Spoofed Email Address Scam

The following is based on an actual case, and shows you how scammers work. In this case not very successfully, but I will come on to that in a moment. 

Scam Plot

A message arrives in your inbox which appears to have come from your account. So it is from you to you. That implies someone may have access to your email account. Something that is likely to generate a panic response, which is exactly what they are hoping for. See below for an example. Click on the image to see a larger version of it. 

For most of you though you will not see this message

Why?  If your email is hosted with me, or with Outlook.com, then you will never see this message because of something called SPF (Server Policy Framework). It is a list of legitimate sending servers which is located in your DNS settings. It is there so that any email system receiving a message from your email sending server can verify that the message actually came from your server and not from somewhere else. It is a basic test, and if it fails the email is discarded. It is handled on the receiving server.

If you do not have an SPF policy set up, then you will see the message as intended by the sender.

What the Spammer Scammer did

In this case there was a trail of evidence, because the actual message that arrived was a bounce back message, and then a reply from the actual server it came from.

It appears that the individual behind this, took over a server in a Canadian hosting company. Either used a special program to do this or wrote a script to do this. The script probably had a list of target email addresses scraped from websites. It formatted the email and populated the sending email address and the destination email address as the same address and then sent out 625 of them. We know it was 625 because the following happened.

  • Email is received and then some automated tests are carried out
  • Email is rejected because it did not come from your sending server, there was not a match, therefore it is a “spoofed email”.
  • A message is sent back to the actual sending server. At this point no email has appeared in your inbox, or in junk mail, this is all happening automatically.
  • The message arrives at the originating server, but there is no corresponding email account at the sending server, and the server replies with an error message back to your inbox.
  • Because it is an error message you get the error message and original payload. This is called a Bounceback message, it is sent to warn you of problems with email.

The bounceback message

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  info@xxxxxxxxxxxxxxxx.org.uk
    Domain tidunglagoon.com has exceeded the max emails per hour (625/500 (125%)) allowed.  Message discarded.

Reporting-MTA: dns; sng123.hawkhost.com

Action: failed

 
Here we can see where it originated from, a mail server for tidunglagoon.com. We can also see from the message that 625 emails have been sent, so this was not the only one.

The Email Header

Not shown here, but viewed by me is the email header. All emails include a header which is not normally visible. But it is present on all emails. It contains information about the source of the email and the destination. It also contains information about any tests that have been subjected to the message, particularly around spam scores. 

This is the first place to look if you get a dodgy email. It is also important if you need to share the email with a third party for analysis. 

There will always be a link or something traceable

In all of the various spoofed emails and scams there will always be a link to something. In this case there is a reference to a digital wallet so the person can receive a bit coin. I do not think you can trace that to an individual, so it is a great way of hiding. Sometimes there is an email address, or a hidden link to a website. While not impossible, those are fairly easy to hide behind too. 

What if you receive something like this?

Firstly do not panic. The sender wants you to panic, that is why these emails are constructed like this. The first task is to move the email to a special folder and leave it there. Do not click on anything in the email or send any reply. Also do not download any hidden images in the email because this confirms someone has read it. 

Calmly read through it and check to see if it is generic (could be applied to anyone) or specific to you. Chances are it is generic. If you are not sure about it, contact me and tell me about it, but do not send it to me. It is highly likely if you send it to me on my usual email address it will be detected and sent straight to my junk mail folder, so just let me know you have a problem you need me to check. 

What I will want to look at is the header in the email as well as the email contents, which is why you should park it somewhere safe and not delete it. 

 

Your Website has been hacked….. send bit coins.

There is a well documented scam going around where you will receive a message which tells you your website has been hacked and they have all of your data, and data from your clients and they are going to contact everyone and sell the data and cause you a load of grief. (I have paraphrased that to keep it short). If you get anything like that please do the following:

1). Don’t panic

2). Send a copy of it to me

3). Wait until you hear back from me

Do not pay anyone anything, or engage in a conversation. The language including grammatical errors are recorded in multiple places on the web. It is a well known scam. Another one which is designed to instil panic in the recipient. 

While I am on the subject there is a second one which claims to have taken over the camera on your computer and has images of you in compromising situations (I will leave that to your imagination!), that one is another scam. I have not seen it recently, but what goes around comes around eventually. 

Both messages will come from a non traceable source, and both are asking you to deposit bit coins in an account.

Fake 20i.com invoices

There have been several instances (around 15 of them) where an invoice has been sent to an organisation claiming to come from 20i.com and stating that their domain name has expired or is about to expire. 

The information relating to your domain name is available to view on the Nominet website: Registration Data Lookup by Nominet Just enter your domain name and other information will be presented. 

Someone, or some group have been trawling through this data and identifying websites that are hosted by 20i.com. I have a reseller account at 20i.com and deal directly with them. You have no relationship with them. Invoices from 20i.com are not sent to you, they are sent to me, and I look after them for you.  The people behind the scam do not know that. 

If you receive anything about your website, or your domain name and you are not sure, send it to me and I will confirm whether it is a scam or not. It stands to reason that if you do not have a relationship with 20i.com then you would not expect to receive an invoice from them. 

20i.com are aware that this is happening, no doubt other hosting companies are being targeted too. 

Complex Forms are now Available

Mainly for Home-Starts

I switched over to Contact Form 7 several years ago and am now familiar with several plugins which extend the functionality, particularly in the area of complex forms.

I now have available:

  • Professional and Self Referral Forms (£130 for both)
  • Volunteer online diary (£80)
  • Volunteer Application Form (£80)

The first professional referral form took 1 week to create from scratch. I start with an off the shelf copy of one of the forms, and take feedback to modify the form for your organisation.

The form has two major components; what you can see online, and a formatted email which is returned to the organisation with all of the data in it. It is also possible to include the data as a CSV string of characters which you could import into a spreadsheet or database. The email is human readable and annotated to clearly list the data submitted by the user. 

You can see some examples on this site and have a play: https://wingrove-media.uk

Contact me for more details. I can also point you to live examples which are currently in use by various organisations. 

Beware of Phishing

Over the past year I have become aware of many instances of phishing, it is much more prevalent than it was 2 years ago. It is also becoming increasingly sophisticated, especially if one person in a group that regularly communicate is compromised, his/ her contacts might be next.

Your regular email address is critically important

Phishing will try to target your email address, and get you to enter your password and email address into a box, believing that you can download something allegedly from a colleague. It may appear as an email in your inbox, or you may at some point be directed to a page with a form on it asking you to enter your credentials.

These attacks will frequently occur on a Friday afternoon, or just before a bank holiday weekend, just because it will be more difficult to independently check to see if something is legitimate or not.

I am aware of several cases where organisations have been caught out by this, it works in the following way:

Jane receives an email from a colleague asking her to download a document from say Sharepoint. Jane knows her colleague and while the email may have been short and to the point, she does not suspect anything. She clicks on a form in her email, and is then taken to the form on a website. She enters her email address and password anticipating this will allow her to download a document.

But nothing happens

Well, nothing obvious happened, so I will just assume it was broken……

What has actually happened is Jane’s email address and password has been passed to a 3rd party. The form was not legitimate.  The hacker can now access Jane’s email. In Jane’s email accounts are year’s of correspondence and messages that reveal whom Jane has been talking to, which other accounts she has access to, bank accounts, websites, Credit Cards etc. But Jane does not know someone is looking at her email.  The hacker could independently copy everything now and study it more carefully, and then contact one of Jane’s colleagues and do the same thing.

I received one of these messages last year, as did my wife.  In both cases our security recognised that the website we were being directed to was not legitimate.

Being Paranoid

Please be especially sensitive to anything that looks vaguely odd. These messages when they occur, are often very short, with no context, or a very limited context such as an invoice or payment has been made, or not been made. Many of them are also designed to shock you into acting quickly. They also arrive at the end of a day or just prior to a weekend.

Take a breath – is it real?

Find an independent route to check in with this person to make sure it was really sent and genuine if you are suspicious.  Don’t ever think it won’t happen to me. Complacency is one of the factors of success. Remember that if your main email address is compromised, it compromises everything that you have used your main email address for. Plus your main email address will be used for password recovery too.

In a case where I responded back to the person that was asking me to click on something, I was suspicious, but the person was known to me; I replied. I immediately got a reply back saying it was all quite innocent and not a phishing email…. So I clicked on it, and my security system immediately flagged up that it was a phishing site before I could enter anything. In this case, the hacker was also sitting on the person’s email account and answering emails. The email account owner was unaware that this was happening. This is why it is better to find a phone number and call them, or call a colleague to check first. In my case I used the same communications channel to ask if it was legitimate or not, and the hacker was waiting.

Remember if it goes wrong….

You are going to have to change all of your passwords starting with your email account, and then all of the accounts tied to your email account. It will take a long time to change everything, and you have to remember to cover everything. So it is worth being careful and more sensitive than “normal” whatever normal means these days!

It can be worse if you are using a free email account….

If you are using gmail, yahoo or hotmail, then the hacker can completely take over your account. You will find it quite challenging to regain control. There is no support desk with live people you can converse with on these free email accounts. So do take care, and make sure you have 2 Factor Authentication set up with any free accounts. That will help to protect you. 

Stackmail

Are you using Stackmail on a regular basis?

I write this because I came across a group this week that was only using Stackmail for their email. I am not sure why. While Stackmail works as a web interface to the 20i hosted email system, it can be a bit slow, and in my experience can be slow to respond on slower connections.  There are however alternatives to accessing email. 

If your sole email system for your charity is through the web interface to Stackmail, I recommend that you use one of the following. 

If you have MS Office and Outlook on your system, you can use Outlook to pick up email. 

If you do not have Outlook on your system, you can install Thunderbird (written by the same group that wrote FireFox), this is free and is a good alternative if you have not got Outlook on your windows platform. 

If you are using a MAC you can download email to your Mac Book or desktop by setting it up in MAC Mail. 

If you are using an iPad or iPhone or any other smart device you can set up email on those as well. 

It’s IMAP not POP3

One of the advantages about the email system is each email account is 10GB in size. That is likely to last you for many years unless the volume of junk to real mail is 100:1. 

If you create folders, and generally keep your mailbox tidy, when you look on the various devices, they all see the same mailbox irrespective of which device you are using. This is because your mail is kept locally on the server, not only on the device. 

In my case I have several windows and several Apple devices all accessing the same email box. I get the same view everywhere.

Need Help?

 There is absolutely no reason why you should only be using StackMail to pick up your email. There is no cost involved if you use Thunderbird, or use Outlook if you already have it on your system. It will save you a lot of time and frustration. 

Contact me if you need any help. 

 

Watch out for Boris & his friends

This Boris comes from the USSR and other states that have no interest in your website other than abusing it. This is a short case study on why it is wise to remain alert.

Invitation to make some changes

On a few sites where I know there is very little annual activity on the behalf of the website owners, I help out from time to time adding a message here and there. Typically this year it has related to coronavirus shut down/ reopening messages. I received a message from one of my clients and proceeded to make the changes yesterday.

On entering the website there was an exclamation mark next to a plugin warning me there was a problem. I investigated, it related to an SMTP plugin which is used to handle sending messages on behalf of the website. This is usually more reliable than sending via PHP the native method in WordPress. By using an SMTP plugin the website connects to an SMTP (outgoing mailserver) and sends the message out through an email account.

In this case it warned me that error messages had been returned from the mail server. It invited me to send a test message to check it. Which I did. The first attempt returned an error, the second attempt a few seconds later was successful, the third attempt returned an error.

What was happening?

I have been down this path a few times, and suspected that the hosting company was limiting messages coming through the mail box, probably because of spam like activity. I raised a ticket with the hosting company and asked them to check and verify.

They never answered the question but requested access to the website to see the fault for themselves. They missed key points in the questions I had raised to them, so I tried again.

Second time around they blamed the plugin for the problem claiming there were no error messages in the hosting relating to failed email attempts. (But still did not answer the question whether they were blocking it or not).  So I tried again.

On the third request they did find error messages in the email log which also mentioned suspected spamming activity through the contact form on this website.

Website Log

At this point I checked the log of website accesses to see if I could spot anything there. Sure enough something was probing the website 4 times a minute over less than a 2 second period. Humans do not work that fast, so it had to be a bot (computer program running on a compromised server somewhere).

All accesses were from this IP address: 5.188.210.4. Checking that IP address it turns out to a server in Russia. Probably a legitimate server that has been compromised by someone.

Why should you be concerned about this?

From the first time around 7 years ago now, when I started to turn on security monitoring and you could actually see beyond normal website usage, I was surprised to see the volume of illegitimate attempts to access websites.

One of the most common is sledgehammer approach password guessing routines which try to get into your website. 

In this case, something was probing the contact us page and attempting to use it to send spam.  It later turned out that the website owner had received 257 spam messages, but they had all been trapped in the email program they were using. 

Whatever it was trying to do, it was triggering a safety function in the hosting which was stopping or rate limiting messages from this website. So while it may have tried to send thousands of messages, only a few got out. BUT…. it also means that this Russian computer was hitting the website so hard, that it would have affected any legitimate messages coming in through the contact us page. 

When I did my test, it failed, then passed, and then failed for another 10 attempts. 

So, if your junk mail rises for any reason beyond a few messages a day, be suspicious. Someone may be targeting your website, and they may be impacting your website’s ability to send messages. Or said another way, your clients to reach you through your website. The main problem here is there is no warning given, no messages of failed delivery. 

How to fix it

In all of my cases, I work locally in the UK, the audience with a few exceptions are all UK based, and in most cases probably within 50 miles of the location of the entity or charity.  Therefore your website would not be of any interest to someone in India, China or Russia. 

The hosting control panel has some country blocking options. You can block by country. In this case I blocked several countries including Russia from this site.  It is not a bombproof solution, there are ways around it from the attackers point of view, they could return through a VPN or some other path from the dark web. But in most cases it will work. 

In this case some 12 hours later, the server in Russia is still probing the website every minute, which just goes to prove it is a hackers program that is doing this running on a remote server, and probably probing hundreds of sites. However in our case it is blocked at the server before it reaches the website. 

 

IP address is now blocked from accessing the hosting

If you are affected…

If you suddenly see an uptick in spam messages, and they all seem to be related (Russian or Chinese for example) send me a message and I will check. They are a nuisance, but there are ways of stopping them, both at the hosting, preventing access to the site, and adding spam filtering if there are some common themes if you are affected by direct email.

However do not ignore it. If the spam is originating via your website contact form, this may impact your other users.  Send me a message through the contact us page if you want me to check.

Phishing Woes

I would like to raise everyone’s attention to a series of official looking Phishing attempts on one of my clients. Having alerted the relevant people, one more came forward to say that they had received a message as well.

This is how it works

You receive a short email to say that your email account has been suspended due to security issues that have been detected. Of course you would wish to rectify this so would read it.

The email is personalised and appears to be addressed to you, because the first part of your email address contains your name. They harvest this part and place it as a field in the email. So you might see something like Dear mark.wingrove, ….

Note the lack of capitalisation, and the “.” in the name. That is a giveaway.

Within the message body is a statement which claims the IT/ Support department for your organisation has detected a problem with the security of your email address and you need to act within the next 48hrs otherwise your email address will be permanently disabled.

There is a link you need to click on to resolve the problem.

What is Phishing

Phishing is a method used by hackers and other bored people to present a form to you and invite you to enter your email address and password into the form. I wrote about this a few years back with an example and how it all worked. You can find it here.

You assume the website/page you are taken to is legitimate and enter the information into the form anticipating you will resolve the problem mentioned in the email.

What actually happens is the form data is forwarded to an anonymous (meaning difficult to trace) email account which the hacker is using. They will then use your email address and password to access your account and take it over.

 

Take care of your security

Once the hacker has got into your email account, now consider how you use your email account and how it is connected to everything else, and you will get an idea why they do it.

I have had examples from a a few years ago where a gmail account was compromised in this way, and the hacker got into a website because the gmail account was associated with a website.

About this particular case

In this instance, it looks like there was a small number of personalised email account addresses on the website. These are under links encouraging people to contact an individual directly. So someone or something had harvested these from the site.

Normally a generic email account is used and mail goes to this mailbox for sorting later.

What to watch out for

If you receive any email, expected or not asking you to follow a link to set up your account, unfreeze your account, or anything to do with entering your account details somewhere do not click on it.

If you were expecting an email like this (for a legitimate reason) then independently go to your account and check it. Do not trust any links sent to your email account in emails especially if they are not solicited. They are likely to be fraudulent.

About your IT department

I am not your IT department, but if I was aware of a problem with your account I would contact you directly. Even if you have a third party looking after your email accounts, they will probably contact you directly, or through their contact in your organisation, it would be very unusual to receive an automated message.

Free Account users

For those of you using Gmail (Googlemail), Yahoo or Hotmail, you are particularly vulnerable. If you loose control of your account, then you will probably lose it for a month or more. Because you are not paying for your email account, it not so surprising that there is not a human you can call to resolve it. You enter an automated process which takes some time to resolve. If that was your only account, or main account, you are now in trouble because you can no longer send or receive mail once the account is suspended. I recommend that if you fall in this category you look at adding 2 factor authentication on your account which will help prevent any third party from taking it over.

If you are using an email account associated with your hosting or domain name, then if it is taken over, it is easy to grab back again. If it happens to you, tell me or your email partner immediately you are aware of the event.

All about Email and Webmail

Email through the hosting

With people working remotely over the past few months I have had a few enquiries about how to do things. Generally when people join I provide a set of guides. In case you have lost yours I have included them all here. Just follow the links below to download your copies.

Note these are only valid for people who are using email provided through the website hosting. Some of you are on Office 365 and Outlook.com; these guides are not for you.

If you are exclusively using Gmail, Hotmail or Yahoo for your main communications (you shouldn’t really!), then these guides are not for you either.

Everyone else, this is how to set up various clients.

A recent change is most accounts should now work with mail.yourdomainname.co.uk for the SMTP and IMAP servers. You substitute yourdomainname.co.uk with; your domain name! So for me in this hosting it would be mail.wingrove-services.co.uk for both the SMTP and IMAP servers.

The guides are as follows:

How to set up Outlook (for older versions of Outlook, for new versions (2016 onwards using Office 365 check the next one. Guide link: How to set up Outlook.

How to set up Outlook in Office 365. There is a parameter which you cannot normally access in Outlook in Office 365 which may cause problems. This tells you how to locate it and set it up. Guide Link: How to set up Outlook in Office 365.

How to set up email on an iPhone or iPad. Guide Link: iPad and Smartphone

How to set up email in Thunderbird. If you are not an Outlook user, you can download and install Thunderbird which is a free email client application by the same group that developed the Firefox Browser. Guide Link: Thunderbird Mail Client.

How to set up email on a Mac using MacMail application. Guide link: Mac Mail application.

How to use Webmail. If you access your email through stackmail.com then this guide tells you how the interface works. Guide Link: Webmail user guide

How to set up Out of Office messages. The email server is the centralised location for your email. If you want to set up an Out of Office message, this guide tells you where to go.  Guide Link: Out of Office.

Any questions or request for further guidance drop me a line.

Staying in control

The primary reason I help charitable and not for profit groups is because they have the least resources and are often limited on what they can achieve with their budgets through the normal IT channels such as web design and development. They are all largely dependent on external help either through volunteers or through contractors. 

When I first enter into a relationship with a client, there are a few questions that get asked to establish how much control they have over their current website and IT systems. Often I find that they do not know the answers, or there is someone else that knows the answers. In one case some years ago the person that owned their domain name had passed away. So it was likely with no action taken their website and email systems would fail when the domain name was not renewed. 

Tips on what you need to know 

Make sure you know the answers to these questions, if you don’t and cannot find anyone that does, it represents a problem for you that may be part of a crisis later. So, make a note of them, and store them somewhere safe, and reference them from your IT policy. 

1). Where is my domain name held?

Why?

The domain name is like the golden set of keys to everything. You should know where it is located, and have access to it. If for any reason you needed to leave a relationship with a developer or hosting organisation, it starts with moving the domain name out to somewhere else. You need to know the web address, the password and the email address/ user account. If you do not have access to the email account associated with the domain registration, change it to one you do have access to. 

Continue reading Staying in control

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)