View Single Post
Old 03 Mar 2004, 18:44   #25
R.
You dig.
 
Join Date: 02.04.2002
Location:  On the fothermucker
Posts: 7,179
Default

To clarify this:

I'm 99,99% sure that Caryl is not spreading any internet worm.
You can verify this quite easily, if you analyse the mail headers.
It's much more likely that one member of that mailing lists got infected and now the worm is harvesting that member's address book.

Additionally a warning:
There are variants of the W32/Bagle worms on the loose.
I received an email from management@mlukfc.com notifying me about my email account utilization.
This is a fake email address and the email is not coming from mlukfc.com.

Code:
Subject: Notify about your e-mail account utilization.

Dear user,  the management of Mlukfc.com  mailing  system wants to let you know  that,

Some of  our clients complained about the  spam (negative e-mail  content)
outgoing from  your e-mail account. Probably, you have been infected by
a  proxy-relay trojan server.  In order to keep your computer safe,
follow the  instructions.

For details see the  attached file.

Cheers,
   The Mlukfc.com  team                                  http://www.mlukfc.com
Part of the email header:

Code:
Received: from  tot-syd-aa01.proxy.aol.com (tot-syd-aa01.proxy.aol.com [202.67.64.151]) by rly-ip04.mx.aol.com (v95.1) with ESMTP id RELAYIN2-340451e33271; Tue, 02 Mar 2004 18:52:20 1900
Received: from toshiba-user ([202.67.122.27])
	by tot-syd-aa01.proxy.aol.com (8.12.10/8.12.10) with SMTP id i22Nm8JB019154
	for <webmaster@mlukfc.com>; Tue, 2 Mar 2004 23:48:10 GMT
This one was sent from a computer called "toshiba-user" in Australia.
Does that sound familiar to someone?
R. is offline   Reply With Quote
 

Page generated in 0.03155 seconds with 13 queries.