Live data from Hacker News

Email from FBI Looks Odd

old.reddit.com

21–30 of 172 posts

Re: Email from FBI Looks Odd

#21
post #4

The FBI don't provide information like this in an email and will speak to you first. This is bogus, delete it.

The dkim header signature is correct. It means it really is from an FBI server.

But still... the FBI don't speak to you like this and wouldn't overprovide information like this.

The only time I've seen the FBI talk like this is when they already have a trusted relationship with you and an open channel and they're off the record.

Just because a server is coerced into sending an email that is signed, it does not mean it is from the FBI.

Re: Email from FBI Looks Odd

#22
The email address seems to point to EIMS (Enterprise Identification and Management Service according to https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/docu...). The email address is also listed at some guide at https://www.justice.gov/tribal/page/file/1260671/download.

My guess would be that there is some integration point somewhere to EIMS that allows requesting/granting some access & takes the email template from submitted form.

Re: Email from FBI Looks Odd

#23

I received this at 1:07 AM PST to my work sysadmin account. It passed Barracuda and Office 365 spam filters. Initially I felt a surging panic when I realized the source IP was indeed FBI, especially considering one of our close partners recently buckled under a ransomware attack they refused to pay, and thus had to rebuild from backups over a period of two weeks. Smells mostly bogus now with no links to a status page…

Did the "one of our close partners [who] recently buckled under a ransomware attack" have contact details for "[you] and other sysadmins", to target the emails?

Re: Email from FBI Looks Odd

#24
post #21

Earlier quoted context omitted.

The dkim header signature is correct. It means it really is from an FBI server.

But still... the FBI don't speak to you like this and wouldn't overprovide information like this. The only time I've seen the FBI talk like this is when they already have a trusted relationship with you and an open channel and they're off the record. Just because a server is coerced into sending an email that is signed, it does not mean it is from the FBI.

The point here isn't whether this is real or fake. The news is that someone is able to impersonate an email as coming from the FBI with all of the correct email headers with dkim signing. I'm speculating here, but this probably means they might have control of one of the FBI subdomains

Re: Email from FBI Looks Odd

#25
The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain.

Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration. Perhaps someone was able to inject a message instead of the regular canned text through some sort of reflection attack? This explains why replies to the message result in a canned response. The system also now appears to be temporarily down. So it’s getting some sort of attention (internally taken down (most likely) or maybe denial of service from the abuse).

The Reddit thread suggests the recipients’ emails are likely ARIN IP range contacts. Those are very available from tools like this [2] so nothing interesting with that, but the real question is WHY someone would do this at all? This was clearly given some thought (on who to send this to who would actually take the time to verify the headers) but given the sloppiness of everything else, is this just a script kiddie flex? Whoever it is pissed off the FBI and gained absolutely nothing.

[0] https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/docu...

[1] https://www.justice.gov/tribal/page/file/1260671/download

[2] http://itools.com/tool/arin-whois-domain-search

Re: Email from FBI Looks Odd

#26
post #4

The FBI don't provide information like this in an email and will speak to you first. This is bogus, delete it.

The dkim header signature is correct. It means it really is from an FBI server.

How can you tell without all the headers mentioned in DKIM-Signature?

Re: Email from FBI Looks Odd

#27
post #25

The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain. Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration…

Awesome. A guide written in 2019 from the FBI that suggests Internet Explorer.

Re: Email from FBI Looks Odd

#28
post #5

Earlier quoted context omitted.

The hackers have the ability to originate legit emails from ic.fbi.gov and they blow it on a spammy phishing campaign with broken English? what a waste..

Sounds about right. A blue chip I work with had a successful phish against them - the attacker ended up with access to the email inbox of an HR person. So they tried basic, stupid 419 type scams, with broken English. They could have pried the entire org wide open - she had masses of private data in her inbox, enough to impersonate or social engineer your way to anywhere. But instead, they blew it - and blew it so bad…

The other episode that springs to mind is the hackers who managed to compromise the Twitter accounts of the likes of Obama and Elon Musk, but used it to promote a shitty Bitcoin gifting scam, which netted them an easily traced $100k and a prison sentence. Probably the scammers promoting the same sort of scheme in the comments with legal fake accounts make more money

Re: Email from FBI Looks Odd

#30
post #25

The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain. Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration…

Awesome. A guide written in 2019 from the FBI that suggests Internet Explorer.

What’s wrong with internet explorer? It’s still in active support.
Post reply on HN