Notices
928 Forum 1978-1995
Sponsored by:
Sponsored by: 928 Specialists

928sRus hacked email

Thread Tools
 
Search this Thread
 
Old 08-03-2020, 10:05 AM
  #1  
ROG100
Basic Sponsor
Rennlist
Site Sponsor

Thread Starter
 
ROG100's Avatar
 
Join Date: Jan 2003
Location: Double Oak, TX
Posts: 16,816
Received 830 Likes on 326 Posts
Default 928sRus hacked email

928sRUs's email accounts have been attacked. We are currently working to contain the situation. There is no indication that private customer information has been affected.

If you received an email from 928sRUs with a questionable attachment, like "request.zip" or any other .zip file, or requires you to use a supplied password to open the attachment, or attaches an invoice when you know you haven't ordered anything in over 6 months... don't open the attachment.

If you did open the attachment, immediately download and run (free) MalwareBytes (malwarebytes.com) to scan for malware on your computer. If it finds anything allow it to quarantine all files found, then reboot your computer and run MalwareBytes again.

We apologize for the stress and inconvenience this might cause. We will post an update when the situation has been contained.
__________________

Does it have the "Do It Yourself" manual transmission, or the superior "Fully Equipped by Porsche" Automatic Transmission? George Layton March 2014

928 Owners are ".....a secret sect of quietly assured Porsche pragmatists who in near anonymity appreciate the prodigious, easy going prowess of the 928."







Last edited by ROG100; 08-03-2020 at 10:14 AM.
The following users liked this post:
911user (08-04-2020)
Old 08-03-2020, 10:09 AM
  #2  
linderpat
Rennlist Member
 
linderpat's Avatar
 
Join Date: Nov 2006
Location: Pittsburgh, PA
Posts: 14,401
Received 2,256 Likes on 1,258 Posts
Default

I just sent you an email on this too. Was going to post here. Glad you caught it. Slick phish scam. Bad guys got your email distribution list apparently.
The following users liked this post:
911user (08-04-2020)
Old 08-03-2020, 10:29 AM
  #3  
Wisconsin Joe
Nordschleife Master
 
Wisconsin Joe's Avatar
 
Join Date: Jan 2013
Location: Kaukauna Wisconsin
Posts: 5,925
Received 302 Likes on 231 Posts
Default

Got one from Zane. The attachment was weird, but I was dumb enough to download it.

It wouldn't open.

I should have known to read this forum before my e-mail.

Thanks for the heads up & link to the
Old 08-03-2020, 10:50 AM
  #4  
Ed Scherer
Addict
Rennlist Member
 
Ed Scherer's Avatar
 
Join Date: Jul 2001
Location: Shawnee, KS, USA
Posts: 7,330
Received 108 Likes on 62 Posts
Default

Got mine! Didn't open (pretty obvious scam/hack) or even bother to investigate.

Hope it didn't jack up your systems very much or victimize your customer base, Roger.

I really hate the bastards that do this crap. If only they'd use their talents to benefit humanity instead.

P.S. They would have had more success with the subject line "Here's one I can't put in the IHI thread"
Old 08-03-2020, 10:51 AM
  #5  
85euro928
Rennlist Member
 
85euro928's Avatar
 
Join Date: Jan 2009
Location: Hampster Bays, LI
Posts: 1,334
Received 87 Likes on 44 Posts
Default

I just received an email from 928sRUs with a 90% off coupon attached, are you telling me it's not good?
The following 3 users liked this post by 85euro928:
beran earms (08-03-2020), ducbil (08-03-2020), linderpat (08-03-2020)
Old 08-03-2020, 11:06 AM
  #6  
sendarius
Pro
 
sendarius's Avatar
 
Join Date: Mar 2004
Location: Perth, Western Australia
Posts: 715
Likes: 0
Received 13 Likes on 12 Posts
Default

Originally Posted by 85euro928
I just received an email from 928sRUs with a 90% off coupon attached, are you telling me it's not good?
Hey!! I got one too!

Not really - but I DID get the "please open this attached quote that you didn't ask for" email.

I may have been born at night, but it wasn't LAST night.
The following users liked this post:
STRIKEMASTER (08-04-2020)
Old 08-03-2020, 11:34 AM
  #7  
RKD in OKC
Rennlist Member
 
RKD in OKC's Avatar
 
Join Date: Oct 2004
Location: In a tizzy
Posts: 4,987
Likes: 0
Received 14 Likes on 11 Posts
Default

Don't try to open the attachment. It is a file that requires a fake microsoft word update and macros that install shell access to your computer. Then they can login, turn of protection and download usernames an passwords saved in your web browser, then turn the protection back on.
Old 08-03-2020, 12:27 PM
  #8  
Daniel5691
Drifting
 
Daniel5691's Avatar
 
Join Date: Jun 2014
Posts: 3,126
Received 235 Likes on 140 Posts
Default

Rec'd email also.
Good luck Roger.
Old 08-03-2020, 12:35 PM
  #9  
Tomkat80222
Racer
 
Tomkat80222's Avatar
 
Join Date: Nov 2014
Location: Rocky Mountains
Posts: 354
Received 42 Likes on 25 Posts
Default

It was early and I've been working with Roger. I opened access to a password protected zip file, but nothing happened. I will investigate, but I already have security software. I don't save passwords to my computers that have any importance.
The following users liked this post:
911user (08-04-2020)
Old 08-03-2020, 12:42 PM
  #10  
drooman
Rennlist Member
 
drooman's Avatar
 
Join Date: Jun 2011
Location: CT & FL
Posts: 2,740
Received 2,011 Likes on 698 Posts
Default

This is an image of what they look like,

there's a special place in hell....



Old 08-03-2020, 12:54 PM
  #11  
Ed Petry
Rennlist Member
 
Ed Petry's Avatar
 
Join Date: Dec 2009
Location: Central Ohio
Posts: 434
Received 19 Likes on 16 Posts
Default

Hi everyone,
I received this phish on my apple messenger account (text messages). Did not open.
(appears I am unable to attach the screenshot -- sorry. Basically free golf)

Last edited by Ed Petry; 08-03-2020 at 01:06 PM. Reason: Add screenshot
Old 08-03-2020, 01:03 PM
  #12  
Bertrand Daoust
Rennlist Member
 
Bertrand Daoust's Avatar
 
Join Date: Oct 2005
Location: Gatineau, Québec, Canada
Posts: 5,139
Received 1,216 Likes on 470 Posts
Default

Got this too this morning.

Forget my email Roger.
Old 08-03-2020, 01:11 PM
  #13  
danglerb
Nordschleife Master
 
danglerb's Avatar
 
Join Date: Oct 2006
Location: Orange, Cal
Posts: 8,575
Received 3 Likes on 3 Posts
Default

Roger thanks for the quick heads up. Running malwarebytes always a good idea, same for not opening anything suspicious.
Old 08-03-2020, 01:51 PM
  #14  
jej3
Three Wheelin'
 
jej3's Avatar
 
Join Date: Feb 2004
Location: Jacksonville and sometimes St. Aug Beach, FL
Posts: 1,727
Received 341 Likes on 171 Posts
Default

Sorry for the 928srus troubles. Just a suggestion... maybe we don't need to all post if we received it. We're probably all having a Monday but this is too dejavu to the people who "Reply All" to an email to tell them to be removed from the "Reply All".

Old 08-03-2020, 02:30 PM
  #15  
Wisconsin Joe
Nordschleife Master
 
Wisconsin Joe's Avatar
 
Join Date: Jan 2013
Location: Kaukauna Wisconsin
Posts: 5,925
Received 302 Likes on 231 Posts
Default

Originally Posted by RKD in OKC
Don't try to open the attachment. It is a file that requires a fake microsoft word update and macros that install shell access to your computer. Then they can login, turn of protection and download usernames an passwords saved in your web browser, then turn the protection back on.
Okay. Thanks for that.

I downloaded (since deleted) the attachment, then tried to open it. When it asked me to install something to open the attachment, I got suspicious (yeah, it took that long).

Got the Malwarebytes that Roger suggested, ran it and it came out clean.


Quick Reply: 928sRus hacked email



All times are GMT -3. The time now is 01:30 AM.