
Strange spam with no subject and a blank body has been showing up with more frequency lately. The headers look like this:
From mybshvvrzrzjs@yahoo.com Fri Feb 6 04:58:36 2004
Return-Path:
Received: from catv-5062365c.miskcatv.broadband.hu (catv-5062365c.miskcatv.broadband.hu [80.98.54.92])
by blackfoot.gulker.com (8.12.10/8.12.8) with SMTP idi16CvN5k021036
for chrisg@gulker.com; Fri, 6 Feb 2004 04:57:29 -0800
Date: Fri, 6 Feb 2004 04:57:23 -0800
From: mybshvvrzrzjs@yahoo.com
Received: from 165.199.0.105 by 80.98.54.92; Thu, 05 Feb 2004 07:02:07 -0600
Message-ID:
X-Scanned-By: MIMEDefang 2.38
Status:
The sender's IP all appear to be addresses on broadband ISP systems. I can ping some of the addresses, including the one above, but the systems won't relay mail (though the header thinks it relayed this one) and in any case has no open ports below 80. The message ID is similar in all received so far, as is the from address - a random-ish string @yahoo.com. My guess is that this either a misfiring virus or some new virus in development... wonder what port it uses to send or relay mail...
8:22:29 AM
|