PDA

View Full Version : can someone help me analyze this



Burzhui
05-23-2004, 07:12 PM
i keep getting this every couple of days

trojan?


The original message was received at Sun, 23 May 2004 22:34:46 -0400 (EDT) from CPE-144-137-77-33.nsw.bigpond.net.au [144.137.77.33]

----- The following addresses had permanent fatal errors ----- <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected]) <[email protected]>
(reason: 550 5.1.1 unknown or illegal alias: [email protected])

----- Transcript of session follows -----
... while talking to ms-mta-01-dmz.rdc-nyc.rr.com.:
>>> DATA
<<< 550 5.1.1 unknown or illegal alias: [email protected]
550 5.1.1 <[email protected]>... User unknown
<<< 550 5.1.1 unknown or illegal alias: [email protected]
550 5.1.1 <[email protected]>... User unknown
<<< 550 5.1.1 unknown or illegal alias: [email protected]
550 5.1.1 <[email protected]>... User unknown
<<< 550 5.1.1 unknown or illegal alias: 3Dacsms@nyc.rr.com
550 5.1.1 <3Dacsms@nyc.rr.com>... User unknown
<<< 550 5.1.1 unknown or illegal alias: seaforthsoccer@nyc.rr.com 550 5.1.1 <seaforthsoccer@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dseaforthsoccer@nyc.rr.com 550 5.1.1 <3Dseaforthsoccer@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: swim@nyc.rr.com 550 5.1.1 <swim@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dswim@nyc.rr.com 550 5.1.1 <3Dswim@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: rnswba@nyc.rr.com 550 5.1.1 <rnswba@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Drnswba@nyc.rr.com 550 5.1.1 <3Drnswba@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dgosford@nyc.rr.com 550 5.1.1 <3Dgosford@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dadmin@nyc.rr.com 550 5.1.1 <3Dadmin@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: contact.us@nyc.rr.com 550 5.1.1 <contact.us@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dcontact.us@nyc.rr.com 550 5.1.1 <3Dcontact.us@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: ceo@nyc.rr.com 550 5.1.1 <ceo@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dtennis@nyc.rr.com 550 5.1.1 <3Dtennis@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: Eo@nyc.rr.com 550 5.1.1 <Eo@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3DEo@nyc.rr.com 550 5.1.1 <3DEo@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: experts@nyc.rr.com 550 5.1.1 <experts@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dexperts@nyc.rr.com 550 5.1.1 <3Dexperts@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: gosford@nyc.rr.com 550 5.1.1 <gosford@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dloughers@nyc.rr.com 550 5.1.1 <3Dloughers@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: torch@nyc.rr.com 550 5.1.1 <torch@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Djulie.whitfield@nyc.rr.com 550 5.1.1 <3Djulie.whitfield@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: nbwnews@nyc.rr.com 550 5.1.1 <nbwnews@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dnbwnews@nyc.rr.com 550 5.1.1 <3Dnbwnews@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: burkej@nyc.rr.com 550 5.1.1 <burkej@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dburkej@nyc.rr.com 550 5.1.1 <3Dburkej@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: se10@nyc.rr.com 550 5.1.1 <se10@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dse10@nyc.rr.com 550 5.1.1 <3Dse10@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: c.finch@nyc.rr.com 550 5.1.1 <c.finch@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dc.finch@nyc.rr.com 550 5.1.1 <3Dc.finch@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: a.williamson@nyc.rr.com 550 5.1.1 <a.williamson@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Da.williamson@nyc.rr.com 550 5.1.1 <3Da.williamson@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: loughers@nyc.rr.com 550 5.1.1 <loughers@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: wrighg@nyc.rr.com 550 5.1.1 <wrighg@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dwrighg@nyc.rr.com 550 5.1.1 <3Dwrighg@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: webeditor@nyc.rr.com 550 5.1.1 <webeditor@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dwebeditor@nyc.rr.com 550 5.1.1 <3Dwebeditor@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: shoroc@nyc.rr.com 550 5.1.1 <shoroc@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dshoroc@nyc.rr.com 550 5.1.1 <3Dshoroc@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: council@nyc.rr.com 550 5.1.1 <council@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: nswgfl@nyc.rr.com 550 5.1.1 <nswgfl@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3Dnswgfl@nyc.rr.com 550 5.1.1 <3Dnswgfl@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: Nswaikikai@nyc.rr.com 550 5.1.1 <Nswaikikai@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: 3DNswaikikai@nyc.rr.com 550 5.1.1 <3DNswaikikai@nyc.rr.com>... User unknown <<< 550 5.1.1 unknown or illegal alias: julie.whitfield@nyc.rr.com 550 5.1.1 <julie.whitfield@nyc.rr.com>... User unknown

Jeffbx
05-24-2004, 04:48 AM
Off the top of my head, I'd say either 1) your mail address is being used as the sending address by a virus (not necessarily on your PC), or 2) someone is using your address & SMTP server to act as a spam relay.

Keep an eye out for follow up messages from people who may have actually received the original message - someone may reply to complain about the virus or spam that appears to have originated from your mail address (even thought you had nothing to do with it). At least then you'll know what you're dealing with.

Markel
05-24-2004, 06:59 PM
For a while I was getting a bunch of delivery failure messages because a spammer was spoofing my email address as the source of the spam. I often forwarded them to abuse@myisp with an explanation (just in case they received complaints that I was sending out spam).

brainsmile
05-24-2004, 07:47 PM
For a while I was getting a bunch of delivery failure messages because a spammer was spoofing my email address as the source of the spam. I often forwarded them to abuse@myisp with an explanation (just in case they received complaints that I was sending out spam).
yeah that's my experience.

verve247
05-24-2004, 09:09 PM
I'm not familiar with abuse@mysip. I've been having the same problem, thinking someoine has been spoofing my address. Can someone give me more information about them. Should i write a little note of the situation and forward each email or just 1 to give them a heads' up.