Sponsors / vendors beware!! Please read

  • Thread starter Thread starter Reef Pets
  • Start date Start date
  • Tagged users Tagged users None

Reef Pets

Bioprospector
View Badges
Joined
Mar 7, 2008
Messages
10,025
Reaction score
1,428
Location
Ohio
Rating - 0%
0   0   0
I am so ticked!! I get on email from an email address that is believe is bluestarfish@???.com. Anyhow, with a name like bluestarfish I opened it and when I opened it I saw other email address that I recognized. The two that were first on the forwarding list was mrcoral and elitereefs and there were other but those two are the only ones that I remember. After seeing that the same email was sent to them I just figured it was something reef related. So, I clicked on the link and it was a dang virus. I just spend a couple hours reformating my computer. My computer is well protect by this virus got through some how.

This person must be targeting R2R vendors and sending out emails with a virus. It has to be from here because I only sponsor this site and a local site. And the other vendors sponsor here as well.
I hope that we can figure out who done this and get rid of them. But, because of this issue I will be blocking emails sent through the site. PM is always better anyhow.
 
That sucks Gary! I hate having to deal with reformating, it is so much work. A lot less than before, but still a lot.

I wouldn't necessarily say that someone is targeting only sponsors of R2R though. Selling on ebay, your site, and the popularity of the PH's brings your name out further than R2R and your local club, which is the only 2 that you sponsor.

Still though, with the threads that are going on now, I wouldn't doubt that happening. It sucks someone would day that for whatever reason though. Definitely not cool.......

At least its not a disgrunted postal worker!
 
That stinks Gary. I've done that before, and it's a giant nightmare. Hope they find out who did it.
 
yep i got the exact same thing. came under a starfire somthing.

i got lucky and saw it on my blackberry and one of my apps warned me about it. it did not notice however that it went ot other members. good looking out bro
 
I got a weird email from bluefirestar04. Good thing I didnt open it.
 
I got the same email, but I knew better than to open it! I do not click links or download anything unless I know for sure who it is from. But yes I got the same exact email.
 
All the reason why I trust
Apple-Logo-in-Blue.jpg
.... :bigsmile: !!

Paul
 
Yep - Star Fire was in the name for the sender and the address was BlueStarFish. Being that Rev got it as well I would have to guarantee that they were targeting people from R2R. I remember seeing a bunch of people from R2R.
Typically I dont open links but for some reason I thought it was safe due to the name and seeing all of the other sposors names on the list...... Another lesson learned.
 
Must read

the email has gone out again

here is all the info

the email comes from

[email protected]

the name it comes under is Star fire


it goes to (i changed the last part of all emails below)

[email protected]>, <elitereefs@eee>, <brianharper@eee>, <rob.1975@eee>, <cadillacja3@eee>, <reneehix0609@eee>, <contest4shiloh@eee>, <mrcoral@eee>, <drnecropolis@eee>, <katrina.cupp@eee>

the message is only a link
DO NOT CLICK ON THE LINK BELOW IT S FOR REFERENCE ONLY
(rev dont worry i changed it a bit just in case someone was dump enough to click on it)

ftp://marge:[email protected]


the message source info is as follows for all the tech heads out there

Received: from web84205.mail.re3.yahoo.com ([216.252.111.5])
by vms169119.mailsrvcs.net
(Sun Java(tm) System Messaging Server 6.3-7.04 (built Sep 26 2008; 32bit))
with SMTP id <[email protected]> for
Fri, 25 Sep 2009 20:33:55 -0500 (CDT)
Received: (qmail 24282 invoked by uid 60001); Sat, 26 Sep 2009 01:33:55 +0000
Received: from [72.134.28.183] by web84205.mail.re3.yahoo.com via HTTP; Fri,
25 Sep 2009 18:33:55 -0700 (PDT)
Date: Fri, 25 Sep 2009 18:33:55 -0700 (PDT)
From: Star Fire <[email protected]>
X-Originating-IP: [216.252.111.5]
To:
Message-id: <[email protected]>
MIME-version: 1.0
X-Mailer: YahooMailClassic/7.0.14 YahooMailWebService/0.7.347.3
Content-type: text/plain; charset=us-ascii
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
t=1253928835; bh=MI28rrkmDw2V1/gTTc1qpPpPsSH7WYYW6ZLM6Furq0g=;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:To:MIME-Version:Content-Type;
b=frxFBF5Hocfok+AL97Zz2F++EA9LRD7zXq7/2IGyj+ggGYqAhCk977RlBY/ARo4hHRR4fkZ3i7vnMYtCK0p2R52UVYN2qdkiPVmFlVyzWa3uwQjQSFv6sRq4blsowVFmOKIqjaLroqvMEnpUorH/k33EqVo0s9MvfbDkQ/8GxkY=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:To:MIME-Version:Content-Type;
b=vCw70pzy6gnqyrp8eFXvCCUkGO2+kr3iex6kYtwDX+/PDP0rg5sGBv3qBGk9JLIHpy9hHwTE4GucNazUaqpJXac4VbchB09JUVK1zQaaDgtf/niah1NTubvq59CGEgZ5udpRmXreLwUFSh6zJ8x2L3kljEJTzJEW14gVCywl5HU=;
X-YMail-OSG: pSvb5ngVM1ld0lP.UmSFvpRNJFaOIgyI3mEe4qOejHyepST.JA7T8NWme8QajYH86vlAm1aUEbeI7n54knF1RbMU0ztUuqr12I8YwJXaSDhisL8rU_TQe5Jn1iFVXhFFCaj8Q4BFxKzB.1gOWzoAfNMoMCkaoxnagZhPD1Zqu4BRK1pll5mtfR33h9SMWykXw1pY7RqfrOEUwM8QnWbhdWuHbCH55H0XR968PCh8FDE6KZEWYb6uViovur5p88TRfPRzU8lvFLfZkHoBGzLcxZc9N0ZKJifScddrCY80S.uZCXc3pd5KuaTAv_JPfaISk_JxAFtP1qlGdwdTI9Hql8XnyLnBPKdgD6fjyjtx3mmErYgF3N.Bng--
 
Last edited:
Thats the person. I got another email again as well. Good that you were able to gather all of the information from the email.
I see that the IP address is posted in there email header. I will be having fun with that.....
Rev - Is there a member by the name of Bluestarfish. Jack from Tritons Garden brought it to my attention that there is an eBay member with the ID and has purchased from me in the past.
Gary


the email has gone out again

here is all the info

the email comes from

[email protected]

the name it comes under is Star fire


it goes to (i changed the last part of all emails below)

[email protected]>, <elitereefs@eee>, <brianharper@eee>, <rob.1975@eee>, <cadillacja3@eee>, <reneehix0609@eee>, <contest4shiloh@eee>, <mrcoral@eee>, <drnecropolis@eee>, <katrina.cupp@eee>

the message is only a link
DO NOT CLICK ON THE LINK BELOW IT S FOR REFERENCE ONLY
(rev dont worry i changed it a bit just in case someone was dump enough to click on it)

ftp://marge:[email protected]


the message source info is as follows for all the tech heads out there

Received: from web84205.mail.re3.yahoo.com ([216.252.111.5])
by vms169119.mailsrvcs.net
(Sun Java(tm) System Messaging Server 6.3-7.04 (built Sep 26 2008; 32bit))
with SMTP id <[email protected]> for
Fri, 25 Sep 2009 20:33:55 -0500 (CDT)
Received: (qmail 24282 invoked by uid 60001); Sat, 26 Sep 2009 01:33:55 +0000
Received: from [72.134.28.183] by web84205.mail.re3.yahoo.com via HTTP; Fri,
25 Sep 2009 18:33:55 -0700 (PDT)
Date: Fri, 25 Sep 2009 18:33:55 -0700 (PDT)
From: Star Fire <[email protected]>
X-Originating-IP: [216.252.111.5]
To:
Message-id: <[email protected]>
MIME-version: 1.0
X-Mailer: YahooMailClassic/7.0.14 YahooMailWebService/0.7.347.3
Content-type: text/plain; charset=us-ascii
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
t=1253928835; bh=MI28rrkmDw2V1/gTTc1qpPpPsSH7WYYW6ZLM6Furq0g=;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:To:MIME-Version:Content-Type;
b=frxFBF5Hocfok+AL97Zz2F++EA9LRD7zXq7/2IGyj+ggGYqAhCk977RlBY/ARo4hHRR4fkZ3i7vnMYtCK0p2R52UVYN2qdkiPVmFlVyzWa3uwQjQSFv6sRq4blsowVFmOKIqjaLroqvMEnpUorH/k33EqVo0s9MvfbDkQ/8GxkY=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com;
h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:To:MIME-Version:Content-Type;
b=vCw70pzy6gnqyrp8eFXvCCUkGO2+kr3iex6kYtwDX+/PDP0rg5sGBv3qBGk9JLIHpy9hHwTE4GucNazUaqpJXac4VbchB09JUVK1zQaaDgtf/niah1NTubvq59CGEgZ5udpRmXreLwUFSh6zJ8x2L3kljEJTzJEW14gVCywl5HU=;
X-YMail-OSG: pSvb5ngVM1ld0lP.UmSFvpRNJFaOIgyI3mEe4qOejHyepST.JA7T8NWme8QajYH86vlAm1aUEbeI7n54knF1RbMU0ztUuqr12I8YwJXaSDhisL8rU_TQe5Jn1iFVXhFFCaj8Q4BFxKzB.1gOWzoAfNMoMCkaoxnagZhPD1Zqu4BRK1pll5mtfR33h9SMWykXw1pY7RqfrOEUwM8QnWbhdWuHbCH55H0XR968PCh8FDE6KZEWYb6uViovur5p88TRfPRzU8lvFLfZkHoBGzLcxZc9N0ZKJifScddrCY80S.uZCXc3pd5KuaTAv_JPfaISk_JxAFtP1qlGdwdTI9Hql8XnyLnBPKdgD6fjyjtx3mmErYgF3N.Bng--
 
Any Idea what virus it was? Not defending the guy but maybe he got the virus and it is being auto forwarded be cause he has R2R people in a groups folder?
 
From what I know some viruses use your address book and try to send the thing to everyone you know so the person you get it from might not be the real sender.
 

TOP 10 Trending Threads

ARE YOU READY TO CONFESS TO CRAZIEST, DUMBEST, FUNNIEST THING YOU’VE EVER DONE IN REEFING?

  • Yeah, I'll confess! (Share your story in the comments!)

    Votes: 65 56.5%
  • Nah, I'll keep mine a secret...(Don't be like that, share with the class!)

    Votes: 50 43.5%
Back
Top
Home
Post thread…
Market
What's new