5. September 2017 06:47 by sirclesadmin
in Internet Security, SPAM
49699367 - True Telecom Invoice for August 2017 Spam Email
This email has a randomly generated number at the beginning of the subject and is impersonating your telecom provider - a good bet as companies often have lots of different telephone and internet providers and this bill has a chance of getting through if you are not careful. It is always worth having a 'live supplier' file so that everyone knows who should be paid and who should not:
True-telecom.com are a genuine telephone company that have no connection to these emails and this email attempts associating their good name with this scam.
The email tries to get you to open a dangerous file in two ways - firstly by attaching the file with a .7z attachment which will require 7zip to open (this seems an odd tactic as most people won't have this software, and if they call the IT people to install it then they will most likely smell a rat) and by clicking the 'View your bill online' link which takes you to the same file, but as a download:
Sent: 04 September 2017 17:08
To: Customer Services
Subject: [SPAM] 49699367 - True Telecom Invoice for August 2017
Dear Deborah Day
We have attached your latest True Telecom bill for August 2017.
View your bill online
To be able to read your invoice file you will require the Adobe Acrobat PDF viewer. You August already have this installed,
if not please visit the Adobe website and download their free viewer.
Payments made by direct debit will be collected 14 days from the date of the Bill.
If you wish to contact us, please do not hesitate to get in touch with one of our friendly customer services agents.
Telephone: 0800 840 40 60
Fax: 0844 779 2253
Please be advised that this is an unmonitored email address.
With Kind Regards,
The True Telecom Team
True Telecom Ltd is registered in England and Wales No. 08225783.
Head Office address: Ground Floor,Lakeview West, Galleon Boulevard, Crossways Business Park, Dartford, Kent, DA2 6QE
This communication together with any attachments transmitted with it ("this E-Mail") is intended only for the use of the addressee and August contain information which is privileged and confidential. If the reader of this E-Mail is not the intended recipient or the employee or agent responsible for delivering it to the intended recipient you are hereby notified that any use, dissemination, forwarding, printing or copying of this E-Mail is strictly prohibited. Addressees should check this E-mail for viruses. The Company makes no representations as regards the absence of viruses in this E-Mail. If you have received this E-Mail in error please immediately delete, erase or otherwise destroy this E-Mail and any copies of it. Any opinions expressed in this E-Mail are those of the author and do not necessarily constitute the views of the Company. Nothing in this E-Mail shall bind the Company in any contract or obligation. The Company only guarantees service in accordance with the service charter. The company accepts no liability for failure of hardware after the termination point. For the purposes of this E-Mail "the Company" is the trading name of True Telecom Ltd. True Telecom Ltd (Registered in England & Wales No. 08225783)
The red-dead.fr link has been disabled in the above. As we can see from the image below, the link takes you to a download of the same attachment that has been sent with the email:
We have seen variants with the following links that contain the same dangerous download:
Under no circumstances open the attachment or open any of these links. If you are a customer of True Telecom then please be extra careful and contact them directly before opening any emails.