Re: Fw:
| From: | Daniel P. Brown | Date: | Mon, 14 Mar 2011 14:43:49 +0000 |
| Subject: | Re: Fw: | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-10625@lists.php.net to get a copy of this message | ||
On Mon, Mar 14, 2011 at 01:03, Percy Galván <pgalvan@comunicarer.com> wrote:
> This IP:
>
> http://www.iplocationfinder.com/69.93.154.13
>
> send the scam mail with this link located in this domain: msg1.ws
>
> The hacker stold my game's account, with credits Ive buyed
And? I'm not sure why you think this would have anything to do
with us. Just because a script is written in PHP (literally millions
of them) doesn't mean we have any knowledge of them --- and we
certainly don't endorse or support them. Instead, you may want to try
contacting whatever service was breeched and ask them to investigate.
Best of luck.
> This is the full email source.
>
>
>
> X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0xO0Q9MTtTQ0w9Mg==
> X-Message-Status: n
> X-SID-PRA: Dead Frontier Online <noreply@deadfrontier.com>
> X-SID-Result: Neutral
> X-AUTH-Result: NONE
> X-Message-Info:
> JGTYoYF78jHoESnoad6ePmWPzo3rlIrFWaDtRiTeUewhIqmjnOqyMdu+2NM06cLdU1rvW/WE1NUjngj4lKN26Xe39tEK58G3e0/QlxIjTuE=
> Received: from gateway12.websitewelcome.com ([69.93.154.13]) by bay0-mc3-f16.Bay0.hotmail.com
> with Microsoft SMTPSVC(6.0.3790.4675);
> Sun, 13 Mar 2011 17:17:34 -0700
> Received: (qmail 19762 invoked from network); 14 Mar 2011 00:16:03 -0000
> Received: from superleggera.websitewelcome.com (174.132.145.130)
> by gateway12.websitewelcome.com with SMTP; 14 Mar 2011 00:16:03 -0000
> Received: from ellector by superleggera.websitewelcome.com with local (Exim 4.69)
> (envelope-from <ellector@superleggera.websitewelcome.com>)
> id 1PyvTY-0003TO-Oj
> for vanumetal@hotmail.com; Sun, 13 Mar 2011 19:17:32 -0500
> To: vanumetal@hotmail.com
> Subject: Earn $ 10,000 by answering the survey of the most entertaininggame of the networ
> X-PHP-Script: 174.132.145.130/~ellector/geoip/a.php for 173.224.209.216
> Date: Sun, 13 Mar 2011 19:17:32 -0500
> From: Dead Frontier Online <noreply@deadfrontier.com>
> Message-ID: <002d8c20899495f67d499c858d9b2675@174.132.145.130>
> X-Priority: 3
> X-Abuse: abuse@ventaselectronics.info
> MIME-Version: 1.0
> Content-Type: multipart/alternative;
> boundary="b1_002d8c20899495f67d499c858d9b2675"
> X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
> X-AntiAbuse: Primary Hostname - superleggera.websitewelcome.com
> X-AntiAbuse: Original Domain - hotmail.com
> X-AntiAbuse: Originator/Caller UID/GID - [3583 32003] / [47 12]
> X-AntiAbuse: Sender Address Domain - superleggera.websitewelcome.com
> X-Source: /usr/bin/php
> X-Source-Args: /usr/bin/php /home/ellector/public_html/geoip/a.php
> X-Source-Dir: ellector.com:/public_html/geoip
> Return-Path: ellector@superleggera.websitewelcome.com
> X-OriginalArrivalTime: 14 Mar 2011 00:17:34.0379 (UTC) FILETIME=[376837B0:01CBE1DD]
>
> --b1_002d8c20899495f67d499c858d9b2675
> Content-Type: text/plain; charset = "iso-8859-1"
> Content-Transfer-Encoding: 8bit
>
> Dead Frontier Beta
>
>
>
>
>
>
> From: Percy Galván
> Sent: Sunday, March 13, 2011 10:51 PM
> To: php-webmaster@lists.php.net
>
>
> Your website is sending viruses, are you responsable for this?
>
>
> http://log1n.1ive.com.msg1.ws/ppsecure/post3.php?wa=wsignin1.0&rpsnv=10&ct=1234387622&rver=5.5.4177.0&wp=MBI
>
>
> __________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950
> (20110313) __________
>
> ESET NOD32 Antivirus ha comprobado este mensaje.
>
> http://www.eset.com
>
>
>
> __________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950
> (20110313) __________
>
> ESET NOD32 Antivirus ha comprobado este mensaje.
>
> http://www.eset.com
>
>
--
</Daniel P. Brown>
Dedicated Servers, Cloud and Cloud Hybrid Solutions, VPS, Hosting
(866-) 725-4321
http://www.parasane.net/