  antiphishing Phishing Scam Terminator Premium join:2004-06-09 Wilkes Barre, PA
1 edit | reply to kpatz Re: largest "spam blasts" in the past twelve months
said by kpatz :Some other things I've noticed: every one has two Received: headers. This makes it look like each email is being relayed through another SMTP server, but in my limited testing, the IP address that sent the spam didn't respond on port 25, so the second Received: is likely spoofed with a random IP. I am starting to notice that the IP number in the "X-Originating-IP" line doesn't respond to port 25, 137,139 or 443.
I am thinking the Trojan infected machine (66.8.213.116) is being used to send the junk email at a much higher port number.
canonical name cpe-66-8-213-116.hawaii.res.rr.com. aliases addresses 66.8.213.116
---------- X-Apparently-To: sgtpepper_1967@yahoo.com via 216.252.121.75; Fri, 13 Apr 2007 00:48:54 -0700 X-YahooFilteredBulk: 66.8.213.116 X-Originating-IP: [66.8.213.116] Return-Path: Authentication-Results: mta257.mail.re4.yahoo.com from=wsc.edu; domainkeys=neutral (no sig) Received: from 66.8.213.116 (HELO cpe-66-8-213-116.hawaii.res.rr.com) (66.8.213.116) by mta257.mail.re4.yahoo.com with SMTP; Fri, 13 Apr 2007 00:48:52 -0700 Received: from ijg ([149.104.110.89]) by cpe-66-8-213-116.hawaii.res.rr.com with Microsoft SMTPSVC(6.0.3790.0); Thu, 12 Apr 2007 21:48:18 -1000 Message-ID: Date: Thu, 12 Apr 2007 21:48:18 -1000 From: "Postmaster" User-Agent: Thunderbird 1.5.0.9 (Windows/20061207) MIME-Version: 1.0 To: sgtpepper_1967@yahoo.com Subject: Virus Detected! ----------
--
Specializing in "takes downs" of phishing and advance fee scams Send your Phishing/Advance fee scams to: phish@antihotmail.com »/profile/1021645
|
|
 AdamD
join:2002-01-09 Maspeth, NY | We don't have a spam problem. We have a stupidity problem. Actually, stupidity epidemic... A dog or cat can be taught not to do something, yet there are people stupid enough to open those attachments.
A. |
|
  antiphishing Phishing Scam Terminator Premium join:2004-06-09 Wilkes Barre, PA
| said by AdamD :We don't have a spam problem. We have a stupidity problem. Actually, stupidity epidemic... A dog or cat can be taught not to do something, yet there are people stupid enough to open those attachments. A. I couldn't say it any better.  --
Specializing in "takes downs" of phishing and advance fee scams Send your Phishing/Advance fee scams to: phish@antihotmail.com »/profile/1021645
|
|