store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 11:44 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: Spammer on my server???
Unread postPosted: Tue May 06, 2008 2:23 am 
Hi guys.
I got a message from "The Planet" today.. but not sure whate to do or where to look...
They told me that they had recieved a complaint about spam comming from my server and attached a txt file to the ticket. That had the following in it:
--------------------------------------------------------------------------
Received: from aus.worldofhosting.com ([70.84.168.26])

by vms172071.mailsrvcs.net

(Sun Java System Messaging Server 6.2-6.01 (built Apr 3 2006))

with ESMTP id <0K0F00LBH63YXSW0@vms172071.mailsrvcs.net> for midilaw@gte.net;

Mon, 05 May 2008 18:47:58 -0500 (CDT)

Received: (qmail 21143 invoked by uid 48); Tue, 06 May 2008 06:29:31 +1000

Received: from 90.2.a8c0.static.theplanet.com

(90.2.a8c0.static.theplanet.com [192.168.2.144])

by webmail.paulrappandco.com.au (Horde MIME library) with HTTP; Tue,

06 May 2008 06:29:23 +1000

Date: Tue, 06 May 2008 06:29:23 +1000

From: The Senate Hoouse <info@atm.com>

Subject: ATM CARD AWARD (6.8 MILLION DOLLARS)

X-Originating-IP: [70.84.168.26]

To: undisclosed-recipients: ;

Reply-to: linda107102@yahoo.com.hk

Message-id: <20080506062923.pr6uxvw3wgowskk0@webmail.paulrappandco.com.au>

MIME-version: 1.0

Content-type: text/plain; charset=ISO-8859-1; DelSp=Yes; format=flowed

Content-transfer-encoding: 7bit

Content-disposition: inline

User-Agent: Internet Messaging Program (IMP) H3 (4.1.5)







This is to officially inform you that ATM Card with a fund worth $6.8 Million

Dollars has been accredited in your favor, Please Contact Mrs. Linda Hill

(linda107102@yahoo.com.hk) With the following,

Full Name:

Delivery Address:

Age:

Occupation:

Phone Number:

Country:



Best Regards.

Senator David Mark.



MIME element (text/html)

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

<HTML><HEAD>

<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">

<META content="MSHTML 6.00.6000.16640" name=GENERATOR>

<STYLE></STYLE>

</HEAD>

<BODY bgColor=#ffffff>

<DIV><FONT face=Arial>Gentlemen:</FONT></DIV>

<DIV><FONT face=Arial>It appears from the highlighted portions of the message

detail pasted below that theplanet.com is being used for phishing and other

improper purposes.</FONT></DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial>I have forwarded this to you for whatever action you may

deem appropriate.</FONT></DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial>S. Kelsey</FONT></DIV>

<DIV><FONT face=Arial>California</FONT></DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV><FONT face=Arial>Received: from aus.worldofhosting.com

([70.84.168.26])<BR>&nbsp;by vms172071.mailsrvcs.net<BR>&nbsp;(Sun Java System

Messaging Server 6.2-6.01 (built Apr&nbsp; 3 2006))<BR>&nbsp;with ESMTP id

&lt;<A

href="mailto:0K0F00LBH63YXSW0@vms172071.mailsrvcs.net">0K0F00LBH63YXSW0@vms172071.mailsrvcs.net</A>&gt;

for <A href="mailto:midilaw@gte.net">midilaw@gte.net</A>;<BR>&nbsp;Mon, 05 May

2008 18:47:58 -0500 (CDT)<BR>Received: (qmail 21143 invoked by uid 48); Tue, 06

May 2008 06:29:31 +1000<BR><STRONG><FONT size=4>Received: from

90.2.a8c0.static.theplanet.com<BR>&nbsp;(90.2.a8c0.static.theplanet.com

[192.168.2.144])</FONT></STRONG><BR>&nbsp;by&nbsp;webmail.paulrappandco.com.au

(Horde MIME library) with HTTP; Tue,<BR>&nbsp;06 May 2008 06:29:23

+1000<BR>Date: Tue, 06 May 2008 06:29:23 +1000<BR>From: The Senate Hoouse &lt;<A

href="mailto:info@atm.com">info@atm.com</A>&gt;<BR>Subject: ATM CARD AWARD (6.8

MILLION DOLLARS)<BR>X-Originating-IP: [70.84.168.26]<BR>To:

undisclosed-recipients: ;<BR>Reply-to: <A

href="mailto:linda107102@yahoo.com.hk">linda107102@yahoo.com.hk</A><BR>Message-id:

&lt;<A

href="mailto:20080506062923.pr6uxvw3wgowskk0@webmail.paulrappandco.com.au">20080506062923.pr6uxvw3wgowskk0@webmail.paulrappandco.com.au</A>&gt;<BR>MIME-version:

1.0<BR>Content-type: text/plain; charset=ISO-8859-1; DelSp=Yes;

format=flowed<BR>Content-transfer-encoding: 7bit<BR>Content-disposition:

inline<BR>User-Agent: Internet Messaging Program (IMP) H3 (4.1.5)</FONT></DIV>

<DIV>&nbsp;</DIV>

<DIV><FONT face=Arial></FONT>&nbsp;</DIV>

<DIV>&nbsp;</DIV>

<DIV><FONT face=Arial>This is to officially inform you that ATM Card with a fund

worth $6.8 Million<BR>Dollars has been accredited in your favor, Please Contact

Mrs. Linda Hill<BR>(<A

href="mailto:linda107102@yahoo.com.hk">linda107102@yahoo.com.hk</A>) With the

following,<BR>Full Name:<BR>Delivery Address:<BR>Age:<BR>Occupation:<BR>Phone

Number:<BR>Country:</FONT></DIV>

<DIV>&nbsp;</DIV>

<DIV><FONT face=Arial>Best Regards.<BR>Senator David

Mark.<BR></FONT></DIV></BODY></HTML>

-----------------------------------------------------------------------------

Can anyone point me in the direction of what I should be looking for??


Top
  
 
 Post subject:
Unread postPosted: Tue May 06, 2008 3:25 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Sat Aug 20, 2005 9:30 am
Posts: 2812
Location: The Netherlands
Looks like a message sent using Horde Webmail at webmail.paulrappandco.com.au. Could very well be a compromised account (guessed password).

_________________
Lemonbit Internet Dedicated Server Management


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group