Im looking for adivice on the folowing:
I am receiving large ammounts of NDR messages, mainly from .ru sites to our [email protected]
I have run a full AV scan on the PC turned off System restore.
Is this SPAM from ourside out network, or virus activity from within our network?
I have also checked the exchange logs, not going through the exchange server, or through our own relay server (headers and footers)
I have attached the header from the mail below..
I have replaced the domainame with ourdomain
This is an automatically generated Delivery Status Notification
Delivery to the following recipient failed permanently:
[email protected]
----- Original message -----
Received: by 10.142.144.16 with SMTP id r16mr2500993wfd.195.1207581718916;
Mon, 07 Apr 2008 08:21:58 -0700 (PDT)
Return-Path: <[email protected]>
Received: from 121.27.52.50 ([121.27.52.50])
by mx.google.com with ESMTP id 32si15177520wri.0.2008.04.07.08.21.57;
Mon, 07 Apr 2008 08:21:58 -0700 (PDT)
Received-SPF: neutral (google.com: 121.27.52.50 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=121.27.52.50;
Authentication-Results: mx.google.com; spf=neutral (google.com: 121.27.52.50 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Message-ID: <000701c898c3$07db3356$c64fa9ac@nyfvjhxq>
From: "Cartier Replica" <[email protected]>
To: "Replica Watches" <[email protected]>
Subject: Sharp, professional and honest
Date: Mon, 07 Apr 2008 13:34:22 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0004_01C898C3.07D8269B"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
This is a multi-part message in MIME format.
------=_NextPart_000_0004_01C898C3.07D8269B
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
NEW WATCH SHOP!
The time is NOW to get YOUR replica watches that are famous around the =
world.=20
----- Message truncated -----
I am receiving large ammounts of NDR messages, mainly from .ru sites to our [email protected]
I have run a full AV scan on the PC turned off System restore.
Is this SPAM from ourside out network, or virus activity from within our network?
I have also checked the exchange logs, not going through the exchange server, or through our own relay server (headers and footers)
I have attached the header from the mail below..
I have replaced the domainame with ourdomain
This is an automatically generated Delivery Status Notification
Delivery to the following recipient failed permanently:
[email protected]
----- Original message -----
Received: by 10.142.144.16 with SMTP id r16mr2500993wfd.195.1207581718916;
Mon, 07 Apr 2008 08:21:58 -0700 (PDT)
Return-Path: <[email protected]>
Received: from 121.27.52.50 ([121.27.52.50])
by mx.google.com with ESMTP id 32si15177520wri.0.2008.04.07.08.21.57;
Mon, 07 Apr 2008 08:21:58 -0700 (PDT)
Received-SPF: neutral (google.com: 121.27.52.50 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=121.27.52.50;
Authentication-Results: mx.google.com; spf=neutral (google.com: 121.27.52.50 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Message-ID: <000701c898c3$07db3356$c64fa9ac@nyfvjhxq>
From: "Cartier Replica" <[email protected]>
To: "Replica Watches" <[email protected]>
Subject: Sharp, professional and honest
Date: Mon, 07 Apr 2008 13:34:22 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0004_01C898C3.07D8269B"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
This is a multi-part message in MIME format.
------=_NextPart_000_0004_01C898C3.07D8269B
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
NEW WATCH SHOP!
The time is NOW to get YOUR replica watches that are famous around the =
world.=20
----- Message truncated -----