Richard would need to verify first that the email came from Katie. In doing so he
may contact Katie by using a different means of communication since she is an old
childhood friend i'm sure he does not have her phone number so he can resort to
social media like Facebook, Instagram, Lindken or possibly classmates.com if she is
registered through there to see if she has updated her email address to the one he
received as well as the contents that were included in the email. Once he has verified
that with her then he should run a virus scan on it to make sure that the attachment
is safe and will not cause harm to his system only because in the process of her
sending the email to him it could have easily been attacked by a virus that can attack
his system. He also wants to make sure the domain she is using is a safe one or at
least a well known like Gmail or Yahoo even then he still needs to be safe in
running the scan. When receiving the email from Kate, Richard should be very care
when opening the email. First, what he should do is run a scan email for viruses to
see if any to trigger the spyware scan. Second, he could try reaching out to Kate
through Facebook or any type other means social media to confirm if in fact it is her
that sent the email. For the attachment he should not open it because it could cause a
backdoor for a hacker to access his personal information or even yet upload a virus
where it could destroy his pc. Richard can do a couple things. First he’ll need to
check for red flags like the sender address isn’t correct or doesn’t seem to know the
addressee, unusual URLs in the embedded links, the language, spelling and grammar
errors and lastly how bizarre or random the content. If any of these red flags apply
most likely it’s spam email that should be reported spam. To be more certain Richard
can use email lookup tools, or search the email with social media networks online like
Twitter, Facebook, LinkedIn, He’ll want to make sure his email authenticates using
SPF, DKIM and DMARC. ISPs will identify and treat email that is not properly
authenticated. Richard should attempt to find an alternative way to reaching out to
Kate such as social media, a previous email or even an acquaintance or family
member if possible. Richard should have a decent virus protection or firewall software
installed that also scans all emails and attachments, preventing any malicious activity
from entering his inbox. Unfortunately, not all malicious emails are able to be stopped
before reaching the inbox. If I were personally in Richards situation and was unable
to find another way to reach out to Kate, I wouldn't take the chance of opening the
file on my main computer. A last option would be to open the file without running it.
Doing this will place the file in your "Downloads" folder. Do not open the folder.
Scan the file for any viruses or malware. Again, even when using these options,
malware can still sneak past firewalls and virus protection if the security software is
outdated or not properly maintained. If I was Richard, I would try contacting Kate
first if I was able to and ask her if she made a new email. You could also ask
family and friends if you weren’t able to get ahold of Kate. This happened to me one
time, I got an email from my friend’s parents in the middle of the night saying they
needed money to get home from being stranded somewhere. I had to call multiple
people to determine if it was them or not. I was obviously concerned that they may
have actually needed help, but I figured it was a scam. I can see how people fall for
these types of things easily when they are worried and may click links or send money
in a moment of panic. Richard first can look in his email for a warning saying the
attachment could be malicious. He can also scan the attachment before he was to
click on it. Ultimately Richard should not click on the attachment if he is unsure if it
was from Kate or looks suspicious at all. I think that Richard should try to contact
Kate through another source, via phone or social media, to verify the authenticity of
the email. I would also consider sending a test email to Kate's new email address to
confirm the true identity of the sender. If neither of these methods work in finding
out the authenticity of the email, then Richard must make a decision to either delete
the email without opening it, or take a chance and open the email, and understand the
possible dangers behind that decision. The email can contain malware that may
destroy data on your computer, allow attackers to read your emails, and allow
attackers to check the user's personal and sensitive information. To make sure that the
email attachment is not malicious, Richard should scan the email attachment for
malware with an anti-virus software, this would keep his data safe from malicious
programs to could potentially damage his system. If I was in Richards shoes I might
first check to see if I have a known way of reaching Kate to verify the authenticity
through her. For instance if I have her as a friend on social media, an old phone
number or email address that’s trustworthy. And I’d message her directly asking if she
sent me an email updating her contact information. If that isn’t the case and I don’t
have any prior means of contacting her I’d check the display name and the email I’m
receiving her message from. I’d stop and make sure that is something reasonable and
is realistic. If the sender is saying they are Kate but I noticed a misspelling in her
name that could be a good indication that it’s a fake email and phishing attempt. I’d
also ask myself how Kate got my email address in the first place. If it’s been so long
that I don’t have current contact information for her I’d be asking myself how she got
it for me. And I might ask a mutual friend if they can validate the email. I’d
probably ask them to pass on my phone number if this was indeed Kate trying to
reach me. Richard should email Kate on her old email address to verify if it is real
or not. If he has access to another way to contact her, he should contact her first to
verify her new email. He should never open anything from an unverified email
address due to the potential of being infected. When you open anything from an
unknown email address you open yourself up to a whole bunch of different types of
malware that can infect your computer. Richard if he is not able to get into contact
with Kate should scan the attachment or check the link with an antiviral software
after updating the definitions of it. Google searching the link sometimes comes up
with potential risks of the link that is sent. Doing this ensures at least a little bit of
security when opening a link from an unknown sender. Also, opening the link on
another device can work better such as a mobile device due to the operating system
being different then the attended source. Devices operating systems like phones while
can be comprised have a lot of fail safes in order to prevent intrusion on the devices.
In order to verify that the email is from Kate, Richard should check the authenticity
of the mail first. He can do this by hovering over the name of the sender, it will
show the information of the user which can be used to find out if the email sent is
really from the said display name. It is extremely common for an attacker to spoof
display names to make it look like it coming from a legitimate person but once you
hover over you will find that it is actually coming from a completely different person.
If Richard still convinced of whether or not it is actually Kate or someone else, he
should then compare the message from the new email address with some of the older
ones from Kate’s older email address. Richard should also be sure to give Kate a call.
That is one of if not the easiest way of finding out whether or not the email came
from her. It also saves Richard a lot of time because he will be going directly to the
source. The first thing Richard should do to validate the authenticity of the email
from Kate is to check the domain. There are few variances generally for the typical
personal email address. Because of that, anything from an unknown and uncommon
domain should be approached skeptically. Secondly, Richard should check the Subject
line or email content from a quick view or over view feature most email accounts
contain to check for personal identifying information. This means anything that can
confirm beyond reasonable doubt that Kate was the sender of the email. Whether it
was context of the picture, a back story from the time frame, or some other
information only the both of you would know, this human touch allows you to weed
out any potentially generic scammer or bot messaging. Lastly, Richard should run the
email attachments through an anti virus program before opening. Most malware in the
form of email attachments aren't sneaky or divisive. They simply need to be opened
for a quick second to leak out onto the device and start duplicating it's code.
Attachment previews are a great tool to use for this as well. If and when all three
steps check out and are passed, Richard is clear to open the attachment. If any red
flags or points of skepticism arise, he should report the email as spam and reach out
to Kate to let her know her name and likeness is being used by scammers. The first
thing Richard should do is check with Kate to see if this was an actual change that
Kate made. If she didn't actually make this change, then problem solved. I would also
inspect the name of the new email address and see if looks suspicious to you. I think
checking the content of the email to check to see if the message sounds like how
Kate would communicate. Sometimes you might be able to tell based on what you
know of the other person sending the email.I would highly recommend checking the
attachment type before opening. If the email states its a picture but the file is an .exe
file type, I would be immediately suspicious and would not open the file. Most
pictures that attached to an email are in jpg format. I think scamming people with
Emails is the oldest trick hackers use and sadly people still fall for it, in my line of
work I come across a number of costumers that do not know how to filter Emails or
recognize what's potentially harmful or not, one of the ways to determine if the email
is genuine or not is by checking the email address by expanding the top pane of your
email and looking at the address if its fake it might contain misspelled words, mix of
upper and lower case letters, and rando numbers.Attachments are the most common
ways to spread viruses and other malware simply just by clicking on them and the
easiest wat to find out if the attachment is safe or not is by checking the extension
which are the three letters after the period at the end of the file name some of those
extensions are considered safe by Microsoft such as (jpg, gif, jpeg, tif, tiff, mpg,
mpeg, mp3, and wav) anything other than those you should be carful when you
receive them unless you are using work email and most of those attachment would
have word documents or pdfs and could have the extensions of TXT or DOC and in
that case you should only open if you know the sender and expecting the email. The
first logical thing to do to check on the authenticity of the new email ID is to verify
the new email with Kate first. Also, Richard should check the authenticity of the
email by hovering over the email to see if the email looks legitimate. To be fair, I
also look at the senders email to see if there is something suspicious about the email
address. Some people do not know how to recognize a fake email, such as the email
address will have random numbers or a mix of lower and uppercase letter and/or
misspelled words. Richard should make sure that the attachment is not malicious by
examining the file name, usually a picture attachment ends in .jpg or perhaps a video
might end in .avi. Usually if a file name ends in .exe, be on the lookout. This is not
cool, because if this file extension is downloaded it can execute an installation of
malware. "This is usually found in email attachments, also some of these malwares
skip the antivirus detection".The first step Richard should take is to examine the
domain. Don't just check the name of the person sending you the email. Check their
address and make sure there are no alterations like additional numbers or letters in the
email address.
I've experienced these types of emails throughout my career in the Army and at my
current job. From my understanding it might be a phishing email. Phishing emails
allows hackers to con you into providing or stealing your information whether you
reply to the suspicious email or by clicking on what the email has attached. Phishing
is one of the easiest forms of cyberattack for criminals to carry out, and one of the
easiest to fall for. It's also one that can provide everything hackers need to ransack
their targets work or personal accounts. My advice to Richard is to find another way
to contact Kate either by via phone or a social media app to confirm the email was
sent by her personally and do not click on the attachment until you have her
confirmation. The email header information can provide details of an email message.
However in the case of validating legitimacy of an email it’s always best to call the
individual that sent it. Some virus protection software offer add-ons for the mail client
in the effort of scanning messages. This would provide some sense of knowing
whether the attachment is malicious. However in a case where this feature is not
available, sandboxing the attachment then scanning it with the antivirus solution would
identify if the content is malicious or not. In detonation of a malicious attachment you
also get to find out what it does so that you’ll be able to provide information to
others in the effort to protect themselves. You just have to take the precaution of
ensuring that the computer that will be used for detonation is totally isolated from the
network. Emails is an effective way to communicate with people we haven’t seen in a
while or even met before. I think there is a small or maybe rare chance that the
email sent to Richard maybe a legitimate one. From what I have researched so far,
the malicious emails create harm if you follow the links or open the attachments that
come with them. Some red flags to malicious emails that attack when opened are
those without senders or subjects on them. Since Richard received one from an
unknown friend, the first step should be to hover over the name to verify the email
address first. The lettering used can mislead in the email address instead of using the
.com the email could read as .co. Hoovering over the email attachment just like the
email address will tell Richard where the attachment is going to send him. It may still
feel like a scam even when the email address matches the name used, so the next
option is to do an email domain search. The domain search will verify if it’s a
working email address and who owns it and the date they set it up. In the end, he
can ask friends and relatives if he had a friend Kate when he was younger.
Sometimes Facebook, Instagram, or other social communication methods will be able
to serve as a search engine to find the person, and only then he could feel safer to
reach out without opening the attachment. Since Richard received an email that is
suspicious claiming to be from his childhood friend, he needs to avoid opening it if
he has not yet. Since the information he has gather about the email has been from the
subject line and can see it has an attachment, he has not put his computer at risk yet.
The best plan of action currently is to contact his friend Kate to validate it did come
from her, whether it is through a call, text, or even emailing her through a known
good email. Attempting to communicate to her directly from the new email can create
a potential risk, if it is a potential hacker attack the hacker may have information to
make it seem legit. With so many social media platforms out today, people tend to
place their daily lives on it without consciously thinking of risk it may create. To
verify the attachment is not malicious Richard should scan it with antivirus software
such as AVG or McAfee. Once the attachment is scanned it will give results showing
if it has any malicious attachment along with it. To help prevent possibly having any
future attacks he should consider installing an Antispam software that will filter
incoming emails and flag them if it detects malicious activity in the email. The first
thing Richard should do before opening any attachments is contact his friend Kate by
either text message or phone call asking her if she indeed sent that email about the
change and if she sent a picture along with it. Emailing Kate back would not be a
good idea in case the account had been compromised and the person in control of it
can then reply as Kate. I always tell people if they are not expecting an attachment or
if the email seems out of the ordinary they should always contact the person who sent
it asking them if it is legit. I think that is the most a normal user can look at. If
Richard is an advanced user, he could check the headers of the email to see where
the email originated. There should be some indication there where the email came
from.
In order to make sure the attachment does not have a virus Richard should have an
Antivirus application on his computer. It should be set to scan all attachments. He can
also run a manual scan on the attachment to find out if it is infected with anything.
He could also do a google search to see if there are any current viruses using the
name of that attachment and that type of email.Richard should be looking for the
following to see authenticity of email id as follows:
He should check the domain whether email came from any domain which is common
or heard about the domain. He should also be checking whether email has any link to
click and when he hover the mouse over the link it shows another address which may
or may not be relevant. Should also be checking for spelling mistakes for domain and
the links if provided. Any provocation words to open email immediately that definitely
be spam.
Check the subject line not relevant to subject. Suspicious or malicious email with
attachments or links in it is usually received from an unknown sender. The subject
line or the email body normally contains a “special one-time offer” or a "call to
action" to tempt you to open the attachment or click on the link. The email client
may detect the message as unsafe and post a warning message. Always check for
hidden links if you are prompted to unlock an exciting offer.
To verify whether email address is valid or not, following info is important to check
before opening an email.
FROM name/address
REPLY-TO name/address
RETURN-PATH address
SOURCE IP address or “X-ORIGIN” address
There are several ways to solve this issue and the number one method is a phishing
email scanner there a several different types of that software available and little
research can lead to a great software program. If Richard decides against this, he can
still verify Kates id by asking some follow up questions.
1. How did they meet?
2. Was there an embarrassing event at the school?
3. What was the teacher’s name?
4. What school was it they attended together?
This simple line a question should make it a little easier to verify Kate’s ID. There is
also email virus scanning software available as well. Bottom line opening an email
from an unverified source is always a risk these are only methods to lower the chance
of being tricked in to downloading malware. The Federal trade commission put
together a really great article involing situations like these for further assistance I have
included the website. Attachments are a tricky piece of work they can be corrupted
even after they are sent from the user to another LSU has a great article on what to
do and how to mitigate that as well. I will also include that web article as well.
When looking at an email there can be some very distinct signs and some very subtle
signs that it is fake or not. When looking at the email you want to first look at the
sender address and make sure that it matches up with a legitimate domain that is
authentic and trusted. If the email looks like it is from an unknown domain it may
not be safe to open. You also want to look at it and make sure that all of the
spelling is correct and it is addressed to the right person. Many spam and malicious
companies or people will bank on the fact that you don't look very closely at the
email or the sender address in hopes of you clicking on the link or attached media. In
the past it was unsafe to open an email that may be potentially harmful because of
embedded malicious scripts. Now days, most email clients don't allow embedded
scripts in an email for security reasons so most of the malicious stuff would have to
be opened through a link. In this case it is most likely safe to open the email and
check the sender address. If you look at the sender address and it is not a
recognizable address then it should be marked as unsafe and be unopened. If the
email can not be identified as safe or unsafe it is better to not open it and send it to
someone who is better at knowing what to look for. It is better to not open it and it
be safe then to open it and it not be safe. If you are ever unsure don't open it.
Richard and everyone else should be very cautious when it comes to opening an
email attachment of any kind. Richard should look at the email address closely, as
well as the proper spelling and grammar in the header (subject) as well as the body
of the email. Richard has to make some judgement calls too. Why is this person
reaching out to him all of a sudden? Why does this person have his work email
address? What do the email security policies and procedures state? Richard does not
seem to know a person named Kate.
The "photograph" attachment could contain a malware that will be loaded on Richard's
device and potentially sent to the network to infect more. Richard should stop what he
is doing and run a scan on his computer to hopefully block the email. The email
could have been sent intentionally from the security department of the organization
Richards at to trick Richard into not being aware of phishing scams.In the
organization I work, we have routine "phishes" and we do have a button in pour
email system to report the message as Junk, Phishing or other. My routine is to
simply get rid of those messages by reporting them. If I am wrong about the email,
security will send it back to me, and if I am right, I may have saved myself and the
company a long painful process of cleaning up the mess caused by my opening the
attachment. When it comes to sending or receiving any type of email it can be tricky.
Only because they family, friends, employees send may not seem like a risk but it
can be very risky. When it comes to this one of the major thing I would be looking
at is if the document is secure or unsecured. This is a big watch out any time
someone is sending some type of document weather it would be photos making sure
that everything is secure. The second point I would say is if they can send it using a
share drive such like google photo instead of it being email this will cut down the
any possible risk of information being stolen. Also have some type of spyware so
before the email is open it will detect any virus or worms. It is very important that
the email is able to be sent secure . Another option is to simply have it go to another
email that is not a work related email such as a personal email and then open it from
there person computer so that way the ID is not anywhere on the computer its or
mobile device.