PDA

View Full Version : Spammers spoofing addies?


BDR
2 Nov 2003, 9:11am
I found this in one of my email boxes just now.
I assume someone is spoofing my addy, because I never sent the email.
-------------------------------------------------------------------------------
The original message was received at Sat, 1 Nov 2003 21:43:24 -0500
(EST)
from ip-11.net-80-236-39.suresnes.rev.numericable.fr [80.236.39.11]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with
its
delivery. The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors
-----".

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail
could
not be delivered. The next line contains a second error message which
is a
general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail
administrator.

--AOL Postmaster



----- The following addresses had permanent fatal errors -----
<bgivens@aol.com>

----- Transcript of session follows -----
... while talking to air-xb01.mail.aol.com.:
>>> RCPT To:<bgivens@aol.com>
<<< 550 MAILBOX NOT FOUND
550 <bgivens@aol.com>... User unknown



Message/delivery-status

Reporting-MTA: dns; rly-xb02.mx.aol.com
Arrival-Date: Sat, 1 Nov 2003 21:43:24 -0500 (EST)

Final-Recipient: RFC822; bgivens@aol.com
Action: failed
Status: 5.1.1
Remote-MTA: DNS; air-xb01.mail.aol.com
Diagnostic-Code: SMTP; 550 MAILBOX NOT FOUND
Last-Attempt-Date: Sat, 1 Nov 2003 21:43:39 -0500 (EST)

Received: from ip-11.net-80-236-39.suresnes.rev.numericable.fr
(ip-11.net-80-236-39.suresnes.rev.numericable.fr [80.236.39.11]) by
rly-xb02.mx.aol.com (v97.7) with ESMTP id MAILRELAYINXB24-903fa46f4abe; Sat, 01
Nov 2003 21:43:24 -0400
Received: from nl ([57.96.221.182])
by ip-11.net-80-236-39.suresnes.rev.numericable.fr
(8.11.6/8.11.6) with SMTP id uptpo309916
for <bgivens@aol.com>; Sat, 1 Nov 2003 22:01:16 -0800
Message-ID:
<1904671067752876@ip-11.net-80-236-39.suresnes.rev.numericable.fr>
From: "andriana" <imbdr@yahoo.com>
To: "bgivens@aol.com" <bgivens@aol.com>
Subject:
Date: Sat, 1 Nov 2003 22:01:16 -0800
MIME-Version: 1.0
Content-Language: en
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-AOL-IP: 80.236.39.11
X-AOL-SCOLL-SCORE: 1:XXX:XX
X-AOL-SCOLL-URL_COUNT: 2

Necropolis
2 Nov 2003, 9:26am
This is not always spammers. Some virus spoof email address when they send themself out. Nothing to worry about if you have a good virus checker and firewall on your machine.

BDR
2 Nov 2003, 9:31am
Could be.
I'm not too worried about my pc's though.
I run a hardware firewall (router) and
I run AVG and update it every couple days.

It's just irritating because the addy that's spoofed is the one I use here, and it's fairly new.

Necropolis
2 Nov 2003, 9:41am
It can get sent from someone you know's PC. It reads from the address book on the machine.

BDR
2 Nov 2003, 9:50am
That's disturbing because I don't know of anyone that uses the email addy of mine that it spoofed, other than a few folks here, and I would think everyone here has a good AV and firewall running. hmmm...

:confused:

wait.. I think I may have found a likely culprit.
I signed up for the new Napster using that addy.
Think someone is harvesting addies from Napster?

:wtf:

Straight_Man
2 Nov 2003, 8:33pm
I would update virus defs and check. The latest descendant of SoBig is called Sober, and it can mine html on a computer and address books. So, if you built a website and stuckl that address in it, guess what??? Sober will use it. If you went to a website have html in your temp internet folders, Sober can use any email: links there as destinations also.

Best advice, scan, and possibly your AV killed it but possible also that since this is a newer one that you might need updated defs to catch it. Very good idea as other said to update definitions.

John.