Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 11-08-2007, 04:24 PM   #1
Ford Prefect
Has Towel, Will Travel
 
Ford Prefect's Avatar
 
Join Date: Jul 2006
Exp:
Default Is This A Scam?

I hope someone in the CP community can help me with this one. I'm familiar with most e-mail scams, but I received an e-mail today that I've never seen before and can't find on sites like snopes.

Following is the text of the message:

"hello.
i work in a private detective agency. my name is not important now.
I'm warning you that i'm going to watch you and monitor your telephone line. Do you want to know who paid for shadowing you? Expect my next e-mail.

P.S. I know, you don't believe me. But i think that the record of your yesterday's telephone conversation will assure you that everything is real. The record is in archive. The password is 123qwe"

The message also included a file attachment with a .rar file extension that supposedly contains the alleged record of my phone calls from yesterday. I use a Mac though and I gather a .rar file is some kind of Windows archive so I can't open it.

Anyway, this is a rather strange message, which I assume is a scam, but I can't confirm it. Has anyone seen or heard of this one before?

FWIW, the domain name of the sender's e-mail address is for some kind of corporate consulting firm in France.

Thanks.
Ford Prefect is offline   Reply With Quote
Old 11-08-2007, 04:27 PM   #2
FlamesFanInEdm
Crash and Bang Winger
 
FlamesFanInEdm's Avatar
 
Join Date: Sep 2005
Location: The Farm
Exp:
Default

sure sounds like a scam. i wouldnt recommend touching that rar archive.

edit: heres a link for you explaining it http://montyy0.livejournal.com/146287.html#cutid1
________
PLYMOUTH EXPRESSO HISTORY

Last edited by FlamesFanInEdm; 03-16-2011 at 09:59 PM.
FlamesFanInEdm is offline   Reply With Quote
Old 11-08-2007, 04:28 PM   #3
Ford Prefect
Has Towel, Will Travel
 
Ford Prefect's Avatar
 
Join Date: Jul 2006
Exp:
Default

Quote:
Originally Posted by FlamesFanInEdm View Post
sure sounds like a scam. i wouldnt recommend touching that rar archive.
Trust me I don't intend to, aside from the obvious reason that a windows file isn't going to work on a mac.
Ford Prefect is offline   Reply With Quote
Old 11-08-2007, 04:29 PM   #4
ricosuave
Threadkiller
 
ricosuave's Avatar
 
Join Date: Oct 2003
Location: 51.0544° N, 114.0669° W
Exp:
Default

LOL sure sounds like it to me.

found evidence of something similar on google.
__________________
https://www.reddit.com/r/CalgaryFlames/
I’m always amazed these sportscasters and announcers can call the game with McDavid’s **** in their mouths all the time.

Last edited by ricosuave; 11-08-2007 at 04:35 PM.
ricosuave is offline   Reply With Quote
Old 11-08-2007, 04:30 PM   #5
J pold
Franchise Player
 
Join Date: May 2004
Exp:
Default

Quote:
Originally Posted by Ford Prefect View Post
Following is the text of the message:

"hello.
i work in a private detective agency. my name is not important now.
And at that point I stop reading and just delete
J pold is offline   Reply With Quote
Old 11-08-2007, 04:30 PM   #6
CaramonLS
Retired
 
Join Date: Mar 2003
Exp:
Default

Open it on a library computer, no one cares about those getting infected with viruses.
CaramonLS is offline   Reply With Quote
Old 11-08-2007, 04:36 PM   #7
octothorp
Franchise Player
 
octothorp's Avatar
 
Join Date: Oct 2002
Location: not lurking
Exp:
Default

Quote:
Originally Posted by Ford Prefect View Post
I hope someone in the CP community can help me with this one. I'm familiar with most e-mail scams, but I received an e-mail today that I've never seen before and can't find on sites like snopes.

Following is the text of the message:

"hello.
i work in a private detective agency. my name is not important now.
I'm warning you that i'm going to watch you and monitor your telephone line. Do you want to know who paid for shadowing you? Expect my next e-mail.

P.S. I know, you don't believe me. But i think that the record of your yesterday's telephone conversation will assure you that everything is real. The record is in archive. The password is 123qwe"

The message also included a file attachment with a .rar file extension that supposedly contains the alleged record of my phone calls from yesterday. I use a Mac though and I gather a .rar file is some kind of Windows archive so I can't open it.

Anyway, this is a rather strange message, which I assume is a scam, but I can't confirm it. Has anyone seen or heard of this one before?

FWIW, the domain name of the sender's e-mail address is for some kind of corporate consulting firm in France.

Thanks.
Definitely sounds like a scam. But for what it's worth, there's a few applications that will open rar files on the mac: http://mac.softpedia.com/get/Compres...Mac-OS-X.shtml.
If it were me, I wouldn't bother. But if you're curious or you've been doing something lately that would attract the attention of a private investigator, it's probably safe to open on your mac: if it's a virus in a rar file, it's fairly certain to have no effect on a mac.
octothorp is offline   Reply With Quote
Old 11-08-2007, 04:43 PM   #8
Ford Prefect
Has Towel, Will Travel
 
Ford Prefect's Avatar
 
Join Date: Jul 2006
Exp:
Default

Quote:
Originally Posted by octothorp View Post
Definitely sounds like a scam. But for what it's worth, there's a few applications that will open rar files on the mac: http://mac.softpedia.com/get/Compres...Mac-OS-X.shtml.
If it were me, I wouldn't bother. But if you're curious or you've been doing something lately that would attract the attention of a private investigator, it's probably safe to open on your mac: if it's a virus in a rar file, it's fairly certain to have no effect on a mac.
Thanks ... I might try that if I get time. I don't have a guilty conscience about anything, but I am a private business owner and a new competitor is in the process of opening up in Quebec ... and I'm taking another business to court over a delinquent account they owe me for. If it's a serious e-mail it would pretty much have to relate to one of those two things. On the other hand, if it's a scam I'm curious as to what their angle is ... are they just trying to spread a virus, or are they going to try to extort some money out of me on the chance I have a guilty conscience about something. They only thing I feel guilty about right now is the second helping of pie I had for dessert last night so I wish them luck if that's their angle.
Ford Prefect is offline   Reply With Quote
Old 11-08-2007, 04:44 PM   #9
foofighter15
#1 Goaltender
 
foofighter15's Avatar
 
Join Date: Aug 2007
Location: Halifax
Exp:
Default

Well i did send my buddy who sits close to me at the office a message like that once, but that wasn't me sending you that so it sounds like a virus to me
foofighter15 is offline   Reply With Quote
Old 11-08-2007, 05:06 PM   #10
BlackArcher101
Such a pretty girl!
 
BlackArcher101's Avatar
 
Join Date: Jan 2004
Location: Calgary
Exp:
Default

What kind of private investigator makes himself known to the person he is monitoring? Talk about a career killing move right there.
__________________
BlackArcher101 is offline   Reply With Quote
Old 11-08-2007, 06:50 PM   #11
arsenal
Director of the HFBI
 
arsenal's Avatar
 
Join Date: Sep 2004
Location: Calgary
Exp:
Default

The attached file contains a virus. Its just a social engineering move to get you to open the attached .rar file and install the file. I would just delete it, forget about it and move on.
__________________
"Opinions are like demo tapes, and I don't want to hear yours" -- Stephen Colbert
arsenal is offline   Reply With Quote
Old 11-08-2007, 08:51 PM   #12
gottabekd
Powerplay Quarterback
 
Join Date: Mar 2006
Exp:
Default

For clarification: A rar is an archive file. It is not executable, and cannot infect you with a virus just by opening and extracting it. Of course, any executable files inside may (and in this case) likely have a virus.
gottabekd is offline   Reply With Quote
Old 11-08-2007, 08:54 PM   #13
MelBridgeman
Lifetime Suspension
 
Join Date: Mar 2007
Location: Calgary
Exp:
Default

of course its a freaking scam...
MelBridgeman is offline   Reply With Quote
Old 11-08-2007, 08:59 PM   #14
Ford Prefect
Has Towel, Will Travel
 
Ford Prefect's Avatar
 
Join Date: Jul 2006
Exp:
Default

Quote:
Originally Posted by MelBridgeman View Post
of course its a freaking scam...
I realize that, but since I have never seen this particular one before and I couldn't find it on snopes or other scam sites to verify that, I was curious to know if anyone at CP has seen it before. I take it by your response that you have, or are you just restating the obvious?
Ford Prefect is offline   Reply With Quote
Old 11-08-2007, 09:47 PM   #15
Bobblehead
Franchise Player
 
Bobblehead's Avatar
 
Join Date: Jul 2005
Location: in your blind spot.
Exp:
Default

I just did a search on "Do you want to know who paid for shadowing you?" (which is pretty unique) and saw there are at least 13 other people asking about the exact same email, all fairly recently. So this will probably be on the hoax sites within the next few days.
__________________
"The problem with any ideology is that it gives the answer before you look at the evidence."
—Bill Clinton
"The greatest obstacle to discovery is not ignorance--it is the illusion of knowledge."
—Daniel J. Boorstin, historian, former Librarian of Congress
"But the Senator, while insisting he was not intoxicated, could not explain his nudity"
—WKRP in Cincinatti
Bobblehead is offline   Reply With Quote
Old 11-08-2007, 10:18 PM   #16
Ford Prefect
Has Towel, Will Travel
 
Ford Prefect's Avatar
 
Join Date: Jul 2006
Exp:
Default

Quote:
Originally Posted by Bobblehead View Post
I just did a search on "Do you want to know who paid for shadowing you?" (which is pretty unique) and saw there are at least 13 other people asking about the exact same email, all fairly recently. So this will probably be on the hoax sites within the next few days.
Thanks Bobblehead ... that's the sort thing I was looking for. when I did similar searches earlier I didn't come up with anything, so it would seem it is very recent alright. What I'm still curious about is the purpose of it ... to spread a virus or scam money. It would seem spreading a virus is the most likely.
Ford Prefect is offline   Reply With Quote
Old 11-08-2007, 10:30 PM   #17
llama64
First Line Centre
 
llama64's Avatar
 
Join Date: Nov 2006
Location: /dev/null
Exp:
Default

Quote:
Originally Posted by gottabekd View Post
For clarification: A rar is an archive file. It is not executable, and cannot infect you with a virus just by opening and extracting it. Of course, any executable files inside may (and in this case) likely have a virus.
It's possible that there is an exploit in the format that allows for execution of code upon decompression. I believe there was a similar issue with an image format (jpeg?) on windows a year or two ago.

If one is really curious, just open it up in a virtualized instance of something like Ubuntu linux.
llama64 is offline   Reply With Quote
Old 11-08-2007, 10:50 PM   #18
ken0042
Playboy Mansion Poolboy
 
ken0042's Avatar
 
Join Date: Apr 2004
Location: Close enough to make a beer run during a TV timeout
Exp:
Default

I know a rar file is a sort of compressed file, like a zip. Some porn distributers use that format for some reason- or so I've heard.

And 7-zip will open it. I wouldn't; however.
ken0042 is offline   Reply With Quote
Old 11-08-2007, 11:07 PM   #19
MelBridgeman
Lifetime Suspension
 
Join Date: Mar 2007
Location: Calgary
Exp:
Default

Quote:
Originally Posted by Ford Prefect View Post
I realize that, but since I have never seen this particular one before and I couldn't find it on snopes or other scam sites to verify that, I was curious to know if anyone at CP has seen it before. I take it by your response that you have, or are you just restating the obvious?
No I havent seen it, and i dont clarification on snopes or scam sites, and just because i have never seen an email before wont make me think it's legit...you get an email from someone you dont even know,stating something outrageous...hinting that maybe you should open the attachment ..is clue enough for me to think its a bunch of crap and its headed for the delete box.
MelBridgeman is offline   Reply With Quote
Old 11-08-2007, 11:18 PM   #20
gottabekd
Powerplay Quarterback
 
Join Date: Mar 2006
Exp:
Default

Quote:
Originally Posted by llama64 View Post
It's possible that there is an exploit in the format that allows for execution of code upon decompression. I believe there was a similar issue with an image format (jpeg?) on windows a year or two ago.
I believe the issue with jpegs was IF someone was already infected with a worm that alters the way the operating system handles jpegs, then it is possible for a jpeg to "execute" malicious code.
Quote:
If one is really curious, just open it up in a virtualized instance of something like Ubuntu linux.
Great advice for anything fishy...Vmware Server is a great, free product. You can load up a guest OS, run some fishy attachment, whatever. If it is a virus, hit the "Revert" button to the previous state, before downloading the virus.
gottabekd is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 11:19 AM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy