Re: Fw:

From: Date: Mon, 14 Mar 2011 14:43:49 +0000
Subject: Re: Fw:
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-10625@lists.php.net to get a copy of this message
On Mon, Mar 14, 2011 at 01:03, Percy Galván <pgalvan@comunicarer.com> wrote: > This IP: > > http://www.iplocationfinder.com/69.93.154.13 > > send the scam mail with this link located in this domain: msg1.ws > > The hacker stold my game's account, with credits Ive buyed And? I'm not sure why you think this would have anything to do with us. Just because a script is written in PHP (literally millions of them) doesn't mean we have any knowledge of them --- and we certainly don't endorse or support them. Instead, you may want to try contacting whatever service was breeched and ask them to investigate. Best of luck. > This is the full email source. > > > > X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0xO0Q9MTtTQ0w9Mg== > X-Message-Status: n > X-SID-PRA: Dead Frontier Online <noreply@deadfrontier.com> > X-SID-Result: Neutral > X-AUTH-Result: NONE > X-Message-Info: > JGTYoYF78jHoESnoad6ePmWPzo3rlIrFWaDtRiTeUewhIqmjnOqyMdu+2NM06cLdU1rvW/WE1NUjngj4lKN26Xe39tEK58G3e0/QlxIjTuE= > Received: from gateway12.websitewelcome.com ([69.93.154.13]) by bay0-mc3-f16.Bay0.hotmail.com > with Microsoft SMTPSVC(6.0.3790.4675); >  Sun, 13 Mar 2011 17:17:34 -0700 > Received: (qmail 19762 invoked from network); 14 Mar 2011 00:16:03 -0000 > Received: from superleggera.websitewelcome.com (174.132.145.130) >  by gateway12.websitewelcome.com with SMTP; 14 Mar 2011 00:16:03 -0000 > Received: from ellector by superleggera.websitewelcome.com with local (Exim 4.69) >  (envelope-from <ellector@superleggera.websitewelcome.com>) >  id 1PyvTY-0003TO-Oj >  for vanumetal@hotmail.com; Sun, 13 Mar 2011 19:17:32 -0500 > To: vanumetal@hotmail.com > Subject: Earn $ 10,000 by answering the survey of the most entertaininggame of the networ > X-PHP-Script: 174.132.145.130/~ellector/geoip/a.php for 173.224.209.216 > Date: Sun, 13 Mar 2011 19:17:32 -0500 > From: Dead Frontier Online <noreply@deadfrontier.com> > Message-ID: <002d8c20899495f67d499c858d9b2675@174.132.145.130> > X-Priority: 3 > X-Abuse: abuse@ventaselectronics.info > MIME-Version: 1.0 > Content-Type: multipart/alternative; >  boundary="b1_002d8c20899495f67d499c858d9b2675" > X-AntiAbuse: This header was added to track abuse, please include it with any abuse report > X-AntiAbuse: Primary Hostname - superleggera.websitewelcome.com > X-AntiAbuse: Original Domain - hotmail.com > X-AntiAbuse: Originator/Caller UID/GID - [3583 32003] / [47 12] > X-AntiAbuse: Sender Address Domain - superleggera.websitewelcome.com > X-Source: /usr/bin/php > X-Source-Args: /usr/bin/php /home/ellector/public_html/geoip/a.php > X-Source-Dir: ellector.com:/public_html/geoip > Return-Path: ellector@superleggera.websitewelcome.com > X-OriginalArrivalTime: 14 Mar 2011 00:17:34.0379 (UTC) FILETIME=[376837B0:01CBE1DD] > > --b1_002d8c20899495f67d499c858d9b2675 > Content-Type: text/plain; charset = "iso-8859-1" > Content-Transfer-Encoding: 8bit > > Dead Frontier Beta > > > > > > > From: Percy Galván > Sent: Sunday, March 13, 2011 10:51 PM > To: php-webmaster@lists.php.net > > > Your website is sending viruses, are you responsable for this? > > > http://log1n.1ive.com.msg1.ws/ppsecure/post3.php?wa=wsignin1.0&rpsnv=10&ct=1234387622&rver=5.5.4177.0&wp=MBI > > > __________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950 > (20110313) __________ > > ESET NOD32 Antivirus ha comprobado este mensaje. > > http://www.eset.com > > > > __________ Información de ESET NOD32 Antivirus, versión de la base de firmas de virus 5950 > (20110313) __________ > > ESET NOD32 Antivirus ha comprobado este mensaje. > > http://www.eset.com > > -- </Daniel P. Brown> Dedicated Servers, Cloud and Cloud Hybrid Solutions, VPS, Hosting (866-) 725-4321 http://www.parasane.net/

« previous php.webmaster (#10625) next »