Receive Annoying Spam sent "by myself"



  • Please, could someone help identifying the real sender of spam.

    Below is the original message text. I hid my personal email addresses. The strange thing is that the spam mail's sender and recipient is my own Vivaldi email. Yet, I don't see it in the Sent folder. Further, the spam landed on my secondary (not Vivaldi) inbox and I couldn't find it in my Vivaldi mailbox in any folder.

    Thanks.

    original_message.txt

    Delivered-To: *MySecondaryEmail@gmail.com
    Received: by 10.236.180.21 with SMTP id f21csp892996pjr;
    Fri, 27 Apr 2018 08:23:45 -0700 (PDT)
    X-Received: by 10.28.48.70 with SMTP id w67mr1623622wmw.47.1524842385381;
    Fri, 27 Apr 2018 08:19:45 -0700 (PDT)
    X-Google-Smtp-Source: AB8JxZqBvMvEfz7B+NyBIhceGtKYLIc9YQUx/t95tOx+vQ4axcX4NrWuAtkJPCWBuGUG5nzNrgeO
    X-Received: by 10.28.48.70 with SMTP id w67mr1623589wmw.47.1524842384587;
    Fri, 27 Apr 2018 08:19:44 -0700 (PDT)
    ARC-Seal: i=1; a=rsa-sha256; t=1524842384; cv=none;
    d=google.com; s=arc-20160816;
    b=vV9ohQhpZx9FEv+5ftiTihKGNCdxNjgBNdbWBgfVHRIdbdrzkhnx76i4gjxRG6PeQ3
    t7sTcIuymLIFnT+M490OT0rgH9eKOafwN/kWcKaRZjglMavPgw2Fb0Awz57mf9wX5Hyi
    H+e8V6fnUJpLjM/IiG59Jp9qyFwFnRpjQ26EciLWPMBFPvEE1y6V+4iRrHwncU2lSDnd
    /2DpNZaqSk5aoO+nggCXcitBanSPXZV6tcNkmddGQRro4OtbSHZ5U9WmblBacidVMc+p
    FUZLZCqL5/HBGH1FQ29x573CC1AtjdQShVxhdEgvogqhc5aLCZkMoIaThkqqbO5jCQWt
    GrTA==
    ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
    h=content-language:thread-index:mime-version:message-id:date:subject
    🇹🇴from:delivered-to:arc-authentication-results;
    bh=egBycGYE+p53SlOMGH/8xe+YydKpnhGM+wtN9V4Plzk=;
    b=fySCQ3kNMFsQ1b7prsnzyyHslUewma3uqwNk1bfsPdM/IG6Tf9kGSDxBmsBT1DTkya
    /xuyBw4HffNenjhzKiZrajq07N2BuuBqzOwJOd8wDlsZiaMu0sqmjIfp4CSlGjv0mUqd
    wbhEyDXSSQpLPa5HPHlL3pel7OU4DQl2S4c8V4kc8033gyMpUC/m2TmN5mv+VhKq9/04
    uiQKHgaEoSM81jaHSHyMwhWtaqyrP084oCCgltQUhYyoFwcMCuVqw64WJ8OVERTQb4rW
    3sVHC5CJfPeRvibOaZO6TwOpoltu79T5ll26xiwkG1m5ruzxG4xv8r61ujy4Ceqkb5lq
    bDHA==
    ARC-Authentication-Results: i=1; mx.google.com;
    spf=pass (google.com: domain of MyVivaldiMail@vivaldi.net designates 82.221.99.162 as permitted sender) smtp.mailfrom=MyVivaldiMail@vivaldi.net;
    dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=vivaldi.net
    Return-Path: MyVivaldiMail@vivaldi.net
    Received: from mail.vivaldi.net ([82.221.99.162])
    by mx.google.com with ESMTPS id s195si1064979wme.117.2018.04.27.08.19.44
    for *MySecondaryEmail@gmail.com
    (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
    Fri, 27 Apr 2018 08:19:44 -0700 (PDT)
    Received-SPF: pass (google.com: domain of MyVivaldiMail@vivaldi.net designates 82.221.99.162 as permitted sender) client-ip=82.221.99.162;
    Authentication-Results: mx.google.com;
    spf=pass (google.com: domain of MyVivaldiMail@vivaldi.net designates 82.221.99.162 as permitted sender) smtp.mailfrom=MyVivaldiMail@vivaldi.net;
    dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=vivaldi.net
    X-Virus-Scanned: Debian amavisd-new at vivaldi.net
    X-Sieve: Pigeonhole Sieve 0.4.2
    X-Sieve-Redirected-From: MyVivaldiMail@vivaldi.net
    X-Original-To: MyVivaldiMail@vivaldi.net
    Delivered-To: MyVivaldiMail@vivaldi.net
    X-Virus-Scanned: Debian amavisd-new at vivaldi.net
    From: MyVivaldiMail@vivaldi.net
    To: MyVivaldiMail@vivaldi.net
    Subject: Stacy
    Date: 28 Apr 2018 00:38:52 +0400
    Message-ID: 003501d3de69$0369a5c5$cb4fb093$@vivaldi.net
    MIME-Version: 1.0
    Content-Type: multipart/alternative;
    boundary="----=_NextPart_000_0032_01D3DE69.0366A7B5"
    X-Mailer: Microsoft Office Outlook 12.0
    Thread-Index: Acf4291b3a8mri4vf4291b3a8mri4v==
    Content-Language: en
    x-cr-hashedpuzzle: 2D4= 291b 3a8m ri4v f429 1b3a 8mri 4vf4 291b 3a8m ri4v f429 1b3a 8mri 4vf4 291b;1;3a8mri4vf4291b3a8mri4vf4291b3a8mri4vf4291b3a8mri;Sosha1_v1;7;{087E6491-1312-8BE6-908A-7FFDFC65087E};ZQB3AGUAZg291b3a8mri4vf4291b3a8mri4vf4291b3a8mri;28 Apr 2018 00:38:52 +0400;4vf4291b3a8mri4v
    x-cr-puzzleid: {087E6491-1312-8BE6-908A-7FFDFC65087E}

    This is a multi-part message in MIME format.

    ------=_NextPart_000_0032_01D3DE69.0366A7B5
    Content-Type: text/plain;
    charset="ibm852"
    Content-Transfer-Encoding: quoted-printable

    my pussy is wet
    ------=_NextPart_000_0032_01D3DE69.0366A7B5
    Content-Type: text/html;
    charset="ibm852"
    Content-Transfer-Encoding: quoted-printable

    <html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
    xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
    xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
    xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
    xmlns=3D"http://www.w3.org/TR/REC-html40"><head><META =
    HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
    charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 12 =
    (filtered medium)"><style><!--
    /* Font Definitions /
    @font-face
    =09{font-family:"Cambria Math";
    =09panose-1:0 0 0 0 0 0 0 0 0 0;}
    @font-face
    =09{font-family:Calibri;
    =09panose-1:2 15 5 2 2 2 4 3 2 4;}
    /
    Style Definitions */
    p.MsoNormal, li.MsoNormal, div.MsoNormal
    =09{margin:0in;
    =09margin-bottom:.0001pt;
    =09font-size:11.0pt;
    =09font-family:"Calibri","sans-serif";}
    a:link, span.MsoHyperlink
    =09{mso-style-priority:99;
    =09color:blue;
    =09text-decoration:underline;}
    a:visited, span.MsoHyperlinkFollowed
    =09{mso-style-priority:99;
    =09color:purple;
    =09text-decoration:underline;}
    span.EmailStyle17
    =09{mso-style-type:personal-compose;
    =09font-family:"Calibri","sans-serif";
    =09color:windowtext;}
    .MsoChpDefault
    =09{mso-style-type:export-only;}
    @page WordSection1
    =09{size:8.5in 11.0in;
    =09margin:1.0in 1.0in 1.0in 1.0in;}
    div.WordSection1
    =09{page:WordSection1;}
    --></style><!--[if gte mso 9]><xml>
    <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
    </xml><![endif]--><!--[if gte mso 9]><xml>
    <o:shapelayout v:ext=3D"edit">
    <o:idmap v:ext=3D"edit" data=3D"1" />
    </o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
    vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal></br>
    <a =
    href=3D"http://axm-auto.ru/media/editors/tinymce/plugins/textcolor/"><b>m=
    y pussy is wet</b></a><o:p></o:p></p></div></body></html>
    ------=_NextPart_000_0032_01D3DE69.0366A7B5--



  • @global The only thing I see it was sent from google with a send as permission. This means Vivaldi servers didn't actually send this message. I would change passwords on both of your accounts, just to be safe.



  • @luetage said in Receive Annoying Spam sent "by myself":

    Not sure where you see that -

    As far as I can see (and as far as headers are preserved or present), this actually originated from mail.vivaldi.com and was accepted by google as being authentic (SPF check for mail.vivaldi.com and sommail@vivaldi.net matching). It was delivered by google to the gmail address.

    It seems this mail actually originated on the vivaldi mail server (i.e. webmail?); if someone had used the vivaldi mail server as a relay there should have been another Received: header, which is not present. So either this was removed or shortened (maimed...) by google for whatever reasons, it was suppressed by vivaldi for whatever reasons, or this mail really originated on mail.vivaldi.net which means to me it must have come from a webmail session. I believe webmail sessions should be hard to trick into spoofing sender data without any reference to who actually was sending the mail, so maybe this really originated at "myvivaldimail@vivaldi.net".

    I also concur in changing both passwords (and possibly security questions) to new and different passwords, respectively.

    (PS: missing afterthought)

    If Received: headers are missing or mangled, this could be a simple fake delivered to Vivaldi mail servers from anywhere (not sure about the first three Received: headers which are incomplete). I guess Vivaldi should not be running an open relay, so maybe your login data for mail.vivaldi.net has ... gone missing?


  • Moderator

    @global Please contact our support (at office Mo-Fr from 08:00-18:00) and sent the the original mail at request.


 

Looks like your connection to Vivaldi Forum was lost, please wait while we try to reconnect.