Strange Domain/Email behaviour.

gson

Active Member
Joined
Feb 28, 2012
Messages
51
Reaction score
0
Hello fellow techies.

So i have been doing a dance with my hosting company for the past month now as i have been dealing with a strange problem with the machines i manage.

About a month ago about 60% of the workstations started receiving send/receive errors in outlook by the bulk, 200+ per cycle.
I brought this up to the hosting company and they recommend we do a site wide password reset of all mail boxes and also a virus/malware scan of all machines. all machines who experienced the send/receive error reported positive for malware,those who didn't have the outlook error where completely uninfected.

fast forward to today, all machines have been scanned and cleared but now iv just received and email from a client who states they received an infected email; phishing attack linked to one of our mailboxes.

can someone tell me what the hell is going on here and where the problem lies,be it with the hosting company or internal?

any response or ideas would be great.

Thanx
 
Hello fellow techies.

So i have been doing a dance with my hosting company for the past month now as i have been dealing with a strange problem with the machines i manage.

About a month ago about 60% of the workstations started receiving send/receive errors in outlook by the bulk, 200+ per cycle.
I brought this up to the hosting company and they recommend we do a site wide password reset of all mail boxes and also a virus/malware scan of all machines. all machines who experienced the send/receive error reported positive for malware,those who didn't have the outlook error where completely uninfected.

fast forward to today, all machines have been scanned and cleared but now iv just received and email from a client who states they received an infected email; phishing attack linked to one of our mailboxes.

can someone tell me what the hell is going on here and where the problem lies,be it with the hosting company or internal?

any response or ideas would be great.

Thanx

It is possible that the hosting providers server had been compromised and mailboxes (including yours) are being used to send spam and phishing emails. Either that, or someone is still gaining access to your mailboxes, through undetected trojan/virus on one of your workstations. (I'm sure there are other possibilities)

Try log into the spam firewall console for the domain and see if you can find the log of any phishing emails sent from that domain. Most hosting providers will have a spam firewall that logs all outbound mails, eg Spam Experts.
 
Top
Sign up to the MyBroadband newsletter
X