Six tips for identifying malicious emails

Summary

This blog post, "Six tips for identifying malicious emails", is a blueAPACHE article from 2017 covering security. In January this year, the Australian Tax Office (ATO) issued a warning regarding scam emails purporting to come from the ATO. The emails contained a link that when clicked had devastating effects; anything from installing keylogging spyware to CryptoLocker ransomware. This was followed in April, by reports of fake emails claiming to be from the Department of Human Services’ myGov website. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2017
Topic Six tips for identifying malicious emails
Services referenced emPOWER Security, Managed Detection and Response, Human Risk Management
Named products or vendors None named beyond blueAPACHE

Article

In January this year, the Australian Tax Office (ATO) issued a warning regarding scam emails purporting to come from the ATO. The emails contained a link that when clicked had devastating effects; anything from installing keylogging spyware to CryptoLocker ransomware. This was followed in April, by reports of fake emails claiming to be from the Department of Human Services’ myGov website. These emails were designed to capture personal information of recipients under the pretext of verifying their identity. Last month, the world witnessed a cyber-attack of unprecedented scale when the WannaCry ransomware was delivered to more than 230,000 computers in over 150 countries via an email containing a link or a PDF file with payload. The common factor in all these attacks? Email. While email scams and malwares have been in existence for a long time, their increasing sophistication and frequency is making them a top concern for many organisations. Moreover, modern email malware use evasion techniques designed to get around traditional security solutions. For instance, in the case of the ATO scam, each email had a unique link making it very difficult for anti-virus software to identify the bulk email as suspicious. Some email malware are so cleverly executed that at times it is difficult even for professionals to identify them. Termed as social engineering and phishing attacks, these malicious emails manipulate people into divulging confidential information or installing malware that can hold them to ransom. According to this year’s Data Breach Investigations Report 1 in 14 users were tricked into following a link or opening an attachment – and a quarter of those went on to be duped more than once. Businesses today are entirely reliant upon emails for everyday communication and a single disruption can cost millions and destroy reputation. In spite of this, many users are not adequately trained on how to recognize phishing and ransomware attempts and often fall prey to them. Even with the growing sophistication of social engineering attacks, there are some basic rules that anyone can use to detect if an email is suspicious or not. How can you identify malicious emails? Here are a few questions to ask yourself to help determine if the email you have received could be malicious:

  1. Who is the email from? An email from a legitimate address will often use the same address as the website. For example, an email from blueAPACHE would be from name@blueapache.com. However, an email from joe427@ato0989.org might indicate suspicious activity. You can view the sender’s email address by clicking on the name or hovering over it.
  2. Is the email unsolicited? Is it from an organisation that you do not normally deal with or are not expecting to hear from? If it mention flights you may have never booked, parcels you did not send or refunds you are not expecting, then be very cautious. If possible, contact the sending organisation to confirm if they sent it to you.
  3. Does the email contain external links? If the link says one thing but points to a different server, it is likely to be malicious. One way to check this without clicking the link is to hover your mouse over the link. A pop up will show you where the link redirects to.
  4. Is the website domain not quite right? Fake domains closely resemble actual ones, but will have small differences – for instance, www.linkedlin.com or www.facbook.com. http://www.whois.com/whois/ is a free service that you can use to find who the domain is registered to. It only takes a few seconds to use and could save you weeks of inconvenience.
  5. Does the email contain any attachments? If the attachment is a file with a .exe, .cmd or .bat extension, it could be a malicious program that will install code onto your computer when run. Check with the sender if the file was sent by them and what it does upon running.
  6. Do the graphics look different? Scammers try to imitate real organisations as closely as possible by using the same logo, graphics and colours, but it will often be of poor quality. When poorly executed, some of them also contain spelling or grammatical errors. What should you do if you have received a malicious email? If you think the email you’ve received could be malicious, get an expert to check it out. Do not reply or forward the email, do not click on links or open attachments contained in the email. If you do suspect you have fallen victim to an attack then log off and shut down your computer immediately and contact your IT support to minimise the impact. To better understand how you can protect your organisation from email malware, contact your blueAPACHE account manager.

Related

Frequently asked questions

What three incidents does the post cite as evidence email-based attacks were escalating that year?

The post cites the ATO's January warning about scam emails delivering keylogging spyware or CryptoLocker ransomware, April reports of fake myGov emails designed to capture personal information, and the WannaCry ransomware outbreak the following month, all delivered via email.

How many computers and countries did the WannaCry outbreak affect, according to the post?

The post says WannaCry was delivered to more than 230,000 computers in over 150 countries via an email containing a malicious link or PDF payload.

Why was the ATO scam email particularly hard for antivirus software to catch, per the post?

The post says each ATO scam email had a unique link, which made it very difficult for anti-virus software to identify the bulk email campaign as suspicious.

What statistic does the post cite from that year's Data Breach Investigations Report about users falling for phishing?

The post cites the Data Breach Investigations Report finding that 1 in 14 users were tricked into following a link or opening an attachment, and that a quarter of those went on to be duped more than once.

How does the post suggest checking whether a sender's email address is legitimate?

The post says a legitimate email will often come from the same domain as the organisation's website, for example name@blueapache.com, whereas an address like joe427@ato0989.org should raise suspicion, and that you can view the sender's actual address by clicking on or hovering over their display name.

What free tool does the post recommend for checking who a suspicious domain is registered to?

The post recommends whois.com/whois/, describing it as a free service that takes only a few seconds to check who a domain is registered to and could save weeks of inconvenience.

Which email attachment file extensions does the post flag as potentially malicious?

The post flags attachments with .exe, .cmd or .bat extensions as potentially malicious programs that could install code on your computer when run, and recommends checking with the sender before opening them.

What does the post say to do if you believe you have already fallen victim to a malicious email?

The post says not to reply to, forward, click links in, or open attachments from a suspected malicious email, and if you believe you have already fallen victim, to log off and shut down your computer immediately and contact your IT support to minimise the impact.

Source

Knowledge Base

What is the topic of blueAPACHE's article 'Six tips for identifying malicious emails'?

The article discusses how to identify malicious emails, referencing real-world scam examples such as fake Australian Tax Office (ATO) emails, fraudulent myGov emails, and the WannaCry ransomware attack, and provides six practical tips for spotting suspicious emails plus advice on what to do if you receive one.

When was the blueAPACHE article on identifying malicious emails originally published?

The article was originally published on June 9, 2017, and is written by blueAPACHE with a read time of about 4 minutes.

What email scam did the Australian Tax Office (ATO) warn about in January of the year the article discusses?

In January that year, the ATO issued a warning about scam emails purporting to come from the ATO. These emails contained a link that, when clicked, could install keylogging spyware or CryptoLocker ransomware.

What was the myGov email scam mentioned in the article?

In April, reports emerged of fake emails claiming to be from the Department of Human Services' myGov website. These emails were designed to capture recipients' personal information under the pretext of verifying their identity.

How did the WannaCry ransomware attack spread according to the article?

The WannaCry ransomware was delivered to more than 230,000 computers in over 150 countries via an email containing a link or a PDF file with a malicious payload.

According to the article, what statistic illustrates how often people fall for phishing links or attachments?

According to that year's Data Breach Investigations Report, 1 in 14 users were tricked into following a link or opening an attachment, and a quarter of those went on to be duped more than once.

What are the six tips the article gives for identifying malicious emails?

The six tips are: 1) Check who the email is from, since legitimate senders usually use an address matching their website (e.g., name@blueapache.com), while suspicious senders may use unrelated domains; 2) Consider whether the email is unsolicited, such as coming from an organisation you don't normally deal with or referencing things you didn't do (like flights or parcels); 3) Check whether the email contains external links, and hover over them to see if the link text matches the actual destination; 4) Check whether the website domain looks slightly off, such as 'linkedlin.com' or 'facbook.com', and use a service like whois.com to check domain registration; 5) Check whether the email contains attachments with extensions like .exe, .cmd, or .bat, which could be malicious programs; 6) Check whether the graphics look different from the real organisation's branding, since scammers often use poor-quality logos or make spelling and grammatical errors.

How can you check where a link in an email actually leads without clicking it?

You can hover your mouse over the link, which will show a pop-up revealing where the link actually redirects to, without needing to click it.

What tool does the article recommend for checking who a suspicious website domain is registered to?

The article recommends using http://www.whois.com/whois/, a free service that lets you find who a domain is registered to in just a few seconds.

What should you do if you think you've received a malicious email?

If you think an email could be malicious, you should get an expert to check it out, and you should not reply to or forward the email, nor click on links or open attachments in it. If you suspect you've already fallen victim to an attack, you should log off and shut down your computer immediately and contact your IT support to minimise the impact.

Who should you contact to learn how to protect your organisation from email malware, according to the article?

The article advises contacting your blueAPACHE account manager to better understand how to protect your organisation from email malware.

Why are modern email malware attacks difficult for traditional security solutions to detect?

Modern email malware uses evasion techniques designed to get around traditional security solutions. For example, in the ATO scam, each email had a unique link, making it very difficult for anti-virus software to identify the bulk email as suspicious.

Images on This Page