Весь моцк сломал уже :(
Подскажите, пожалуйста, как найти этот злорадный скрипт, который рассылает спам и грузит ЦП на 100%.ПО на сервере: Directadmin, Apache, Php, Mysql, Exim, Dovecot, Proftpd
Процесс mail (perl 5.8.8) запускатся с частотой 10-15 минут. Убиение процессов ни к чему не приводит.
Пробовал следующее:
В директории /var/log/httpd логи апача всех клиентов.
[root@da /var/log/httpd]# grep -r "\.pl" *
[root@da /var/log/httpd]# grep -r "\.cgi" *
Только эрроры
Полный лог proftpd за несколько часов
[root@da /var/log/proftpd]# cat paranoid.log
::ffff:178.95.25.6 UNKNOWN ftp [21/Jul/2011:23:04:26 +0300] "USER yuzhnyorg" 331 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:27 +0300] "PASS (hidden)" - -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:27 +0300] "SYST" 215 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:27 +0300] "FEAT" 211 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:27 +0300] "PWD" 257 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:27 +0300] "TYPE A" 200 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:28 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:28 +0300] "LIST" 226 915
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:33 +0300] "CWD public_html" 250 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:33 +0300] "PWD" 257 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:33 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:34 +0300] "LIST" 226 2082
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:50 +0300] "SIZE page.php" 550 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:50 +0300] "TYPE I" 200 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:50 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:04:51 +0300] "RETR page.php" 226 3284
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:05:22 +0300] "SIZE head.php" 213 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:05:22 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:05:22 +0300] "RETR head.php" 226 2969
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:41 +0300] "PWD" 257 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:44 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:45 +0300] "STOR head.php" 226 4731
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:45 +0300] "SIZE head.php" 213 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:45 +0300] "TYPE A" 200 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:45 +0300] "PASV" 227 -
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:06:45 +0300] "LIST" 226 2082
::ffff:178.95.25.6 UNKNOWN yuzhnyorg [21/Jul/2011:23:12:21 +0300] "QUIT" 221 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:11 +0300] "USER anonymous" 331 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:11 +0300] "PASS (hidden)" 530 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:12 +0300] "QUIT" 221 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:12 +0300] "USER anonymous" 331 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:13 +0300] "PASS (hidden)" 530 -
::ffff:66.249.72.3 UNKNOWN ftp [22/Jul/2011:00:35:13 +0300] "QUIT" 221 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:35:53 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:38:59 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:00 +0300] "PASS (hidden)" 530 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:00 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:00 +0300] "PASS (hidden)" 530 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:30 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:30 +0300] "PASS (hidden)" 530 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:30 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:39:30 +0300] "PASS (hidden)" 530 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:40:30 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:40:30 +0300] "PASS (hidden)" 530 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:40:30 +0300] "USER anonymous" 331 -
::ffff:93.81.219.118 UNKNOWN ftp [22/Jul/2011:00:40:31 +0300] "PASS (hidden)" 530 -
Информация о системе:
[root@da /home]# uname -a
FreeBSD da.geonic.net 6.2-RELEASE FreeBSD 6.2-RELEASE #0: Fri Jan 12 11:05:30 UTC 2007 root@dessler.cse.buffalo.edu:/usr/obj/usr/src/sys/SMP i386
[root@da /home]# top
last pid: 12857; load averages: 3.47, 2.66, 3.25 up 1+02:39:54 00:31:23
114 processes: 7 running, 106 sleeping, 1 zombie
CPU states: 63.5% user, 0.0% nice, 31.8% system, 2.1% interrupt, 2.6% idle
Mem: 178M Active, 508M Inact, 244M Wired, 40M Cache, 109M Buf, 1620K Free
Swap: 4096M Total, 60M Used, 4036M Free, 1% Inuse
PID USERNAME THR PRI NICE SIZE RES STATE C TIME WCPU COMMAND
12685 root 1 127 0 12824K 10520K RUN 1 0:26 44.10% dataskq
12207 apache 1 102 0 11228K 5428K select 1 1:04 11.43% perl5.8.8
11680 apache 1 104 0 10544K 5572K RUN 1 2:06 11.28% perl5.8.8
12326 apache 1 103 0 9996K 5316K select 1 0:49 11.18% perl5.8.8
12327 apache 1 103 0 10472K 5300K select 0 0:52 10.74% perl5.8.8
11544 apache 1 100 0 10516K 5496K RUN 0 2:16 8.59% perl5.8.8
11583 apache 1 102 0 11188K 5696K RUN 0 2:34 8.54% perl5.8.8
12206 apache 1 99 0 11140K 5348K select 0 0:55 7.76% perl5.8.8
11689 apache 1 99 0 11048K 5496K RUN 0 2:14 7.62% perl5.8.8
11545 apache 1 98 0 11352K 5512K select 0 2:30 6.25% perl5.8.8
11679 apache 1 98 0 10936K 5584K select 1 2:21 5.96% perl5.8.8
11690 apache 1 99 0 10664K 5596K select 1 2:03 5.86% perl5.8.8
11582 apache 1 98 0 10844K 5512K select 1 2:12 5.57% perl5.8.8
12493 apache 1 101 0 7912K 4692K select 1 0:18 5.52% perl5.8.8
11440 apache 1 100 0 8892K 4944K CPU1 1 1:29 5.32% perl5.8.8
11454 apache 1 98 0 9148K 4932K select 0 1:31 4.69% perl5.8.8
12814 apache 1 96 0 7508K 4640K select 1 0:02 1.99% perl5.8.8
12752 apache 1 20 0 30556K 19964K lockf 0 0:01 1.40% httpd
12749 apache 1 20 0 32832K 22236K lockf 0 0:01 0.85% httpd
971 bind 1 96 0 23192K 19836K select 0 5:46 0.00% named
633 root 1 96 0 6196K 488K select 1 2:01 0.00% snmpd
94022 mysql 5 20 0 43468K 25704K kserel 0 0:30 0.00% mysqld
759 apache 5 20 0 200M 1100K kserel 0 0:24 0.00% mysqld
854 root 1 8 0 916K 272K nanslp 0 0:03 0.00% da-popb4smt
1571 apache 1 20 0 1692K 392K pause 1 0:03 0.00% cache_clean
703 root 1 96 0 3084K 1372K select 0 0:01 0.00% openvpn
9157 koshak 1 96 0 6252K 2656K select 0 0:01 0.00% sshd
99496 mail 1 96 0 3052K 2332K select 0 0:01 0.00% exim
11534 root 1 8 0 29952K 18996K nanslp 0 0:01 0.00% httpd
6138 koshak 1 96 0 6252K 2476K select 0 0:01 0.00% sshd
748 root 1 8 0 1436K 316K nanslp 0 0:01 0.00% cron
12806 apache 1 20 0 30584K 19628K lockf 0 0:01 0.00% httpd
9159 root 1 8 0 12784K 11380K wait 0 0:01 0.00% bash
91002 root 1 4 0 1536K 1024K kqread 0 0:01 0.00% dovecot
91003 root 1 4 0 2228K 1524K kqread 0 0:01 0.00% dovecot-aut
12750 apache 1 20 0 30512K 19784K lockf 0 0:00 0.00% httpd
734 root 1 96 0 3536K 348K select 0 0:00 0.00% sshd
6929 root 1 5 0 3288K 1768K ttyin 1 0:00 0.00% bash
12805 apache 1 4 0 30540K 19752K kqread 0 0:00 0.00% httpd
799 root 1 8 0 4300K 168K wait 0 0:00 0.00% directadmin
12764 apache 1 20 0 30548K 19804K lockf 0 0:00 0.00% httpd
12751 apache 1 96 0 36968K 26208K select 0 0:00 0.00% httpd
12804 apache 1 96 0 33172K 22400K select 0 0:00 0.00% httpd
677 root 1 96 0 1288K 116K select 1 0:00 0.00% usbd
12773 apache 1 20 0 31056K 20260K lockf 0 0:00 0.00% httpd
12498 mail 1 4 0 3196K 2492K sbwait 1 0:00 0.00% exim
12753 apache 1 20 0 32840K 22100K lockf 0 0:00 0.00% httpd
3309 root 1 96 0 1376K 896K select 0 0:00 0.00% syslogd
3469 root 1 96 0 3400K 2540K select 1 0:00 0.00% proftpd
12838 root 1 96 0 2588K 1668K CPU0 0 0:00 0.00% top
6126 root 1 4 0 6276K 2476K sbwait 0 0:00 0.00% sshd
9143 root 1 4 0 6276K 2652K sbwait 0 0:00 0.00% sshd
6139 koshak 1 8 0 3220K 1588K wait 0 0:00 0.00% bash
94001 root 1 8 0 1728K 928K wait 0 0:00 0.00% sh
9158 koshak 1 8 0 3220K 1804K wait 1 0:00 0.00% bash
[root@da /home]# ps -ax | grep perl
11440 ?? Rs 1:32.13 mail (perl5.8.8)
11454 ?? Ss 1:34.00 mail (perl5.8.8)
11544 ?? Rs 2:21.31 mail (perl5.8.8)
11545 ?? Rs 2:35.56 mail (perl5.8.8)
11582 ?? Rs 2:17.47 mail (perl5.8.8)
11583 ?? Rs 2:39.45 mail (perl5.8.8)
11679 ?? Ss 2:26.66 mail (perl5.8.8)
11680 ?? Ss 2:10.03 mail (perl5.8.8)
11689 ?? Rs 2:18.40 mail (perl5.8.8)
11690 ?? Ss 2:07.97 mail (perl5.8.8)
12206 ?? Rs 0:59.91 mail (perl5.8.8)
12207 ?? Rs 1:08.43 mail (perl5.8.8)
12326 ?? Rs 0:52.70 mail (perl5.8.8)
12327 ?? Rs 0:55.82 mail (perl5.8.8)
12493 ?? Rs 0:20.31 mail (perl5.8.8)
12814 ?? Rs 0:05.79 mail (perl5.8.8)
12864 ?? Rs 0:02.65 mail (perl5.8.8)
12865 ?? Ss 0:02.70 mail (perl5.8.8)
12940 p1 RL+ 0:00.00 grep perl
[root@da /home]# lsof -p 11583
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
perl5.8.8 11583 apache cwd VDIR 0,90 512 2 /
perl5.8.8 11583 apache rtd VDIR 0,90 512 2 /
perl5.8.8 11583 apache txt VREG 0,90 9424 11262916 /usr/local/bin/perl
perl5.8.8 11583 apache txt VREG 0,90 158712 13942785 /libexec/ld-elf.so.1
perl5.8.8 11583 apache txt VREG 0,90 1143145 11611342 /usr/local/lib/perl5/5.8.8/mach/CORE/libperl.so
perl5.8.8 11583 apache txt VREG 0,90 98120 26189828 /lib/libm.so.4
perl5.8.8 11583 apache txt VREG 0,90 28680 26189826 /lib/libcrypt.so.3
perl5.8.8 11583 apache txt VREG 0,90 43572 26189832 /lib/libutil.so.5
perl5.8.8 11583 apache txt VREG 0,90 922668 26189837 /lib/libc.so.6
perl5.8.8 11583 apache txt VREG 0,90 16534 11591352 /usr/local/lib/perl5/5.8.8/mach/auto/IO/IO.so
perl5.8.8 11583 apache txt VREG 0,90 23392 11611159 /usr/local/lib/perl5/5.8.8/mach/auto/Socket/Socket.so
perl5.8.8 11583 apache txt VREG 0,90 103741 11591527 /usr/local/lib/perl5/5.8.8/mach/auto/POSIX/POSIX.so
perl5.8.8 11583 apache 0r VCHR 0,26 0t0 26 /dev/null
perl5.8.8 11583 apache 1w VCHR 0,26 0t0 26 /dev/null
perl5.8.8 11583 apache 2w VCHR 0,26 0t0 26 /dev/null
perl5.8.8 11583 apache 3u IPv4 0xc6a09000 0t0 TCP geonic.net:59071->mail.kemptonchiropractic.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 4u PIPE 0xc4ed5be0 0 ->0xc4ed5b28
perl5.8.8 11583 apache 5u IPv4 0xc77fe168 0t0 UDP *:53615
perl5.8.8 11583 apache 6u IPv4 0xc50ef740 0t0 TCP geonic.net:58411->ns35.xenserve.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 7u IPv4 0xc76c5cb0 0t0 TCP geonic.net:59256->mx1c38.carrierzone.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 8u IPv4 0xc621b570 0t0 TCP geonic.net:58928->cmx0.sol.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 9u IPv4 0xc8388740 0t0 TCP geonic.net:58660->mail.vcity.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 10u IPv4 0xc80eae10 0t0 UDP *:59257
perl5.8.8 11583 apache 11u IPv4 0xc77863a0 0t0 TCP geonic.net:59192->mx0a-00075501.pphosted.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 12u IPv4 0xc654eae0 0t0 TCP geonic.net:59103->168.61.70.65:smtp (ESTABLISHED)
perl5.8.8 11583 apache 13u IPv4 0xc77cf924 0t0 UDP *:57613
perl5.8.8 11583 apache 14u IPv4 0xc8023570 0t0 TCP geonic.net:58385->hood.cnchost.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 15u IPv4 0xc7fc8b40 0t0 UDP *:63470
perl5.8.8 11583 apache 16u IPv4 0xc77293a0 0t0 TCP geonic.net:59169->74-94-197-163-Pennsylvania.hfc.comcastbusiness.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 17u IPv4 0xc5c3f5a0 0t0 UDP *:57839
perl5.8.8 11583 apache 18u IPv4 0xc83c0570 0t0 TCP geonic.net:57230->mail1.sadad.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 19u IPv4 0xc5a4c000 0t0 TCP geonic.net:58377->tripmail.trip.com.br:smtp (ESTABLISHED)
perl5.8.8 11583 apache 20u IPv4 0xc5012000 0t0 TCP geonic.net:59074->westpointcity.org:smtp (ESTABLISHED)
perl5.8.8 11583 apache 21u IPv4 0xc9dd3910 0t0 TCP geonic.net:59188->server86.appriver.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 22u IPv4 0xc74b27bc 0t0 UDP *:57251
perl5.8.8 11583 apache 23u IPv4 0xc98e8000 0t0 TCP geonic.net:58829->ns2.nittsu.co.jp:smtp (ESTABLISHED)
perl5.8.8 11583 apache 24u IPv4 0xc66a8ae0 0t0 TCP geonic.net:57921->obmail.paccar.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 25u IPv4 0xc606d1d0 0t0 TCP localhost:59058->localhost:smtp (ESTABLISHED)
perl5.8.8 11583 apache 26u IPv4 0xc8320910 0t0 TCP geonic.net:59159->smtpproxy3.earth1.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 27u IPv4 0xc9d94cb0 0t0 TCP geonic.net:58952->mx3.xs4all.nl:smtp (ESTABLISHED)
perl5.8.8 11583 apache 28u IPv4 0xc59f71d0 0t0 TCP geonic.net:58917->mail.enterprise.k12.ca.us:smtp (ESTABLISHED)
perl5.8.8 11583 apache 29u IPv4 0xc7eb4000 0t0 UDP *:50424
perl5.8.8 11583 apache 30u IPv4 0xc5045cb0 0t0 TCP geonic.net:58902->mail.dl.cn:smtp (ESTABLISHED)
perl5.8.8 11583 apache 31u IPv4 0xc6ddb3a0 0t0 TCP geonic.net:59028->dfw0100b.zsi.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 32u IPv4 0xc5cf0d5c 0t0 UDP *:60706
perl5.8.8 11583 apache 33u IPv4 0xc63da3a0 0t0 TCP geonic.net:57180->mail2.pharsight.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 34u IPv4 0xc621aae0 0t0 TCP geonic.net:57487->www.ihz.it:smtp (ESTABLISHED)
perl5.8.8 11583 apache 35u IPv4 0xc92491d0 0t0 TCP geonic.net:58397->mx.jazztel.es:smtp (ESTABLISHED)
perl5.8.8 11583 apache 36u IPv4 0xc82d2910 0t0 TCP geonic.net:59221->ns4.ecore.com.au:smtp (SYN_SENT)
perl5.8.8 11583 apache 37u IPv4 0xc644f000 0t0 TCP geonic.net:58960->eastmailhub.treas.gov:smtp (ESTABLISHED)
perl5.8.8 11583 apache 38u IPv4 0xc6885000 0t0 TCP geonic.net:59089->super.bagco-ng.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 40u IPv4 0xc66a7910 0t0 TCP geonic.net:58425->mx.jazztel.es:smtp (ESTABLISHED)
perl5.8.8 11583 apache 41u IPv4 0xc9d9e3a0 0t0 TCP geonic.net:58977->mailgw.hamur.hanjin.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 42u IPv4 0xc6a2e3a0 0t0 TCP geonic.net:59065->ww-in-f27.1e100.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 43u IPv4 0xc6e60cb0 0t0 TCP geonic.net:58672->mtalibero21.libero.it:smtp (ESTABLISHED)
perl5.8.8 11583 apache 44u IPv4 0xc9e5e3a0 0t0 TCP geonic.net:59020->commcenter.bresnan.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 45u IPv4 0xc9eab910 0t0 TCP geonic.net:59235->mtalibero08.libero.it:smtp (ESTABLISHED)
perl5.8.8 11583 apache 46u IPv4 0xc6b54000 0t0 TCP geonic.net:59024->correu.lleida.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 47u IPv4 0xc63a60b4 0t0 UDP *:56295
perl5.8.8 11583 apache 48u IPv4 0xc78c7000 0t0 TCP geonic.net:59151->dd8100.kasserver.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 49u IPv4 0xc6dd91d0 0t0 TCP geonic.net:59183->mx.east.cox.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 50u IPv4 0xc98f0910 0t0 TCP geonic.net:59036->smtp-in-1.userservices.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 51u IPv4 0xc5895740 0t0 TCP geonic.net:59008->Static-IP-cr19014612612.cable.net.co:smtp (SYN_SENT)
perl5.8.8 11583 apache 52u IPv4 0xc77fd7bc 0t0 UDP *:62986
perl5.8.8 11583 apache 53u IPv4 0xc83cc570 0t0 TCP geonic.net:59155->207-234-130-219.ptr.primarydns.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 54u IPv4 0xc8074570 0t0 TCP geonic.net:59225->mailgw-4.kofax.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 55u IPv4 0xc63c0cb0 0t0 TCP geonic.net:58310->71-9-150-74.static.oxfr.ma.charter.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 56u IPv4 0xc83c6570 0t0 TCP geonic.net:59100->wy-in-f27.1e100.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 57u IPv4 0xca05e000 0t0 TCP geonic.net:58153->search-core1.bo3.lycos.com:smtp (ESTABLISHED)
perl5.8.8 11583 apache 58u IPv4 0xc83a33a0 0t0 TCP geonic.net:58520->mx1.earthlink.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 59u IPv4 0xc9f70cb0 0t0 TCP geonic.net:57799->65.214.185.134:smtp (ESTABLISHED)
perl5.8.8 11583 apache 60u IPv4 0xc9092cb0 0t0 TCP geonic.net:57999->knott.8086.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 61u IPv4 0xc82f31d0 0t0 TCP geonic.net:58523->external.hdis.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 62u IPv4 0xc5d3b740 0t0 TCP geonic.net:59110->mail2.cancer.org:smtp (ESTABLISHED)
perl5.8.8 11583 apache 63u IPv4 0xc5a36ae0 0t0 TCP geonic.net:58546->mx1.earthlink.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 64u IPv4 0xc82a8cb0 0t0 TCP geonic.net:58550->smtp.getontheweb.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 65u IPv4 0xc8284910 0t0 TCP geonic.net:59238->server94.appriver.com:smtp (SYN_SENT)
perl5.8.8 11583 apache 66u IPv4 0xca0633a0 0t0 TCP geonic.net:59173->hood.cnc.net:smtp (SYN_SENT)
perl5.8.8 11583 apache 67u IPv4 0xc7e13740 0t0 TCP geonic.net:58332->200.39.223.100:smtp (SYN_SENT)
perl5.8.8 11583 apache 68u IPv4 0xc6dd73a0 0t0 TCP geonic.net:59138->dy-in-f27.1e100.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 69u IPv4 0xc66a91d0 0t0 TCP geonic.net:58336->200.39.223.100:smtp (SYN_SENT)
perl5.8.8 11583 apache 72u IPv4 0xc8286000 0t0 TCP geonic.net:59179->mx.east.cox.net:smtp (ESTABLISHED)
perl5.8.8 11583 apache 490u VREG 0,90 0 24777126 / (/dev/ar0s1a)
netstat приводить нет смысла, там много обращений на 25 порт на разные айпишники.