Skip to content
DnsLister Forum

Where domain hunters compare notes

Smart Phishing Mail or actual help?

I got an email by somebody named Kirurusec.com / Salvatore Ansani.
Original mail at the end.

Trying to lay this out clearly because three separate things may or may not be connected.

The setup

I run a small print on demand business. I work with an assistant in the philippines who connects to an old windows 10 machine of mine over RDP. My own daily driver is windows 11.

2 different email addresses are involved

Email A: got the alert/mail from Salvatore. Used for lots of accounts but i almost never send mail from it. Not listed on haveibeenpwned.

Email B: leaked in a big 2020 breach, confirmed on haveibeenpwned.

Timeline

2020 – Email B gets leaked. Nothing i could have prevented.

Since then – once a year someone sends bad english emails to my old contacts. Stranger's address, but my name as the display name.

A few months ago – 2FA codes by SMS for tiktok and amazon on my phone (Email B & C not A!), daily for about a week, then it stopped. Nothing happened, no money gone.

Last week – the KiruruSec email lands on Email A.

The email itself

Guy calls himself an independent security researcher, KiruruSec / Salvatore Ansani. Says Email A shows up in an infostealer log, so malware on a device i use, not a normal website breach. He lists 10 domains where i supposedly have accounts.

5 domains matches: facebook, teepublic, freepik and a philippine job platform (I dont use). Oddly specific and all genuinely mine. Plus a german private LAN router address.

5 doesn't: a game launcher i have never used, and netflix, i was never signed up there with that address.

What i already did

Full scan on the windows 11 machine, clean. Haven't touched the old windows 10 box yet, and that's honestly where i'd expect something if anything.

What bugs me

He wants no money and sends no links, but i have to reply to get the full list. And where did he even get this mail address, it isn't on haveibeenpwned.

Questions

How should I react?

I know some of my data are out there and people try to log in. But I use a really save password manager, use super long passwords and every account a different one. I didnt had any problems yet except the display spoofing mails once a year.

Is this just a smarter flavour of phishing, or do people really do this?

How reliable are these domain lists from stealer logs, can entries from other machines get mixed in?

Where did he got this mail address?

Original email below.

https://preview.redd.it/r5lzcfno03oh1.png?width=617&format=png&auto=webp&s=4eba56d72ec7504a41cc59bbda4d20cf24a7121b

https://preview.redd.it/hq5v1snp03oh1.png?width=620&format=png&auto=webp&s=f540a3e5bf65603ca5ec27e64fead51e40af9805

Source: r/cybersecurity_help · by /u/WhatAmIdoingHere9839

Leave a Reply

Your email address will not be published. Required fields are marked *