Email Mystery - Possible Hack

The machines we love to hate

Moderator: Wiz Feinberg

Post Reply
User avatar
Richard Sinkler
Posts: 17067
Joined: 15 Aug 1998 12:01 am
Location: aka: Rusty Strings -- Missoula, Montana

Email Mystery - Possible Hack

Post by Richard Sinkler »

Erv Niehouse keeps getting an email with a link that is supposedly from me. It's not. When I right click on my name (as the sender), I get harry.gether@t-online.de.

Since the time before this, I have changed all my passwords. SGF, Facebook, Gmail, Yahoo, ATT Mail, Google, Microsoft, Apple, pretty much everyone.

He seems to be the only one I know who gets the email. Is there any way to see if I got hacked or if he got hacked?
Carter D10 8p/8k, Dekley S10 3p/4k C6 setup,Regal RD40 Dobro, NV400, NV112 . Playing for 53 years and still counting.
User avatar
Wiz Feinberg
Posts: 6091
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
Contact:

Post by Wiz Feinberg »

The link goes to a fat burning scam page on a compromised website. I see these all the time. They come from the Necurs Botnet.

As for how the spammers captured your name to use in the From field, it's done by harvesting email addresses on compromised computers. People get infected with Trojans. Some of the Trojans drop a spam bot component that scans for user names and email addresses and sends this information home to the bot controller. They compose a list of names and email accounts to send spam to/from, then rent time on a spam botnet.

You can change your passwords on all email accounts and set up 2FA with a smart phone if it is available. That would warn you if somebody else logs into your email server with an unrecognized device or IP address.

As in the former cases of the Nigerian 419 scammers who plagued our forum in the mid-2000s, you are welcome to "forward as attachment" a sample of a scam email. Contact me by PM to arrange this. In the meantime, read my old blog article that explains how display the originating email headers for reporting. It contains a section about forwarding as an attachment and explains why this is necessary. The article is old, but the information is valid.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
User avatar
Jim Cohen
Posts: 21749
Joined: 18 Nov 1999 1:01 am
Location: Philadelphia, PA
Contact:

Post by Jim Cohen »

Wiz Feinberg wrote:...As in the former cases of the Nigerian 419 scammers who plagued our forum in the mid-2000s...
Come to think of it, I get way fewer emails these days from purported "Barristers" telling me that I have inherited the sum of "Twenty Million US Dollars" and I just need to provide my banking information for them to transfer the funds to me.

How come?
User avatar
Richard Sinkler
Posts: 17067
Joined: 15 Aug 1998 12:01 am
Location: aka: Rusty Strings -- Missoula, Montana

Post by Richard Sinkler »

Heck Jim. Send me 20 million through PayPal, and I won't need you banking info. 20 mil will set me up for life and I won't have to steal more from you. :whoa:
Carter D10 8p/8k, Dekley S10 3p/4k C6 setup,Regal RD40 Dobro, NV400, NV112 . Playing for 53 years and still counting.
User avatar
Jim Cohen
Posts: 21749
Joined: 18 Nov 1999 1:01 am
Location: Philadelphia, PA
Contact:

Post by Jim Cohen »

Sure thing Richard. Just PM me your bank account number, password and last 4 of your social security and I'll take care of the rest. :lol:
User avatar
Richard Sinkler
Posts: 17067
Joined: 15 Aug 1998 12:01 am
Location: aka: Rusty Strings -- Missoula, Montana

Post by Richard Sinkler »

Jim Cohen wrote:Sure thing Richard. Just PM me your bank account number, password and last 4 of your social security and I'll take care of the rest. :lol:
Heck, for you I'll even give all of the numbers in my social security number. Or I might send you my actual social security card.
Carter D10 8p/8k, Dekley S10 3p/4k C6 setup,Regal RD40 Dobro, NV400, NV112 . Playing for 53 years and still counting.
User avatar
Jim Cohen
Posts: 21749
Joined: 18 Nov 1999 1:01 am
Location: Philadelphia, PA
Contact:

Post by Jim Cohen »

Richard Sinkler wrote:Heck, for you I'll even give all of the numbers in my social security number. Or I might send you my actual social security card.
Don't bother, I was just kidding. I already have all that. It came in one of the data packs I purchased a few months ago...
Post Reply