Skip to content

Gossamer Web Design

Websites That Work (530) 583-7989

  • Tahoe Reno Web Design
    • Divi
    • Elementor
    • Open Source
    • WordPress
  • Search Engine Optimization
  • Web Design Services
    • Advertising
    • Google Apps
  • System Administration
    • Postfix + Amavis + OpenDKIM + SPF
    • Postfix Service Matrix
  • Contact
    • Cart
    • Checkout
    • My account
    • Shop
  • Resume

your mailbox has been deactivated

November 16, 2009November 18, 2009 adminAdmin, Email

The forging of email addresses of our domain names continues as the never ending barrage of phishing and other dangerous SPAM email is received. These attacks are socially engineered in that they rely on the fact that the email appears to come from your domain name, but does not. The most recent attack received looks like the following and contains the subject line “your mailbox has been deactivated“:

We are contacting you in regards to an unusual activity that was identified in your mailbox. As a result, your mailbox has been deactivated. To restore your mailbox, you are required to extract and run the attached mailbox utility.

Best regards, pfeiferhouse.com technical support.

It appears to be from support@yourdomain.[com,net,org]. If you examine the email header information and trace the IP address you will find that the IP address does not match that of the IP address of the email server for your domain name.

Outlook users can look at the email header information by right clicking on the email and selecting the ‘Options…’ menu item. A window will appear that looks similar to the following:

Return-Path: <na**********@************ch.de>
Delivered-To: we*******@**********se.com
Received: (qmail 61213 invoked by uid 98); 16 Nov 2009 18:06:16 -0000
Received: from 83.30.108.137 by tahoestores.org (envelope-from <na**********@************ch.de>, uid 1002) with qmail-scanner-2.01
(clamdscan: 0.95.1/9441. spamassassin: 3.2.5.
Clear:RC:0(83.30.108.137):SA:0(2.1/2.5):.
Processed in 2.550748 secs); 16 Nov 2009 18:06:16 -0000
X-Spam-Status: No, score=2.1 required=2.5
X-Spam-Level: ++
Received: from cbk137.neoplus.adsl.tpnet.pl (83.30.108.137)
by tahoestores.org with SMTP; 16 Nov 2009 18:06:11 -0000
Received: from 83.30.108.137 by mailin.rzone.de; Mon, 16 Nov 2009 19:05:35 +0100
From: “su*****@**********se.com” <su*****@**********se.com>
To: <we*******@**********se.com>
Subject: your mailbox has been deactivated
Date: Mon, 16 Nov 2009 19:05:35 +0100
Message-ID: <000d01ca66e7$65718f20$6400a8c0@nappingyz166>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary=”—-=_NextPart_000_000E_01CA66E7.65718F20″
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0)
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2905
Importance: Normal

Notice the Return path and the IP address highlighted above. If the Return path does not match the email address you see in your inbox you will know right away that the email address is forged. You can further verify that the email is SPAM by comparing the IP address to the IP address of our email server which is 207.158.15.91.

Customers of Gossamer can also rest assured that the configuration of our email server cannot be modified or otherwise updated by running a program on your local machine.

You will not continue to see these emails as Gossamer blocks the offending IP addresses permanently from our email server as soon as they are received. In addition, our virus and SPAM filters will generally update within 24 hours to block similar SPAM and virus content.

If you do receive a suspicious email related to the continued use of your email account you may safely ignore it and remember the golden email rule. Also remember the corollary, do not click on links contained in email from those you do not know.

If you do receive a similar email, follow the golden email rule and delete it. If you are so inclined, you can also send the email header information to me and I will immediately ban the IP address.

You may also review a variety of other similar attacks on Google by searching on ‘your mailbox has been deactivated’.

AdslBarrageDomain NameDomain NamesEmail AddressesEmail DomainEmail ServerIp AddressLtMessage IdOptions MenuOutlook UsersPhishingReturn PathRzoneScannerSecsSmtpSpam EmailSpamassassinSpoofingSsvSubject Line
  • Pages

    • Tahoe Reno Web Design
      • Divi
      • Elementor
      • Open Source
      • WordPress
    • Search Engine Optimization
    • Web Design Services
      • Advertising
      • Google Apps
    • System Administration
      • Postfix + Amavis + OpenDKIM + SPF
      • Postfix Service Matrix
    • Contact
      • Cart
      • Checkout
      • My account
      • Shop
    • Resume
  • Archives

    • November 2025
    • October 2025
    • September 2025
    • April 2025
    • March 2020
    • February 2020
    • February 2017
    • December 2016
    • November 2016
    • October 2016
    • September 2016
    • June 2012
    • March 2012
    • February 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • April 2011
    • March 2011
    • December 2010
    • August 2010
    • June 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
  • Categories

    • Admin (84)
    • Email (12)
    • Flash (2)
    • google (3)
    • Hp (1)
    • Perl (18)
    • PHP (18)
    • Press Releases (4)
    • Resume (20)
    • Security (1)
    • SEO (4)
    • Specials (1)
    • Uncategorized (8)
    • Unix (36)
    • Web Design (9)
    • Windows (9)
    • WordPress (39)
    • Yoder Group (1)

Gossamer Web Design

Tahoe Reno, NV
530 583-7989
  • Tahoe Reno Web Design
  • Search Engine Optimization
  • Web Design Services
  • System Administration
  • Contact
  • Resume
Powered by WordPress | Theme: Astrid by aThemes.

Web Design by Gossamer

All Rights Reserved © Gossamer Computer Services