| From | Sent On | Attachments |
|---|---|---|
| Jay Hennigan | Jan 19, 2012 12:59 pm | |
| Michael Hare | Jan 19, 2012 1:01 pm | |
| Tim Jackson | Jan 19, 2012 1:02 pm | |
| Dave Ellis | Jan 19, 2012 1:03 pm | |
| Jay Hennigan | Jan 19, 2012 1:04 pm | |
| Michael J McCafferty | Jan 19, 2012 1:04 pm | |
| ML | Jan 19, 2012 1:05 pm | |
| Randy Carpenter | Jan 19, 2012 1:05 pm | |
| Alan Clegg | Jan 19, 2012 1:08 pm | |
| Andrew D. Dibble | Jan 19, 2012 1:15 pm | |
| Chris Adams | Jan 19, 2012 1:16 pm | |
| Chris Adams | Jan 19, 2012 1:18 pm | |
| Lane Powers | Jan 19, 2012 1:27 pm | |
| PC | Jan 19, 2012 1:33 pm | |
| Carlos Alcantar | Jan 19, 2012 1:34 pm | |
| Simon Lockhart | Jan 19, 2012 1:35 pm | |
| Todd Lyons | Jan 19, 2012 1:37 pm | |
| Ryan Gelobter | Jan 19, 2012 2:36 pm | |
| -Hammer- | Jan 20, 2012 6:06 am | |
| Mike Andrews | Jan 20, 2012 6:55 am | |
| Robert Bonomi | Jan 20, 2012 11:05 am | |
| Carlos Alcantar | Jan 27, 2012 10:11 am | |
| Bryan Horstmann-Allen | Jan 27, 2012 10:16 am | |
| Randy Epstein | Jan 27, 2012 10:20 am | |
| Mike | Jan 27, 2012 10:21 am | |
| Vald...@vt.edu | Jan 27, 2012 10:22 am | |
| Randy Epstein | Jan 27, 2012 10:31 am | |
| Carlos Alcantar | Jan 27, 2012 10:45 am | |
| Sean Donelan | Jan 27, 2012 10:52 am | |
| Jon Lewis | Jan 27, 2012 12:22 pm | |
| Harry Hoffman | Jan 27, 2012 12:29 pm | |
| Martin Hannigan | Jan 27, 2012 7:19 pm | |
| bman...@vacation.karoshi.com | Jan 28, 2012 8:30 am | |
| John Peach | Jan 28, 2012 8:39 am | |
| Ryan Gelobter | Jan 28, 2012 7:11 pm | |
| Jack Bates | Jan 30, 2012 7:53 am | |
| Matthew S. Crocker | Jan 30, 2012 7:55 am | |
| Carlos Alcantar | Jan 31, 2012 2:30 pm | |
| Phil Dyer | Jan 31, 2012 4:38 pm | |
| Ryan Pavely | Jan 31, 2012 4:43 pm | |
| Ronald Bonica | Jan 31, 2012 5:29 pm | |
| Carlos Alcantar | Jan 31, 2012 6:52 pm | |
| TFML | Feb 1, 2012 7:32 am | |
| PC | Feb 1, 2012 11:53 am | |
| Robert E. Seastrom | Feb 2, 2012 2:57 am | |
| bman...@vacation.karoshi.com | Feb 2, 2012 3:22 am |
| Subject: | Re: US DOJ victim letter | |
|---|---|---|
| From: | Andrew D. Dibble (adib...@quantcast.com) | |
| Date: | Jan 19, 2012 1:15:05 pm | |
| List: | edu.merit.nanog | |
Operation Ghost Click - someone in your AS has malware which changes their DNS
server to an evil IP. ICANN (IIRC) replaced these servers with clean ones
around November 2011 and now it seems like the FBI is trying to contact everyone
who is still talking to that server.
FBI seems to have a list of netblocks hosting rogue DNS servers here: https://forms.fbi.gov/check-to-see-if-your-computer-is-using-rogue-DNS
So if one of the computers inside your network is talking to one of those IPs
for DNS, you probably have malware.
Drew
On Jan 19, 2012, at 1:03 PM, Tim Jackson wrote:
The 3rd email they sent:
This email is intended to provide clarification on a previous email sent to you. You will be receiving a letter by U.S. Postal Service in the coming days. In the meantime, please visit the link below which provides more details on the investigation and identifying you as a possible victim:
www.fbi.gov/news/stories/2011/november/malware_110911
-- Tim





