Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Email in my Sent box that I did not send, contains credentials in plain text


  • This topic is locked This topic is locked
4 replies to this topic

#1 bbeirdWtf

bbeirdWtf

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:17 AM

Posted 06 September 2024 - 12:44 PM

The subject line is in regard to a very specific portion of what I'm dealing with at the moment. I was very lazy with my online credentials (using one password everywhere). They were obtained somehow and I've been scrambling to lock everything down properly ever since. The point of the post is in bold text below, but a quick summary of the sequence of events.....

 

I received a message from LinkedIn that an alternate email was added to my account. I did not do that myself so I tried to log in to see what had happened. I found myself locked out of LinkedIn and have not been able to get back in. I need to either 1) email them a photocopy of my ID, or 2) get a form notarized. I'm not sending a picture of my ID electronically as a resolution to identity fraud...

 

I then started receiving replies to messages I did not send from within Facebook market place. Someone was in my Facebook and trying to buy things. I sent messages to all of the recipients of the malicious messages, telling them not to believe a word I say.

 

I immediately changed my credentials and enabled mfa wherever possible

 

I'm using unique randomly generated passwords for every account I can recall having....but I keep recalling new ones each day so I cannot say for sure that the leaked credentials are now useless everywhere but I'm getting there.

 

I have McAfee and have run full scans on any device I've been using. There have been no hits on anything malicious. McAfee does agree that my (previous) credentials have been leaked to the wild but I already knew that part.

 

I received an email that contained a number of my previous passwords in plain text, along with a .jpg and a .pdf that I did not open. I still have the email, but know I need some sort of sandbox environment if I want to examine the attachments. My guess is that the pdf is going to demand I pay a ransom or else... 

 

I then found a message in my outlook sent messages fold from me, containing my login credentials in plain text. The complete message was:

 

Subject: CHECKER RESULT: v1

 

New--Smtp--Test

Host: smtp.office365.com

Port: 587

User: xxxx

Pass: xxxx

 

 

where the xxxx was my real outlook email credentials. 

 

this message was sent to fdskamil566@gmail.com

 

 

I don't know if this is the origin of the leak, or someone taking advantage of the previously leaked credentials to gain further access. However, I don't know how this email was triggered, or how to prevent it from happening again since my McAfee software is not finding anything wrong. I'm hoping this sounds familiar to someone and I can get a point in the right direction. 

 

Let me re-iterate... I was being completely lazy and am now laying in the bed I made....if you'd still like to reassure me of just how stupid I was being using the same password everything, I'll understand, but I am on the road to securing everything as properly as I can.

 

Thank you in advance for any help!! I really appreciate it. 



BC AdBot (Login to Remove)

 


#2 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 36,797 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:17 PM

Posted 06 September 2024 - 01:44 PM

Download and install min-toolbox from here: https://www.bleepingcomputer.com/download/minitoolbox/
 
minitoolbox.png
 
With the following:
 
Last 10 error messages from the logs
Installed Application
Problematic Devices 
List users and partitions
US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

#3 bbeirdWtf

bbeirdWtf
  • Topic Starter

  •  Avatar image
  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:09:17 AM

Posted 06 September 2024 - 03:01 PM

Thank you for the fast response. The output of the MiniToolBox is attached. Most of the contents are beyond my knowledge but I will say that anything to do with sysinternals Autorun happened after my security breach. 

Attached Files

  • Attached File  MTB.txt   36.43KB   3 downloads


#4 cryptodan

cryptodan

    Bleepin Madman


  •  Avatar image
  • Members
  • 36,797 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:17 PM

Posted 06 September 2024 - 03:19 PM

I am going to refer you to post a request in the virus removal section

https://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

I saw nothing out of the ordinary but there could be something cause this is strange.


Edited by buddy215, 06 September 2024 - 07:01 PM.

US Navy Veteran from 2002 to 2006
Masters in Computer and Digital Forensics Expert - Stevenson University Alumni 2015
Arch Desktop - https://termbin.com/1h62
Arch Laptop - hhttps://www.termbin.com/98dd
Ubuntu Server - https://termbin.com/ng9t

#5 midimusicman79

midimusicman79

    Sec & Web Browser Enthusiast


  •  Avatar image
  • BC Advisor
  • 5,620 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Norway
  • Local time:02:17 PM

Posted 07 September 2024 - 11:22 AM

It turns out that the OP already has an active MRL Forum topic here:

 

Outlook Sent email that I did not send, contained credentials in plain text.


Microsoft Windows 10 Professional 64-bit V. 22H2 (19045) Retail Desktop PC, EAMH Paid/EEK, MB 5 Prem., and Unchecky, MDFW, FF with uBO/AG, Grammarly Free, MBBG, and Acronis True Image Essentials, RuckZuck, PatchMyPC, UpdateHub, UniGetUI, UCheck, and Winget. I have 29.5 Years of PC Experience.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users