Yahoo Groups archive

Emu XL-7 & MP-7 User's Group

Archive for xl7.

Index last updated: 2026-03-30 01:19 UTC

Thread

Re: ALERT: Potential Malicious E-Mail pretending to come from xl-7owner@yahoogroups.com

Re: ALERT: Potential Malicious E-Mail pretending to come from xl-7owner@yahoogroups.com

2016-03-23 by smw-mail@...

Brief update:

Today I received what I assume is another bogus e-mail with an attachment from whoever is pretending to be xl7-owner. The subject started with the word "Image" followed by a string of numbers and ending in ".pdf."

About an hour later Yahoo Groups appropriately rejected a posting from spoofer. The subject was the same except that the string of numbers was different. 


I am still thinking the individual e-mails are only going to the moderators/owner, not to members, but I did set up a short-term poll.


As long as the attempted posts are rejected by Yahoo, they should not appear in the digests. 


FOOTNOTE: On December 2, 2015 we had the most number of rejected attempted posts for at least the past 12 months. (Usually its less than a handful if any) I checked a site yesterday that tracks cyber attacks and interestingly enough on November 30, 2015 and December 1, 2015, the site reports some massive attempts at Denial of Service attacks in multiple countries. I have no idea if these were connected, but I wondered about it.


Steve

Re: ALERT: Potential Malicious E-Mail pretending to come from xl-7owner@yahoogroups.com

2016-05-19 by smw-mail@...

Brief Update:  Please note: I believe this only pertains to moderators of Yahoo Groups (this one and probably others).


The potentially malicious e-mails are no longer coming with the spoofed xl7/yahoogroups sender. You now need to check the full header [ideally in a safe environment]. For example, in several recent ones I found this:


X-Apparently-To: xl7-owner@yahoogroups.com


In many (possibly all) cases, the message is bounced by the yahoogroups server. 


Off topic (but probably related): on my personal phone, I have noticed an increase in spam/spoofed calls seeming to come from a phone number that is one digit off from my phone number (almost always the last digit) and usually with a different area code. 


Sad to say, but cyberwars is very real.  To me it is mind boggling that a company like Yahoo, with all of it's technological resources, can't stop potentially malicious communication from being bounced back to moderators. Perhaps they found a way or preventing the e-mail with the previous strategy the cyberwarriors were using. That might explain why the mail is being sent with different senders than the others.


Anyhow, it seems that members are still being protected.


Steve