/var/log/qmail/current:
2015-03-06 00:19:25.241340500 new msg 28344921
2015-03-06 00:19:25.241342500 info msg 28344921: bytes 2350 from <egrambow@wintermute.XXX.com> qp 9218 uid 453
2015-03-06 00:19:25.464009500 starting delivery 118968: msg 28344921 to local alias-localdelivery-maillog@XXX.com
2015-03-06 00:19:25.464012500 status: local 1/20 remote 0/20
2015-03-06 00:19:25.464013500 starting delivery 118969: msg 28344921 to remote friedrich-blase@YYY.de
2015-03-06 00:19:25.464015500 status: local 1/20 remote 1/20
2015-03-06 00:19:25.648957500 new msg 28345016
2015-03-06 00:19:25.648959500 info msg 28345016: bytes 2475 from <egrambow@wintermute.XXX.com> qp 9226 uid 400
2015-03-06 00:19:25.766755500 starting delivery 118970: msg 28345016 to local maillog@wintermute.XXX.com
2015-03-06 00:19:25.766757500 status: local 2/20 remote 1/20
2015-03-06 00:19:25.766759500 delivery 118968: success: forward:_qp_9226/did_0+0+1/
2015-03-06 00:19:25.766761500 status: local 1/20 remote 1/20
2015-03-06 00:19:25.778446500 delivery 118970: success: procmail:_Couldn't_create_"/var/mail/maillog"/did_0+0+2/
2015-03-06 00:19:25.778449500 status: local 0/20 remote 1/20
2015-03-06 00:19:25.778450500 end msg 28345016
2015-03-06 00:19:25.779421500 delivery 118969: failure: 194.25.134.9_failed_after_I_sent_the_message./Remote_host_said:_550-5.7.0_Message_considered_as_spam_or_virus,_rejected/550-5.7.0_Your_IP:_80.152.140.223/550-5.7.0_Mailhost:_mailin53.aul.t-online.de/550-5.7.0_Timestamp:_2015-03-05T23:19:25Z/550-5.7.0_Expurgate-ID:_149288::1425597565-00001484-840A5F02/0-16018943334/0-10/550-5.7.0_Authenticator:_1F643F346C84648EFBC471676D248C7586342FBF75BFF24F5F03EAF21A31AD793F5B18D4/550-5.7.0_/550-5.7.0_Your_message_has_been_rejected_due_to_spam_or_virus_classification./550-5.7.0_If_you_feel_this_is_inapplicable,_please_report_the_above_error_codes/550-5.7.0_back_to_FPR@RX.T-ONLINE.DE_to_help_us_fix_possible_misclassification./550-5.7.0_We_apologize_for_any_inconvenience_and_thank_you_for_your_assistance!/550-5.7.0_/550-5.7.0_Die_Annahme_Ihrer_Nachricht_wurde_abgelehnt,_da_sie_als_Spam_oder/550-5.7.0_Virus_eingestuft_wurde._Sollten_Sie_dies_als_unzutreffend_ansehen,/550-5.7.0_senden_Sie_bitte_obige_Fehlercodes_an_FPR@RX.T-ONLINE.DE,_damit_wir/550-5.7.0_die_Klassifizierung_untersuchen_k__nnen._Wir_entschuldigen_uns_f__r/550_5.7.0_etwaige_Unannehmlichkeiten_und_bedanken_uns_f__r_Ihre_Unterst__tzung!/
2015-03-06 00:19:25.779565500 status: local 0/20 remote 0/20
2015-03-06 00:19:25.941008500 bounce msg 28344921 qp 9241
2015-03-06 00:19:25.941070500 end msg 28344921
2015-03-06 00:19:25.941243500 new msg 28345064
/var/log/qpsmtpd/current invece contiene righe tipo:
2015-03-06 09:14:51.344486500 2987 Accepted connection 0/40 from 195.135.130.51 / mail2.osite.de
2015-03-06 09:14:51.344488500 2987 Connection from mail2.osite.de [195.135.130.51]
2015-03-06 09:14:51.345921500 2987 tls plugin (init): ciphers: HIGH:!SSLv2:!ADH:!aNULL:!MD5:!RC4
2015-03-06 09:14:51.348964500 2987 tls plugin (init): ciphers: HIGH:!SSLv2:!ADH:!aNULL:!MD5:!RC4
2015-03-06 09:14:51.365589500 2987 tls plugin (init): ciphers: HIGH:!SSLv2:!ADH:!aNULL:!MD5:!RC4
2015-03-06 09:14:52.372999500 2987 check_earlytalker plugin (connect): remote host said nothing spontaneous, proceeding
2015-03-06 09:14:52.380260500 2987 220 wintermute.XXX.com ESMTP
2015-03-06 09:14:52.469703500 2987 dispatching EHLO mail2.osite.de
2015-03-06 09:14:52.471887500 2987 250-XXX.com Hi mail2.osite.de [195.135.130.51]
2015-03-06 09:14:52.471913500 2987 250-PIPELINING
2015-03-06 09:14:52.471942500 2987 250-8BITMIME
2015-03-06 09:14:52.471973500 2987 250-SIZE 15000000
2015-03-06 09:14:52.472007500 2987 250 STARTTLS
2015-03-06 09:14:52.492380500 2987 dispatching MAIL FROM:<> SIZE=4564 BODY=8BITMIME
2015-03-06 09:14:52.492612500 2987 full from_parameter: FROM:<> SIZE=4564 BODY=8BITMIME
2015-03-06 09:14:52.495453500 2987 getting mail from <>
2015-03-06 09:14:52.495517500 2987 250 <>, sender OK - how exciting to get mail from you!
2015-03-06 09:14:52.495664500 2987 dispatching RCPT TO:<egrambow@wintermute.XXX.com>
2015-03-06 09:14:52.646529500 2987 check_goodrcptto plugin (rcpt): stripping '-' extensions
2015-03-06 09:14:52.647707500 2987 check_goodrcptto plugin (rcpt): recipient egrambow@wintermute.XXX.com denied
2015-03-06 09:14:52.648014500 2987 logging::logterse plugin (deny): ` 195.135.130.51 mail2.osite.de mail2.osite.de <> check_goodrcptto 901 relaying denied egrambow@wintermute.XXX.com msg denied before queued
2015-03-06 09:14:52.648138500 2987 550 relaying denied egrambow@wintermute.XXX.com
2015-03-06 09:14:52.648286500 2987 dispatching DATA
2015-03-06 09:14:52.648649500 2987 503 RCPT first
2015-03-06 09:14:52.738018500 2987 dispatching RSET
2015-03-06 09:14:52.738207500 2987 250 OK
2015-03-06 09:14:52.738296500 2987 dispatching QUIT
2015-03-06 09:14:52.738431500 2987 221 XXX.com closing connection. Have a wonderful day.
2015-03-06 09:14:52.738468500 2987 click, disconnecting
(che a me sembrano normali, pero' guarda caso relative a un solo utente e sempre lo stesso)
Le email sospette sembrano essersi fermate verso le 7 di stamattina, nel frattempo ho chiesto all'utente di cambiare di nuovo password con una difficile da indovinare.
Possono servire altri log?
Grazie x l'attenzione