Subject: [Req #26455] Re: Undeliverable mail--"The Mustang Back Support With Suspenders, 728, "
From: Mitchell Wand (email@example.com)
Date: Tue Jun 11 2002 - 14:24:14 EDT
I don't think these messages are from somebody on dem. It is more
likely that someone with an infected machine has dem in their address
Here's my copy of the message in question, with headers intact. Note
that the From: line has also been forged, so that the message appears
to be from the recipient's postmaster.
The forged From: is characteristic of the Klez virus. Earlier
versions simply supplied a From: address from the infectee's address
book. The forged From:=postmaster is a new variation that has shown
up just in the last week or so.
See also my Req's 26422 and 26448.
From firstname.lastname@example.org Tue Jun 11 10:10:50 2002
Received: by amber.ccs.neu.edu (Postfix)
id 1F25C1AA10; Tue, 11 Jun 2002 10:10:16 -0400 (EDT)
Received: from domail1 (unknown [188.8.131.52])
by amber.ccs.neu.edu (Postfix) with ESMTP id B19A61AAA1
for <email@example.com>; Tue, 11 Jun 2002 10:10:11 -0400 (EDT)
Received: from pmail.emirates.net.ae (pmail.emirates.net.ae [184.108.40.206])
(iPlanet Messaging Server 5.2 HotFix 0.2 (built Apr 26 2002))
with ESMTP id <0GXJ00D3DNVLM5@domail1.emirates.net.ae> for firstname.lastname@example.org;
Tue, 11 Jun 2002 17:52:34 +0400 (GST)
Received: from Grzgnoiev (lda145.emirates.net.ae [220.127.116.11])
(Sun Internet Mail Server sims.4.0.2000.10.12.16.25.p8)
with SMTP id <0GXJ00J2XNUF4U@pmail.emirates.net.ae> for email@example.com; Tue,
11 Jun 2002 17:52:16 +0400 (GST)
Date-warning: Date header was inserted by pmail.emirates.net.ae
From: postmaster <firstname.lastname@example.org>
Subject: Undeliverable mail--"The Mustang Back Support With Suspenders, 728, "
Date: Tue, 11 Jun 2002 17:52:16 +0400 (GST)
<FONT>The following mail can't be sent to bIbxfrrbuit@ao.o:<br>
Subject: The Mustang Back Support With Suspenders, 728, <br>
The file is the original mail</FONT></BODY></HTML>
Content-type: application/octet-stream; name=Vshng.exe
Content-disposition: attachment; filename=Vshng.exe
This archive was generated by hypermail 2b28 : Tue Jun 11 2002 - 14:24:25 EDT