Hi,
 
This is a snippet from my log file. This session dropped a virus, f-prot calls it the Lentin.F virus, others seem to call it the yaha virus. I'm trying to track down the machine/person that has been sending us this virus for the last couple of days.
 
What I need to know is wheter the HELO packet here is the name of my mail server, correct, or the name of the server on the other side. If the latter then (s)he is impersonating our mailserver and I'm starting to doubt whether this is accidental. The ip number is for a dial-up connection on the freesurf.nl domain, (Name:    hmm-dca-ap03-d11-081.dial.freesurf.nl Address:  62.100.10.81).
 
20020624 160346 127.0.0.1       SMTPD (00240266) [213.53.199.208] connect 62.100.10.81 port 2982
20020624 160346 127.0.0.1       SMTPD (00240266) [62.100.10.81] HELO mail.tio.nl
20020624 160347 127.0.0.1       SMTPD (00240266) [62.100.10.81] MAIL FROM:<[EMAIL PROTECTED]>
20020624 160347 127.0.0.1       SMTPD (00240266) [62.100.10.81] RCPT TO:<[EMAIL PROTECTED]>
20020624 160358 127.0.0.1       SMTPD (00240266) [62.100.10.81] C:\IMail\spool\D26c3266.SMD 43136   
 

Groetjes,
 
Bonno Bloksma

Reply via email to