Page 1 of 1

Strange emails

Posted: Tue Jan 31, 2006 4:54 am
by ichabod
Hey Luke,

This morning i checked my emails and there were 3 in my inbox without a subject but the sender was ******@yahoo.com.

When you open the email there are a lot of pictures that were blocked due to the security, and all 3 had strange attatchments, the file names ending in .mim .pif and .zza

Obviously i had the sense not to open them and download the contents, and I'm pretty sure that you didn't send them.

I just thought I'd bring this up in case anyone else gets an email they think is from UD and opens the contents to find something nasty is lurking within.

Any idea as to what is going on?

Ichabod

Posted: Tue Jan 31, 2006 7:34 am
by memnv
I would not open them they sound like viruses

Posted: Tue Jan 31, 2006 8:10 am
by Luke
Sorry to hear that you got something like that and that it looked like it was from me. I'm not sure how it works when we see e-mails that are obviously viruses and they look like they come from an address you know. If I was in your address book, I might suspect something, but I still wouldn't know how it's done. Needless to say, I didn't send it. But if you can check full header information and pass that information on to me, I can look into it and see if there's a problematic IP or something.

I'm glad you made this thread in case others get it too. There's this and there's the whole people not getting e-mails thing that makes me want to ditch Yahoo! Mail, though I'm so used to using it with ease.

Posted: Tue Jan 31, 2006 8:34 am
by Paka
Yeah, I've received 2 very similar emails from "tsdvd" thus far, one yesterday and one today. I suspected they were just viruses or worms or trojans or whatever those kRaZy hackers are spreading 'round these days, but I'm glad now to know that it wasn't just me. :P

Posted: Tue Jan 31, 2006 2:25 pm
by ichabod
Well I just received another one, and here is the full header

MIME-Version: 1.0
Received: from Danrath ([69.67.184.246]) by bay0-mc12-f15.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Tue, 31 Jan 2006 11:28:34 -0800
X-Message-Info: 6sSXyD95QpVKNW2bVsyr3eq+yvz3KgyXoZI7y2drKxk=
Return-Path: tsdvd@yahoo.com
X-OriginalArrivalTime: 31 Jan 2006 19:28:35.0070 (UTC) FILETIME=[872461E0:01C6269C]

Hope it's of some use

Posted: Tue Jan 31, 2006 2:50 pm
by Luke
Thanks, ichabod. Not that I expect it to make a great amount of difference, but I've banned the originating IP from this site. I don't know how or why whoever does this stuff does it, but hopefully, no one falls for that nonsense.

Posted: Fri Feb 17, 2006 1:45 am
by ichabod
Just a bump to say that this morning I received another email, which hotmail had identified as posing a risk. This time however the sender was from Jnseiley@yahoo.com which you may know is UD's Jack's email address. So if you get an email from him, it may not be a friendly greeting from our sometimes AWOL friend!

Posted: Fri Feb 17, 2006 12:40 pm
by Luke
I have gotten those Jack e-mails in the past, but it's been a while. Not as long as it's been since getting a real Jack e-mail though!