Mail delivery subsystem

Post scam emails to warn other rental owners, or if you are not sure if an enquiry is genuine, put it up here and see what others think.
canda
Posts: 14
Joined: Mon Aug 22, 2005 4:14 pm
Location: Ernee, Mayenne

Mail delivery subsystem

Post by canda »

Hi

I keep receiveing e-mails supposedly telling me that my mail cannot be delivered. They all come with attachments. As far as I am aware none of my mail has been undelivered. Is this a new way of infecting a system with a virus of some sort. I have copied one of the messages below:
The original message was received at Thu, 8 Jun 2006 02:17:39 -0400 (EDT)
from sp604001mt.neufgp.fr [84.96.92.60]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its
delivery. The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors -----".

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail could
not be delivered. The next line contains a second error message which is a
general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail
administrator.

--AOL Postmaster



----- The following addresses had permanent fatal errors -----
<dafs37@aol.com>

----- Transcript of session follows -----
... while talking to air-ya04.mail.aol.com.:
>>> DATA
<<< 554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not been sent.
554 <dafs37@aol.com>... Service unavailable
<P><HR></P>Received: from Smtp.neuf.fr (sp604001mt.neufgp.fr [84.96.92.60]) by rly-ya06.mx.aol.com (v109.13) with ESMTP id MAILRELAYINYA610-7744487c102363; Thu, 08 Jun 2006 02:17:39 -0400
Received: from wanadoo.fr ([84.5.19.122]) by sp604001mt.gpm.neuf.ld
(Sun Java System Messaging Server 6.2-5.05 (built Feb 16 2006))
with ESMTP id <0J0J00JQ82Q1WP10@sp604001mt.gpm.neuf.ld> for dafs37@aol.com;
Thu, 08 Jun 2006 08:15:38 +0200 (CEST)
Date: Thu, 08 Jun 2006 08:11:36 +0200
From: figgins@wanadoo.fr
Subject: DELIVERY REPORTS ABOUT YOUR E-MAIL
To: dafs37@aol.com
Message-id: <0J0J00JQ92Q1WP10@sp604001mt.gpm.neuf.ld>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: multipart/mixed; boundary="Boundary_(ID_yjCIaJZOZ6y9N1eUuExJYg)"
X-Priority: 3
X-MSMail-priority: Normal
X-AOL-IP: 84.96.92.60
X-AOL-SCOLL-SCORE: 0:2:444115692:8509404
X-AOL-SCOLL-URL_COUNT: 0


It all looks very convincing, but I have just been deleting them as I don't think they are genuine. What else should I do?

Canda
User avatar
Chalky
Posts: 128
Joined: Sat Aug 13, 2005 1:31 pm
Location: La Duquesa, Costa del Sol
Contact:

Post by Chalky »

Did you send a message to dafs37@aol.com? If not you're probably the subject of some hoaxer. If you did, did they receive your message?
Chalky

Image
canda
Posts: 14
Joined: Mon Aug 22, 2005 4:14 pm
Location: Ernee, Mayenne

Post by canda »

Chalky

I haven't sent any messages to aol addresses. So far today I have received 5 undelivered mail messages. Is there any way of stopping it that you know of? What do the hoaxers get out of it? Thanks for your reply.

Canda
User avatar
Normandy Cow
Posts: 2687
Joined: Sun Nov 28, 2004 7:14 am
Location: Normandy
Contact:

Post by Normandy Cow »

I've been getting one nearly every day with the following text:
The original message was received at Wed, 7 Jun 2006 11:30:25 -0700
from [222.138.205.106]

----- The following addresses had permanent fatal errors -----
<info@legaldeeds.net>
(reason: 550 unknown user <admin@legaldeeds.com>)

----- Transcript of session follows -----
.. while talking to mail.legaldeeds.com.:
>>> RCPT To:<admin@legaldeeds.com>
<<< 550 unknown user <admin@legaldeeds.com>
550 5.1.1 <info@legaldeeds.net>... User unknown
I have no idea what legaldeeds.net is and I have never (knowingly) sent them an email. I don't really know what to do either. :(
User avatar
paolo
Posts: 3885
Joined: Thu Jun 17, 2004 1:18 pm
Location: Provence, France
Contact:

Post by paolo »

I think the point of these emails is like any spam, to get you to click on a link or attachment. Either it will launch a virus, trojan, spyware, etc, or take you to a porn site.

Sending them under the guise of 'Undelivered email' makes them seem bone fide and recipients drop their guard.

If it really is your email that failed to be delivered, your original email will be at the bottom of the message. If it isn't there, delete. I'm sure everyone gets lots of these.
Paolo
Lay My Hat
Post Reply