Results 1 to 8 of 8
  1. #1
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    734
    Thanks
    143
    Thanked 185 Times in 147 Posts

    Default Your Site Has Been Hacked

    At the outset I will point out that I am guessing that this is a simple phishing attempt, the site is unlikely to be threatened by anything and many of you probably receive similar emails.

    My questions regarding this:

    1. how to get rid of such spam? Yes I know there are many solutions, however I use mail on cpanel and supposedly spam filters are enabled and I still receive emails like these, ads for ointments and medicines, food, supplements and many other unwanted messages.
    Maybe authentication on the contact form page?

    2. how do you think there are people who unfortunately actually fall for such scammers?




    Message: We have hacked your website https://.. and extracted your databases.

    How did this happen?

    Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.

    What does this mean?

    We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site was at fault thusly damaging your reputation and having angry customers/associates with whatever angry customers/associates do. Lastly any links that you have indexed in the search engines will be de-indexed based off of blackhat techniques that we used in the past to de-index Our targets.

    How do i stop this?

    We are willing to refrain from destroying your site's reputation for a small fee. The current fee is $3000 in bitcoins (0.044 BTC).

    Send the bitcoin to the following Bitcoin address (Make sure to copy and paste):

    btc adress.....

    Once you have paid we will automatically get informed that it was your payment. Please note that you have to make payment within 5 days after receiving this e-mail or the database leak, e-mails dispatched, and de-index of your site WiLL start!

    How do i get Bitcoins?

    You can easily buy bitcoins via several websites or even offline from a Bitcoin-ATM.

    What if i don't pay?

    We will start the attack at the indicated date and uphold it until you do, there's no counter measure to this, you will Only end up wasting more money trying to find a solution. We will completely destroy your reputation amongst google and your customers.

    This is not a hoax, do not reply to this email, don't try to reason or negotiate, we will not read any replies. Once you have paid we will stop what we were doing and you will never hear from us again!

    Please note that Bitcoin is anonymous and no one will find out that you have complied.

  2. #2
    TheBoyMitchell is offline Private Member
    Join Date
    March 2008
    Location
    Kent
    Posts
    577
    Thanks
    280
    Thanked 299 Times in 189 Posts

    Default

    So far today (yes, today) I've had 359 of these emails all from the same source. It's quite annoying.

  3. #3
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    5,098
    Thanks
    433
    Thanked 2,333 Times in 1,555 Posts

    Default

    Quote Originally Posted by dannyx View Post
    1. how to get rid of such spam? Yes I know there are many solutions, however I use mail on cpanel and supposedly spam filters are enabled and I still receive emails like these, ads for ointments and medicines, food, supplements and many other unwanted messages.
    Maybe authentication on the contact form page?
    Definitely add a captcha, it will eliminate a huge amount of that stuff. You can either use recaptcha if you want a google solution or hcaptcha if you don't want google involved.

    I've heard adding an extra required field can throw off a lot of bots as well, but not really tested it much myself.

    You can also set up your spam filters to catch it. If you're getting the same kinds of message then take a snippet of the text and use it to filter out spam messages.

    Eg: "a vulnerability within your site"

    Tbh you could also do it with specific words that are unlikely to be in a legit message to your site (eg: names of medicines or ointments if they are a common occurrence), but obviously the more common the work the higher the chance you'll get false positives.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding - see the spreadsheet here.

  4. The Following 2 Users Say Thank You to baldidiot For This Useful Post:

    dannyx (22 March 2024), TheGooner (22 March 2024)

  5. #4
    universal4's Avatar
    universal4 is online now Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,896
    Thanks
    4,522
    Thanked 9,277 Times in 5,965 Posts

    Default

    #1 way to stop the spam (temporarily) is close the email account. This works until the replacement email address ends up on the right lists where it's starts up again. If it is an email registered at affiliate programs, banks etc, too time consuming.

    Yes people do in fact still fall for such things.

    Adding a captcha? IMO won't change anything, unless it is a web form that exposes the email without the captcha, and then that will only slow down the automation of adding the email to the lists. If an email is associated with a site url, the email is on thousands of lists of site owners and those are the most common lists purchased for such scam emails.

    As badidiot suggested, if you are getting a ton of them, filters to dump them will stop having to look at them.


    Rick
    Universal4

  6. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    Cash Bonus (24 March 2024), dannyx (23 March 2024)

  7. #5
    TheGooner's Avatar
    TheGooner is offline Private Member
    Join Date
    March 2007
    Location
    New Zealand
    Posts
    4,563
    Thanks
    2,092
    Thanked 4,533 Times in 2,175 Posts

    Default

    You could add an email rule in your filter to remove messages that match a criteria ...

    Say a rule like body contains "Bitcoin address" or extracted your database or destroy your reputation .
    You could bounce it, delete it or just send it to a spam folder.

    They would all be unlikely to appear in a real message right?? Put the rule in and you'll never know they were sent.
    I've added a dozen rules blocking mass domains and or message subjects or body contains ...

    Works like a charm.

    EDIT : Yeah - just noticed that Baldie already said this up the thread ... sorry.

  8. The Following 2 Users Say Thank You to TheGooner For This Useful Post:

    dannyx (23 March 2024), universal4 (22 March 2024)

  9. #6
    dannyx is offline Public Member
    Join Date
    November 2019
    Posts
    734
    Thanks
    143
    Thanked 185 Times in 147 Posts

    Default

    Thanks for the all answers, will test in the near future.
    I have also seen advice to block emails from Gmail. However, I am not yet convinced to do that.

  10. #7
    baldidiot is offline Private Member
    Join Date
    January 2010
    Posts
    5,098
    Thanks
    433
    Thanked 2,333 Times in 1,555 Posts

    Default

    Quote Originally Posted by universal4 View Post
    Adding a captcha? IMO won't change anything, unless it is a web form that exposes the email without the captcha, and then that will only slow down the automation of adding the email to the lists. If an email is associated with a site url, the email is on thousands of lists of site owners and those are the most common lists purchased for such scam emails.
    It sounded like they were using a contact form ("Maybe authentication on the contact form page?") hence the captcha suggestions, obviously that won't do anything for direct emails.

    Personally we never send acknowledgement emails from a contact form either - that stops the address getting out there. Ie: If someone spams a contact form and you never reply, if they also don't get an acknowledgement from the site then they won't ever know the email so it won't get put on lists.

    We actually don't get any direct spam to the emails we use for our contact form addresses this way.
    onlinegamblingwebsites.com - Formally known as goodbonusguide.

    Gambling Domains: Small clear out of some of the domains we've been hoarding - see the spreadsheet here.

  11. The Following User Says Thank You to baldidiot For This Useful Post:

    universal4 (23 March 2024)

  12. #8
    NoDepositCasinos's Avatar
    NoDepositCasinos is offline Public Member
    Join Date
    November 2022
    Location
    Colombia
    Posts
    1,220
    Thanks
    356
    Thanked 472 Times in 388 Posts

    Default

    Quote Originally Posted by dannyx View Post
    At the outset I will point out that I am guessing that this is a simple phishing attempt, the site is unlikely to be threatened by anything and many of you probably receive similar emails.

    My questions regarding this:

    1. how to get rid of such spam? Yes I know there are many solutions, however I use mail on cpanel and supposedly spam filters are enabled and I still receive emails like these, ads for ointments and medicines, food, supplements and many other unwanted messages.
    Maybe authentication on the contact form page?

    2. how do you think there are people who unfortunately actually fall for such scammers?




    Message: We have hacked your website https://.. and extracted your databases.

    How did this happen?

    Our team has found a vulnerability within your site that we were able to exploit. After finding the vulnerability we were able to get your database credentials and extract your entire database and move the information to an offshore server.

    What does this mean?

    We will systematically go through a series of steps of totally damaging your reputation. First your database will be leaked or sold to the highest bidder which they will use with whatever their intentions are. Next if there are e-mails found they will be e-mailed that their information has been sold or leaked and your site was at fault thusly damaging your reputation and having angry customers/associates with whatever angry customers/associates do. Lastly any links that you have indexed in the search engines will be de-indexed based off of blackhat techniques that we used in the past to de-index Our targets.

    How do i stop this?

    We are willing to refrain from destroying your site's reputation for a small fee. The current fee is $3000 in bitcoins (0.044 BTC).

    Send the bitcoin to the following Bitcoin address (Make sure to copy and paste):

    btc adress.....

    Once you have paid we will automatically get informed that it was your payment. Please note that you have to make payment within 5 days after receiving this e-mail or the database leak, e-mails dispatched, and de-index of your site WiLL start!

    How do i get Bitcoins?

    You can easily buy bitcoins via several websites or even offline from a Bitcoin-ATM.

    What if i don't pay?

    We will start the attack at the indicated date and uphold it until you do, there's no counter measure to this, you will Only end up wasting more money trying to find a solution. We will completely destroy your reputation amongst google and your customers.

    This is not a hoax, do not reply to this email, don't try to reason or negotiate, we will not read any replies. Once you have paid we will stop what we were doing and you will never hear from us again!

    Please note that Bitcoin is anonymous and no one will find out that you have complied.
    Have you tried using the SpamAssassin tool and increasing the spam threshold?

    If you've already tried it and it didn't work or you're still not satisfied, another option is to filter specific words (in my case, these messages were all practically identical, even if they were from different senders) and report the message for phishing. That's what I did, and now I only receive one or two messages of that type in months
    casinobonusnewsletter.com - AMs contact me for deals

    revenueoptimization.io - DM me if you want to be featured in our blog

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •