Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: Another Potentially Malicious Email Making The Rounds SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Another Potentially Malicious Email Making The Rounds

We received an email from a reader indicating that he has received several suspicious emails purporting to be from his ISP.  The emails indicate that his email space is running out and tells him to click on the link to increase the space.  Of course, the email is another example of social engineering attempts in email. I am wondering how many others are receiving this email and how wide spread it is.  Please let us know if you have seen these emails.

 

Deb Hale

Deborah

278 Posts
ISC Handler
I have been getting these e-mails for some time now, from various ISPs and mail providers. Of course, I have all of my e-mail for the various domains I support hosted with GMail for domains, and administer them myself. Funny how I receive these e-mails from my 'e-mail administrator' but never recall sending them to myself :)

My users have all been told, repeatedly, to ignore any e-mails of this nature and to confirm with me prior to clicking any links in such e-mails.
timstarlipers.com

3 Posts
Universities have been bombarded with these for a couple of years now. Mostly they're from the "Lads from Lagos" using compromised accounts. They also use the compromised accounts to send large quantities of 419 scams etc.

So far I haven't seen links hosting malicious code as such; they're generally not that sophisticated!

I help to maintain lists of reply addresses and links at the APER project http://code.google.com/p/anti-phishing-email-reply/ (SVN repository at http://aper.svn.sourceforge.net/)
Anonymous
I too like Robert always get a chuckle out of my 'e-mail administrator' sending me mail since my 'e-mail administrator' is me as well.

I am surprised this even manages to make news in the diary anymore. This stuff is like the same joke forwarded you from some friend new to the internet, only problem is that you've been forwarded this same joke every couple years since in my case, '96.

Greg

25 Posts

Sign Up for Free or Log In to start participating in the conversation!