Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Interesting email thread with passworded zip file

 
Thread Tools Search this Thread
Old 03-03-2004, 05:02 AM   #1
Default Interesting email thread with passworded zip file


Tonight I was pulling email from the account I list in my sig (it's a
disposable account) and got two email's telling me that my email account
had been deactivated and that the details where in an attached Zip file.
One thing to note, the account still works fine. Both Zip files were
different names, but were sent from the same email server.

I called RR and they know nothing about it, I warned them and sent the
file to so they could be on the lookout for it too.

Now, I'm not anywhere stupid enough to open a passworded Zip file, and
not stupid enough to fall for this childish crap, but I thought I would
post this out there in case anyone else gets something like this:

Return-Path: <>
Received: from mx3.biz.rr.com ([192.168.201.29]) by fep05.biz.rr.com
(InterMail vM.5.01.03.06 201-253-122-118-106-20010523) with
ESMTP
id <. rr.com>
for <>; Tue, 2 Mar 2004 23:41:06 -0500
Received: from Hours (hours.micro.uiuc.edu [128.174.97.18])
by mx3.biz.rr.com (8.12.10/8.12.10) with SMTP id i234f5U4002896
for <>; Tue, 2 Mar 2004 23:41:05 -0500 (EST)
Date: Tue, 02 Mar 2004 22:42:21 -0600
To:
Subject: E-mail account security warning.
From:
Message-ID: <>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------xxlqmnigdawgslfadase"

Dear user of Rrohio.com gateway e-mail server,

Your e-mail account has been temporary disabled because of
unauthorized access.

Please, read the attach for further details.

Attached file protected with the password for security reasons.
Password is 01747.

Kind regards,
The Rrohio.com team
http://www.rrohio.com


--
--

(Remove 999 to reply to me)


Leythos
  Reply With Quote
Old 03-03-2004, 05:17 AM   #2
kulm_nd
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
My ISP has already posted warnings, a virus/trojan for sure.

--

************************************************

g-w


"Leythos" <> wrote in message
news:...
> Tonight I was pulling email from the account I list in my sig (it's a
> disposable account) and got two email's telling me that my email account
> had been deactivated and that the details where in an attached Zip file.
> One thing to note, the account still works fine. Both Zip files were
> different names, but were sent from the same email server.
>
> I called RR and they know nothing about it, I warned them and sent the
> file to so they could be on the lookout for it too.
>
> Now, I'm not anywhere stupid enough to open a passworded Zip file, and
> not stupid enough to fall for this childish crap, but I thought I would
> post this out there in case anyone else gets something like this:
>
> Return-Path: <>
> Received: from mx3.biz.rr.com ([192.168.201.29]) by fep05.biz.rr.com
> (InterMail vM.5.01.03.06 201-253-122-118-106-20010523) with
> ESMTP
> id <. rr.com>
> for <>; Tue, 2 Mar 2004 23:41:06 -0500
> Received: from Hours (hours.micro.uiuc.edu [128.174.97.18])
> by mx3.biz.rr.com (8.12.10/8.12.10) with SMTP id i234f5U4002896
> for <>; Tue, 2 Mar 2004 23:41:05 -0500 (EST)
> Date: Tue, 02 Mar 2004 22:42:21 -0600
> To:
> Subject: E-mail account security warning.
> From:
> Message-ID: <>
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
> boundary="--------xxlqmnigdawgslfadase"
>
> Dear user of Rrohio.com gateway e-mail server,
>
> Your e-mail account has been temporary disabled because of
> unauthorized access.
>
> Please, read the attach for further details.
>
> Attached file protected with the password for security reasons.
> Password is 01747.
>
> Kind regards,
> The Rrohio.com team
> http://www.rrohio.com
>
>
> --
> --
>
> (Remove 999 to reply to me)





kulm_nd
  Reply With Quote
Old 03-03-2004, 05:52 AM   #3
Never anonymous Bud
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
While still snuggled in a 'spider hole', Leythos <> scribbled:

>Tonight I was pulling email from the account I list in my sig (it's a
>disposable account) and got two email's telling me that my email account
>had been deactivated and that the details where in an attached Zip file.
>One thing to note, the account still works fine. Both Zip files were
>different names, but were sent from the same email server.


Those zip files contain a virus. Just delete them.






To reply by email, remove the XYZ.

Lumber Cartel (tinlc) #2063. Spam this account at your own risk.

This sig censored by the Office of Home and Land Insecurity....


Never anonymous Bud
  Reply With Quote
Old 03-03-2004, 05:53 AM   #4
Micheal Robert Zium
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
Leythos wrote:

>I called RR and they know nothing about it, I warned them and sent the
>file to so they could be on the lookout for it too.


You may want to give the University of Illinois a heads-up as well.
I'm sure their IT staff would be interested to know that one of their
computers is potentially spreading malware.



Micheal Robert Zium
  Reply With Quote
Old 03-03-2004, 12:24 PM   #5
Leythos
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
In article <>, mrozium@XSPAMX-
yahoo.com says...
> Leythos wrote:
>
> >I called RR and they know nothing about it, I warned them and sent the
> >file to so they could be on the lookout for it too.

>
> You may want to give the University of Illinois a heads-up as well.
> I'm sure their IT staff would be interested to know that one of their
> computers is potentially spreading malware.


I sent it to last night with full headers and the actual
email's.

--
--

(Remove 999 to reply to me)


Leythos
  Reply With Quote
Old 03-03-2004, 03:04 PM   #6
Jon Sturgeon
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
On Wed, 03 Mar 2004 05:02:12 GMT, Leythos <> wrote:

>Tonight I was pulling email from the account I list in my sig (it's a
>disposable account) and got two email's telling me that my email account
>had been deactivated and that the details where in an attached Zip file.
>One thing to note, the account still works fine. Both Zip files were
>different names, but were sent from the same email server.


Most likely W32/Bagle.j@MM - more info at:
http://vil.nai.com/vil/content/v_101071.htm

>I called RR and they know nothing about it,


No surprise there then

Jon


Jon Sturgeon
  Reply With Quote
Old 03-04-2004, 12:32 AM   #7
ShadowDragon
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
"Jon Sturgeon" <> wrote in message
news:...
> On Wed, 03 Mar 2004 05:02:12 GMT, Leythos <> wrote:
>
> Most likely W32/Bagle.j@MM - more info at:
> http://vil.nai.com/vil/content/v_101071.htm


Actually it's probably K. I got three of those myself today.




ShadowDragon
  Reply With Quote
Old 03-05-2004, 04:52 AM   #8
Anthony Brant
 
Posts: n/a
Default Re: Interesting email thread with passworded zip file
I've gotten tons of these, but it was quite obvious that it wasn't real. I
own several domain names, and I kept getting "Dear user of <domain> gateway
e-mail server" and messages signed as "The <domain> team"

I'm sure a shitload of people are falling for or freaking out about it
though.

"Leythos" <> wrote in message
news:...
> Tonight I was pulling email from the account I list in my sig (it's a
> disposable account) and got two email's telling me that my email account
> had been deactivated and that the details where in an attached Zip file.
> One thing to note, the account still works fine. Both Zip files were
> different names, but were sent from the same email server.
>
> I called RR and they know nothing about it, I warned them and sent the
> file to so they could be on the lookout for it too.
>
> Now, I'm not anywhere stupid enough to open a passworded Zip file, and
> not stupid enough to fall for this childish crap, but I thought I would
> post this out there in case anyone else gets something like this:
>
> Return-Path: <>
> Received: from mx3.biz.rr.com ([192.168.201.29]) by fep05.biz.rr.com
> (InterMail vM.5.01.03.06 201-253-122-118-106-20010523) with
> ESMTP
> id <. rr.com>
> for <>; Tue, 2 Mar 2004 23:41:06 -0500
> Received: from Hours (hours.micro.uiuc.edu [128.174.97.18])
> by mx3.biz.rr.com (8.12.10/8.12.10) with SMTP id i234f5U4002896
> for <>; Tue, 2 Mar 2004 23:41:05 -0500 (EST)
> Date: Tue, 02 Mar 2004 22:42:21 -0600
> To:
> Subject: E-mail account security warning.
> From:
> Message-ID: <>
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
> boundary="--------xxlqmnigdawgslfadase"
>
> Dear user of Rrohio.com gateway e-mail server,
>
> Your e-mail account has been temporary disabled because of
> unauthorized access.
>
> Please, read the attach for further details.
>
> Attached file protected with the password for security reasons.
> Password is 01747.
>
> Kind regards,
> The Rrohio.com team
> http://www.rrohio.com
>
>
> --
> --
>
> (Remove 999 to reply to me)





Anthony Brant
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
I have become rich in 30 days lemony-snicket A+ Certification 2 09-07-2009 03:01 PM
How to turn $6 to $16000 in few days of web crawling please@dontreply.net DVD Video 0 02-02-2007 07:25 AM
This is incredible! jc_ice DVD Video 1 08-13-2006 10:47 AM
Re: Ripping DVDs. Please answer the attached question. - Question.txt Stan Brown DVD Video 19 02-09-2005 11:19 PM
Burn process failed - help! Log file posted for help troubleshooting Michael Mason DVD Video 1 08-16-2004 09:24 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46