 1 edit | [Scam] Your InDesign CS4 License Key Here Received: from EDGE101.ihostexchange.net (66.46.182.31) by hub105.ihostexchange.net (66.46.182.55) with Microsoft SMTP Server (TLS) id 8.3.137.0; Wed, 2 Nov 2011 19:37:25 -0400 Received: from mc-tc-102.ihostexchange.net (66.46.182.95) by mail1.ihostexchange.net (66.46.182.31) with Microsoft SMTP Server id 8.3.137.0; Wed, 2 Nov 2011 19:37:25 -0400 Received: from adobe.com ([UNAVAILABLE]. [193.133.138.40]) by 66.46.182.95:25 (trex/4.3.64); Wed, 02 Nov 2011 23:37:25 GMT X-MC-REJECTLIMIT: 100 X-MC-JUNKLIMIT: 90 X-MC-DATA: Organization Settings: adobe.com X-MC-RESULT: WHITELIST X-MC-CM-SCORE: 100 X-MC-DELIVER: INBOX Message-ID: <002b01cc99b8$5e5f344e$2406ea0a@d09387> From: Adobe <news-no8715[at]adobe.com> To: <gp [ at ] (domain hidden)> BCC: <gp [ at ] greenwaldrealty dot com>, <gp [ at ] greenwichvillagepr dot com>, <gp [ at ] gregnrykyleandassociates dot com>, <gp [ at ] gregorykyleandassociates dot com> Subject: Your InDesign CS4 License key here Date: Wed, 2 Nov 2011 23:37:22 +0100 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_0026_01CC99B8.5E5CBD30" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.2180 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 Return-Path: news-no8715@adobe.com
Message:
Dear customer,
Your Adobe CS4 License key is in attached document below. We encourage you to explore its new and enhanced capabilities with these helpful tips, tutorials, and eSeminars. Thank you for buying Adobe InDesign CS4 software.
Adobe Systems Incorporated
:End Message
Attachment: License_key_N2570.zip
VirusTotal Data:
MD5: 9e215c17894435a548d2887cb068b909 Date first seen: 2011-11-03 03:16:29 (UTC) Date last seen: 2011-11-03 05:21:04 (UTC) Detection ratio: 6/43
I'm unsure if Adobe's mail server have been compromised or not. I bet Adobe would never send an attachment containing a product key. I'm wondering if that attachment is already in VirusTotal as I'm going to delete this right away.
Note: I've deleted the e-mail and the attachment permanently.
Update: Fixed the < and >.
-- Current Soft Phone (temp): Ekiga (ordered Yealink T22P to switch from Ekiga) Phone System: Asterisk 1.8; Server: Ubuntu Server 10.04 with Windows Server 2008 R2 Standard as guest |
|
|
|
 AVDRespice, Adspice, ProspicePremium join:2003-02-06 Onion, NJ | could be a bad email address |
|
 jimkyleBtrieve GuyPremium join:2002-10-20 Oklahoma City, OK kudos:2 | could be, I guess, but I got it twice from two different senders -- and the only Adobe product I use is their "Digital Editions" that's required by my local library for electronic checkout... -- Jim Kyle |
|
 | Dear customer,
If you receive the following email, it is a scam:
Your Adobe CS4 License key is in attached document below. We encourage you to explore its new and enhanced capabilities with these helpful tips, tutorials, and eSeminars. Thank you for buying Adobe InDesign CS4 software.
Adobe Systems Incorporated |
|
 Doctor FourMy other vehicle is a TARDISPremium join:2000-09-05 Dallas, TX | reply to GraysonPeddi It's a trojan downloader, and not from Adobe. I got one in my Yahoo spam folder a few days after first seeing this topic and searching the MD5 on VirusTotal. It is now being detected by 18/43 scanners.
Avira AntiVir is one of those that detects it, so it is likely I would not have been able to download it to submit it to VirusTotal. -- I, for one, welcome our new Computer Overlords. |
|
 | Well, that's good to know I'm not alone, because about 96 to 99% of the time, I've rarely received spam in my e-mail account. I've blacklisted the following TLDs and free services:
•*.biz •*.ch •*.cn •*.in •*.nl •*.pl •*.ru •@gmail.* •@live.* •@yahoo.*
Of course, I do whitelist those that I have relationship or done business with.
Perhaps someone at Adobe got tired and must have caused a mischief -- or something. -- Current Soft Phone (temp): Ekiga (ordered Yealink T22P to switch from Ekiga) Phone System: Asterisk 1.8; Server: Ubuntu Server 10.04 with Windows Server 2008 R2 Standard as guest |
|
 Doctor OldsI Need A Remedy For What's Ailing Me.Premium,VIP join:2001-04-19 1970 442 W30 kudos:18 | said by GraysonPeddi:Perhaps someone at Adobe got tired and must have caused a mischief -- or something. It didn't come from Adobe or even through Adobe servers. Check the IPs listed as the Adobe.com header is clearly a forgery. -- Whats the point of owning a supercar if you cant scare yourself stupid from time to time? |
|