Some of you have been receiving email addressed from the masscops.com domain with an attachment. DO NOT OPEN THESE ATTACHMENTS.
This is a result of the W32.Mytob.EV@mm email worm.
W32.Mytob.EV@mm is a mass-mailing worm that has back door capabilities and uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.
The worm uses its own SMTP engine to send itself to the email addresses that it finds. The email has the following characteristics:
From:
(Spoofed) It could be an email address that the worm finds on the compromised machine.
It also could be one of the following:
adam
alex
andrew
anna
bill
bob
brenda
brent
brian
claudia
dan
dave
david
debby
frank
fred
george
helen
jack
james
jane
jerry
jim
jimmy
joe
john
jose
josh
julie
kevin
leo
linda
maria
mary
matt
michael
mike
paul
peter
ray
robert
sales
sam
serg
smith
stan
steve
ted
tom
Or one of the following with the same email domain as the recipient:
admin
administrator
info
mail
register
sandra
service
support
webmaster
Subject:
One of the following:
Your password has been updated
Your password has been successfully updated
You have successfully updated your password
Your new account password is approved
[RANDOM]
Message:
Dear user [USER NAME],
You have successfully updated the password of your [DOMAIN] account.If you did not authorize this change or if you need assistance with your
account, please contact [DOMAIN] customer service at: [SPOOFED EMAIL]
Thank you for using [DOMAIN]!
The [DOMAIN] Support Team
+++ Attachment: No Virus (Clean)
+++ [DOMAIN] Antivirus - www.[FULL DOMAIN]
When it sends a .zip as attachment, the zipped copy has .doc, .htm, or .txt as the first extension, and .exe, .pif, or .scr as the second extension. The first extension may also have many spaces.
The email may also be in the following format:
From:
Spoofed in the same way as above mentioned.
Subject:
One of the following:
Your Account is Suspended'
*DETECTED* Online User Violation
Your Account is Suspended For Security Reasons
Warning Message: Your services near to be closed.
Important Notification
Members Support
Security measures
Email Account Suspension
Notice of account limitation
[RANDOM]
Message:
One of the following:
Dear user [USER NAME],
It has come to our attention that your [DOMAIN] User Profile ( x ) records are out of date. For further details see the attached document.
Thank you for using [DOMAIN]!
The [DOMAIN] Support Team
+++ Attachment: No Virus (Clean)
+++ [DOMAIN] Antivirus - www.[FULL DOMAIN]
Dear [DOMAIN] Member,
We have temporarily suspended your email account [email].
This might be due to either of the following reasons:
1. A recent change in your personal information (i.e. change of address).
2. Submiting invalid information during the initial sign up process.
3. An innability to accurately verify your selected option of subscription due to an internal error within our processors.
See the details to reactivate your [DOMAIN] account.
Sincerely,The [DOMAIN] Support Team
+++ Attachment: No Virus (Clean)
+++ [DOMAIN] Antivirus - www.[FULL DOMAIN]
Dear [DOMAIN] Member,
Your e-mail account was used to send a huge amount of unsolicited spam messages
during the recent week. If you could please take 5-10 minutes
out of your online experience and confirm the attached document so you
will not run into any future problems with the online service.
If you choose to ignore our request, you leave us no choice but to cancel your membership.
Virtually yours,
The [DOMAIN] Support Team
+++ Attachment: No Virus found
+++ [DOMAIN] Antivirus - www.[FULL DOMAIN]
Note: [DOMAIN] is the domain part of the recipient's email address, [USER NAME] is the username part of the recipient's email address, [SPOOFED EMAIL] is a spoofed email address on the same domain, and [email] is the recipient's email address.
When it sends a .zip as attachment, the zipped copy has .doc, .htm, or .txt as the first extension and .exe, .pif, or .scr as the second extension. The first extension may also have many spaces.
ma police, boston ma police, massachusetts police, massachusetts police, mass state police, mass police, ma, mass, massachusetts, massachusetts, massachutes, massachusetts law, massachusetts polece, police, officer, police officer, cops, police gear, law enforcement, police duty gear, state police, sheriff, law, police supply, police agency directory, police agency, police department, traffic officer, police dept, state trooper, dispatcher, massachusetts county sheriff, massachusetts sheriff, massachusetts department of corrections, ma doc, doc, dept of corrections, police information, civil service, ma civil service, massachusetts crime, police training, police academy, ma police academy, massachusetts officers, masscop, masscops, mpa, bpa, ibpoa, police association, massachusetts police news, massachusetts crime news, mass most wanted, police career information, police patrol, police administration, police books, crime scene training, police discussion, crime discussions, cops
About MassCops, the home for Massachusetts law enforcement.
The Massachusetts Law Enforcement Network opened in 1998 and is now a part of the New England Police Network The site is a pro-police discussion forum intended for sworn police officers and civilian law enforcement officials as well as those interested in pursuing a career in law enforcement here in Massachusetts.
The goal of The Massachusetts Law Enforcement Network is to provide an informal network of law enforcement officials here in Massachusetts for educational and informational purposes.
The forum covers many topics such as Police Related News Articles, Agency & Profession Discussions, Police Training as well as Law Enforcement Career Information.
The Massachusetts Law Enforcement Network and The New England Police Network (NEPN) and it's network sites are privately owned websites/domains and are not affiliated with or endorsed by any government association or agency.
MassCops (masscops.com) and (masscop.com) are privately owned are not affiliated with or endorsed by the Massachusetts Coalition of Police (masscop.org)