Quantcast
Channel: Micro Focus Forums
Viewing all articles
Browse latest Browse all 11924

Email Possibly Hacked

$
0
0
I have been attempting to identify the account or host computer that seems to have been compromised by malware/spyware as viewed in our GWIA logs. I have read through this thread in hope of being able to identify the path to view a log showing which account the mass of failed/non-forwarded emails are coming from. Can anyone provide me the path to find logs showing which account is sending the mass of emails to a variety of @yahoo.com.tw accounts? Thanks in advance for any assistance!

Here is a copy/paste of one GWIA log:

****** 01-10-13 08:11:03 ******
08:11:03 F40F DMN: MSG 1923340 Will not relay: duqianghuai@yahoo.com.tw (::ffff:1.164.102.194)
08:11:03 F3CF DMN: MSG 1923336 Will not relay: candy001999@yahoo.com.tw (::ffff:111.250.78.44)
08:11:03 F3A6 DMN: MSG 1923341 Will not relay: cwwonghk@yahoo.com.tw (::ffff:114.45.197.146)
08:11:03 F40F DMN: MSG 1923340 Will not relay: gaoningsheng@yahoo.com.tw (::ffff:1.164.102.194)
08:11:03 F3E7 DMN: MSG 1923335 Will not relay: k2rx1m@yahoo.com.tw (::ffff:1.164.102.194)
08:11:03 F473 *************** Switching to new log file ***************
08:11:03 F473 Begin Configuration Information
08:11:03 F473 GroupWise Agent Build Version: 12.0.1-103731
08:11:03 F473 GroupWise Agent Build Date: 09-06-12
08:11:03 F473 Platform= UNIX
08:11:03 F473 Domain and Agent= usd376.GWIA
08:11:03 F473 Foreign Name= mail.usd376.com
08:11:03 F473 Description= Unified School District #376.
08:11:03 F473 Alias Type= <none specified>
08:11:03 F473 Root Directory= /var/opt/novell/groupwise/mail/usd376/wpgate/gwia
08:11:03 F473 Work Directory= /var/opt/novell/groupwise/mail/usd376/wpgate/gwia/000.prc/gwwork
08:11:03 F473 Log File= /var/log/novell/groupwise/gwia.usd376/0110gwia.012
08:11:03 F473 Directory ID= gwi270f
08:11:03 F473 Directory Synchronization= NO
08:11:03 F473 Directory Exchange= NO
08:11:03 F473 Accounting= YES
08:11:03 F473 Convert GroupWise Status to Messages= NO
08:11:03 F473 Outbound Status Level= UNDELIVERED
08:11:03 F473 Log Level= Normal
08:11:03 F473 Log Max Age= 30 days
08:11:03 F473 Log Max Space= 102400 kb
08:11:03 F473 Enable Recovery= YES
08:11:03 F473 Retry Count= 10
08:11:03 F473 Retry Interval= 60 seconds
08:11:03 F473 Failed Recovery Wait= 3600 seconds
08:11:03 F473 Network Reattach Command= <none specified>
08:11:03 F473 Correlation DB Enabled= YES
08:11:03 F473 Correlation DB Age= 14 days
08:11:03 F473 Correlation DB Directory= /var/opt/novell/groupwise/mail/usd376/wpgate/gwia
08:11:03 F473 Send/Receive Cycle= 2 minutes
08:11:03 F473 Minimum Run= 0 minutes
08:11:03 F473 Idle Sleep Duration= 10 seconds
08:11:03 F473 Snap Shot Interval= 10 minutes
08:11:03 F473 Time Zone= CST
08:11:03 F473 GMT Offset= -6 hours, 0 minutes
08:11:03 F473 Hemisphere= NORTH
08:11:03 F473 Daylight Saving Change= 1 hours, 0 minutes
08:11:03 F473 Daylight Saving Begin= 3/10 (month/day)
08:11:03 F473 Daylight Saving End= 11/3 (month/day)
08:11:03 F473 SNMP On
08:11:03 F473 Startup Switches= --home /var/opt/novell/groupwise/mail
08:11:03 F473 /usd376/wpgate/gwia --smtp --nosmtpversion --mime --m
08:11:03 F473 udas 2 --sd 8 --rd 16 --p 10 --te 2 --tg 5 --tc 5 --t
08:11:03 F473 r 5 --td 3 --tt 10 --pt 10 --it 10 --ldapthrd 10 --st
08:11:03 F473 4 --rt 4 --dsn --dsnage 4 --xspam
08:11:03 F473 End Configuration Information
08:11:03 F3A6 DMN: MSG 1923341 Will not relay: aa58901067@yahoo.com.tw (::ffff:114.45.197.146)
08:11:03 F40F DMN: MSG 1923340 Will not relay: frank123456767@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F3CF DMN: MSG 1923336 Will not relay: zx99999999999999@yahoo.com.tw (::ffff:111.250.78.44)
08:11:04 F3E7 DMN: MSG 1923335 Will not relay: marco6901261847@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F40F DMN: MSG 1923340 Will not relay: amylases@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F3E7 DMN: MSG 1923335 Will not relay: zqgc@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F40F DMN: MSG 1923340 Will not relay: a2752147@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F3CF DMN: MSG 1923336 Will not relay: li50826@yahoo.com.tw (::ffff:111.250.78.44)
08:11:04 F3E7 DMN: MSG 1923335 Will not relay: gcem@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F40F DMN: MSG 1923340 Will not relay: xhnr@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F3E7 DMN: MSG 1923335 Will not relay: fen0626@yahoo.com.tw (::ffff:1.164.102.194)
08:11:04 F3CF DMN: MSG 1923336 Will not relay: chongpeiyee@yahoo.com.tw (::ffff:111.250.78.44)
08:11:05 F40F DMN: MSG 1923340 Will not relay: coffee33540@yahoo.com.tw (::ffff:1.164.102.194)
08:11:05 F3E7 DMN: MSG 1923335 Will not relay: demon_koko@yahoo.com.tw (::ffff:1.164.102.194)
08:11:05 F40F DMN: MSG 1923340 Will not relay: fishjan2001@yahoo.com.tw (::ffff:1.164.102.194)
08:11:05 F3C7 DMN: MSG 1923337 Will not relay: 223500125@yahoo.com.tw (::ffff:1.164.113.72)
08:11:05 F3CF DMN: MSG 1923336 Will not relay: eiij@yahoo.com.tw (::ffff:111.250.78.44)
08:11:05 F40F DMN: MSG 1923340 Will not relay: ecvt.tw@yahoo.com.tw (::ffff:1.164.102.194)
08:11:05 F3A6 DMN: MSG 1923341 Will not relay: bpellen@yahoo.com.tw (::ffff:114.45.197.146)
08:11:05 F3C7 DMN: MSG 1923337 Will not relay: amy8408@yahoo.com.tw (::ffff:1.164.113.72)
08:11:05 F40F DMN: MSG 1923340 Will not relay: c_ad_taiwan@yahoo.com.tw (::ffff:1.164.102.194)
08:11:05 F3A6 DMN: MSG 1923341 Will not relay: christine19@yahoo.com.tw (::ffff:114.45.197.146)
08:11:05 F3CF DMN: MSG 1923336 Will not relay: eesca@yahoo.com.tw (::ffff:111.250.78.44)
08:11:05 F3C7 DMN: MSG 1923337 Will not relay: dan1502@yahoo.com.tw (::ffff:1.164.113.72)
08:11:06 F37E DMN: MSG 1923290 SMTP session ended: [::ffff:118.167.97.217] ()

Viewing all articles
Browse latest Browse all 11924

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>