Odd email - query spam


Sigurd

Well-known member
Member
VIP
Local time
9:57 PM
Posts
423
Visit site
OS
Windows 11 - Updated automatically
I received two emails this morning which I am pretty sure are scams. However they are genuine enough looking to make me think.
One is from Shared-Documents via SharePoint | My domain name <sharepointmyname@edocs.com>
The other is the same content but from DocuSign-Account | My domain name<sharefile-myname@edocs.com>

I have no financial or legal transactions pending, though have had some from my bank a few weeks ago that used similar system.
Hovering over Review document shows https: *//t.co/and a string of letters and numbers (My asterisk)
Header is
ARC-Seal: i=1; cv=none; a=rsa-sha256; d=********; s=default;
t=1729740559;
b=fWk9VuhJTBrHbS6PAsxbS456OPAx2Q2fNc0uYtO2P9pL2TO6mBCjUzatS2SKRyKA8iyie
xgHibU/K11YPEX3xLDIZg/c23UyQQSSj20T7K7U57jKHXfxcyItf39X/xrpH2OFkn46bmNM
NZJbXKr0vDgp6IJnHPzlXRiPoq+ZZB8=
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed;
d=*******; s=default; t=1729740559; h=from : to : subject : date
: message-id : mime-version : content-type : content-transfer-encoding
: from; bh=Dl91aeOZr6BuSx0ujOOLEolWacFnm/EL0b4W8XMVtyw=;
b=qKenenM8kHrNlaL0iGLBEGAb5EvmdSlzXy/rE6MKIZcJhWIWWB4yXEPimgmgjiFYPRpK/
QpVC1fP+M+t3XJmLkm3g4+OK9ix4N4p6Hb14HFv0+hE/wSH7fDwX9AcmHHkHEwZya+1nEEh
wlP/fQCmRpieChH62E+zc0+l+N23RQM=
ARC-Authentication-Results: i=1; ynh4.uk.easy-server.com;
dmarc=none smtp.from=edocs.com header.from=edocs.com;
spf=none smtp.mailfrom=sharepoint********@edocs.com smtp.helo=edocs.com
Return-Path: <sharepointi********@edocs.com>
X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on
ynh4.uk.easy-server.com
X-Spam-Level: *
X-Spam-Status: No, score=1.4 required=4.0 tests=HTML_FONT_SIZE_LARGE,
HTML_MESSAGE,MIME_HTML_ONLY,RCVD_IN_MSPIKE_BL,RCVD_IN_MSPIKE_L5,
RCVD_IN_VALIDITY_RPBL_BLOCKED,RCVD_IN_VALIDITY_SAFE_BLOCKED,RDNS_NONE,
SPF_HELO_NONE,SPF_NONE,TO_NO_BRKTS_NORDNS_HTML,URIBL_BLOCKED autolearn=no
autolearn_force=no version=3.4.0
X-Original-To: *****************
Delivered-To: *****************
Received: from edocs.com (unknown [201.218.200.106])
by ynh4.uk.easy-server.com (Postfix) with ESMTP id 8EBDFA0FA0
for <*****************>; Thu, 24 Oct 2024 04:29:17 +0100 (BST)
Authentication-Results: ynh4.uk.easy-server.com;
dmarc=none (p=NONE sp=NONE) smtp.from=edocs.com header.from=edocs.com;
spf=none (sender IP is 201.218.200.106) smtp.mailfrom=sharepointimcandrew@edocs.com smtp.helo=edocs.com
Received-SPF: none (ynh4.uk.easy-server.com: no valid SPF record)
From: "Shared-Documents via SharePoint | stbees.org.uk" <sharepointimcandrew@edocs.com>
To: **************
Subject: DocuSign Important received a New Secured Document ************** 10/23/2024
Date: 23 Oct 2024 22:29:16 -0500
Message-ID: <20241023222915.7EC4B503766BA989@edocs.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

The screen grab is attached.

1729762439900.png
 

My Computer

System One

  • OS
    Windows 11 - Updated automatically
    Computer type
    PC/Desktop
    Manufacturer/Model
    Updated Chillblast
    CPU
    Intel i7 12700K Twelve Core 3.6Ghz
    Motherboard
    MSI PRO Z690-A DDR4 Motherboard
    Memory
    Corsair 32Gb Vengeance RAM
    Cooling
    Air cooled
    Internet Speed
    72Mb down, 18Mb up
    Browser
    Chrome
    Antivirus
    Avast
edocs.com

I can’t load that domain.

The subject of one “DocuSign Important received a New Secured Document
Screams scam.

smtp.mailfrom=sharepointimcandrew @ edocs.com
lol

Do you have 5 min? You want me to connect right now and check the emails out?

Probably not necessary though: I’m calling it dangerous scam spam.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.4249
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    4 x LG 23MP75 - 2 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    100/40Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Other Info
    …still on a horse.
(y) Good job posting the Header info, Ian
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.4249
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    4 x LG 23MP75 - 2 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    100/40Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Other Info
    …still on a horse.
Unless I know the sender I'll just delete any email without even opening it -- if the message is a genuine message and important enough the sender will communicate again soon enough via a more recogniseable message.

Cheers
jimbo
 

My Computer

System One

  • OS
    Windows XP,7,10,11 Linux Arch Linux
    Computer type
    PC/Desktop
    CPU
    2 X Intel i7
So are you expecting any financial statements and documents about cash flow??
 

My Computers

System One System Two

  • OS
    Windows 11 2xH2 (latest update ... forever anal)
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Slim S01
    CPU
    Intel i5-12400
    Memory
    8GB
    Graphics Card(s)
    NVIDIA GeForce GT730
    Sound Card
    OOBE
    Monitor(s) Displays
    Acer 32"
    Screen Resolution
    1920x1080
    Hard Drives
    512GB KIOXIA NVMe
    1TB SATA SSD
    PSU
    OOBE
    Case
    OOBE
    Cooling
    OOBE
    Keyboard
    BT
    Mouse
    BT
    Browser
    Brave FFox Chrome Opera
    Antivirus
    KIS
  • Operating System
    Windows 11 Pro 2xH2 (latest update ... 4ever anal)
    Computer type
    Laptop
    Manufacturer/Model
    HP Pavillion 15
    CPU
    i7-1165G7 @ 2.80GHz
    Graphics card(s)
    Intel Iris Xe Graphics
    Hard Drives
    Samsung NVMe 512GB
    + numerous/multiple SSD Type C USB enclosures
    Internet Speed
    NBN FTTN 50
    Browser
    Brave
    Antivirus
    KIS
So are you expecting any financial statements and documents about cash flow??
Not unless some rich relative I don't know has left me something in his will. :rolleyes:
Do you have 5 min? You want me to connect right now and check the emails out?

Probably not necessary though: I’m calling it dangerous scam spam.
Agree - not necessary. Zapping it!

Thanks all.
 

My Computer

System One

  • OS
    Windows 11 - Updated automatically
    Computer type
    PC/Desktop
    Manufacturer/Model
    Updated Chillblast
    CPU
    Intel i7 12700K Twelve Core 3.6Ghz
    Motherboard
    MSI PRO Z690-A DDR4 Motherboard
    Memory
    Corsair 32Gb Vengeance RAM
    Cooling
    Air cooled
    Internet Speed
    72Mb down, 18Mb up
    Browser
    Chrome
    Antivirus
    Avast
Not unless some rich relative I don't know has left me something in his will. :rolleyes:

Agree - not necessary. Zapping it!

Thanks all.
If that were the case I'd bet your phone would be in the old parlance "be ringing off the hook". !!

Cheers
jimbo
 

My Computer

System One

  • OS
    Windows XP,7,10,11 Linux Arch Linux
    Computer type
    PC/Desktop
    CPU
    2 X Intel i7
You might register at spamcop and start a report there.
After inserting the suspected code of the email, you get an analysis of the email.
They search the email-code for tricks in the adresses and report the analysis-result to you.
If you would want to report the email to spamcop and possibly other adresses, it will be mentioned where they send it to (you can choose them as well). But you don't need to report the mail, you just can only use it for analyzing purposes.

When you indeed report the email, all personal data will be anonymized!

That's how I do it, when I get emails that look suspicious but might be real.
 

My Computer

System One

  • OS
    Windows 11 Pro 23H2 22631.4751
    Computer type
    PC/Desktop
    Manufacturer/Model
    Build by vendor to my specs
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    MSI PRO B550M-P Gen3
    Memory
    Kingston FURY Beast 2x16GB DIMM DDR4 2666 CL16
    Graphics Card(s)
    MSI GeForce GT 730 2GB LP V1
    Sound Card
    Creative Sound Blaster Audigy FX
    Monitor(s) Displays
    Samsung S24E450F 24"
    Screen Resolution
    1920 x 1080
    Hard Drives
    1. SSD Crucial P5 Plus 500GB PCIe M.2
    2. SSD-SATA Crucial MX500-2TB
    PSU
    Corsair CV650W
    Case
    Cooler Master Silencio S400
    Cooling
    Cooler Master Hyper H412R with Be Quiet Pure Wings 2 PWM BL038 fan
    Keyboard
    Cherry Stream (wired, scissor keys)
    Mouse
    Asus WT465 (wireless)
    Internet Speed
    70 Mbps down / 80 Mbps up
    Browser
    Firefox 130.0
    Antivirus
    F-secure via Internet provider
    Other Info
    Router: FRITZBox 7490
    Oracle VirtualBox 7 for testing software on Win 10 or 11
So are you expecting any financial statements and documents about cash flow??

Not unless some rich relative I don't know has left me something in his will. :rolleyes:

Not that that domain anyway. It’s all a scam.

Docusigns domains is

docusign.com
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.4249
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    4 x LG 23MP75 - 2 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    100/40Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Other Info
    …still on a horse.
Dmarc=none in the header is enough to tell me this was not sent by any reputable company.

People can post onto your Google drive and bypass emails spam traps. I guess the same can happen with SharePoint?
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2 26100.2894
    Computer type
    Laptop
    Manufacturer/Model
    Acer Swift SF114-34
    CPU
    Pentium Silver N6000 1.10GHz
    Memory
    4GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD
    Cooling
    fanless
    Internet Speed
    150 Mbps
    Browser
    Brave
    Antivirus
    Webroot Secure Anywhere
    Other Info
    System 3

    ASUS T100TA Transformer
    Processor Intel Atom Z3740 @ 1.33GHz
    Installed RAM 2.00 GB (1.89 GB usable)
    System type 32-bit operating system, x64-based processor

    Edition Windows 10 Home
    Version 22H2 build 19045.3570
  • Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot

Latest Support Threads

Back
Top Bottom