Email address being spoofed to send spam?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tubnotub1, Jun 10, 2014.

Thread Status:
Not open for further replies.
  1. Tubnotub1

    Tubnotub1 Private First Class

    Recently (within the last week) I have received spam email from two separate accounts both of which belong to me. The spam was sent to myself and a couple others. One account is a hotmail account, another is a gmail account. Both accounts have had two-factor authentication enable since long before these spam emails. I have since changed both passwords (just to be sure) but I do not believe these emails are originating from my accounts, I believe my email addresses are being spoofed due to the following:

    As stated above, both of my accounts are 2-factor authenticated and have been since long before these issues.

    The spam email that was sent from my hotmail account shows as mailed-by: terra.com.br, *not* hotmail.com as it should.

    The spam email that was sent from my gmail account shows *no* authentication information. There is no mailed-by information. Here is the source information, note all instances of my actual email address have been removed and replaced with myemailaddress@gmail.com in order to avoid additional spam from crawlers:

    Delivered-To: myemailaddress@gmail.com
    Received: by 10.140.108.246 with SMTP id j109csp57763qgf;
    Fri, 6 Jun 2014 22:37:26 -0700 (PDT)
    X-Received: by 10.112.14.5 with SMTP id l5mr6831420lbc.12.1402119445848;
    Fri, 06 Jun 2014 22:37:25 -0700 (PDT)
    Return-Path: <blinkbvm1@dopefiends.com>
    Received: from co.za (8ta-229-187-240.telkomadsl.co.za. [197.229.187.240])
    by mx.google.com with ESMTP id i6si12696449lah.35.2014.06.06.22.37.24
    for <myemailaddress@gmail.com>;
    Fri, 06 Jun 2014 22:37:25 -0700 (PDT)
    Received-SPF: none (google.com: blinkbvm1@dopefiends.com does not designate permitted sender hosts) client-ip=197.229.187.240;
    Authentication-Results: mx.google.com;
    spf=neutral (google.com: blinkbvm1@dopefiends.com does not designate permitted sender hosts) smtp.mail=blinkbvm1@dopefiends.com;
    dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
    Message-ID: <5392A16D.302080@dopefiends.com>
    Date: Sat, 7 Jun 2014 07:37:24 +0200
    From: <myemailaddress@gmail.com>
    User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.9.2.12) Gecko/20101027 Thunderbird/3.1.6
    MIME-Version: 1.0
    To: <myemailaddress@gmail.com>
    Subject: [Removed due to inappropriate nature]
    Content-Type: text/plain; charset=UTF-8; format=flowed
    Content-Transfer-Encoding: 7bit

    And none of these emails are showing up in my sent folder.

    Also, my wife recently received a spam email sent to herself from one of her accounts. This account also has (and has had since before the spam) two factor authentication active.

    The email that was sent from her hotmail account also does not appear to be authenticated.

    When I inspect the source of the email I find the following:

    X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
    X-AntiAbuse: Primary Hostname - nc-ph-0088-03.web-hosting.com
    X-AntiAbuse: Original Domain - hotmail.com
    X-AntiAbuse: Originator/Caller UID/GID - [515 516] / [47 12]
    X-AntiAbuse: Sender Address Domain - nc-ph-0088-03.web-hosting.com
    X-Get-Message-Sender-Via: nc-ph-0088-03.web-hosting.com: authenticated_id: emporioa/only user confirmed/virtual account not confirmed
    Return-Path: emporioa@nc-ph-0088-03.web-hosting.com
    X-OriginalArrivalTime: 09 Jun 2014 23:47:28.0733 (UTC) FILETIME=[2C4080D0:01CF843D]

    I find it very disconcerting that all three of our email addresses are having spam issues within a couple days of each other but I still don't see how it is possible that our accounts have been compromised what w/ the 2 factor authentication we run and the fact that all of our computers appear clean after multiple virus/adware/spyware scans. Am I right in assuming that most likely this is a case of our email accounts being spoofed and not that either of our accounts have been compromised? And if they are being spoofed, is there any way to combat this? Thanks in advance!
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds