Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Sep 2003 11:49:01 +0300
From:      Alin-Adrian Anton <aanton@reversedhell.net>
To:        freebsd-questions@freebsd.org
Subject:   global lists virus spammer
Message-ID:  <3F5EE57D.8010409@reversedhell.net>

index | next in thread | raw e-mail

[-- Attachment #1 --]
There is a lame virus (probably written in VB judging by the size of the 
file) who keeps hitting the smtp servers, and I noticed it in  the 
freebsd lists. It has attachments like .pif and .scr.

I also noticed it filled my e-mail box with 67.5 Mb in just 3-4 days. 
Now that was nice. It spreads using impersonated fake e-mail addresses 
but I noticed it is always being sent by the very same IP:
"The original message was received on Tue, 09 Sep 2003 23:45:15 +0300
from KLAUS (pD9E8A85B.dip.t-dialin.net [217.232.168.91]"

After more then 2 weeks, it still keeps pushing out junk smtp data, so I 
blocked any SMTP coming from that server (via ipfw hammer tool).

I hope this message will be helpfull to all of us. Cheers.

Alin.


[-- Attachment #2 --]
0	*H
010	+0	*H
	00D
r0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
030901225717Z
040831225717Z0I10UThawte Freemail Member1&0$	*H
	aanton@reversedhell.net0"0
	*H
0
P 3k[76i*TUIӝWY᛻5EѳmVlCHH>=؏wrO/Qh!ev'kkZRtڌL!Ys,4;m3}@P0#c/B1
PL	O“2Agih\<?/63l4r87ۻ0ZcWeTObbǺ*>tED?`+u4020"U0aanton@reversedhell.net0U00
	*H
,Al5`	tq@!{mnS%
?!D<TċJ2fڛۿ.u؝C	N QVT/I7'?0w\)(RrN00D
r0
	*H
0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
030901225717Z
040831225717Z0I10UThawte Freemail Member1&0$	*H
	aanton@reversedhell.net0"0
	*H
0
P 3k[76i*TUIӝWY᛻5EѳmVlCHH>=؏wrO/Qh!ev'kkZRtڌL!Ys,4;m3}@P0#c/B1
PL	O“2Agih\<?/63l4r87ۻ0ZcWeTObbǺ*>tED?`+u4020"U0aanton@reversedhell.net0U00
	*H
,Al5`	tq@!{mnS%
?!D<TċJ2fڛۿ.u؝C	N QVT/I7'?0w\)(RrN0?0
0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
030717000000Z
130716235959Z0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00
	*H
0Ħ<UsUNʙZhup[v:aQP
0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr`00U00CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380
	*H
HP.
fgCL!6-6/P p<ab:~t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1;070i0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0	+0	*H
	1	*H
0	*H
	1
030910084901Z0#	*H
	1q6:ʑGi*t0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0x	+71k0i0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0z*H
	1ki0b10	UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0
	*H
4lRFHa	}#EYrA
4Xzc0mRu0($0菞*1gBa1\߆*ʝG%5:<MD)DuQSDD
{A]r}>sd,
EC?*,R+jYגNDW?F{8#ѿ٫|]mB>`ózјWhw5d:_ٸw1BĿFl6
help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3F5EE57D.8010409>