There is a bogus email
I got it twice. The first one was with an attachment that ClamWin auto-stripped in my hMailserver (I love ClamWin). The second one was with bogus link only.
People should know, Microsoft NEVER sends either update attachments or links to updates. They ALWAYS make you go through the normal update process.
Update for Microsoft Outlook / Outlook Express (KB910721)
Brief Description
Microsoft has released an update for Microsoft Outlook / Outlook Express. This update is critical and provides you with the latest version of the Microsoft Outlook / Outlook Express and offers the highest levels of stability and security.
Instructions
- To install Update for Microsoft Outlook / Outlook Express (KB910721) please visit Microsoft Update Center:
ht://update.microsoft.com/microsoftofficeupdate/isapdl/default.aspx?ln=en-us&id=69856679253865343173165925879729351302763190300486843409431
Quick Details
- File Name: officexp-KB910721-FullFile-ENU.exe
- Version: 1.4
- Date Published: Tue, 23 Jun 2009 10:21:29 -0300
- Language: English
- File Size: 81 KB
System Requirements
- Supported Operating Systems: Windows 2000; Windows 98; Windows ME; Windows NT; Windows Server 2003; Windows XP; Windows Vista
This update applies to the following product: Microsoft Outlook / Outlook Express
Regardless of what the link text says, the actual link goes to illlihff.com. This is strange because WHOIS gives me this .
Domain Name: ILLLHI1.COM
Registrant [1938512]:
mary ramsden Jamiesonrl@yahoo.co.uk
410 charlton ave
south orange
NJ
07079
US
Administrative Contact [1938512]:
mary ramsden Jamiesonrl@yahoo.co.uk
410 charlton ave
south orange
NJ
07079
US
Phone: +1.973451855
Billing Contact [1938512]:
mary ramsden Jamiesonrl@yahoo.co.uk
410 charlton ave
south orange
NJ
07079
US
Phone: +1.973451855
Technical Contact [1938512]:
mary ramsden Jamiesonrl@yahoo.co.uk
410 charlton ave
south orange
NJ
07079
US
Phone: +1.973451855
Domain servers in listed order:
NS1.2-PROFESSIONAL.COM
NS1.COMPARE-TRANSLATED.COM
Record created on: 2009-06-22 12:14:59.0
Database last updated on: 2009-06-23 09:24:59.823
Domain Expires on: 2010-06-22 12:15:00.0
–
Pinging the DNS name gets me this
C:\Users\Slamlander.CASELLE-NET>ping update.microsoft.com.ILLLHI1.COM
Pinging update.microsoft.com.ILLLHI1.COM [95.76.65.228] with 32 bytes of data:
Now I take the IP number that DNS gave me and look it up
C:\Users\Slamlander.CASELLE-NET>whois 95.76.65.228
OrgName: RIPE Network Coordination Centre
OrgID: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
ReferralServer: whois://whois.ripe.net:43
NetRange: 95.0.0.0 – 95.255.255.255
CIDR: 95.0.0.0/8
NetName: 95-RIPE
NetHandle: NET-95-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
NameServer: NS-PRI.RIPE.NET
NameServer: SEC1.APNIC.NET
NameServer: SEC3.APNIC.NET
NameServer: TINNIE.ARIN.NET
NameServer: NS2.LACNIC.NET
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 2007-07-30
Updated: 2009-05-18
# ARIN WHOIS database, last updated 2009-06-22 19:10
# Enter ? for additional hints on searching ARIN’s WHOIS database.
Found a referral to whois.ripe.net:43.
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to ’95.76.64.0 – 95.76.67.255′
inetnum: 95.76.64.0 – 95.76.67.255
netname: ASTRAL
descr: ASTRAL TIMISOARA
country: RO
admin-c: UPC1-RIPE
tech-c: UPC1-RIPE
remarks: ***********************************
remarks: * report abuse to abuse@upc.ro *
remarks: ***********************************
status: ASSIGNED PA
mnt-by: ASTRALTELECOM-MNT
mnt-lower: ASTRALTELECOM-MNT
mnt-routes: ASTRALTELECOM-MNT
source: RIPE # Filtered
role: UPC Romania LIR
address: 62D, Nordului St.
address: District 1, 014104
address: Bucharest
phone: +40-31-1018100
fax-no: +40-31-1018101
org: ORG-ATS4-RIPE
admin-c: AH1598-RIPE
admin-c: HMCB1-RIPE
admin-c: SB666-RIPE
admin-c: LPT7-RIPE
tech-c: LPT7-RIPE
nic-hdl: UPC1-RIPE
remarks: ***************************************
remarks: * for abuse please use abuse@upc.ro *
remarks: ***************************************
abuse-mailbox: abuse@upc.ro
mnt-by: ASTRALTELECOM-MNT
source: RIPE # Filtered
% Information related to ’95.76.0.0/15AS6746′
route: 95.76.0.0/15
descr: UPC Romania
origin: AS6746
mnt-by: ASTRALTELECOM-MNT
source: RIPE # Filtered
People should know and it bears repeating, Microsoft NEVER sends either update attachments or links to updates. They ALWAYS make you go through the normal update process.
UPDATE: I looked at the headers again, using SquirrelMail, which has a much better source view than Outlook. This time I got the correct DNS name. Since this is a live server and definite attempt to obfuscate the DNS name then this may indeed be the actual culprit.
UPDATE1: I ran it again, using the full DNS link address and got an IP address in Romania. I am reasonably confident in this one.