1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

A new hacker trick?

Discussion in 'Security and Privacy' started by Shturmovik, 2004/04/30.

Thread Status:
Not open for further replies.
  1. 2004/04/30
    Shturmovik

    Shturmovik Inactive Thread Starter

    Joined:
    2002/09/03
    Messages:
    73
    Likes Received:
    0
    I received the following email today. It did not have an attachment so I can't figure it out .

    _____________________________________________
    ScanMail for Microsoft Exchange has detected virus-infected attachment(s).

    Sender = xxxxxxxxx@xxxxxxxxxx.com
    Recipient(s) = xxxxxxxxx
    Subject = Your day
    Scanning Time = 04/30/2004 11:10:08
    Engine/Pattern = 7.000-1004/877

    Action on virus found:
    The attachment postcard.zip contains WORM_NETSKY.P virus. ScanMail has Deleted it.

    Warning to sender. ScanMail has detected a virus in an email you sent.
    ___________________________________________

    1. In the sender line it had my correct email address except for the provider which is not a .com.
    2. I do not know the recipient, unless he works at some company I have emailed recently but in that case I would think there would have been something to denote that.
    3. In the 'subject' line it says "your day ". I have not titled anything I wrote like that.
    4. I haven't sent an "attachment postcard.zip "; wouldn't even know how to send a zip attachment.
    5. My Norton AV did not alert on this so if it is malicious how would it work?

    What gives with this?
     
  2. 2004/04/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    No doubt you would have received a virus had you clicked the link - delete it.

    Had a similar one today - clue is it is generally refers to an address that you never sent to.
     

  3. to hide this advert.

  4. 2004/04/30
    Shturmovik

    Shturmovik Inactive Thread Starter

    Joined:
    2002/09/03
    Messages:
    73
    Likes Received:
    0
    But there was no link, that is the weird part; no links, no attachments! What is ScanMail for Microsoft Exchange? I just did a complete system scan with latest Symantec update and am clean so I don't think it was some unknown business contact. I have been getting loads of netsky attacks but they have all had links and/or attachments.
     
  5. 2004/04/30
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
  6. 2004/04/30
    Shturmovik

    Shturmovik Inactive Thread Starter

    Joined:
    2002/09/03
    Messages:
    73
    Likes Received:
    0
    But I am the sender referred to! The 'recipient' was my purported victim of an 'infected' email. That is why it makes no sense.
     
  7. 2004/04/30
    Hulka

    Hulka Inactive

    Joined:
    2002/01/07
    Messages:
    330
    Likes Received:
    0
    Your email address was spoofed by an infected computer. When the infected message arrived at the recipient's mail server it sent notifcation to the "sender" that the message contained a virus. The receiving mail server does not know you were not the actual sender, it only send its auto-reply to the sender indicated in the headers.
     
  8. 2004/04/30
    Shturmovik

    Shturmovik Inactive Thread Starter

    Joined:
    2002/09/03
    Messages:
    73
    Likes Received:
    0
    That makes sense but why didn't it try to get me with an attachment or poisoned link? And why did it have my email address as xxxx@xxx.com when it isn't a .com (although it had the rest right)?
     
  9. 2004/04/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Don't know about the .com part, but the attachment was undoubtedly deleted at the server, before it got to you.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.