Thanks MIchael!

  I will start making some rules to weed this out.

Travis

> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Michael Hudson
> Sent: Wednesday, January 28, 2004 4:07 PM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] Alert! - fraudulent e-mail - FBI and FDIC
> 
> 
> Attached is a copy for everyone's reference.  I've taken references to 
> my domain name out and replaced them with example.com.
> 
> It seems to be standard phishing.
> 
> I received nine copies, using three different real IPs in the URI; All 
> of the URI's used port 3180, though.  I imagine the messages are sent 
> through machines turned zombies through recent viruses.
> 
> The IP's of the sending machines:
> 24.190.170.234
> 24.202.111.221
> 24.202.7.19
> 24.226.181.155
> 63.139.158.202
> 128.39.54.28
> 148.240.16.95
> 200.103.136.197
> 220.27.216.46
> These IPs are cable modems, etc.  Again, probably zombies.
> 
> The Phishing URI's were:
> 5 http://[EMAIL PROTECTED]:3180/index.htm
> 3 http://[EMAIL PROTECTED]:3180/index.htm
> 1 http://[EMAIL PROTECTED]:3180/index.htm
> These three are assigned through APNIC.
> 
> The "%01" trick will cause some browsers to stop displaying the rest of 
> the URI.  So the user may actually see only "http://www.fdic.gov"; in 
> some cases!
> 
> It's been my opinion as of late that user education is absolutely 
> critical to preventing viruses and phishing alike.  So don't pursue a 
> 100% technical solution.
> 
> Regards,
> Michael Hudson
> 

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to