Accrington Web

Accrington Web (https://www.accringtonweb.com/forum/index.php)
-   Crash Computers Chat (https://www.accringtonweb.com/forum/f82/)
-   -   Not seen this email malware before (https://www.accringtonweb.com/forum/f82/not-seen-this-email-malware-before-67437.html)

Studio25 26-06-2015 16:54

Not seen this email malware before
 
Just had an email purporting to be from the DVLA about direct debit payments for my car tax.

The registration number is wrong, which is probably intentional (scare people into thinking they are paying for someone else's RFL).

The malware is a macro embedded in a word document, so while it's not likely to steal your bank details, it's probably going to irritate the hell out of you if you use Microsoft Office.

https://dl.dropboxusercontent.com/u/...poof_email.jpg

Michael1954 26-06-2015 18:32

Re: Not seen this email malware before
 
It looks genuine, so if phony, it's very clever and convincing. Rohan Gye is the DVLA's Service Manager.

How did you find out it has malware?

Gremlin 26-06-2015 18:46

Re: Not seen this email malware before
 
DVLA don't email you, they send letters.
Not everybody has email.
Press delete and forget.

Gordon Booth 26-06-2015 18:50

Re: Not seen this email malware before
 
Does just opening it let the malware in or do you have to open some attachment?
And yes, how did you catch on? I wouldn't have.

Studio25 26-06-2015 20:42

Re: Not seen this email malware before
 
Quote:

Originally Posted by Michael1954 (Post 1143431)
It looks genuine, so if phony, it's very clever and convincing. Rohan Gye is the DVLA's Service Manager.

How did you find out it has malware?

[answered below]

Quote:

Originally Posted by Gremlin (Post 1143432)
DVLA don't email you, they send letters.
Not everybody has email.

...except to people who have signed up for online services
Quote:

Originally Posted by Gremlin (Post 1143432)
Press delete and forget.

...or publicise, then delete. Not everybody can spot a scam.

Quote:

Originally Posted by Gordon Booth (Post 1143434)
Does just opening it let the malware in or do you have to open some attachment?
And yes, how did you catch on? I wouldn't have.

I knew it was a scam because I don't do my online DVLA transactions from the email account that they targeted.

To spot a scam, look at the email for bad spelling and the name of the addressee. Something full of errors and with the salutation "Dear Studio" is going to ring alarms for me. I've read that the inclusion of spelling and grammar errors is deliberate. The scammer doesn't want reasonably well educated people with a flair for attention to detail from clicking their links. They want the people who are naive enough to be frightened by the email.

Malware via email is either included in attached files or by links to infected websites.
The attached file is usually a ZIP, PDF, EXE or DOC file. There are older formats such as SCR. The golden rule with email attachements is that you don't open them unless you know the person or organisation who is sending the email and you have been told already to expect the email.
With web links, always look at the status bar before you actually click the mouse. You will be given a preview of which site you will be taken to.

Malware changes your computer for a number of nefarious reasons. The sender may just be trying to show how clever they are, they might be using your computer as part of a network for their own ends, such as overwhelming a large organisation with internet requests. They might want to obtain money from you by ransoming your files, or just damage your data because they are mentally unhinged.

It's not just malware you need to worry about. Obtaining your personal details by deception ("phishing") is of greater concern, because it's not often picked up by antivirus software. This is often done with links to dubious websites, as above. This is almost always for financial gain. The hacked website that you're sent to has pages designed to look like the site you were expecting to visit. You enter your details which are captured by the scammer, and they can then empty your account.

Bear in mind that these scams prey directly on human nature and are often defeated by a bit of common sense. If you're the sort of person that fires up the paper shredder if you receive something through the letterbox telling you you've won either £10,000, a yacht, a new car or a pen; then you're probably going to be OK. If in doubt, create a Gmail account and forward the worrying email to that address. Google's antivirus is pretty good at picking up on scams.

10 tips for spotting a phishing email - TechRepublic

gpick24 26-06-2015 21:13

Re: Not seen this email malware before
 
Just another tip for spotting dodgy emails, look to see how many other people it has been sent to. I received an email at work a while back, subject was something like "invoice" but it was CC`d to lots of other email addresses (and had a .RAR attachment, you should never open these). I rang the supplier in question and they confirmed that their email had been hacked.

Restless 26-06-2015 21:40

Re: Not seen this email malware before
 
I tend to avoid programs that download emails to the computer and as you say only opening attachments from those you trust

Michael1954 26-06-2015 21:43

Re: Not seen this email malware before
 
Thanks for the tips, everyone.


All times are GMT. The time now is 14:57.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Search Engine Friendly URLs by vBSEO 3.6.1
© 2003-2013 AccringtonWeb.com