<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months in </title>
<link>http://www.dslreports.com/forum/r18165264</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 20:39:46 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 20:39:46 EDT</lastBuildDate>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18167003</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  AdamD <A HREF="/useremail/u/558484"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>We don't have a spam problem. We have a stupidity problem. Actually, stupidity epidemic... A dog or cat can be taught not to do something, yet there are people stupid enough to open those attachments.<br><br>A.<br> </DIV>I couldn't say it any better.  :D<br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18167003</guid>
<pubDate>Fri, 13 Apr 2007 19:33:41 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18166499</link>
<description><![CDATA[<A HREF="/useremail/u/558484"><b>AdamD</b></A> : We don't have a spam problem. We have a stupidity problem. Actually, stupidity epidemic... A dog or cat can be taught not to do something, yet there are people stupid enough to open those attachments.<br><br>A.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18166499</guid>
<pubDate>Fri, 13 Apr 2007 18:01:18 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18165444</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  kpatz <A HREF="/useremail/u/825971"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Some other things I've noticed:  every one has two Received: headers.  This makes it look like each email is being relayed through another SMTP server, but in my limited testing, the IP address that sent the spam didn't respond on port 25, so the second Received: is likely spoofed with a random IP.<br><br> </DIV>I am starting to notice that the IP number in the "X-Originating-IP" line doesn't respond to port 25, 137,139 or 443.<br><br>I am thinking the Trojan infected machine (66.8.213.116) is being used to send the junk email at a much higher port number.<br><br>canonical name cpe-66-8-213-116.hawaii.res.rr.com. <br>aliases  <br>addresses 66.8.213.116<br><br>----------<br>X-Apparently-To: sgtpepper_1967@yahoo.com via 216.252.121.75; Fri, 13 Apr 2007 00:48:54 -0700 <br><B>X-YahooFilteredBulk: 66.8.213.116 <br>X-Originating-IP: [66.8.213.116] </B><br>Return-Path:  <br>Authentication-Results: mta257.mail.re4.yahoo.com from=wsc.edu; domainkeys=neutral (no sig) <br>Received: from 66.8.213.116 (HELO cpe-66-8-213-116.hawaii.res.rr.com) (66.8.213.116) by mta257.mail.re4.yahoo.com with SMTP; Fri, 13 Apr 2007 00:48:52 -0700 <br><B>Received: from ijg ([149.104.110.89]) by cpe-66-8-213-116.hawaii.res.rr.com with Microsoft SMTPSVC(6.0.3790.0); </B>Thu, 12 Apr 2007 21:48:18 -1000 <br>Message-ID:  <br>Date: Thu, 12 Apr 2007 21:48:18 -1000 <br>From: "Postmaster"   <br><B>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) </B><br>MIME-Version: 1.0 <br>To: sgtpepper_1967@yahoo.com <br><B>Subject: Virus Detected! <B><br>----------<br> <br><br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165444</guid>
<pubDate>Fri, 13 Apr 2007 14:59:36 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18165372</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : They're using a botnet to distribute these, so chances are every copy you see will come from a different IP.<br><br>The Thunderbird header is likely hard-coded in the template used to construct the emails.<br><br>Some other things I've noticed:  every one has two Received: headers.  This makes it look like each email is being relayed through another SMTP server, but in my limited testing, the IP address that sent the spam didn't respond on port 25, so the second Received: is likely spoofed with a random IP.<br><br>The GIF files containing the message are formatted uniquely.  The name of the GIF varies, as well.  The width varies from one to next, causing the text to wrap/format differently across different samples.  Of course, the attachment name and password are always different, too.  The passwords seem to always be three letters, two numbers, so this is probably a fixed random password generator algorithm.<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165372</guid>
<pubDate>Fri, 13 Apr 2007 14:45:44 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18165264</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : <div class="bquote"><SMALL>said by  kpatz <A HREF="/useremail/u/825971"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Most recent one I got is:<br><br> <br>Seems like the headers are consistent, particularly the User-Agent header.  It's always that particular build of Thunderbird. ;)<br> </DIV>I noticed that particular point also regarding the Thunderbird build number. <br><br>I thought the junk email along with the Trojans where coming from a single zombie machine with the Thunderbird email software installed.<br><br>After looking at all the emails again, at three of the spams infected with the malware had different IP numbers associated with them, which leads me to believe that the information is forged.<br><br>X-Originating-IP: [189.169.127.165] <br>X-Originating-IP: [201.79.68.55] <br>X-Originating-IP: [162.39.116.180] <br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165264</guid>
<pubDate>Fri, 13 Apr 2007 14:23:33 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18165232</link>
<description><![CDATA[<A HREF="/useremail/u/1410407"><b>d0nni3q</b></A> : It's as simple as denying *.zip files for me. :-D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165232</guid>
<pubDate>Fri, 13 Apr 2007 14:17:31 EDT</pubDate>
</item>

<item>
<title>Re: largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18165167</link>
<description><![CDATA[<A HREF="/useremail/u/825971"><b>kpatz</b></A> : Most recent one I got is:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>From: "Support Team" &lt;***@cfl.rr.com&gt;<br>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207)<br>MIME-Version: 1.0<br>To: (my wifey's address)<br>Subject: Virus Detected! ***VIRUS DETECTED: (encrypted)***<br>X-Orig-Subject:Virus Detected!<br>Attachment: removal-66943.zip<HR></BLOCKQUOTE><br><br>My Linux firewall/email server box adds the ***VIRUS DETECTED*** message to the subj. line when it detects nasties.<br><br>Seems like the headers are consistent, particularly the User-Agent header.  It's always that particular build of Thunderbird. ;)<br><SMALL>--<br>Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18165167</guid>
<pubDate>Fri, 13 Apr 2007 14:03:15 EDT</pubDate>
</item>

<item>
<title>largest &#x22;spam blasts&#x22; in the past twelve months</title>
<link>http://www.dslreports.com/forum/remark,18164875</link>
<description><![CDATA[<A HREF="/useremail/u/1021645"><b>antiphishing</b></A> : From: "Postmaster"   <br>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) <br>MIME-Version: 1.0 <br>To: sgtpepper_1967@yahoo.com <br>Subject: Virus Detected! <br>File name: patch_92657.zip <br>File size: 38kb <br><br>From: "Support Team Robot"  <br>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) <br>MIME-Version: 1.0 <br>To: html_edit@yahoo.com <br>Subject: Virus Alert! <br>File name: bugfix_16471.zip <br>File size: 38kb <br><br>From: "Support Team"   <br>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) <br>MIME-Version: 1.0 <br>To: html_edit@yahoo.com <br>Subject: Virus Activity Detected! <br>File name: hotfix_25203.zip <br>File size: 38kb <br><br>From: "Customer Support Center"   <br>User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) <br>MIME-Version: 1.0 <br>To: html_edit@yahoo.com <br>Subject: Virus Detected! <br>File name: patch_1482.zip <br>File size: 38kb <br><SMALL>--<br><B><br>Specializing in "takes downs" of phishing and advance fee scams<br>Send your Phishing/Advance fee scams to: <A HREF="mailto:phish@antihotmail.com">phish@antihotmail.com</A> <br>&raquo;<A HREF="/profile/1021645">/profile/1021645</A><br></B></SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18164875?c=1151378&ret=L2ZvcnVtL3IxODE2NTI2NC54bWw%3D"><IMG TITLE="4735 bytes" BORDER=0 WIDTH=509 HEIGHT=290 SRC="/r0/download/1151378~866d050da37f3375f613296b17f7c6c2/Message.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18164875</guid>
<pubDate>Fri, 13 Apr 2007 13:04:49 EDT</pubDate>
</item>

</channel>
</rss>
