I would like to know how to identify the script a spammer is using to send out SMTP HELO requests as keqakku.com via Port 25.
I have already used several scanners like chkrootkit & rkhunter wiht no success. Inspecting the sys.log and ufw.log files wasn't successful as they don't log my own SMTP HELO request neither, just mail delivery.
By the way, my own valid SMTP HELO requests as my actual domain don't let my IP getting blacklisted.