Click here to return to the home page.
Image of a road.
Who's Online Now
7 members (DJC, Jo S, Adam12, Themorganeer, TalkMorgan, OZ 4/4, Image), 310 guests, and 40 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
John V6 85
+8Rich 68
DaveW 67
Newest Members
Wilfried, Classic-Line, BrunswickGreen44, Franco Morgan, Joachim
9,202 Registered Users
Newest Topics
Goggle eyed
by Roady - 19/07/25 06:16 PM
FOR SALE AERO8 series 1 WHEELS
by t50 - 19/07/25 12:07 PM
Lions Tour
by OZ 4/4 - 19/07/25 11:55 AM
Morgan rebuild on Facebook
by TBM - 19/07/25 10:50 AM
Ride Comfort & Tyre Age – Plus 4 Duratec
by Nick B - 19/07/25 10:22 AM
Super3 Accessory Rails for Side Blades
by BillHart - 18/07/25 11:59 PM
Glitch
by BobtheTrain - 18/07/25 05:47 PM
Latest Photos
More Pictures of the MHR Visit
More Pictures of the MHR Visit
by DaveK, July 19
Visit to the Factory- Historic Morgan Group
brake reaction stay fitting
brake reaction stay fitting
by Caveman, July 15
BHM Breakfastclub 5/7/2025
BHM Breakfastclub 5/7/2025
by DirkM, July 13
Parrot upgrade
Parrot upgrade
by Mr Mogoo, June 19
Forum Statistics
Forums34
Topics48,329
Posts812,862
Members9,202
Most Online1,046
Aug 24th, 2023
Today's Birthdays
Lenmog, plus4bassman, Saxonian
Previous Thread
Next Thread
Print Thread
Page 1 of 2 1 2
Joined: Sep 2011
Posts: 14,723
Likes: 149
Member of the Inner Circle
OP Offline
Member of the Inner Circle
Joined: Sep 2011
Posts: 14,723
Likes: 149
Maybe one of our resident computer experts can help with this.

One of the email accounts of one of our domains has been apparently hacked. It does not necessarily mean that the server has been hacked as it appears to affect only one account but it may mean that one of the devices (MacBook or recent and updated Android phone) has a virus, or that there has been an intercept of log-in details between the device and the server.

We got to know about it because of two gmail bounces with the following message:

[quote]This is the mail system at host relay.mailchannels.net.

I'm sorry to have to inform you that your message could not
be delivered to one or more recipients. It's attached below.

For further assistance, please send mail to postmaster.

If you do so, please include this problem report. You can
delete your own text from the attached returned message.

The mail system

<xxxxxxxxxx@gmail.com>: host gmail-smtp-in.l.google.com[74.125.195.26] said:
550 5.2.1 [ERN] Recipient is receiving email too quickly. (in reply to RCPT
TO command)
[/quote
(<xxxxxxxxxx@gmail.com> - the real gmail address I removed)

In both cases the bounced emails had a spoofed email address that was our email address but the origin of the bounced emails was from an IP in Vietnam and another in Iran.

The message that was attached contained one line and a a signature line that was a persons name that was also the subject of the email. It is that one line that is the real worry because it contained the smtp server, username, email address and the real password. The line is as below (with modified details) and, needless to say, the password has now been changed and before the new password is implemented in the devices a virus scan will be run.

Code
UNIQ:smtp://name@namedomain.it|smtp.namedomain.it:465|name@namedomain.it|password


If anyone has come across this before and has any information I would be pleased to know about it.


Peter

[Linked Image]
Joined: Apr 2012
Posts: 5,013
Likes: 32
Charter Member
Offline
Charter Member
Joined: Apr 2012
Posts: 5,013
Likes: 32
I would be interested to know how this happens too.... My address book is held by Google, my personal email is a Yahoo address. I am often (apparently) sending out spoof emails from Yahoo - despite the mail account not being hacked or my Google account being hacked.


+8 4.8
Joined: Mar 2009
Posts: 11,220
Likes: 159
Smile, it confuses them
Member of the Inner Circle
Offline
Smile, it confuses them
Member of the Inner Circle
Joined: Mar 2009
Posts: 11,220
Likes: 159
Peter it may be that they did not get access to the email but simply mined your contacts list, have you looked at this ?

If it does not appear to have actually come out of your system through your SMTP servers then this is also possible. Someone mine your contacts and then uses the email ID to send them out from a totally different dummy account to your contact list, masked address so it looks like you. This is a common phishing attack.

I would start by looking at what applications have access to contacts on the phone and laptop. The usual range of nasties like Farcebook try and copy your contacts up to “make life easier” and then if they have a breach the list can be stolen from them. This list is then sold on and used for phishing.

Not much you can do once it is out there but I am guessing you probably are aware of this with your experience ?


Everyone loves a Morgan. Even me, unless it's broken again.
Joined: May 2019
Posts: 386
Likes: 17
Learner Plates Off!
Offline
Learner Plates Off!
Joined: May 2019
Posts: 386
Likes: 17
It doesn't sound like you were hacked. The scumbag is just pretending to be from your operation. Sort of like writing someone else's return address ona letter. Very hard to track down the culprit, but not really a problem for you.


65 Plus 4 / 4 Seater, car addict
Joined: Sep 2011
Posts: 14,723
Likes: 149
Member of the Inner Circle
OP Offline
Member of the Inner Circle
Joined: Sep 2011
Posts: 14,723
Likes: 149
Edwin and Alistair. Thanks for the response but the problem is that the email password that was in the bounced mail was the real one. I have checked to see if the email and password is listed on HPI Identity Leak Checker and https://haveibeenpwned.com/.I am familiar with spoofed email addresses but I am not sure whether or not they actually used our server to send the mail but without a doubt the contents of the mail would have given the receiver access to the email account.

The system has been scanned for viruses and I am waiting for a second scan to complete. The first scan with Dr. Antivirus (Mac) came up with what was probably a couple of false positives for a Windows Trojan.

The next step will be to see if any sites have been accessed with the same password. We have changed it for the email account.


Peter

[Linked Image]
Joined: Jan 2012
Posts: 4,328
D
Gone to Porsche
Part of the Furniture
Offline
Gone to Porsche
Part of the Furniture
D
Joined: Jan 2012
Posts: 4,328
Originally Posted by Alistair
Peter it may be that they did not get access to the email but simply mined your contacts list, have you looked at this ?

If it does not appear to have actually come out of your system through your SMTP servers then this is also possible. Someone mine your contacts and then uses the email ID to send them out from a totally different dummy account to your contact list, masked address so it looks like you. This is a common phishing attack.

I would start by looking at what applications have access to contacts on the phone and laptop. The usual range of nasties like Farcebook try and copy your contacts up to “make life easier” and then if they have a breach the list can be stolen from them. This list is then sold on and used for phishing.

Not much you can do once it is out there but I am guessing you probably are aware of this with your experience ?



Was made aware today by several of my email recipients that they had received an email from me with a "link" to open, how worried should I be ?
Should I take any action.
It's my private address hotmail not used for business corresponding.


www.generalpaint.biz/color.php Problem with your Colour, we offer TM members impartial advice.
Joined: Apr 2014
Posts: 6,825
Likes: 59
Talk Morgan Sage
Offline
Talk Morgan Sage
Joined: Apr 2014
Posts: 6,825
Likes: 59
I'm going to be arrested immediately by the police for tax fraud. See you in 10 years!


Best Regards
Lang may yer lum reek
Joined: Dec 2009
Posts: 35,767
Likes: 468
Tricky Dicky
Member of the Inner Circle
Offline
Tricky Dicky
Member of the Inner Circle
Joined: Dec 2009
Posts: 35,767
Likes: 468
Looking forward to reading the inside story, Barlinnie ?


2009 4/4 Henrietta
1999 Indigo Blue +8
2009 4/4 Sport Green prev
1993 Connaught Green +8 prev





Joined: Apr 2014
Posts: 6,825
Likes: 59
Talk Morgan Sage
Offline
Talk Morgan Sage
Joined: Apr 2014
Posts: 6,825
Likes: 59
Probably Pe'erheed. Don't fancy the Bar L.


Best Regards
Lang may yer lum reek
Joined: Sep 2016
Posts: 996
Likes: 23
M
mph Offline
Talk Morgan Regular
Offline
Talk Morgan Regular
M
Joined: Sep 2016
Posts: 996
Likes: 23
Originally Posted by BobtheTrain
I'm going to be arrested immediately by the police for tax fraud. See you in 10 years!


Don't worry I'll pay for a top lawyer for you.

Seems I've just received £2 million in bitcoins.

Page 1 of 2 1 2

Moderated by  TalkMorgan 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.5