• Resolved Kimbert

    (@kimbert)


    I am receiving spam emails from my own site.

    they have links in them. What does this mean? Is it malware being plugged into my data base?

    I have had changes done on my site and on my host

    The following files were added to your host:

    /home/mydatabase/www/wp-content/cache/wp-cache-db61df2e122a07351f2de02b1ef4b2a2.php (modified on: 2016-06-10 15:07:01)
    /home/mydatabase/www/wp-content/cache/wp-cache-90f06f614daadc3678d6cab33d0bd0c7.php (modified on: 2016-06-10 14:58:32)
    /home/mydatabase/www/wp-content/cache/meta/wp-cache-8e029fc8cd13af2aec7978408edfc330.php (modified on: 2016-06-10 15:07:08)
    /home/mydatabase/www/wp-content/cache/meta/wp-cache-90f06f614daadc3678d6cab33d0bd0c7.php (modified on: 2016-06-10 14:58:32)
    /home/mydatabase/www/wp-content/cache/meta/wp-cache-db61df2e122a07351f2de02b1ef4b2a2.php (modified on: 2016-06-10 15:07:01)
    /home/mydatabase/www/wp-content/cache/wp-cache-8e029fc8cd13af2aec7978408edfc330.php (modified on: 2016-06-10 15:07:08)
    ======================================

    The following files were removed from your host:

    /home/mydatabase/www/wp-content/cache/supercache/thereddoorgallery.org/a-propos/index.html (modified on: 2016-06-09 18:28:52)
    ======================================

    The following files were changed on your host:

    /home/mydatabase/www/.htaccess (modified on: 2016-06-10 15:18:47)
    /home/mydatabase/www/wp-content/languages/admin-network-fr_FR.po (modified on: 2016-06-10 13:56:51)
    /home/mydatabase/www/wp-content/languages/admin-network-pt_PT.mo (modified on: 2016-06-10 02:45:31)
    /home/mydatabase/www/wp-content/languages/admin-pt_PT.mo (modified on: 2016-06-10 02:45:31)
    /home/mydatabase/www/wp-content/languages/admin-fr_FR.po (modified on: 2016-06-10 13:56:51)

    and alot more languages files

    /home/mydatabase/www/wp-content/wflogs/config.php (modified on: 2016-06-10 15:07:52)
    /home/mydatabase/www/wp-content/aiowps_backups/.htaccess.backup (modified on: 2016-06-10 15:18:47)
    /home/mydatabase/www/wp-content/plugins/wp-spamshield/readme.txt (modified on: 2016-06-10 14:59:37)
    /home/mydatabase/www/wp-content/plugins/wordfence/tmp/configCache.php (modified on: 2016-06-10 15:11:56)
    /home/mydatabase/www/wp-content/plugins/wp-super-cache/readme.txt (modified on: 2016-06-10 14:59:58)
    ======================================

    https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/

Viewing 9 replies - 1 through 9 (of 9 total)
  • Plugin Contributor wpsolutions

    (@wpsolutions)

    I am receiving spam emails from my own site

    No this is not spam.
    You have enabled the file change detection feature and it is sending you an email when it detects a file change on your system.

    Events which are not necessarily malicious but which will cause the file change detection feature to trigger are:
    1) WP core was automatically updated on your site
    2) A plugin was automatically updated on your site
    3) You updated a theme or plugin
    4) You are using a caching plugin which regularly changes/adds/deletes files.
    5) You uploaded photos or other media via the wp media uploader.
    6) there are probably other legitimate cases I’m sure I’ve missed

    And of course the file change detection feature will also detect when an unauthorised file change has been made.

    Thread Starter Kimbert

    (@kimbert)

    Here is the header of one of the spam emails I am receiving

    Return-Path: <trdg@thereddoorgallery.org>
    Delivered-To: trdg@thereddoorgallery.org
    Received: from localhost (HELO queue) (127.0.0.1)
    by localhost with SMTP; 10 Jun 2016 18:23:15 +0200
    Received: from out3.mail.ovh.net (149.202.197.45)
    by mx1.ovh.net with AES256-GCM-SHA384 encrypted SMTP; 10 Jun 2016 18:23:13 +0200
    Received: from vr1.mail.ovh.net (vr1.mail.ovh.net [37.59.21.180])
    by out3.mail.ovh.net (Postfix) with ESMTP id 826141A5FB
    for <trdg@thereddoorgallery.org>; Fri, 10 Jun 2016 18:23:13 +0200 (CEST)
    Received: from in6.mail.ovh.net (in6.mail.ovh.net [149.202.197.44])
    by vr1.mail.ovh.net (Postfix) with ESMTP id 7217513B4
    for <trdg@thereddoorgallery.org>; Fri, 10 Jun 2016 18:23:13 +0200 (CEST)
    Received-SPF: Permerror (SPF Permanent Error: Void lookup limit of 2 exceeded) identity=mailfrom; client-ip=113.162.238.203; helo=dynamic.vdc.vn; envelope-from=trdg@thereddoorgallery.org; receiver=trdg@thereddoorgallery.org
    Received: from dynamic.vdc.vn (unknown [113.162.238.203])
    by in6.mail.ovh.net (Postfix) with ESMTP id 5F2881CE
    for <trdg@thereddoorgallery.org>; Fri, 10 Jun 2016 18:23:12 +0200 (CEST)
    From: <trdg@thereddoorgallery.org>
    To: <trdg@thereddoorgallery.org>
    Subject: [SPAM] [SPAM] Advanced Formula – Brand-New Progressive Product
    Date: 11 Jun 2016 05:11:03 +0600
    Message-ID: <001801d1c36f$079ad5a3$2b61dab5$@thereddoorgallery.org>
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary=”—-=_NextPart_000_0015_01D1C36F.0795E7FC”
    X-Mailer: Microsoft Office Outlook 11
    Thread-Index: Ac7af7sp55c31bd77af7sp55c31bd7==
    X-MimeOLE: Produced By Microsoft MimeOLE V6.1.7601.17514
    X-Ovh-Tracer-Id: 16821226084797613959
    X-VR-SPAMSTATE: SPAM
    X-VR-SPAMSCORE: 300
    X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrfeekledrjeejgdeliecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemuceftddtnecuogfuphgrmhffohhmrghinhculdeftddtmd
    X-Ovh-Spam-Status: SPAM
    X-Ovh-Spam-Reason: vr: SPAM; dkim: disabled; spf: disabled
    X-Ovh-Message-Type: SPAM
    X-Ovh-Remote: 149.202.197.45 (out3.mail.ovh.net)
    X-Ovh-Local: 213.186.33.29 (mx1.ovh.net)
    X-OVH-SPAMSTATE: SPAM
    X-OVH-SPAMSCORE: 300
    X-OVH-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrfeekledrjeejucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuqfggjfenuceurghilhhouhhtmecufedttdenucgspfgrthgthhelucdlfedttddm
    X-Spam-Tag: YES (ovhvrmailscanner[300])

    This is a multi-part message in MIME format.

    ——=_NextPart_000_0015_01D1C36F.0795E7FC
    Content-Type: text/plain;
    charset=”iso-8859-1″
    Content-Transfer-Encoding: quoted-printable

    Are you tired of the excess weight and would like to get back on track =
    without any painful efforts?

    Brand-new formula and advanced structure of our exclusive product will =
    compliment your results
    and will help you to lose weight with no side-effects.

    Click Here!

    Stock is limited, make sure to get yours in order to have a beautiful =
    and healthy body!
    ——=_NextPart_000_0015_01D1C36F.0795E7FC
    Content-Type: text/html;
    charset=”iso-8859-1″
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE HTML PUBLIC “-//W3C//DTD HTML 4.0 Transitional//EN”>
    <HTML><HEAD>
    <META content=3D”text/html; charset=3Dus-ascii” =
    http-equiv=3DContent-Type>
    <META name=3DGENERATOR content=3D”MSHTML 8.00.7601.17514″></HEAD>
    <BODY>
    <DIV><SPAN class=3D321615397-10062016><FONT size=3D2=20
    face=3DArial>Are you tired of the excess weight and would like to get =
    back on track without any painful efforts?

    Brand-new formula and advanced structure of our exclusive product will =
    compliment your results
    and will help you to lose weight with no side-effects.

    <a =
    href=3D”http://cvit.dk/wp-content/plugins/simple-tags/assets/css/”><b>Cli=
    ck Here!</b>

    Stock is limited, make sure to get yours in order to have a beautiful =
    and healthy body!
    </FONT></SPAN></DIV></BODY></HTML>
    ——

    Plugin Contributor wpsolutions

    (@wpsolutions)

    In this case it looks like you may have been hacked and you should get your site cleaned.
    You might find the following useful:
    https://codex.wordpress.org/FAQ_My_site_was_hacked

    Hi,

    You’re not receiving email from your site, unless you host it in Vietnam (see the whois info for the IP below):

    Received: from dynamic.vdc.vn (unknown [113.162.238.203])
    

    If you wonder how it’s possible that someone sends emails that look like they have been sent from your email address, there’s a good article on it on Lifehacker.

    Cheers,
    Česlav

    Thread Starter Kimbert

    (@kimbert)

    Ceslav,

    I like angels like you!

    will look into this…at the moment I am organising too many things but will be into this soon…

    Why didn’t my host tell me this?

    Thread Starter Kimbert

    (@kimbert)

    If I want to report him/her on the stop spammers site, how do I do that?

    Thread Starter Kimbert

    (@kimbert)

    Here is what they ask for

    Spammer username *
    Spammer email address *
    Spammer IP address *
    Your API key *
    Evidence

    I don’t want to report myself!!!

    Hi,

    I’m glad I could help, but bear in mind that this is support forum for AIOWPSF plugin. If you need help dealing with spammers, you have to look elsewhere, your problem is completely unrelated to AIOWPSF.

    Thread Starter Kimbert

    (@kimbert)

    I just received an email from my server showing me options to block out spam

    They say to create an SPF field (probably different in English) that allows the receiving server to insure that the email has been sent by the valid server. This is to limit spam, but only works if the receiving server is configured to treat the SPF fields.
    (this is my bad translation of their explanations below)

    Il vous est possible de mettre en place un champ SPF.
    Le SPF permet au serveur de réception mail de s’assurer que l’email a bien été envoyé par un serveur qui en a le droit. Ceci a pour but de limiter le spam, mais cela ne fonctionne que si le serveur de réception est configuré pour interpréter les champs SPF.

Viewing 9 replies - 1 through 9 (of 9 total)
  • The topic ‘receiving spam emails via my site’ is closed to new replies.