Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


How to find what IP a user is accessing Exchange from remotly?

Posted on 2014-11-05
Medium Priority
Last Modified: 2015-01-26
I have a user that has left the company, but due to an employee contract he has e-mail access until the end of the year. The problem is that whatever computer he is using is probably infected with some kind of botnet.

Every night his e-mail sends out about 30 e-mails in German with trojan attachments. GFI has blocked all of these e-mails, but since I have no access to the computer he may be using at his new job, I cannot ensure those computers are clean. I need to find out what IP this is coming from. Is there a way to do this? If I find out it is the IP of his new company, I can shut down access until that computer has been cleaned.
Question by:j_crow1
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
LVL 19

Expert Comment

by:Adam Farage
ID: 40424476
You should be able to find the source of the email in the message tracking logs:

Get-TransportServer | Get-MessageTrackingLog -MessageSubject "enter Trojan message subject here" | Select Timestamp, {$_.Recipients}, Sender, SenderIP, ClientHostname | Export-CSV C:\Log.csv

Open in new window

From there make the table in Excel, and then search for the client IP that is not an Exchange server.

Author Comment

ID: 40424523
It is not displaying an IP address, but it does display a client host accurate is this?
LVL 19

Expert Comment

by:Adam Farage
ID: 40424583
The ClientHostname should be accurate, but I am surprised you are not getting a client address. Most likely coming from someones mailbox or an open relay.

Do you see the sender address and can you log into that mailbox?
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why


Author Comment

ID: 40424635
Yes, but those items are not in his sent folder. I do not have an open relay...where else should I check for where this could be coming from?
LVL 19

Accepted Solution

Adam Farage earned 1500 total points
ID: 40424754
Its most likely his mailbox, but using a raw MAPI connection on his machine.

Try disabling MAPI connectivity to the mailbox and see if that works for you (Set-CASMailbox -MapiEnabled:$FALSE)

It will disable his outlook access (along with any other MAPI access) but it should help figure out if it his client machine or not.

Author Comment

ID: 40424870
I will try that tonight and see if those e-mails get sent out.
LVL 19

Expert Comment

by:Adam Farage
ID: 40426302
Any luck?

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
There are times when we need to generate a report on the inbox rules, where users have set up forwarding externally in their mailbox. In this article, I will be sharing a script I wrote to generate the report in CSV format.
how to add IIS SMTP to handle application/Scanner relays into office 365.
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question