MySwag.org The Off-road Camper Trailer Forum

General => General Discussion => Topic started by: pajamajero on April 21, 2015, 07:17:02 PM

Title: Dangerous Emails
Post by: pajamajero on April 21, 2015, 07:17:02 PM
Hi Folks

There are nasty emails around at the moment, my company at a different location to me made a mistake in opening an attachment. It was ...  resume.zip. Unfortunately they were accepting job applications at the time, so the attachment looked normal. Here is a copy of an email I sent to all staff members, friends and customers.

There are dangerous emails spreading across North Qld and beyond.
They will come often from people or customers you know.

The suspect emails contain RANSOMWARE, which will take over your files and encrypt them, then demand money to restore the files.

The files we have seen are all *.ZIP.
We have received so far

resume.zip
electronic.zip
invoice.zip

We have suffered an attack at Mareeba, and today received 2 more infected emails here in Innisfail, one from a local company, and one from a real estate company in Cairns.

DO NOT double click or open these ZIP files, it will activate the RANSOMWARE which is trouble for you and everybody on your contacts list

Advise everyone you can


The ransomware is called CRYPTOWALL, a google search will return more information.
It encrypts every file it can find on you hard drive, and leaves files telling you how to pay them US$500.
It even encrypted files on our company Dropbox. It also searches out your 'contacts' and sends them all an email with the*.zip file. You can see how quickly it can spread. Your contacts are not expecting a contaminated email from you. If caught you will quickly learn how a fairly current backup of your hard drive can save your *ss. You made need professional help to sort your computer out. If you are not really a computer person but own and use a computer, the key word here is BACKUP.

These emails are not an issue unless you double click the attachment !! Just delete them.
Not sure - Don't risk it, even from friends.

If you are unfamiliar with some of the terms I have used - please ask and will do my best to explain them

Cheers

Paj




 
Title: Re: Dangerous Emails
Post by: Nomad on April 21, 2015, 07:22:45 PM
Yeah too true.

My IT guy has told me to delete any email that comes in with a ZIP file attached. He reckons its just rife at the moment.

 :cheers:
Title: Re: Dangerous Emails
Post by: duggie on April 21, 2015, 07:29:55 PM
Hi  pajamajero,

thanks for the heads up.

cheers duggie
Title: Re: Dangerous Emails
Post by: JCOJ on April 21, 2015, 07:32:08 PM
I received a few of them today. I got sus as soon as I read that the e-mail that it came from was from Letitia@ my company!?!?

Title: Re: Dangerous Emails
Post by: Bird on April 21, 2015, 09:12:51 PM
theres that much Shit going on at the moment, its no wonder some companies have got rid of email all together....
Title: Re: Dangerous Emails
Post by: bruce93 on April 21, 2015, 10:26:28 PM
When I was working in I.T last year one of our users in Sydney opened one. Infected 2 servers in Sydney before they noticed it. Thankfully we took the VPN down between Melb and Sydney so the servers I was looking after didn't get infected. Took the Sydney boys 2 days to recover the data from back ups. Very very nasty stuff ransomware!!
Title: Re: Dangerous Emails
Post by: peterdeg on April 22, 2015, 08:47:21 AM
The funny thing is that they're ethical crooks. If you pay the ransom, they do actually give you the unlock key.
Title: Re: Dangerous Emails
Post by: tk421 on April 22, 2015, 10:06:46 AM
We are really well protected at work, but we still had a few machines at work taken out by ransom-ware a while ago. People got an email  from Energy Australia saying "You owe money. Click here to see the bill".   Funny thing was, no-one who clicked the link was actually with Energy Australia. No one thought to question it.

We just flattened the machines and they lost all their data because you can't really recover from the cryptotography.  But seeing as our company policy is specifically to not store any company data on your local hard-drives because they're not backed up (all other systems are) the responses were along the lines of "Sucks to be you". "Lost your Bali holiday photos? Tough"
Title: Re: Dangerous Emails
Post by: pajamajero on April 22, 2015, 01:20:16 PM
The advice is never pay, no matter how bad your issues are.
The other thing is they want payment by bitcoin, which would prove difficult at best

Paj
Title: Re: Dangerous Emails
Post by: BaseCamp on April 22, 2015, 05:36:31 PM
The funny thing is that they're ethical crooks. If you pay the ransom, they do actually give you the unlock key.

no sadly its all just business as usual in Scumville....

If they didn't go to the bother of sending you the unlock key - then I guess pretty soon social media and a gazillion web based forums such as this; would be warning victims not to pay ...   "because you are screwed in any case"...

This is very different from a person hostage situation because you WILL pay the ransom (if possible) - to get your loved one back; but its a once off deal; (with high risk to victim-returning so called "ethical crook"...)

AKA - most times they will just kill em and dump the bodies somewhere
Title: Re: Dangerous Emails
Post by: #jonesy on April 22, 2015, 06:05:01 PM
My wife's work had the same last week, resume.zip
 One of the employees got it and deleted it then thought they better check it, not that he was in a position to read resumes anyway. Lucky they back up regularly.

Never open zip files unless you know where they are from. virus scanners don't scan them as viruses

Title: Re: Dangerous Emails
Post by: nic0 on April 30, 2015, 04:42:50 PM
Buy a portable hard disk, connect it up one a month, backup all of your important stuff then unplug it. In my opinion its a cheap insurance policy.
Title: Re: Dangerous Emails
Post by: Humphreythebear on April 30, 2015, 07:01:15 PM
Erm , I opened one this morning ....... I know - goose alert !

But , it was from the AFP , as in Australian Federal Police , a driving infringement. When you clucky clicky it takes you to the official AFP site .

I rang the AFP and the answer was "oh yeah that started this morning "
No announcement that they have been hacked ..........

If you can't trust our police , who do you trust ?


And yes , the it guy hates me !
Q
Title: Re: Dangerous Emails
Post by: #jonesy on May 01, 2015, 06:11:40 AM
Did it have the real AFP Site.         afp.gov.au?

What was the address it came from?    ????@afp.gov.au,   Or more like.    .????@afp.au.dodgy-country-code

Same rules apply,

- NEVER open zip files.
- Check the from address.
- Check the county codes at the end of any website links.
- If it is not personally addressed to you, by name.
- No bank etc EVER asks for you to log into your account via email links
Title: Re: Dangerous Emails
Post by: Humphreythebear on May 01, 2015, 05:40:50 PM
Yep , genuine AFP site - I rang them using the contact details ......
Our it guy has re or is that un buggered my computer , he is still shirty with me !
Title: Re: Dangerous Emails
Post by: KingBilly on May 01, 2015, 06:28:51 PM
Erm , I opened one this morning ....... I know - goose alert !

But , it was from the AFP , as in Australian Federal Police , a driving infringement. When you clucky clicky it takes you to the official AFP site .

I rang the AFP and the answer was "oh yeah that started this morning "
No announcement that they have been hacked ..........

If you can't trust our police , who do you trust ?


And yes , the it guy hates me !
Q

Do you live in the ACT?  Or have you driven through the ACT lately?

KB
Title: Re: Dangerous Emails
Post by: Humphreythebear on May 02, 2015, 05:53:35 PM
No , in Vic - drive past Melbourne airport every morning and night .
Also apparently AFP don't do traffic infringements.....
So I'm a double goose ! Or is that a super goose .
Title: Re: Dangerous Emails
Post by: shrek4 on May 02, 2015, 06:05:21 PM
No , in Vic - drive past Melbourne airport every morning and night .
Also apparently AFP don't do traffic infringements.....
So I'm a double goose ! Or is that a super goose .
i

So long as you're not a cooked goose!