Top Offenders





Today

Postfix log summaries for Jul 15

Grand Totals
------------
messages

6 received
6 delivered
0 forwarded
0 deferred
0 bounced
2 rejected (25%)
0 reject warnings
0 held
0 discarded (0%)

12344 bytes received
12344 bytes delivered
2 senders
1 sending hosts/domains
2 recipients
2 recipient hosts/domains


Per-Hour Traffic Summary
------------------------
time received delivered deferred bounced rejected
--------------------------------------------------------------------
0000-0100 0 0 0 0 0
0100-0200 0 0 0 0 0
0200-0300 1 1 0 0 0
0300-0400 1 1 0 0 0
0400-0500 0 0 0 0 0
0500-0600 0 0 0 0 0
0600-0700 0 0 0 0 0
0700-0800 0 0 0 0 0
0800-0900 2 2 0 0 0
0900-1000 2 2 0 0 0
1000-1100 0 0 0 0 0
1100-1200 0 0 0 0 1
1200-1300 0 0 0 0 0
1300-1400 0 0 0 0 0
1400-1500 0 0 0 0 0
1500-1600 0 0 0 0 0
1600-1700 0 0 0 0 0
1700-1800 0 0 0 0 0
1800-1900 0 0 0 0 0
1900-2000 0 0 0 0 1
2000-2100 0 0 0 0 0
2100-2200 0 0 0 0 0
2200-2300 0 0 0 0 0
2300-2400 0 0 0 0 0

Host/Domain Summary: Message Delivery
--------------------------------------
sent cnt bytes defers avg dly max dly host/domain
-------- ------- ------- ------- ------- -----------
3 6752 0 0.8 s 0.9 s gmail.com
3 5592 0 0.0 s 0.1 s somagroup.com.br

Host/Domain Summary: Messages Received
---------------------------------------
msg cnt bytes host/domain
-------- ------- -----------
6 12344 somagroup.com.br

Senders by message count
------------------------
3 root@somagroup.com.br
3 www-data@somagroup.com.br

Recipients by message count
---------------------------
3 root@somagroup.com.br
3 leonardochen0@gmail.com

Senders by message size
-----------------------
6752 www-data@somagroup.com.br
5592 root@somagroup.com.br

Recipients by message size
--------------------------
6752 leonardochen0@gmail.com
5592 root@somagroup.com.br

message reject detail
---------------------
RCPT
504 5.5.2 <WIN-6H79TFFJL6O>: Helo command rejected: need fully-qualified hostname; from=<info@somagroup.com.br> to=<meregion69@gmail.com> proto=ESMTP helo=<WIN-6H79TFFJL6O> (total: 1)
1 2.57.122.202 (info@somagroup.com.br)
504 5.5.2 <WIN-QHD98838P8B>: Helo command rejected: need fully-qualified hostname; from=<spameri@tiscali.it> to=<spameri@tiscali.it> proto=ESMTP helo=<WIN-QHD98838P8B> (total: 1)
1 165.231.148.207 (spameri@tiscali.it)

Warnings
--------
smtpd (total: 5)
1 hostname worker-12.sfj.censys-scanner.com does not resolve to address 192.35.168.203
1 hostname zg-0708a-135.stretchoid.com does not resolve to address 192.241.222.214: Name or service not known
1 hostname zg-0708a-230.stretchoid.com does not resolve to address 192.241.234.7: Name or service not known
1 hostname mqzg.solliez.science does not resolve to address 69.46.30.68: Name or service not known
1 non-SMTP command from implant-scanner-victims-will-be-notified.threatsinkhole.com[172.105.89.161]: GET / HTTP/1.0
trivial-rewrite (total: 4)
4 do not list domain somagroup.com.br in BOTH mydestination and virtual_alias_domains

Yesterday

Postfix log summaries for Jul 14

Grand Totals
------------
messages

5 received
6 delivered
0 forwarded
0 deferred
0 bounced
4 rejected (40%)
0 reject warnings
0 held
0 discarded (0%)

7216 bytes received
8102 bytes delivered
2 senders
1 sending hosts/domains
3 recipients
2 recipient hosts/domains


Per-Hour Traffic Summary
------------------------
time received delivered deferred bounced rejected
--------------------------------------------------------------------
0000-0100 0 0 0 0 0
0100-0200 0 0 0 0 0
0200-0300 1 1 0 0 0
0300-0400 1 1 0 0 0
0400-0500 0 0 0 0 0
0500-0600 0 0 0 0 0
0600-0700 0 0 0 0 0
0700-0800 0 0 0 0 0
0800-0900 1 1 0 0 0
0900-1000 0 0 0 0 0
1000-1100 0 0 0 0 0
1100-1200 0 0 0 0 0
1200-1300 0 0 0 0 0
1300-1400 0 0 0 0 1
1400-1500 0 0 0 0 1
1500-1600 0 0 0 0 1
1600-1700 1 2 0 0 0
1700-1800 0 0 0 0 0
1800-1900 0 0 0 0 0
1900-2000 0 0 0 0 0
2000-2100 0 0 0 0 0
2100-2200 0 0 0 0 0
2200-2300 0 0 0 0 0
2300-2400 1 1 0 0 1

Host/Domain Summary: Message Delivery
--------------------------------------
sent cnt bytes defers avg dly max dly host/domain
-------- ------- ------- ------- ------- -----------
4 6330 0 0.0 s 0.0 s somagroup.com.br
2 1772 0 0.9 s 0.9 s gmail.com

Host/Domain Summary: Messages Received
---------------------------------------
msg cnt bytes host/domain
-------- ------- -----------
5 7216 somagroup.com.br

Senders by message count
------------------------
4 root@somagroup.com.br
1 www-data@somagroup.com.br

Recipients by message count
---------------------------
4 root@somagroup.com.br
1 ricardochen.empresas2@gmail.com
1 rodrigochen.empresas4@gmail.com

Senders by message size
-----------------------
6330 root@somagroup.com.br
886 www-data@somagroup.com.br

Recipients by message size
--------------------------
6330 root@somagroup.com.br
886 ricardochen.empresas2@gmail.com
886 rodrigochen.empresas4@gmail.com

message reject detail
---------------------
RCPT
504 5.5.2 <WIN-C5C8GSO5NLE>: Helo command rejected: need fully-qualified hostname; from=<spameri@tiscali.it> to=<spameri@tiscali.it> proto=ESMTP helo=<WIN-C5C8GSO5NLE> (total: 1)
1 156.96.116.44 (spameri@tiscali.it)
504 5.5.2 <win2012r2RDP>: Helo command rejected: need fully-qualified hostname; from=<spameri@tiscali.it> to=<spameri@tiscali.it> proto=ESMTP helo=<win2012r2RDP> (total: 1)
1 37.49.224.141 (spameri@tiscali.it)
554 5.7.1 <galeriapet@galeriapet.com.br>: Relay access denied; from=<166-SUM-744.0.959694.0.0.19535.9.6343012-1@bounce.bni.com> to=<galeriapet@galeriapet.com.br> proto=ESMTP helo=<bounce.bni.com> (total: 1)
1 bni.com (166-SUM-744.0.959694.0.0.19535.9.6343012-1@bounce.bni.com)
554 5.7.1 <validxxxg@gmail.com>: Relay access denied; from=<iasciznqf@blt-design.com> to=<validxxxg@gmail.com> proto=ESMTP helo=<mail.blt-design.com> (total: 1)
1 38.68.48.110 (iasciznqf@blt-design.com)

Warnings
--------
smtpd (total: 43)
35 hostname ip-113-114.4vendeta.com does not resolve to address 78.128.113.114: Name or service not known
2 hostname 178-73-215-171-static.glesys.net does not resolve to address 178.73.215.171: Name or service not known
1 hostname security.criminalip.com does not resolve to address 89.248.168.112
1 hostname zg-0708a-64.stretchoid.com does not resolve to address 192.241.214.134: Name or service not known
1 hostname rnd.group-ib.ru does not resolve to address 80.82.70.118
1 hostname zg-0708c-1.stretchoid.com does not resolve to address 162.243.129.151: Name or service not known
1 non-SMTP command from implant-scanner-victims-will-be-notified.threatsinkhole.com[172.105.89.161]: GET / HTTP/1.0
1 TLS library problem: error:1420918C:SSL routines:tls_early_post_process_client_hello:version too low:../ssl/statem/statem_srvr.c:1667:
trivial-rewrite (total: 4)
4 do not list domain somagroup.com.br in BOTH mydestination and virtual_alias_domains