Strange email delivery event from mail.ru
Hello,
one of our customer get strange undelivery emails. I copied one of the message. This is a test email from info@ice-star.hu to info@ice-star.hu.
As you see somehow the mail forwarded to the russian forward2office3@mail.ru email address, but i dont know how. No forwarders found on cpanel.
Reinstalled all pc to w10/nod32/normal user rights. Changed all passwords 2-3x, last idea was just use the cpanel webmail (no outlook, thunderbird etc). Checked DNS, gateway IPs. But no luck.
I wanted to know, they get a crypto virus in dec that eat all windows servers. They have 2 virtual windows server with file shares, no AD, SQL.
And they have 2 linux server with only DB server. The windows servers reinstalled from zero.
I have no idea where i can find the problem, maybe someone can help me.
Thank you, Atis
mail head:
Return-Path: <>
Delivered-To: info+INBOX@ice-star.hu
Received: from cpanel.sicob.hu
by cpanel.sicob.hu with LMTP
id MDYfBwg/H15cXgAAUHZF6Q
(envelope-from <>)
for ; Wed, 15 Jan 2020 17:34:16 +0100
Return-path: <>
Envelope-to: info@ice-star.hu
Delivery-date: Wed, 15 Jan 2020 17:34:16 +0100
Received: from mailnull by cpanel.sicob.hu with local (Exim 4.92)
id 1irlcV-0006MA-S6
for info@ice-star.hu; Wed, 15 Jan 2020 17:34:15 +0100
X-Failed-Recipients: forward2office3@MAIL.ru
Auto-Submitted: auto-replied
From: Mail Delivery System
To: info@ice-star.hu
Content-Type: multipart/report; report-type=delivery-status; boundary=1579106055-eximdsn-1040061028
MIME-Version: 1.0
Subject: Mail delivery failed: returning message to sender
Message-Id:
Date: Wed, 15 Jan 2020 17:34:15 +0100
mail body:
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
forward2office3@MAIL.ru
(ultimately generated from info@ice-star.hu)
host mxs.mail.ru [94.100.180.31]
SMTP error from remote mail server after end of data:
550 spam message rejected. Please visit or report details to abuse@corp.mail.ru. Error code: 5AFA77879C65645BB493ACE1435C055BEA8E34E5C03044B3AAA2E88B66650A51. ID: 0000002900006BB82EAED173.
| T"rgy | proba webmailrol |
| Felad" (Sender) | info@ice-star.hu |
| C"mzett (Recipient) | info@ice-star.hu |
| D"tum | Ma 17:34 |
Please sign in to leave a comment.
Comments
0 comments