PDA

View Full Version : Spybot fake email


mjc
July 23rd, 2003, 09:45 PM
From Mike at Spywareinfo......

-{ Quote: "It has come to my attention that someone using ntlworld.com ISP is distributing the bugbear virus from Spybot-S&D Support <spybotsd@aol.com> and signing the email as Patrick Kolla. The email is not addressed to anyone, so most likely any recipients are being BCCed (Blind Carbon Copy).

THIS EMAIL IS NOT FROM PATRICK KOLLA OR SPYBOT S&D. DON'T OPEN IT!

Below is the content of one such email in my posession. Given this, I cannot believe this to simply be some poor fool infected with the virus. At first glance, this seems to be a malicious attack, and we'll see what ntlworld has to say about one of their customers sending this out.

Normally I would bother sending a mailing about something like this. It happens to me, to Lavasoft, and to other companies all the time. This one looks convincing enough that I feel it necessary to warn everyone. Spread the word about this before people start getting infected.


Regards,

Mike Healan
http://www.spywareinfoforum.com/


-------------------------------------------------
From: Spybot-S&D Support <spybotsd@aol.com>
Subject: Your mail has been received...
Date: Wed, 23 Jul 2003 22:51:43 +0100

Dear Spybot-S&D user,

Due to the massive amount of mails I get each day, and a huge amount of mails already piled up, I cannot guarantee an immediate reply. I will reply to any mail that needs an answer, but please allow me a few days...
and for future questions, please keep in mind that you will most likely get faster support if you use the support forum.

Thanks for your patience!
Patrick Kolla


------------------------------------------------------------------------------" }-

JacK
July 24th, 2003, 06:45 AM
-{ Quote: " quoting: mjc link=board=18;threadid=11652;start=0#msg75360 date=1059011147]
From Mike at Spywareinfo......

-{ Quote: "It has come to my attention that someone using ntlworld.com ISP is distributing the bugbear virus from Spybot-S&D Support <spybotsd@aol.com> and signing the email as Patrick Kolla. The email is not addressed to anyone, so most likely any recipients are being BCCed (Blind Carbon Copy).

THIS EMAIL IS NOT FROM PATRICK KOLLA OR SPYBOT S&D. DON'T OPEN IT!

Below is the content of one such email in my posession. Given this, I cannot believe this to simply be some poor fool infected with the virus. At first glance, this seems to be a malicious attack, and we'll see what ntlworld has to say about one of their customers sending this out.

Normally I would bother sending a mailing about something like this. It happens to me, to Lavasoft, and to other companies all the time. This one looks convincing enough that I feel it necessary to warn everyone. Spread the word about this before people start getting infected.


Regards,

Mike Healan
http://www.spywareinfoforum.com/


-------------------------------------------------
From: Spybot-S&D Support <spybotsd@aol.com>
Subject: Your mail has been received...
Date: Wed, 23 Jul 2003 22:51:43 +0100

Dear Spybot-S&D user,

Due to the massive amount of mails I get each day, and a huge amount of mails already piled up, I cannot guarantee an immediate reply. I will reply to any mail that needs an answer, but please allow me a few days...
and for future questions, please keep in mind that you will most likely get faster support if you use the support forum.

Thanks for your patience!
Patrick Kolla


------------------------------------------------------------------------------" }-
" }-


Hello,

It's a well known fact that Bugbear and other worm may send a mail from an infected machine using an addy from its contacts AND with a message token from its messages or another file from the infected machine, adding or not the virus.

Furthermore it's no P. Kolas' addy but a false addy made
from 2 or different addies like a lot of worms proceed :

aaaa@bbbb.ccc
dddd@eeee.fff
gggg@hhhh.kkk
permit the worm to sentd a message with the addy
dddd@bbb.ccc for instance

At second glance, it does not look like a malicious attack ;)

Rgds,