Posted on Nov 18, 2024
SPC Jeff Daley, PhD
3
3
0
Has RP sent a message to change our password? With the hacking that takes place today caution is a consideration.

The message header reads as follows:

Received: from SA6PR02MB10357.namprd02.prod.outlook.com (2603:10b6:806:405::6)
by SN6PR02MB4415.namprd02.prod.outlook.com with HTTPS; Mon, 18 Nov 2024
21:43:33 +0000
Received: from MW4PR03CA0033.namprd03.prod.outlook.com (2603:10b6:303:8e::8)
by SA6PR02MB10357.namprd02.prod.outlook.com (2603:10b6:806:405::6) with
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8158.23; Mon, 18 Nov
2024 21:43:32 +0000
Received: from SJ5PEPF000001F4.namprd05.prod.outlook.com
(2603:10b6:303:8e:cafe::5f) by MW4PR03CA0033.outlook.office365.com
(2603:10b6:303:8e::8) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.8158.23 via Frontend
Transport; Mon, 18 Nov 2024 21:43:31 +0000
Authentication-Results: spf=pass (sender IP is 205.201.139.29)
smtp.mailfrom=mandrillapp.com; dkim=pass (signature was verified)
header.d=mandrillapp.com;dmarc=bestguesspass action=none
header.from=rallypoint.com;compauth=pass reason=109
Received-SPF: Pass (protection.outlook.com: domain of mandrillapp.com
designates 205.201.139.29 as permitted sender)
receiver=protection.outlook.com; client-ip=205.201.139.29;
helo=mail29.wdc04.mandrillapp.com; pr=C
Received: from mail29.wdc04.mandrillapp.com (205.201.139.29) by
SJ5PEPF000001F4.mail.protection.outlook.com (10.167.242.72) with Microsoft
SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.8158.14
via Frontend Transport; Mon, 18 Nov 2024 21:43:31 +0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandrillapp.com;
s=mte1; t= [login to see] ; x= [login to see] ;
bh=ZnDypK47zsdG7LYGXsMriRtDa40G0aV2PGML+2vu7oQ=;
h=From:Subject:Reply-To:To:Feedback-ID:Message-Id:Date:MIME-Version:
Content-Type:CC:Date:Subject:From;
b=lSCBfSZrb2sTqQrJaaac1CeECUL23MqgbbaYk98R12Obr36kaMuc9V0FhC1PI/zoF
+1Bs3HBujDQDZ0TIVYZp4+UrQHcHiITdQ0WevfhsoiyHleRdfB99JpjkGk4btfnM4v
F4yXQP7x0pay5sJOlHGfJ9pBTcGEWVj5ZiNSZZyseqgeSXXFOeHPzrkPDeLqiWFR+n
fshZc33X9loKpw8bPFAM/Dgtu/VLd5EoDM/tUfDHYMuTFzdgzfBLKyxAAEHoQuk1Rx
7107kRCLLkC9WLCwnw9GIVoT/LorjtYulQJXy9qn9t211zkpScF3mMTfRJFvyaLin+
We0re1v7V8A+g==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=RallyPoint.com;
s=mandrill; t= [login to see] ; x= [login to see] ;
bh=ZnDypK47zsdG7LYGXsMriRtDa40G0aV2PGML+2vu7oQ=;
h=From:Subject:Reply-To:To:Feedback-ID:Message-Id:Date:MIME-Version:
Content-Type:CC:Date:Subject:From;
b=kxEeITiwFw5OMflybk0ySBngtTF+s8oZxNMzjnuiU4iyon/b9Rzsc7zJVyIKdrhYR
Xi/otCODer6mMpo06+Sp6OYBubHSd6sE7xib+cUQBFW7iVS9bPR20TEWhqhuX8DtJ7
elVzfHwuAPmo49aAGEbhK4kNnk4n3MPRHKtBz46w=
Received: from pmta16.mandrill.prod.suw01.rsglab.com (localhost [127.0.0.1])
by mail29.wdc04.mandrillapp.com (Mailchimp) with ESMTP id 4Xsh2V2nnJz7lmCnX
for < [login to see] >; Mon, 18 Nov 2024 21:43:30 +0000 (GMT)
From: RallyPoint < [login to see] >
Subject: =?utf-8?Q?Your=20RallyPoint=20Password=20Reset=20Request?=
Received: from [52.7.239.114] by mandrillapp.com id 27fe9d3060c34aaba23148a4bf1ae7db; Mon, 18 Nov 2024 21:43:30 +0000
Reply-To: [login to see]
To: [login to see]
X-Native-Encoded: 1
X-Report-Abuse: =?UTF-8?Q?Please=20forward=20a=20copy=20of=20this=20message,=20including=20all=20headers,=20to= [login to see] .=20You=20can=20also=20report=20abuse=20here:=20https://mandrillapp.com/contact/abuse=3Fid=3D9384837.27fe9d3060c34aaba23148a4bf1ae7db?=
X-Mandrill-User: md_9384837
Feedback-ID: 9384837:9 [login to see] 1118:md
Message-Id: <9 [login to see] [login to see] .673bb50254a [login to see] [login to see] .mandrillapp.com>
Date: Mon, 18 Nov 2024 21:43:30 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="_av-Cj7KlxgdtEbJq6lYUh2ulQ"
Return-Path:
[login to see]
X-MS-Exchange-Organization-ExpirationStartTime: 18 Nov 2024 21:43:31.6751
(UTC)
X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
X-MS-Exchange-Organization-Network-Message-Id:
2fec2241-c818-4308-c934-08dd081a0bce
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 2db92ce5-e71e-4604-a0bb-3ca09771a70d:0
X-MS-Exchange-Organization-MessageDirectionality: Incoming
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic:
SJ5PEPF000001F4:EE_|SA6PR02MB10357:EE_|SN6PR02MB4415:EE_
X-MS-Exchange-Organization-AuthSource:
SJ5PEPF000001F4.namprd05.prod.outlook.com
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Office365-Filtering-Correlation-Id: 2fec2241-c818-4308-c934-08dd081a0bce
X-MS-Exchange-Organization-SCL: -1
X-Microsoft-Antispam:
BCL:0;ARA:13230040| [login to see] 5| [login to see] 7| [login to see] | [login to see] | [login to see] ;
X-Forefront-Antispam-Report:
CIP:205.201.139.29;CTRY:US;LANG:en;SCL:-1;SRV:;IPV:NLI;SFV:SFE;H:mail29.wdc04.mandrillapp.com;PTR:mail29.wdc04.mandrillapp.com;CAT:NONE;SFS:(13230040) [login to see] 5) [login to see] 7) [login to see] 2) [login to see] ) [login to see] );DIR:INB;
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 18 Nov 2024 21:43:31.2845
(UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 2fec2241-c818-4308-c934-08dd081a0bce
X-MS-Exchange-CrossTenant-Id: 2db92ce5-e71e-4604-a0bb-3ca09771a70d
X-MS-Exchange-CrossTenant-AuthSource:
SJ5PEPF000001F4.namprd05.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA6PR02MB10357
X-MS-Exchange-Transport-EndToEndLatency: 00:00:02.3574519
X-MS-Exchange-Processed-By-BccFoldering: 15.20.8158.013
X-Microsoft-Antispam-Mailbox-Delivery:
wl:1;pcwl:1;ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(811239)(255002)(410001)(930097)(140003);
X-Microsoft-Antispam-Message-Info:
=?us-ascii?Q?COeWXEqfgRUVohmGKAo9jb+RyujY7mdQxEbQu94xDuV2q9PDQn476luq7GPk?=
=?us-ascii?Q?zzxoPf/7U1a0rXktlqtw87bL3GkgH2WpjursSDtwv76iZUgdV2XVWNZhxSM2?=
=?us-ascii?Q?gkj5iB3zEvfva1l3o+Jxk7znhUUb/hd/xWCiTHd51CrIYqO++gr2f/G6Ge6H?=
=?us-ascii?Q?C5z/5177r52hNplFBhIWsP8BlkSDsghFyNext+B6qr/h2Fy/1lD0oalaK3cl?=
=?us-ascii?Q?HmS6ZzByY4oBMALz48yXgJHFAKupHUZL9I4fai6OzKpTlN2dD82KSW1AbKRh?=
=?us-ascii?Q?3LR9ioNtc3yJJ6TcdTUyXodhmKHD+KprvSGDfWccR1MFVu3hjesBNo2weqSc?=
=?us-ascii?Q?HLmmDteoVnAKPuWVix0jbdqPccVEUFZUi9A/CV4ngbZTSsQvG1wwLCWCHa81?=
=?us-ascii?Q?QbVg4Gu3/h80HIL5EeNfiW5rvW1LyNbkf3vvKAO34jI0XUGGA9nZr3i/sKzr?=
=?us-ascii?Q?rJM+LRVJWVOsaSKxzFB1ByJ+0VKmEtw5XOJgE8qguM/PJc/vGAt9ClvScbIQ?=
=?us-ascii?Q?Z5iMZMYCxWwTlV+f3FVZ87RCs+2qoVmM1lxlhm05CmMZrNjjAYV4x6dUyWZK?=
=?us-ascii?Q?l2algREDQfAiOJwq77nIHTH/vJaJ56H87Ri1WBMZz7onWj2JJ0caTDXc7uPh?=
=?us-ascii?Q?kcXMGhRd4qaKvn7Dn9Mn2hMG1Jj14HbE8dM99CNmN3sUFMIDvyKTwFUvwhdg?=
=?us-ascii?Q?0Aq/hzpdyTVTj+6d7bXRLcjbo8MjeaTALaNzR5PIu2lildoEzl60a05YAAai?=
=?us-ascii?Q?Cqk2Mhb3g9lwFtY8/YokwkF1ZKD/dTDt5W300CMuTefkk27dblBsbk0Cb0Sb?=
=?us-ascii?Q?q/jJoOXwPD5dNBWIkpYuJXFHWP6n2LPl+DSCmxR4epCNUNNjdqDsInRBfArs?=
=?us-ascii?Q?Lcq+BaQ5Y8gX6rufhXhV9kkpc44NBmsZKR/82ZmwFBlILPkIFXuCVWHfEl0Y?=
=?us-ascii?Q?3tSKp6GsioGt5sX28WiU9EGrg2Yw1THmINpq2I/xRVRLaqXz2FQKmYENhYfb?=
=?us-ascii?Q?Getb5am9jTHiKGzlm0pSEJGB9qhvSPKDz+MY19tOBXEuSpVgg5buI2F2yi0M?=
=?us-ascii?Q?QYTcCKxcYpZej+WHRqy2Mf3ClSHpEMxP/F4WisNC4Hp1vop9mQ8q4u5iSKI5?=
=?us-ascii?Q?0Jy85miS/9sSHmid4YxSYU25aR8uY9wy28l02FPaRQi1eKDr88QLHxySgmhw?=
=?us-ascii?Q?OSJHpr/Q/4O+dYuZOy32Lk1KMN3l1xuiGKu4PXMp8OaAGo02KLSy325Q28f3?=
=?us-ascii?Q?votYotJJtBe3DT+hJBStCS1uNEF91x9zeDen2Wx1l5rRqKnyQsntMW+Wxv0s?=
=?us-ascii?Q?cz3yl34Mhmi86ivQ39I4uq1Q9bFNm63rQB393r1jsUtLjBNICnFcBBerE3s3?=
=?us-ascii?Q?9Z2QXwmTIrn2XUQOUTs6KtkpyJdJsEgOkVBu6///vn8tbndaKD7m2QFfzlE6?=
=?us-ascii?Q?8wGiz0IZ0fcMCQWM4Yd90HXCpOnWmd/zh1oyfpsAP/YDCJ1iOTAcGCfMURdW?=
=?us-ascii?Q?oQ850Tk3rDWLYBwC4yoWfG4C2p3eNsY8OO7AbTuHvFTjBaqyNS0ckhGUXfaq?=
=?us-ascii?Q?Ls+WUs5UxNoT2z3g+HlGho1/wlhkk/foivek5m7AsLbZNQSmju28PcAD9vCn?=
=?us-ascii?Q?uNkusFAxAbwSS7kdgn/CA//MOxMakoTzk/4ganh5l46nA3K/wv/KCinJKkOq?=
=?us-ascii?Q?7K5YtK+HHVc+BMdrsNrlFBoB32lm3ZJMxblOqmwxu8UMfoA65fRkLGIEPj6W?=
=?us-ascii?Q?Y1jCeSPjZRo3N17MOTX/tmNaZw0EwvLntMO4SijpakrzVnOKdySKvPm8JOKk?=
=?us-ascii?Q?941wmwsUhh5+0b9oKYfU0tBu7eti9bLFCqx0Edrnqkh70AtIqbJTEJMoAzXM?=
=?us-ascii?Q?jVbxuN4x+bMG13Lg1gCDNtWRAmnsN8aGEWMi5DcP3IKFr5OO4saFGXUrDC+F?=
=?us-ascii?Q?k66ugReMwz05KniyZ3cHkQ=3D=3D?=
Posted in these groups: 987f343c Hacking
Avatar feed
Responses: 5
LTC Kevin B.
1
1
0
I didn't receive anything like that, and the content you posted looks very suspicious. I would delete the email and ignore it. If you clicked on any link within the email and changed your password, I suggest changing your password yet again.

SSG Carlos Madden
(1)
Comment
(0)
Avatar small
SP5 Dennis Loberger
1
1
0
I never received anything like this
(1)
Comment
(0)
Avatar small
Maj Kevin "Mac" McLaughlin
1
1
0
No and without even attempting to sort through the SMTP encoding, I would ask 1. Did the email give you a link to change it and 2. Did you click the link?

If #1 is "yes" delete the email and move on (and if you want to be sure, go to the RP site directly and change your password). If #2 is "yes" your system is likely at risk.

RP should never send an email to tell you your password needs to be changed with a link to go with it. However, you can ask the moderators to chime in on whether they know the protocol.
(1)
Comment
(0)
Avatar small

Join nearly 2 million former and current members of the US military, just like you.

close