Obvious Scam but..

Soldato
Joined
25 Jan 2008
Posts
2,923
Location
Peterboro, Distro:Ubuntu
How did they get all my details perfectly correct ?

(Name, Address, & Phone Number)

*** link to malware removed ***

So I googled ruebsamen and it appears to be some kind of computer fan site.

=================================================


Ok so I downloaded the Zip file and pulled it into Virtualbox and ran it..

Ta Daaaaar.....

RansomWare

I6aCZku.jpg

Question remains though .... How'd they get my exact details ?
 
Last edited:
Soldato
Joined
14 Jul 2003
Posts
14,611
Seen a few ransomware attacks in the past year, it's all too common in large companies sadly especially those with access to personal e-mail at work.

OP chances are they got your details from a hacked site you had shared them with, 707 million accounts were compromised in 2015 alone according to recorded/reported breaches. It's also now more common for your basic information to be shared between companies under data sharing agreements without consent, with implied consent, or with consent but lots of small print.
 
Soldato
OP
Joined
25 Jan 2008
Posts
2,923
Location
Peterboro, Distro:Ubuntu
Seen a few ransomware attacks in the past year, it's all too common in large companies sadly especially those with access to personal e-mail at work.

OP chances are they got your details from a hacked site you had shared them with, 707 million accounts were compromised in 2015 alone according to recorded/reported breaches. It's also now more common for your basic information to be shared between companies under data sharing agreements without consent, with implied consent, or with consent but lots of small print.

Thanks for that heads up as The Wife and I were a tad concerned about the correct details !
 
Soldato
OP
Joined
25 Jan 2008
Posts
2,923
Location
Peterboro, Distro:Ubuntu
I just sent an email to the CEO and it's just been returned failed.

I have just received an email supposedly from your company.

Your request has been satisfied.

You can read contract here: URL removed



Original will be sent to the next adress:

With my CORRECT home address including postcode AND phone Number. I don't believe I have ever ordered anything from your site and so I'm a bit mystified !

I had strong suspicions about this email and so used private browsing to go to the link and downloaded the Zip (Ok..So at this point I knew it would be a scam)

Feeling confident as I run linux I opened the zip up in a Virtual session of Windows and low and behold.. It's RansomWare !


I realise this is obviously not from yourselves but thought it might be in your interests to know your company name has been attached !

Regards

Paul !



Ps.. This link below is a screengrab I took and uploaded to imgur
 
Soldato
Joined
9 Jun 2009
Posts
3,067
Location
OCUK Detention Centre
My Company has an info@ public email, displayed on the web site, this has obviously been harvested, and the amount of attempts at this and other exploits is amazing,

I dread to think what would happen if I had office staff, getting emails like ' unpaid invoice details attached' etc.
 
Associate
Joined
14 Aug 2014
Posts
1,070
Fortunate you're tech savvy enough to be running a virtual machine OP. Hacked databases or unscrupulous companies passing your details on to other unscrupulous parties are likely the source of them getting your details. The eBay hack two years ago gave away loads of user information for instance, including physical addresses, dates of birth and phone numbers.
 
Soldato
Joined
24 Dec 2002
Posts
3,551
You can check to see if your email has been in any data breaches in the last couple of years.

https://haveibeenpwned.com/

Most excellent website, you can sign up and it'll automatically email you if your email (or even domain if you have one) is ever in any future data breach.

It's run by Troy Hunt a security professional and Microsoft MVP for several years... so you don't need to worry about it being a dodge site too ;)

Read a few of Troy's blog posts to see how easy it really is for someone (any one) to get hold of your details if you're ever unlucky enough to be signed up to a hacked site.
 
Man of Honour
Joined
24 Sep 2005
Posts
35,584
I called my Nan before work yesterday and mid call she got upset and explained she thought she had been scammed / manipulated by an email into calling a number and giving her bank details. Absolute *******s :mad:
 
Soldato
Joined
16 Jun 2013
Posts
5,375
It's probably not advisable to open in VMs anymore there's been a couple that "break out" normally via the network as the host is connected. Can't imagine ransomware is too far away from utilising such a feature to slow down AV vendors testing it.
 
Last edited:
Back
Top Bottom