Forum
iyi çalışmalar, bu sabah exchange mail kulanıcılarından birine aşağıdaki mail gelmişti. mail serverı ve client pc'yi virüs taramasından geçirdim fakat bişey çıkmadı. sosyal mühendislik gibi duruyor ama alıcı ve gönderen kısımda aynı mail adresi var. bu gibi spam saldırılarına maruz kalanlar oldumu, ne gibi çözümlerle bu spam mailleri durdurabiliriz. foruma genel olarak daha önce de baktığımda tavsiye edilen çözümleri denemiştim fakat bugün yine gelmiş spam mail ve bu defa fidye isteyerek, alıcı ve gönderici kısmında bizim mail gözüküyor, kendinden kendine göndermiş gibi. sizlerin bu gibi sorunlar karşısında uygulayıp netice aldığınız ne gibi çözümler var.
"From: [email protected]
To: abcd.efgh@xxx.com.tr
Subject: account abcd.efgh@xxx.com.tr is compromised
Hello!
I'm a hacker who cracked your email and device a few months ago.
You entered a password on one of the sites you visited, and I intercepted it.
Of course you can will change it, or already changed it.
But it doesn't matter, my malware updated it every time.
Do not try to contact me or find me, it is impossible, since I sent you an email from your account.
Through your email, I uploaded malicious code to your Operation System.
I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources.
Also I installed a Trojan on your device and long tome spying for you.
You are not my only victim, I usually lock computers and ask for a ransom.
But I was struck by the sites of intimate content that you often visit.
I am in shock of your fantasies! I've never seen anything like this!
So, when you had fun on piquant sites (you know what I mean!) I made screenshot with using my program from your camera of yours device.
After that, I combined them to the content of the currently viewed site.
There will be laughter when I send these photos to your contacts!
BUT I'm sure you don't want it.
Therefore, I expect payment from you for my silence.
I think $866 is an acceptable price for it!
Pay with Bitcoin.
My BTC wallet: 1DVU5Q2HQ4srFNSSaWBrVNMtL4pvBkfP5w
If you do not know how to do this - enter into Google "how to transfer money to a bitcoin wallet". It is not difficult.
After receiving the specified amount, all your data will be immediately destroyed automatically. My virus will also remove itself from your operating system.
My Trojan have auto alert, after this email is read, I will be know it!
I give you 2 days (48 hours) to make a payment.
If this does not happen - all your contacts will get crazy shots from your dark secret life!
And so that you do not obstruct, your device will be blocked (also after 48 hours)
Do not be silly!
Police or friends won't help you for sure ...
p.s. I can give you advice for the future. Do not enter your passwords on unsafe sites.
I hope for your prudence.
Farewell."
mailin header bilgileri ise aşağıdaki gibi:
Received: from yyyy.xxxx.com.tr (mail serverın local ip'si) by
yyyy.xxxx.com.tr (mail serverın local ip'si) with Microsoft SMTP Server (TLS) id
15.1.225.42; Thu, 25 Oct 2018 07:57:23 +0300
Received: from [202.53.172.94] (mail serverın public ip'si) by yyyy.xxxx.com.tr
(mail serverın local ip'si) with Microsoft SMTP Server id 15.1.225.42 via Frontend
Transport; Thu, 25 Oct 2018 07:57:23 +0300
From: <abcd.efgh@xxx.com.tr>
To: <abcd.efgh@xxx.com.tr>
Subject: account abcd.efgh@xxx.com.tr is compromised
Date: Thu, 25 Oct 2018 15:40:25 +0500
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset="ibm852"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Ac5q0nh0d20rg5qq5q0nh0d20rg5qq==
Content-Language: en
Return-Path: abcd.efgh@xxx.com.tr
Received-SPF: None (yyyy.xxxx.com.tr: abcd.efgh@xxx.com.tr does
not designate permitted sender hosts)
buradaki 202.53.172.94 ip Bangladeş gözüküyor baktığımda.
phishing'tir 🙂