Re: has my sendmail been compromised?
- From: doctor@xxxxxxxxxxxxxxxxx (The Doctor)
- Date: Fri, 5 Aug 2005 12:39:54 +0000 (UTC)
In article <42f2d1dc$1_1@xxxxxxxxxxxxxxxxxxxxxxxxx>,
don garb <don_garb@xxxxxxxx> wrote:
>-=-=-=-=-=-
>
>Please see attachments - WARNING! I believe the sloppily masqueraded exe
>file to be malware although an online scanner that I submitted it to
>said it was clean. I am on Linux so I am immune to this windows exe but
>I would only open it only on a non-essential quarantined machine.
>
>I host my website with hostingplex and they use sendmail, my account
>name is Eve. Yesterday I noticed the default mailbox had 183 pieces of
>junk and I deleted them all. Only afterwards did I think it was
>suspicious that most of the junk mail was return to sender, stop
>spamming us, undeliverable and out of office auto replies. So that made
>me think my domain was being spoofed to send out spam.
>
>Then today I received this:
>
>*Dear Adamandevedreamdates Member, *
>
>We have temporarily suspended your email account
>eve@xxxxxxxxxxxxxxxxxxxxxxxxx
>
>This might be due to either of the following reasons:
>
>1. A recent change in your personal information (i.e. change of address).
>2. Submitting invalid information during the initial sign up process.
>3. An innability to accurately verify your selected option of
>subscription due
>to an internal error within our processors.
>See the attached details to reactivate your Adamandevedreamdates account.
>
>Sincerely,The Adamandevedreamdates Support Team
>
>This message purportedly came from admin@mydomain but there is no admin
>account. Also the grammar is bad and reason 3 is gibberish.
>
>I have included the original message with the attachment which might
>fool some people into thinking it's a txt file but really it's an exe.
>If the exe doesn't make it to the newsgroup I have posted it at
>h2g.ca/chris. Be very careful downloading and running it.
>
>I can ssh into my account to configure things at a low level since my
>host's cpanel and horde web clients are pretty tame.
>
>If anyone can help I would be truly grateful. Thanks in advance!
>
>-=-=-=-=-=-
>-=-=-=-=-=-
>
>Dear Adamandevedreamdates Member,
>
>We have temporarily suspended your email account eve@xxxxxxxxxxxxxxxxxxxxxxxxx
>
>This might be due to either of the following reasons:
>
>1. A recent change in your personal information (i.e. change of address).
>2. Submiting invalid information during the initial sign up process.
>3. An innability to accurately verify your selected option of
>subscription due to an internal error within our processors.
>See the attached details to reactivate your Adamandevedreamdates account.
>
>Sincerely,The Adamandevedreamdates Support Team
>-=-=-=-=-=-
>[Attachment type=application/octet-stream, name=account-details.zip]
>-=-=-=-=-=-
>-=-=-=-=-=-
>[Attachment type=application/octet-stream, name=account-details.txt.exe]
>-=-=-=-=-=-
Get clamav into your system. The above is a virus!@
--
Member - Liberal International
This is doctor@xxxxxxxxxx Ici doctor@xxxxxxxxxx
God Queen and country! Beware Anti-Christ rising!
Better to serve in Heaven that to Rule in Hell.
.
- Prev by Date: Re: has my sendmail been compromised?
- Next by Date: Combining LDAP routing and aliasing
- Previous by thread: Re: has my sendmail been compromised?
- Next by thread: Combining LDAP routing and aliasing
- Index(es):