2

我的网站管理员万能电子邮件地址开始收到来自各种电子邮件系统的大量“交付状态通知(失败)”回复。每小时 1 次。

显然是垃圾邮件被发送,因为内容是关于药物的。我想弄清楚是否

1)不是由我们发送,而是在我们的站点上设置了回复字段,因此我们收到了失败通知或 2)我们的系统已被破坏并且由我们发送,损害了我们的声誉。另外 - 如果是这种情况,我在哪里寻找解决问题?!

谢谢!

这是一个例子:

 Delivery to the following recipient failed permanently:

 grdchurch@mail.calvinseminary.edu

 Technical details of permanent failure:
 Google tried to deliver your message, but it was rejected by the recipient domain. We         recommend contacting the other email provider for further information about the cause of    this error. The error that the other server returned was: 550 550 5.1.1   <grdchurch@calvinseminary.edu>... User unknown (state 13).

 ----- Original message -----

 Received: by 10.204.152.70 with SMTP id f6mr6872450bkw.7.1341224023720;
 Mon, 02 Jul 2012 03:13:43 -0700 (PDT)
 Received: by 10.204.152.70 with SMTP id f6mr6872447bkw.7.1341224023673;
 Mon, 02 Jul 2012 03:13:43 -0700 (PDT)
 Return-Path: <Ester7CB4674@mysite.com>
 Received: from 94.98.142.218 ([94.98.142.218])
 by mx.google.com with ESMTP id hi9si10538192bkc.151.2012.07.02.03.13.38;
 Mon, 02 Jul 2012 03:13:39 -0700 (PDT)
 Received-SPF: neutral (google.com: 94.98.142.218 is neither permitted nor denied by   best guess record for domain of Ester7CB4674@mysite.com) client-ip=94.98.142.218;
 Authentication-Results: mx.google.com; spf=neutral (google.com: 94.98.142.218 is neither permitted nor denied by best guess record for domain of Ester7CB4674@mysite.com)    smtp.mail=Ester7CB4674@mysite.com
 Date: Mon, 02 Jul 2012 03:13:39 -0700 (PDT)
 Message-Id: <20120702131340.6C18454BE719A3A513E9@USER-PC>
 From: Leslie Browning <Ester7CB4674@mysite.com>
 To: grdchurch <grdchurch@calvinseminary.edu>
 Reply-To: Maryanne Whitehead <Terry1DA24@starlane411.com>
 Subject: For grdchurch
 Mime-Version: 1.0
 Content-Type: text/plain; charset=utf-8
 Content-Transfer-Encoding: 7bit

 best ED meds! Be confident! Buy here http://www.akermedic.ru/

 B3B0ED3F2E14A898C2C644020D7E9A8071
 30DA492A4CF3EB0A0E3DE1371040BE5C81
 4C9CF9C9AC2D7881DACD5D1B0A9A460
4

2 回答 2

1

您可以在邮件标题中看到

Received: from 94.98.142.218 ([94.98.142.218])

如果那里的 IP 不等于任何主机的 ip,则它只是欺骗的From标头。标Received头不是由发件人创建的,而是由(可能)也向您发送Delivery Status Notification (Failure)消息的中间邮件服务器创建的。这不能轻描淡写。攻击者也不需要欺骗,因为他已经您的系统作为欺骗。

所以我认为这指向一个指向你的欺骗From标题的方向。当然没有保证。

于 2012-07-02T16:38:02.503 回答
1

Try installing some anti-virus and anti-malware like:

http://www.malwarebytes.org/

http://www.microsoft.com/security/pc-security/mse.aspx

and run a full system scan, see what you come up with.

于 2012-07-02T16:18:03.470 回答