Hello All. This morning I started to get a bunch of MAILER-DAEMON, returned Email errors. They all were from a non real user on my network to chineese sites. Specifically, they were from one of my domains@mydomain.com (spcomputers@spcomputers.com). Again, this user does not exist. below is an example header.
****************************************************
Hi. This is the qmail-send program at mapango.net.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.
<joonlove0125@hanmail.net>:
211.43.197.153 does not like recipient.
Remote host said: 550 5.1.1 <joonlove0125@hanmail.net>... Inactive mbox
Giving up on 211.43.197.153.
--- Below this line is a copy of the message.
Return-Path: <spcomputers@spcomputers.com>
Received: (qmail 4915 invoked from network); 8 Dec 2005 12:53:53 -0000
Received: from unknown (HELO fqx.ser.qdekm.com) (61.96.188.159)
by server.mapango.net (66.225.16.170) with SMTP; 08 Dec 2005 12:53:53 -0000
Message-ID: <SMPYBAAHXJGPRLRXURYHID@IJSSK>
From: "±è±ÔÀ¸"<spcomputers@spcomputers.com>
To: joonlove0125@hanmail.net
Subject: =?ks_c_5601?q?<=B1=A4=B0=ED>=C3=EB=C1=F7=20100%=20=20"=BB=E7=C8=B8=20=BA=B9=C1=F6=BB=E7"=C0=DA=B7=E1=B4=C2=20=B9=AB=B7=E1"=20@oyt553@?=
X-Mailer: Microsoft Outlook Express 6.00.2462.0000
X-Priority: 5
X-MSMail-Priority: Low
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Content-type: text/html
****************************************************
I am running SME 6X, fully patched, and rkhunter. All but one of the PC's in my office run Linux or OSX. This seems to come from a worm called w32.jubon@mm. It also seems to originate from a user running Outlook Express, which non of us run. It could come from someone whom I host, but I'm having trouble finding a way to trace the mail back to the actual sender, via the log files. What is more funkey, is that we are ALL receiving the MAILER-DAEMON error.
Any ideas all you guru's out there, or is there a qmail log file that will tell the IP of the machine sending the Email?
Chris Curtis