Marcus L. Rowland (ffutures) wrote,
Marcus L. Rowland
ffutures

Another cunning virus ploy

Received this tonight (read in mailwasher, needless to say with great care)


Dear user of Ntlworld.com,

Some of our clients complained about the spam (negative e-mail content) outgoing from your e-mail account. Probably, you have been infected by a proxy-relay trojan server. In order to keep your computer safe, follow the instructions.

For further details see the attach.

Best wishes,
The Ntlworld.com team http://www.ntlworld.com


Needless to say "the attach" is a .pif file called morinfo, presumably a virus payload of some sort. That or Ntlworld technical support are TRULY stupid, because there is no way I'm opening an attachment of that sort.

Here's the full header, for anyone who's interested or wants to take a crack at tracing the source. I've replaced the usual HTML brackets with curly brackets in what follows and deleted my address:



Return-Path: {czVrldGLqVJAFwia@00.d0.59.f5.d0.2a}
Received: from dispatch ([67.164.248.44]) by mta03-svc.ntlworld.com
(InterMail vM.4.01.03.37 201-229-121-137-20020806) with SMTP
id {20040304155443.YOMD22458.mta03-svc.ntlworld.com@dispatch}
for {xxxxxxxxxxxxxxxx@ntlworld.com};
Thu, 4 Mar 2004 15:54:43 +0000
Date: Thu, 04 Mar 2004 08:56:56 -0700
To: xxxxxxx@ntlworld.com
Subject: Warning about your e-mail account.
From: support@ntlworld.com
Message-ID: {etchsvwvojumewsoxpq@ntlworld.com}
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------tjbeqniifnaoportlvak"

----------tjbeqniifnaoportlvak
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Subscribe
  • Post a new comment

    Error

    Anonymous comments are disabled in this journal

    default userpic

    Your reply will be screened

  • 10 comments