Received from local host 127.0.0.1 ???????

joecrash

Banned
Local time
5:54 PM
Messages
49
I've been plauged by trojans and worms in spoofed emails with forged headers. So, I now at least look at the email headers now, even if I do not understand all of it - I had this in the header of 2 emails today:

"from localhost ([127.0.0.1] helo=sfs-ml-2.v29.ch3.sourceforge.com) by sfs-ml-2.v29.ch3.sourceforge.com with esmtp (Exim 4.74) (envelope-from <[email protected]>) id 1Q47OU-00008s-Gd; Mon, 28 Mar 2011 08:01:46 +0000"

What does this mean? Is this a spoofed email header?

Thanks in advance for your help!
 

My Computer My Computer

At a glance

Win 7 HP 64 bitIntel i36GBIntegrated w/ MoBo
Computer Manufacturer/Model Number
Lenovo K320
OS
Win 7 HP 64 bit
CPU
Intel i3
Motherboard
Intel
Memory
6GB
Graphics Card(s)
Integrated w/ MoBo
Sound Card
Same as above
Monitor(s) Displays
E-Machine 17"
Hard Drives
Seagate 1TB
PSU
Stock 450Watt
Case
stock
Cooling
stock

My Computer My Computer

At a glance

Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
I didn't look further than the "received from" IP

Yes, I did subscribe to the Sleuthkit mailings. I didn't look past the "local host" part -

So, even if the "received from" portion of the header says "from local host 127.0.0.1"

this by itself doesn't indicate mal/spy ware? I'd just never seen that before, and just assumed it had to be incorrect.

I'm paranoid now because of all the forged emails I've had in the past with trojans in them.
 

My Computer My Computer

At a glance

Win 7 HP 64 bitIntel i36GBIntegrated w/ MoBo
Computer Manufacturer/Model Number
Lenovo K320
OS
Win 7 HP 64 bit
CPU
Intel i3
Motherboard
Intel
Memory
6GB
Graphics Card(s)
Integrated w/ MoBo
Sound Card
Same as above
Monitor(s) Displays
E-Machine 17"
Hard Drives
Seagate 1TB
PSU
Stock 450Watt
Case
stock
Cooling
stock
The "from localhost" is a common issue, has to do something with the way the mail is relayed and how the hosts file is setup and what software is used. But AFAIK, it doesnt indicate any malware. If you want to get into the details, post in the networking subforum.
 

My Computer My Computer

At a glance

Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
Computer Manufacturer/Model Number
Too many to describe...
OS
Windows 7 x64 pro/ Windows 7 x86 Pro/ XP SP3 x86
"from localhost ([127.0.0.1] helo=sfs-ml-2.v29.ch3.sourceforge.com) by sfs-ml-2.v29.ch3.sourceforge.com with esmtp (Exim 4.74) (envelope-from <[email protected]>) id 1Q47OU-00008s-Gd; Mon, 28 Mar 2011 08:01:46 +0000"
!

I really wouldn't be concerned, if you take a closer look you can see what its doing.

When it says localhost ([127.0.0.1] it is talking about the loopback address on your machine.

by sfs-ml-2.v29.ch3.sourceforge.com with esmtp this is the mail server address which uses esmtp (a mail protocol) to send it.

(Exim 4.74) is the mail server which sent the mail

[email protected] is the email adress it sent from

Mon, 28 Mar 2011 08:01:46 is just your date/time stamp for the email.

Nothing out of the ordinary here, all this text is in every email, you just normally cant see it.
 

My Computer My Computer

At a glance

Windows 7 Professional x64 Backtrack 4 R2Intel Core i5-6504 GB Geil PC3 12800HIS HD 4870 X2
OS
Windows 7 Professional x64 Backtrack 4 R2
CPU
Intel Core i5-650
Motherboard
Gigabyte P55-UD3
Memory
4 GB Geil PC3 12800
Graphics Card(s)
HIS HD 4870 X2
Sound Card
Sound Blaster X-Fi Titanium Fatal1ty Champion
Monitor(s) Displays
BenQ 22" G2220HD
Hard Drives
Seagate Barracuda 7200.12 500GB
Seagate Barracuda 7200.12 500GB
PSU
Antec High Current Gamer 620W Power Supply
Case
Thermaltake Armor+ MX
Keyboard
Microsoft SideWinder X6
Mouse
Razer Abyssus
Thank you

Thanks for looking at that, it lessens my paranoia a bit!:D

I'll have to research email headers and forging them to be able to pick the bad ones out in the future, but at least I know I'm OK for now.
Thanks Again.
 

My Computer My Computer

At a glance

Win 7 HP 64 bitIntel i36GBIntegrated w/ MoBo
Computer Manufacturer/Model Number
Lenovo K320
OS
Win 7 HP 64 bit
CPU
Intel i3
Motherboard
Intel
Memory
6GB
Graphics Card(s)
Integrated w/ MoBo
Sound Card
Same as above
Monitor(s) Displays
E-Machine 17"
Hard Drives
Seagate 1TB
PSU
Stock 450Watt
Case
stock
Cooling
stock
Glad i could be of some assistance. :)
 

My Computer My Computer

At a glance

Windows 7 Professional x64 Backtrack 4 R2Intel Core i5-6504 GB Geil PC3 12800HIS HD 4870 X2
OS
Windows 7 Professional x64 Backtrack 4 R2
CPU
Intel Core i5-650
Motherboard
Gigabyte P55-UD3
Memory
4 GB Geil PC3 12800
Graphics Card(s)
HIS HD 4870 X2
Sound Card
Sound Blaster X-Fi Titanium Fatal1ty Champion
Monitor(s) Displays
BenQ 22" G2220HD
Hard Drives
Seagate Barracuda 7200.12 500GB
Seagate Barracuda 7200.12 500GB
PSU
Antec High Current Gamer 620W Power Supply
Case
Thermaltake Armor+ MX
Keyboard
Microsoft SideWinder X6
Mouse
Razer Abyssus
Back
Top