Enviado em 24/09/2013 - 11:41h
Prezados primeiramente obrigado a todos pela ajuda! Segue meu log, vejo o endereço do usuário que envia o spam mas não consigo encontrar que maquina pode ter sido infectada. Alguém pode ajudar?
Sep 24 11:28:27 mail amavis[10191]: (10191-15-10) Blocked SPAM, [198.24.174.167] [198.24.174.167] <pqhgzks@mcq.com.br> -> <akeem@acampar.com.br>,<akeem@almix.com.br>,<akeem@ar-net.com.br>,<akeem@arconet.com.br>,<akeem@armprsc.com.br>,<akeem@arnet.com.br>,<akeem@b.com.br>,<akeem@bluenet.com.br>,<ake@wnet.com.br>,<ake@worldline.com.br>, quarantine: n/spam-nx7geSf3oHGh.gz, mail_id: nx7geSf3oHGh, Hits: 14.057, size: 4580, 128 ms
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@acampar.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@almix.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@ar-net.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@arconet.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@armprsc.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@arnet.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@b.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<akeem@bluenet.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<ake@wnet.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/smtp[10241]: DD1DD37587: to=<ake@worldline.com.br>, relay=127.0.0.1[127.0.0.1]:10024, conn_use=10, delay=2, delays=1.8/0.05/0/0.13, dsn=2.5.0, status=sent (250 2.5.0 Ok, id=10191-15-10, DISCARD(bounce.suppressed))
Sep 24 11:28:27 mail postfix/qmgr[7277]: DD1DD37587: removed