home | list info | list archive | date index | thread index

Interesting scam email - they know I use Roundmail

<html><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /></head><body style='font-size: 10pt; font-family: Verdana,Geneva,sans-serif'>
<div style="font-size: 10pt; font-family: Verdana,Geneva,sans-serif;">
<div style="font-size: 10pt; font-family: Verdana,Geneva,sans-serif;">
<p>I got a couple of these from different source addresses.</p>
<p>Source email on this one is: <a href="mailto:takise [ at ] p-alt [ dot ] co [ dot ] jp">takise [ at ] p-alt [ dot ] co [ dot ] jp</a></p>
<p>Posting as an example of more focused email scams arising, possibly using AI to get at something as niche as RoundCube.<br />Really small groups like Roundcube users are not safe from attack.</p>
<p>Rob</p>
<pre><br />After the image:<br /><br />The source code of the image part of the email.<br />Some line breaks and bold added for clarity.<br /><br /><img src="cid:176030126068ec10cc70350636206248@echlin.ca" /><br /><br />&lt;!DOCTYPE html&gt; &lt;html lang="en"&gt; <br />&lt;head&gt;
&lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&gt;
 &lt;meta charset=utf-8&gt; &lt;meta http-equiv="X-UA-Compatible" content="IE=edge"&gt;
&lt;title&gt;Retrieve Delayed Mails&lt;/title&gt;
 &lt;style&gt; body { font-family: Roboto, sans-serif; background-color: 
#f4f4f4; color: #2c363a; font-size: 14px; } .container { max-width: 680px; 
margin: 20px auto; background-color: #ffffff; padding: 20px; /* Removed 
border */ } h2 { font-size: 1.5em; color: #333333; font-weight: bold; 
margin-top: 0; } .section { border: 1px solid #428bca; margin-top: 20px; 
} .section-header { background-color: #428bca; color: #ffffff; padding: 
10px 15px; font-weight: bold; } table { width: 100%; border-collapse: 
collapse; font-size: 13px; } td { padding: 8px; border-top: 1px solid 
#ddd; } .actions a { display: inline-block; background-color: #348eda; 
color: #ffffff; padding: 10px 15px; margin: 5px 5px 0 0; text-decoration: 
none; border-radius: 4px; } .footer { font-size: 12px; color: #555; 
margin-top: 20px; } &lt;/style&gt; &lt;/head&gt;
 &lt;body&gt; &lt;div class="container"&gt; <br />&lt;h2&gt;Client Configuration Settings for 
"echlin.ca"&lt;/h2&gt; &lt;div class="section"&gt; &lt;div class="section-header"&gt;Secure 
SSL / TLS Settings (Recommended)&lt;/div&gt;&lt;table&gt; &lt;tr&gt;&lt;td&gt;Recipient:&lt;/td&gt;&lt;td&gt;
rob [ at ] echlin [ dot ] ca&lt;/td&gt; &lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Password:&lt;/td&gt;<br />&lt;td&gt;Use the email account's 
password.&lt;/td&gt; &lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Message:&lt;/td&gt;&lt;td&gt; Temporary IMAP/POP3 server 
issues (port: 993) have delayed some incoming emails to your inbox.&lt;br&gt;
&lt;br&gt; &lt;div class="actions"&gt; &lt;a 
href="https://mkmhousing.co.uk/i/ic.uc.php?code=6f1e#rob [ at ] echlin [ dot ] ca" 
target="_blank"&gt;Receive all emails&lt;/a&gt; &lt;a 
href="<strong>https://mkmhousing.co.uk</strong>/i/ic.uc.php?code=6f1e#rob [ at ] echlin [ dot ] ca" 
target="_blank"&gt;Delete all emails&lt;/a&gt; &lt;/div&gt; &lt;br&gt; Do not reply to this 
automated message. &lt;/td&gt; &lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Date:&lt;/td&gt;&lt;td&gt;This notice was 
generated on Saturday, September 27, 2025.&lt;/td&gt; &lt;/tr&gt; &lt;/table&gt; &lt;/div&gt; 
&lt;div class="footer"&gt; A mobile configuration file for use with iOS and 
macOS Mail.app is attached to this message.&lt;br&gt; &amp;copy; 2025 echlin.ca 
cPanel, L.L.C. &lt;/div&gt; &lt;/div&gt; &lt;/body&gt;
 &lt;/html&gt;</pre>
<p><br /></p>
<div id="v1v1_rc_sig"></div>
</div>
</div>
</body></html>

PNG image