I'm getting a surge in bounced e-mails that I didn't send (thanks to the protection offered by Sender Policy framework - SPF) of TROJ_AGENT.AYZO (or some variant of it) trying to spam people with links to infected web sites using an invalid user address at this domain.
If you receive an e-mail from prototypetimeless (note the backwards order of surname and firstname) from the timelessprototype dot com domain which contains a link to any URL ending in "viewmovie.html", it ain't from me and someone is intending to get your computer infected, so don't click the link.
I have a saying: If you have evidence that I've tried to hack you, then I've been framed. However, that kind of integrity has been recognized and the spammer obviously knows this and intends to make use of that trust on innocent victims by using an (incorrect) e-mail address at my domain, hoping people will click it.
I've never used that user address at this domain ever, so someone must have constructed it by hand. I find it hard to believe a spam bot would know that a domain it's about to spoof contains two words and that it should swap those two words for the username. This feels targetted. At least, that's probably what someone wants me to think.
Phail tbh.
Please remember to implement Sender Policy Framework in your DNS and configure your mail servers to use strict SPF.
The nice thing about SPF bounced e-mails, I get to see the IP addresses of who's trying to send them
. So if any virus researchers, ISPs and/or law enforcement types want those, please contact me via the contact page on this blog. Thanks.
Currently rated 5.0 by 2 people
- Currently 5/5 Stars.
- 1
- 2
- 3
- 4
- 5