Mon, 10/19/2009 - 12:15 | Emmanuel Goldstein
Thanks for the heads up.

Mon, 10/19/2009 - 12:18 | Cheeky Bastard
Fuck you NSA, GS, JPM and the lot.

Thank you Marla, i would probably open it.

Mon, 10/19/2009 - 12:38 | SWRichmond
CB / Marla,

I have clients getting this exact email with a different mail server named.  Cheeky, that's not to say it isn't NSA.

Marla, thanks for the heads up, and thanks for not clicking on the link.  You really can't be too careful.

Mon, 10/19/2009 - 12:43 | Cheeky Bastard
i know man, i was just kidding, i haven't got it yet; maybe GMail isn't a worthless piece of shit as i thought it was.

Mon, 10/19/2009 - 12:22 | Gilgamesh
Hmm, at least that looks more legit than FINRA returning money to investors:


Mon, 10/19/2009 - 12:27 | Hephasteus
If you had clicked it then it would have sent your email history out. So it's safe to say we won't be getting those emails.

Mon, 10/19/2009 - 12:42 | Careless Whisper
Speaking of Squid programmers, why the silence on Sergey? His Federal case was adjourned until October 16. Come and gone. FREE SERGEY

Mon, 10/19/2009 - 12:49 | bookwurm
o           .'`/
      '      /  (
    O    .-'` ` `'-._      .')
       _/ (o)        '.  .' /
       )       )))     ><  <
       `\  |_\      _.'  '. \
         '-._  _ .-'       '.)
         `\__\ all yur passwords are belong to us
Mon, 10/19/2009 - 19:36 | MsCreant
You draw nice bait.

There is a pun I must do. Please don't be offended.

With a picture like that you have established yourself as a master baiter.

Mon, 10/19/2009 - 12:58 | Biff Malibu
Thanks Marla glad to see you and Travis posting more.  Not to take anything away from Tyler but the variety of commentators on this site makes it the first website I visit every time I get on the internet.




Mon, 10/19/2009 - 12:59 | . . .
I doubt any ZH'ers will end up receiving a phishing or spam email.  I would like to think that the readers are smart enough to sign up for the site using a disposable email address they close immediately after ZH verifies it.

Mon, 10/19/2009 - 15:46 | Anonymous
The real ones wouldn't want to create a user id so that their opinions could be correlated back to them, on another web site under a different name, probably by their writing style and common colloquialism used by them.

As well, they won't feel the need to stroke their egos by having their comments associated with them.

Mon, 10/19/2009 - 13:42 | Anonymous
lame attempt by GS

Mon, 10/19/2009 - 13:53 | Sqworl
I got several on all my accounts and did not open.  They used my biz account name.  I replied with cc to FBI.  The IP address came from USSR.  Never a dull day in the land of spirits.

Mon, 10/19/2009 - 14:17 | Cheeky Bastard
there is no USSR anymore Sqworl baby

Mon, 10/19/2009 - 14:46 | VegasBD
Maybe not, but they are filming Red Dawn 2 right now.

...and guess which city looks like a war zone enough to film it in...

Mon, 10/19/2009 - 14:47 | Cheeky Bastard
Mon, 10/19/2009 - 13:53 | waterdog
I could tell that this was a scam. It was too nice to be coming from Marla. If Marla had sent a notice of changes, it would have gone like this- I changed some things to make your life better, accept it. Do not respond or I will pile drive your account into the lower reaches of hell.

Mon, 10/19/2009 - 16:34 | MinnesotaNice
Mon, 10/19/2009 - 14:58 | Jim_Rockford
Wow, I didn't realize that my subscription to ZeroHedge included an email box.  jim_rockford@zerohedge.com .... how cool is that?  How much extra am I being charged for this?

Mon, 10/19/2009 - 15:02 | Cheeky Bastard
Marla, do we all have this, or just the chosen ones 

Mon, 10/19/2009 - 16:53 | Miles Kendig
BTW, since you asked.  Here is a slice of pie where we happen to have found each other.  Except some folks know that the oil deal is just a cover.



Mon, 10/19/2009 - 18:36 | Cognitive Dissonance
Thanks Miles Kendig.

There were no bad scenes in "Good Will Hunting". Only better and best. This was one of the best. 

Mon, 10/19/2009 - 20:58 | Intuition
I was just a kid when I saw that movie for the first time. I mean utterly wet-behind-the-ears, juvenile thinking, adolescent child. And yet somehow it spoke to me. And that scene was one that somehow conveyed truth that I could not understand nor even really recognize. I've seen it dozens of times since then and it has much truth to this day.

Mon, 10/19/2009 - 15:45 | crzyhun
MS, I use a real address...still if I don't know you you get flushed....and truly I am not so big headed to think that you would ever contact me, since I don't know you.


Mon, 10/19/2009 - 18:38 | Cognitive Dissonance
Follow safe e-mail practices. As you say, dump everything you don't know and always wear a full body condom while reading your e-mail. And don't go all cheap on me and reuse the condom.

Mon, 10/19/2009 - 15:59 | SV
Marla, you know this is what you get for pissing on the Anon's that bring their HuffPo logic skills here, right?  I come bace from leaving for a week unplugged and what's that - Tyler having to pull Dante references about Hell in relation to the markets.

Ahhh, it's nice to be back.

Mon, 10/19/2009 - 16:04 | Cheeky Bastard
welcome back man, i for one, missed your comments.

Mon, 10/19/2009 - 16:35 | SV
Thank you CB. I appreciate her civility in dealing with the morons, hence I try to extend the same.  I'm now trying to unbury myself from the crap that has awaited my return.  I was on the road so I didn't trade OPEX either; would have shot myself... 

Mon, 10/19/2009 - 16:43 | Miles Kendig
The weekend after hours action seeps into Monday. Perhaps a new faze has arrived since the attempts at mockery have fallen flat.

Mon, 10/19/2009 - 16:58 | Quackking
I run a few Drupal sites on some of my servers and I got this myself. (with the domain name of one of them) - I suspect it is somebody trawling for Drupal credentials, and can't quite understand why. The link itself is going nowhere - it isn't an obfuscated redirect, it actually is trying to go someplace on my server where there is no handler. (So nothing would happen if you clicked on it, that is.)

It is also possible that it is targeting a whole bunch of Windows boxen that have been compromised so there is in fact an /owa/ directory - but again, I don't exactly see this as a high yield attack. Hmm. See below.


Not Found

The requested URL http://[victimdomain.com]/owa/service_directory/settings.php was not found on this server. Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.


Update: more here, http://isc.sans.org/diary.html?storyid=7357


I don't see the obfuscated link because I (safely) only view the text/plain version of this email. There is a link in the HTML version, apparently.




Mon, 10/19/2009 - 17:48 | SWRichmond
The link in one of the versions I got for examination went to xxxxxx.xxxxxxx.xxxxxx.eu, and DNS on the name got me IP's registered in:

Chile, Korea, Taiwan, Morocco, Israel, and Argentina, among others.

Fun stuff.

Mon, 10/19/2009 - 16:55 | Anonymous
Are you sure this is a phishing attack?! The link goes directly back to the host server - it doesn't really seem like phishing.

Where does the email originate? "Full headers" or "Show original" or whatever it takes to get your email client to show you all the text. Follow the "Received by" headers.

Mon, 10/19/2009 - 17:43 | TomJoad
If this was the best the Anon comments poster from yesterday's Iran article could do in terms of his awesome intraw3bzz retaliation, I am somewhat disappointed. 


It's nice to be back on again, the firewall on my SATCOM system wouldn't let me post on ZH, it was all read-only for the past 45 days or so.

Mon, 10/19/2009 - 20:03 | peterr
Tbanks for the heads up!

Goldman and Bank of Amerika run the markets along with Geithner, and beagle boy Ben. There is no free markets, only welfare capitalism and socialism for capitalism.

Mon, 10/19/2009 - 21:03 | Intuition
Apparently I've been left out. This is going to wreak havoc on my inferiority complex.

