Forum Home
PC World Chat
 
Thread ID: 58953 2005-06-17 04:38:00 Warning....Spammers target domains with viri personthingy (1670) PC World Chat
Post ID Timestamp Content User
364560 2005-06-17 04:38:00 Maybe this is old hat, but i haven't seen it before, and its allmost nasty enough to be personal......

Quote:
Dear Millerton Member,

Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.

If you choose to ignore our request, you leave us no choice but to cancel your membership.

Virtually yours,
The Millerton Support Team

Thre is an attachment, a zipped document containing
"annual report.doc (long space).pif I assume a .pif is something designed to attack a windows computer?

I've started getting a lot of them, presumably as a result of some robot discovering www.millerton.co.nz, although i did get the first wave of viral emails just after i banned someone from an E-group i modererate. There may be a connection, there may not.

These are being sent to random-names@millerton.co.nz The particular one i quoted was sent to "paul"

Now, apart from 3 others with specific addresses, all "millerton.co.nz" mail goes to me, and i own the domain. I therfore am resonably sure its fake :p , but i can see how some noob getting such an email might be fooled and "view" the "document".

I'm interested to hear if anyone else has got such "personalised" viral spam.
personthingy (1670)
364561 2005-06-17 05:19:00 I think "annual report.doc (long space).pif" is the attachment that holds the virus.
A pif is a MS shortcut file (or an old picture file) I have seen viruses with virus.exe.pif so that it gets past the scanners.
netchicken (4843)
364562 2005-06-17 05:27:00 Same *****, different "personal" message......

Dear user debby,

You have successfully updated the password of your Millerton account.

If you did not authorize this change or if you need assistance with your account, please contact Millerton customer service at: mail@millerton.co.nz

Thank you for using Millerton!
The Millerton Support Team

Funny, i don't remember "james" "david" "debbie" or "paul" in my staff, close friends, or family ;)
personthingy (1670)
364563 2005-06-17 06:22:00 A further twist... they appear to be coming from someone using an Auckland ISP, KC Internetworks. 202.27.212.78 belongs to them, although the headers say its from me (mail.millerton.co.nz)!

Return-Path: <mail@millerton.co.nz>
Received: from millerton.co.nz ([202.27.212.78])
by drs.registerdirect.net.nz (8.11.6p2-20030920/8.11.0) with ESMTP id j5H1QRX61753
for <david@millerton.co.nz>; Fri, 17 Jun 2005 13:26:27 +1200 (NZST)
(envelope-from mail@millerton.co.nz)

I have nothing to do with KC internetworks, nor do registerdirect, the people who hold the email associated with my domain.
personthingy (1670)
364564 2005-06-17 08:46:00 I'm getting two or three versions of the same scam myself.

Mailwasher does the honours. :thumbs:

Cheers

Billy 8-{)
Billy T (70)
364565 2005-06-17 10:46:00 I'm getting two or three versions of the same scam myself .

Mailwasher does the honours . :thumbs:

Cheers

Billy 8-{)Are they coming from the same ISP in AK?
What IP do they appear to originate from?

Does mailwasher send the spam back to the apparent sender still?
If so it would send it directly back to the return address, which is a fake millerton . co . nz address, so MW would send it strait back to me again and again in an endless loop . . . . . . . . . . . .
Hmmm, that's nasty . . . . . . . .

I've had 4 since i last logged out, about an hour ago .
Zip file and recipiant name varies . . .
And look . . . "Millerton . co . nz" (ha) claims to have a virus checker checking its mail now, so we KNOW the attachment is safe :p :lol: :lol:

latest versions:
---------------------------------------------------------------------
Dear user enquiries,

It has come to our attention that your Millerton User Profile ( x ) records are out of date . For further details see the attached document .

Thank you for using Millerton!
The Millerton Support Team






+++ Attachment: No Virus (Clean)
+++ Millerton Antivirus - www . millerton . co . nz
scn . zip
---------------------------------------------------------------------------------
Dear user debby,

You have successfully updated the password of your Millerton account .

If you did not authorize this change or if you need assistance with your account, please contact Millerton customer service at: mail@millerton . co . nz

Thank you for using Millerton!
The Millerton Support Team






+++ Attachment: No Virus (Clean)
+++ Millerton Antivirus - www . millerton . co . nz
account-password . zip
------------------------------------------------------------------------------------------------
personthingy (1670)
364566 2005-06-17 10:58:00 What is wrong with you people.
Just ignore and delete them.

This a phishing e-mail doing the rounds at the moment.
A phishing e-mail is one that appears to be a legitimate e-mail coming from what looks like a legitimate source asking you for private information such as your username and password or to click on a link to validate your e-mail address.
The messages are coming from virus infected computers with the latest MyTob virus.
Safari (3993)
364567 2005-06-17 12:12:00 What is wrong with you people.
Just ignore and delete them.

This a phishing e-mail doing the rounds at the moment.
A phishing e-mail is one that appears to be a legitimate e-mail coming from what looks like a legitimate source asking you for private information such as your username and password or to click on a link to validate your e-mail address.
The messages are coming from virus infected computers with the latest MyTob virus.A virus designed to attack a windows system aint going to do any damage to my linux system, and by posting it hereWE HELP PEOPLE KNOW WHAT NOT TO OPEN Anyway, what has this got to do with phishing? This is designed to get the recipiant to open the virus and infect thier system, not ask me my credit card number, or bank details!

As for whats wrong with me..... PM me and i'll tell ya! :p
personthingy (1670)
364568 2005-06-17 23:46:00 A virus designed to attack a windows system aint going to do any damage to my linux system, and by posting it hereWE HELP PEOPLE KNOW WHAT NOT TO OPEN

Agreed. :thumbs: Many already know about the danger of opening a .pif attachment, but surely others reading PF1 will not, or are in need of reminding to be vigilant.
Strommer (42)
364569 2005-06-18 00:11:00 Agreed. :thumbs: Many already know about the danger of opening a .pif attachment, but surely others reading PF1 will not, or are in need of reminding to be vigilant.This might be true, but do we really need a thread for every virus going round?

The skeleton of this virus has been around in similar formats for a couple of years now. It's not exactly breaking news.

I get much more interesting virii sent to me than this every few hours, people would soon get sick of threads about it.

Never mind the fact that the whole title of the thread is also wrong. This is not "spammers" targeting domains, it's a self propagating virus sending itself off an infected host, to people whose e-mail addresses are on the infected machine. It just tailors the e-mail a little. It isn't unsolicited commercial e-mail or spam at all.
ninja (1671)
1 2