Spoofed email

Frogpond51

New member
Local time
7:00 PM
Messages
86
Location
In the pond -of course!
Hi All,
I received an email from my cousin that she never sent to me. Looking at the body of the letter it was apparent that her name was altered and her email address in "<xxxxxxxxxx>" was incorrect. The hyperlink was also suspicious. Of course I did not click on it and called her to verify that she did not send it.
We have both updated & scanned our computers with anti-virus & anti-malware programs and come up clean.
Question: Is it possible to track down the original sender and what the threat would be that they are sending?
Is there any good sites or tutorials on how to track down this type of junk?
I have saved the code of the email, but am unsure what all the IP addresses in the code mean in back-tracking this. I know this isn't a high priority issue to most, but it's got me a little pissed and I just wanted to know how to track down this crap and maybe find out what the real threat might be.
Any help or input is greatly appreciated.
Thanks for reading & Cheers!

Froggy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
I used to get these all the time after my ISP changed email providers. I have even gotten email from myself that was spoofed. The only way we got rid of it was to send the ISP support folks the offending emails, which they sent to the email provider (tucows). Eventually, the spoofed emails stopped for the most part. We still get one every few months and I just forward them on to the the ISP support team.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
ASUS
OS
Windows 7 Home Premium 64 bit SP1
CPU
i5-2320 @3.00 GHz
Memory
6GB
Graphics Card(s)
NVIDIA GeForce 7300 LE
Monitor(s) Displays
Acer S200HQL 19.5 LED
Screen Resolution
1280 x 800 (1900 x 900 max)
Hard Drives
Drive 1: 1 TB SATA internal: C drive
Drive 2: 250 GB SATA internal: User Data Backup
Drive 3: 500 GB SATA USB: Full System Backup 1, Father
Drive 4: 500 GB SATA USB: Full System Backup 2, Son
Drive 5: 40 GB IDE USB: Kindle, ASUS Tabl
Keyboard
ASUS KB34211
Mouse
Logitech m325 cordless
Internet Speed
27Mb down, 3 Mb up cable modem w/Netgear R6400 WiFi
Antivirus
NIS, Spybot S&D, CCleaner, Malwarebytes, MSERT, MRT
Browser
FF v44.0.2;IE11 v11.0.9600.18015,uv11.0.23;Chrome v44.0.2403
Other Info
FF has AdBlockPlus and Ghostery plugins,
Hi jamis, thanks for the good advice reporting to the ISP folks.
I guess my main question is, can I play detective and track the rats down and find out what the real threat might be? I'm just curious on how to do this & a bit put off about it.

Cheers!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
I found it to be a pretty futile effort. After talking with my ISP's support folks, the problem was at the email service provider's end. It seemed that someone had a worm in their system and was stealing email addresses as they went through their system. All of the spoofed emails we got were scam pitches or phising attempts. It was frustrating while it was happening, but letting the email provider fix it was the best recourse. I just kept sending the offending emails to the ISP until it stopped. Oddly enough, I've not had this issue with Yahoo or gMail accounts, but these are specialty used only for certain organization memberships I have. Our primary email account is through our ISP, which is also our cable TV, and land line phone provider.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
ASUS
OS
Windows 7 Home Premium 64 bit SP1
CPU
i5-2320 @3.00 GHz
Memory
6GB
Graphics Card(s)
NVIDIA GeForce 7300 LE
Monitor(s) Displays
Acer S200HQL 19.5 LED
Screen Resolution
1280 x 800 (1900 x 900 max)
Hard Drives
Drive 1: 1 TB SATA internal: C drive
Drive 2: 250 GB SATA internal: User Data Backup
Drive 3: 500 GB SATA USB: Full System Backup 1, Father
Drive 4: 500 GB SATA USB: Full System Backup 2, Son
Drive 5: 40 GB IDE USB: Kindle, ASUS Tabl
Keyboard
ASUS KB34211
Mouse
Logitech m325 cordless
Internet Speed
27Mb down, 3 Mb up cable modem w/Netgear R6400 WiFi
Antivirus
NIS, Spybot S&D, CCleaner, Malwarebytes, MSERT, MRT
Browser
FF v44.0.2;IE11 v11.0.9600.18015,uv11.0.23;Chrome v44.0.2403
Other Info
FF has AdBlockPlus and Ghostery plugins,
You probably would not be successful in tracking down the source of the email. Typically the sender has gone to great lengths to make this as difficult as possible. Assessing the nature of the threat would also be very difficult.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP
OS
Windows 7 Pro 64 bit
CPU
Xeon W3520
Memory
8 GB
Graphics Card(s)
Nvidia Geforce 210
One last thought. Your cousin's email or provider may be the source of the spoofed address. If you have only gotten spoofed email from her, then the issue may be at her end.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
ASUS
OS
Windows 7 Home Premium 64 bit SP1
CPU
i5-2320 @3.00 GHz
Memory
6GB
Graphics Card(s)
NVIDIA GeForce 7300 LE
Monitor(s) Displays
Acer S200HQL 19.5 LED
Screen Resolution
1280 x 800 (1900 x 900 max)
Hard Drives
Drive 1: 1 TB SATA internal: C drive
Drive 2: 250 GB SATA internal: User Data Backup
Drive 3: 500 GB SATA USB: Full System Backup 1, Father
Drive 4: 500 GB SATA USB: Full System Backup 2, Son
Drive 5: 40 GB IDE USB: Kindle, ASUS Tabl
Keyboard
ASUS KB34211
Mouse
Logitech m325 cordless
Internet Speed
27Mb down, 3 Mb up cable modem w/Netgear R6400 WiFi
Antivirus
NIS, Spybot S&D, CCleaner, Malwarebytes, MSERT, MRT
Browser
FF v44.0.2;IE11 v11.0.9600.18015,uv11.0.23;Chrome v44.0.2403
Other Info
FF has AdBlockPlus and Ghostery plugins,
@jamis: thanks for the input, yes I received a similar email from another person we both know the day before, but I had just deleted when I saw it, so we are presuming that it is another person we know that is infected. The list of recipients CC'd was selective, only a few of the same contacts.

@LMiller7: Thanks for your reply. Guess I can't play detective then? I was hoping that I could sleuth this without too much complication. It appears the opinions are that this is a futile attempt to find the culprit(s).

Thanks for your replies,
Cheers!
Froggy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
Rogue email that appears to come from a friend is often due to the friend having a virus that has scanned their email contact list and sent back the data (and the friend's details). This could have happened a while ago and the virus could have been found and removed during a regular scan. It's a simple matter for the hacker to send out spoofed emails to all the people on his list (apparently from their friends). There's usually a link in the email 'here's a cute cat' etc that is in fact a link to more malware.

It's quite easy to change the info in an email header so it appears to come from elsewhere, although IIRC some providers check for a data mismatch and warn you.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
Windows 7 Pro x64 sp1
CPU
i7 4770K
Motherboard
MSI B85M-E45
Memory
8GB Corsair Vengeance 1600MHz
Graphics Card(s)
onboard
Monitor(s) Displays
LG 27MP35
Screen Resolution
1920-1080
Hard Drives
Seagate 2TB
PSU
Cooler Master GX 750
Case
Antec 300
Cooling
Seidon 120V
Internet Speed
60/18
Antivirus
MSE
Browser
Firefox
Hi badcrc, thanks for your reply,
Yes the body of the letter has the reference like " ...Oprah thinks it's awesome" blabla, then the suspect hyperlink. I could post a screenshot of the body of the letter with email recipients and hyperlink blacked out, but it probably wouldn't be much help. :rolleyes:

Cheers!
Froggy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
This site can give some info on email origin etc

Trace Email IP: Track Email Header, Email Tracker, Email Tracer - ID Mail Tracking

I use Thunderbird, and I just tried the site by view - message source - and copy/pasting the header info from the msg Seven Forums just sent. It showed origin as Houston, Texas and a ton of other stuff. I guess your rogue email would show Russia, China etc (no insults intended).

This all happened to me a few years ago - I started getting suspicious emails supposedly from a mate. Either by accident or design, the hacker had included his contact list as cc (and so were visible to me). The thing is - he'd been on dating sites, so had contacts like sexylady99, foxybabe77 etc (he never lived that one down LOL). I guess that's where he got the virus. I actually closed that gmail account, just to be on the safe side. Took a while to change all my eBay, Amazon etc.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
Windows 7 Pro x64 sp1
CPU
i7 4770K
Motherboard
MSI B85M-E45
Memory
8GB Corsair Vengeance 1600MHz
Graphics Card(s)
onboard
Monitor(s) Displays
LG 27MP35
Screen Resolution
1920-1080
Hard Drives
Seagate 2TB
PSU
Cooler Master GX 750
Case
Antec 300
Cooling
Seidon 120V
Internet Speed
60/18
Antivirus
MSE
Browser
Firefox
One small step for the future.
Request all your friends to change their passwords. Of course this will not help with the already stole information.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Hi badcrc, thanks for the link!
I had my suspicions that it was from here, but wasn't sure.
Here is the header info without the offending IP address...

IP Address Country: Argentina
IP Continent: South America
IP Address City Location: Buenos Aires
IP Address Region: Distrito Federal
IP Address Latitude: -34.6506,
IP Address Longtitude: -58.3822
Organization: Telefonica de Argentina
ISP: Telefonica de Argentina

Cheers!
Froggy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
Hi Layback Bear,
Thanks for the post. Yup, that is good advice indeed, to be safe. I'm pretty sure we haven't been compromised. However, I'm sure someone we know mutually has this email bug. :(
Too bad I couldn't post the the suspect link somewhere to find out what the threat actually is in this link...

Cheers!
Froggy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Ultimate 64bit & Windows XP Pro (Dual Boot)
CPU
AMD Phenom II x4 965 3.40GHz
Motherboard
ECS A885GM-A2
Memory
8.00 GB
Graphics Card(s)
AMD Radeon HD 6670
Monitor(s) Displays
HP L2445w
Screen Resolution
1920 x 1200
Hard Drives
Samsung SSD 840 series SATA 120GB-Win 7 &
WD 1Tb Caviar Black 7200 rpm-XP Pro
PSU
Cooler Master Elite Power 460 Watt ATX Power Supply
Case
Thermaltake V3 Black Edition ATX Mid Tower
Cooling
Cooler Master Hyper 212 EVO Universal CPU Cooler
Keyboard
Logitech
Internet Speed
30 Mg download-10 Mg upload
Antivirus
Bitdefender & Malwarebytes Pro
Browser
IE 11-because I like a SLOW browser!
Back
Top