Har fået 3 mails fra mig selv med virus
Hejjeg kører med argosoft mail server og i dag har jeg fået 3 mails med virus i.
De er modtaget af serveren fra IP:80.162.216.3 og indholdet lyder:
1.
Dear user of e-mail server "Klaverportalen.dk",
Your e-mail account has been temporary disabled because of unauthorized access.
Please, read the attach for further details.
Attached file protected with the password for security reasons. Password is 87074.
Sincerely,
The Klaverportalen.dk team http://www.klaverportalen.dk
2.
Dear user of e-mail server "Klaverportalen.dk",
We warn you about some attacks on your e-mail account. Your computer may contain viruses, in order to keep your computer and e-mail account safe, please, follow the instructions.
For further details see the attach.
For security purposes the attached file is password protected. Password is "87074".
Best wishes,
The Klaverportalen.dk team http://www.klaverportalen.dk
Når jeg så åbner zip-filen og indtaster koden er der så en exe-fil. denne scanner jeg med avg og ganske rigtigt var dette selve virusen..
Umiddel kommer IP'en iflg dk-hostmaster fra:
3.216.162.80.in-addr.arpa 2714 PTR 50A2D803.flatrate.dk
www.flatrate.dk giver ingenting så jeg undrer mig lidt over hvem det er der er sjov ???
Internet headeren lyder:
Received: from [80.162.216.3] by mic-lab
(ArGoSoft Mail Server Pro for WinNT/2000/XP, Version 1.8 (1.8.3.6)); Mon, 13 Dec 2004 09:41:58 +0100
Date: Thu, 13 Dec 2001 09:45:04 +0100
To: michael@klaverportalen.dk
Subject: Notify about your e-mail account utilization.
From: staff@klaverportalen.dk
Message-ID: <ojmllqojjmvoxpltxrt@klaverportalen.dk>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------ggkgtnwajgrdbqiurtnw"
