"DirectAdmin Client Message" Email - Scam/Real?

Recently I've got the message marked as spam with SPAMASSASSIN.


Content analysis details: (5.4 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.4 RCVD_IN_BRBL_LASTEXT RBL: RCVD_IN_BRBL_LASTEXT [91.219.194.3 listed in bb.barracudacentral.org]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
2.0 BAYES_80 BODY: Bayes spam probability is 80 to 95% [score: 0.9215]
0.0 LOTS_OF_MONEY Huge... sums of money


from Andrew Lloyd <[email protected]>
 
Here is the page used to send out this new emails... it is the same as last time, only the host is changed: http://creativno.net/wp-content/plugins/sendme.php
And, yes, i got this new one too... so it's sent only to DA account holders.
They must be exploiting an exploit somewhere, maybe a 777 one, as I keep seeing this sendme.php file within directories that, if using mod_php, need 777 permissions.
 
Anyone warned the owner of creativno.net yet?
To be fair, its none of our business, unless it bothers you, then:

organisation: ORG-BGCL1-RIPE
org-name: Best-Hoster Group Co. Ltd.
org-type: OTHER
address: 192029, Russia, Saint-Petersburg, ul.Tkachei, d.4, lit A, pom. 12
e-mail: michelin[@]best-hoster.ru
 
Its back, so must have fixed/patched it (WordPress).

I doubt this sendme.php is just for this DA spam, if you search "sendme.php" in the big G, it is widely used in random directories for different scams.

I've now set up a crude daily bash script to find this file in /home/, then email me. I'm not sure of the legalities of searching customers files, but its better than being RBL'd.
 
@bartkob:

Please in the future do not save links in spam emails sent to the list. You should post by the reply button, not the quick reply, and choose to not convert links. Otherwise we may not bother to approve the post when blocked by the forum spamblock software.

@everyone:

Does anyone know with certainty if this particular email has anything to do with the DirectAdmin site compromise? Or is it just coincidentally happening at the same time? Why are you calling it DA spam?

Jeff
 
Does anyone know with certainty if this particular email has anything to do with the DirectAdmin site compromise? Or is it just coincidentally happening at the same time? Why are you calling it DA spam?
Well, I've never seen this spam email before this happened, this is why I call it DA spam - but it could be global, the email I use with JBMC is personal, only certain people know it.

The hackers may have sold our email addresses to someone, but I've never seen this type of spam email before the compromise.
 
Does anyone know with certainty if this particular email has anything to do with the DirectAdmin site compromise? Or is it just coincidentally happening at the same time? Why are you calling it DA spam?

Jeff

Received this copyright email only at my email address that I have registered with, and only with, Direct admin. It's only used for DA and the DA forums. It's the only email address I have that has received the email and until this and the earlier email has never been compromised with spam. Pretty well narrows it down for me.
 
Back
Top