Date: Wed, 10 Sep 2003 11:49:01 +0300 From: Alin-Adrian Anton <aanton@reversedhell.net> To: freebsd-questions@freebsd.org Subject: global lists virus spammer Message-ID: <3F5EE57D.8010409@reversedhell.net>
index | next in thread | raw e-mail
[-- Attachment #1 --]
There is a lame virus (probably written in VB judging by the size of the
file) who keeps hitting the smtp servers, and I noticed it in the
freebsd lists. It has attachments like .pif and .scr.
I also noticed it filled my e-mail box with 67.5 Mb in just 3-4 days.
Now that was nice. It spreads using impersonated fake e-mail addresses
but I noticed it is always being sent by the very same IP:
"The original message was received on Tue, 09 Sep 2003 23:45:15 +0300
from KLAUS (pD9E8A85B.dip.t-dialin.net [217.232.168.91]"
After more then 2 weeks, it still keeps pushing out junk smtp data, so I
blocked any SMTP coming from that server (via ipfw hammer tool).
I hope this message will be helpfull to all of us. Cheers.
Alin.
[-- Attachment #2 --]
0 *H
010 + 0 *H
00D
r0
*H
0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
030901225717Z
040831225717Z0I10UThawte Freemail Member1&0$ *H
aanton@reversedhell.net0"0
*H
0
P 3k[76i*TUIӝWY5EѳmVlCHH>=؏wrO/Qh!ev'kkZRtڌL!Ys,4;m3}@P0#c/B1
PL O2Agih\<?/63l4r87ۻ0ZcWeTO bbǺ*>tED?`+u 4020"U0aanton@reversedhell.net0U0 0
*H
,Al5 ` tq@!{mnS%
?!D<TċJ2fڛۿ.u؝C N QVT/I7'?0w\)(RrN00D
r0
*H
0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0
030901225717Z
040831225717Z0I10UThawte Freemail Member1&0$ *H
aanton@reversedhell.net0"0
*H
0
P 3k[76i*TUIӝWY5EѳmVlCHH>=؏wrO/Qh!ev'kkZRtڌL!Ys,4;m3}@P0#c/B1
PL O2Agih\<?/63l4r87ۻ0ZcWeTO bbǺ*>tED?`+u 4020"U0aanton@reversedhell.net0U0 0
*H
,Al5 ` tq@!{mnS%
?!D<TċJ2fڛۿ.u؝C N QVT/I7'?0w\)(RrN0?0
0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
030717000000Z
130716235959Z0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00
*H
0 Ħ<UsUNʙZhup[v:aQP
0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr` 00U0 0CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380
*H
HP.
fgCL!6-6/P p<ab:~ t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO1;070i0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0 + 0 *H
1 *H
0 *H
1
030910084901Z0# *H
1q6:ʑGi*t0R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0x +71k0i0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0z*H
1ki0b10 UZA1%0#U
Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA
r0
*H
4lRFHa }#EYrA
4Xzc0mRu0($0菞*1gBa 1\߆*ʝG%5:<MD)DuQSDD
{A]r}>sd,
EC?*,R+jYגNDW?F{8#ѿ٫|]mB>`ózјWhw5d:_ٸw1BĿFl6
help
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3F5EE57D.8010409>
