Forum Replies Created

Viewing 2 replies - 1 through 2 (of 2 total)
  • Thread Starter yokemate

    (@yokemate)

    for example, one example junk email sent:

    
    Subject: You got a message "Ваш билет неизрасходован"
    Details 
    Sent on
    Dec 13, 2020 2:23 PM
    From
    [email protected]
    Reply-to
    [email protected]
    To
    <hidden>@gmail.com
    Message ID
    <[email protected]>
    
    Message Body: Д о б р ы й д е н ь ! Н а п о м и н а е м о В а ш е м в ы и г р ы ш н о м б и л е т е Г о с Л о т о ! З а б е р и т е с в о й в ы и г р ы ш : www.tinyurl.com/y3wx9kny -- This e-mail was sent from a contact form on Report (https://news.china.com.au)
    
    • This reply was modified 4 years, 2 months ago by Yui.
    • This reply was modified 4 years, 2 months ago by Yui. Reason: email redacted
    Thread Starter yokemate

    (@yokemate)

    Thank you for the information.

    I don’t think the wp_mail is working, that’s why we use WP Mail SMTP, right?

    I do have the access.log here:

    
    74.120.14.56 - - [11/Dec/2020:23:39:04 +1100] "GET / HTTP/1.1" 403 146 "-" "-"
    74.120.14.56 - - [11/Dec/2020:23:39:04 +1100] "\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x85z\xDD\xA4\x84Z\xA0\xB66\xBE9\xC1\xBBW}\xDEK\x07p\xA0\x17d\xFCxz\xF1\xBAtFG_\xF0\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"
    74.120.14.56 - - [11/Dec/2020:23:39:04 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
    209.17.96.34 - - [12/Dec/2020:07:48:10 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; https://cloudsystemnetworks.com)"
    209.17.97.66 - - [13/Dec/2020:10:58:29 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; https://cloudsystemnetworks.com)"
    167.248.133.40 - - [13/Dec/2020:11:38:21 +1100] "\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xFAXs\x9A\xF3n!\xE0\x0C\xB42\xDB\xFC\x1B\x98\xD8\x03\xE1\xAD\x08\xFB\xAF\x0C\x9C\x9F\xA4\x88\xA159\xF8\xDE\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"
    167.248.133.40 - - [13/Dec/2020:11:38:22 +1100] "GET / HTTP/1.1" 403 146 "-" "-"
    167.248.133.40 - - [13/Dec/2020:11:38:22 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
    74.120.14.56 - - [13/Dec/2020:13:55:00 +1100] "GET / HTTP/1.1" 403 146 "-" "-"
    74.120.14.56 - - [13/Dec/2020:13:55:01 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
    74.120.14.56 - - [13/Dec/2020:13:55:02 +1100] "\x16\x03\x01\x00{\x01\x00\x00w\x03\x03Q+6\xD6\x84u\xB7\xD6z\x89U\x16\x87\xA2\x229H\x08S\xEB\x97\xB7\xD7\xCAG.\x9B\x94_\x96x\xC7\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"
    167.248.133.39 - - [14/Dec/2020:05:03:06 +1100] "\x16\x03\x01\x00{\x01\x00\x00w\x03\x03:\x92\xF3\xAB\x127~4\xE1\xCD\xA8Y\x01\xDB|,\xB1\xE9m\x8B\x95\xFD\xB5\xBFE\xB6\xF0\xFC\x89\x09\x10\xEC\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"
    167.248.133.39 - - [14/Dec/2020:05:03:07 +1100] "GET / HTTP/1.1" 403 146 "-" "-"
    167.248.133.39 - - [14/Dec/2020:05:03:07 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
    162.142.125.53 - - [14/Dec/2020:08:17:58 +1100] "GET / HTTP/1.1" 403 146 "-" "-"
    162.142.125.53 - - [14/Dec/2020:08:17:58 +1100] "\x16\x03\x01\x00{\x01\x00\x00w\x03\x03(\xF9+\x96;.N\x8F4\xBA\xF1\xDF\xD9P]\x83[!\x89n%\xC0\xEF\xA2\xB6h\xB8 \xFE\xA0\xFD\xD5\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0" 400 150 "-" "-"
    162.142.125.53 - - [14/Dec/2020:08:17:58 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
    206.189.182.216 - - [14/Dec/2020:10:38:57 +1100] "GET / HTTP/1.0" 403 146 "-" "-"
    209.17.96.178 - - [14/Dec/2020:14:41:04 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; https://cloudsystemnetworks.com)"
    112.213.126.151 - - [14/Dec/2020:18:43:27 +1100] "GET /pma HTTP/1.1" 404 548 "https://54.79.226.8:888/pma" "Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)"
    209.17.97.2 - - [15/Dec/2020:13:48:16 +1100] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; https://cloudsystemnetworks.com)"
    

    Don’t know why and how they access my site, but nothing I can see if anyone is using the WP Mail SMTP to send out those emails.

    If you like, I can send you the site.log which is about 160Mb. In side, most of them posts/pages viewed by visitors.

    • This reply was modified 4 years, 2 months ago by Yui.
    • This reply was modified 4 years, 2 months ago by Yui. Reason: please use CODE button for proper formatting
Viewing 2 replies - 1 through 2 (of 2 total)