PDA

View Full Version : suspect e-mail



Vic 970
12-09-2002, 02:27 PM
just rec this...,

X-From_: issy@laneham.fsnet.co.uk Mon Dec 09 10:27:39 2002
Return-path: <issy@laneham.fsnet.co.uk>
Envelope-to: me@????.??????.co.uk
Delivery-date: Mon, 09 Dec 2002 10:27:39 +0000
Received: from [128.242.207.107] (helo=linux1587.dn.net)
by imailm1.svr.pol.co.uk with esmtp (Exim 3.35 #1)
id 18LL8U-0007tN-00
for me@????>.??????.co.uk; Mon, 09 Dec 2002 10:27:38 +0000
Received: from [195.92.195.171] (helo=cmailg1.svr.pol.co.uk)
by linux1587.dn.net with esmtp (Exim 3.22 #2)
id 18LKgp-0008Vb-00; Mon, 09 Dec 2002 04:59:03 -0500
Received: from modem-224.llama.dialup.pol.co.uk ([217.135.176.224] helo=p****ie)
by cmailg1.svr.pol.co.uk with smtp (Exim 3.35 #1)
id 18LKsA-0000Vn-00; Mon, 09 Dec 2002 10:10:48 +0000
From: "Microsoft Corporation Security Center" <rdquest12@microsoft.com>
To: "Microsoft Customer" <'customer@yourdomain.com'>
Subject: Internet Security Update
Reply-To: <rdquest12@microsoft.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="NextPart_000235"
--------------------------------------
This is a multi-part message in MIME format.You should read this with client which supported MIME standard.

Budfred
12-09-2002, 03:03 PM
I'm pretty sure this is a hoax and possibly malware. MS doesn't send out email alerts, but there have been some scams that do.

Budfred

YODA74
12-09-2002, 03:04 PM
get rid of that one if it were from an honest or it was legit it wouldn't have this in it


helo=p****ie)

not sure what your asking but if you have gotten rid of it great

mjc needs to do some editing on this one I think :D

Vic 970
12-09-2002, 04:16 PM
checked it in mailwasher, mailwasher hadn't marked it as spam or virus or anything I just did'nt like the look of it.
I'll blacklist it & delete,

Budfred
12-09-2002, 09:34 PM
I get a fair number of things that are clearly SPAM or other junk that MailWasher doesn't catch. I think you can update their blacklists, but I just add them myself as they come in. I don't rely on MailWasher for that purpose.

Budfred

mjc
12-09-2002, 10:59 PM
Before I edit......I have seen that one before and it is viral in nature, badtrans (not quite sure on that but that is the one that comes to mind). Get rid of it and scan for infestation.....

Vic 970
12-10-2002, 04:44 PM
thanks all

mjc. I didn't actually d/l it, I became suspicious whilst it was in mail washer and left it there whilst I posted, after recieving the above answers I blacklisted it & deleted it. I have however just done a/v on pitstop just in case. ( I can't seem to get housecall to work any more, even with internet settings on low.)

Just goes to show, no matter how many progs we use to protect the system we still have to be veeeeery cautious.

deddard
12-10-2002, 05:55 PM
Anything like this - kill it stone dead. Microsoft may be stupid sometimes, but they don't send mail like this.
If I have the slightest suspicion about an email, it either gets deleted instantly or quarantined in Norton.

Vic 970
12-11-2002, 01:38 PM
yup. just got one that mailwasher highlighted as a virus. the other one I was curious about just to see what might be creeping through. whether it was a virus or just a hoax or spam.