{"id":12754,"date":"2018-02-05T10:53:01","date_gmt":"2018-02-05T08:53:01","guid":{"rendered":"http:\/\/blogs.sun.ac.za\/it\/?p=12754"},"modified":"2018-02-27T10:15:11","modified_gmt":"2018-02-27T08:15:11","slug":"virus-warning","status":"publish","type":"post","link":"https:\/\/blogs.sun.ac.za\/it\/2018\/02\/virus-warning\/","title":{"rendered":"[:en]Virus warning[:]"},"content":{"rendered":"<p>[:en]<\/p>\n<p>If you receive an email with the subject: <strong>\u201cURGENT &#8211; CCMA Final Reminder: Case GAJK0238819-18 (GAJK) is scheduled for &#8216;Arbitration&#8217;\u2026<\/strong>\u201d allegedly sent by the CCMA, and with an attachment with a <strong>.DOC.gz<\/strong> extension, <strong><u>DO NOT<\/u><\/strong> try to open it. The attachment is a rather nasty Trojan-variant of a Crypto virus.<\/p>\n<p>This virus opens the &#8220;back door&#8221; of your computer to hackers once it infects your PC. The trojan is programmed to run at every start-up, giving the hackers, who originated the program, access to your hard drive. In addition, this trojan can re-create itself, making it hard to remove it completely.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-large wp-image-12755\" src=\"http:\/\/blogs.sun.ac.za\/it\/files\/2018\/02\/ccma-500x454.jpg\" alt=\"\" width=\"500\" height=\"454\" srcset=\"https:\/\/blogs.sun.ac.za\/it\/files\/2018\/02\/ccma-500x454.jpg 500w, https:\/\/blogs.sun.ac.za\/it\/files\/2018\/02\/ccma-300x272.jpg 300w, https:\/\/blogs.sun.ac.za\/it\/files\/2018\/02\/ccma.jpg 507w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>If you received this email or any similar ones, please it to the Information Technology Security Team using the following method:<\/p>\n<p>Send the spam\/phishing mail to\u00a0<a href=\"mailto:help@sun.ac.za\">help@sun.ac.za<\/a> and\u00a0<a href=\"mailto:sysadm@sun.ac.za\">sysadm@sun.ac.za<\/a><\/p>\n<p>Attach the phishing or suspicious mail on to the message if possible. There is a good tutorial on how to do this at the following link (Which is safe) : <a href=\"http:\/\/stbsp01.stb.sun.ac.za\/innov\/it\/it-help\/Wiki%20Pages\/Spam%20sysadmin%20Eng.aspx\">http:\/\/stbsp01.stb.sun.ac.za\/innov\/it\/it-help\/Wiki%20Pages\/Spam%20sysadmin%20Eng.aspx<\/a><\/p>\n<ol>\n<li>Start up a new mail addressed to <a href=\"mailto:sysadm@sun.ac.za\">sysadm@sun.ac.za<\/a> (CC: <a href=\"mailto:help@sun.ac.za\">help@sun.ac.za<\/a>)<\/li>\n<li>Use the Title \u201cSPAM\u201d (without quotes) in the Subject.<\/li>\n<li>With this New Mail window open, drag the suspicious spam\/phishing mail from your Inbox into the New Mail Window. It will attach the mail as an enclosure and a small icon with a light yellow envelope will appear in the attachments section of the New Mail.<\/li>\n<li>Send the mail.<\/li>\n<\/ol>\n<p>IF YOU HAVE FALLEN FOR THE SCAM:<\/p>\n<p>If you did click on the link of this phishing spam and unwittingly give the scammers your username, e-mail address and password you should immediately go to <a href=\"http:\/\/www.sun.ac.za\/useradm\">http:\/\/www.sun.ac.za\/useradm<\/a> and change the passwords on ALL your university accounts (making sure the new password is completely different, and is a strong password that will not be easily guessed.) as well as changing the passwords on your social media and private e-mail accounts (especially if you use the same passwords on these accounts.)<\/p>\n<p>IT have set up a website page with useful information on how to report and combat phishing and spam. The address is:\u00a0<a href=\"http:\/\/blogs.sun.ac.za\/it\/en\/2017\/11\/reporting-spam-malware-and-phishing\/\">http:\/\/blogs.sun.ac.za\/it\/en\/2017\/11\/reporting-spam-malware-and-phishing\/<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: right;\">[Article by David Wiles]<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>[:]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[:en] If you receive an email with the subject: \u201cURGENT &#8211; CCMA Final Reminder: Case GAJK0238819-18 (GAJK) is scheduled for &#8216;Arbitration&#8217;\u2026\u201d allegedly sent by the CCMA, and with an attachment with a .DOC.gz extension, DO NOT try to open it. The attachment is a rather nasty Trojan-variant of a Crypto virus. This virus opens the [&hellip;]<\/p>\n","protected":false},"author":259,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29187],"tags":[54506,29175],"class_list":["post-12754","post","type-post","status-publish","format-standard","hentry","category-security-2","tag-krypto","tag-trojan"],"publishpress_future_action":{"enabled":false,"date":"2026-05-08 03:43:09","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/users\/259"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/comments?post=12754"}],"version-history":[{"count":3,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12754\/revisions"}],"predecessor-version":[{"id":12758,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/12754\/revisions\/12758"}],"wp:attachment":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/media?parent=12754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/categories?post=12754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/tags?post=12754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}