Koozali.org: home of the SME Server

contribs.org -> you have virus or other sending in your n

cyberdude

contribs.org -> you have virus or other sending in your n
« on: January 27, 2004, 08:05:01 PM »
Hi!

I have got a virus e-mail from staff@contribs.org

Here are the messag source :

Return-Path: <staff@contribs.org>
Delivered-To: sonny@ddpnet.dk
Received: (qmail 12796 invoked from network); 27 Jan 2004 09:24:39 -0000
Received: from fupa.post.tele.dk (HELO fupA.post.tele.dk) (195.41.53.68)
  by mug.spnet.dk (192.x.x.x) with ESMTP; 27 Jan 2004 09:24:39 -0000
Received: from coleman.net (unknown [69.9.12.20])
   by fupA.post.tele.dk (Postfix) with SMTP id 79FC9BE16
   for <sonny@ddpnet.dk>; Tue, 27 Jan 2004 10:24:37 +0100 (CET)
Received: (qmail 11140 invoked from network); 27 Jan 2004 09:24:16 -0000
Received: from pc-00025.coleman.net (HELO contribs.org) (10.1.1.25)
  by dev.coleman.net (10.1.1.1) with ESMTP; 27 Jan 2004 09:24:16 -0000
From: staff@contribs.org
To: sonny@ddpnet.dk
Subject: hi
Date: Tue, 27 Jan 2004 02:24:18 -0700
MIME-Version: 1.0
Content-Type: multipart/mixed;
   boundary="----=_NextPart_000_0007_02795497.D6C0D72C"
X-Priority: 3
X-MSMail-Priority: Normal
X-Spam-Status: No, hits=1.7 required=5.0
   tests=MISSING_MIMEOLE,NO_REAL_NAME,PRIORITY_NO_NAME
   version=2.53
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 2.53 (1.174.2.15-2003-03-30-exp)
Message-Id: <20040127092437.79FC9BE16@fupA.post.tele.dk>


--- end of messag source ---

it has an attached file named "file.zip"
it contains the virus "MyDoom"

I did never open the file, and did not get infected!

RavenIV

contribs.org -> you have virus or other sending in your n
« Reply #1 on: January 28, 2004, 12:13:07 AM »
this mail is a fake.
it does not come from staff@contribs.org .
somebody (maybe the virus) has stolen the email-adress.

same happened to my private email-adress.
i got a reply-message that i sent a mail to xyz@domain.hu. the mail was sent at 07.10.
on my mailserver there is no entry in the logs for that time. so the mail was not sent via my mailserver.

cheers klaus