Ok, so my parent companies IT director came to me today and stated that he received a call from our ISP today stating that they are noticing quite an out flux of "spam" messages coming off of my network. They told him the external IP address, as well as the port (25) and stated that it seemed to them that we have a Spam Bot that has setup its own SMTP server on our network. Well I have been enlisted to help him out, however I haven't had this problem before and I am not quite sure how to track it down. As we speak they are seeing degradation of the performance of the network from our companies that VPN into the network. Can anyone point me in the right direction as to how to locate this "Bot".
I have sent out instructions to all 162 users on how to install and run Spybot, however I cannot be sure that they have done this. Is there a way to "sniff" it out from my desktop? I would use Snort, or Etherpeek or the like if someone could throw me a little guidance on how to use these.
Please any suggestions, or help would be greatly appreciated.
Start Free Trial