Issue 40400 - Bizarre virus or SPAM mails have been going.
Summary: Bizarre virus or SPAM mails have been going.
Status: CLOSED IRREPRODUCIBLE
Alias: None
Product: Infrastructure
Classification: Infrastructure
Component: Mailing lists (show other issues)
Version: current
Hardware: All All
: P3 Trivial (vote)
Target Milestone: ---
Assignee: stx123
QA Contact: issues@www
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-01-11 16:00 UTC by tora3
Modified: 2005-01-12 10:22 UTC (History)
1 user (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---


Attachments
Received headers in a series of e-mails (2.03 KB, text/txt)
2005-01-11 16:02 UTC, tora3
no flags Details
One of suspicious e-mails that I have received (19.45 KB, text/plain)
2005-01-11 16:05 UTC, tora3
no flags Details

Note You need to log in before you can comment on or make changes to this issue.
Description tora3 2005-01-11 16:00:14 UTC
It is something weird.

I have recently received several e-mails with strange attachments.
All those e-mails include similar header information but their origination 
IP addresses are greatly different each other.

A mail client or something like that seems to introduce itself to the our 
MX server s002.sfo.collab.net as "HELO mail-kr3.openoffice.org":

Received: from unknown (HELO mail-kr3.openoffice.org) (84.222.173.38)
  by s002.sfo.collab.net with SMTP; 11 Jan 2005 10:39:04 -0000
Comment 1 tora3 2005-01-11 16:02:43 UTC
Created attachment 21358 [details]
Received headers in a series of e-mails
Comment 2 tora3 2005-01-11 16:05:54 UTC
Created attachment 21359 [details]
One of suspicious e-mails that I have received
Comment 3 stx123 2005-01-11 23:04:18 UTC
I understand that you were subject to virus activity and received messages from
hosts claiming to be in the openoffice.org domain. Thanks for reporting the
incident, but what do you expect us to do?
Comment 4 tora3 2005-01-12 06:22:27 UTC
Thank you for taking care of this issue.

We might not need to do anything for this phenomenon right now.

The suspicious phenomenon could infer that there might be a virus that targeted
at the MX server of OOo in order for sabotage. Such kind of virus might have been
deliberately created and gradually spreading over the world. 
Comment 5 stx123 2005-01-12 08:16:42 UTC
Hi, I guess the virus is not targeted especially at OOo but chooses a hostname 
in the domain of the target email address or mail exchanger.
Greetings, Stefan
Comment 6 tora3 2005-01-12 10:22:35 UTC
OK, let us close this issue.

Information: http://www.google.com/search?q=mail-kr3+virus

As you say, similar e-mails have been reported, especially:
http://www.usenetarchive.org/Dir4/File113.html

Cheers, Tora