Re: [tor-relays] Phishy

2014-02-03 Thread Jurre van Bergen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hey, It doesn't seem to be targetted. It looks like your email was sucked into a spamlist to send malware too. For malware researchers, the sample can be obtained over here: https://malwr.com/analysis/YjQ1Y2FjZTcxMTgxNDgwNmE4MWIyYjIzN2RjNWM1YTc/ Jur

Re: [tor-relays] Phishy

2014-02-03 Thread Jesse Victors
> FYI: Just got this to my Tor relay mail address, with a zip file > attached extracting to a '.scr' win exe. Curiously routed via a .gov.uk > mail relay... > > GB03022014.scr: PE32 executable (GUI) Intel 80386, for MS Windows > > MD5: dba1e52929f6ca9d1a1bf87e4ff469cf GB2546241.zip > MD5: fb11414

Re: [tor-relays] Phishy

2014-02-03 Thread Geoff Down
Your mailserver received it from an Orange France IP 217.109.27.97 . Before that you can't really trust the headers. GD > > On 02/03/2014 10:33 PM, phrag wrote: > > FYI: Just got this to my Tor relay mail address, with a zip file > > attached extracting to a '.scr' win exe. Curiously routed via a