Help me get rid of spammer sending from my hmail server!
Posted: 2007-07-10 21:23
First, info about my system: Windows Server 2003, hMail v4.4, ASSP 1.3.1 (spam protection)
I'm hoping someone here has some advice! I have a spammer somehow using my hmail server to send spam to external email addresses (the messages are sent from external email addresses to external email addresses--they never involve local mail addresses at all). The spam messages get queued up under Undelivered Messages long enough for me to see the source mail addresses and their IP, but the IP addresses are always different. I'm thinking that this huge mass of spam transfer is the cause of some recent connectivity issues with my mail server.
If left long enough, the messages do eventually send, at which point they pass through my spam protection (ASSP), which doesn't stop them and in fact places the messages in its 'not spam' folder even after I added all the bad source email addresses to my blacklist (there are about six email addresses the spammer is sending from right now, though the IP addresses are always different).
I searched this forum and found someone else who experienced a similar issue but the resolution was never posted. See: (http://www.hmailserver.com/forum/viewto ... ht=spammer)
I followed the advice given in this forum and checked the settings:
1) Allow Deliveries from External to External Account is NOT checked off
2) The Open Relay tests I have run tell me that I have no relay open.
3) In the IP Range -> Internet ->"Require Authentication for deliveries
to remote accounts" is checked off
4) Here are some excerpts from the log, where the spammer address service@paypal.com (the spammer addresses are ALWAYS service@something) tries to send to yhlbb@go.com. This message got through to my ASSP spam protection eventually, though I noticed that the hmail log seems to recognize it doesn't exist. Note: I've changed my domain name to domain.com.
is one minute's worth of log, starting from the time the spam appeared:
PD" 3536 62255 "2007-07-10 14:00:51.000" "127.0.0.1" "SENT: 220 domain.com ESMTP"
"SMTPD" 3536 62249 "2007-07-10 14:00:51.000" "127.0.0.1" "RECEIVED: RCPT TO:<yhlbb@go.com>"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: HELO IPCheck"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 Hello."
"SMTPD" 3536 62249 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 OK"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: RSET"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 OK"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: QUIT"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 221 goodbye"
"TCPIP" 3500 "2007-07-10 14:00:51.015" "Disconnecting socket 4264 for session 62255"
*******************
"SMTPD" 3500 62249 "2007-07-10 14:00:57.734" "127.0.0.1" "SENT: 250 Queued (0.375 seconds)"
"APPLICATION" 272 "2007-07-10 14:00:57.734" "SMTPDeliverer - Message 241363: Delivering message from service@paypal.us to yhlbb@go.com, yhlclwtr@mercuryspeed.com, yhmaffozfds@hotmail.com, yhofer@cox.net, yhpwong@hkusua.hku.hk, yhquhl@jblqiiz.net, yhyz99@163.com, yia@valley.net, yiannis.koulas@nokia.com, yiannis@lepalais.gr, yiayiamst@mailcity.com, yichongik@hanmail.net, yigawa@aol.com, yimmy@beefblast.org, yinginze@pacific.net.sg, yingyiduan@hotmail.com, yinwei@mbox5.singnet.com.sg, yiranayah@fhtm.us, yixuanxuan@yahoo.ca, yjedimike@aol.com. File: D:\hMailServer\Data\{27C069BE-3D4D-499D-848C-67DB8E8E3F62}.eml"
"TCPIP" 4884 "2007-07-10 14:00:57.875" "DNS - MX Result: 16 IP addresses were found."
"SMTPD" 3500 62249 "2007-07-10 14:00:57.890" "127.0.0.1" "RECEIVED: QUIT"
"SMTPD" 3500 62249 "2007-07-10 14:00:57.890" "127.0.0.1" "SENT: 221 goodbye"
********************
"APPLICATION" 272 "2007-07-10 14:01:27.514" "SMTPDeliverer - Message 241363: No mail servers exists for the address yhlbb@go.com."
*****************************
"SMTPC" 3536 62340 "2007-07-10 14:01:42.905" "64.97.204.10" "SENT: HELO wpshc.com"
"APPLICATION" 4444 "2007-07-10 14:01:42.983" "SMTPDeliverer - Message 241247: Failed to connect to 199.81.130.93."
"SMTPC" 3536 62340 "2007-07-10 14:01:43.061" "64.97.204.10" "RECEIVED: 250 sc0-in04.emaildefenseservice.com"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.061" "64.97.204.10" "SENT: MAIL FROM:<service@paypal.us>"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.186" "64.97.204.10" "RECEIVED: 250 2.1.0 Ok"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.186" "64.97.204.10" "SENT: RCPT TO:<yhlbb@go.com>"
"TCPIP" 3500 "2007-07-10 14:01:43.311" "Created accept socket 2916 on listening socket 2020"
****************************
"SMTPC" 3500 62360 "2007-07-10 14:01:48.201" "192.118.82.144" "SENT: HELO domain.com"
"SMTPC" 3536 62340 "2007-07-10 14:01:48.358" "64.97.204.10" "RECEIVED: 550 5.7.1 <yhlbb@go.com>: Recipient address rejected: RCPT TO:<yhlbb@go.com> User unknown"
"SMTPC" 3536 62340 "2007-07-10 14:01:48.358" "64.97.204.10" "SENT: QUIT"
"TCPIP" 3536 "2007-07-10 14:01:48.858" "Disconnecting socket 3256 for session 59716"
"TCPIP" 3500 "2007-07-10 14:01:48.858" "Disconnecting socket 2980 for session 59790"
"TCPIP" 3460 "2007-07-10 14:01:48.858" "Disconnecting socket 2884 for session 60007"
"TCPIP" 3556 "2007-07-10 14:01:48.858" "Disconnecting socket 2524 for session 60096"
*******************
"TCPIP" 3536 "2007-07-10 14:02:11.654" "Disconnecting socket 3792 for session 62408"
"TCPIP" 272 "2007-07-10 14:02:11.654" "DNS - MX Lookup: jblqiiz.net"
"TCPIP" 272 "2007-07-10 14:02:11.701" "DNS - MX Result: 0 IP addresses were found."
"APPLICATION" 272 "2007-07-10 14:02:11.701" "SMTPDeliverer - Message 241363: No mail servers exists for the address yhlbb@go.com."
"TCPIP" 272 "2007-07-10 14:02:11.701" "DNS - MX Lookup: lepalais.gr"
"APPLICATION" 4768 "2007-07-10 14:02:11.748" "SMTPDeliverer - Message 241115: Failed to connect to 66.240.173.8."
"TCPIP" 4768 "2007-07-10 14:02:11.748" "DNS - MX Lookup: missionpublishing.net"
"SMTPC" 3536 62380 "2007-07-10 14:02:11.779" "65.24.7.12" "RECEIVED: 250 recipient <eevans@nj.rr.com> ok"
"S
I'm hoping someone here has some advice! I have a spammer somehow using my hmail server to send spam to external email addresses (the messages are sent from external email addresses to external email addresses--they never involve local mail addresses at all). The spam messages get queued up under Undelivered Messages long enough for me to see the source mail addresses and their IP, but the IP addresses are always different. I'm thinking that this huge mass of spam transfer is the cause of some recent connectivity issues with my mail server.
If left long enough, the messages do eventually send, at which point they pass through my spam protection (ASSP), which doesn't stop them and in fact places the messages in its 'not spam' folder even after I added all the bad source email addresses to my blacklist (there are about six email addresses the spammer is sending from right now, though the IP addresses are always different).
I searched this forum and found someone else who experienced a similar issue but the resolution was never posted. See: (http://www.hmailserver.com/forum/viewto ... ht=spammer)
I followed the advice given in this forum and checked the settings:
1) Allow Deliveries from External to External Account is NOT checked off
2) The Open Relay tests I have run tell me that I have no relay open.
3) In the IP Range -> Internet ->"Require Authentication for deliveries
to remote accounts" is checked off
4) Here are some excerpts from the log, where the spammer address service@paypal.com (the spammer addresses are ALWAYS service@something) tries to send to yhlbb@go.com. This message got through to my ASSP spam protection eventually, though I noticed that the hmail log seems to recognize it doesn't exist. Note: I've changed my domain name to domain.com.
is one minute's worth of log, starting from the time the spam appeared:
PD" 3536 62255 "2007-07-10 14:00:51.000" "127.0.0.1" "SENT: 220 domain.com ESMTP"
"SMTPD" 3536 62249 "2007-07-10 14:00:51.000" "127.0.0.1" "RECEIVED: RCPT TO:<yhlbb@go.com>"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: HELO IPCheck"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 Hello."
"SMTPD" 3536 62249 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 OK"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: RSET"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 250 OK"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "RECEIVED: QUIT"
"SMTPD" 3500 62255 "2007-07-10 14:00:51.015" "127.0.0.1" "SENT: 221 goodbye"
"TCPIP" 3500 "2007-07-10 14:00:51.015" "Disconnecting socket 4264 for session 62255"
*******************
"SMTPD" 3500 62249 "2007-07-10 14:00:57.734" "127.0.0.1" "SENT: 250 Queued (0.375 seconds)"
"APPLICATION" 272 "2007-07-10 14:00:57.734" "SMTPDeliverer - Message 241363: Delivering message from service@paypal.us to yhlbb@go.com, yhlclwtr@mercuryspeed.com, yhmaffozfds@hotmail.com, yhofer@cox.net, yhpwong@hkusua.hku.hk, yhquhl@jblqiiz.net, yhyz99@163.com, yia@valley.net, yiannis.koulas@nokia.com, yiannis@lepalais.gr, yiayiamst@mailcity.com, yichongik@hanmail.net, yigawa@aol.com, yimmy@beefblast.org, yinginze@pacific.net.sg, yingyiduan@hotmail.com, yinwei@mbox5.singnet.com.sg, yiranayah@fhtm.us, yixuanxuan@yahoo.ca, yjedimike@aol.com. File: D:\hMailServer\Data\{27C069BE-3D4D-499D-848C-67DB8E8E3F62}.eml"
"TCPIP" 4884 "2007-07-10 14:00:57.875" "DNS - MX Result: 16 IP addresses were found."
"SMTPD" 3500 62249 "2007-07-10 14:00:57.890" "127.0.0.1" "RECEIVED: QUIT"
"SMTPD" 3500 62249 "2007-07-10 14:00:57.890" "127.0.0.1" "SENT: 221 goodbye"
********************
"APPLICATION" 272 "2007-07-10 14:01:27.514" "SMTPDeliverer - Message 241363: No mail servers exists for the address yhlbb@go.com."
*****************************
"SMTPC" 3536 62340 "2007-07-10 14:01:42.905" "64.97.204.10" "SENT: HELO wpshc.com"
"APPLICATION" 4444 "2007-07-10 14:01:42.983" "SMTPDeliverer - Message 241247: Failed to connect to 199.81.130.93."
"SMTPC" 3536 62340 "2007-07-10 14:01:43.061" "64.97.204.10" "RECEIVED: 250 sc0-in04.emaildefenseservice.com"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.061" "64.97.204.10" "SENT: MAIL FROM:<service@paypal.us>"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.186" "64.97.204.10" "RECEIVED: 250 2.1.0 Ok"
"SMTPC" 3536 62340 "2007-07-10 14:01:43.186" "64.97.204.10" "SENT: RCPT TO:<yhlbb@go.com>"
"TCPIP" 3500 "2007-07-10 14:01:43.311" "Created accept socket 2916 on listening socket 2020"
****************************
"SMTPC" 3500 62360 "2007-07-10 14:01:48.201" "192.118.82.144" "SENT: HELO domain.com"
"SMTPC" 3536 62340 "2007-07-10 14:01:48.358" "64.97.204.10" "RECEIVED: 550 5.7.1 <yhlbb@go.com>: Recipient address rejected: RCPT TO:<yhlbb@go.com> User unknown"
"SMTPC" 3536 62340 "2007-07-10 14:01:48.358" "64.97.204.10" "SENT: QUIT"
"TCPIP" 3536 "2007-07-10 14:01:48.858" "Disconnecting socket 3256 for session 59716"
"TCPIP" 3500 "2007-07-10 14:01:48.858" "Disconnecting socket 2980 for session 59790"
"TCPIP" 3460 "2007-07-10 14:01:48.858" "Disconnecting socket 2884 for session 60007"
"TCPIP" 3556 "2007-07-10 14:01:48.858" "Disconnecting socket 2524 for session 60096"
*******************
"TCPIP" 3536 "2007-07-10 14:02:11.654" "Disconnecting socket 3792 for session 62408"
"TCPIP" 272 "2007-07-10 14:02:11.654" "DNS - MX Lookup: jblqiiz.net"
"TCPIP" 272 "2007-07-10 14:02:11.701" "DNS - MX Result: 0 IP addresses were found."
"APPLICATION" 272 "2007-07-10 14:02:11.701" "SMTPDeliverer - Message 241363: No mail servers exists for the address yhlbb@go.com."
"TCPIP" 272 "2007-07-10 14:02:11.701" "DNS - MX Lookup: lepalais.gr"
"APPLICATION" 4768 "2007-07-10 14:02:11.748" "SMTPDeliverer - Message 241115: Failed to connect to 66.240.173.8."
"TCPIP" 4768 "2007-07-10 14:02:11.748" "DNS - MX Lookup: missionpublishing.net"
"SMTPC" 3536 62380 "2007-07-10 14:02:11.779" "65.24.7.12" "RECEIVED: 250 recipient <eevans@nj.rr.com> ok"
"S