Live data from Hacker News

Email from FBI Looks Odd

old.reddit.com

11–20 of 172 posts

Re: Email from FBI Looks Odd

#12
post #7
post #3

Earlier quoted context omitted.

The news here is the headers look good.

Except that the OP did not post all the information to verify. The IP address does belong to the fbi.gov (both forward and reverse DNS lookups check out). The DKIM public key does exist at the given selector [0], but without the complete raw message, it is not possible to verify the signature. He also excluded the authentication-result header from his post. [0] https://www.mailhardener.com/tools/dkim-validator?domain…

> Except that the OP did not post all the information to verify.

A few other people on that thread got the same mail and did verify it. Either they're all sockpuppets or it verifies.

Re: Email from FBI Looks Odd

#13
the only vaguely reliable item in an email header is the last ip in the square bracket inserted bt your mailserver saying where it thinks it "Received from"

note that in this case it is: Received: from dap00040.str0.eims.cjis (dap00040.str0.eims.cjis [10.66.2.72])

and that 10.X.X.X is an un-routable address (unless you are part of the originating network)

Since I'm not part of the FBI I would strongly suspect some one was misrepresenting their address to my mailserver.

adding that I really don't know jack about this. sec is not an interest of mine so please, experts, straighten out any misconceptions I am propagating

Re: Email from FBI Looks Odd

#14
post #13

the only vaguely reliable item in an email header is the last ip in the square bracket inserted bt your mailserver saying where it thinks it "Received from" note that in this case it is: Received: from dap00040.str0.eims.cjis (dap00040.str0.eims.cjis [10.66.2.72]) and that 10.X.X.X is an un-routable address (unless you are part of the originating network) Since I'm not part of the FBI I would strongly suspect some on…

The one inserted by my mailserver is Received: from mx-east.fbi.gov (mx-east-ic.fbi.gov [153.31.119.142])

The 10.* ones were inserted by theirs.

Re: Email from FBI Looks Odd

#15
post #13

the only vaguely reliable item in an email header is the last ip in the square bracket inserted bt your mailserver saying where it thinks it "Received from" note that in this case it is: Received: from dap00040.str0.eims.cjis (dap00040.str0.eims.cjis [10.66.2.72]) and that 10.X.X.X is an un-routable address (unless you are part of the originating network) Since I'm not part of the FBI I would strongly suspect some on…

There's a paste from another recipient's headers:

https://pastebin.com/8ES3t1hv

I believe the very top line is inserted by the victim mailserver and points to an FBI IP in a way that can be considered accurate.

Re: Email from FBI Looks Odd

#16
I received this at 1:07 AM PST to my work sysadmin account. It passed Barracuda and Office 365 spam filters.

Initially I felt a surging panic when I realized the source IP was indeed FBI, especially considering one of our close partners recently buckled under a ransomware attack they refused to pay, and thus had to rebuild from backups over a period of two weeks.

Smells mostly bogus now with no links to a status page and so many others reporting the exact same sloppy email, but how did they know to email me and other sysadmins, and how did they send from an FBI IP address?

Edit: typo

Re: Email from FBI Looks Odd

#17
Lack of full body and some headers mentioned in the DKIM-Signature headers makes it impossible to verify DKIM authenticity. Would (reddit) OP not cut out their Authentication-Results headers, we we would know how their MTA's anti-forgery mechanisms saw this alleged message.

But, assuming that what's on reddit is true, this is interesting. It looks like FBI attempting to discredit a researcher (which I doubt because this would be one of dumbest ways to do so) or maybe someone gained enough access to FBI's infra to at least bounce a message by their systems without it looking so (but earlier Received headers do not suggest that the message originated from outside the network).

EDIT: Another idea is that OP's systems may be so compromised already that someone simply created FBI-looking message on their system and it never touched network.

Re: Email from FBI Looks Odd

#18

I received this at 1:07 AM PST to my work sysadmin account. It passed Barracuda and Office 365 spam filters. Initially I felt a surging panic when I realized the source IP was indeed FBI, especially considering one of our close partners recently buckled under a ransomware attack they refused to pay, and thus had to rebuild from backups over a period of two weeks. Smells mostly bogus now with no links to a status page…

Are you listed on any contacts or WHOIS? One of my friends got it to every single possible ARIN POC - abuse, noc, any named users for their IP space, and any emails that could be found for their domain.

Re: Email from FBI Looks Odd

#19
"email from FBI", and the Nigerian FBI office at that ... Reminded - a professor of a Moscow University couple months ago received a call from Russian Central Bank advising him that his account in some bank is being actively targeted by scammers/hackers, and that he needs to temporarily transfer the money to the special holding account the Central Bank rep provided, so the professor did. Some time later the scammers started to target the professor's condo - the police agent called him informing about it and asking for help to catch the scammers - when the scammers come with the prepared documents for the condo sale, professor would need to play the part as if he doesn't know what it is a scam and to sign the documents, receive the money and after that to give the money as evidence to the special agents in the car near the condo building. And professor did as he was told. So far - no money, no condo, no bank account with the significant sum of money...

Or as our corporate anti-phishing/etc. training - which was forced again upon us last month - instructs "Got a call from John from company A ? Hang up and call the public phone number of the company A and ask for the John."

Re: Email from FBI Looks Odd

#20
post #18

I received this at 1:07 AM PST to my work sysadmin account. It passed Barracuda and Office 365 spam filters. Initially I felt a surging panic when I realized the source IP was indeed FBI, especially considering one of our close partners recently buckled under a ransomware attack they refused to pay, and thus had to rebuild from backups over a period of two weeks. Smells mostly bogus now with no links to a status page…

Are you listed on any contacts or WHOIS? One of my friends got it to every single possible ARIN POC - abuse, noc, any named users for their IP space, and any emails that could be found for their domain.

No, actually. All domains use an alias but this was sent directly to my primary, but not sent to any of our historic or present domain WHOIS contacts.
Post reply on HN