Am primit si eu in ultima perioada cam 20 de emailuri de phishing. Din curiozitate am dat click pe link ca sa vad din ce zona geografica este serverul infectat. Era din insulele Maldive. Le`am trimis la proprietarii site`ului un email prin care ii informam ca serverul lor a fost spart si ca se face phishing de pe siteul lor dar emailul mi`a fost rejectat. Dilema mea este: hackerii au corupt si sistemul de mail sau exista o alta cauza tehnica pentru care mi`a fost rejectat mailul?
Uitati ce am primit inapoi:
This report relates to a message you sent with the following header fields:
Return-path: <
accesinterzis@gmail.com>
Received: from tcp_intranet-daemon.inet01.mv.undp.org by inet01.mv.undp.org
(iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8 2003))
id <
FOBT08T02YXO0301VW@inet01.mv.undp.org>; Sun,
1 FEB 2009 02:16:38 +0500 (West Asia Standard Time)
Received: from dedicated832.dhivehinet.net.mv
(dedicated832.dhivehinet.net.mv [192.168.1.123])
by inet01.mv.undp.org (iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8
2003)) with SMTP id <
FO9X08T11BVC0302H0@inet01.mv.undp.org> for
ahmed.nazif@undp.org (ORCPT
ahmed.nazif@undp.org); Sun,
01 Feb 2009 02:16:30 +0500 (West Asia Standard Time)
Received: from inet01.mv.undp.org ([192.168.1.123])
by dedicated832.dhivehinet.net.mv (SMSSMTP 4.0.5.66)
with SMTP id M2009020102162812257 for <
ahmed.nazif@undp.org>; Sun,
01 Feb 2009 02:16:29 +0500
Received: from mr01.undp.org (mr01.undp.org [57.69.30.7])
by inet01.mv.undp.org (iPlanet Messaging Server 5.2 HotFix 1.21 (built Sep 8
2003)) with ESMTP id <
FNY108TYBIMW03021G@inet01.mv.undp.org> for
ahmed.nazif@undp.org (ORCPT
mvwebmaster@undp.org); Sun,
01 Feb 2009 02:16:27 +0500 (West Asia Standard Time)
Received: from mr01.undp.org (localhost [127.0.0.1]) by mr01.undp.org (Postfix)
with SMTP id 526D9D6C98E; Sat, 31 Jan 2009 16:16:14 -0500 (EST)
Received: from psmtp.com (exprod7mx246.postini.com [64.18.2.100])
by mr01.undp.org (Postfix) with SMTP id 33B5FD6C82B; Sat,
31 Jan 2009 16:16:11 -0500 (EST)
Received: from source ([72.14.204.175]) by exprod7mx246.postini.com
([64.18.6.14]) with SMTP; Sat, 31 Jan 2009 16:16:20 -0500 (EST)
Received: by qb-out-1314.google.com with SMTP id q18so411359qbq.28 for
<multiple recipients>; Sat, 31 Jan 2009 13:16:17 -0800 (PST)
Received: by 10.142.218.4 with SMTP id q4mr1095023wfg.225.1233436576085; Sat,
31 Jan 2009 13:16:16 -0800 (PST)
Date: Sat, 31 Jan 2009 23:16:16 +0200
From: marian marian <
accesinterzis@gmail.com>
Subject: Alert !!!
To:
registry.mv@undp.org,
aminath.ibrahim@undp.org,
mvwebmaster@undp.org Message-id: <
bd8df3e80901311316i6dad3f34t31f4acc21460488e@mail.gmail.com>
MIME-version: 1.0
Content-type: multipart/alternative; boundary=000e0cd22f28f875a40461cdd469
Authentication-Results: mr01.undp.org; dkim=pass (1024-bit key)
header.i=@gmail.com
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com;
s=gamma; h=domainkey-signature:mime-version:received:date:message-id:subject
:from:to:content-type; bh=Qi+MiJNMlk+O11xYhY0YK6OofdJOxjQqAM2xiGVrXFU=;
b=unv5b0AvxNs3gSrOYDW9I1Z8GRx+jhBmi6NDxTOm6UyPZvqLuGg9q2Se5kPyEEvQfD
fA85FdyoqEa2D6bufXTbBNcF201IE1xQl+TMbOaKsZ06TJA37Yw1TNjtmfH4GNWzMMvJ
FoaRy8dLFFuRVeAEdMQxY8D6YTbnqkyHIP4qE=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:to:content-type;
b=jQOiOBcFVcVjgr5auCrdn8AxPYigaZrv4UHJQFlOJeDlDGIK8733H6XmIpfEJFTLJK
9VB1LTyN+CQydO4auGUkf9jDIJptO8ANi7B6RXC+VgWgT8N8P4CruRZ6Blji7RoEHSb1
FEROngjI0HlYFFe5+micIRbrCXFtB5QvU6VH0=
X-DKIM: Sendmail DKIM Filter v2.4.0 mr01.undp.org 33B5FD6C82B
X-pstn-neptune: 0/0/0.00/0
X-pstn-levels: (S: 8.74983/99.90000 CV:99.9000 R:95.9108 P:95.9108 M:97.0282
C:98.6951 )
X-PMX-Version: 5.5.1.360522, Antispam-Engine: 2.6.1.350677,
Antispam-Data: 2009.1.31.210418
X-PMX-Spam: Gauge=IIIIIIIII, Probability=10%,
Report='CTYPE_MULTIPART_NO_QUOTE 0.5, FORGED_FROM_GMAIL 0.1,
BODY_SIZE_1000_LESS 0, BODY_SIZE_2000_LESS 0, BODY_SIZE_5000_LESS 0,
BODY_SIZE_800_899 0, SMALL_BODY 0, __CP_MEDIA_BODY 0, __CP_URI_IN_BODY 0,
__CT 0, __CTYPE_HAS_BOUNDARY 0, __CTYPE_MULTIPART 0, __CTYPE_MULTIPART_ALT 0,
__FRAUD_419_WEBMAIL 0, __FRAUD_419_WEBMAIL_FROM 0, __FROM_GMAIL 0,
__HAS_HTML 0, __HAS_MSGID 0, __MIME_HTML 0, __MIME_VERSION 0,
__PHISH_IMG_UL_DIR_WEBPAGE 0, __PHISH_SPEAR_SUBJECT 0, __SANE_MSGID 0,
__STOCK_SUBJ_9 0'
Your message cannot be delivered to the following recipients:
Recipient address: @mr01.hq.undp.org:ahmed.nazif@undp.org
Original address:
ahmed.nazif@undp.org Reason: Remote SMTP server has rejected address
Diagnostic code: smtp;550 5.1.1 <
ahmed.nazif@undp.org>: Recipient address rejected: User unknown in relay recipient table
Remote system: dns;smtp.undp.gmessaging.net (mr03.undp.org ESMTP Postfix)
Reporting-MTA: dns;inet01.mv.undp.org (tcp_intranet-daemon)
Original-recipient: rfc822;
ahmed.nazif@undp.orgFinal-recipient: rfc822;@mr01.hq.undp.org:ahmed.nazif@undp.org
Action: failed
Status: 5.1.1 (Remote SMTP server has rejected address)
Remote-MTA: dns;smtp.undp.gmessaging.net (mr03.undp.org ESMTP Postfix)
Diagnostic-code: smtp;550 5.1.1 <
ahmed.nazif@undp.org>: Recipient address
rejected: User unknown in relay recipient table
-----Inline Message Follows-----
Some blackhat hackers crack your server and now they make phishing by your site. Verify this URL urgent
http://www.mv.undp.org//Images/undp/login.htmThis blackhat hackers fraud the Raiffeisen Bank and Raiffeisen Bank`s clients.