Bluehost.com Web Hosting $6.95

OT: Heads up for Viktor

This is a discussion on OT: Heads up for Viktor within the mailing.postfix.users forums, part of the Mail Servers and Related category; --Signature=_Fri__8_Oct_2004_07_16_28_-0700_l3Us+6UPJG4rtS+j Content-Type: text/plain; charset=US-ASCII Content-Disposition: inline Content-Transfer-Encoding: 7bit If ...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-08-2004
Robin Lynn Frank
 
Posts: n/a
Default OT: Heads up for Viktor

--Signature=_Fri__8_Oct_2004_07_16_28_-0700_l3Us+6UPJG4rtS+j
Content-Type: text/plain; charset=US-ASCII
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

If you aren't already aware, your email address is being spoofed
(although badly munged) by virus-generated mail.


From: "Content-filter at omega.paradigm-omega.net"
<virusalert@paradigm-omega.net> To: <virusalert@paradigm-omega.net>
Subject: VIRUS (Worm.Gibe.F) FROM
<?@dial81-131-248-41.in-addr.btopenworld.com> Date: Fri, 8 Oct 2004
06:51:18 -0700 (PDT)

A virus was found: Worm.Gibe.F

A banned name was found:
P=p005,M=application/x-msdownload,T=exe,T=exe-ms,N=UPDATE25.exe

Scanner detecting a virus: ClamAV-clamd

The mail originated from: <?@dial81-131-248-41.in-addr.btopenworld.com>
According to the 'Received:' trace, the message originated at:
[81.131.248.41]
unknown (HELO yxlwmpr)
(victor.duchovni@morganstanley.co@81.131.248.41 with poptime)

Notification to sender will not be mailed.

The message WAS NOT delivered to:
<rlfrank@paradigm-omega.com>:
250 2.7.1 Ok, discarded, id=14872-01-32 - VIRUS: Worm.Gibe.F

Virus scanner output:
p005: Worm.Gibe.F FOUND

The message has been quarantined as:
/var/spool/amavis/virusmails/virus-20041008-065118-14872-01-32

------------------------- BEGIN HEADERS -----------------------------
Return-Path: <bpriestley@btinternet.com>
Received: from smtp804.mail.ukl.yahoo.com (smtp804.mail.ukl.yahoo.com
[217.12.12.141]) by omega.paradigm-omega.net (Postfix) with SMTP id
569CB7AD38 for <rlfrank@paradigm-omega.com>; Fri, 8 Oct 2004 06:50:16
-0700 (PDT) Received: from unknown (HELO yxlwmpr)
(victor.duchovni@morganstanley.co@81.131.248.41 with poptime) by
smtp804.mail.ukl.yahoo.com with SMTP; 8 Oct 2004 11:52:09 -0000 From:
"Microsoft Security Center" <iyogwbowdiv@bulletin.com> To: "Client"
<client@bulletin.com> SUBJECT: Newest Microsoft Critical Pack
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="dxuaonykepvqjok"
Message-Id: <20041008135016.569CB7AD38@omega.paradigm-omega.net>
Date: Fri, 8 Oct 2004 06:50:16 -0700 (PDT)
-------------------------- END HEADERS ------------------------------


--
Robin Lynn Frank
Director of Operations
Paradigm-Omega, LLC
http://www.paradigm-omega.com
==============================
Sed quis custodiet ipsos custodes?

--Signature=_Fri__8_Oct_2004_07_16_28_-0700_l3Us+6UPJG4rtS+j
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQFBZqFFo0pgX8xyW4YRA9ppAJ99UGgxqPD4I+q7/Ph7+WovfeJAIwCgnGrI
ZBO9jiZzGEqT5GiVCrT024I=
=nHHx
-----END PGP SIGNATURE-----

--Signature=_Fri__8_Oct_2004_07_16_28_-0700_l3Us+6UPJG4rtS+j--
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 11:07 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0