>This is a snippet from my log file. This session dropped a virus, f-prot 
>calls it the Lentin.F virus, others seem to call it the yaha virus. I'm 
>trying to track down the machine/person that has been sending us this 
>virus for the last couple of days.
>
>20020624 160346 127.0.0.1       SMTPD (00240266) [213.53.199.208] connect 
>62.100.10.81 port 2982
>20020624 160346 127.0.0.1       SMTPD (00240266) [62.100.10.81] HELO 
>mail.tio.nl
>20020624 160347 127.0.0.1       SMTPD (00240266) [62.100.10.81] MAIL 
>FROM:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
>20020624 160347 127.0.0.1       SMTPD (00240266) [62.100.10.81] RCPT 
>TO:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
>20020624 160358 127.0.0.1       SMTPD (00240266) [62.100.10.81] 
>C:\IMail\spool\D26c3266.SMD 43136

The IP address of the server that sent to E-mail is 62.100.10.81 
(hmm-dca-ap03-d11-081.dial.freesurf.nl).

>What I need to know is wheter the HELO packet here is the name of my mail 
>server, correct, or the name of the server on the other side.

The HELO data is the name of the remote mailserver, according to them.  In 
this case, the Lentin/Yaha virus is the mailserver, and it claims to be 
YOUR mailserver (probably as an attempt to make it harder to identify the 
real sender).  Only the IP address can be trusted (about 99.999% of the time).

>If the latter then (s)he is impersonating our mailserver and I'm starting 
>to doubt whether this is accidental.

It is definitely not accidental.  The virus impersonates your mailserver on 
purpose.  I too was confused the first time I saw one of these, as 
Yaha/Lentin is the first one to do this (some others would use a random 
string instead).

>  The ip number is for a dial-up connection on the freesurf.nl domain, 
> (Name:    hmm-dca-ap03-d11-081.dial.freesurf.nl Address:  62.100.10.81).

That is correct, and the only useful information you have about the source 
of the E-mail, unfortunately.

                                                    -Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to