[126183] in North American Network Operators' Group
Interesting combination of SPAM + Phishing + stupidity
daemon@ATHENA.MIT.EDU (Jorge Amodio)
Tue May 4 20:38:44 2010
Date: Tue, 4 May 2010 19:38:15 -0500
From: Jorge Amodio <jmamodio@gmail.com>
To: NANOG <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
this is obviously no news and the attachment as you all probably know
is a trojan executable.
The interesting part and kind of a test to determine who is more
stupid, the one sending the message or the one opening and executing
the attachment, the message is supposedly sent by UPS but signed as
DHL Customer Service, sort of "Welcome to Wells Fargo, your Bank of
America support team", duhhh.
Also, almost 3 months to notify you that a package was not delivered ?
Are spammers getting smarter ? or users getting dumber ?
Cheers
>From - Tue May 04 17:34:08 2010
>Return-Path: <anidiot@spamheaven.kom>
>Delivery-Date: Tue, 04 May 2010 18:25:37 -0400
>From: "UPS Manager Sal Erwin" <help@ups.com>
>To: <xyz@potential.moron.com>
>Subject: UPS Delivery Problem NR 97981.
>Date: Wed, 5 May 2010 00:25:03 +0100
>MIME-Version: 1.0
>Content-Type: multipart/mixed;
> boundary=3D"----=3D_NextPart_000_0006_01CAEBD8.A43991A0"
>
>This is a multi-part message in MIME format.
>
>------=3D_NextPart_000_0006_01CAEBD8.A43991A0
>Content-Type: text/plain;
> charset=3D"Windows-1252"
>Content-Transfer-Encoding: 7bit
>
>Hello!
>
>We failed to deliver the package you have sent on the 6th of February in t=
ime
>because the recipient=92s address is wrong.
>Please print out the invoice copy attached and collect the package at our =
office.
>
>DHL Customer Services.
>
>
>------=3D_NextPart_000_0006_01CAEBD8.A43991A0
>Content-Type: application/zip;
> name=3D"UPS_invoice_4978.zip"
>Content-Transfer-Encoding: base64
>Content-Disposition: attachment;
> filename=3D"UPS_invoice_4978.zip"