Primary Hostname Sending spam

Operating System & Version
CentOS 7.9
cPanel & WHM Version
102.0.8
Jul 7, 2006
20
4
153
Hi,

Recently deployed a Cpanel server. We noticed a great deal of spam coming from the server hostname
Server hostname : ns1.wizkidhosting.com

A snippet of exim_mainlog

2022-04-25 08:22:24 1nimUi-0000ST-0I <= [email protected] H=(ns1.domain.com) [127.0.0.1]:57276 P=esmtp S=24112 id=[email protected] T="You appeared in 4 searches this week" for [email protected]
2022-04-25 08:22:24 SMTP connection from (ns1.domain.com) [127.0.0.1]:57276 closed by QUIT
2022-04-25 08:22:24 1nimUi-0000SU-1m <= [email protected] H=(ns1.domain.com) [127.0.0.1]:57278 P=esmtp S=23834 id=[email protected] T="You appeared in 5 searches this week" for [email protected]


Any insights much appreciated.
 
Last edited by a moderator:
Jul 7, 2006
20
4
153
Hi @quietFinn,

Yep but I can say that these accounts are non-existent and keeps changing all the time, in fact ns1.wizkidhosting.com is the primary domain and does not have a default mailbox
 

quietFinn

Well-Known Member
Feb 4, 2006
2,023
542
493
Finland
cPanel Access Level
Root Administrator
There is no such a thing as "primary domain", in the exim log you can see the usernames where the mails are sent from (i.e. form USERNAME@HOSTNAME).
If those users are not cPanel users I'd think that your server is compromised.
Check what users you have in /home directory.
 

Spirogg

Well-Known Member
Feb 21, 2018
700
163
43
chicago
cPanel Access Level
Root Administrator
@philwebservices

when I tried to access your site I got this in my browser.

Website blocked due to a Trojan
Your Malwarebytes Premium blocked this website because it may contain a Trojan.

We strongly recommend you do not continue.

@quietFinn seems to be correct, you are compromised unfortunately
 
  • Like
Reactions: philwebservices

Spirogg

Well-Known Member
Feb 21, 2018
700
163
43
chicago
cPanel Access Level
Root Administrator