I mentioned in an earlier email reporting dodgy emails. I received this today and post it to show how easy it is to deliver a trojan onto your system. It took me around 2 minutes to track the sender IP address and find a host address to report the sender. This network owner (Virginia Tech in the US) has a good IT backroom and I received an Incident Response immediately. Satisfying I will help catch the culprit or make him/her a better programmer.
The suspect IP address is highlighted in
red bold.
I have edited the header to reduce size and take out identifying info. Read from Top down, the email is right at the bottom and the link has been replaced with a dummy.
Use a site like this one (
Registration Services - Whois) to locate your sender network and an email address to report abuse.
Incident INC0116245 has been opened on your behalf.
[TABLE="align: center"]
[TR]
[TD]
Category:[/TD]
[TD]
Inquiry / Help[/TD]
[TD]
Subcategory:[/TD]
[TD][/TD]
[/TR]
[TR]
[TD]
Assignment Group:[/TD]
[TD]
ABUSE[/TD]
[TD]
Assigned to:[/TD]
[TD][/TD]
[/TR]
[TR]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[/TR]
[TR]
[TD]
Caller:[/TD]
[TD]
Guest[/TD]
[TD]
Caller Email:[/TD]
[TD]
prozac@xx_xx_x.com.au[/TD]
[/TR]
[TR]
[TD][/TD]
[TD][/TD]
[TD]
Phone:[/TD]
[TD][/TD]
[/TR]
[TR]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[/TR]
[TR]
[TD]
Opened by:[/TD]
[TD]
Guest[/TD]
[TD]
Open time:[/TD]
[TD]
04-24-2016 09:25:49 PM EDT[/TD]
[/TR]
[TR]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[TD][/TD]
[/TR]
[TR]
[TD="colspan: 4"]
Short description: Fwd: 2 new eDocs[/TD]
[/TR]
[/TABLE]
04-24-2016 09:25:49 PM EDT - Guest
forwarded by: prozac@xx_x.com.au
Please find below Abuse email sent via your network (*128.173.172.170*).
See directly below the email Header.
Regards
prozac@xx_xx.com.au
_*HEADER*_
From - Mon Apr 25 06:39:53 2016
X-Account-Key: account1etc
etc
Received: from outbound.smtp.vt.edu (HELO omr2.cc.vt.edu) ([23.23.123.123
I have changed this IP address])
by mx03.syd.iprimus.net.au with ESMTP; 25 Apr 2016 01:00:17 +1000
Received: from mr5.cc.vt.edu (mr5.cc.ipv6.vt.edu [IPv6:2001:468:c80:2105:0:2b8:b328:9234])
by omr2.cc.vt.edu (8.14.4/8.14.4) with ESMTP id u3OExB2j003207;
Sun, 24 Apr 2016 10:59:11 -0400
Received: from [10.22.1.216] (apps2.pamplin.vt.edu [*
128.173.172.170*])
by mr5.cc.vt.edu (8.14.4/8.14.4) with ESMTP id u3OEtwpo020106;
Sun, 24 Apr 2016 10:59:11 -0400
Message-Id: <
[email protected]>
Content-Type: multipart/alternative; boundary="===============1065067583=="
MIME-Version: 1.0
Subject: 2 new eDocs
To: - <
[email protected]>
From: "Barclays plc." <
[email protected]>
Date: Sun, 24 Apr 2016 10:59:37 -0400
X-Spam-Status: No, score=1.2 required=5.0 tests=DATE_IN_FUTURE_48_96,
HELO_MISC_IP,HTML_MESSAGE,MISSING_MID autolearn=disabled version=3.3.1
X-Spam-Level: *
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on mr5.cc.vt.edu
X-Antivirus: AVG for E-mail 2016.0.7539 [4556/12092]
X-AVG-ID: ID76339489-6F4AC6EFYou will not see this in a MIME-aware mail reader.
--===============1065067583==
-------- Forwarded Message --------
Subject: 2 new eDocs
Date: Sun, 24 Apr 2016 10:59:37 -0400
From: Barclays plc. <
[email protected]>
To: - <
[email protected]>
You have 2 new Secure eDocs on your cloud storage.
VIEW HERE.
BarclaysCloud-It.