Spoofed Email Address Scam

The following is based on an actual case, and shows you how scammers work. In this case not very successfully, but I will come on to that in a moment. 

Scam Plot

A message arrives in your inbox which appears to have come from your account. So it is from you to you. That implies someone may have access to your email account. Something that is likely to generate a panic response, which is exactly what they are hoping for. See below for an example. Click on the image to see a larger version of it. 

For most of you though you will not see this message

Why?  If your email is hosted with me, or with Outlook.com, then you will never see this message because of something called SPF (Server Policy Framework). It is a list of legitimate sending servers which is located in your DNS settings. It is there so that any email system receiving a message from your email sending server can verify that the message actually came from your server and not from somewhere else. It is a basic test, and if it fails the email is discarded. It is handled on the receiving server.

If you do not have an SPF policy set up, then you will see the message as intended by the sender.

What the Spammer Scammer did

In this case there was a trail of evidence, because the actual message that arrived was a bounce back message, and then a reply from the actual server it came from.

It appears that the individual behind this, took over a server in a Canadian hosting company. Either used a special program to do this or wrote a script to do this. The script probably had a list of target email addresses scraped from websites. It formatted the email and populated the sending email address and the destination email address as the same address and then sent out 625 of them. We know it was 625 because the following happened.

  • Email is received and then some automated tests are carried out
  • Email is rejected because it did not come from your sending server, there was not a match, therefore it is a “spoofed email”.
  • A message is sent back to the actual sending server. At this point no email has appeared in your inbox, or in junk mail, this is all happening automatically.
  • The message arrives at the originating server, but there is no corresponding email account at the sending server, and the server replies with an error message back to your inbox.
  • Because it is an error message you get the error message and original payload. This is called a Bounceback message, it is sent to warn you of problems with email.

The bounceback message

This message was created automatically by mail delivery software.

A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:

  info@xxxxxxxxxxxxxxxx.org.uk
    Domain tidunglagoon.com has exceeded the max emails per hour (625/500 (125%)) allowed.  Message discarded.

Reporting-MTA: dns; sng123.hawkhost.com

Action: failed

 
Here we can see where it originated from, a mail server for tidunglagoon.com. We can also see from the message that 625 emails have been sent, so this was not the only one.

The Email Header

Not shown here, but viewed by me is the email header. All emails include a header which is not normally visible. But it is present on all emails. It contains information about the source of the email and the destination. It also contains information about any tests that have been subjected to the message, particularly around spam scores. 

This is the first place to look if you get a dodgy email. It is also important if you need to share the email with a third party for analysis. 

There will always be a link or something traceable

In all of the various spoofed emails and scams there will always be a link to something. In this case there is a reference to a digital wallet so the person can receive a bit coin. I do not think you can trace that to an individual, so it is a great way of hiding. Sometimes there is an email address, or a hidden link to a website. While not impossible, those are fairly easy to hide behind too. 

What if you receive something like this?

Firstly do not panic. The sender wants you to panic, that is why these emails are constructed like this. The first task is to move the email to a special folder and leave it there. Do not click on anything in the email or send any reply. Also do not download any hidden images in the email because this confirms someone has read it. 

Calmly read through it and check to see if it is generic (could be applied to anyone) or specific to you. Chances are it is generic. If you are not sure about it, contact me and tell me about it, but do not send it to me. It is highly likely if you send it to me on my usual email address it will be detected and sent straight to my junk mail folder, so just let me know you have a problem you need me to check. 

What I will want to look at is the header in the email as well as the email contents, which is why you should park it somewhere safe and not delete it. 

 

The take out more domains scam……

This scam is very subtle, it preys on fear, uncertainty and doubt. If you are not regularly doing business in this field and receive a message like this, it can be quite distressing. Note that this email below is not actually asking you for anything, but it is begging you to reply.  (click on the image to see a larger version of it). 

How does it work?

I have deliberately changed the real domain name in question to homestart-czw.

The sender (who is probably real) claims that they wish to use homestart-czw as a keywork in Chinese domain names.

They know that there is a homestart-czw.org.uk and that is how they found it. Similar scams along this theme may claim ownership of copyright or trademarks. What they want you to do is reply to the message. In other words start a conversation.

The sender will claim that you should protect your domain name against misuse by purchasing a set of CN (Chinese) domain names to protect your uk one. It will not stop there, they will also recommend that you purchase other domain names including the text “homestart-czw” for Thailand, Malaysia, Indonesia, Vietnam, Philippines etc. Before you know it you have purchased maybe 5 or more domain names that you do not need. Plus you have to renew them every year. The last one of these I looked at a few years ago would have amounted to an annual bill of £100 per year

Why should I ignore this?

Fundamentally because you are not trading worldwide, at best you are trading at the county level and most of you are at the local level covering a sub region in a county. Your domain name will generally give a clue about where you are:  homestart-czw.org.uk is an Organisation (charity) based in the UK. You are not providing services in China or Asia, therefore no conflict exists.

However you have to admit; from a “plausible deniability” perspective, that the person making the enquiry could just claim he is trying to help you! Sadly there is nothing going on here which could be deemed to be illegal.

If you receive a message like this, send it over and I will check it for you.

The highlighted red ring around the web address is designed to fool spam checking tools which will probably be looking for that website address. That is why it has spaces and square brackets where there should not be any.

Self directing spam to a spam folder!

We are all subject to spam messages, and sometimes they can be a real pain. There are various mechanisms for reducing it, the more sophisticated methods I use require a match between some text and an image. 

However if a human is behind sending spam, then they can defeat these systems and send it anyway. 

During an idle moment, I started think about it a bit more. 

If it is a human sending spam messages, then it is likely that they do not get paid much, and probably do not pay too much attention to what they are sending. I can tell this by looking at some of the messages that come in which have letters for example where telephone numbers should be. Or perhaps the systems are automated and have a human standing by when a problem occurs. 

Either way, I have also noted that if a choice is already made in a form, then the default choice is often used. So what happens if the default selection is “I send Spam“?  So I tried it. 

In the image you can see that there is now a selection for the subject line of the message. The default setting is “I send spam”. If a bot or bored human sends a message they will not change that setting.  Anyone genuinely wishing to contact the website will make a selection other than “I send spam”

… And here is the first candidate through this form. It is a spam message and they have not changed the subject line. So if this theory holds up I can now create a filter in my email box, that redirects the suspect message into a folder for messages that have “I send spam” in the subject line. 

The filter above will detect any messages coming into this mail box which contains the precise text “I send spam” on the subject line, and redirect it to a special folder called Spam Suspects.

About this approach

It is experimental, but looking promising.

Pros:

  • It should trap spammers who are either bots, human, bots supported by humans, people that are not paying attention.
  • With the default subject line the message can be accurately detected and sent to a special folder.
  • The inbox should be more clear of spam than it was before.

Cons:

  • A real enquirer not paying attention might also fall for it.
  • You still have to check the spam suspects folder and clear it out from time to time in case there is something important in there.

Your Website has been hacked….. send bit coins.

There is a well documented scam going around where you will receive a message which tells you your website has been hacked and they have all of your data, and data from your clients and they are going to contact everyone and sell the data and cause you a load of grief. (I have paraphrased that to keep it short). If you get anything like that please do the following:

1). Don’t panic

2). Send a copy of it to me

3). Wait until you hear back from me

Do not pay anyone anything, or engage in a conversation. The language including grammatical errors are recorded in multiple places on the web. It is a well known scam. Another one which is designed to instil panic in the recipient. 

While I am on the subject there is a second one which claims to have taken over the camera on your computer and has images of you in compromising situations (I will leave that to your imagination!), that one is another scam. I have not seen it recently, but what goes around comes around eventually. 

Both messages will come from a non traceable source, and both are asking you to deposit bit coins in an account.

Fake 20i.com invoices

There have been several instances (around 15 of them) where an invoice has been sent to an organisation claiming to come from 20i.com and stating that their domain name has expired or is about to expire. 

The information relating to your domain name is available to view on the Nominet website: Registration Data Lookup by Nominet Just enter your domain name and other information will be presented. 

Someone, or some group have been trawling through this data and identifying websites that are hosted by 20i.com. I have a reseller account at 20i.com and deal directly with them. You have no relationship with them. Invoices from 20i.com are not sent to you, they are sent to me, and I look after them for you.  The people behind the scam do not know that. 

If you receive anything about your website, or your domain name and you are not sure, send it to me and I will confirm whether it is a scam or not. It stands to reason that if you do not have a relationship with 20i.com then you would not expect to receive an invoice from them. 

20i.com are aware that this is happening, no doubt other hosting companies are being targeted too. 

Refresher Training

Forgotten how to edit your website?

Don’t despair, I have some solutions available for you.

While I provide a lot of help FOC for short enquiries, I do have quite a large number of people I am in contact with now.

For all new websites and since those days of Covid I have been providing online training for Divi site owners. Before Covid, I used to visit most people and do the training face to face. I now have a few sites in Scotland and Northern Ireland so that is not always feasible.

I can provide the following to you:

  • 2hr tutorial on what you need to know about WordPress and how to edit your website and create news.
  • Editor page built into your website with support PPT on it and links to other resources.
  • Editing exercise page.
  • 1 hr post editing training support. This is on an as needed basis, so if you need me to check something or have a question, this will be debited by the minute.
  • A video of the Zoom session.

This is a more elaborate version of what I did when visiting my clients.  It is designed to help you to be independent. Cost is £50 only available to direct clients with sites I have built.

No Budget – No Problem

I also have some training resources and tips on this special page: https://wingrove-media.uk/hsuk/ if you scroll to bottom of this page you will find there is a tutorial online and a list of times for the various exercises. This is available free of charge.

Editing Credits

While this service is not part of my normal package, I realise that some people do not need to edit their sites very frequently, or just want to outsource editing the website. I can provide up to 3hrs of editing time on an as needed basis. To take advantage of this you purchase an editing credit. Once that is agreed, you pass content to me and I will place it on your website for you. I keep a record of how long each one takes and share that with you. Contact me for more details. This service is only available if I built your website.

Page Redirect crashing some websites

On most websites I use a plugin which redirects a user to a Thank You page after they complete a form. This is a trivial function, and not one you might think could bring a website down.  I have had six cases over the past week where sites have stopped working due to an upgrade of this plugin.  It appears that the authors have substantially rewritten it, and there is probably a bug in there somewhere causing the problem. Can you all check your websites and let me know if you have a message about a critical error has occurred. 

That is the symptom. It is easy for me to fix and will take a few moments to do so, but right now I have not been through all of the websites.  You can help me to help you. 

Normally this type of incident is very rare, and it is clear that not all sites are affected either, so it is probably a combination of things. Around a year ago WordPress made some changes to error monitoring, where a site may have continued to work in the past with some issues, they seem to stop working now.

You may occasionally see a 500 error on your website, these are transient and indicate that the server cannot respond. They will clear themselves. You should never see CRITICAL ERROR. If you see that flag it to me immediately and I will sort it out for you. 

Another Phishing Scam – You may be targeted

It has just been brought to my attention that there is a phishing scam going on where people who have websites at 20i.com (I have your a reseller account here) are being sent phishing emails. It works like this:

The hacker has done some research based on name servers and then identified the websites that are hosted at a data centre. They then visit the website and scrape an email from it. They then take a screen shot of a legitimate page from the parent hosting company and attach that into the body of a an email.  

Fortunately none of you receive any emails from 20i.com directly, so hopefully your suspicions will be raised immediately. However it would be possible for me to automate the accounting side of my reseller package and you would receive emails like this. I have just never bothered to set it up. 

In the image below I shown the email which someone had kindly detected and flagged to me. I recognised it immediately as a 20i message. You would never receive one of these unless you had your own account with them. 

I have also placed my cursor over the image so you can see where the link goes to. You can see immediately it does not go to 20i.com, it goes to a server in Spain. 

This is a classic Phishing Scam. What they are after is maybe payment, or a username and password to log into the system. Either way it is a criminal act. 

Ways to detect these types of scams

When you look at the image above, it does look genuine on first glancing at it and not looking closely. It is actually based on a real message that they send out, but I am the only one that might get one, not you. 

There is a glaring error on the first line where they have adapted the message. “…. will expire within the next days.”  The actual number of days is missing. That is so they can create a reusable block of text for anyone. There are also special characters embedded in it which do not display correctly and if you look at the punctuation it is incorrectly spaced as well. 

Bottom line

If you receive a message and it does not look right, it probably is not right. The general give away is not much context and a link, or a lot of credible context, but the link is through an image. You can always find where a link goes to in most mail programs by placing your cursor on top of the link but not clicking.  In this case you would be passing information to a hacked server at http://……clinicapodologiabarcelona.es  (I suspect a foot clinic in Barcelona). 

Invoices relating to your services

You will only ever receive a message directly from me, it will not contain any links for you to login somewhere else. You would never receive a message from the hosting provider I use directly unless you had an account with them. 

Please remain vigilant, and drop me a line if you are unsure about anything, I would rather spend time replying than see anyone caught out, there is a lot of this going on right now. 

 

Beware of the peaks!

For much of the past month I have been working my way around sites and making sure the sites are updating correctly. In some cases they have not been doing this without additional input. I have not got to the bottom of why, some of it is related to the Divi template. I spent a very tortuous 2 days seeking support to find out why. It would have been more productive watching paint dry. 

However I digress, I looked at around 70 of the sites I am hosting. I had to make changes to them to get the last version of WordPress to manage the updates. After I have done this the sites should in theory look after themselves. 

In the dashboard of most sites is a Google Analytics summary of the last 30 days of activity on your site. I noted the image below which has a strange peak in it on one of the sites. 

This is not normal

Then I found another one

And another one

And another one

Unravelling the thread

I found five in around 70 sites, so it was not everywhere. But what is it? I chose one site and decided to check Google Analytics to see what it recorded.  The peak in most cases occurred over a 5 minute period when allegedly around 350+ people from around the world decided to visit your website at 9am in the morning. And I do mean from around the world, not just in the UK. Any country in the image below that is a shade of blue, means people (allegedly) came from that country. 

The image on the left shows the top 31 countries and how many computers in each country.  Click on the image to see a larger version.  Not listed here, but I did check, looking at Russia countrywide, the visits did not come from one computer, but came from many across Russia.

What is going on?

Given the attack which is still going on some 4 weeks after I was notified on another site, I am very conscious of how long that took to sort out. I checked in with the hosting company to ask about these and what they thought they were. I did not get a straight answer, other than any attack will be handled by special measures in the hosting and the site will continue to work despite this.

It is unlikely that these sites were affected in any way, the visits in this case were no different to UK based visitors. The only difference is they came from everywhere in a very short period of time, apparently altogether or in quick succession.

Speculation

A few years ago I witnessed an attack on one of my sites while with another hosting company. I documented it at the time in this site. The site in this case had a protection mechanism built in that if there were too many visitors arriving at once, or trying to log in, they delayed any further activity from that IP address. As soon as one was blocked another one started. When that was blocked another one started, and they skipped all around the world in a few minutes.

The site was not taken down, but this is basically known as a DDoS or Distributed Denial of Service attack. The expectation being that if enough computers hit your site it will consume the server resources and your site will grind to a halt.

 

Click on the image to see a larger version

BOT Network

It is highly likely that I was witnessing a Bot network which is a set of compromised servers from around the world controlled by one central resource and they were testing it. When I last came across this I had all of the IP addresses of the computers, and could do a geo location search and also identify the owners of the computers (if they were a server for example). In many cases they were corporate servers owned by respectable companies that probably had no idea that there were additional processes running off of their computers. 

The system might be targeted at some point on a corporate server and financial demands made to turn it off. 

Things for you to think about

If you see a massive peak in your statistics that you cannot account for, let me know ASAP. I will look into it. If you have one of these it means your statistics for that period are no longer valid. So do not use them in any promotional documentation. 

You may have seen in the past messages like “We checked your website and it was not getting many visitors pay us ££££ and we will increase the number of visitors to your site”  Well this is one way of doing it. It will not however generate any more business because the visitors are not real.  

I can selectively turn off countries from accessing your website and take some other measures with the hosting company if you see anything like this. 

However it should not really impact your website, or your existing visitors. If you are not sure about something; drop me a line. 

Captcha Solution for Contact Form 7

I have been using contact form 7 on many websites for the past few years. I have noticed that there are some anti spam measures which are being defeated by spam bots (computers that post spam into forms).

I am reluctant to use Google Captcha because I think that while it is undoubtedly effective, it also presents a barrier to some users, particularly elderly ones. I have also seen preferential treatment (aka easy access) when a user is using Chrome, but other browsers they may be stuck answering questions makes bypassing it frustrating to say the least.

I have just found Contact Form 7 Image Captcha by KC Computing (Kyle Charlton) which is very elegant, simple and works fine. It asks the user to click on an image which matches some text. A user has to complete this step before submitting the form.

If your site is using Contact Form 7, you can load this plugin into the library and then insert the following shortcode into the form: [cf7ic “toggle”]

If your website uses the form in a dark coloured panel, the formatting of the text may not work very well. To get around that problem you can add the following text into the CSS for your site. For Divi users this can be found on the Divi settings page at the bottom. There is a space to add CSS in there. It will change the selected text to yellow.

 

 

.captcha-image .cf7ic_instructions span {
color:yellow !important;
}

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)