iplural

Hey I don't know why but I keep on getting emails from you, all with viruses. Apperently the source of all those emails is from hc_studio.com via delta.pxnetwork.com.

(helo=hc_studio.com)
by delta.pxnetwork.com with smtp (Exim 4.24)
2,958 views 16 replies
Reply #1 Top
I haven't seen iplural around the message board for a little while.
Reply #2 Top
Rolf, It's not Iplural...It's just the latest virii going round >
Reply #3 Top
#68 by IPlural - 5/9/2004 11:20:49 AM Sheesh, It was the Chili, so excuse me already.IPlural turns back to spraying Flower Scented Lysol around office.



....IP lives........
Reply #4 Top
Yeah I was pretty sure its that, chinacat.

It's suddenly much more common to see virus warnings nowdays, normally I never see those ever.
Reply #5 Top
now that would be a tirck considering we've never conversed via email

I'll check with the server and see whats happening on that end, though it is probably my hosting service was raped by a spyder...

If I can put a stop to it I will.

The other odd thing is that I do not email anyone from that account except three people and they haven't had any problems.


btw: I don't get WORM's or Virus problems, least of all attacking my address book...






Powered by SkinBrowser!
Reply #6 Top
Date: Sun, 09 May 2004 10:36:03 +0100
From: Rolf
To: Iplural
Subject: RE: Message Notify
Part(s): 1 unnamed text/html 0.10 KB
2 acueygeyzb.gif image/gif 1.38 KB
3 You_are_dismissed.zip application/octet-stream 29.59 KB

-

Rolf did you send this to me at 10:36 this morning?



Powered by SkinBrowser!
Reply #7 Top
Subject: RE: Message Notify < that is the common MSN-Messenger email alert if I am thinking correctly...



Powered by SkinBrowser!
Reply #8 Top
Hmm no. Last email I sent were 3 days ago.

*edit*
Received: from [80.55.235.222] (helo=hc_studio.net)
by delta.pxnetwork.com with smtp (Exim 4.24)

That is same for all the returned emails. I think that server got borked. Either 2 servers anyway.
[Message Edited]
Reply #9 Top
ack, yeah, has me wondering if a spyder hasn't picked up the emails on the site for a spam list.

going to change mine to something different and see what happens over the next month.
Reply #10 Top
Return-path: Rolf-at-removedfor sanities sake.net
Envelope-to: iplural-a-wackybobo.com
Delivery-date: Sun, 09 May 2004 03:35:40 -0500
Received: from 80.55.235.222 helo=hc_studio.org
by delta.pxnetwork.com with smtp Exim 4.24
id 1BMjmY-0001gH-9
for iplural-at-wackybobo.com Sun, 09 May 2004 03:35:34 -0500
Date: Sun, 09 May 2004 10:36:03 +0100
To: "Iplural" iplural-at-wackybobo.com
From: "Rolf" Rolf-at-removed again.net
Subject: RE: Message Notify
Message-ID: wkmsdzvzrlfpyukoewn-at-wackybobo.com
MIME-Version: 1.0
Content-Type: multipart/mixed
boundary="ijjedlowkhxpohummqpf"
Status: O
X-Status:
X-Keywords:
X-UID: 5
X-NAS-Bayes: #0: 0.79379 #1: 0.20621
X-NAS-Classification: 0
X-NAS-MessageID: 340
X-NAS-Validation: 48BC27F7-EED9-47F1-9E6F-D07D1504CB75
-

changing email upon posting this to see what takes place over time with such spam crap...


I am betting it is a Site Spider data-mining email addresses to build dbf''''s for spambots.

[Message Edited]
[Message Edited]
Reply #11 Top
Odd. delta.pxnetwork.com is some Cpanel thingy site, and hc_studio.org is nonexistant, but IP address points to an another site.
Reply #12 Top
Hi guys, I received an e-mail apparently from webgizmos, with whom I have never before corresponded, and caught some similar information in the header. Thought I would post it here in case you are interested.

X-Apparently-To: shamelessdesigns @yahoo.com via 216.136.232.73 Sun, 09 May 2004 01:40:12 -0700
Return-Path: webgizmos @msn.com
Received: from 80.55.235.222 (HELO hcstudio.net) (80.55.235.222) by mta115.mail.scd.yahoo.com with SMTP Sun, 09 May 2004 01:39:56 -0700
Date: Sun, 09 May 2004 10:40:28 +0100
To: "Shamelessdesigns"
From: "Webgizmos" Add to Address Book
Subject: Forum notify
Message-ID: pkdtnowhwcjvdkydnyd @yahoo.com
MIME-Version: 1.0
Content-Type: multipart/mixed boundary="opkkmpokxgjjzluoufpa"
Content-Length: 24256


The message contained two attachments, both containing virii. Since both webgizmos and I have these email addresses posted in our profiles here, it appears to me that some type of spyder is crawling the site looking for addresses.

BTW, webgizmos, if you read this, I have no doubt that you did not send the email to me.


[Message Edited]
[Message Edited]
Reply #13 Top
I think the WC emails did get spidered. I got one legit email at design HatH joe doug * com but over 100 spam a day. It really sucks.
Reply #15 Top
mmm, I'll go ahead and keep the email addy active and run email-tracker to the source and visual route on the source, the info compiled could be used to go against those doing it and tracking them down possibly...
Reply #16 Top
I forwarded the email I received to Security @ yahoo for them to trace, though I don't really expect to ever hear from them again. That would be my idea of one of the ultimate thankless jobs. All they ever get are complaints and rarely if ever any recognition or gratitude.