Advertisement
Guest User

Untitled

a guest
Oct 10th, 2017
415
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.01 KB | None | 0 0
  1. There are our server logs:
  2. ###
  3. 4m 12K 1e1Uul-003IoE-G8 <> *** frozen ***
  4. lpfcom@chi-rs31.websitehostserver.net
  5.  
  6. 3m 12K 1e1UvA-003J0n-GC <> *** frozen ***
  7. lpfcom@chi-rs31.websitehostserver.net
  8.  
  9. 3m 12K 1e1Uvj-003JFi-29 <> *** frozen ***
  10. lpfcom@chi-rs31.websitehostserver.net
  11.  
  12. 3m 2.3K 1e1Uvl-003JJj-VG <> *** frozen ***
  13. root@chi-rs31.websitehostserver.net
  14.  
  15. 3m 2.3K 1e1Uvm-003JJy-7c <> *** frozen ***
  16. root@chi-rs31.websitehostserver.net
  17.  
  18. 2m 12K 1e1Uvw-003JOn-00 <> *** frozen ***
  19. lpfcom@chi-rs31.websitehostserver.net
  20.  
  21. 1m 12K 1e1UxB-003Jzx-No <> *** frozen ***
  22. lpfcom@chi-rs31.websitehostserver.net
  23.  
  24. 1m 12K 1e1UxT-003K9O-JP <> *** frozen ***
  25. lpfcom@chi-rs31.websitehostserver.net
  26.  
  27. 1m 12K 1e1Uxe-003KEy-3H <> *** frozen ***
  28. lpfcom@chi-rs31.websitehostserver.net
  29.  
  30. 2017-10-09 05:06:58 1e1Uxe-003KEy-3H <= <> R=1e1UxY-003KBm-9C U=mailnull P=local S=11962 T="Mail delivery failed: returning message to sender" for lpfcom@chi-rs31.websitehostserver.net
  31. 2017-10-09 05:06:58 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1e1Uxe-003KEy-3H
  32. 2017-10-09 05:06:58 1e1Uxe-003KEy-3H Sender identification U=mailnull D=-system- S=mailnull
  33. 2017-10-09 05:06:58 1e1Uxe-003KEy-3H ** lpfcom@chi-rs31.websitehostserver.net R=fail_remote_domains: The mail server could not deliver mail to lpfcom@chi-rs31.websitehostserver.net. The account or domain may not exist, they may be blacklisted, or missing the proper dns entries.
  34. 2017-10-09 05:06:58 1e1Uxe-003KEy-3H Frozen (delivery error message)
  35.  
  36. 2017-10-09 05:06:52 1e1UxY-003KBm-9C <= lpfcom@chi-rs31.websitehostserver.net U=lpfcom P=local S=10397 T="Pandora Factory Outlet 80% OFF" for deudeuchman@orange.fr
  37. 2017-10-09 05:06:52 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1e1UxY-003KBm-9C
  38. 2017-10-09 05:06:52 1e1UxY-003KBm-9C Sender identification U=lpfcom D=lpf.com.cy S=lpfcom
  39. 2017-10-09 05:06:52 1e1UxY-003KBm-9C SMTP connection outbound 1507543612 1e1UxY-003KBm-9C lpf.com.cy deudeuchman@orange.fr
  40. 2017-10-09 05:06:58 1e1UxY-003KBm-9C ** deudeuchman@orange.fr R=lookuphost T=remote_smtp H=smtp-in.orange.fr [80.12.242.9] X=TLSv1:DHE-RSA-AES256-SHA:256 CV=yes: SMTP error from remote mail server after end of data: 550 5.2.0 Mail rejete. Mail rejected. ofr_506 [506]
  41. 2017-10-09 05:06:58 cwd=/var/spool/exim 7 args: /usr/sbin/exim -t -oem -oi -f <> -E1e1UxY-003KBm-9C
  42. 2017-10-09 05:06:58 1e1Uxe-003KEy-3H <= <> R=1e1UxY-003KBm-9C U=mailnull P=local S=11962 T="Mail delivery failed: returning message to sender" for lpfcom@chi-rs31.websitehostserver.net
  43. 2017-10-09 05:06:58 1e1UxY-003KBm-9C Completed
  44. ###
  45.  
  46. Also, we've found the following malicious files:
  47. ###
  48. /home/lpfcom/public_html/pub/docs/model/search/reports/public/formlist.php
  49. /home/lpfcom/public_html/wp-content/languages/mo.php
  50. /home/lpfcom/public_html/funcs/info.php
  51. ###
  52.  
  53. Please provide us with your WAN IP address and we will allow access to your account from that address only. Thus you will have the ability to take appropriate measures.Here is the link to find out what your WAN IP is: http://myip.is/. Looking forward to hearing from you.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement