2

I have noticed huge amounts of email going to random .com.tw domains. My Exchange event log its erroring with them every few seconds. I am wondering is it possible to see which computer this is coming from maybe its a virus? Has anyone had similar experience with this? Im running Small Bussiness Server 2003.

Thanks,

Grishanko
  • 410
  • 5
  • 14

4 Answers4

4

Are you running an Open Relay? If not then I believe you do have a virus. It's time to find the culprit, do that fast otherwise you'll get your domain blacklisted. Something like this happened to me a long time ago and it was I was running an open relay.

Run this site to see if you're running an Open Relay: http://www.checkor.com/

Check this thread for more info on the sending spam: Recommendations for handling Directory Harvesting spam on Exchange 2003

Hondalex
  • 693
  • 4
  • 8
  • +1 for doing this fast, in fact, you might want to shutdown your email server. Other email servers will probably just add the emails to a queue to try to resend later so you won't loose incoming mail probably. Better down for a while than blacklisted!! – Kyle Brandt Aug 03 '09 at 17:08
  • Clarifying what Kyle said: Other email servers *will* just add the emails to a queue to try to resend later, so you won't loose incoming mail. – Carl C Aug 03 '09 at 18:20
  • The server did have an open relay, one of the other admins accidentaly opened it up when trying to resolve a different issue. we got that taken care of and we did indeed get blacklisted by Barracuda, we requested remove from the list. They were great at getting that taken care of. – Grishanko Aug 08 '09 at 15:04
  • Glad to hear that you got it resolved and that Barracuda removed you without any issue. – Hondalex Aug 10 '09 at 13:32
2

You should be able to turn up the SMTP logging using the Exchange console. It is on the Diagnostics tab, SMTP transport. Then you will have a log written to your Logs folder under your Windows directory for the SMTP service which should capture the SMTP conversation between the client and your exchange server leading you to the offending machine.

Kevin Kuphal
  • 9,064
  • 1
  • 34
  • 41
1

It is possible that this traffic is back-scatter. If incoming email is being addressed to "aabbccddeeeff@[yourdomain]", you'll get outbound mail destined to the listed MAIL FROM: address, as a delivery-status-notice gets sent informing them that no such user exists on your system. This is a form of directory-harvest attack that relies on an actual receiving mailbox to determine which addresses did NOT result in a DSN being sent and are therefore valid email addresses.

sysadmin1138
  • 131,083
  • 18
  • 173
  • 296
0

Are you running any type of AV on your mail server? What are some of the errors you are seeing, can you post a screenshot of them?

DanBig
  • 11,393
  • 1
  • 28
  • 53