[问题] 点到假的信封

楼主: LoveWin7 (WIN 7再战10年)   2018-02-01 12:54:05
去年底我家人收到这封邮件,内容如下
Immediate action required : Your Apple ID Has Been Locked for Security Reason
Apple Store
[Billing Fraud] Apple Store Recently Purchase Confirmation
for purchasing the following item : Space Qube X
Order Number : MHDH6YMK37
Order Total : $101.99
- if you initiated this download , you can disregard this email , it was only
se
initiate the download yourself
- if you did not initiate this download , please cancel the transaction this p
ur
To cancel this purchase Read your secure message by opening the attacment (pdf
).
(view) the file or save (download) it to your computer. for best results, save
t
Web browser.
Sincerely
Apple Support
里面有附PDF档
内容如下
Dear Customer,
Your Apple ID has just been used to purchase from the App Store on a computer
or
device that had not previously been associated with your Apple ID. You may als
o
receiving this email if you reset your password since your last purchase.
If you initiated this purchase, you can disregard this email. It was only sent
t
you in case you had not initiated this purchase yourself.
If you did not initiate this purchase, we recommend that you go to here to cha
ng
your password, or see Apple ID: Security and your Apple ID for update your
information.
Regards,
Apple
https://i.imgur.com/GheldGy.png
https://i.imgur.com/nWLr9xQ.png
https://i.imgur.com/kI94cQL.png
https://i.imgur.com/5aLJ6tG.png
请问这是钓鱼信件吗??
有点里面pdf附的连结,不过该网页开不起来
不知道这样电脑会不会有事啊? 有点担心的说
(PS:家人用的是Yahoo收到这封信,而且Yahoo没把这两封列为垃圾邮件!!!)
重点是 我家人根本没有申请苹果ID啊
作者: LtcShadow (shadow085566)   2018-02-01 13:24:00
连结按右键复制连结网址然后丢去扫毒看看?https://www.virustotal.com/zh-tw/ 这里
作者: raidcrash   2018-02-01 13:47:00
100%钓鱼 登入网页没有TLS就肯定是假的了 而且哪家公司会把域名设成这种乱七八糟的样子
作者: LtcShadow (shadow085566)   2018-02-01 14:20:00
那可能是半吊子的钓鱼吧 或是网站马上就被封掉了总之那个网域太白痴了这一定是假的
作者: munsimli (口嫌体正直)   2018-02-01 15:54:00
百分百假的,请手残爱乱点的那个人多点资安概念
作者: likeus (Brand)   2018-02-01 17:48:00
这种假的信件你还点开pdf喔... 不担心是APT吗= =这种有问题的信件 即便扫描安全 也不代表没问题
作者: DINJIAPC (鼎家)   2018-02-01 22:30:00
请重新安装系统
作者: waterblue85 (waterblue)   2018-02-02 00:24:00
保险一点就重灌吧 重灌是所有方法里最省时间的
作者: minihyde (minihyde)   2018-02-02 14:08:00
暂不考虑重灌的话 先关远端和封port
作者: MVagusta (Dragster RR)   2018-02-02 22:38:00
保险点重灌吧
作者: likeus (Brand)   2018-02-03 08:51:00
APT的症状就是没症状 当然啦 我是用最坏的情况跟你讲你的pdf是透过Yahoo浏览 还是有下载到电脑才开? 感觉你是前者下载到电脑的才比较严重因为线上阅读器功能有限 比较不容易执行到恶意代码
作者: mathrew (Joey)   2018-02-05 21:32:00
骇客要偷你东西 还让你有症状? 别傻了
作者: Wutsei   2018-02-08 03:18:00
重灌比较好,之前公司内有人打开一个文件,结果隔两星期才发现他的电脑变僵尸。不止防毒软件清不干净,为了收拾他那台电脑中毒带来的影响,搞得超痛苦。中毒的电脑不仅往厂商、客户散播邮件。在其他人中毒后,还引来网络攻击。这东西防毒软件不一定能认出,我之前看过能逃过防毒、APT防护系统法眼的。虽然我这边遇到的恶意程式跟你遇到的不同,但你可以做为参考
作者: waterblue85 (waterblue)   2018-02-09 13:39:00
看来原po没有很在意他电脑安不安全吧
作者: nk950357 (nk950357)   2018-02-13 01:33:00
跟你讲办法你又不听那你问啥
作者: oh78wei (coolwei)   2018-02-16 09:02:00
没差啦 不用重灌

Links booklink

Contact Us: admin [ a t ] ucptt.com