Web Hosting Talk







View Full Version : malicious attempt ?


vegs
11-26-2001, 04:33 PM
Someone intend to send me a virus but it seems that exim did something to it.

This message has been rejected because it has
a potentially executable attachment "New_Napster_Site.MP3.pif"
This form of attachment has been used by
recent viruses or other malware.
If you meant to send this file then please
package it up as a zip file and resend it.

------ This is a copy of the message, including all the headers. ------

Return-path: <sales@xx***********>
Received: from host213-1-129-242.btinternet.com ([213.1.129.242] helo=aol.com)
by xxxx.xxx.xxx with smtp (Exim 3.33 #1)
id 168Rzc-0001XS-00
for sales@x***********; Mon, 26 Nov 2001 15:04:41 -0500
From: "Support" <support@cyberramp.net>
To: sales@***********
Subject: Re:
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="====_ABC1234567890DEF_===="
X-Priority: 3
X-MSMail-Priority: Normal
X-Unsent: 1
Message-Id: <E168Rzc-0001XS-00@xxxx.xxx.xxx>
Date: Mon, 26 Nov 2001 15:04:41 -0500

--====_ABC1234567890DEF_====
Content-Type: multipart/alternative;
boundary="====_ABC0987654321DEF_===="

--====_ABC0987654321DEF_====
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable


<HTML><HEAD></HEAD><BODY bgColor=3D#ffffff>
<iframe src=3Dcid:EA4DMGBP9p height=3D0 width=3D0> </iframe></BODY></HTML>
--====_ABC0987654321DEF_====--

--====_ABC1234567890DEF_====
Content-Type: audio/x-wav;
name="New_Napster_Site.MP3.pif"
Content-Transfer-Encoding: base64
Content-ID: <EA4DMGBP9p>

TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAA8AAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1v
ZGUuDQ0KJAAAAAAAAAAoxs1SbKejAWynowFsp6MBF7uvAWinowHvu60BbqejAYS4qQF2p6MBhLin
AW6nowEOuLABZaejAWynogHyp6MBhLioAWCnowHUoaUBbaejAVJpY2hsp6MBAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAUEUAAEwBAwCoIP47AAAAAAAAAADgAA8BCwEGAABwAAAAEAAAANAAAEBHAQAA
4AAAAFABAAAAQAAAEAAAAAIAAAQAAAAAAAAABAAAAAAAAAAAYAEAAAQAAAAAAAACAAAAAAAQAAAQ
AAAAABAAABAAAAAAAAAQAAAAAAAAAAAAAABkUAEAMAEAAABQAQBkAAAAAAAAAAAAAAAAAAAAAAAA

is there any potential danger to my server ? I almost had it with cc fraud and now this.

netsolutions
11-26-2001, 04:54 PM
This is the same virus everybody on WHT has been getting.

vegs
11-26-2001, 04:59 PM
does this mean that my server has been infected by this virus ?

RackMy.com
11-26-2001, 05:02 PM
Not unless you opened up the virus on your server.

netsolutions
11-26-2001, 05:05 PM
The virus is not a serious problem. All it does so far is send the email to everybody in your address book.

Dylan
11-27-2001, 12:28 AM
Viruses are starting to make me sick...

YET AGAIN, today I received another virus.

It tried to save itself to my pc and at the same time pretended that it wanted to make use of some image in my temporary internet files directory.

Which makes me worried, so I better be on my way and do a scan...

magnafix
11-27-2001, 12:03 PM
here's the virus info:

http://securityresponse.symantec.com/avcenter/venc/data/w32.badtrans.b@mm.html


We had one poor customer send it to us 5 times in under a minute.