Malicious Mailings and Virus Alert

Andy B

Bronze
Jan 1, 2002
774
0
0
www.elmarinique.com
Many of us have been recieving viruses on a fairly regular basis. However, myself and my webmaster began to notice a pattern in the ones we've recieved in the past 6 months. After a lot of tracing email headers, sometimes from infected messages being bounced all around the world in an attempt to hide the originator, we have discovered several perpertrators and they will be dealt with.

However it has also come to our attention that some people are sending viruses using our name (Hillbilly, remember the virus you recieved from me some time ago?) and accordingly we have posted the below statement on www.samananet

Statement:

September 01/2002 Samana D.R.
For over a year now, we at Samana Net have been receiving viruses that are being maliciously sent. We know some are a deliberate attempt to sabotage our computers and we have traced them back to several competing website operators.
They are being dealt with.
However, it has recently come to our attention that other people have been receiving attached viruses purportedly sent by our website?s business addresses: Comments, Sales, etc., all at Samana Net.
~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~. Be ADVISED that UNLESS you have INITIATED correspondence with us and are EXPECTING a reply, that we DID NOT send the message, and that the infected message is an atempt to DISCREDIT our reputation.
DO NOT open the attachement but SEND US a copy of the message?s HEADER information so that we may trace the origin of the perpertrator. ~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.~.
We regret that this has happened but in today?s cyberworld many unscrupulous persons exist and it?s become apparent that they will resort to anything including sending viruses, an international form of terrorism, in the pursuit of their warped objectives.
 
H

Hadrian

Guest
Andy

More likley than not, YOU ARE SENDING the virus. It is a simple matter for these idiots to send you a worm, then the worm gets into your address book and sends the mail FROM YOU. It actually comes from your computer and to people in your address book
 

Ken

Platinum
Jan 1, 2002
13,884
495
83
This has become a serious problem. Hackers these days have software that lets them send email that looks like it comes from anyone/any organization or business that they want it to.

For example, on a security board that I read regularly someone was complaining the other day that Hotmail was sending out viruses. To the uninitiated, the offending email looked exactly like it had been sent out by Hotmail. There have also been complains about email that supposedly was sent by Microsoft.

There are things in the header that give it away, and this is why Andy has requested you send it if you get something purportedly from his website that contains a virus.

But Andy, I think you should explain exactly what you want sent. Also, some people may have their email programs set up so the full header doesn't normally show. What should they do to give you the info you want?
computer012.gif
 

Hillbilly

Moderator
Jan 1, 2002
18,948
514
113
Thanks Andy. Appreciate the heads up!

I figure that you and your partner can handle this from here on.

HB ;)
 

Andy B

Bronze
Jan 1, 2002
774
0
0
www.elmarinique.com
Hadrian,
Our computers are clean and are protected by firewalls. And as a matter of course, we clean them at least once a week and check for worms, trojans, etc.
Also, the "sent from" addresses being used do not exist in our outgoing mail programs so we know they are bogus. And one other address being used is mostly only known by those that are real computer savy. The people we are dealing with are real pros. There are other things involved that led us to this; things I won't go into for obvious reasons.

To answer Ken's question: send us what info you can. Just copy and paste the header info that comes up under message properties. If you can't send all, that's OK. We appreciate all the help we can get.