://www.declude.com
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/