Who Or What Is Sending Stuff From My Mailbox?

Discussion in 'Malware Help - Public (Anyone Can Post & Respond)' started by Earthling, Feb 8, 2018.

  1. Earthling

    Earthling Interplanetary Geek

    Had two 'undeliverable' notifications in the last 24 hours, both from the same domain but with different names. Both had attachments which I have not tried to open. I've had this now unused account nearly 20 years and this has never happened before, though the ISP in question has a poor security record and the account does get a lot of spam. Can anyone throw any light on the content?

    Capture.PNG
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you have been hacked. Of course one solution would be to dump the account and create a new one. Another thing you can try is to create a new folder, move all your known none infected type emails to that folder and delete the original folder. I assume you have marked them as spam? Did you try looking up the IP addy?
     
  3. Earthling

    Earthling Interplanetary Geek

    tracert failed after just three hops so no joy there. These messages are telling me that something is sending from my account so I don't want them just disappearing into Junk, I want to know. What I would really like to know is what messages were sent successfully, but if there are any my Sent folder isn't recording them. I would simply close the account but the ISP doesn't provide the means to do so.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    person: Nguyen Dang Tiep
    address: Viettel Network Corporation
    address: No 1, Tran Huu Duc street, My Dinh 2 ward, Nam Tu Liem
    Viet Nam.
     
  5. Earthling

    Earthling Interplanetary Geek

    A new password should sort it.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As long as you use a different computer to do it.
     
  7. Earthling

    Earthling Interplanetary Geek

    Interesting point - the account is on every computer here and is an IMAP account. No way to identify which computer has been compromised or which would be safe to use.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing that comes to mind is that they spoofed your email account, sent emails to a dummy account so it would be returned to you in the hopes you would become curious and open the attachment. I hope that without any response, they will give up sooner or later.
     
  9. Earthling

    Earthling Interplanetary Geek

    I like that Tim - just hope it's right. Thanks.
     
  10. Geek_Justin

    Geek_Justin Corporal

    Howdy forum, I'm Justin's dad Dan. I saw this post checking out his forums. The name that Tim found comes back to the Vietnamese Ministry of Defense. There are spiders that comb the web for old unused email accounts to take over. If this is an unused account I'd try to get it deleted. If not as suggested above change the password using a different computer and do it three times.
     
  11. Earthling

    Earthling Interplanetary Geek

    Hi Dan. As I said in #7 the account is an IMAP account so these undeliverable notices are not associated with any one computer. The two messages were received about 12 hours apart four days ago and nothing since so atm I'm inclined to think TimW may be right (#8). It isn't possible to delete the account as the ISP that issued it long since disappeared in subsequent mergers. It's quite possible though that I may be able to change the password on the server. Haven't tried yet as I want to see if it continues.
     
  12. Replicator

    Replicator MajorGeek

    Yes, no response/activity is best....their bots will drop the account and move on, which it seems they may have already done so!

    A password change (if possible) will also kill the motivation to re-exploit a dead end.

    Smart kid you have there Dan!
     
    Last edited: Feb 21, 2018
  13. Earthling

    Earthling Interplanetary Geek

    It has been impossible for the last few days to login to this compromised account, either via a client or on the ISPs website. Not only that but a number of others using addresses at the same old domain have also found they cannot login - Incorrect Username or Password. Since all these addresses are quite old and have been running ok for years it's clearly not a coincidence. The staff there are investigating and say their system automatically disables compromised accounts. They say they will issue new usernames and passwords for affected accounts so this looks like my chance to close the account. I'm assuming it's their server that was cracked rather than any computer here but they aren't commenting on that.
     
    TimW likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds