最近公司部分帳號信箱會一直收到這樣的勒索信,郵件是由國外隨意IP寄出
郵件"寄件者"跟"收件者"都是自己,原本懷疑是郵件密碼被破解,結果更改過密碼後
還是持續收到。公司郵件伺服器架設在內部,這會是什麼問題?
郵件內文如下:
Hello!
I'm a programmer who cracked your email account and device about half year ago.
You entered a password on one of the insecure site you visited, and I catched it.
Of course you can will change your password, or already made it.
But it doesn't matter, my rat software update it every time.
Please don't try to contact me or find me, it is impossible, since I sent you an email from your email account.
Through your e-mail, I uploaded malicious code to your Operation System.
I saved all of your contacts with friends, colleagues, relatives and a complete history of visits to the Internet resources.
Also I installed a rat software on your device and long tome spying for you.
You are not my only victim, I usually lock devices and ask for a ransom.
But I was struck by the sites of intimate content that you very often visit.
I am in shock of your reach fantasies! Wow! I've never seen anything like this!
I did not even know that SUCH content could be so exciting!
So, when you had fun on intime sites (you know what I mean!)
I made screenshot with using my program from your camera of yours device.
After that, I jointed them to the content of the currently viewed site.
Will be funny when I send these photos to your contacts! And if your relatives see it?
BUT I'm sure you don't want it. I definitely would not want to ...
I will not do this if you pay me a little amount.
I think $823 is a nice price for it!
I accept only Bitcoins.
My BTC wallet: 17XHRucfd4kx3W5ty7ySLGiKHqmPUUdpus
If you have difficulty with this - Ask Google "how to make a payment on a bitcoin wallet". It's easy.
After receiving the above amount, all your data will be immediately removed automatically.
My virus will also will be destroy itself from your operating system.
My Trojan have auto alert, after this email is looked, I will be know it!
You have 2 days (48 hours) for make a payment.
If this does not happen - all your contacts will get crazy shots with your dirty life!
And so that you do not obstruct me, your device will be locked (also after 48 hours)
Do not take this frivolously! This is the last warning!
Various security services or antiviruses won't help you for sure (I have already collected all your data).
Here are the recommendations of a professional:
Antiviruses do not help against modern malicious code. Just do not enter your passwords on unsafe sites!
I hope you will be prudent.
Bye.
附上郵件表頭:
Received: from customer-189-216-57-31.cablevision.net.mx (unknown [189.216.57.31])
by mail.xxx.com.tw (Postfix) with ESMTP id 318A26AE4059
for moska@xxx.com.tw; Mon, 29 Oct 2018 08:14:52 +0800 (CST)
Message-ID:
From: moska@xxx.com.tw
To: moska@xxx.com.tw
Subject: moska@xxx.com.tw is compromised. Password must be changed
Date: 28 Oct 2018 10:56:13 -0700
MIME-Version: 1.0
Content-Type: text/plain;
charset="ibm852"
Content-Transfer-Encoding: 8bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.0471
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.0471
SMTP記錄:
Oct 29 08:14:52 mail postfix/smtpd[3226]: disconnect from unknown[189.216.57.31]
Oct 29 08:14:52 mail postfix/smtpd[3226]: 318A26AE4059: client=unknown[189.216.57.31]
Oct 29 08:14:51 mail postfix/smtpd[3226]: connect from unknown[189.216.57.31]
Oct 29 08:14:51 mail postfix/smtpd[3226]: warning: hostname customer-189-216-57-31.cablevision.net.mx does not resolve to address 189.216.57.31: Name or service not known
請服用 "使用UMail或Mail-God,收到自己寄給自己的廣告信如何過濾刪除!!(退信攻擊)"
http://ns2.ublink.org/viewtopic.php?f=5&t=2611#p4531
先備份,再置板凳,看看48小時過去後,會發生什麼精采的事情!
假的 !!
https://www.youtube.com/watch?v=dtuMAWGIyw0&t=324s
再來一點:要823個比特幣.
目前比特幣相當於6,000美元(USD)
美元對台幣的匯率為:1:31
算一下:相當台幣多少錢? 已經破億了 !!
本司最近也常收到這種詐騙信,也是自己寄給自己,不過看起來並非自身Mail Relay ,但目前也找不到方法可以阻擋。
那這種又是怎麼一回事? 密碼還猜對了 (但是不是這個 EMAIL 的密碼)
是其它網站登入的 ID:EMAIL PW:KXXXXXX 都被知道了
(個人猜是某些網站的註料資料外流,我上網查大躴從 10/20日開始有人上網問這問題,這期間我只有註冊幾個新的網站,我猜是 18X 的網站外流的)
假的...
我公司連群組信箱都可以收到
群組帳號根本沒密碼啊...
你覺得會是真的還是假的?
寄這種信不用hack mail server 啦
寄件者本來就可以亂打
找可以被Relay 的Mail Server幫忙寄就是了
寄件者是自己是垃圾郵件的基本入門
另外既然有帳號密碼了
要入侵你的電腦
加密檔案根本不是問題
真的要錢
就直接加密再勒索不是更有用?
我每天收到一堆.... 煩都煩死了
網域信件被偽冒,只要設定過濾條件即可
通常會偽裝寄件者為你的公司網域 , 讓你誤以為是公司同事寄給你的信 , 而誘使收件者來打開這封信 , 進而達到廣告信的效益 或者是病毒等惡意行為,引誘用戶開啟 郵件過濾器 -> 過濾規則管理 , 增加一條過濾規則 , 記得先把過濾器功能啟用 設定條件為"AND",當接收信件,卻寄件者是公司網域時 刪除該信件即可
參考設定方式 :https://www.richesinfo.com.tw/index.php/mxmail/mxmail-faq/215-faq-mxmail-181030
剛剛打開信箱收信,看到一封類似的勒索信,信件標題寫出我的密碼,當下我很震驚,我也被鎖定了嗎? 前幾天剛好有看到這裡在討論,趕快再上網搜尋是否有類似的情形,過了幾分鐘的思考,不對,我的密碼似乎早改了,那個勒索信的密碼是舊密碼。
又再仔細思考,為什麼那個勒索信會有那個密碼呢? 我在猜是不是我在那個論壇留下的信箱帳號、密碼,一般人密碼幾乎都用同一組,我就是其中一個,那個勒索信是用亂槍打鳥的方式,總會有人密碼設一樣的會被猜到。我看我也要盡量用動態密碼,不同網站設不同的密碼。
http://www.softnext.com.tw/news_main.html?tag=t&nid=978
這裡有一篇文章
大家參考一下