PDA

View Full Version : Aurelia Plumbar. Scam, or foul up?



Excalibur
02-09-2014, 06:08 PM
Got this email today. As far as I know, nothing's been ordered. :confused:The file's in a format I can't open. As far as I can see no money's left any accounts.

Thank you for using our services!
Your order #2946167661 will be shipped on 04-09-2014.

Date: September 02, 2014. 12:24pm
Price: £172.19
Payment method: Wire transfer
Transaction number: 49ACD267923A

Please find the detailed information on your purchase in the attached file (item_2014-09-02_11-42-18_2946167661.arj)

Best regards,
Sales Department
Aurelia Plumbar
+07468 56 76 38


Thoughts?

lazersounds
02-09-2014, 06:18 PM
From a website:

Order no. 26187973020 is another one from the current zbot runs which try to drop cryptolocker, ransomware and loads of other malware on your computer. They are using email addresses and subjects that will entice a user to read the email and open the attachment. A very high proportion are being targeted at small and medium size businesses, with the hope of getting a better response than they do from consumers.

Corabar Entertainment
02-09-2014, 06:19 PM
Thoughts?1. Never try to open ANYTHING you don't recognise

2. Since you tried:-

a. Make sure your virus definitions are up to date
b. Run a full scan, and
c. Download and run Malwarebytes to be sure!

3. Never, ever, ever, do anything like that again! :lol:

Excalibur
02-09-2014, 06:45 PM
3. Never, ever, ever, do anything like that again! :lol:

Yes Miss. :o:o:o

Jim - Scotland's Party DJ
02-09-2014, 08:49 PM
I feel you - I got an e-mail the other day mentioning something about a direct debit in the title which promptly went into the bin.

I then sussed out that it was something to do with a sizeable DJ Kit order I'd recently made on credit and I can't get the e-mail back :muppet::beer1:

DJColsie
03-09-2014, 06:16 AM
Got this email today. As far as I know, nothing's been ordered. :confused:The file's in a format I can't open. As far as I can see no money's left any accounts.

Thank you for using our services!
Your order #2946167661 will be shipped on 04-09-2014.

Date: September 02, 2014. 12:24pm
Price: £172.19
Payment method: Wire transfer
Transaction number: 49ACD267923A

Please find the detailed information on your purchase in the attached file (item_2014-09-02_11-42-18_2946167661.arj)

Best regards,
Sales Department
Aurelia Plumbar
+07468 56 76 38


Thoughts?

I work in a bank for my 9-5 and we had two people come in yesterday having received the exact same email. They were concerned that money had gone from their account but in both cases this was not the case!

Creature
03-09-2014, 08:52 AM
arj - is a compression format that comepeted with .zip

You dont here about it much these days ( still going - http://www.arjsoftware.com/),

the torrent boys loved it and it could be more secure than .zip files at the time.

your hint here that email is a scam, why is it compressed? if it was genuine it would probally be in adobe or other format but never compressed

Also your name is not there

and also probally there email addy will give it away

As been said dont reconise it - dont open it :)

DazzyD
03-09-2014, 11:18 AM
1. Never try to open ANYTHING you don't recognise

2. Since you tried:-

a. Make sure your virus definitions are up to date
b. Run a full scan, and
c. Download and run Malwarebytes to be sure!

3. Never, ever, ever, do anything like that again! :lol:

What Angela said!! ;)

From my work against scams, this one is pretty basic but we are hearing more and more reports about it. I was going to write a paragraph on this sort of thing but it's easy to get more info from Google on these specific threats and new breeds of malware. Just make sure you only click through to reputable websites. Security firm websites, such as Kaspersky, BitDefender and AVG are usually a good source of info.

But we can't stress this enough. Never, ever, ever click on an attachment or link in email that you weren't expected, haven't requested or haven't heard of. That's what your "move to trash" facility is for. The only exception to this rule is if you know what "sandboxing" is all about! ;)

Excalibur
03-09-2014, 11:41 AM
The only exception to this rule is if you know what "sandboxing" is all about! ;)

Am I close?

DazzyD
03-09-2014, 01:11 PM
Am I close?

Actually, not too far away in principle!

Sandboxing is running applications or files within a "sandbox", a program or OS environment which keeps the process separate from the main OS and other programs so that it can't have an effect on the system. It means that when you run the program or file it can't affect anything else on the system, for example, malware or malicious code can't reach any other part of the system and, therefore, can't do any harm.

It's how we test these suspicious email attachments and also how anti-virus software manufacturers test their programs for identifying real threats.

http://en.wikipedia.org/wiki/Sandbox_%28computer_security%29

Oh, I was just checking my own email inbox a short while ago and came across this:


Thank you for using our services!
Your order #57679658480 will be shipped on 04.09.2014.

Date: September 03, 2014. 09:58am
Price: £159.30
Payment method: Credit card
Transaction number: B1DF17C2666CDA31

Please find the detailed information on your purchase in the attached file (sale_2014-09-03_09-27-27_57679658480.arj)

Best regards,
Sales Department
Nu Solar
+07624 451364

There is also an .arj attachment. Look familiar to anyone??? ;) It's now binned!! :)

EDIT:

Curiosity got the better of me and I decided to do a couple of security scans on this attachment. I'm really puzzled as both AVG and MBAM both found nothing. Hmm. I'm still convinced it's malware, though!

funkymook
03-09-2014, 01:48 PM
These scams are out to catch the non-computer savvy and the old and befuddled - they seem to work very well!

Jim - Scotland's Party DJ
03-09-2014, 05:14 PM
So here's a question:

Say you get an e-mail and you're not sure that it's a scam or legit. Does opening the e-mail (but not clicking on any links or attachments) leave you open to attack?

Excalibur
03-09-2014, 07:20 PM
These scams are out to catch the non-computer savvy and the old and befuddled - they seem to work very well!

It's a good job I'm a technological whizz kid then, isn't it? :whistle::D:D


So here's a question:

Say you get an e-mail and you're not sure that it's a scam or legit. Does opening the e-mail (but not clicking on any links or attachments) leave you open to attack?

As the resident computer genius ( :fp: ) I believe that even this can be risky.

Imagine
03-09-2014, 09:13 PM
Yes, just opening the email can be risky. Not so much from infection, but just the fact that the spammers can prove you've looked at it and are therefore a legit email address to be targeted in the future.

You wouldn't believe how many people RESPOND to these things either.

One of the batches went out from one of my personal domain names. Not, I hasten to add from any of my machines....they just pick domain names out of the air and send using an email address from that domain (called spoofing).

First I knew of it was a load of non-delivery notifications (they used my email domain as the return address). Immediately ran full security checks just in case I'd got something nasty but nothing there.

Anyhoo.....shortly after that, I start getting angry recipients emailing me back threatening legal action as they haven't ordered etc....one of them even provided me with their address and bank details so that i could check nothing had left their account! (They didn't know me and i certainly didn't reply to any of them).

So there are people out there that read them, and even respond to them.

Moral of the story which has already been mentioned, NEVER open an email you're not expecting....if anything doesn't feel right, bin it.

DazzyD
03-09-2014, 11:48 PM
So here's a question:

Say you get an e-mail and you're not sure that it's a scam or legit. Does opening the e-mail (but not clicking on any links or attachments) leave you open to attack?


Yes, just opening the email can be risky. Not so much from infection, but just the fact that the spammers can prove you've looked at it and are therefore a legit email address to be targeted in the future.

You wouldn't believe how many people RESPOND to these things either.

One of the batches went out from one of my personal domain names. Not, I hasten to add from any of my machines....they just pick domain names out of the air and send using an email address from that domain (called spoofing).

First I knew of it was a load of non-delivery notifications (they used my email domain as the return address). Immediately ran full security checks just in case I'd got something nasty but nothing there.

Anyhoo.....shortly after that, I start getting angry recipients emailing me back threatening legal action as they haven't ordered etc....one of them even provided me with their address and bank details so that i could check nothing had left their account! (They didn't know me and i certainly didn't reply to any of them).

So there are people out there that read them, and even respond to them.

Moral of the story which has already been mentioned, NEVER open an email you're not expecting....if anything doesn't feel right, bin it.

Hi Jim

Firstly, I'll tackle your original question :


Say you get an e-mail and you're not sure that it's a scam or legit. Does opening the e-mail (but not clicking on any links or attachments) leave you open to attack?

This really depends on the type of email in question. There are two types of email formats that are commonly used - plain text and HTML. With plain text email, there is no threat to your system from opening the email as it is simply text, the same as would be created on NotePad on a Windows machine. There is no specific formatting and, more importantly, no chance for embedded malicious code that could be run to harm your computer. Plain text emails are the kind that both Peter and myself have quoted in this thread. There are no background images, no fancy fonts or colours, and no risk of potential harm. Then we have HTML. HTML is the language that a lot of websites are created in. Now, I have never personally come across an email in HTML which can install malicious code just by opening the email. BUT there are instances of websites having code embedded in them that activates just by visiting the site - i.e. with no need to click on anything. Malware generated by these types of attacks are commonly known as "drive-by infections". These infections, to be fair, are few and far between with scammers more interested in sending out emails with malicious attachments to thousands, tens of thousands or even millions of email addresses. This is because sending vast amounts of emails nowadays cost pennies, if not free, and, if only a tenth of a percent of people click the link, the attack will be profitable. Embedding malicious code is much more technologically advanced which would explain it's, comparative, lack of use. So, in theory, if an HTML website can attack your machine just by visiting the site, it's plausible that an HTML email could infect your computer just by opening it. However, in reality, most email clients stop this code running by default so you would actually need to allow your email software to execute it before it could do any damage. Therefore, I don't believe there is a significant risk from simply opening an email. If your email client shows a pop up box with something along the lines of "Allow script to run" then don't. This could be JavaScript or any other coding language. But, if you aren't 100% sure it's safe, then take no risks and block it.

Right. Next, I'll clear up some other points. Firstly:


the fact that the spammers can prove you've looked at it and are therefore a legit email address to be targeted in the future

Despite the comment, this is not a fact at all. The only way a sender can prove you've opened an email is if you allow your email client to send a Read Receipt. And any reputable email software or webmail service will always ask you first before sending a receipt. I've never encountered a request for a read receipt from a spam email. But if you do, just click "No". It's as simple as that. No email sender can tell you've read their email just by opening it. So you're safe on that one. They may get a Delivery Receipt but that just proves your mailbox exists - it doesn't prove that it's in use. Many email address, especially disposable webmail ones, lie dormant and just fill up with received mail (junk, spam or otherwise) until they reach their Mailbox Full limits.


You wouldn't believe how many people RESPOND to these things either.

I'm one of the few people who would believe this!! But I can't stress enough NEVER, EVER, EVER respond to a spam email. If the email is for something you've never subscribed to, NEVER click any "Unsubscribe" links. In fact, if you don't know the sender, NEVER CLICK ANY LINKS AT ALL. By clicking these links all you are doing is letting the spammer know your mailbox exists and it's actively monitored. This information is worth a fortune to the spammers who can sell it on to other spammers who will bombard you with more spam. The best advice is to bin the email and take no other action on it. It's an inconvenience but it's plausible that spam will die off if the spammers think your mailbox is no longer actively monitored because then it's not worth anything to anyone.

The comments about email address spoofing are very valid. Spoofing is a way for the spammers to get around your anti-spam filters. It works by masking the original email sender address with that of one of your own or from someone in your address book (which means it's automatically on your White (or Safe) List). The frustrating thing about spoofed emails is that they haven't actually come from your own email service even though they have your email address on them. Therefore, changing your password is of no use. In fact, a leading internet security expert advised me that there is no way to stop this. If your email address has been spoofed all you can do is advise all of the people in your address book of this so they know any emails they may get, apparently from you, are not necessarily from you. And, perhaps, change your email address. Spoofed email addresses are unlikely to get your email address blacklisted at Spamhaus as Spamhaus works off a combination of your email and IP addresses. When your email address has been spoofed, the emails are not sent from your IP address.



Moral of the story which has already been mentioned, NEVER open an email you're not expecting....if anything doesn't feel right, bin it.

For the reasons I've explained earlier, I wouldn't go as far as not opening an email. However, if you have any doubts at all to it's authenticity, get rid of it. You might miss out on a chance of something nice (last year I missed out on a £50 bar tab at my local pub because the email went straight to spam!) but it's always much better to be safe than sorry. And with threats getting ever more advanced it's down to you yourself to keep yourself safe online.

Imagine
04-09-2014, 10:34 PM
Despite the comment, this is not a fact at all. The only way a sender can prove you've opened an email is if you allow your email client to send a Read Receip

I beg to differ on that one. There are ways of finding someone's opened an email without a read receipt.
I use a system called Mailchimp a lot for a lot of the stuff I do with Scout media and communications. I can tell who's read an email, when and even where in the world.

OK - it applies to HTML formatted emails, and relies on the end user allowing remote images to be displayed (which a lot do), but no read receipt is required.

A lot of the spam I get does use remote images in this way (I don't automatically download them).

DazzyD
05-09-2014, 10:35 AM
I beg to differ on that one. There are ways of finding someone's opened an email without a read receipt.
I use a system called Mailchimp a lot for a lot of the stuff I do with Scout media and communications. I can tell who's read an email, when and even where in the world.

OK - it applies to HTML formatted emails, and relies on the end user allowing remote images to be displayed (which a lot do), but no read receipt is required.

A lot of the spam I get does use remote images in this way (I don't automatically download them).

Ah, so it's not just a case of opening the email and you actually have to download remote content for this to happen. As remote content is usually blocked by default by the current crop of mail clients, simply opening the email won't tell the sender anything. You need to download the content (usually images) which sends a tracking code to the holding server that the content has been downloaded and it can register that this has happened and forward those details on to the sender.

In all honesty, I think this system is really disgraceful as the recipient of the email is largely unaware that this is happening. It's sending details about the recipient to the sender without their knowledge and, as such, is a privacy issue. The good news is that people are getting more and more privacy-aware which is why there has been a huge backlash recently over the Facebook Messenger app as it requires a huge list of permissions, a number of which are totally irrelevant to it's purpose as a messaging app.

From the emails I've come across, the ones with downloadable content tend to come from legitimate services in that they are ones the recipient has subscribed to receive. This is often considered spam but you have to be careful what boxes you're ticking (or unticking!!) and exactly what the consequences of doing so are. The real scams tend to be sent in plain text, as is the case with the ones Peter, myself and now Angela have recently received. The reason for this is simple - plain text emails tend to get through to your inbox. There's no active active content to block and, as they come from spoofed email addresses, they often get through spam filters, too. These are the ones that have attachments to be wary of.

Excalibur
05-09-2014, 07:51 PM
Well I'm simultaneously disappointed and impressed.
My £170 worth of free gift hasn't arrived. :(:( Now I'll never know what it was. :confused:


I am however impressed with the company name and ethos. They've obviously found the Philosopher's stone, which turns Plumbar ( Lead ) into Aurelia ( Gold. )

Yes, I know that's not entirely accurate, but I still like the name. I do hope it was intentional.