我正在尝试隔离在我的网络上发送恶意软件的电子邮件。标题如下:
Received: from z.local.domain (172.18.248.22) by z.local.domain (172.18.248.22) with Microsoft SMTP Server (TLS) id 15.0.712.24 via Mailbox Transport; Mon, 30 Sep 2013 02:35:43 -0700
Received: from z.local.domain (172.18.248.22) by z.local.domain (172.18.248.22) with Microsoft SMTP Server (TLS) id 15.0.712.24; Mon, 30 Sep 2013 02:35:43 -0700
Received: from localhost (172.18.248.18) by z.local.domain (172.18.248.22) with Microsoft SMTP Server (TLS) id 15.0.712.24 via Frontend Transport; Mon, 30 Sep 2013 02:35:43 -0700
Received: from www-data by localhost with local (Exim 4.80) (envelope-from <[email protected]>) id 1VQZtH-0002oq-13 for [email protected]; Mon, 30 Sep 2013 02:35:43 -0700
MIME-Version: 1.0
Subject: Subject: eRKpqkSHqdjESMjhqQ
Return-Path: [email protected]
X-MS-Exchange-Organization-Authsource: z.local.domain
Date: Mon, 30 Sep 2013 02:35:43 -0700
X-MS-Exchange-Organization-Network-Message-ID: d786a17d-ef12-4403-aa12-08d08bd7914a
X-MS-Exchange-Organization-Authas: Anonymous
content-type: text/html; charset="utf-8"
Message-ID: <E1VQZtH-0002oq-13@localhost>
To: <[email protected]>
X-PHP-Originating-Script: 0:ticket.php
From: Benjamin <[email protected]>
X-RT-Original-Encoding: iso-8859-1
Content-Length: 500
我已经用clamwin 和malwarebytes 扫描了Z 服务器,但都返回了否定的结果。除了帮助台之外,似乎没有其他人在我们的网络中报告过这种垃圾邮件。(Helpdesk 位于运行 Request Tracker 4 的 Debian 7.1 主机上 - 这是检查此电子邮件帐户的唯一位置。)
我可以在 Z 服务器上运行任何其他扫描仪还是问题出在其他地方?
您的标头显示此邮件来自 172.18.248.18。这就是您需要查看的机器。