Odd activity in mail - anyone else?? - ehMac.ca
Facebook
Twitter
YouTube
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read


Reply
 
LinkBack Thread Tools Display Modes
Old Feb 7th, 2004, 09:27 PM   #1
Assured Advertiser
Honourable Citizen
 
MacDoc's Avatar
 
Join Date: Nov 2001
Location: Planet Earth.....on FASTER boil :-(
Posts: 30,604
Question

I sent this note off to our hosting site about the continuous messages we've been receiving about undeliverable mail. Anyone else seeing this activity.
••••••

to Verio tech support

"I am continually receiving notification of these undeliverable messages that purport to originate from our macdoc.com domain.

The names are always simple first names and sent towards other addresses also with simple first names and a domain. None of these names are legitimate macdoc addresses

This appears to be some sort of unauthorized activity and would like it controlled.
These are arriving every few minutes.

I have now set the spam filter up to intercept them but I would like an explanation as to the nature and origin.
We are an entirely Mac based setup here and 99% of our clients are as well so I can only think it is something occurring at the server end."

typical messages - they all had two attachments - a report and a .zip file
••••••
Forwarded Message
From: MAILER-DAEMON@cmlapp400.van.ca.siteprotect.com Mail Delivery System)
Date: Sat, 7 Feb 2004 18:51:17 -0600 CST)
To: peter@macdoc.com
Subject: Undelivered Mail Returned to Sender

This is the Postfix program at host cmlapp400.van.ca.siteprotect.com.

I'm sorry to have to inform you that the message returned
below could not be delivered to one or more destinations.

For further assistance, please send mail to <postmaster>

If you do so, please include this problem report. You can
delete your own text from the message returned below.

The Postfix program

<alex@summitdirect.com>: unknown user: "alex@summitdirect.com"


Reporting-MTA: dns; cmlapp400.van.ca.siteprotect.com
Arrival-Date: Sat, 7 Feb 2004 18:51:17 -0600 CST)

Final-Recipient: rfc822; alex@summitdirect.com
Action: failed
Status: 5.0.0
Diagnostic-Code: X-Postfix; unknown user: "alex@summitdirect.com"


From: peter@macdoc.com
Date: Sat, 7 Feb 2004 19:33:25 -0500
To: alex@summitdirect.com
Subject: Test

------ End of Forwarded Message

••••••

This is an automatically generated Delivery Status Notification.

Delivery to the following recipients failed.

george@lbcc.edu



Reporting-MTA: dns;prometheus.lbccd.lbcc.cc.ca.us
Received-From-MTA: dns;macdoc.com
Arrival-Date: Sat, 7 Feb 2004 17:55:10 -0800

Final-Recipient: rfc822;george@lbcc.edu
Action: failed
Status: 5.1.1


From: george@macdoc.com
Date: Sat, 7 Feb 2004 20:36:16 -0500
To: george@lbcc.edu
Subject: Hi

The message contains Unicode characters and has been sent as a binary attachment.
•••••

The original message was received at Sat, 7 Feb 2004 16:20:36 -0500 EST)
from uucp@localhost

----- The following addresses had permanent fatal errors -----
<james@nonline.net>
reason: 550 5.1.1 <james@nonline.net>... User unknown)
expanded from: <james@nonline.net>)

----- Transcript of session follows -----
... while talking to 127.0.0.1]:
>>> DATA
<<< 550 5.1.1 <james@nonline.net>... User unknown
550 5.1.1 <james@nonline.net>... User unknown
<<< 503 5.0.0 Need RCPT recipient)


Reporting-MTA: dns; mail.nonline.net
Arrival-Date: Sat, 7 Feb 2004 16:20:36 -0500 EST)

Final-Recipient: RFC822; james@nonline.net
Action: failed
Status: 5.1.1
Remote-MTA: DNS; 127.0.0.1]
Diagnostic-Code: SMTP; 550 5.1.1 <james@nonline.net>... User unknown
Last-Attempt-Date: Sat, 7 Feb 2004 16:20:36 -0500 EST)


From: linda@macdoc.com
Date: Thu, 5 Feb 2004 23:16:28 -0500
To: james@nonline.net
Subject: wwncruu
__________________
Spring Cleaning Sale email for flyer..sweet prices across the board • Many Retina's, Airs, new iMacs all on sale - great • OWC at par Trades welcome
MacDoc is offline   Reply With Quote
Sponsored Links
Advertisement
 
Old Feb 7th, 2004, 09:57 PM   #2
Full Citizen
 
hmto's Avatar
 
Join Date: Jul 2003
Location: GTA
Posts: 535
Post

Hi Dave,
I had the same thing happen to me about a week or two ago with a total of maybe 6 email notifications Very strange and offputting especially since it had a recorded time like 3 or 4am and with the same attachments and zips. I'm sleeping at that time!! They also had origins from Australia and such. User names also one named. Currently running 10.3 on mail with rogers high speed cable.
hmto is offline   Reply With Quote
Old Feb 7th, 2004, 10:31 PM   #3
Honourable Citizen
 
kloan's Avatar
 
Join Date: Feb 2002
Location: Ventura, California
Posts: 4,352
Post

I am also getting the same thing with my Rogers account. Last week I got maybe 1 or 2 a day. I am also getting many of those stupid MS Security update ones, all of course have viruses attached... lucky I have Norton, but it certainly is annoying. All this because I made ONE post in a newsgroup with my Rogers account.. never had any problems before..
kloan is offline   Reply With Quote
Old Feb 7th, 2004, 10:43 PM   #4
Left The Building
 
Join Date: Jun 2003
Location: Jasoom
Posts: 8,381
Post

Couldn't this be connected to MyDoom (or similar) spoofing of legitimate e-mail addresses? I haven't had any problems like this, at any rate.
The Doug is offline   Reply With Quote
Old Feb 7th, 2004, 11:08 PM   #5
Full Citizen
 
kent's Avatar
 
Join Date: Oct 2003
Location: Vancouver
Posts: 630
Post

I believe that this is one of the ways that "My Doom" disguises itself. I probably recieved at least 150+ email messages over the past two weeks with: "Hello", "TEST", "Hi" or an error message about a returned email (people I don't even know). I'm using Telus ADSL. All these messages had a 22 KB file attached. I was and still am getting REALLY sick of receiving this emails!
__________________
PowerMac G5 QUAD; Cinema Display; PowerBook G4 [Al. 1.25 GHz]
kent is offline   Reply With Quote
Old Feb 7th, 2004, 11:11 PM   #6
Assured Advertiser
Honourable Citizen
 
MacDoc's Avatar
 
Join Date: Nov 2001
Location: Planet Earth.....on FASTER boil :-(
Posts: 30,604
Post

Yes I suspect it's either aresult of the myDoom directly or some odd combination of a spammer attempting random hits then that being multiplied by the virus or being intercepted as a virus carrier.
It's just annoying as it's random enough that Spamsieve is not catching them right now.
__________________
Spring Cleaning Sale email for flyer..sweet prices across the board • Many Retina's, Airs, new iMacs all on sale - great • OWC at par Trades welcome
MacDoc is offline   Reply With Quote
Old Feb 7th, 2004, 11:19 PM   #7
Honourable Citizen
 
iPetie's Avatar
 
Join Date: Nov 2003
Location: Kitchener
Posts: 1,778
Send a message via AIM to iPetie Send a message via MSN to iPetie
Post

This"is" MyDoom virus. The mail to you is diguised as undeliverable mail from someone within the infected users address book. This is to throw you off as you would have remembered if you had sent the mail to the initial contact.
My question is this, How stupid are people to actually open an attachment under such suspicious circumstances?
Boggles what is left of my mind.
__________________
"A positive attitude may not solve all your problems,
but it will annoy enough people to make it worth the effort".
Herm Albright
iPetie is offline   Reply With Quote
Old Feb 8th, 2004, 08:20 AM   #8
Assured Advertiser
Honourable Citizen
 
MacDoc's Avatar
 
Join Date: Nov 2001
Location: Planet Earth.....on FASTER boil :-(
Posts: 30,604
Post

Well at least SpamSieve has figured it out now but I'm a big concerned it's over trained and might catch some legit incoming tho that's been exceedingly rare.
__________________
Spring Cleaning Sale email for flyer..sweet prices across the board • Many Retina's, Airs, new iMacs all on sale - great • OWC at par Trades welcome
MacDoc is offline   Reply With Quote
Old Feb 8th, 2004, 09:15 AM   #9
Resident Curmudgeon
 
SINC's Avatar
 
Join Date: Feb 2001
Location: Central Alberta
Posts: 60,853
Send a message via AIM to SINC
Post

While I have not experienced this, my daughter has. She has the same email address on my computer as well as her Lombard, at the same server as me.

She received 160 such emails when she opened her mail one morning last week. She deleted all, and in alarm changed her email address and sent a notice out to her address book, to approximately 20 people.

The new email address began receiving about 60 per hour again. I asked her to set up yet another email address, but not to notify those in her address book. This address has not received any mail other than from me and works fine.

My conclusion is one of her friends has a PC (well MOST of her friends have PCs) that is infected with the MyDoom worm.
I told her to try giving the new address to one friend at a time, and wait for a reply. She should be able to figure out which one is infected if the spam shows up after the reply, and advise her friend accordingly is my reasoning.

Will my theory work?

Cheers

[img]smile.gif[/img]
__________________
Visit my website:
St. Albert's Place On The Web
(Over 1.4 million folks have.)

NOTICE: If you see links to ads in the above post, blame the ad-linking software used by the owners of this website. I do not endorse these ad links. Don't click on them.
SINC is offline   Reply With Quote
Old Feb 8th, 2004, 09:38 AM   #10
kps
Tritium Glow
 
kps's Avatar
 
Join Date: May 2003
Location: GTA & Beyond
Posts: 6,783
Post

At times like these I'm glad I use Mailsmith, it has a built in "POP Monitor", which allows me to view incoming mail on the remote server and delete those messages which are obviously spam or potential virus carriers without ever downloading any of them to my machine.

There used to be a stand alone app of the same name, but I have not been able to find it at Version Tracker.

Barebones has a trial version of Mailsmith if anyone is interested in this capability.
__________________
••••••••••••••••••••••••••••••••••••••••••••••••
Please help fight Cancer -Donate or volunteer to the Canadian Cancer Society
---------------
MOΛΩN ΛABE
kps is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Sympatico vs. Mail Carl Mac, iPhone, iPad and iPod Help & Troubleshooting 7 Oct 23rd, 2007 08:37 AM
Mail and Sympatico HELP... MacGYVER Mac, iPhone, iPad and iPod Help & Troubleshooting 5 Nov 9th, 2005 06:47 PM
Mail won't send, weird details... stillmot Mac, iPhone, iPad and iPod Help & Troubleshooting 7 Sep 29th, 2005 12:34 PM
Rogers Compatibility with Mail? EditorGuy Mac, iPhone, iPad and iPod Help & Troubleshooting 9 Oct 28th, 2003 02:08 PM
Moving over to Mail csonni Anything Mac 5 Feb 2nd, 2003 09:33 AM


All times are GMT -4. The time now is 12:19 AM.



Copyright © 1999 - 2012, ehMac.ca All rights reserved. ehMac is not affiliated with Apple Inc. Mac, iPod, iTunes, iPhone, Apple TV are trademarks of Apple Inc. Content Relevant URLs by vBSEO 3.6.0 RC 2

Tribe.ca: Urban living in Toronto!