Cyber Spamming - Beware
I mentioned on the weekend that I have been getting a lot of spam containing viruses recently - purportedly coming from ronmetcalfe.com - yah, like I’m sending myself emails …
I have just been deleting them - and of course not opening the attachments - which contain the virus.
This week I have had emails ‘returned’ to me that were sent to New School University in Greenwich Village New York - marked as contaminated and not accepted by that institution’s anti-virus software. I had never heard of this university and have not ever emailed them.
So, these spammers are not only sending emails from me to me but also to other places too.
Today it occurs to me I should be warning those that read this blog about this - as these spam virus-laden emails could be going anywhere - including your computer.
These are a few samples of the type of wording they are using.
From: webmaster @ronmetcalfe.com [mailto:webmaster @ronmetcalfe.com]
Sent: 14 June 2005 11:27
To: tom @ronmetcalfe.com
Subject: Your password has been successfully updated
Dear user tom,
You have successfully updated the password of your Ronmetcalfe account.
If you did not authorize this change or if you need assistance with your account, please contact Ronmetcalfe customer service at: webmaster @ronmetcalfe.com
Thank you for using Ronmetcalfe!
The Ronmetcalfe Support Team
+++ Attachment: No Virus (Clean)
+++ Ronmetcalfe Antivirus - www .ronmetcalfe.com
From: register @ronmetcalfe.com [mailto:register @ronmetcalfe.com]
Sent: 14 June 2005 10:46
To: jose @ronmetcalfe.com
Subject: Members Support
Dear Ronmetcalfe Member,
Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service.
If you choose to ignore our request, you leave us no choice but to cancel your membership.
Virtually yours,
The Ronmetcalfe Support Team
+++ Attachment: No Virus found
+++ Ronmetcalfe Antivirus - www. ronmetcalfe.com
From: info @ronmetcalfe.com [mailto:info @ronmetcalfe.com]
Sent: 14 June 2005 10:46
To: james @ronmetcalfe.com
Subject: Members Support
Dear user james,
It has come to our attention that your Ronmetcalfe User Profile ( x ) records are out of date. For further details see the attached document.
Thank you for using Ronmetcalfe!
The Ronmetcalfe Support Team
+++ Attachment: No Virus (Clean)
+++ Ronmetcalfe Antivirus - www. ronmetcalfe.com
You can see they are slightly ‘off’ - ‘The Ronmetcalfe Support Team’ or ‘Thank you for using Ronmetcalfe’. So this should make you suspicious! Of course if you reply to that address I suspect that automatically confirms your address as a ‘live account’ - and fair game to go on a spammers address list (and no doubt sold on as well to other spammers).
Please be aware I will not send anyone an email with an attachment. In the rare instance where I do - we will have discussed it first so you will know to expect it.
I will also only send out emails which are address to you personally with your name, or nickname, on them.
I would not ask anyone to fill out documents about your Forum membership, etc - without posting such information on the Forum first - again you would know to expect it.Nor would I threaten I have “no choice” but to close your account.
(As I write this four more such emails have come into my Inbox)
Ben and I are talking about ways to diminish these spam emails - and will be making some changes to alleviate my problem soon - but I think it fair to point out this nasty trend in case something finds it’s way to your computer - looking like it has come from my domain.
June 16th, 2005 at 11:45 am
It turns out this is not a spammer, it’s a worm that has infected the offending party’s computer. They won’t even know they’ve been infected.
This is what happens when you install dodgy software or open unknown mail attachments.
You can find out more about it here: http://www.enterasys.com/support/security/incidents/2005/06/12581.html