goodgirl
Verified User
I have a server that we have found phishing emails are going through. I did add a limit on outgoing email to help find which user account the emails were going through.
I have found this part out. I know it isn't the user but I'm not sure what to look for to find how they are sending them.
I did: locate formmail.pl and found nothing.
Here is the header:
-----------------------------------------
> > Return-Path: <[email protected]>
> > Delivered-To: [email protected]
> > Received: (qmail 19009 invoked from network); 3 Jan 2006 12:44:40 -0000
> > Received: from xuxa.iecc.com (208.31.42.42)
> > by mail.iecc.com with SMTP; 3 Jan 2006 12:44:40 -0000
> > Received: (qmail 11448 invoked from network); 3 Jan 2006 12:44:40 -0000
> > Received: from rdns-225-226.securedprivatenetwork.net (HELO
>server.dedicatedroute.com) (216.144.225.226)
> > by smtp.abuse.net with SMTP; 3 Jan 2006 12:44:39 -0000
> > Received: from [62.139.80.98] (helo=d-1ca4bacff9d64)
> > by server.dedicatedroute.com with esmtpa (Exim 4.50)
> > id 1Eu76J-0005PP-85; Wed, 04 Jan 2006 03:46:43 -0800
> > From: "Bank of America" <[email protected]>
> > Subject: Online Banking Alert (update your information)
> > To: [email protected]
> > Content-Type: text/html;iso-8859-1
> > Reply-To: [email protected]
> > Date: Tue, 3 Jan 2006 02:44:26 +0200
> > X-Priority: 3
> > X-Library: Indy 8.0.25
> > X-DCC-IECC-Metrics: tom.iecc.com 1107; Body=1 Fuz1=1 Fuz2=1
I will post part of the mainlog for exim in a few mins.
I have found this part out. I know it isn't the user but I'm not sure what to look for to find how they are sending them.
I did: locate formmail.pl and found nothing.
Here is the header:
-----------------------------------------
> > Return-Path: <[email protected]>
> > Delivered-To: [email protected]
> > Received: (qmail 19009 invoked from network); 3 Jan 2006 12:44:40 -0000
> > Received: from xuxa.iecc.com (208.31.42.42)
> > by mail.iecc.com with SMTP; 3 Jan 2006 12:44:40 -0000
> > Received: (qmail 11448 invoked from network); 3 Jan 2006 12:44:40 -0000
> > Received: from rdns-225-226.securedprivatenetwork.net (HELO
>server.dedicatedroute.com) (216.144.225.226)
> > by smtp.abuse.net with SMTP; 3 Jan 2006 12:44:39 -0000
> > Received: from [62.139.80.98] (helo=d-1ca4bacff9d64)
> > by server.dedicatedroute.com with esmtpa (Exim 4.50)
> > id 1Eu76J-0005PP-85; Wed, 04 Jan 2006 03:46:43 -0800
> > From: "Bank of America" <[email protected]>
> > Subject: Online Banking Alert (update your information)
> > To: [email protected]
> > Content-Type: text/html;iso-8859-1
> > Reply-To: [email protected]
> > Date: Tue, 3 Jan 2006 02:44:26 +0200
> > X-Priority: 3
> > X-Library: Indy 8.0.25
> > X-DCC-IECC-Metrics: tom.iecc.com 1107; Body=1 Fuz1=1 Fuz2=1
I will post part of the mainlog for exim in a few mins.