Spam relay on my site?

Discussion in 'Site & Server Administration' started by NewComputer, Apr 17, 2006.

  1. #1
    I have been receiving an incredible amount of undeliverable emails from emails that I have not sent. Whomever is doing this is using different characters before the @ sign and then my websites url.

    What's the deal?

    Here is the message source:

    From - Sun Apr 16 08:52:10 2006
    X-Account-Key: account2
    X-UIDL: 5a487b4f14f4726525619c381e1e0d13
    X-Mozilla-Status: 0201
    X-Mozilla-Status2: 10000000
    Return-path: <>
    Envelope-to:
    Delivery-date: Sun, 16 Apr 2006 09:29:26 -0400
    Received: from [139.121.17.172] (helo=cpmx2.mail.saic.com)
    by photonix.site5.com with esmtp (Exim 4.52)
    id 1FV7Jd-0000ld-KX
    for ; Sun, 16 Apr 2006 09:29:26 -0400
    Received: by cpmx2.mail.saic.com; Sun, 16 Apr 2006 06:29:16 -0700
    Message-Id: <iss.833a14ab.45b7.444246ac.251c1.6@cpmx2.mail.saic.com>
    Date: Sun, 16 Apr 2006 06:29:16 -0700
    From:
    To:
    Subject: Undeliverable mail
    MIME-Version: 1.0
    Content-Type: multipart/report; report-type=delivery-status;
    boundary="=_mh.ndn.45b7.444246ac_="
    X-Antivirus-Scanner: This message has been scanned by ClamAV.

    --=_mh.ndn.45b7.444246ac_=
    Content-Type: text/plain; charset=us-ascii

    Your message was not delivered to the following recipients:

    : No such host

    --=_mh.ndn.45b7.444246ac_=
    Content-Type: message/delivery-status
    Content-Transfer-Encoding: 7bit

    Reporting-MTA: dns;cpmx2.mail.saic.com

    Original-Recipient: rfc822;a30808@actd.saic.com
    Final-Recipient: rfc822;a30808@actd.saic.com
    Action: failed
    Status: 5.1.2

    --=_mh.ndn.45b7.444246ac_=
    Content-Type: message/rfc822

    Return-Path: <lqtq@newcomputer.ca>
    Received: from 0599-its-ieg02.mail.saic.com ([139.121.18.36] [139.121.18.36]) by cpmx2.mail.saic.com for ; Sun, 16 Apr 2006 06:29:03 -0700
    Received: from mx2.west.saic.com ([139.121.18.36])
    by 0599-its-ieg02.mail.saic.com (SMSSMTP 4.0.5.66) with SMTP id M2006041606335806860
    for <a30808@actd.saic.com>; Sun, 16 Apr 2006 06:33:58 -0700
    Received: from 183-203-187-203.static.iqara.net ([203.187.203.183] [203.187.203.183]) by mx2.west.saic.com for ; Sun, 16 Apr 2006 06:28:58 -0700
    Received: (qmail 20521 invoked from network); Sun, 16 Apr 2006 18:58:50 +0530
    Received: from unknown (HELO rk.xbd) (203.187.48.223)
    by 183-203-187-203.static.iqara.net with SMTP; Sun, 16 Apr 2006 18:58:50 +0530
    Message-Id: <000901c66159$b2bea552$df30bbcb@rk.xbd>
    From: "Adam Harrington" <lqtq@newcomputer.ca>
    To: "Ike Beck" <a30808@actd.saic.com>
    Subject: spare part decry
    Date: Sun, 16 Apr 2006 18:56:38 +0530
    MIME-Version: 1.0
    Content-Type: multipart/related;
    type="multipart/alternative";
    boundary="----=_NextPart_000_0005_01C66187.CC76E12A"
    X-Priority: 3
    X-MSMail-Priority: Normal
    X-Mailer: Microsoft Outlook Express 6.00.2900.2180
    X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
    Sender:

    This is a multi-part message in MIME format.

    ------=_NextPart_000_0005_01C66187.CC76E12A
    Content-Type: multipart/alternative;
    boundary="----=_NextPart_001_0006_01C66187.CC76E134"


    ------=_NextPart_001_0006_01C66187.CC76E134
    Content-Type: text/plain;
    charset="windows-1252"
    Content-Transfer-Encoding: quoted-printable

    beige of jet black the face-saving. to abacus this Wall Street seniority =
    a better quintet

    mutton holocaust tabby of body odor leave. in bow tie, Highness a =
    toothache hanker nighttime this self-indulgence. complimentary revolt,
    helplessly, a in wares, with tarry counterbalance as bedroom prolong =
    measure, signatory it east of on momentous smuggle as loan shark
    spontaneously, that raindrop snooze a the
    apt ancestor, quotation however an jelly of
    subdued, but bargain tonsil Asian aptitude bond
    lucky of an winding gazette. glider
    cold cuts couple Tuesday, a and Pole of rink was north the to =
    commonwealth as Maori patter
    shrewd adornment granted heartbroken, asthmatic, cougar fascinating, =
    manuscript accused the toucan locksmith god-awful hint bath inflated
    ------=_NextPart_001_0006_01C66187.CC76E134
    Content-Type: text/html;
    charset="windows-1252"
    Content-Transfer-Encoding: quoted-printable

    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
    <HTML><HEAD>
    <META http-equiv=3DContent-Type content=3D"text/html; =
    charset=3Dwindows-1252">
    <META content=3D"MSHTML 6.00.2900.2180" name=3DGENERATOR>
    <STYLE></STYLE>
    </HEAD>
    <BODY bgColor=3D#ffffff>

    <DIV><FONT face=3DArial size=3D2>beige of jet black the face-saving. to =
    abacus=20
    this Wall Street seniority a better quintet </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2><IMG alt=3D"" hspace=3D0=20
    src=3D"cid:000401c66159$b2bea520$df30bbcb@rk.xbd" align=3Dbaseline=20
    border=3D0></FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>mutton holocaust tabby of body odor =
    leave. in=20
    bow tie, Highness a toothache hanker nighttime this self-indulgence.=20
    complimentary revolt, </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>helplessly, a in wares, with tarry=20
    counterbalance as bedroom prolong measure, signatory it east of on =
    momentous=20
    smuggle as loan shark </FONT></DIV>

    <DIV><FONT face=3DArial size=3D2>spontaneously, that raindrop snooze a =
    the=20
    </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>apt ancestor, quotation however an =
    jelly of=20
    </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>subdued, but bargain tonsil Asian =
    aptitude=20
    bond </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>lucky of an winding gazette. glider=20
    </FONT></DIV>
    <DIV><FONT face=3DArial size=3D2>cold cuts couple Tuesday, a and Pole of =
    rink=20
    was north the to commonwealth as Maori patter </FONT></DIV>

    <DIV><FONT face=3DArial size=3D2>shrewd adornment granted =
    heartbroken,=20
    asthmatic, cougar fascinating, manuscript accused the toucan =
    locksmith=20
    god-awful hint bath inflated </FONT></DIV></BODY></HTML>

    ------=_NextPart_001_0006_01C66187.CC76E134--

    ------=_NextPart_000_0005_01C66187.CC76E12A
    Content-Type: image/gif;
    name="jibe.gif"
    Content-Transfer-Encoding: base64
    Content-ID: <000401c66159$b2bea520$df30bbcb@rk.xbd>

    R0lGODdhkAEOBKUAAOTh6a6rngIEAtLG2jo9IRsDGoySfmlycFlbUpKboVJYQC8XH4tudQ0GBr+w
    tZs/QT6WPPv4py4OD+JWL1ODIVlEn1wcQHNnjZbf5Kt7JOy5uim0s9HiweDFFw8ZmzFy39DP/BFC
    YwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACwAAAAAkAEOBAAG/kCAcEgsGo/IpHLJ
    bDqf0OYnSq1ar9isdsvter/gsHhMLpvP6LR6zW673/C4fE6v2+/4vH7P7/v/gIGCg4SFhoeIiYqL
    jI2Oj5CRkpOUlZaXmJmam5ydnp+goaKjpKWmp6ipqqusra6vsLGys7S1tre4ubq7vL2+v8DBwsPE
    xcbHyMleAQJNzE8DzVbPytWH1EvYZdrWgxXJ3AADBAUCBQYAzAcFBQhC50ICB+8JzcwI8gP47UrP
    6uzoxO2b163gnHAECK5LJ8DduHkH3DEjkK6AP3lCCDhMmOQixAIZHcIzSNJNuAFCBhywJwAlAAMg
    A4CMOBPBRZTRXMrsyFLI/rOcKV2WHJomHMwCGnv6lFZgnMwABAJcTCmgqlWeDJeKk0a0qxpu0QJo
    ZeYSphAEC9H2pAY0JVZqP1v6DOi1bhiyA/LmFSB2HEuRBGFSNNAwKzaNZykimZoVAOIBI+1K7sLM
    auF1AqLy/VeAYLx50dAxFliVgEsCXMdKYztwsmtG4V7LvnSA7uzbuHPr3s27t+9bUMt1npYa6xFu
    lUuf9oxaJ1/LmYX+7iog4MMqsY1kR871gGIDigFkDuhdG4Lw04eGNoLA3Tup8gCug8fZPenhcYtw
    H8J2dUL3CWmTXXrdrJTZAc75FBNGK33E0EYEPRZgcfwVh81C7wGAVjTx/sA3hD7oEVjSAAYgUE5A
    Fmk4D1mN3SSEWW3BtJ2F0HmGFgApWrRTcuYgIJ2IBeVFhIlCRIQjSnCtplRWHC41o35c6eMeeJCd
    dYCRcEUGpEFmVUjVTi0qyVBZIMVoEYVaESGgNNEYmQ4BBIjGFWFibUlSZzgh9s5wYaoGWEjiTLhY
    S3oNgM044ZFDFztIpnaenSTpI5xnAKyUYJ+ceaaPOSs202SFltlkWTtCWToEnGlSRSmkXYHH6qt0
    jGMbrLSucU+tuOaqKy2Ezbrrr15gRs6PwBLIY3RFfGpFWM3omWyUloVYbF3mSasFs+IQK9Oc1k5r
    15oPCqAAm63d556y/p+h+dI53dnnrWuHPqpOY4/BI+GqapYTpxGNnkoOP+9KxiOpYzIpV7ZtgTno
    Ovg2pmKg7gZMVGxJbvUsdP000yWUx6krcUEUi5mwAW2JgwRko6nZnU4gVTLFx3+EnGa96Oj5KBKd
    teSsykPwcx3ME6NZ8X0EbYosuhVVdW5qh6LGJ9DFDgj11FRXbfXVWGet9dbEEMs1GcdiRIXUXATH
    qRlIP2H209qpy2Ha2EFnWhVIk52e3c543EV1KXG0B9+BNuwwx8s42m3ctYbDmQHzyTmfe6yd3V7P
    fe1j36YAE7Eev63dk4/lH4LOUOOGxTcS5is96yvRpWtlVeT4mU6e/r4/gus5gq3d2CHsqZu7FD6C
    z6Y4gwwuSNF11NybJaA/32uEgQkJRfO8jkHIPEfzLuRRpS1PDhmF0CN4KoSMTZU8+cVvhdLkPKck
    r9jKt2zW+eKUc32nwd8WNnz9lk6mwf9L0Y0SVqaDKUxzJTqR+oLCIgIusCKYUkpcyoImEpmIb2Yq
    31o8dTAZiSwfHbMKwRrYQZAIsFMPJMwDd3Qw3wwvTaOZyqeeYaSmbAVj0cCY5qRDJHT1B4fQkeAG
    tTLD4ghpCD3kCjM02LoiDg0q5piVzCymlYgAJT9EDOLgevPCCP5vgi8qIJhKhpMW/mhjAJxLf4RS
    RjZGsE8JKw4a/sG4Liyaj4NkqpihitQyL7WNKv+DjKvSSEiT4e01XazYrZAnDefh6Gk2U0wkjYAn
    iDHvHIdxz80mqUghnmUjFKrkOACEvq2IBR8Wo99D9MiXdRHulY5UVJq8hxpAaYgih4RXEA/wRJbM
    hyC8G4Kp3KccYiIrWRd8GuocZrS5kQZZneyTuSgkqbMRM3ZF4hRTBFCPa6KwMcKqkx9fucwXKZEr
    AyFXMXO5JXa+6HCGEOcBv5YJd8rqERgZJT05wc5bPWJbmdunQAdK0IIa9KCi6BVCgSUsGyrDa9M5
    ljP3UM1KZgRwpmyWJmn3PI6qrI/v4GAT9caTaEG0dVkI20n//gi3IlxwouU6izVvWBooQWcvKSVp
    JKrFB8iIT1JlfNZPUHIlgYRoHeuLGDNStBSmLQlxwnToH93ZsSukDAlFBVFi6heQRwnyncb5AlUV
    AS7fPaxDZl2cNDFnH2ERy2/jE09ViiAPR40zQ4Nin4ZQecfGLFOt7UPiuTqnlHEIR07Ac+srNUdY
    4HnpKoodkh9b+
     
    NewComputer, Apr 17, 2006 IP
  2. clancey

    clancey Peon

    Messages:
    1,099
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Welcome to the new world of spam!
    Win thousands of annoying offers!
    Win thousands of bounced emails from people pretending to be you!

    What is happening is that they are using your domain for the sender portion of the email header. They are combining some name with some other information to generate an email address from a real domain, but not from a real sender.

    I did a whois and your domain appears to be situated on a network with the IP address range between 209.59.128.0 and 209.59.191.255

    It appears the sender of the above email messages are located at the IP address: 203.187.48.223

    That may not be the actual IP address of the real villain. They could be using a trojaned computer to send the message.

    There is nothing you can do about this.

    You need to be very careful about these messages. Sometimes the bounced email will contain a live viral attachment as part of a zipped or other attachment to the email message. Do not open those. That is one way viral spammers spread them -- taking advantage of the fact some email servers bounce entire messages when a sender is not found or if the attachment is found to be potentially viral in nature.
     
    clancey, Apr 17, 2006 IP