Networking Forums

Networking Forums > Network Hardware > Home Networking > Email attack

Reply
 
 
Ritch
Guest
Posts: n/a

 
      09-20-2003, 08:26 AM
Hi

Ive just received 295 emails and I dont know what the hell they are. They
have titles Like: -

Bug Report
Newest Network Security Upgrade
current internet critical update
Undelivered Message
Newest Internet Security Pack
Last Network Upgrade

They keep coming and I have no idea why, I have not tried to open them just
in case they contain a virus or something. I have not subscribed to any
news letters as far as I know.

Anyone else had this problem?

thanks for any help
Ritch


 
Reply With Quote
 
 
 
 
Groove
Guest
Posts: n/a

 
      09-20-2003, 08:29 AM
Ritch said this...

> Bug Report
> Newest Network Security Upgrade
> current internet critical update
> Undelivered Message
> Newest Internet Security Pack
> Last Network Upgrade



All part of a major virus attack happening right now, mostly junk
pretending to be MSoft upgrades. Delete them and don't worry.

--
º~ dªv¡d ~º
 
Reply With Quote
 
Linux Penguin
Guest
Posts: n/a

 
      09-20-2003, 09:05 AM

its a virus - your virus program should detect it and delete the message


On Sat, 20 Sep 2003 08:29:34 GMT, Groove <(E-Mail Removed)> wrote:

>Ritch said this...
>
>> Bug Report
>> Newest Network Security Upgrade
>> current internet critical update
>> Undelivered Message
>> Newest Internet Security Pack
>> Last Network Upgrade

>
>
>All part of a major virus attack happening right now, mostly junk
>pretending to be MSoft upgrades. Delete them and don't worry.


 
Reply With Quote
 
Stephen
Guest
Posts: n/a

 
      09-20-2003, 09:25 AM
Like groove said its the latest in hoax MS viruses! some are variations of
Blaster.
Update virus scanner.

I also have a tracker to find where they actually came from

Stephen

"Linux Penguin" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> its a virus - your virus program should detect it and delete the message
>
>
> On Sat, 20 Sep 2003 08:29:34 GMT, Groove <(E-Mail Removed)>

wrote:
>
> >Ritch said this...
> >
> >> Bug Report
> >> Newest Network Security Upgrade
> >> current internet critical update
> >> Undelivered Message
> >> Newest Internet Security Pack
> >> Last Network Upgrade

> >
> >
> >All part of a major virus attack happening right now, mostly junk
> >pretending to be MSoft upgrades. Delete them and don't worry.

>



 
Reply With Quote
 
Groove
Guest
Posts: n/a

 
      09-20-2003, 10:16 AM
Stephen said this...
> I also have a tracker to find where they actually came from


Don't they just come from random infected boxes?

--
º~ dªv¡d ~º
 
Reply With Quote
 
TX2
Guest
Posts: n/a

 
      09-20-2003, 10:55 AM
In article <bkh30e$8q0$(E-Mail Removed)>,
(E-Mail Removed) says...


> Ive just received 295 emails and I dont know what the hell they are.


Viruses.

And given that intended recipients are being harvested from Usenet in
the main, you ought to do something about not publishing your full email
address to such a medium.
 
Reply With Quote
 
Tim Downie
Guest
Posts: n/a

 
      09-20-2003, 11:28 AM
Ritch wrote:
> Hi
>
> Ive just received 295 emails and I dont know what the hell they are.


A virus

>
> They keep coming and I have no idea why,


It's because you haven't disguised your email address for usenet posting.

I have an e-mail address I use only for usenet (as the german server I use
asks for a valid address). It's attracting 200+ of these messages a day.
My private e-mail address doesn't get any. I use POP3 Scan Mailbox to
delete them off the server.

I'm willing to bet most recipients have had their addresses harvested from
usenet.

HTH

Tim

 
Reply With Quote
 
Joe
Guest
Posts: n/a

 
      09-20-2003, 05:44 PM
In article <bkhdkc$1t897$(E-Mail Removed)>, timdownie2000
@yahoo.co.uk says...
> Ritch wrote:
> > Hi
> >
> > Ive just received 295 emails and I dont know what the hell they are.

>
> A virus
>
> >
> > They keep coming and I have no idea why,

>
> It's because you haven't disguised your email address for usenet posting.
>
> I have an e-mail address I use only for usenet (as the german server I use
> asks for a valid address). It's attracting 200+ of these messages a day.
> My private e-mail address doesn't get any. I use POP3 Scan Mailbox to
> delete them off the server.
>
> I'm willing to bet most recipients have had their addresses harvested from
> usenet.
>
> HTH
>
> Tim
>
>

Tim,

cis.dfn.de asks for a valid name on joing but when you're on usenet you
can change it to a 'dummy'. Might save you getting 200+ a day on a real
but unused account that you obviously watch and have to clean.
(I'm on that server too)
 
Reply With Quote
 
=?ISO-8859-1?Q?Andr=E9_Franke?=
Guest
Posts: n/a

 
      09-20-2003, 09:05 PM
"Ritch" <(E-Mail Removed)> wrote before:
in <bkh30e$8q0$(E-Mail Removed)>

>Hi
>
>Ive just received 295 emails and I dont know what the hell they are.


That's just a start. I filtered about 4000 mails in the past 36 hours.
To learn more about what's going on, read here:
http://www.trendmicro.com/vinfo/viru...SWEN.A&VSect=T

To filter those mails, you need to scan the body of the mails for the
strings *undeliver* and *cumulative patch* .
The mails come in two general versions:
One pretends to be an undeliverable mail, returned to you.
(filter for *undeliver*)
The other is a faked Microsoft Support Mail that delivers a "patch".
(filter for *cumulative patch*)
The "returned" mails were never sent from your e-mail account, but the
RETURN-PATH-field in the headers may tell from what infected host they
came.
The "Microsoft" mails can only be faked, since Microsoft never _sends_
any patches nor updates to you. They would send you information on how
you can download such files, if they would send you anything at all.

regards
André
--
For e-mail use plain-text only, please.
HTML and attachments will be silently discarded.
 
Reply With Quote
 
Jock Mackirdy
Guest
Posts: n/a

 
      09-20-2003, 09:10 PM
In article <bkhdkc$1t897$(E-Mail Removed)>, Tim Downie wrote:

> It's because you haven't disguised your email address for usenet posting.
>
> I have an e-mail address I use only for usenet (as the german server I use
> asks for a valid address). It's attracting 200+ of these messages a day.
> My private e-mail address doesn't get any. I use POP3 Scan Mailbox to
> delete them off the server.
>
> I'm willing to bet most recipients have had their addresses harvested from
> usenet.


After spending hours locating and deleting the 50 or so .EXE file
attachments, I've decided to use different addresses for mail and newsgroups.
I use Virtual Access as my newsreader, which makes this easy. It also avoids
being troubled with nasties designed to attack Outlook.

--

Jock Mackirdy
Bedford


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Possible attack? Anon E. Muss Linux Networking 13 12-02-2008 04:57 PM
email extractor , site , solutions , email based marketing , email marketing solution , email extractor , newsletter software , mass email , e-mail marketing , email marketing solutions , bulk email software , web advertising , email marketing , mark Nuclear Incorporation. www.nuclear-inc.com Broadband 0 04-05-2007 08:38 PM
email extractor , site , solutions , email based marketing , email marketing solution , email extractor , newsletter software , mass email , e-mail marketing , email marketing solutions , bulk email software , web advertising , email marketing , mark Nuclear Incorporation. www.nuclear-inc.com Home Networking 0 04-05-2007 08:31 PM
Is my router under attack? Ian Burley Broadband 8 05-29-2004 08:58 AM
SYN attack R.J. Rabenberg Wireless Internet 2 02-01-2004 05:16 PM



1 2 3 4 5 6 7 8 9 10 11