I'm assuming it is some kind of virus; but it seems strange. I update my definitions daily, but today I got the following:
This came with an attatchment called text.zip that comes up clean when scanned. Now the funny thing is; there IS no staff@portlandsoxfan.com, as I am a one man operation. Here is the detail:
>Return-path: <portlan@server20.totalchoicehosting.com>
Envelope-to: psf@portlandsoxfan.com
Delivery-date: Tue, 02 Mar 2004 19:26:44 -0500
Received: from portlan by server20.totalchoicehosting.com with local-bsmtp (Exim 4.24)
id 1AyKDj-0003cv-Gs
for psf@portlandsoxfan.com; Tue, 02 Mar 2004 19:26:44 -0500
Received: from [141.211.138.55] (helo=michael-a7jfe9q)
by server20.totalchoicehosting.com with smtp (Exim 4.24)
id 1AyKDj-0003cp-4P
for psf@portlandsoxfan.com; Tue, 02 Mar 2004 19:26:43 -0500
Date: Tue, 02 Mar 2004 19:26:44 -0500
To: psf@portlandsoxfan.com
Subject: E-mail account disabling warning.
From: staff@portlandsoxfan.com
Message-ID: <qwtoysfeshkgqjginhy@portlandsoxfan.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="--------ibjtinqlmvrsbmggfkgd"
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on
server20.totalchoicehosting.com
X-Spam-Status: No, hits=-1.3 required=5.0 tests=BAYES_20,NO_REAL_NAME
autolearn=no version=2.63
X-Spam-Level:
my concern is that portlan@server20.totalchoicehosting.com is my main account name...any ideas? My system still comes up clean.
EDIT: OK, I'm tired..it appears that this is a clever little virus that takes the domain of your email address, and makes it look like a custom email from the domain owner. IP goes back to University of Michigan....and I'm not even an Ohio State fan.