cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1284
Views
0
Helpful
2
Replies

passed spam emails c100

we have a trouble with Schenker.bg.The applience was passed some spam emails.This is the log from ironport of one of the passed messages:


Thu Jan 31 11:38:23 2008 Info: Start MID 682107 ICID 907643
Thu Jan 31 11:38:23 2008 Info: MID 682107 ICID 907643 From: <chang>
Thu Jan 31 11:38:23 2008 Info: MID 682107 ICID 907643 RID 0 To: <marian>
Thu Jan 31 11:38:23 2008 Info: MID 682107 Message-ID '<000901c863ec>'
Thu Jan 31 11:38:23 2008 Info: MID 682107 Subject 'Exquisite Replica'
Thu Jan 31 11:38:23 2008 Info: MID 682107 ready 2975 bytes from <chang>
Thu Jan 31 11:38:23 2008 Info: MID 682107 matched all recipients for per-recipient policy DEFAULT in the inbound table
Thu Jan 31 11:38:23 2008 Info: ICID 907643 close
Thu Jan 31 11:38:23 2008 Info: MID 682107 antivirus negative
Thu Jan 31 11:38:23 2008 Info: MID 682107 queued for delivery
Thu Jan 31 11:38:23 2008 Info: New SMTP DCID 180471 interface 10.207.40.60 address 10.207.40.16 port 25
Thu Jan 31 11:38:23 2008 Info: Delivery start DCID 180471 MID 682107 to RID [0]
Thu Jan 31 11:38:23 2008 Info: Message done DCID 180471 MID 682107 to RID [0]
Thu Jan 31 11:38:23 2008 Info: MID 682107 RID [0] Response '2.6.0 <000901c863ec> Queued mail for delivery'
Thu Jan 31 11:38:23 2008 Info: Message finished MID 682107 done
Thu Jan 31 11:38:23 2008 Info: Connection Error: DCID: 180460 IP: 169.232.46.249 port: 25 details: timeout interface: 10.207.40.60 reason: connection timed out
Thu Jan 31 11:38:28 2008 Info: DCID 180471 close

and this is from the messages header :

Microsoft Mail Internet Headers Version 2.0
Received: from ironport.schenker.bg ([10.207.40.60]) by mx.schenker.bg with Microsoft SMTPSVC(6.0.3790.3959);
Thu, 31 Jan 2008 11:39:31 +0200
Received: from vmail-1.orbitel.bg ([195.24.32.29])
by ironport.schenker.bg with ESMTP; 31 Jan 2008 11:38:23 +0200
X-IronPort-AV: i="4.25,284,1199656800";
d="scan'208,217"; a="682107:sNHT45831490"
Received: from localhost (mailprotection [10.0.0.2])
by vmail-1.orbitel.bg (Postfix) with ESMTP id E3F5610583C
for <marian>; Thu, 31 Jan 2008 11:38:12
+0200 (EET)
X-Virus-Scanned: by amavisd-new at orbitel.bg
Received: from vmail-1.orbitel.bg ([10.0.0.1])
by localhost (sof-rv1.orbitel.bg [10.0.0.2]) (amavisd-new, port
10024)
with ESMTP id f2kzdprYfFO7 for <marian>;
Thu, 31 Jan 2008 11:38:11 +0200 (EET)
X-Greylist: Passed host: 87.205.174.19
Received: from 87-205-174-19.adsl.inetia.pl (87-205-174-19.adsl.inetia.pl [87.205.174.19])
by vmail-1.orbitel.bg (Postfix) with ESMTP id BB4F510583D
for <marian>; Thu, 31 Jan 2008 11:38:10
+0200 (EET)
Message-ID: <000901c863ec>
From: "Replica Watches" <chang>
To: "Exquisitor" <marian>
Subject: Exquisite Replica
Date: Thu, 31 Jan 2008 07:50:46 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01C863EC.0673986C"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
Return-Path: chang@electronic-atlas.com
X-OriginalArrivalTime: 31 Jan 2008 09:39:31.0468 (UTC) FILETIME=[2E4434C0:01C863ED]

2 Replies 2

Hello,

From the paste, it seems Antispam is not running on the policy that this email came in on.

Thu Jan 31 11:38:23 2008 Info: ICID 907643 close
Thu Jan 31 11:38:23 2008 Info: MID 682107 antivirus negative
Thu Jan 31 11:38:23 2008 Info: MID 682107 queued for delivery

If you grep for the ICID 907643, you should see which SenderGroup (SG) this connection came on. In the HAT you'll be able to change this group so it has anti-spam scanning on. Chances are it's coming from an IP that is whitelisted (either directly, or via SBRS).

steven_geerts
Level 1
Level 1

totally off-topic, but important to mention (I think):
it's not wise to anounce the security product you use by naming your host to it's vendor.

I saw in your header that you named your Ironport "ironport.schenker.bg" This way every hacker or spammer can see you are using Ironport and create a customised attack that might uitilise "known" Ironport bugs.

I agree, there are not many known bugs... but anyhow.....

Steven

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: