• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Spam / Spyware / Return Mail -- HELP!

Syndacate

Weaksauce
Joined
Mar 5, 2009
Messages
93
Hey,

My dad is getting these reply messages, such as 'no such recipient', 'auto reply..', 'mail delivery failure', etc.

I don't do IT, but I'm trying to help him the best I can.

The frequency is EXTREMELY high for a personal system behind a router, about 5 e-mails every 1/2 day.

AVG, Spybot, and Malwarebytes' anti-malware all showed up nothing.

Also enabled (it's typically disabled) ZA FW, it did NOT detect any outbound connections from untrusted sources.

Also, appears to be no unknown processes running, though if it's running under an svchost or something then it obviously won't be recognized.

I believe these are ACTUAL mail replies, but I DON'T think they're being sent by his computer. I turned off his computer for a night (usually he leaves it on), and the frequency was left unchanged, the same number of failures or auto-replies were in his inbox when I booted it back up in the morning. This leads me to believe that there's not an actual virus with an SMTP client which is sending e-mails.

I changed his e-mail password, and this appeared to fix it for the day, but the problem came back today. Though I did do this on New Year's Eve so it's very possible there was no correlation between the password change and the disruption of the flow of failures.

This leads me to one of 3 conclusions:
1) There's a virus on his computer which is sending the e-mail password (doubt it's a key logger, it would have to be taking it out of Thunderbird).
2) Spoofs
2a) Somebody's sending e-mails which are spoofed to be FROM him, even though they're not
2b) Somebody's actually sending the e-mail failures (spoofed) TO him.
Note: Never actually got a reply from the recipients, just failures (for variety of reasons including e-mail not existing) or out of office replies.

**

I don't believe the problem is an actual virus on his computer, but I could be wrong. Either way, I am unable to format his system as I don't have the time and he doesn't have the down-time. The system is seemingly snappy and clean, this isn't one of those systems bogged down with malware/spyware.

Any thoughts?
 
can you post the full headers of a bounce message? Edit out his email address so its not displayed in the forum
 
2a) Somebody's sending e-mails which are spoofed to be FROM him, even though they're not
That would be my best guess. His addy was in someone's contact list, their Outlook/Hotmail or whatever got hit with a virus that harvested their contacts. Spammers often spoof the "from" field, and that person gets all the bounced emails.
 
I thought it was 'backscatter' also (before I knew what the name was, lol), but it really made me wonder if these were just the failures, then it had to be sending TONS out...and if this was the case, how did ONE person not respond to ANY of them? ALL of their spam filters got them? Just seems a bit weird to me, y'know?

I'll post the e-mail headers up later today, when he e-mails them to me.
 
I had a customer who was getting hundreds of these. Turns out they were using a very basic email password. I changed it to something complex and within 6 hours it all had stopped.
 
I thought it was 'backscatter' also (before I knew what the name was, lol), but it really made me wonder if these were just the failures, then it had to be sending TONS out...and if this was the case, how did ONE person not respond to ANY of them? ALL of their spam filters got them? Just seems a bit weird to me, y'know?

I'll post the e-mail headers up later today, when he e-mails them to me.

a lot of times, the reply-to address is different from the from address; so even if they did reply, the reply would be sent elsewhere; unless they either did a reply all or took the time to change the reply to address to the from address (both of which are pretty unlikely)
 
I had a customer who was getting hundreds of these. Turns out they were using a very basic email password. I changed it to something complex and within 6 hours it all had stopped.

Yeah, I'm not sure if that's the case and he has some spyware, or what.

At one point I changed his PW and it seemed the e-mails ceased (few trickled through)..but they started back about 12-24 hours later. I'm not sure if that's indicative that there's a virus on his computer that's sending the PW once it's changed...but I would have no idea how it's even getting the new password? I mean I'm assuming T-bird encrypts it at some level, but I suppose it can be overridden with the right tool? I just have a hard time believing there's something on his computer, and nothing picked it up (unless it's a root kit, obviously). I just really don't have the time to format on a hunch.

I changed his password at a bad time, right around the new year, so it's hard to pin point the reasoning behind the slow-down of failure messages.

a lot of times, the reply-to address is different from the from address; so even if they did reply, the reply would be sent elsewhere; unless they either did a reply all or took the time to change the reply to address to the from address (both of which are pretty unlikely)

That's a good point, yeah, they're typically different in any kind of scam e-mail.

------------------------------

So here's some sample kick-back messages, these ones ironically don't say delivery failure...and he already erased all the other ones.. These are the same deal, flooding in in like packs of 5:

The first 2 are similar to each other, the last 2 are similar to each other, but a bit less similar to the first 2..

I'm sorry these 4 sample headers are such shitty examples, just had to work with whatever my dad had at the moment. Let me know if there's any more info I can grab? I told my dad to grab these by (in thunderbird) going to "view" >> "message header" >> "all" and copy/paste it all. I'm not sure if there's more data I can get him to snag? I know in gmail if you click "show original" you get a lot more info and it's typically more detailed than this IIRC.

Any thoughts?

*****************************1*******************************

Delivery to the following recipients was aborted after 0 second(s):

* dolly.kaur@longandfoster.com

Reporting-MTA: dns; qmta15.emeryville.ca.mail.comcast.net [76.96.27.228]
Received-From-MTA: dns; omta18.emeryville.ca.mail.comcast.net [76.96.30.74]
Arrival-Date: Tue, 03 Jan 2012 11:33:17 +0000

Final-recipient: rfc822; dolly.kaur@longandfoster.com
Action: failed
Status: 5.1.1
Diagnostic-Code: smtp; 550 5.1.1 <dolly.kaur@longandfoster.com>: Recipient
address rejected: User unknown in relay recipient table
Last-attempt-Date: Tue, 03 Jan 2012 11:33:17 +0000

Part 1.2

Subject: Bank of America ALERT
From: <Dad's e-mail>
Date: 1/3/2012 6:25 AM
To: maltster@hotmail.com
Received: from omta18.emeryville.ca.mail.comcast.net ([76.96.30.74]) by
qmta15.emeryville.ca.mail.comcast.net with comcast id GzZF1i0031bwxycAFzZHsP;
Tue, 03 Jan 2012 11:33:17 +0000
Received: from servidor ([213.195.80.69]) by omta18.emeryville.ca.mail.comcast.net
with comcast id H0Da1i00A1VjtbH8e0Dmhw; Tue, 03 Jan 2012 12:14:45 +0000
X-Authority-Analysis: v=2.0 cv=e6GEuNV/ c=1 sm=1
a=aTMyUTMlAiHJ3qSzu2J0Jg==:17 a=Qn4S1PuXAAAA:20a=ZqjGJahZpRnvyZOH0aUA:9 a=x-DJcopou5kA:10 a=ddZT45GQ4RAA:10
a=aTMyUTMlAiHJ3qSzu2J0Jg==:117
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-Mailer: MIME-tools 5.41 (Entity 5.404)
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html
Message-ID: <CHILKAT-MID-155e7d59-6337-6326-3170-
eba6918bafb0@servidor>

*****************************2*******************************

Delivery to the following recipients was aborted after 1 second(s):

* danastott@ameritech.net

Reporting-MTA: dns; qmta13.emeryville.ca.mail.comcast.net [76.96.27.243]
Received-From-MTA: dns; omta18.emeryville.ca.mail.comcast.net [76.96.30.74]
Arrival-Date: Tue, 03 Jan 2012 11:33:17 +0000

Final-recipient: rfc822; danastott@ameritech.net
Action: failed
Status: 5.1.1
Diagnostic-Code: smtp; 550 5.2.1 <danastott@ameritech.net>... Addressee
unknown, relay=[76.96.27.243]
Last-attempt-Date: Tue, 03 Jan 2012 11:33:18 +0000

Part 1.2

Subject: Bank of America ALERT
From: <Dad's e-mail>
Date: 1/3/2012 6:25 AM
To: maltster@hotmail.com
Received: from omta18.emeryville.ca.mail.comcast.net ([76.96.30.74]) by
qmta13.emeryville.ca.mail.comcast.net with comcast id GzZ91i0021bwxycADzZHn9;
Tue, 03 Jan 2012 11:33:17 +0000
Received: from servidor ([213.195.80.69]) by omta18.emeryville.ca.mail.comcast.net
with comcast id H0Da1i00A1VjtbH8e0Dmhw; Tue, 03 Jan 2012 12:14:45 +0000
X-Authority-Analysis: v=2.0 cv=e6GEuNV/ c=1 sm=1
a=aTMyUTMlAiHJ3qSzu2J0Jg==:17
a=Qn4S1PuXAAAA:20
a=aTMyUTMlAiHJ3qSzu2J0Jg==:117
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-Mailer: MIME-tools 5.41 (Entity 5.404)
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html
Message-ID: <CHILKAT-MID-155e7d59-6337-6326-3170-
eba6918bafb0@servidor>

*****************************3*******************************

Delivery to the following recipients was aborted after 2 second(s):

* medina.157@**************

Reporting-MTA: dns; qmta10.westchester.pa.mail.comcast.net [76.96.62.17]
Received-From-MTA: dns; omta13.westchester.pa.mail.comcast.net [76.96.62.52]
Arrival-Date: Tue, 03 Jan 2012 11:11:02 +0000

Final-recipient: rfc822; medina.157@**************
Action: failed
Status: 5.1.1
Diagnostic-Code: smtp; 550 spam message discarded. Please visit http://**************
/notspam/abuse?c=4_t0EhO80-xNy5eUJSvbqiThv4x_o46IAQAAAAsFAADIvlYi
or report details to abuse@corp.**************. Error code:
1274FBE3ECD3BC139497CB4DAADB2B258CBFE124888EA37F. ID:
000000010000050B2256BEC8.
Last-attempt-Date: Tue, 03 Jan 2012 11:11:04 +0000

Part 1.2

Subject: Bank of America: Account ALERT
From: <Dad's e-mail>
Date: 1/3/2012 6:09 AM
To: product-price-approvals@exgate.tek.com
Received: from omta13.westchester.pa.mail.comcast.net ([76.96.62.52]) by
qmta10.westchester.pa.mail.comcast.net with comcast id
Gz9w1i00317dt5G5AzB2R5; Tue, 03 Jan 2012 11:11:02 +0000
Received: from SERVER2.ESMCableCorp.local ([209.177.118.198]) by
omta13.westchester.pa.mail.comcast.net with comcast id
Gz9o1i00G4Gv7ex3Zz9ve5; Tue, 03 Jan 2012 11:10:57 +0000
X-Authority-Analysis: v=2.0 cv=NaZkJh/4 c=1 sm=1
a=y0NBxINholcsVXsKlsxcKQ==:17 a=cO_51YjEJhIA:10 a=5o-MDfasAAAA:20
a=UFcCHFYm0BThTzs6MUsA:9 a=IwwMhL2HAQcA:10 a=ddZT45GQ4RAA:10
a=y0NBxINholcsVXsKlsxcKQ==:117
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-Mailer: Ximian Evolution 1.0.3 (1.0.3-6)
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html
Message-ID: <CHILKAT-MID-a2242501-e3b7-8bce-
1051-7a37f12f0b72@SERVER2.ESMCableCorp.local>

*****************************4*******************************

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients was aborted after 1 second(s):

* aziza_91@**************

Reporting-MTA: dns; qmta04.emeryville.ca.mail.comcast.net [76.96.30.40]
Received-From-MTA: dns; omta12.emeryville.ca.mail.comcast.net [76.96.30.44]
Arrival-Date: Tue, 03 Jan 2012 10:45:07 +0000

Final-recipient: rfc822; aziza_91@**************
Action: failed
Status: 5.1.1
Diagnostic-Code: smtp; 550 spam message rejected. Please visit http://**************
/notspam/abuse?c=BH2A2r5J6MWGme-Cu9PchLP2PsRWV6vxLiPCT3F5-
ssFAAAADAUAAPfdshk~ or report details to abuse@corp.**************. Error code:
DA807D04C5E849BE82EF998684DCD3BBC43EF6B3F1AB57564FC2232ECBFA7971.
ID: 000000050000050C19B2DDF7.
Last-attempt-Date: Tue, 03 Jan 2012 10:45:08 +0000

Part 1.2

Subject: Bank of America: Bill payment canceled
From: <Dad's e-mail>
Date: 1/3/2012 5:36 AM
To: dsmith25@apria.com
Received: from omta12.emeryville.ca.mail.comcast.net ([76.96.30.44]) by
qmta04.emeryville.ca.mail.comcast.net with comcast id GyjZ1i0020x6nqcA4yl7B0;
Tue, 03 Jan 2012 10:45:07 +0000
Received: from y0155bo3p51s5s0 ([155.230.118.71]) by
omta12.emeryville.ca.mail.comcast.net with comcast id Gyke1i00D1YWoWK8YykksS;
Tue, 03 Jan 2012 10:45:47 +0000
X-Authority-Analysis: v=2.0 cv=ac7jbGUt c=1 sm=1
a=oCkBwt33jbiDXEvKuometg==:17 a=lypCBnzNWqAA:10 a=pZOWd8nwAAAA:20
a=UFcCHFYm0BThTzs6MUsA:9 a=0QUXR68DQycA:10 a=ddZT45GQ4RAA:10
a=oCkBwt33jbiDXEvKuometg==:117
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-Mailer: The Bat! (v2.00.9) Personal
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html
Message-ID: <CHILKAT-MID-df835175-90c4-0346-4d0c-
89c458103423@y0155bo3p51s5s0>
 
infected hosts spoofing from address

Received: from servidor ([213.195.80.69]) by omta18.emeryville.ca.mail.comcast.net
with comcast id H0Da1i00A1VjtbH8e0Dmhw;


Received: from servidor ([213.195.80.69]) by omta18.emeryville.ca.mail.comcast.net
with comcast id H0Da1i00A1VjtbH8e0Dmhw;


Received: from SERVER2.ESMCableCorp.local ([209.177.118.198]) by
omta13.westchester.pa.mail.comcast.net with comcast id
Gz9o1i00G4Gv7ex3Zz9ve5;


Received: from y0155bo3p51s5s0 ([155.230.118.71]) by
omta12.emeryville.ca.mail.comcast.net with comcast id Gyke1i00D1YWoWK8YykksS

213.195.80.69 (servidor), 209.177.118.198 (SERVER2.ESMCableCorp.local), and 155.230.118.71 (y0155bo3p51s5s0) were the actual senders of the emails.

213.195.80.69 = Spain
209.177.118.198 = US, apparently belonging to ESM Cable Corp (their Exchange server, most likely)
155.230.118.71 = South Korea
 
email one originated San Sebastian spain
email two originated San Sebastian spain
email three originated from Patterson California
email four originated frim Daegu Korea

so all spoofed with your dads email as the return sender
 
infected hosts spoofing from address



213.195.80.69 (servidor), 209.177.118.198 (SERVER2.ESMCableCorp.local), and 155.230.118.71 (y0155bo3p51s5s0) were the actual senders of the emails.

213.195.80.69 = Spain
209.177.118.198 = US, apparently belonging to ESM Cable Corp (their Exchange server, most likely)
155.230.118.71 = South Korea

email one originated San Sebastian spain
email two originated San Sebastian spain
email three originated from Patterson California
email four originated frim Daegu Korea

so all spoofed with your dads email as the return sender

So in other words, my dad's computer is fine..but his e-mail is pretty much hosed?

My dad doesn't know anybody in SK or Spain. So it's just a mass distributed phishing attack?

It seems like somebody on his contacts list got harvested - though I would have thought that their computers would be used to send e-mail from. So what would your guy's best bet of what it means?

My dad sent me another sample today, things such as the 'authentication results' worry me, should it? This one looks quite a bit different.

I'd love if this could be narrowed down to some possible contacts, so maybe they can have their computers checked out..you think the one in Cali is real? Think he has a friend out in SF. Though if it's not being sent from their computer there's not much that can be done.

Any thoughts?


This Message was undeliverable due to the following reason:

Your message was not delivered because the destination computer was
not reachable within the allowed queue period. The amount of time
a message is queued before it is returned depends on local configura-
tion parameters.

Most likely there is a network problem that prevented delivery, but
it is also possible that the computer is turned off, or does not
have a mail system running right now.

Your message was not delivered within 4 days and 0 hours.
Host rawgonzo.com is not responding.

The following recipients did not receive this message:

<g4s@rawgonzo.com>

The following websites may contain more information to assist you:

http://help.rr.com/HMSLogic/rrmail.aspx

http://postmaster.rr.com/help

Please do not reply to this message, as it will go to an unread
mailbox

Reporting-MTA: dns; hrndva-qmta03.mail.rr.com
Arrival-Date: Fri, 30 Dec 2011 11:28:51 +0000
Received-From-MTA: dns; hrndva-omtalb.mail.rr.com (10.128.143.53)

Final-Recipient: RFC822; <g4s@rawgonzo.com>
Action: failed
Status: 4.4.7
Remote-MTA: dns; rawgonzo.com
Subject: Stock market nightmare: E-trade Bankruptcy
From: <Dad's E-mail>
Date: 12/30/2011 6:30 AM
To: g4s@rawgonzo.com
Received: from hrndva-omtalb.mail.rr.com ([10.128.143.53]) by hrndva-
qmta02.mail.rr.com with ESMTP id <20111230112851464.HHH1596@hrndva-
qmta02.mail.rr.com> for <g4s@rawgonzo.com>; Fri, 30 Dec 2011 11:28:51 +0000
Received: from [79.48.12.183] ([79.48.12.183:3835] helo=SERVER) by hrndva-
oedge03.mail.rr.com (envelope-from <Dad's E-mail>) (ecelerity 2.2.3.46
r()) with ESMTPA id BF/4A-19860-430ADFE4; Fri, 30 Dec 2011 11:27:51 +0000
Return-Path: <Dad's E-mail>
Authentication-Results: hrndva-omtalb.mail.rr.com smtp.user=<Dad's E-mail>; auth=pass (LOGIN)
X-Authority-Analysis: v=2.0 cv=A5HuztqG c=1 sm=0
a=ymllauddMci9HA5L74Ik3g==:17 a=xYDu3fk1IMAA:10 a=hSvIvFAFAAAA:20
a=UFcCHFYm0BThTzs6MUsA:9 a=RZYaz6t7CNYA:10 a=ddZT45GQ4RAA:10
a=ymllauddMci9HA5L74Ik3g==:117
X-Cloudmark-Score: 0
X-Originating-IP: 79.48.12.183
MIME-Version: 1.0
X-Priority: 3 (Normal)
X-Mailer: Pegasus Mail for Win32 (v3.12c)
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html
Message-ID: <CHILKAT-MID-5da4e9cd-0d59-b1f4-
b8f9-89c40af3d73a@SERVER>

Read more about alerts
 
Received: from [79.48.12.183] ([79.48.12.183:3835] helo=SERVER) by hrndva-
oedge03.mail.rr.com (envelope-from <Dad's E-mail>) (ecelerity 2.2.3.46
r()) with ESMTPA id BF/4A-19860-430ADFE4; Fri, 30 Dec 2011 11:27:51 +0000


that one was sent frrom Italy.
most likely what happend is somebody who has your dad's email address in their address book got infected, and it harvested the emails frrom that address book.

even cleaning that particular computer up now would do no good, as the address is already in the spambots' database.
 
Received: from [79.48.12.183] ([79.48.12.183:3835] helo=SERVER) by hrndva-
oedge03.mail.rr.com (envelope-from <Dad's E-mail>) (ecelerity 2.2.3.46
r()) with ESMTPA id BF/4A-19860-430ADFE4; Fri, 30 Dec 2011 11:27:51 +0000


that one was sent frrom Italy.
most likely what happend is somebody who has your dad's email address in their address book got infected, and it harvested the emails frrom that address book.

even cleaning that particular computer up now would do no good, as the address is already in the spambots' database.

Okay, that's what I was getting at. I was wondering if since it was harvested, and sent back to a 'central' db of addresses, then any cleaning up at this point on their end. Opposed to one of my dad's friends being on the bot-net and their computer being 'fixable' or not..
 
Back
Top