Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
Thumbs down EMail Virus attempt? Who wants to play detective?

I just received this Email. Sure as hell looks like an attempt to coax me into downloading some crap. What do you think?


Header first followed by body of message:

X-Apparently-To: xxxx@yahoo.com via 206.190.37.243; Thu, 15 Sep 2005 18:11:48 -0700
X-Originating-IP: [165.254.68.66]
Return-Path:
Authentication-Results: mta100.mail.re2.yahoo.com from=yahoo.com; domainkeys=neutral (no sig)
Received: from 165.254.68.66 (EHLO yahoo.com) (165.254.68.66) by mta100.mail.re2.yahoo.com with SMTP; Thu, 15 Sep 2005 18:11:48 -0700
From: Send an Instant Message admin@yahoo.com Add to Address BookAdd to Address Book
To: xxxx@yahoo.com
Subject: xjdvh
Date: Thu, 15 Sep 2005 21:11:44 -0400
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0001_5827C8E1.1DAF1A4E"
X-Priority: 3
X-MSMail-Priority: Normal
Content-Length: 33611

Dear Yahoo Member,

Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.

If you choose to ignore our request, you leave us no choice but to cancel your membership.

Virtually yours,
The Yahoo Support Team

__________________
Warren & Ron, may you rest in Peace.

Last edited by RickM; 09-15-2005 at 05:49 PM..
Old 09-15-2005, 05:35 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
Registered
 
bryanthompson's Avatar
 
Join Date: May 2003
Posts: 5,058
Garage
Send a message via ICQ to bryanthompson
definitely virus attempt, without a doubt.

Been used on other hosts as well: http://www.logic.bm/pop_announcement.html
__________________
1983 944 - Sable Brown Metallic / Saratoga / LSD : IceShark Light Kit
Old 09-15-2005, 05:41 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Registered
 
bryanthompson's Avatar
 
Join Date: May 2003
Posts: 5,058
Garage
Send a message via ICQ to bryanthompson
more info: http://nl.trendmicro-europe.com/enterprise/vinfo/encyclopedia.php?VName=WORM_MYTOB.HF
__________________
1983 944 - Sable Brown Metallic / Saratoga / LSD : IceShark Light Kit
Old 09-15-2005, 05:42 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
Wow, that was quick Bryan. I can usually spot a fake when I pass the cursor over the return addresses and read the true destination on the botton address bar (Or right click for properties). This looks legit when I do this.

BTW, after spending about 10 minutes on the Yahoo site I can't locate a secuity section to report hsi type of stuff.

Thanks!
__________________
Warren & Ron, may you rest in Peace.
Old 09-15-2005, 05:48 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Senior Member
 
Join Date: Jun 2000
Location: N. Phoenix AZ USA
Posts: 28,943
Quote:
Originally posted by RickM
Wow, that was quick Bryan. I can usually spot a fake when I pass the cursor over the return addresses and read the true destination on the botton address bar (Or right click for properties). This looks legit when I do this.

BTW, after spending about 10 minutes on the Yahoo site I can't locate a secuity section to report hsi type of stuff.

Thanks!
You have learned the fastest way to figure these out! Passing the cursor over the address shows where its really going and if the two are not the same, something is smelly.

Wish we could find these ba$tards and put them on desert island somewhere with no internet...

JoeA
__________________
2013 Jag XF, 2002 Dodge Ram 2500 Cummins (the workhorse), 1992 Jaguar XJ S-3 V-12 VDP (one of only 100 examples made), 1969 Jaguar XJ (been in the family since new), 1985 911 Targa backdated to 1973 RS specs with a 3.6 shoehorned in the back, 1959 Austin Healey Sprite (former SCCA H-Prod), 1995 BMW R1100RSL, 1971 & '72 BMW R75/5 "Toaster," Ural Tourist w/sidecar, 1949 Aeronca Sedan / QB
Old 09-15-2005, 05:59 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
bryanthompson's Avatar
 
Join Date: May 2003
Posts: 5,058
Garage
Send a message via ICQ to bryanthompson
Quote:
Originally posted by RickM
Wow, that was quick Bryan. I can usually spot a fake when I pass the cursor over the return addresses and read the true destination on the botton address bar (Or right click for properties). This looks legit when I do this.

BTW, after spending about 10 minutes on the Yahoo site I can't locate a secuity section to report hsi type of stuff.

Thanks!
It looked juuuuust well-written enough to pass for legit. If those Nigerians find a grammar checker, we're all screwed
__________________
1983 944 - Sable Brown Metallic / Saratoga / LSD : IceShark Light Kit
Old 09-15-2005, 06:13 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
Moderator
 
Z-man's Avatar
 
Join Date: Feb 2001
Location: NJ, USA
Posts: 9,628
Garage
I was just sent an email stating that my Paypal account may have an unauthorized credit card attached to it.

Funny, I don't have a Paypal account, nor do I have any unauthorized cc.

I just hate these hackers...the interweb's an unsafe place...
-Z.
__________________
2010 Cayman S - 12-2020 -
2014 MINI Cooper S Coupe - 05-17 - 05-21
1989 944S2 - 06-01 - 01-14
Carpe Viam.
<><
Old 09-15-2005, 07:31 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
pwd72s's Avatar
 
Join Date: Apr 2001
Location: Linn County, Oregon
Posts: 48,517
I've gotten some addressed to my last name from my last name...no message, just an attachment. I just dump 'em. Anybody else have that happen to them?
__________________
"Now, to put a water-cooled engine in the rear and to have a radiator in the front, that's not very intelligent."
-Ferry Porsche (PANO, Oct. '73) (I, Paul D. have loved this quote since 1973. It will remain as long as I post here.)
Old 09-16-2005, 06:43 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Registered
 
Steeve's Avatar
 
Join Date: Jul 2004
Location: Houston, TX
Posts: 426
z-man I got the exact same email the other day. I figured it was a scam, and deleted it. Then went and logged into Paypal, and all was rosy.
__________________
'86 911 targa
'04 MB 230K Sport (daily)
Old 09-16-2005, 06:43 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
Well, this morn I reicieved the other two versions of the email. Now I have the complete set.

__________________
Warren & Ron, may you rest in Peace.
Old 09-16-2005, 06:48 AM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Reply


 


All times are GMT -8. The time now is 12:20 AM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.