(Topic ID: 198485)

Attention! Virus e-mails being sent from Stern Pinball spoofed e-mails!

By capguntrooper

6 years ago


Topic Heartbeat

Topic Stats

  • 102 posts
  • 58 Pinsiders participating
  • Latest reply 4 years ago by fliperz
  • Topic is favorited by 2 Pinsiders

You

Linked Games

Topic Gallery

View topic image gallery

Screen Shot 2018-11-07 at 11.03.52 (resized).png
probably dangerous (resized).jpg
0195046D-413C-4181-B7DF-9D5D5FE9E3C0 (resized).jpeg
~.pdf (PDF preview)
Screenshot_2017-10-10-12-39-38 (resized).png
38294750-B8EC-4BB9-BDDE-227AEAAA2AC2 (resized).png
well-why-dont-you-cry-about-it (resized).jpeg
Screen Shot 2017-10-03 at 16.40.36 (resized).png
Screen Shot 2017-09-26 at 18.12.46 (resized).png
Screenshot_20170926-113801.jpg
zzzzzzvirus (resized).jpg
Screen Shot 2017-09-25 at 2.57.11 PM (resized).png
vt2 (resized).png
vt (resized).png
Screen Shot 2017-09-20 at 11.09.22 (resized).png
Screen Shot 2017-09-20 at 11.08.57 (resized).png
There are 102 posts in this topic. You are on page 1 of 3.
24
#1 6 years ago

!!!!!ATTENTION PINSIDE MEMBERS!!!!!

DO NOT, for any reason open invoice emails sent to your email from Stern Pinball and PLEASE do not forward them to your distributors. Delete without opening!

Stern was recently hacked and trojan/worm links with possible virus properties were emailed to customers of Stern Pinball. I just got off the phone with Patrick Powers who confirmed this and its effect on the international buyers as well.

I know some of you might think I am Stern bashing or throwing Pat under the bus, I assure you I am not, Pat is a great guy and I have always had positive experiences with him. I will however not sit on this and let some of you have your computers infected and identities compromised. So I would suggest anyone receiving this email to do a security scan of your computers to be safe and notify your distributors not to open invoice emails.

I have submitted this email to one of my cyber security officers in my command to dissect and analyze the potential threat it may have on computers/networks/servers and so on. If I am permitted to pass off details I will. Please pass this information on in other threads to warn pinside of security threats to their computers and or identities.

More to follow.

Screen Shot 2017-09-20 at 11.08.57 (resized).pngScreen Shot 2017-09-20 at 11.08.57 (resized).png
Screen Shot 2017-09-20 at 11.09.22 (resized).pngScreen Shot 2017-09-20 at 11.09.22 (resized).png

Edit: Thread title edited to better reflect what's going on.

-5
#2 6 years ago

Bit of a strange title I think. It could well be you that is hacked and the malware is using your addressbook to send out false messages.

Also check the mail address of the sender (not what is shown above) to see what the real address is where the mail comes from. It could be just spoofing and also then Stern is not hacked at all.

Not bashing on you and thank you for the info, but just change the title untill its clear what is going on.

#3 6 years ago
Quoted from ronaldvg:

Bit of a strange title I think. It could well be you that is hacked and the malware is using your addressbook to send out false messages.
Also check the mail address of the sender (not what is shown above) to see what the real address is where the mail comes from. It could be just spoofing and also then Stern is not hacked at all.
Not bashing on you and thank you for the info, but just change the title untill its clear what is going on.

The title is perfectly clear, and AGAIN was confirmed by Patrick Powers as I received a phone call from him confirming this.

39
#5 6 years ago

I hear those emails can suck 6k - 9k out of your bank account and send you a mostly working pinball machine!

10
#6 6 years ago
Quoted from ronaldvg:

Bit of a strange title I think.

how so??

and even if he's incorrect, what's the harm in giving folks a head's up? more of a strange response, if you ask me.

#7 6 years ago

Man if it was titled "We didn't forget you - Stern code update for your game"

I think all of us would be taken down within the day. I'd probably open it 10 times hoping for long lost code updates that I never got.

#8 6 years ago

Wow the Stern fanboys are out with the first post spin. To some they can truly do no wrong.

#9 6 years ago

Deploy Stern Army!

#10 6 years ago

That sucks. Glad Stern is on it.

LTG : )

#11 6 years ago

I had it too..

But not from Patrick powers but from another person with a weird name

#12 6 years ago
Quoted from Darscot:

Wow the Stern fanboys are out with the first post spin. To some they can truly do no wrong.

Actually, I am in the "will not buy Stern again ever and sold all my Sterns because I get sick of them" camp, but I know how confusing these things can be with hacking and virusses and stuff.

@capguntrooper: thanks for your answer back.

-2
#13 6 years ago

More accurate title would be "If you use Windows, don't open any emails from Stern!"

#14 6 years ago
Quoted from ronaldvg:

Actually, I am in the "will not buy Stern again ever and sold all my Sterns because I get sick of them" camp, but I know how confusing these things can be with hacking and virusses and stuff.
capguntrooper: thanks for your answer back.

Fair enough, with text it's easy to imply intent. I can accept I made assumptions.

#15 6 years ago

Where's the (malware) code?

#16 6 years ago
Quoted from s1500:

Where's the (malware) code?

I would assume the "danheretic" link included in the email leads to an infected website, since it's not a link to the Stern website.

#17 6 years ago

Stern has never sent me any invoice emails so why the F would someone open one if they did? That's not normal people!! Come on use your heads! Think and read before you click! Sheeesh!!!!!!!

#18 6 years ago

Looks like a (likely-infected) Word document.

vt (resized).pngvt (resized).png
vt2 (resized).pngvt2 (resized).png

#19 6 years ago

just received this

Screen Shot 2017-09-25 at 2.57.11 PM (resized).pngScreen Shot 2017-09-25 at 2.57.11 PM (resized).png

#20 6 years ago

yeah, typical 'scraping the address book' infection somewhere. So now the spammers will be sending all kinds of emails with the from lines forged to all their contacts.

#21 6 years ago
Quoted from frolic:

just received this

JT is hiding out in England with some bird named Melissa?

#22 6 years ago
Quoted from capguntrooper:

The title is perfectly clear, and AGAIN was confirmed by Patrick Powers as I received a phone call from him confirming this.

Visit https://haveibeenpwned.com/ and put in Patrick's address. Looks like this is from the Onliner Spambot breach.
https://www.troyhunt.com/inside-the-massive-711-million-record-onliner-spambot-dump

#23 6 years ago

I've gotten this one from other areas of business as well

#24 6 years ago
Quoted from Sinestro:

More accurate title would be "If you use Windows, don't open any emails from Stern!"

If it really is an infected Word file, any machine with Word installed may be vulnerable. Doesn't have to be Windows.

#25 6 years ago

They must have been hacked. I got an email saying that they are dropping the prices by $500 on the next game.

#26 6 years ago

They must have been hacked. I got an email from them...

#27 6 years ago

I like the one where I was informed I have been selected to be a code beta tester for Stern and after I finished testing it on the new free machine they would send me. Then I would receive my employee check from my long lost 3rd cousin twice removed from Sterns Nigerian factory and I was going to get paid 5,000,000 for my services and testing, all they need now is my account information to transfer the funds to my account.

#28 6 years ago

This is getting serious, I just got one too!

Do NOT open that link!!!!!!!!!!!!!!

zzzzzzvirus (resized).jpgzzzzzzvirus (resized).jpg

#29 6 years ago
Quoted from vid1900:

This is getting serious, I just got one too!

wow, and it's even an invoice. So does that mean he's charging for said slumber party?

#30 6 years ago
Quoted from CaptainNeo:

wow, and it's even an invoice. So does that mean he's charging for said slumber party?

I hate to see the price of admission..........

#31 6 years ago

*cringe* Man you guys... lol....

#32 6 years ago
Quoted from vid1900:

I hate to see the price of admission..........

Got his pricing info from never-neverland I bet.

#33 6 years ago

And pinside keeps on pinsidin'...

#34 6 years ago

For a moment then I saw the heading "Stern Pinball Hacked" and thought someone had updated the code for Ghostbusters to fix all the bugs and complete all the Game modes... Alas Not

#35 6 years ago

Is it just stern or linked to sullivan group? I bought sterns hd glass through a stern site but invoice is from sullivangroupusa.com

I received an email afterwards saying they need my card info that it was declined. Have not done so yet. Don't think they would have sent it without being paid first.. shows in my account as pending.

Screenshot_20170926-113801.jpgScreenshot_20170926-113801.jpg

#36 6 years ago
Quoted from Knine:

Is it just stern or linked to sullivan group? I bought sterns hd glass through a stern site but invoice is from sullivangroupusa.com
I received an email afterwards saying they need my card info that it was declined. Have not done so yet. Don't think they would have sent it without being paid first.. shows in my account as pending.

That organization is not affiliated with Stern as far as I'm aware.

Not listing the actual item(s) you ordered or the order number in the email is a big clue.

I would delete it.

#37 6 years ago
Quoted from ForceFlow:

That organization is not affiliated with Stern as far as I'm aware.
Not listing the actual item(s) you ordered or the order number in the email is a big clue.
I would delete it.

I plan to, i should add that i called them(contact for sullivan) directly when i placed the order because i thought it was funny, they showed the order as processed.. then i called stern who confirmed my order also and said it was shipped.

Which is why I'm not getting a good feeling about this. Highly doubt they would have sent it if they didn't receive payment. The contact info i showed you is the same info from my original order.

Scammers would likely provide such and hope you just send your card info on a silver platter by email.. whoever would is window licker quality. Ha.

Thanks for the info.

#38 6 years ago

Never send your CC number in e-mail. Just call them up and provide over the phone.

***Edit - By call them up, I mean call up whom ever you are buying from to provide payment information. Never send in an e-mail even if the company is a known company that you've dealt with. I recently did this and learned the hard way. Company I've done business with dozens of times and I sent my CC for a parts order (for a car). 2 days later the bogus charges started to happen. I was suspicion on how that happened until the owner called me and apologized because they were hacked. Handful of customers CC #'s were taken and they tracked it back to them.

#39 6 years ago
Quoted from 85vett:

Never send your CC number in e-mail. Just call them up and provide over the phone.

No, they aren't legit.

#40 6 years ago
Quoted from ForceFlow:

No, they aren't legit.

Yeah, I kind of left that important part out of my post Editing it now...

#41 6 years ago
Quoted from apLundell:

If it really is an infected Word file, any machine with Word installed may be vulnerable. Doesn't have to be Windows.

That's not entirely true. This is a likely variant of a word macro virus. They get you to hit a link with a word document. The document comes up, and then runs the macro (if macros are not enabled, it will try to fool you into enabling it). Once the macro is running, it then jumps externally to download an executable file off a remote server (and then execute it). There are multiple variants of this exploit, but a common one was installing ransom ware. Long story short, due to the way it works; it would only infect a windows machine. MAC users would not be impacted (mac would not let word start the executable, nor would the executable run on mac).

For what it's worth. I have not clicked the link to confirm the malware variant, so I'm going by others in this post that it linked to a word file.

#42 6 years ago

AAAAAAAAND ANOTHER ONE! This time from Chas.

Screen Shot 2017-09-26 at 18.12.46 (resized).pngScreen Shot 2017-09-26 at 18.12.46 (resized).png

#43 6 years ago

Don't know if it's related, but someone left a message on my company line a couple days ago saying they were calling from Stern and we owe them money on an unpaid invoice... Considering we have never ordered directly from Stern... uh ok, let me get to work paying that!

#44 6 years ago

Just got one of these today.

#45 6 years ago

I'm taking this cyber stuff seriously. In fact anyone sending me an invoice I will not pay it. Sorry people cant open cant pay. Perhaps the US Mail will start making money again.

#46 6 years ago

OH MY! It appears Patrick Powers is comfortable enough with me to call me Dear. How sweeeeeeeeeet.

Screen Shot 2017-10-03 at 16.40.36 (resized).pngScreen Shot 2017-10-03 at 16.40.36 (resized).png

#47 6 years ago

I got one of these emails today as well, supposedly from Chas, telling me he paid the outstanding balance on a machine. Weird.

-1
#48 6 years ago
Quoted from capguntrooper:

OH MY! It appears Patrick Powers is comfortable enough with me to call me Dear. How sweeeeeeeeeet.

Are you even looking at the headers to see if they are coming from Stern mail servers?

We all know once the names/contacts are harvested, spoofing will go on for ages even after the original target is cleaned up.

#49 6 years ago

Feeling like the odd man out. No emails, no calls, no chocolates. Come on Stern, love ME.

My company requires employees take a simple internet/ email security training webinar and to pass a test showing your head isn't up your azz. They periodically send spoof emails, and if you try to reply or click on the link, it logs your name and flags you to take the training again.

#50 6 years ago
Quoted from flynnibus:

Are you even looking at the headers to see if they are coming from Stern mail servers?
We all know once the names/contacts are harvested, spoofing will go on for ages even after the original target is cleaned up.

Agreed. These are all very likely spoofed and will continue regardless of what Stern does to secure their systems. If someone can post the full mail header we can confirm...

-Jay

Promoted items from Pinside Marketplace and Pinside Shops!
$ 80.00
Cabinet - Shooter Rods
Reflex Mods
 
$ 26.95
From: $ 99.99
Cabinet - Other
Lighted Pinball Mods
 
7,500
Machine - For Sale
Advance, NC
$ 6,999.00
Pinball Machine
Maine Home Recreation
 
$ 19.95
Playfield - Toys/Add-ons
ULEKstore
 
From: $ 30.00
Cabinet - Toppers
+CY Universal
 
$ 8.95
$ 30.00
Playfield - Other
YouBentMyWookie
 
$ 64.00
Lighting - Under Cabinet
Lermods
 
$ 1.29
Playfield - Toys/Add-ons
Daddio's 3D Printed Mods
 
$ 24.95
Lighting - Other
The MOD Couple
 
$ 120.00
Cabinet - Shooter Rods
Super Skill Shot Shop
 
$ 28.00
Playfield - Toys/Add-ons
ULEKstore
 
$ 69.99
Playfield - Toys/Add-ons
Lighted Pinball Mods
 
$ 99.99
Lighting - Other
Lighted Pinball Mods
 
32,495
Machine - For Sale
Ontario, CA
$ 69.99
Playfield - Toys/Add-ons
Lighted Pinball Mods
 
$ 169.99
Cabinet - Shooter Rods
Maine Home Recreation
 
7,300
Machine - For Sale
Waxhaw, NC
10,600
$ 40.00
Playfield - Toys/Add-ons
WilliPinball Mods
 
$ 110.00
Cabinet - Shooter Rods
Super Skill Shot Shop
 
$ 160.00
Cabinet - Toppers
Sparky Pinball
 
$ 35.50
Cabinet - Armor And Blades
The MOD Couple
 
Great pinball charity
Pinball Edu
There are 102 posts in this topic. You are on page 1 of 3.

Reply

Wanna join the discussion? Please sign in to reply to this topic.

Hey there! Welcome to Pinside!

Donate to Pinside

Great to see you're enjoying Pinside! Did you know Pinside is able to run without any 3rd-party banners or ads, thanks to the support from our visitors? Please consider a donation to Pinside and get anext to your username to show for it! Or better yet, subscribe to Pinside+!


This page was printed from https://pinside.com/pinball/forum/topic/stern-hacked-do-not-open-invoice-emails-from-stern?hl=aplundell and we tried optimising it for printing. Some page elements may have been deliberately hidden.

Scan the QR code on the left to jump to the URL this document was printed from.