What is source of this virus spam?

I

I'm_A_Victim

Below is the full header except for my email address which is not board at
ogs. I have been receiving about 1 virus spam a day for a couple of weeks
supposedly from board..... I know that this is bogus as the board is really
a distribution list at the ogs.org site.
+++++++++++++++++++++++++

X-Originating-IP: [64.224.219.78]
Return-Path: <[email protected]>
Received: from 64.224.219.78 (EHLO mail4.atl.registeredsite.com)
(64.224.219.78) by mta270.mail.scd.yahoo.com with SMTP; Thu, 08 Jul 2004
22:14:23 -0700
Received: from imta03a2.registeredsite.com
(imta03a2.registeredsite.com [64.225.255.12]) by
mail4.atl.registeredsite.com (8.12.11/8.12.8) with ESMTP id i695DHwE000941;
Fri, 9 Jul 2004 05:13:17 GMT
Received: from inbound-mx8.atl.registeredsite.com ([64.224.219.118])
by imta03a2.registeredsite.com with ESMTP id
<20040709051317.KFLB6886.imta03a2.registeredsite.com@inbound-mx8.atl.registe
redsite.com> for <board at ogs.org>; Fri, 9 Jul 2004 01:13:17 -0400
Received: from ogs.org (66-242-38-154.iscg-tol-oh.powersupply.net
[66.242.38.154] (may be forged)) by inbound-mx8.atl.registeredsite.com
(8.12.11/8.12.8) with ESMTP id i695CWng011712 for <board at ogs.org>; Fri, 9
Jul 2004 05:12:33 GMT
Message-Id:
<[email protected]>
From: (e-mail address removed) Add to Address Book
To: board at ogs.org
Subject: Re: Virus Sample
Date: Fri, 9 Jul 2004 01:12:33 -0400
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
X-Priority: 3
X-MSMail-Priority: Normal
Content-Length: 30403



+++++++++++++
W32.Netsky.P@mm was the attachment. I want to stop these giys. The address
board at ogs.org is forged. I have modified it to prevent it from being
harvested. Also I doubt that support at symantec would be sending me this
message.

If you want to email me send mail to rwma rble at yaho o dot com <
no spaces and change the "at" and "dot"

Thanks in advance for your help
 
I

Ionizer

I'm_A_Victim said:
Below is the full header except for my email address which is not board at
ogs. I have been receiving about 1 virus spam a day for a couple of weeks
supposedly from board..... I know that this is bogus as the board is really
a distribution list at the ogs.org site.
+++++++++++++++++++++++++

I managed to run it through SpamCop and the bottom line was:

Report Spam To:
Re: 66.242.38.154 (Administrator of network where email originates)
postmaster @ iscg.net
 
G

GSV Three Minds in a Can

from said:
Below is the full header except for my email address which is not board at
ogs. I have been receiving about 1 virus spam a day for a couple of weeks
supposedly from board..... I know that this is bogus as the board is really
a distribution list at the ogs.org site.
+++++++++++++++++++++++++

X-Originating-IP: [64.224.219.78]

If that is true (and it might not be) you stick that into the whois
database (google for 'whois') and you get


Search results for: 64.224.219.78

OrgName: Interland
OrgID: INTD
Address: 101 Marietta Street
City: Atlanta
StateProv: GA
PostalCode: 30039
Country: US

NetRange: 64.224.0.0 - 64.227.255.255
CIDR: 64.224.0.0/14
NetName: INTERLAND-5
NetHandle: NET-64-224-0-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: A.NS.INTERLAND.NET
NameServer: B.NS.INTERLAND.NET
NameServer: C.NS.INTERLAND.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2000-02-23
Updated: 2002-03-04

TechHandle: BW995-ARIN
TechName: Wright, Barry
TechPhone: +1-404-720-8301
TechEmail: (e-mail address removed)

OrgAbuseHandle: ABUSE579-ARIN
OrgAbuseName: ABUSE
OrgAbusePhone: +1-404-260-4500
OrgAbuseEmail: (e-mail address removed)

OrgTechHandle: ASNAD3-ARIN
OrgTechName: ASNADMIN
OrgTechPhone: +1-404-260-4500
OrgTechEmail: (e-mail address removed)

# ARIN WHOIS database, last updated 2004-07-09 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.


so I suggest you forward the received messages with FULL HEADERS
(including your email address) to (e-mail address removed) and ask them to
sort it out (if it is really from one of their systems or customers), or
ring Barry Wright.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top