Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Exchange Mailserver Spam

Posted on 2010-09-15
6
Medium Priority
?
630 Views
Last Modified: 2012-06-27
I need assistance in analyzing an email header. Someone seems to be passing Spam through a customers Exchange server, but can't see how.

Header information below. The IP address of: 70.89.4.109 is the  Exchange Mailserver. The IP of the intruder appears to be: 64.186.141.117

Return-Path: bristollotto03redacted@yahoo.co.jp
Received: from imta19.westchester.pa.mail.comcast.net (LHLO
imta19.westchester.pa.mail.comcast.net) (76.96.62.15) by
sz0165.ev.mail.comcast.net with LMTP; Tue, 14 Sep 2010 12:12:39 +0000 (UTC)
Received: from mailserver2.Inst-Child-Lit.Com ([70.89.4.109])
by imta19.westchester.pa.mail.comcast.net with comcast
id 6cCe1f0202M7bz20KcCefL; Tue, 14 Sep 2010 12:12:40 +0000
X-CAA-SPAM: N00001
X-Authority-Analysis: v=1.1 cv=xQtC0Syy8SjLhPQcxulnFUoy7eUGsAEUo+3gGakOX9w=
c=1 sm=1 p=G0y4NAOPbeQA:10 p=H7zlAlwjME0A:10 p=FlyXWrF0noTvJhcw3_cA:9
a=Dyoqhi_TatcA:10 a=8EU9Q7FnrCoA:10 a=Cfj4BQAnxiAA:10
a=4UKdybQ46eJVya8Ku_wA:7 a=l9BT-LX5JHtfJXMJ0NHU38ZYah4A:4 a=Ft8UYL4EG9YA:10
a=heEvz1zlalEA:10 a=XjuyCbnmBgpgFB-i:21 a=jTmyPk-QPQLX5MgK:21
a=L5inqJBnP8MMvF9QzrwThA==:117
Received: from User ([64.186.141.117]) by mailserver2.Inst-Child-Lit.Com with Microsoft SMTPSVC(6.0.3790.4675);
Mon, 13 Sep 2010 18:42:03 -0400
Reply-To: <bristolsweepstakesredacted@yahoo.co.jp>
From: "BRISTOL LOTTERY"<bristollotto03redacted@yahoo.co.jp>
Subject: AWARD NOTIFICATION.
0
Comment
Question by:frankv_43
6 Comments
 
LVL 8

Expert Comment

by:Mkris9
ID: 33683070
have you checked your sever for relay settings ? may be its an open relay ?
0
 

Author Comment

by:frankv_43
ID: 33683151
Yes, the Exchange box has been checked and is NOT open relay.  
0
 
LVL 8

Expert Comment

by:rr1968
ID: 33683454
64.186.141.117 resolves to farm1.myforexvps.com
Also this server is not open relay or at least port 25 is blocked on their side.
Why can't you add this ip in your block list?

0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 

Accepted Solution

by:
frankv_43 earned 0 total points
ID: 33683563
We did all the obvious stuff, including blocking 64.186.141.117.

Thanks
0
 
LVL 2

Expert Comment

by:joe_h
ID: 33683686
It would really help to see the corresponding log entries from the affected Exchange server. It seems to me that the Exchange box actually is misconfigured as an open relay.
0
 
LVL 6

Expert Comment

by:collins23
ID: 33684069
where is the email destined ?
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you an Exchange administrator employed with an organization? And, have you encountered a corrupt Exchange database due to which you are not able to open its EDB file. This article will explain all the steps to repair corrupt Exchange database.
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question