Showing posts with label nigerian prince. Show all posts
Showing posts with label nigerian prince. Show all posts

Tuesday, March 17, 2020

The Nigerian NFL SPAM!

by Michael Seese

It's been a while since I've posted anything in the infosec or BCP space. I've been a tad preoccupied of late with that whole "author thing." But just like rainstorms bring out the earthworms, calamities bring out the cockroaches. And with the Coronavirus scare / hoopla taking over EVERYTHING, I'm sure the email below is the first of many con jobs I'll see. So I thought it would be a good idea to hold class again on SPAM Detection 101. 

Of course, this lame attempt at SPAM is so funny, it's almost beyond belief. There are so many things wrong with it. (In fact there should be a contest. See if you can find any obvious holes that I missed, and post them as comments.) 

And, yes, I realize that the image may intrude on the standard blog info to the right. But I wanted you to be able to read it. 

























First and foremost, it's an easy Google search to confirm there's nobody named John Blair who plays in the NFL. 

First-and-a-half, if he's 20, he's probably not IN the NFL. And unless he was a coveted high draft pick (see point #1) he's not worth $4.6 million.

Second, he's American. I'm American. Why does he feel compelled to specify USD? 

Third, if he accessing his email, offering his largess to a random stranger, I'm gonna go out on a limb and say he's probably not in the ICU and dying.

Third-and-a-half, if I only had a "couple of days left," I'm not sure I'd take "a little time to make up my mind."  

Those are just a few of things I just see when I read emails like this. But it's second nature to me. I share this because it might not be second nature to everyone.

How about y'all? Anything else I missed, aside from bad grammar? (But, hey, he's an NFL player.... right?)

If you're looking for tips on how to avoid SPAM and myriad other infosec gotchas, pick up a copy of Scrappy Information Security

Stay safe!

Stay Scrappy!  


Friday, July 13, 2018

Lazy SPAM

by Michael Seese

First came self-service gas stations. Then self-service supermarket checkouts. And now, apparently self-serve SPAM, per the extortive email below. 


There's no hyperlink to click on.

No email address to write back to the Nigerian prince and claim my untold riches. 

Just vague instructions to send $700 worth of Bitcoin to some big, long string of letters and numbers.

Though I do appreciate the friendly "howdy" from Saudi arabia. 

I could imagine these guys robbing a bank. "This is a hold-up. Put your money in this bag. We'll be sitting over there."

The way I see it, there are three main problems with their tack.

1. Send Bitcoin? Um, how do I that? From Paypal? My online bank account? Seriously, I work in IT, and have no idea how to do it.

2. Or what? Did they lock up my PC with ransonware? Kidnap my dog and will force her to listen to Ariana Grande talk?  No, they claim they have dirt on me, and will show it to my friends. Which leads to...

3. If I received an email with the subject, "Wait until you see the gross thing John Doe did," I'd delete without opening it. Unless I needed fodder for another rant about SPAM. And I think I can speak for my friends when I say they're too smart to fall for it as well.

Though I've never assigned a letter grade to the SPAM emails I receive, if I were to do so, this one wouldn't even rate an E for "effort."

And if, by chance, you do get an email with the subject, "Wait until you see the gross thing Michael Seese did," you can ignore it. It's not real, or it was photo-shopped, or something.

In all seriousness, I looked through my record of posts and saw my last entry on SPAM was two years ago. And though I know I've gotten a few in the interim, it really has tailed off for me. How about you? Are you getting more or less SPAM than you were a few years back?