• Strange Email

    From Buffalo@1:396/4 to All on Sat Dec 3 23:05:22 2016
    From: "Buffalo" <phoney@physco.invalid.net>

    It was sent to me by 'me' and I didn't send it.
    The sending and receiving addy are the same.
    The Subject was "Wife Out of Control" and it contained a 9 kb .dat file.
    Here are some portions of that email which I opened with NotePad Plus after submitting it to 3 different websites and MBAM, SAS and Avast for checks.
    Top couple of lines are:

    --J40RcGh9G43sZJ6E6s"
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: base64


    Last several lines are:

    "NzNPVSc+Cjxicj4KPElNRyBzcmM9Imh0dHA6Ly9wbGFjZXBoYWwuc3BhY2UvODU3My84WlphZS5q cGciPjwvYT4KPGJyPgo8YSBocmVmPSdodHRwOi8vcGxhY2VwaGFsLnNwYWNlLzM1MzU3N1NHMzY4 Mzc1TU0zODM2NDA5MlJtODIzMGdoOHdSdTg1NzNGVCc+CjxJTUcgc3JjPSJodHRwOi8vcGxhY2Vw aGFsLnNwYWNlLzg1NzMvT3M4U0suanBnIj48L2E+CjxJTUcgc3JjPSdodHRwOi8vcGxhY2VwaGFs LnNwYWNlLzM1MzU3N25FMzY4Mzc1Q0gzODM2NDA5MnFrODIzMGhkOFVjbzg1NzNudCcgd2lkdGg9 JzFweCcgaGVpZ2h0PScxcHgnPgo="

    Any ideas on what is going on?

    Thanks,
    Buffalo

    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
  • From mark lewis@1:3634/12.73 to Buffalo on Sun Dec 4 17:23:18 2016

    03 Dec 16 23:05, you wrote to All:

    From: "Buffalo" <phoney@physco.invalid.net>

    [trim]

    Any ideas on what is going on?

    it is mime encoded spam... they're trying to get to to go to some web site... probably an infester site... if you don't send mail to yourself, set up a rule to delete them... either way, it is spam...

    you're probably wondering how i know it is trying to send you to some web site... i know because i paste the block of mime into an online decoder and read the results ;)

    i used this site here: https://www.base64decode.org/

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... To be wronged is nothing unless you continually remember it.
    ---
    * Origin: (1:3634/12.73)
  • From Wolf K@1:396/4 to All on Sun Dec 4 06:42:30 2016
    From: Wolf K <wolfmac@sympatico.ca>

    On 2016-12-04 14:05, Buffalo wrote:
    It was sent to me by 'me' and I didn't send it.
    The sending and receiving addy are the same.
    The Subject was "Wife Out of Control" and it contained a 9 kb .dat file. Here are some portions of that email which I opened with NotePad Plus after submitting it to 3 different websites and MBAM, SAS and Avast for checks.
    Top couple of lines are:

    --J40RcGh9G43sZJ6E6s"
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: base64


    Last several lines are:

    "NzNPVSc+Cjxicj4KPElNRyBzcmM9Imh0dHA6Ly9wbGFjZXBoYWwuc3BhY2UvODU3My84WlphZS5q cGciPjwvYT4KPGJyPgo8YSBocmVmPSdodHRwOi8vcGxhY2VwaGFsLnNwYWNlLzM1MzU3N1NHMzY4 Mzc1TU0zODM2NDA5MlJtODIzMGdoOHdSdTg1NzNGVCc+CjxJTUcgc3JjPSJodHRwOi8vcGxhY2Vw aGFsLnNwYWNlLzg1NzMvT3M4U0suanBnIj48L2E+CjxJTUcgc3JjPSdodHRwOi8vcGxhY2VwaGFs LnNwYWNlLzM1MzU3N25FMzY4Mzc1Q0gzODM2NDA5MnFrODIzMGhkOFVjbzg1NzNudCcgd2lkdGg9 JzFweCcgaGVpZ2h0PScxcHgnPgo="

    Any ideas on what is going on?

    Thanks,
    Buffalo

    Common hack + phishing. Quite easy to do.

    --
    Best,
    Wolf K
    https://kirkwood40.blogspot.com
    It's called "opinion" because it's not knowledge.
    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
  • From Buffalo@1:396/4 to All on Mon Dec 5 00:00:12 2016
    From: "Buffalo" <phoney@physco.invalid.net>

    "mark lewis" wrote in message news:000011c2@net396.fidonet.org...

    + User FidoNet address: 1:3634/12.73
    03 Dec 16 23:05, you wrote to All:

    From: "Buffalo" <phoney@physco.invalid.net>

    [trim]

    Any ideas on what is going on?

    it is mime encoded spam... they're trying to get to to go to some web >site...
    probably an infester site... if you don't send mail to yourself, set up a >rule
    to delete them... either way, it is spam...

    you're probably wondering how i know it is trying to send you to some web >site... i know because i paste the block of mime into an online decoder and >read the results ;)

    i used this site here: https://www.base64decode.org/

    Thanks to both of you for your informative replies.
    --
    Buffalo

    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
  • From Buffalo@1:396/4 to All on Wed Dec 21 00:50:00 2016
    From: "Buffalo" <phoney@physco.invalid.net>

    It was sent to me by 'me' and I didn't send it.
    The sending and receiving addy are the same.
    The Subject was "Wife Out of Control" and it contained a 9 kb .dat file. Here are some portions of that email which I opened with NotePad Plus after submitting it to 3 different websites and MBAM, SAS and Avast for checks. Top couple of lines are:

    --J40RcGh9G43sZJ6E6s"
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: base64


    Last several lines are:

    "NzNPVSc+Cjxicj4KPElNRyBzcmM9Imh0dHA6Ly9wbGFjZXBoYWwuc3BhY2UvODU3My84WlphZS5q cGciPjwvYT4KPGJyPgo8YSBocmVmPSdodHRwOi8vcGxhY2VwaGFsLnNwYWNlLzM1MzU3N1NHMzY4 Mzc1TU0zODM2NDA5MlJtODIzMGdoOHdSdTg1NzNGVCc+CjxJTUcgc3JjPSJodHRwOi8vcGxhY2Vw aGFsLnNwYWNlLzg1NzMvT3M4U0suanBnIj48L2E+CjxJTUcgc3JjPSdodHRwOi8vcGxhY2VwaGFs LnNwYWNlLzM1MzU3N25FMzY4Mzc1Q0gzODM2NDA5MnFrODIzMGhkOFVjbzg1NzNudCcgd2lkdGg9 JzFweCcgaGVpZ2h0PScxcHgnPgo="

    Any ideas on what is going on?

    Thanks,
    Buffalo

    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
  • From FromTheRafters@1:396/4 to All on Tue Dec 20 21:47:44 2016
    From: FromTheRafters <erratic@nomail.afraid.org>

    Buffalo pretended :
    + User FidoNet address: 1:396/4
    From: "Buffalo" <phoney@physco.invalid.net>

    It was sent to me by 'me' and I didn't send it.
    The sending and receiving addy are the same.
    The Subject was "Wife Out of Control" and it contained a 9 kb .dat file. Here are some portions of that email which I opened with NotePad Plus after submitting it to 3 different websites and MBAM, SAS and Avast for checks. Top couple of lines are:

    --J40RcGh9G43sZJ6E6s"
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: base64


    Last several lines are:

    "NzNPVSc+Cjxicj4KPElNRyBzcmM9Imh0dHA6Ly9wbGFjZXBoYWwuc3BhY2UvODU3My84WlphZS5q cGciPjwvYT4KPGJyPgo8YSBocmVmPSdodHRwOi8vcGxhY2VwaGFsLnNwYWNlLzM1MzU3N1NHMzY4 Mzc1TU0zODM2NDA5MlJtODIzMGdoOHdSdTg1NzNGVCc+CjxJTUcgc3JjPSJodHRwOi8vcGxhY2Vw aGFsLnNwYWNlLzg1NzMvT3M4U0suanBnIj48L2E+CjxJTUcgc3JjPSdodHRwOi8vcGxhY2VwaGFs LnNwYWNlLzM1MzU3N25FMzY4Mzc1Q0gzODM2NDA5MnFrODIzMGhkOFVjbzg1NzNudCcgd2lkdGg9 JzFweCcgaGVpZ2h0PScxcHgnPgo="

    Any ideas on what is going on?

    Thanks,
    Buffalo

    That is a form for you to fill out in order to remove your email and to confirm the email address at which you received their email.

    hxxp://placephal.space/
    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
  • From FromTheRafters@1:396/4 to All on Tue Dec 20 21:49:44 2016
    From: FromTheRafters <erratic@nomail.afraid.org>

    It happens that Buffalo formulated :
    + User FidoNet address: 1:396/4
    From: "Buffalo" <phoney@physco.invalid.net>

    It was sent to me by 'me' and I didn't send it.
    The sending and receiving addy are the same.
    The Subject was "Wife Out of Control" and it contained a 9 kb .dat file. Here are some portions of that email which I opened with NotePad Plus after submitting it to 3 different websites and MBAM, SAS and Avast for checks. Top couple of lines are:

    --J40RcGh9G43sZJ6E6s"
    Content-Type: text/html; charset=UTF-8
    Content-Transfer-Encoding: base64


    Last several lines are:

    "NzNPVSc+Cjxicj4KPElNRyBzcmM9Imh0dHA6Ly9wbGFjZXBoYWwuc3BhY2UvODU3My84WlphZS5q cGciPjwvYT4KPGJyPgo8YSBocmVmPSdodHRwOi8vcGxhY2VwaGFsLnNwYWNlLzM1MzU3N1NHMzY4 Mzc1TU0zODM2NDA5MlJtODIzMGdoOHdSdTg1NzNGVCc+CjxJTUcgc3JjPSJodHRwOi8vcGxhY2Vw aGFsLnNwYWNlLzg1NzMvT3M4U0suanBnIj48L2E+CjxJTUcgc3JjPSdodHRwOi8vcGxhY2VwaGFs LnNwYWNlLzM1MzU3N25FMzY4Mzc1Q0gzODM2NDA5MnFrODIzMGhkOFVjbzg1NzNudCcgd2lkdGg9 JzFweCcgaGVpZ2h0PScxcHgnPgo="

    Any ideas on what is going on?

    Thanks,
    Buffalo

    http://d-info.me/placephal.space
    --- NewsGate v1.0 gamma 2
    * Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)