Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Warning: message 1bXPdy- .... delayed 48 hours

1,965 views
Skip to first unread message

ftr

unread,
Aug 14, 2016, 1:24:17 PM8/14/16
to mozilla-suppo...@lists.mozilla.org
Hi,
since two days I get a number of warning messages with the above subject
lines from various senders to which I have not send the first message,
of course. A spammer has glued my news group email address to his spams.
Often, the recipients have nothing to do with me, but sometimes the spam
is sent to news groups or forums where I subscribed.

I don't see email addresses that are part of my address book. Does this
mean that my address book is not compromised ? My AV says the pc is ok
(hope the prog is right).

Anything I should (and can) do about the messages and their causes?

- ftr


Here is an example:


This message was created automatically by mail delivery software.
A message that you sent has not yet been delivered to one or more of its
recipients after more than 48 hours on the queue on rescue.mediafire.org.

The message identifier is: 1bXPe7-0002hV-LN
The subject of the message is: cool news
The date of the message is: Wed, 10 Aug 2016 12:17:50 +0300

The address to which the message has not yet been delivered is:

anaelle_...@yahoo.fr
host mx-eu.mail.am0.yahoodns.net [188.125.69.79]
Delay reason: SMTP error from remote mail server after MAIL
FROM:<news...@free.fr> SIZE=4736:
421 4.7.1 [TS03] All messages from 67.43.1.67 will be permanently
deferred; Retrying will NOT succeed. See
https://help.yahoo.com/kb/postmaster/SLN3436.html

No action is required on your part. Delivery attempts will continue for
some time, and this warning may be repeated at intervals if the message
remains undelivered. Eventually the mail delivery software will give up,
and when that happens, the message will be returned to you.



Reporting-MTA: dns; rescue.mediafire.org

Action: delayed
Final-Recipient: rfc822;anaelle_...@yahoo.fr
Status: 4.0.0
Remote-MTA: dns; mx-eu.mail.am0.yahoodns.net
Diagnostic-Code: smtp; 421 4.7.1 [TS03] All messages from 67.43.1.67
will be permanently deferred; Retrying will NOT succeed. See
https://help.yahoo.com/kb/postmaster/SLN3436.html



Return-path: <news...@free.fr>
Received: from d53-65-154.nap.wideopenwest.com ([64.53.154.65]:53180
helo=nkobkc.org)
by rescue.mediafire.org with esmtpsa
(TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256)
(Exim 4.87)
(envelope-from <news...@free.fr>)
id 1bXPe7-0002hV-LN; Wed, 10 Aug 2016 05:17:56 -0400
From: news.ftr <news...@free.fr>
To: "Anaelleata" <anaelle_...@yahoo.fr>, "Amazon"
<re...@boomboompowamazon.fr>, "Alexandre Pachot" <pac...@gmail.com>,
"Blanc Cerise par shopea" <an...@lk4545.pro>, "Barna Groupbarna"
<barn...@mail154.atl121.mcsv.net>
Subject: cool news
Date: Wed, 10 Aug 2016 12:17:50 +0300
Message-ID: <0000687fbe23$dd6959f6$4b8f14fb$@free.fr>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0001_1F773091.22EAF8D7"
X-Mailer: Microsoft Outlook 15.0
Thread-Index: AdHuLNG6ee7l+74qn75Qfu6JeAIUnw==
Content-Language: en-us

Good Guy

unread,
Aug 14, 2016, 5:02:08 PM8/14/16
to mozilla-suppo...@lists.mozilla.org


On 14/08/2016 18:23, ftr wrote:


Anything I should (and can) do about the messages and their causes?



The only thing you could do is not to use your real email address on newsgroups such as this one.  Spammers can harvest emails from newsgroups and forums so if you avoid using real working emails then you are safe.  Alternatively, you could use something like this:

news.ftr-REMOVE -TH...@free.fr

People would know what to do with this but bots can't.



--

If you want to filter all of my posts then please read this article:
<https://support.mozilla.org/en-US/kb/organize-your-messages-using-filters>
In step 7 select "Delete"

With over 350 million devices now running Windows 10, customer satisfaction is higher than any previous version of windows.

Wolf K.

unread,
Aug 14, 2016, 7:39:07 PM8/14/16
to mozilla-suppo...@lists.mozilla.org
On 2016-08-14 13:23, ftr wrote:
> Hi,
> since two days I get a number of warning messages with the above subject
> lines from various senders to which I have not send the first message,
> of course. A spammer has glued my news group email address to his spams.
> Often, the recipients have nothing to do with me, but sometimes the spam
> is sent to news groups or forums where I subscribed.
>
> I don't see email addresses that are part of my address book. Does this
> mean that my address book is not compromised ? My AV says the pc is ok
> (hope the prog is right).
>
> Anything I should (and can) do about the messages and their causes?
>
> - ftr
>
>
> Here is an example:
>
>
> This message was created automatically by mail delivery software.
> A message that you sent has not yet been delivered to one or more of its
> recipients after more than 48 hours on the queue on rescue.mediafire.org.
[...]

Looks to me like malware (a bot?) on a correspondent's computer. We had
something similar here, messages bounced from unknown recipients, and
supposedly sent from one of our accounts. The content of the messages
suggested the likely victim, I notified them, they cleaned their
machine. But I deleted the account (via my ISP's account self-service
site), and created a new one, sent an explanatory mail to all possibly
affected correspondents. I suspect that's the only cure.

Good luck,

--
Best,
Wolf K.
kirkwood40.blogspot.ca

ftr

unread,
Aug 24, 2016, 5:30:22 PM8/24/16
to mozilla-suppo...@lists.mozilla.org
Thank you both for your ideas.
It is the email address for news groups, forums, and for web site logins
(news, papers, ...) that has been compromised. I got now 147 mail
delivery failed messages...
-ftr
0 new messages