DocHeb
Veteran Member
My wife received an email delivery failure message. She never sent an email to the supposed recipient, and there are attachments that have a hidden .zip file. I am running Norton Firewall and Antivirus (up-to-date) and received no warnings. I think this may be an intrusion attempt. What do you think? If it is, they are really getting sneaky.
<font color="red">Received: from mc6.midcoast.com ([69.39.100.16])
by rwcrmxc23.comcast.net (rwcrmxc23) with ESMTP
id <20041204120625r23005kr9ce>; Sat, 4 Dec 2004 12:06:25 +0000
X-Originating-IP: [69.39.100.16]
Received: by mc6.midcoast.com (Postfix)
id EC53919EF7; Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Date: Sat, 4 Dec 2004 07:05:43 -0500 (EST)
From: MAILER-DAEMON@mc6.midcoast.com (Mail Delivery System)
Subject: Undelivered Mail Returned to Sender
To: Nannygoat@comcast.net
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary="C9D1616847.1102161943/mc6.midcoast.com"
Message-Id: <20041204120543.EC53919EF7@mc6.midcoast.com>
This is a MIME-encapsulated message.
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Notification
Content-Type: text/plain
This is the Postfix program at host mc6.midcoast.com.
I'm sorry to have to inform you that the message returned
below could not be delivered to one or more destinations.
For further assistance, please send mail to <postmaster>
If you do so, please include this problem report. You can
delete your own text from the message returned below.
The Postfix program
<ron@r.mail.midcoast.com>: host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, id=19727-08 - VIRUS: Worm.Sober.I (in reply to end of
DATA command)
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Delivery error report
Content-Type: message/delivery-status
Reporting-MTA: dns; mc6.midcoast.com
Arrival-Date: Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Final-Recipient: rfc822; ron@r.mail.midcoast.com
Action: failed
Status: 5.0.0
Diagnostic-Code: X-Postfix; host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, id=19727-08 - VIRUS: Worm.Sober.I (in reply to end of
DATA command)
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Undelivered Message
Content-Type: message/rfc822
Received: from test.dns.midcoast.com (test.dns.midcoast.com [69.39.100.30])
by mc6.midcoast.com (Postfix) with ESMTP id C9D1616847
for <ron@r.mail.midcoast.com>; Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Received: by test.dns.midcoast.com (Postfix)
id 0276D23D385; Sat, 4 Dec 2004 07:07:34 -0500 (EST)
Delivered-To: ron@midcoast.com
Received: from luwak.midcoast.com (luwak.midcoast.com [69.39.100.7])
by test.dns.midcoast.com (Postfix) with ESMTP
id F13E623D18A; Sat, 4 Dec 2004 07:07:33 -0500 (EST)
Received: from glqnc.net (pcp04040536pcs.wbrmfd01.mi.comcast.net [68.43.226.227])
by luwak.midcoast.com (Postfix) with SMTP
id B50062BAF6F; Sat, 4 Dec 2004 07:09:12 -0500 (EST)
From: Nannygoat@comcast.net
To: Your_Account@random-abstract.com
Date: Sat, 04 Dec 2004 11:52:44 GMT
Subject: Details
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
Message-ID: <04bc.010160e7ef8@comcast.net>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="======bac5a05bcff.ccaf9f442c1d5"
Content-Transfer-Encoding: 7bit
This is a multi-part message in MIME format.
--======bac5a05bcff.ccaf9f442c1d5
I was surprised, too!
Who_could_suspect_something_like_that? shityiiiii
--======bac5a05bcff.ccaf9f442c1d5
Content-Type: application/octet-stream; name=thats_hard.zip
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="thats_hard.zip"</font>
<font color="red">Received: from mc6.midcoast.com ([69.39.100.16])
by rwcrmxc23.comcast.net (rwcrmxc23) with ESMTP
id <20041204120625r23005kr9ce>; Sat, 4 Dec 2004 12:06:25 +0000
X-Originating-IP: [69.39.100.16]
Received: by mc6.midcoast.com (Postfix)
id EC53919EF7; Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Date: Sat, 4 Dec 2004 07:05:43 -0500 (EST)
From: MAILER-DAEMON@mc6.midcoast.com (Mail Delivery System)
Subject: Undelivered Mail Returned to Sender
To: Nannygoat@comcast.net
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary="C9D1616847.1102161943/mc6.midcoast.com"
Message-Id: <20041204120543.EC53919EF7@mc6.midcoast.com>
This is a MIME-encapsulated message.
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Notification
Content-Type: text/plain
This is the Postfix program at host mc6.midcoast.com.
I'm sorry to have to inform you that the message returned
below could not be delivered to one or more destinations.
For further assistance, please send mail to <postmaster>
If you do so, please include this problem report. You can
delete your own text from the message returned below.
The Postfix program
<ron@r.mail.midcoast.com>: host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, id=19727-08 - VIRUS: Worm.Sober.I (in reply to end of
DATA command)
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Delivery error report
Content-Type: message/delivery-status
Reporting-MTA: dns; mc6.midcoast.com
Arrival-Date: Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Final-Recipient: rfc822; ron@r.mail.midcoast.com
Action: failed
Status: 5.0.0
Diagnostic-Code: X-Postfix; host 127.0.0.1[127.0.0.1] said: 550 5.7.1 Message
content rejected, id=19727-08 - VIRUS: Worm.Sober.I (in reply to end of
DATA command)
--C9D1616847.1102161943/mc6.midcoast.com
Content-Description: Undelivered Message
Content-Type: message/rfc822
Received: from test.dns.midcoast.com (test.dns.midcoast.com [69.39.100.30])
by mc6.midcoast.com (Postfix) with ESMTP id C9D1616847
for <ron@r.mail.midcoast.com>; Sat, 4 Dec 2004 07:05:43 -0500 (EST)
Received: by test.dns.midcoast.com (Postfix)
id 0276D23D385; Sat, 4 Dec 2004 07:07:34 -0500 (EST)
Delivered-To: ron@midcoast.com
Received: from luwak.midcoast.com (luwak.midcoast.com [69.39.100.7])
by test.dns.midcoast.com (Postfix) with ESMTP
id F13E623D18A; Sat, 4 Dec 2004 07:07:33 -0500 (EST)
Received: from glqnc.net (pcp04040536pcs.wbrmfd01.mi.comcast.net [68.43.226.227])
by luwak.midcoast.com (Postfix) with SMTP
id B50062BAF6F; Sat, 4 Dec 2004 07:09:12 -0500 (EST)
From: Nannygoat@comcast.net
To: Your_Account@random-abstract.com
Date: Sat, 04 Dec 2004 11:52:44 GMT
Subject: Details
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
Message-ID: <04bc.010160e7ef8@comcast.net>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="======bac5a05bcff.ccaf9f442c1d5"
Content-Transfer-Encoding: 7bit
This is a multi-part message in MIME format.
--======bac5a05bcff.ccaf9f442c1d5
I was surprised, too!
Who_could_suspect_something_like_that? shityiiiii
--======bac5a05bcff.ccaf9f442c1d5
Content-Type: application/octet-stream; name=thats_hard.zip
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="thats_hard.zip"</font>