Fw:
| From: | Percy Galván | Date: | Mon, 14 Mar 2011 05:03:29 +0000 |
| Subject: | Fw: | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-10623@lists.php.net to get a copy of this message | ||
This IP:
http://www.iplocationfinder.com/69.93.154.13
send the scam mail with this link located in this domain: msg1.ws
The hacker stold my game's account, with credits Ive buyed
This is the full email source.
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0xO0Q9MTtTQ0w9Mg==
X-Message-Status: n
X-SID-PRA: Dead Frontier Online <noreply@deadfrontier.com>
X-SID-Result: Neutral
X-AUTH-Result: NONE
X-Message-Info:
JGTYoYF78jHoESnoad6ePmWPzo3rlIrFWaDtRiTeUewhIqmjnOqyMdu+2NM06cLdU1rvW/WE1NUjngj4lKN26Xe39tEK58G3e0/QlxIjTuE=
Received: from gateway12.websitewelcome.com ([69.93.154.13]) by bay0-mc3-f16.Bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.4675);
Sun, 13 Mar 2011 17:17:34 -0700
Received: (qmail 19762 invoked from network); 14 Mar 2011 00:16:03 -0000
Received: from superleggera.websitewelcome.com (174.132.145.130)
by gateway12.websitewelcome.com with SMTP; 14 Mar 2011 00:16:03 -0000
Received: from ellector by superleggera.websitewelcome.com with local (Exim 4.69)
(envelope-from <ellector@superleggera.websitewelcome.com>)
id 1PyvTY-0003TO-Oj
for vanumetal@hotmail.com; Sun, 13 Mar 2011 19:17:32 -0500
To: vanumetal@hotmail.com
Subject: Earn $ 10,000 by answering the survey of the most entertaininggame of the networ
X-PHP-Script: 174.132.145.130/~ellector/geoip/a.php for 173.224.209.216
Date: Sun, 13 Mar 2011 19:17:32 -0500
From: Dead Frontier Online <noreply@deadfrontier.com>
Message-ID: <002d8c20899495f67d499c858d9b2675@174.132.145.130>
X-Priority: 3
X-Abuse: abuse@ventaselectronics.info
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="b1_002d8c20899495f67d499c858d9b2675"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - superleggera.websitewelcome.com
X-AntiAbuse: Original Domain - hotmail.com
X-AntiAbuse: Originator/Caller UID/GID - [3583 32003] / [47 12]
X-AntiAbuse: Sender Address Domain - superleggera.websitewelcome.com
X-Source: /usr/bin/php
X-Source-Args: /usr/bin/php /home/ellector/public_html/geoip/a.php
X-Source-Dir: ellector.com:/public_html/geoip
Return-Path: ellector@superleggera.websitewelcome.com
X-OriginalArrivalTime: 14 Mar 2011 00:17:34.0379 (UTC) FILETIME=[376837B0:01CBE1DD]
--b1_002d8c20899495f67d499c858d9b2675
Content-Type: text/plain; charset = "iso-8859-1"
Content-Transfer-Encoding: 8bit
Dead Frontier Beta
From: Percy Galván
Sent: Sunday, March 13, 2011 10:51 PM
To: php-webmaster@lists.php.net
Your website is sending viruses, are you responsable for this?
http://log1n.1ive.com.msg1.ws/ppsecure/post3.php?wa=wsignin1.0&rpsnv=10&ct=1234387622&rver=5.5.4177.0&wp=MBI
__________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950
(20110313) __________
ESET NOD32 Antivirus ha comprobado este mensaje.
http://www.eset.com
__________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950
(20110313) __________
ESET NOD32 Antivirus ha comprobado este mensaje.
http://www.eset.com