Virus Spam Is Getting Better
[WHO]Them
You can call me Dave Join Date: 2002-12-11 Member: 10593Members, Constellation
![[WHO]Them](https://forumsdata.unknownworlds.com/uploads/ipb/nav-10593.jpg)
in Off-Topic
<div class="IPBDescription">Check out this little beauty I got</div> As you all know, the Internet is plagued by numerous email virii in the form of retarded screensavers and executables.
Every single one of these comes with an email written in the poorest engrish ever conceived and can be spotted by that trait alone. Well this morning I got a brand new style that is slightly more convincing to look at the attachment, but still falls short in the engrish department.
Take a look at the message source....
<!--c1--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>CODE</b> </td></tr><tr><td id='CODE'><!--ec1-->
Return-Path: <darren@web.de>
Received: from R2D.de (p5080F310.dip.t-dialin.net [80.128.243.16])
by mezotint.clanwho.com (8.12.8/8.12.8) with ESMTP id hBNApJ6a009690
for <them@clanwho.com>; Tue, 23 Dec 2003 02:51:20 -0800
Date: Tue, 23 Dec 2003 02:51:19 -0800
Message-Id: <200312231051.hBNApJ6a009690@mezotint.clanwho.com>
From: darren@web.de
To: them@clanwho.com
Subject: You use illegal File Sharing ...
X-MailScanner: Scanned
Importance: Normal
X-Mailer: Axion
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="87396e0a73.9af820fd9"
X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on
mezotint.clanwho.com
X-Spam-Level: ***
X-Spam-Status: No, hits=3.7 required=5.0 tests=MICROSOFT_EXECUTABLE,
MSGID_FROM_MTA_SHORT,NO_REAL_NAME autolearn=no version=2.60
This is a multi-part message in MIME format.
--87396e0a73.9af820fd9
Ladies and Gentlemen,
Downloading of Movies, MP3s and Software is illegal and punishable by law.
We hereby inform you that your computer was scanned under the IP 193.198.183.236 . The
contents of your computer were confiscated as an evidence, and you will be indicated.
In the next days, you'll get the charge in writing.
In the Reference code: #40336, are all files, that we found on your computer.
The sender address of this mail was masked, to protect us against mail bombs.
- You get more detailed information by the Federal Bureau of Investigation -FBI-
- Department for "Illegal Internet Downloads", Room 7350
- 935 Pennsylvania Avenue
- Washington, DC 20535, USA
- (202) 324-3000
--87396e0a73.9af820fd9
Content-Type: application/octet-stream; name=refcode40336.scr
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="refcode40336.scr"
<!--c2--></td></tr></table><span class='postcolor'><!--ec2-->
after the end of that was a bunch of uuencoded data for the "refcode40336.scr" file which I can only assume is a virus.
So, yeah, I only have one question......
If these guys are so determined to fool you, why can't they ever friggin proofread?!???!?!??!?!??!!!?!?
Just thought I'd share <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif'><!--endemo-->
Every single one of these comes with an email written in the poorest engrish ever conceived and can be spotted by that trait alone. Well this morning I got a brand new style that is slightly more convincing to look at the attachment, but still falls short in the engrish department.
Take a look at the message source....
<!--c1--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>CODE</b> </td></tr><tr><td id='CODE'><!--ec1-->
Return-Path: <darren@web.de>
Received: from R2D.de (p5080F310.dip.t-dialin.net [80.128.243.16])
by mezotint.clanwho.com (8.12.8/8.12.8) with ESMTP id hBNApJ6a009690
for <them@clanwho.com>; Tue, 23 Dec 2003 02:51:20 -0800
Date: Tue, 23 Dec 2003 02:51:19 -0800
Message-Id: <200312231051.hBNApJ6a009690@mezotint.clanwho.com>
From: darren@web.de
To: them@clanwho.com
Subject: You use illegal File Sharing ...
X-MailScanner: Scanned
Importance: Normal
X-Mailer: Axion
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="87396e0a73.9af820fd9"
X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on
mezotint.clanwho.com
X-Spam-Level: ***
X-Spam-Status: No, hits=3.7 required=5.0 tests=MICROSOFT_EXECUTABLE,
MSGID_FROM_MTA_SHORT,NO_REAL_NAME autolearn=no version=2.60
This is a multi-part message in MIME format.
--87396e0a73.9af820fd9
Ladies and Gentlemen,
Downloading of Movies, MP3s and Software is illegal and punishable by law.
We hereby inform you that your computer was scanned under the IP 193.198.183.236 . The
contents of your computer were confiscated as an evidence, and you will be indicated.
In the next days, you'll get the charge in writing.
In the Reference code: #40336, are all files, that we found on your computer.
The sender address of this mail was masked, to protect us against mail bombs.
- You get more detailed information by the Federal Bureau of Investigation -FBI-
- Department for "Illegal Internet Downloads", Room 7350
- 935 Pennsylvania Avenue
- Washington, DC 20535, USA
- (202) 324-3000
--87396e0a73.9af820fd9
Content-Type: application/octet-stream; name=refcode40336.scr
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="refcode40336.scr"
<!--c2--></td></tr></table><span class='postcolor'><!--ec2-->
after the end of that was a bunch of uuencoded data for the "refcode40336.scr" file which I can only assume is a virus.
So, yeah, I only have one question......
If these guys are so determined to fool you, why can't they ever friggin proofread?!???!?!??!?!??!!!?!?
Just thought I'd share <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif'><!--endemo-->
Comments