How to find spammer on server?

We are having serious problems last days, someone spamming through our server by using our SMTP and we cant find him...

We have installed mail header (http://choon.net/php-mail-header.php) but it doesn't show any information.

I think spammer using remote connection to SMTP, but we have SMTP tweak enable in Tweak Setup settings.

Please help to find that *******.

Thank you!

Here is example of email header.
Code:
"From verified@visa.com Sat Aug 27 11:43:12 2005"
Return-Path: <verified@visa.com>
X-Original-To: x
Delivered-To: x
Received: from server1.somehost.com (server1.somehost.com [222.22.222.222])
by lucite.kapu.net (Postfix) with ESMTP id D031A8B4879
for <x>; Sat, 27 Aug 2005 11:43:11 -1000 (HST)
Received: from host-81-190-134-215.olsztyn.mm.pl ([81.190.134.215] helo=User)
by server1.somehost.com with esmtpa (Exim 4.50)
id 1E98Rm-0003Mr-SQ; Sat, 27 Aug 2005 17:42:50 -0400
Reply-To: <verified@visa.com>
From: "verified@visa.com" <verified@visa.com>
Subject: Visa Accounts Security Center - Verified By Visa
Date: Sun, 28 Aug 2005 00:42:43 +0300
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server1.somehost.com
X-AntiAbuse: Original Domain - kapu.net
X-AntiAbuse: Originator/Caller UID/GID - [0 0] / [47 12]
X-AntiAbuse: Sender Address Domain - visa.com
X-Source:
X-Source-Args:
X-Source-Dir:
Message-Id: <2005__________________4879@lucite.kapu.net>
To: undisclosed-recipients:;
Comments: INPUT 222.22.222.222
Comments: HELO server1.somehost.com
Comments: RDNS server1.somehost.com.
Comments: Spammo: DNSBL SpamCop.net
Comments: Spammo_Gold: X-Mailer: Faux-Outlook; does not match Message-ID:
Comments: Warning: Message-Id: assigned locally.
Comments: Spammo: HTML-only email.
Comments: Warning: To: contains undisclosed or suppressed
Comments: Spammo_Gold: Scored DNSBLs, Message-Id:s
Comments: ASN 13749

 

 

 

 

Top