NHD
2003-08-24 12:52:18 UTC
I've been getting hundreds of SoBig.f infected mails every day from spoofed
e-mail addresses. I changed my MX record to go through a filtering service,
whcih has caught about 10% of them, but the rest keep coming through.
The ones that get through all seem to be coming from the same IP address,
unless that's spoofed also. Is it?
Here are the headers:
Received: from SPARKY
(ool-182f6abf.dyn.optonline.net [24.47.106.191])
by rosekissin.com; Sun, 24 Aug 2003 08:48:15 -0400
From: <***@musicmatch.com>
To: <***@irpcg.com>
Subject: Re: Your application
Date: Sun, 24 Aug 2003 8:48:23 --0400
X-MailScanner: Found to be clean
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="_NextPart_000_1D5BC0F5"
e-mail addresses. I changed my MX record to go through a filtering service,
whcih has caught about 10% of them, but the rest keep coming through.
The ones that get through all seem to be coming from the same IP address,
unless that's spoofed also. Is it?
Here are the headers:
Received: from SPARKY
(ool-182f6abf.dyn.optonline.net [24.47.106.191])
by rosekissin.com; Sun, 24 Aug 2003 08:48:15 -0400
From: <***@musicmatch.com>
To: <***@irpcg.com>
Subject: Re: Your application
Date: Sun, 24 Aug 2003 8:48:23 --0400
X-MailScanner: Found to be clean
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="_NextPart_000_1D5BC0F5"