Receiving bad Russi...
 
Notifications
Clear all

Receiving bad Russian links from some of you...

49 Posts
28 Users
0 Reactions
8 Views
Wendell
(@wendell)
Posts: 5782
Admin
Topic starter
 

Hey guys,

Be careful out there. I'm getting messages from some of you with a link to a Russian website. I can only guess that it infects your PC and sends itself to everyone on your contact list, then some of them click on the link, etc.

So, first of all, please DO NOT CLICK THE LINK! Secondly, delete the message immediately.

I don't know the source of this problem, but it can either be a direct hack of your account or it could simply be a case of spoofing. But it seems peculiar that I'm getting the message only from other surveyors. Might just be coincidence.

For safety's sake, I'm having my host perform a security audit on the server, just to make sure. However, I don't suspect that to be the problem.

 
Posted : March 31, 2011 9:15 pm
 RADU
(@radu)
Posts: 1091
Registered
 

Did U get one from my public yahoo address? As my main email address did not receive one (Probably because spammer stopped it) Doug Casement emailed that he got one.

For those who have been invaded you will get returned emails from odd addresses that are not in your address book .

Wendell I went to log in on my face book page and my yahoo email address was sitting there as large as life and I was not logged in !

I suspect Facebook is the security leak !

RADU

 
Posted : March 31, 2011 11:16 pm
Wendell
(@wendell)
Posts: 5782
Admin
Topic starter
 

Word has it, Keith had the same problem earlier today...

 
Posted : March 31, 2011 11:40 pm
 RADU
(@radu)
Posts: 1091
Registered
 

Yes he did.

RADU

 
Posted : April 1, 2011 12:48 am
(@jeff-d-opperman)
Posts: 198
Registered
 

I Got One

I got one from a fellow surveyor this morning that looked like the normal email messages that I got from him and it simply said "Many thanks" and it had the surveyors name, address, registration number - everything very typical of our other correspondence. When I clicked on the link, a page full of letters, characters and numbers came up. After I closed it, AVG came on the screen with a full page notification that it had caught it and stopped it. I have been deleting the returned email notifications for a week, but this one caught me off guard. Good thing that it didn't catch AVG off guard...

 
Posted : April 1, 2011 2:14 am
(@floyd-carrington)
Posts: 277
Registered
 

I got emails from "Deral Paulk" and "Beer Legs" this morning with no subject line and links. Both were deleted on the spot.

 
Posted : April 1, 2011 2:56 am
 RADU
(@radu)
Posts: 1091
Registered
 

I Got One from Sanibel Surveys on two of my email addresses

Andrew D. Johnson, PSM
Sanibel Surveys

He is on Facebook too!

How does one tell Facebook that they are being breached?

RADU

 
Posted : April 1, 2011 2:57 am
(@mark-laing)
Posts: 24
Registered
 

I agree it's likely Facebook. When it happened to me, I spent time arguing with Yahoo.com. Then afterward went back to Facebook, and was told I had last signed on in California. I live in Florida. I don't think they're bad people (facebook) I think it's just such a large site they're a good target for hackers.

 
Posted : April 1, 2011 2:58 am
(@floyd-carrington)
Posts: 277
Registered
 

Also I am not on Facebook.

 
Posted : April 1, 2011 2:59 am
(@carl-b-correll)
Posts: 1910
 

Wendell, (and everybody)

Here is some more info for your investigation:

I got those messages from Chris Harmon, Deral Paulk, and Sanibel Surveys (Andy Johnson). These are all gmail addresses, as is mine.

Deral's "To:" list included at least 4 of my personal friends that have probably been included with Deral and Andy on small "mass" mass e-mailings by me, of a joke or a picture, or whatever.

I do not have Chris Harmon on my facebook, nor my regular contacts list, and I don't know if he's got a pseudonym (BeerLegs?).

I hope this helps.

Carl

 
Posted : April 1, 2011 3:51 am
(@andy-j)
Posts: 3121
 

i agree, GMAIl is the source,,, i got return email and texts this morning from friends that are neither surveyors nor facebookers. hell,my account may have been the source for all I know.

 
Posted : April 1, 2011 4:22 am
(@carl-b-correll)
Posts: 1910
 

> i agree, GMAIL is the source,,, i got return email and texts this morning from friends that are neither surveyors nor facebookers. hell,my account may have been the source for all I know.

It could be. I'm not casting aspersions or anger, just facts. I find it odd that MY friends ended up on Derals list. Of course, you can only see parts of the email list that the ruskie spammer sent. Oddly, most of them begin with the letter "C".

 
Posted : April 1, 2011 4:26 am
 RADU
(@radu)
Posts: 1091
Registered
 

I only got return email from Yahoo, but sanibel surveys came in on gmail and my business email as I have written to Andy so in his address book

Seems it is going from address book to address book and adding or making up addresses.

Still believe initial hack through FB

RADU

 
Posted : April 1, 2011 4:26 am
(@holy-cow)
Posts: 25292
 

I knew I should have checked in here first.

A few minutes ago I checked my Hotmail account and found a message from jppls1, Jim Petty in Arkysaww. Same thing. I clicked on the link. AAARRRGGGHHH

I do not participate on Facebook. Visible recipients started with B.

 
Posted : April 1, 2011 4:30 am
(@andy-j)
Posts: 3121
 

in a reply from someone i spammed, all the addresses started with a C as well..

 
Posted : April 1, 2011 4:31 am
 RADU
(@radu)
Posts: 1091
Registered
 

What happened when U clicked on link?

RADU

 
Posted : April 1, 2011 4:33 am
(@holy-cow)
Posts: 25292
 

Weird letters and symbols everywhere.

Any chance this is tied to LinkedIn?

 
Posted : April 1, 2011 4:38 am
(@daniel-s-mccabe)
Posts: 1457
 

I got one from Deral, but hotmail said the link was blocked for spamming.

 
Posted : April 1, 2011 4:47 am
 RADU
(@radu)
Posts: 1091
Registered
 

Could also be..

RADU

 
Posted : April 1, 2011 4:55 am
(@keith-luttrell)
Posts: 100
Registered
 

I got hit with the thing also. I didn't hit the link either. Makes me want to find the POS in a dark alley and give a good 'spamming' to him.

 
Posted : April 1, 2011 4:59 am
Page 1 / 3