SIGforum
SPAM From University of Maryland (Baltimore County)

This topic can be found at:
https://sigforum.com/eve/forums/a/tpc/f/230601935/m/6330094294

June 04, 2022, 12:23 PM
V-Tail
SPAM From University of Maryland (Baltimore County)
My spam folder is catching a couple hundred junk mail messages daily. Maybe half of these, or more, of the ones that are addressed to my business email account, are from the same sender:

hshel1@umbc.edu

It appears that eitherThe spam covers a wide range of topics, things like confirmation needed for delivery of FedEx packages, confirmation like payments for a win in a lawsuit, etc.

Are any of y'all getting flooded with spam from hshel1@umbc.edu?



הרחפת שלי מלאה בצלופחים
June 04, 2022, 01:18 PM
BurtonRW
Thank God, no. I get enough from UMBC’s Alumni Association.

Go Retrievers!

-Rob (UMBC Class of ‘01)




I predict that there will be many suggestions and statements about the law made here, and some of them will be spectacularly wrong. - jhe888

A=A
June 04, 2022, 01:22 PM
sigmonkey
You can report it to the University IT folks.

https://itsecurity.umbc.edu/report




"the meaning of life, is to give life meaning" Ani Yehudi אני יהודי Le'olam lo shuv לעולם לא שוב!
June 05, 2022, 04:41 AM
RichardC
I was expecting hotplate recipes.


____________________
June 05, 2022, 08:07 AM
V-Tail
I'm not 100% positive that I know how to read an expanded email header, but if I'm reading it correctly, it looks like the spam is originating in Ukraine and the umber.edu "sender's address" is spoofed.

Recipes will be posted later, for RichardC. I would send them directly, but there is no email address in his profile.



הרחפת שלי מלאה בצלופחים
June 05, 2022, 08:42 AM
ensigmatic
quote:
Originally posted by V-Tail:
I'm not 100% positive that I know how to read an expanded email header, but if I'm reading it correctly, it looks like the spam is originating in Ukraine and the umber.edu "sender's address" is spoofed.
What you're looking for, primarily, is "Received:" headers. They are in reverse-chronological order, with the topmost being the most recent.

Specifically: The "Received:" header that will tell the story, nine-times-out-of-ten, is the very first one your mail server adds. That's the one that tells you who delivered it to your mail server. The very first/oldest one that can be trusted, because it's the first/oldest one your mail server put there.

If that "Received:" header reads something like "from yadda-yadda-yadda (unknown[ip.add.re.ss])," rather than "from hostname.example.com (hostname.example.com[ip.add.re.ss])," that means the "yadda-yadda-yadda" identity is likely untrustworthy. Then you can maybe use whois to track-down whence it actually came.



"America is at that awkward stage. It's too late to work within the system,,,, but too early to shoot the bastards." -- Claire Wolfe
"If we let things terrify us, life will not be worth living." -- Seneca the Younger, Roman Stoic philosopher