I have a user that is receiving the Yaha.E virus about once a day. We keep our AV definitions up to date so it is always detected, but it would be nice to be able to identify the source. Since the return address is spoofed is there a way to track these things down?
You might try checking your mail server logs, you'd at least get the IP address (and probably domain) of the mail server sending it to you, and assuming it's not AOL/Hotmail/Earthlink you could probably contact the mailserver admin and have them contact the user or block the account.
-Steve
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.