Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

SPAM how to determine the originator? Exchange 2003

Posted on 2010-09-10
13
Medium Priority
?
919 Views
Last Modified: 2012-05-10
I have two users who have been recieving messages like these for the last couple of days.  I don't think that they are coming from my server.  How do I determine where they are originating from?  


Your message did not reach some or all of the intended recipients.
      Subject:  smiling to you, dear
      Sent:     9/10/2010 7:33 AM
The following recipient(s) could not be reached:
      dta77@hotmail.com on 9/10/2010 7:33 AM
            There was a SMTP communication problem with the recipient's email server.  Please contact your system administrator.
            <SNT0-MC3-F30.Snt0.hotmail.com #5.5.0 smtp;550 Requested action not taken: mailbox unavailable (1044235902:3448:-2147467259)>
0
Comment
Question by:bmsjeff
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 3
  • +1
13 Comments
 
LVL 32

Assisted Solution

by:endital1097
endital1097 earned 664 total points
ID: 33646283
right click on the message and select message options
review the header to determine the origin
the first entry at the top should be your server receiving it and as you go down the last will be the source
0
 
LVL 57

Expert Comment

by:giltjr
ID: 33646346
This assumes that somebody has not forged any of the SMTP header information.
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33646372
this is for the hops, not the from
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 28

Expert Comment

by:sunnyc7
ID: 33646533
view > options > header info.
Copy paste the entire contents into notepad

check the message-id: field
Message-ID: <76131413fe3ae29312fea96dd9fbf5@tifa-5fa7cbaf0b>

If its a exchange server - the part after the @ sign is the mailbox servername.
If its java etc - it is probably scripted through some Java/PHP mailer

now look for this field
Received: from TIFA-5FA7CBAF0B.Local (tifadc05@112.105.178.186 with login)
        by smtp109.mail.tp2.yahoo.com with SMTP; 03 Sep 2010 22:32:18 -0700 PDT

--
what I do is
a) Find the originating server - TIFA in this case.
b) Search for TIFA in the header field.
The IP address next to that = source of spam

--
But these things can be spoofed too.
0
 
LVL 57

Expert Comment

by:giltjr
ID: 33646706
I can insert fake from's to make it look like my SMTP server was the middle of the stream instead of the originator of the stream.
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33646714
True @ giltjr
0
 
LVL 14

Author Comment

by:bmsjeff
ID: 33648020
Here is the header.
 
spam.txt
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33648064
Message-ID: <LbIUndNXh0000e41f@SNT0-MC3-F14.Snt0.hotmail.com>
spam
0
 
LVL 32

Expert Comment

by:endital1097
ID: 33648076
most likely someone using hotmail for their relay
0
 
LVL 57

Accepted Solution

by:
giltjr earned 668 total points
ID: 33648109
If  you beleive everything the 1st entry point is:

Received: from FILESERVER (LRouen-152-83-1-113.w80-13.abo.wanadoo.fr [80.13.64.113])
            by mwinf2721.orange.fr (SMTP Server) with SMTP id B2D3E1C00042;
            Fri, 10 Sep 2010 11:00:34 +0200 (CEST)

Which means a computer with the IP address of 80.13.64.113 sent them e-mail thru the smtp server mwinf2721.orange.fr

Now are these the header from the e-mail telling you it was rejected?  Or are these the headers from the rejected e-mail?
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33648111
all of these headers can be spoofed.

They even have a x- header with spam assassin signature as clean.

------------------
Microsoft Mail Internet Headers Version 2.0

Received: from mail.spamserver.net ([x.x.x.x]) by exchange.myserver.com with Microsoft SMTPSVC(6.0.3790.4675);

Resent-To: info@exchange.myserver.com
Resent-From: info@myserver.com
Resent-Message-Id: <B0534444566@mail.spamserver.net>
Resent-Date: Fri, 10 Sep 2010 05:05:57 -0400

X-Modus-Audit: FALSE;0;0;0

Received: from mailin-1.spamserver.net (unverified [x.x.x.x]) by mail.spamserver.net (Vircom SMTPRS 5.0.916.0)
with ESMTP id <B0534444564@mail.spamserver.net> for <info@myserver.com>;

X-Modus-BlackList: x.x.x.x=OK;=OK
X-Modus-Trusted: x.x.x.x=NO
X-Modus-Audit: FALSE;0;0;0
Received: from snt0-omc4-s43.snt0.hotmail.com (snt0-omc4-s43.snt0.hotmail.com [65.54.51.94])
            by mailin-1.spamserver.net (Postfix) with ESMTP id 4E1EAC30356
            for <info@myserver.com>; Fri, 10 Sep 2010 05:00:36 -0400 (EDT)
Received: from SNT0-MC3-F14.Snt0.hotmail.com ([65.55.90.199]) by snt0-omc4-s43.snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
             Fri, 10 Sep 2010 02:00:36 -0700
Message-ID: <LbIUndNXh0000e41f@SNT0-MC3-F14.Snt0.hotmail.com>
Subject: Delivery Status Notification (Failure)

X-MailScanner: Found to be clean
X-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, score=0,
            required 7, autolearn=disabled, RCVD_IN_DNSWL_NONE -0.00)

Received: from smtp27.orange.fr ([80.12.242.96]) by SNT0-MC3-F14.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
             Fri, 10 Sep 2010 02:00:36 -0700
Received: from me-wanadoo.net (localhost [127.0.0.1])
            by mwinf2721.orange.fr (SMTP Server) with ESMTP id 22C8F1C00042;
            Fri, 10 Sep 2010 11:00:35 +0200 (CEST)
Received: from me-wanadoo.net (localhost [127.0.0.1])
            by mwinf2721.orange.fr (SMTP Server) with ESMTP id 14E071C00280;
            Fri, 10 Sep 2010 11:00:35 +0200 (CEST)
Received: from FILESERVER (LRouen-152-83-1-113.w80-13.abo.wanadoo.fr [80.13.64.113])
            by mwinf2721.orange.fr (SMTP Server) with SMTP id B2D3E1C00042;
            Fri, 10 Sep 2010 11:00:34 +0200 (CEST)
0
 
LVL 28

Assisted Solution

by:sunnyc7
sunnyc7 earned 668 total points
ID: 33648124
To answer your question

This is the source and then it got routed through others (Received From fields)

--------
Received: from FILESERVER (LRouen-152-83-1-113.w80-13.abo.wanadoo.fr [80.13.64.113])
            by mwinf2721.orange.fr (SMTP Server) with SMTP id B2D3E1C00042;
---------
Can you download a trial of VamSoft ORF
www.vamsoft.com/orfee_features.asp

It provides a before/after scenario and out of the box functionality for backscatter and other spam attacks.
0
 
LVL 14

Author Comment

by:bmsjeff
ID: 33648133
This is the header from the e-mail telling you it was rejected.

I have not record of sending the email.
0

Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question