Is it one of you funny clowns?

CougTek

Hairy Aussie
Joined
Jan 21, 2002
Messages
8,726
Location
Québec, Québec
I received three messages in my home e-mail account containing unusual files. The messages were writen in English, so it's not from one of my close contacts and it probably came from people on one of the forum I'm member of (although I generally don't advertise that specific address in my profile). I didn't activated these files (one is a .bat, the others are .pif and .sr) since I don't know who sent them to me and what damage they might do.

All three messages were in the style : "I hope you'll like this tool." Since my test system is down for now, I don't plan to take the chance of double clicking on any of them (and since I don't open my mail with Outlook, I don't think I risk anything from Outlook-specific macro nuisance).

If any of you wants to send me anything, please clearly identify yourself and explain in detail the utility/file/whatever you send me. Otherwise, it will go down the drain and you'll have wasted your time.

Thanks
 

Tea

Storage? I am Storage!
Joined
Jan 15, 2002
Messages
3,749
Location
27a No Fixed Address, Oz.
Website
www.redhill.net.au
Nope. I got this the other day though.

Code:
Return-Path: <reply@seekercenter.net>
Delivered-To: [email]twilson@netconnect.com.au[/email]
Received: (qmail 2876 invoked by uid 1087); 8 May 2002 10:57:55 -0000
Delivered-To: [email]twilson-tea@redhill.net.au[/email]
Received: (qmail 2872 invoked by uid 620); 8 May 2002 10:57:55 -0000
Received: from [email]reply@seekercenter.net[/email] by ren.netconnect.com.au with qmail-scanner-0.94 (uvscan: v4.1.40/v4201. . Clean. Processed in 1.071633 secs); 08/05/2002 20:57:54
Received: from unknown (HELO tiantang163) (211.101.236.162)
  by 0 with SMTP; 8 May 2002 10:57:54 -0000
From: "Vanessa Lintner" <reply@seekercenter.net>
Subject: I have visited [url]WWW.STORAGEFORUM.NET[/url] and noticed that ...
To: [email]tea@redhill.net.au[/email]
Content-Type: text/html;
Sender: Vanessa Lintner <reply@seekercenter.net>
Reply-To: "Vanessa Lintner" <vanessa@seekercenter.net>
Date: Wed, 8 May 2002 19:00:53 +0800
X-Priority: 3
X-Library: Business Promotion

<html>
<head>
<title></title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css">
.stbtm {
	BACKGROUND-COLOR:#cecbde; BORDER-BOTTOM: #665b8e 1px solid; BORDER-LEFT: #ffffff 1px solid; BORDER-RIGHT: #665b8e 1px solid; BORDER-TOP: #ffffff 1px solid; COLOR: #000000; FONT-SIZE: 12pt; HEIGHT: 26px; WIDTH: 120px; clip:        rect(   )}
.stedit {
	 background-color:#484C68; white-space: nowrap; border: #000000; BORDER-BOTTOM: #ffffff 1px solid; BORDER-LEFT: #ffffff 1px solid; BORDER-RIGHT: #ffffff 1px solid; BORDER-TOP: #ffffff 1px solid; FONT-SIZE: 10pt; color: #CCCCCC; font-weight: bold}

</style>
</head>
<BODY leftMargin=0 onload="" topMargin=0 marginheight="0" marginwidth="0" bgcolor="#FFFFFF">
  
<table width="778" border="0" cellspacing="0" cellpadding="0">
  <tr>
      
    <td height="233" width="21"></td>
      
    <td height="233" colspan="3" width="757"> 
      <table width="621" border="0" cellspacing="0" cellpadding="0" align="left">
        <tr> 
            
          <td width="373" height="64"> 
            <table width="373" border="0" cellspacing="0" cellpadding="0" background="http://image.seekercenter.net/letter_bg.jpg" height="327">
                <tr> 
                  
                <td>

 
                  <font face=Arial size=2>
                  </font> <font face=Arial size=2><font face="Verdana, Arial, Helvetica, sans-serif" color="#000000">Hello,

                  

                  I have visited [url='http://www.storageforum.net']www.storageforum.net[/url] and noticed that your website is not listed on some search engines.
                  I am sure that through our service the number of people who visit your website will definitely increase. [url="http://www.seekercenter.net/index.php"]SeekerCenter[/url] 
                  is a unique technology that instantly submits your website 
                  to over 500,000 search engines and directories  
                  -- a really low-cost and effective way to advertise your site. 
                  For more details please go to [url="http://www.seekercenter.net/index.php"]SeekerCenter.net[/url].

                  

                  Give your website maximum exposure today!

                  Looking forward to hearing from you.

                  

                  <table border=0 width=100%><TR><TD width=50%>
                  <font face="Verdana, Arial, Helvetica, sans-serif" size=2 color="#000000">Best 
                  Regards,

                  Vanessa Lintner

                  Sales & Marketing 

                  [url="http://www.seekercenter.net/index.php"]www.SeekerCenter.net[/url]</font></font></font>
                  <TD><td width=50%>
                   <div align="center" valign=middle>
                   <form target=_blank action=http://www.seekercenter.net method=POST>
                          <input type="submit" name="Submit" value="Signup Now!!!" class="stbtm">
                   </form>
                        </div>
                  </TD>
                  </TR>
                  </table>
                  </td>
                </tr>
              </table>
            </td>
            
          <td width="242" height="64" valign="bottom"> 
            <table width="257" border="0" cellspacing="0" cellpadding="0">
              
                <tr>
                  <td colspan="3" height="2"></td>
                </tr>
                <tr> 
                  <td colspan="3" height="3"> 
                    
                  

[img]http://image.seekercenter.net/letter_top01.jpg[/img]</p>
                    </td>
                </tr>
                <tr> 
                  <td colspan="3">[img]http://image.seekercenter.net/letter_right01.jpg[/img]<A target=_blank Href ="http://www.storageforum.net"><IMG Src =http://image2.seekercenter.net/image162a/1/88/img422.jpg Border=0 width="256" height="184"></A>[img]http://image.seekercenter.net/letter_left01.jpg[/img]</td>
                </tr>
                
              <tr> 
                <td colspan="3" height="80" background="http://image.seekercenter.net/letter_bottom01.jpg"> 
                  <table width="326" border="0" cellspacing="0" cellpadding="0" height="80">
                    <tr>
                      <td width="36" height="43"></td>
                      <td width="157" height="43"></td>
                      <td width="134" height="43"></td>
                    </tr>
                    <tr>
                      <td width="36" height="2"></td>
                      <td width="157" height="2"></td>
                      <td width="134" height="2"></td>
                    </tr>
                  </table>
                  
                </td>
                </tr>
                <tr> </tr>
              </table>
            </td>
          </tr>
        </table>
      </td>
    </tr>
  </table>
  </body>
</html>
 

CougTek

Hairy Aussie
Joined
Jan 21, 2002
Messages
8,726
Location
Québec, Québec
If it's not from you three guys (no Buck, it wasn't from the address you gave), then I don't think it's from anyone here as you are the only ones who know this address, along with Doug, Tim Zak and perhaps Andrew (not sure).

No clue who it was. Thanks for replying.
 

Handruin

Administrator
Joined
Jan 13, 2002
Messages
13,741
Location
USA
Tea, I got the same exact message the other day, I thought it was some type of spam so it went in the trash.

I've setup the e-mail on this forum so that it is web based and other sites can't consume all of your addresses. Unless they have found a way, any mail that comes from clicking on the mail button will look like it was from me (webmaster I believe), or storageforum.net. It will also clearly indicate that it is from SF and also who the person was that sent it.

Coug, I did not send you any mail either, and I did not give out the address. In fact, I don't even recall your e-mail address, maybe I've sent you message through PM and through xoops.
 

Cliptin

Wannabe Storage Freak
Joined
Jan 22, 2002
Messages
1,206
Location
St. Elmo, TN
Website
www.whstrain.us
Nor I.

If .sr is instead .scr, this is a known method of trojan attack. Screensavers are not considered tools. :)

The other two go without saying.
 

CougTek

Hairy Aussie
Joined
Jan 21, 2002
Messages
8,726
Location
Québec, Québec
I don't have the full header. The first message comes from drcItaahwnns@omi.o, the second is from winlnist@hotmail.com and the last one is from ...hey wait a second, it's from a place in Québec. The file in the last message is called Et.scr. I know the provider so I can probably retrace the person who sent it. If it's a virus, a crowbar and a hood together aren't very expensive :twistd:

Is it possible to contact Hotmail so that they close an account if it's proven that the user used it in shaddy ways? I guess that yes.
 
Top