Die Mugu-Parade, Teil 1:
Spamcast-Zombie in Florida:
header:
01: Received: from mta03.eastlink.ca (smtpout.eastlink.ca [24.222.0.30])
02: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
03: for xxxxx; Thu, 7 Jan 2010 xx:xx:xx +0100 (CET)
04: Received: from ip05.eastlink.ca ([unknown] [24.222.39.68])
05: by mta03.eastlink.ca (Sun Java(tm) System Messaging Server 7.3-11.01 64bit
06: (built Sep 1 2009)) with ESMTP id
07: <0KVW007SX7PI0020 [at] mta03.eastlink.ca>; Thu,
08: 07 Jan 2010 xx:xx:xx -0400 (AST)
09: Received: from me02.eastlink.ca (HELO eastlink.ca) ([24.224.136.25])
10: by ip05.eastlink.ca with ESMTP; Thu, 07 Jan 2010 xx:xx:xx -0400
11: Received: from [76.18.8.63] by me02.eastlink.ca (mshttpd); Thu,
12: 07 Jan 2010 xx:xx:xx +0100
IP: 24.224.136.25 ---> c-76-18-8-63.hsd1.fl.comcast.net
die Amsterdam-Konnektion:
header:
01: Received: from vhost1.tyc.edu.tw (relay2.tyc.edu.tw [163.28.50.24])
02: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
03: for xxxxx; Sat, 9 Jan 2010 xx:xx:xx +0100 (CET)
04: Received: from User (d126141.upc-d.chello.nl [213.46.126.141])
05: by vhost1.tyc.edu.tw (Postfix) with ESMTP ID: [ID filtered]
06: Wed, 6 Jan 2010 xx:xx:xx +0800 (CST)
Muguphon: +31- 645 141 466 ---> Telfort B.V., NL
Mugufax: +31- 847 323 886 ---> J2 Global (Netherlands) B.V.
header:
01: Received: from universe.uohyd.ernet.in (EHLO universe1.uohyd.ernet.in)
02: [202.41.85.90]
03: by mx0.gmx.net (mx013) with SMTP; 09 Jan 2010 xx:xx:xx +0100
04: X-IronPort-Anti-Spam-Filtered: true
05: X-IronPort-Anti-Spam-Result:
06: AtX/AHWTR0usEAEL/2dsb2JhbAAIQnSIWIUkCwEIijmBBIEqExCGBKYVCIp1giIFEQcIgWgE
07: Subject: [SPAM] URGENT REPLY !!!!!!
08: X-IronPort-AV: E=Sophos;i="4.49,246,1262543400";
09: d="scan'208";a="123765"
10: Received: from unknown (HELO node1.uohyd.ernet.in) ([172.16.1.11])
11: by universe1.uohyd.ernet.in with ESMTP; 09 Jan 2010 xx:xx:xx +0530
12: MIME-version: 1.0
13: Content-transfer-encoding: 7BIT
14: Content-type: text/plain; CHARSET=US-ASCII
15: Received: from User ([unknown] [82.128.23.123])
16: by node1.uohyd.ernet.in (Sun Java(tm) System Messaging Server 7.3-11.01
17: 64bit
18: (built Sep 1 2009)) with ESMTPA id
19: <0KVY006D4PN5LPY0 [at] node1.uohyd.ernet.in>;
20: Sat, 09 Jan 2010 xx:xx:xx +0530 (IST)
IP: 82.128.23.123 ---> Multilinks Telecommunications Limited, Nigeria
gecrackter Orange-Account via Spamadoo:
header:
01: Received: from smtp20.orange.fr (smtp20.orange.fr [80.12.242.26])
02: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
03: for xxxxx; Sat, 9 Jan 2010 xx:xx:xx +0100 (CET)
04: Received: from me-wanadoo.net (localhost [127.0.0.1])
05: by mwinf2028.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
06: Sat, 9 Jan 2010 xx:xx:xx +0100 (CET)
07: Received: from me-wanadoo.net (localhost [127.0.0.1])
08: by mwinf2028.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
09: Sat, 9 Jan 2010 xx:xx:xx +0100 (CET)
10: Received: from User (LRouen-151-72-19-84.w80-13.abo.wanadoo.fr
11: [80.13.178.84])
12: by mwinf2028.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
13: Sat, 9 Jan 2010 xx:xx:xx +0100 (CET)
header:
01: Received: from smtp20.orange.fr (smtp20.orange.fr [193.252.22.31])
02: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
03: for xxxxx; Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
04: Received: from me-wanadoo.net (localhost [127.0.0.1])
05: by mwinf2021.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
06: Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
07: Received: from me-wanadoo.net (localhost [127.0.0.1])
08: by mwinf2021.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
09: Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
10: Received: from User (LRouen-151-72-19-84.w80-13.abo.wanadoo.fr
11: [80.13.178.84])
12: by mwinf2021.orange.fr (SMTP Server) with ESMTP ID: [ID filtered]
13: Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
hier hat man Horde bei der Uni Ulm gecrackt:
header:
01: Received: from mail.uni-ulm.de (mail.uni-ulm.de [134.60.1.11])
02: (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
03: (No client certificate requested)
04: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
05: for xxxxx; Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
06: Received: from poseidon.rz.uni-ulm.de (localhost [127.0.0.1])
07: by smtp.uni-ulm.de (8.14.3/8.14.2) with ESMTP ID: [ID filtered]
08: Sun, 10 Jan 2010 xx:xx:xx +0100 (MET)
09: Received: (from cyrus [at] localhost)
10: by poseidon.rz.uni-ulm.de (8.14.3/8.14.2/Submit) ID: [ID filtered]
11: Sun, 10 Jan 2010 xx:xx:xx +0100 (MET)
12: Received: from 41.138.180.15 ([41.138.180.15]) by imap.uni-ulm.de (Horde
13: MIME library) with HTTP; Sun, 10 Jan 2010 xx:xx:xx +0100
IP: 41.138.180.15 ---> Visafone Communications Limited, Nigeria
Muguphon: +2347032957777 ---> MTN Nigeria Communications Ltd.
über China-Zombie:
header:
01: Received: from dns.okumura.to (218-228-196-207.eonet.ne.jp
02: [218.228.196.207])
03: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
04: for xxxxx; Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
05: Received: from localhost (localhost [127.0.0.1])
06: by dns.okumura.to (Postfix) with ESMTP ID: [ID filtered]
07: Mon, 11 Jan 2010 xx:xx:xx +0900 (JST)
08: X-Quarantine-ID: [ID filtered]
09: X-Virus-Scanned: amavisd-new at okumura.to
10: Received: from dns.okumura.to ([127.0.0.1])
11: by localhost (dns.okumura.to [127.0.0.1]) (amavisd-new, port 10024)
12: with ESMTP ID: [ID filtered]
13: Received: from User (unknown [218.25.59.156])
14: by dns.okumura.to (Postfix) with ESMTP ID: [ID filtered]
15: Mon, 11 Jan 2010 xx:xx:xx +0900 (JST)
IP: 218.25.59.156 ---> China Unicom Liaoning
header:
01: Received: from ns11.wistee.fr (dns-ns11.wistee.fr [94.124.84.11])
02: (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
03: (No client certificate requested)
04: by xxxxx (Postfix) with ESMTP ID: [ID filtered]
05: for xxxxx; Sun, 10 Jan 2010 xx:xx:xx +0100 (CET)
06: Received: from vfbb233239.4u.com.gh ([41.218.233.239] helo=User)
07: by ns11.wistee.fr with esmtpa (Exim 4.67)
08: (envelope-from <imfor_555 [at] sify.com>)
09: ID: [ID filtered]
- kjz