False work proposal : virus !

Discuss anything you like on this forum.
Post Reply
User avatar
ROUBAL
Licensed Customer
Posts: 2199
Joined: Mon Jan 25, 2010 5:25 pm
Location: FRANCE
Contact:

Today, I have received an E-mail saying : We are an English company. We have seen your recent work about London, and we have a work proposal for you. You can see the main lines of the project here... The only thing I found by clicking on the link has been a virus ! :cry:

Fortunately my machines are well protected.

There are really some nasty people on the web ! :(
French Blender user - CPU : intel Quad QX9650 at 3GHz - 8GB of RAM - Windows 7 Pro 64 bits. Display GPU : GeForce GTX 480 (2 Samsung 2443BW-1920x1600 monitors). External GPUs : two EVGA GTX 580 3GB in a Cubix GPU-Xpander Pro 2. NVidia Driver : 368.22.
User avatar
ROUBAL
Licensed Customer
Posts: 2199
Joined: Mon Jan 25, 2010 5:25 pm
Location: FRANCE
Contact:

Hello guys, I have received the same message again. This time, I destroyed it on the server directly from my mail filter.

As I see no reason that such known company do that kind of agression, I sent them an e-mail to make them know that someone uses their name to commit web attacks.

I have voluntarily replaced the end of the link to avoid someone falling in the trap by accident !

The body of the mail itself was infected. This is just a safe screen copy (I forgot to write the name of the virus before cleaning) :

John Mark
F&C Asset Management Plc
16 Bramley Hill
London
CR2 6LY
United Kingdom

Goodday,

We are British company in London, we got to see some of your products
and we are interested in it also we want you to take a look of the pictures attached on this mail to see if we can get exact products
in your stocks

Haven confirm the products sample we needed from your company, we will ask your company to supply us, we will appreciate you download, view and give us details, prize and quantity that can be made available because we need supplies or production to be made fast.

if you cannot get the veiw very well on this mail, you can view it on this site below....

copy link
http://www.mediafire.com/XXXXXXXXXXXX
Best Regard,

John Mark.
French Blender user - CPU : intel Quad QX9650 at 3GHz - 8GB of RAM - Windows 7 Pro 64 bits. Display GPU : GeForce GTX 480 (2 Samsung 2443BW-1920x1600 monitors). External GPUs : two EVGA GTX 580 3GB in a Cubix GPU-Xpander Pro 2. NVidia Driver : 368.22.
User avatar
matej
Licensed Customer
Posts: 2083
Joined: Fri Jun 25, 2010 7:54 pm
Location: Slovenia

Hm, the lesson here is: If the author claims he's from UK, but the mail is written in some horrible engrish grammer, then it's a scam / virus / spam bot... :)
SW: Octane 3.05 | Linux Mint 18.1 64bit | Blender 2.78 HW: EVGA GTX 1070 | i5 2500K | 16GB RAM Drivers: 375.26
cgmo.net
User avatar
ROUBAL
Licensed Customer
Posts: 2199
Joined: Mon Jan 25, 2010 5:25 pm
Location: FRANCE
Contact:

Yes, but for people (like me) whom native language is not english, it is easy to not notice these grammar errors ! :roll:
French Blender user - CPU : intel Quad QX9650 at 3GHz - 8GB of RAM - Windows 7 Pro 64 bits. Display GPU : GeForce GTX 480 (2 Samsung 2443BW-1920x1600 monitors). External GPUs : two EVGA GTX 580 3GB in a Cubix GPU-Xpander Pro 2. NVidia Driver : 368.22.
User avatar
steveps3
Licensed Customer
Posts: 1118
Joined: Sat Aug 21, 2010 4:07 pm
Location: England

Then the moral of the story is that if you don't know who it is from then assume that it is spam / hoax etc. 95% of the time it will be.
(HW) Intel i7 2600k, 16GB DDR3, MSI 560GTX ti (2GB) x 3
(SW) Octane (1.50) Blender (2.70) (exporter 2.02)
(OS) Windows 7(64)
User avatar
ROUBAL
Licensed Customer
Posts: 2199
Joined: Mon Jan 25, 2010 5:25 pm
Location: FRANCE
Contact:

I get very few orders for work, so I can't be too suspicious and ignore proposal from people I don't know. The company really exist, but the message came from someone using illegally their name. As I am working on a project about London, it could be have been really from someone serious...

I wonder what can be the benefit of this kind of bad behaviour...
French Blender user - CPU : intel Quad QX9650 at 3GHz - 8GB of RAM - Windows 7 Pro 64 bits. Display GPU : GeForce GTX 480 (2 Samsung 2443BW-1920x1600 monitors). External GPUs : two EVGA GTX 580 3GB in a Cubix GPU-Xpander Pro 2. NVidia Driver : 368.22.
User avatar
glimpse
Licensed Customer
Posts: 3740
Joined: Wed Jan 26, 2011 2:17 pm
Contact:

well, not all those that live in Englan are born there.. =)
some might be from other countries having companies there..
ROUBAL wrote:I wonder what can be the benefit of this kind of bad behaviour...
take it as sick joke. SomeOne probably has weird sense of humor..
User avatar
matej
Licensed Customer
Posts: 2083
Joined: Fri Jun 25, 2010 7:54 pm
Location: Slovenia

The bad English used in this mail is quite obvious, even to non-native English speakers like myself. You would expect that someone who is supposedly the head of some department in some serious company in London, would (be required to) speak English properly, even if he's not born in England. The body of the mail is on a "spam-bot literacy level".

Also the name John Mark sounds weird. Something like Jack Joe from USA :lol:

I know that the prospect of a new client sounds exciting, but sometimes it's better to be cautious. I also don't think this is a joke, but some sort of (automated bot?) phishing attempt.
SW: Octane 3.05 | Linux Mint 18.1 64bit | Blender 2.78 HW: EVGA GTX 1070 | i5 2500K | 16GB RAM Drivers: 375.26
cgmo.net
User avatar
steveps3
Licensed Customer
Posts: 1118
Joined: Sat Aug 21, 2010 4:07 pm
Location: England

A British person wouldn't start an email with "Goodday". It is an Australian greeting and certainly not one that would be used in a work proposal.

Hopefully there is no damage to your PC. It is probably worth doing a very thorough scan of the entire system. They were probably trying to install a botnet or something like that. I don't think people write viruses just for fun these days. There is normally some sort of attack involved. Good job you had done the right thing had protection. It pays to be covered.
(HW) Intel i7 2600k, 16GB DDR3, MSI 560GTX ti (2GB) x 3
(SW) Octane (1.50) Blender (2.70) (exporter 2.02)
(OS) Windows 7(64)
User avatar
steveps3
Licensed Customer
Posts: 1118
Joined: Sat Aug 21, 2010 4:07 pm
Location: England

Looks like this one is doing the rounds


http://purportal.com/spam/12682/

p.s. this is not a spambot link, I promise, it is a link to a site reporting the same emails.
(HW) Intel i7 2600k, 16GB DDR3, MSI 560GTX ti (2GB) x 3
(SW) Octane (1.50) Blender (2.70) (exporter 2.02)
(OS) Windows 7(64)
Post Reply

Return to “Off Topic Forum”