Hijacked email

The machines we love to hate

Moderator: Wiz Feinberg

User avatar
David Wright
Posts: 5363
Joined: 4 Aug 1998 11:00 pm
Location: Pilot Point ,Tx USA.
State/Province: -
Country: United States

Hijacked email

Post by David Wright »

I have att email, seems I am sending out Viagra adds...what to do?? Im a Mac user
User avatar
Wiz Feinberg
Posts: 6118
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

What makes you think your Mac is sending out spam?
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
David Wright
Posts: 5363
Joined: 4 Aug 1998 11:00 pm
Location: Pilot Point ,Tx USA.
State/Province: -
Country: United States

Post by David Wright »

two friends asked me about it, they got a email from me with link to a sight I didn't send.
User avatar
Cal Sharp
Posts: 2874
Joined: 4 Aug 1998 11:00 pm
Location: the farm in Kornfield Kounty, TN
State/Province: Tennessee
Country: United States

Post by Cal Sharp »

I got one a couple hours ago. Such a deal on Viagra! Oops, I just checked it again and the page won't load. Oh, well...
C#
Me: Steel Guitar Madness
Latest ebook: Steel Guitar Insanity
Custom Made Covers for Steel Guitars & Amps at Sharp Covers Nashville
User avatar
Wiz Feinberg
Posts: 6118
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

David Wright wrote:two friends asked me about it, they got a email from me with link to a sight I didn't send.
Precisely! You didn't send it and neither did your MacIntosh computer. However, one of your contacts has a Windows computer that is infected with email harvesting malware. Their PC is probably part of a spam Botnet. They had your email name and account details in their address book or contacts list and it was sent home to a spam database. The spammers then sell their harvested email accounts on CDs, by the million names, to others who rent Botnets to send spam for pharmaceuticals, fake diplomas, counterfeit watches and bogus male enhancement products.

Your stolen email details are forged as the sender in some of the spams sent by the rented out Botnet.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Bent Romnes
Posts: 5985
Joined: 28 Feb 2007 2:35 pm
Location: London,Ontario, Canada
State/Province: -
Country: United States

Post by Bent Romnes »

What is this??
A week or so ago, I got the usual newsletter from Bobbe Seymour ...on the usual day of the week. By the address- and subject line it was Bobbe for sure. When I clicked to open it, a spam mail for Viagra appeared in the body of the message...no newsletter. Has Bobbe's or my email been hijacked? This rings of something different than a regular hijack.

The next newsletter from Bobbe 3 days later was A-ok.
User avatar
David Wright
Posts: 5363
Joined: 4 Aug 1998 11:00 pm
Location: Pilot Point ,Tx USA.
State/Province: -
Country: United States

Post by David Wright »

well, I changed my pass word , hope that helps fix it... :D
User avatar
Wiz Feinberg
Posts: 6118
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

Bent Romnes wrote:What is this??
A week or so ago, I got the usual newsletter from Bobbe Seymour ...on the usual day of the week. By the address- and subject line it was Bobbe for sure. When I clicked to open it, a spam mail for Viagra appeared in the body of the message...no newsletter. Has Bobbe's or my email been hijacked? This rings of something different than a regular hijack.

The next newsletter from Bobbe 3 days later was A-ok.
Spammers have performed a Joe Job on Bobbe's email list. You should contact him and let him know. He should check all of his and his store's computers for Spambots and keyloggers.

Tell Bobbe to contact me if he needs assistance tracking this down.

This same thing happened to a friend of mine. He frequently sends group emails and his PC was infected. A harvester component harvested all recognizable email addresses and the names used by the senders. Then, the bot sent links to malware to each recipient, in a group mailing, using a plain text CC list, with a subject including the name of my friend.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Cal Sharp
Posts: 2874
Joined: 4 Aug 1998 11:00 pm
Location: the farm in Kornfield Kounty, TN
State/Province: Tennessee
Country: United States

Post by Cal Sharp »

I wish people would quit forwarding jokes to me and all their other friends with all the email addresses visible. This would help to keep things like this from happening.
BTW, that link I got from David yesterday is back up, and it's a redirect.
well, I changed my pass word , hope that helps fix it...
Since you're able to change your password, that shows that your email account hasn't been compromised (right, Wiz?), so it probably won't do anything about this situation. But it's still a good idea to change passwords every once in a while.
C#
Me: Steel Guitar Madness
Latest ebook: Steel Guitar Insanity
Custom Made Covers for Steel Guitars & Amps at Sharp Covers Nashville
User avatar
Wiz Feinberg
Posts: 6118
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
State/Province: Michigan
Country: United States

Post by Wiz Feinberg »

A CC email group list is a spammer's delight. Some contain over 100 active email addresses and common names. Most spam databases use account details stolen by harvesters on infected PCs that are in Botnets.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Chuck Hall
Posts: 784
Joined: 1 Apr 2000 1:01 am
Location: Warner Robins, Ga, USA
State/Province: -
Country: United States

Post by Chuck Hall »

What about BCC
Chuck
MCI D10 8/4 Nashville 400 and a Profex.
User avatar
Cal Sharp
Posts: 2874
Joined: 4 Aug 1998 11:00 pm
Location: the farm in Kornfield Kounty, TN
State/Province: Tennessee
Country: United States

Post by Cal Sharp »

What about BCC
That's the way to do it.
C#
Me: Steel Guitar Madness
Latest ebook: Steel Guitar Insanity
Custom Made Covers for Steel Guitars & Amps at Sharp Covers Nashville
User avatar
Steve Alonzo Walker
Posts: 471
Joined: 6 Aug 2000 12:01 am
Location: Spartanburg,S.C. USA (deceased)
State/Province: -
Country: United States

Post by Steve Alonzo Walker »

My Hotmail was hacked on July5th. I filled out a form from Microsoft about this and they sent me a reset for my password and now i'm back in control.