Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 12-30-2002, 07:38 PM   #1
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
Question email address hijacking - please help

Hello there,

I have been experiencing a very strange and disturbing phenomenon with my email lately and I have a strong feeling that someone is hijacking my domain and sending unsolicited mail from it. The situation is that I am receiving a significant volume of “returned to sender” emails each day (see below for an example). These are emails that I definitely haven’t sent and are from an address (at my domain) which I don’t use regularly. My initial reaction was that I had some kind of worm infection that was sending out emails from my address book. However, none of the addresses were in my address book and they seemed to follow the systematic, alphabetic patterns adopted by spammers (eg malibu@yahoo.com followed by malia_aloha@yahoo.com). As the only ones being returned are those which have been sent to invalid or inactive email addresses, this raises the very disconcerting possibility that my business email (eg @onlinebooks.co.uk) is being sent out to stacks of people as spam.

What recourse is available to me – is there any way for me to track down the perpetrator and more importantly, how can I stop this.

I would be very grateful for some feedback as I am very concerned about the effect this could be having on my company’s name.

Thanks in advance guys,

Matt.

Example email

> From:
> To:
> Sent: Sunday, December 29, 2002 5:08 PM
> Subject: Delivery failure
>
>
> > Message from yahoo.com.
> > Unable to deliver message to the following address(es).
> >
> > :
> > Sorry your message to malia_aloha@yahoo.com cannot be delivered. This
> account has been disabled or discontinued [#103].
> >
> > :
> > This user doesn't have a yahoo.com account (malibu@yahoo.com)
> >
> > --- Original message follows.
> >
> > X-Rocket-Spam: 207.99.39.15
> > X-YahooFilteredBulk: 207.99.39.15
> > X-Track: 5511: 20
> > X-Rocket-Server: 66.163.174.38
> > Return-Path:
> > Received: from 207.99.39.15 (207.99.39.15)
> > by mta444.mail.yahoo.com with SMTP; 29 Dec 2002 09:08:27 -0800 (PST)
> > From: "malia_aloha"
> > Reply-To: "malia_aloha"
> > Date: Sun, 29 Dec 2002 17:11:32 +0000
> > Subject: Re: Ok, why not?
> > X-Priority: 1
> > MIME-Version: 1.0
> > X-Mailer: Microsoft Outlook Express 6.00.2600.0000
> > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
> > X-Precedence-Ref: 1234506789zxcvbnmlkjhg
> > Content-Type: text/plain; charset=us-ascii
> > Content-Transfer-Encoding: 7bit
> >
> > Hi )) malia_aloha ,
> >
> >
> > Hi there!
> >
> > think you relayed to my personal ad!
> > Yes I do get a lot of responses but you got me curious I haven't done
this
> > in a while so please forgive my nervousness. And I hope your still
around,
> > (the good people always get taken fast) Anyway since I know a "little"
> about
> > you (that was cute by the way), you should take a look at me so that
> you
> > can decide if we match.
> > I'm not sure exactly what ad you replied to, I have a couple, but I do
> > have a detailed profile with a picture
> >
> > at http://www.singlers.com/index_vip.html
> > Chris
> > Well...If you're not interested any more, that's ok too....
> > Have a great night.
> > Bye....
> > ChrisBrenda27
> >
> >
> >
> >
> >
> > [K9^":}H&*TG0BK5NKIYs5]
matt_richards is offline   Reply With Quote
Old 12-30-2002, 08:03 PM   #2
Telcom Tech
 
ktkendall's Avatar
 
Join Date: Feb 2002
Location: Western, Pa.
Posts: 5,409
SirCam Virus

Sounds like the SirCam virus. I actually opened an attachment on my company PC that I thought was safe and got infected. It caused me to constantly get hundreds of unsendable e-mails, it causes infected PC to just constantly send out emails to a bogus address, and it tries to affect your PC's ability to run executable files.
May not be though in your case, since you seem to have a trac on where it came from, and was caused by.
Here is link with description of the virus and the removal tool.
http://securityresponse.symantec.com...m.worm@mm.html
KK
__________________
If it ain't broke, "TWEAK IT"
ktkendall is offline   Reply With Quote
Old 12-30-2002, 08:09 PM   #3
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
I will investigate that just in case - but based on other reports i have read, it seems that some unscrupulous party has hijacked the email address. The specific site in question seems to be: httpwww.singlers.comindex_vip.html.

It is all very frustrating - there must be a way to stop them! The worrying thing is, every single person who receives the unsolicited mail will associate my company with some bloody spammer. I just have no idea how many people are receiving these spurious messages, so I don't know what the impact could be.

Cheers,

Matt.

Last edited by matt_richards; 12-30-2002 at 08:14 PM.
matt_richards is offline   Reply With Quote
Old 12-30-2002, 08:44 PM   #4
Member (11 bit)
 
Computer Hobbyist's Avatar
 
Join Date: Feb 2001
Location: Blue Springs, MO
Posts: 1,766
You might want to read this page at spamcop. It should help you.

CH
Computer Hobbyist is offline   Reply With Quote
Old 12-31-2002, 02:17 AM   #5
Tuf
Member (12 bit)
 
Tuf's Avatar
 
Join Date: Dec 1999
Location: Oklahoma
Posts: 3,261
I don't know what recourse you do or don't have in the UK. I know if someone was using my name and my equipment to spam I would prosecute them and most likely pay them a personal visit if possible.


What they are doing is a crime here in the states, I would think it would be there as well.
Tuf is offline   Reply With Quote
Old 01-01-2003, 05:20 PM   #6
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
That spam cop page was very informative CH - it seems the first port of call is to contact my ISP and try and establish who their ISP is.

Tuf - I am a tiny bit confused about the equipment thing. The problem is that someone is using my domain to send out spam, they have no access to any of my hardware. I have no way of personally visiting them as I have no idea who or where they are!

Does anyone know of any action that I could personally take on a technical - rather than legal - level to secure my domain against such attacks. My concern is that if I have to wait on other parties like the ISP's this could really drag on - I have read that they are notoriously inefficient when it comes to dealing with this kind of stuff.

Cheers,

Matt.
matt_richards is offline   Reply With Quote
Old 01-01-2003, 05:41 PM   #7
Power in the Box-P4 XEON!
 
Hpro's Avatar
 
Join Date: May 2001
Location: Europe >Swiss
Posts: 3,014
Yes - since it is from YAHOO so make a REGISTERED LETTER signed by you with a copy of some kind of indentification and explain them - I think they help you - they helped me when I was spammed by some stupid there -... and that guy is still around on yahoo changing his login name like other people theyr shirts...
Hpro
__________________
It's not as hard to do as you may think...It's just that you try.!And I'm still trying..!

The Machine: i7 920CPU @ 2.66 Hypertreading / Asus P6T / 12GB DDR3 Ram 1366 / 3 x Sata 160GB Hot Swap / 1x Sata 160GB / 2 x Sata 300 GB / Plextor DVD 800 SATA / Plextor CDRW IDE / Audigy Sound Blaster 24 Bit / ASUS Nvidia ENGT 240/ Chieftec Full Tower / PSU Chieftec 600 Watt / Win7 x64 Ultimate MAPS
Hpro is offline   Reply With Quote
Old 01-02-2003, 06:13 AM   #8
Member (8 bit)
 
Join Date: Apr 2002
Posts: 144
Thanks mate,

I will do that.
matt_richards is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:30 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2