Date : Mon, 26 Oct 2015 21:51:20 +0000 (WET)
From : bbcmicro@... (Peter Coghlan)
Subject: Fw: new message
>
> > It appears to me the spams are resulting from one or more real
> > list members machines getting compromised and being used
> > by the malware to send out spams and/or having email addresses
> > lifted from them which are then passed on to other spamming
> > zombie machines.
> >
>
> The format of the spam VERY closely resembles that which many *. members got
> spammed. See here:http://www.stardot.org.uk/forums/viewtopic.php?f=14&t=10106
>
> I suspect one of the *. spammees clicked, got infected and then got their
> address book lifted and now the ML address has been added to the mix.
> Just a hypothesis
>
Sounds plausable.
(Who are these people that usurped our abbreviation for *CAT :-)
I got a response back from RapidSwitch, the ISP responsible for the ip address
which was sending out the spams. They said that spammers had somehow gotten
hold of one of their customer's SMTP password and that it has now been changed.
Regards,
Peter Coghlan.