Almost caught me out.
Posted by: Roy T on 01 November 2004
This morning an email hove into view and the subject line looked almost right for the text returned by the system because an email could not be delivered. Almost right but not quite right enough for me to click on it without thinking but right enough to sail through the mailsystem spam filters. As I run Mozilla FireFox configured not to download anything without my say so I though I'd just have a quick peek inside.
As you can see the text looked about right but according to whois 116.237.138.83 is
and the email contained a file called "letter.zip" a sure sign that it is something not very nice.
I then downloaded the zip onto my desktop and when examined by AVG it contained a copy of I-worm / mydoom.n so a quite clever attack thay failed and one of the very few I thought might be a false positive and I was right.
=========
Date: Sun, 31 Oct 2004 19:02:08 -0600
From: Automatic Email Delivery Software <MAILER-DAEMON@******.com>
[ Add to Address Book | Block Address | Report as Spam ]
To: <******@******.com>
Subject: Mail System Error - Returned Mail
This Message was undeliverable due to the following reason:
Your message was not delivered because the destination computer was
not reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.
Your message was not delivered within 6 days:
Host 116.237.138.83 is not responding.
The following recipients did not receive this message:
<******@******.com>
Please reply to postmaster@******.com
if you feel this message to be in error.
=======
As you can see the text looked about right but according to whois 116.237.138.83 is
quote:
Server Used: [ none ] ERROR: IP Range Reserved by IANA.org
and the email contained a file called "letter.zip" a sure sign that it is something not very nice.
I then downloaded the zip onto my desktop and when examined by AVG it contained a copy of I-worm / mydoom.n so a quite clever attack thay failed and one of the very few I thought might be a false positive and I was right.
=========
Date: Sun, 31 Oct 2004 19:02:08 -0600
From: Automatic Email Delivery Software <MAILER-DAEMON@******.com>
[ Add to Address Book | Block Address | Report as Spam ]
To: <******@******.com>
Subject: Mail System Error - Returned Mail
This Message was undeliverable due to the following reason:
Your message was not delivered because the destination computer was
not reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.
Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.
Your message was not delivered within 6 days:
Host 116.237.138.83 is not responding.
The following recipients did not receive this message:
<******@******.com>
Please reply to postmaster@******.com
if you feel this message to be in error.
=======