Author Topic: Phishing?  (Read 1811 times)

Offline Gregg

  • TS Addict
  • *****
  • Posts: 11748
    • View Profile
    • http://
Phishing?
« on: August 19, 2008, 06:42:44 AM »
My Inbox had a message called:

QUOTE
Subject:     Delivery Status Notification (Failure)

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

ates@nationalticket.com



This was followed by some gobbledy goop, and then:

QUOTE
Paris Hilton Paparazzi & Glamour
About this mailing:
You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the "Unsubscribe" link below. This will not unsubscribe you from e-mail communications from third-party advertisers that may appear in MSN Feature Offers. This shall not constitute an offer by MSN. MSN shall not be responsible or liable for the advertisers' content nor any of the goods or serviceadvertised. Prices and item availability subject to change without notice.

©2008 Microsoft | Unsubscribe | More Newsletters | Privacy

Microsoft Corporation, One Microsoft Way, Redmond, WA 98052


The underlined items were links in the e-mail. The first one was large and in color. It's just text here.

I just deleted the whole thing. Not following those links. No way!

Of course, there is not an e-mail in my Sent box to the address contained in this "notice".
« Last Edit: August 19, 2008, 06:51:43 AM by Gregg »
Ya gotta applaud those bunnies for sacrificing their hearing just so some guy in Cupertino can have better TV reception.

Offline Paddy

  • Administrator
  • TS Addict
  • *****
  • Posts: 13797
    • View Profile
    • https://www.paddyduncan.com
Phishing?
« Reply #1 on: August 19, 2008, 10:15:59 AM »
nationalticket.com is on a spam blacklist I found via Google.

The only way to see where the links actually lead would be to look at the source code (no harm in that).

Not phishing - just spamming and hoping to hook "live" ones when you hit the unsubscribe link, no doubt!
« Last Edit: August 19, 2008, 10:16:30 AM by Paddy »
"If computers get too powerful, we can organize them into committees. That'll do them in." ~Author unknown •iMac 5K, 27" 3.6Ghz i9 (2019) • 16" M1 MBP(2021) • 9.7" iPad Pro • iPhone 13

Offline chriskleeman

  • Administrator
  • TS Addict
  • *****
  • Posts: 2255
    • View Profile
    • http://www.chriskleeman.com
Phishing?
« Reply #2 on: August 20, 2008, 09:14:37 AM »
Hi Gregg,

I've been getting similar messages about all kinds of stuff, from Paris Hilton Nude Videos to body parts I don't care to modify from these guys... I blacklisted them on my spam filter and so far, after a few days, I'm not getting these any more... but it's always that same stuff...

QUOTE
You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your privacy. If you do not wish to receive this MSN Featured Offers e-mail, please click the "Unsubscribe" link below. This will not unsubscribe you from e-mail communications from third-party advertisers that may appear in MSN Feature Offers. This shall not constitute an offer by MSN. MSN shall not be responsible or liable for the advertisers' content nor any of the goods or serviceadvertised. Prices and item availability subject to change without notice.


So, yes, delete, delete, delete!

Chris K whistling.gif

Just a dumb guitar player...
My Website

Offline tacit

  • TS Addict
  • *****
  • Posts: 1628
    • View Profile
    • http://www.xeromag.com/
Phishing?
« Reply #3 on: August 20, 2008, 10:32:40 AM »
These aren't spam. They are attempts to download computer viruses.

The Russian Zlob gang has been spending a gret deal of time and effort on this distribution technique lately. Here's how it works:

1. They find Web sites with weak security--usually poor FTP passwords. They do this by using automated software tht scans tens of thousands of IP addresses an our trying the most common FTP usernames and passwords.

2. Once they've broken into a Web site, they upload an exe file (the virus itself) and a Web page that downloads the virus disguised as movie player software. The Web site has what looks like CNN, Time.com, or MSNBC logos on it, and what looks like a movie. If you try to play the "movie," a message tells you that your computer's Flash movie player software is outdated and you won't be able to play the movie until you install the update (which is, of course, the virus).

3. They send out millions of spam messages advertising this "news story," with a link that leads to the page they have placed on the hacked site. The spam messages are sent to addresses harvested from other Web sites, and are also sent with "From:" addresses harvested from Web sites. That way, if a spam message bounces, there is a chance that the bounce will go to a real person.

You got that email because the virus writers forged your address as the "from" address of the spam. It bounced, so it came back to you.

Nationalticket.com is not a spammer. They have been blacklisted because their Web site has been hacked and a virus has been placed on it. The same thing has happened to a very large number of high-profile, big-name Web sites that ought to know better lately, including Delta Airlines.
A whole lot about me: www.xeromag.com/franklin.html

Offline Gregg

  • TS Addict
  • *****
  • Posts: 11748
    • View Profile
    • http://
Phishing?
« Reply #4 on: August 20, 2008, 06:14:12 PM »
A succinct explanation, as usual. So they use "spam" to spread a virus. Just hope there's no E. coli in the can. wink.gif

And yes, it looked very polished and "official", but the message was a dead giveaway.
Ya gotta applaud those bunnies for sacrificing their hearing just so some guy in Cupertino can have better TV reception.

Offline chriskleeman

  • Administrator
  • TS Addict
  • *****
  • Posts: 2255
    • View Profile
    • http://www.chriskleeman.com
Phishing?
« Reply #5 on: August 21, 2008, 12:08:09 AM »
Thanks Tacit, great to know what's really going on here! notworthy.gif

It's amazing how much stuff like this goes on without many folks paying any attention to it.

Thanks for your vigilance!

Chris K salute.gif
Just a dumb guitar player...
My Website