Thanks MIchael! I will start making some rules to weed this out.
Travis > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Michael Hudson > Sent: Wednesday, January 28, 2004 4:07 PM > To: [EMAIL PROTECTED] > Subject: Re: [IMail Forum] Alert! - fraudulent e-mail - FBI and FDIC > > > Attached is a copy for everyone's reference. I've taken references to > my domain name out and replaced them with example.com. > > It seems to be standard phishing. > > I received nine copies, using three different real IPs in the URI; All > of the URI's used port 3180, though. I imagine the messages are sent > through machines turned zombies through recent viruses. > > The IP's of the sending machines: > 24.190.170.234 > 24.202.111.221 > 24.202.7.19 > 24.226.181.155 > 63.139.158.202 > 128.39.54.28 > 148.240.16.95 > 200.103.136.197 > 220.27.216.46 > These IPs are cable modems, etc. Again, probably zombies. > > The Phishing URI's were: > 5 http://[EMAIL PROTECTED]:3180/index.htm > 3 http://[EMAIL PROTECTED]:3180/index.htm > 1 http://[EMAIL PROTECTED]:3180/index.htm > These three are assigned through APNIC. > > The "%01" trick will cause some browsers to stop displaying the rest of > the URI. So the user may actually see only "http://www.fdic.gov" in > some cases! > > It's been my opinion as of late that user education is absolutely > critical to preventing viruses and phishing alike. So don't pursue a > 100% technical solution. > > Regards, > Michael Hudson > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
