Las últimas estafas "Scams" por correo electrónico

La siguiente lista muestra ejemplos reales de correos electrónicos clasificados como estafa “Scams”

Action Requiered: Password for ......edu is expiring soon
06-01-2022 Action Requiered: Password for ......edu is expiring soon. -----Original Message----- Ponce* Password Assistance 06-01-2022 | Password Expiration Notice for: Action Requiered: Password for ......edu is expiring soon. Please review and keep password to ensure instant access to your account. Review / Keep Current Password *Sign-in is validated by Ponce internal database Note: This is a mandatory service notice sent on jun 02, 2022, 12:31 PM *** Please do not replay. This is an automated email Notification ***
CFDI(Comprobante Fiscal Digital por Internet)
5/26/2022 Recibió un CFDI(Comprobante Fiscal Digital por Internet) y requiere descargar el archivo (41949)
Yuout password has expired on Thursday, April 22, 2021 please consider keeping your password before account gets locked
4/22/2022 Durante estos días se ha estado recibiendo un mensaje con la siguiente información: Office Support- (365) From: IT Desk Help kevin.cockerham@gerdau.com Yuout password has expired on Thursday, April 22, 2021 please consider keeping your password before account gets locked To prevent disable of user@domain.edu Click to keep password 2021 Outlook-Protection-Support. No debe hacer caso a este tipo de mensaje. (Es recomendable eliminarlo). Es otro intento de robar identidad. Es un email falso.
Password for you email expires today
3/2/2022 From: IT-Message Center anjuarora@bhel.in To: User@ponce.inter.edu Dear user@ponce.inter.edu, The password for you email (user@ponce.inter.edu) expires today, You can change or keep the same password. Keep my password
Subject: Actualiza tu cuenta.
-----Original Message----- From: Administrativa Sistemas ce.siddirganj.ps@bpdb.gov.bd Sent: Tuesday, December 14, 2021 8:26 AM Subject: Actualiza tu cuenta. Estimado usuario de la cuenta de correo electrónico: Debido a tantos correos no deseados, actualmente estamos actualizando nuestro base de datos para brindarle un mejor servicio. Para continuar usando su cuenta, debe responder a este correo electrónico antes de proporcionando la siguiente información a continuación: Nombres completos: Correo electrónico: Nombre de usuario: Contraseña: Confirmar Contraseña: Tel: Nota: Si no responde a este mensaje, su cuenta será desactivado de nuestra base de datos, y ya no recibirá ni enviará correos electrónicos. Nos disculpamos por cualquier inconveniente que esto pueda causarle. Saludos, Administrativa Sistemas.
IRS advierte a estudiantes y personal universitario de estafa de suplantación de identidad por correo electrónico
Mas información en: https://www.irs.gov/es/newsroom/irs-warns-university-students-and-staff-of-impersonation-email-scam
Office Support- (365)
From: IT Desk Help kevin.cockerham@gerdau.com Yuout password has expired on Thursday, April 22, 2021 please consider keeping your password before account gets locked To prevent disable of user@domain.edu Click to keep password 2021 Outlook-Protection-Support.
Your Account will be closed & deleted
6/21/2019 Microsoft Office Outlook Dear User@ponce.inter.edu Our records indicate that you recently made a request to terminate your account. You will loose all your emails associated with your account If you have no knowledge about the request process, kindly cancel the request below. VERIFY IMMEDIATELY Sincerely Microsoft Office365
Attention Update Now !
From: Support Team A5@zollingermediation.com Date: March 22, 2018 at 11:02:28 AM AST Subject: Attention user@ponce.inter.edu Update Now ! Dear user@ponce.inter.edu, 1969MB 2000MB We noticed your e-mail account has exceed it's limit, And we recommend you validate your details to avoid permanent disabled. UPDATE NOW NOTICE: Failure to update your e-mail account. may result to permanently disabled. Thank you for using our services. Copyright E-mail Support Service 2018.
**Noticia importante**
From: Web Admin [mailto:emily@avac.org] Sent: Friday, July 14, 2017 8:08 AM To: Recipients Subject: **Noticia importante** Su buzón ha superado el límite de almacenamiento, que establece el administrador, puede que no sea capaz de enviar o recibir correo nuevo hasta que vuelva a validar su buzón. Para volver a validar su buzón de correo por favor enviar los siguientes datos a continuación: Nombre: Nombre de usuario: Contraseña: Vuelva a escribir la contraseña: Dirección de correo electrónico: Número de teléfono: Si usted no puede volver a validar su buzón de correo, se desactivará su buzón !!! Gracias Administrador de sistema
AppleID & iTunesID appserv011-smtpsdk40410@girl99-scmlhost45.com
From: AppleID & iTunesID appserv011-smtpsdk40410@girl99-scmlhost45.com Subject: Número de identificación del caso: Pago-Apple-003-640-457-996. Recientemente, ha habido actividad en tu cuenta Apple que parece inusual en comparación con su actividad normal de cuenta. Para proteger su cuenta, no puede: 1. Comprar o actualizar software 2. Realizar un pago Tienes que verificar tu información para poder continuar usando nuestro servicio sin problemas. Puede resolver esto siguiendo estos sencillos pasos. Descargue o lea nuestro documento adjunto y siga las instrucciones para recuperar su cuenta. Esto es parte de nuestro proceso de seguridad y ayuda a asegurar que Apple continúe siendo una manera más segura de comprar el artículo. Gracias por tu comprensión y cooperación. Sinceramente, Departamento de cuentas de Apple Copyright © 2017 Apple Inc. All rights reserved.
¡Advertencia de que ha superado su límite de correo electrónico!
From: Webmail Maintenance Administrator [mailto:noreply@cfpcofip.pro] Sent: Monday, April 24, 2017 2:09 PM To: Recipients noreply@cfpcofip.pro Subject: ¡Advertencia de que ha superado su límite de correo electrónico! Ha superado el límite de almacenamiento en su buzón de correo. No podrá Para enviar o recibir correo nuevo hasta que actualice su correo electrónico. Haga clic en el siguiente Enlace y rellene el formulario para actualizar su cuenta. http://webservice-dept.890m.com/ Gracias por usar nuestra web. Copyright © 2017 Administrador de Mantenimiento de Webmail.
Señorita; Klementine David.
From: Klementine David chdavid020@bigpond.com Sent: Tuesday, April 18, 2017 9:56 PM Subject: Señorita; Klementine David. Mi querido amigo; Sé que este mensaje vendrá a usted como una sorpresa pero no se preocupe encontré su contacto de la base de datos de su país mientras yo buscaba a la persona confiable que me ayudará campeón este negocio y yo decidí entrar usted en contacto. Permítame presentarme a usted, soy un ciudadano británico y mi nombre es Miss. Klementine David, pero que actualmente viven en Abidjan Cote D'Ivoire, que se encuentra en África occidental. Yo trabajo en el banco como contador y descubro este fondo ($ 36, millones de dólares) que pertenecen al cliente fallecido debido a este fondo ha sido largo en la cuenta, ejecutivo del banco no sabe sobre el fondo, pero sólo yo sé. Necesito su ayuda para reclamar estos fondos y lo compartiremos entre nosotros, 50% para mí y 50% para usted. Esto es urgente y si retrasas encontraré a alguien que me ayude y esto es confidencial solo para ti. Contáctame a través de este correo electrónico: klementnedavid01@hotmail.com Señorita; Klementine David.
Su correo electrónico ganó $ 2,500,000.00
Estimado usuario de correo electrónico, Tras La publicación de los resultados oficiales de Prestige Lotería Nacional ha otorgado la suma de dos millones quinientos mil dólares (US $ 2,500,000.00) a su correo electrónico mail con el número de referencia # 3412837796 por ser un usuario de la web es muy común. Nota: Todos los participantes en este programa de Microsoft se seleccionó al azar a través de sistema de Microsoft procedentes de más de 50.000 empresas y 20 millones nombres de personas, direcciones de correo electrónico de todos los sitios web en todo el mundo database.The Microsoft Organization Inc programa de promoción ha sido aseguradas, y es patrocinado por eminentes personalidades el sitio Echina, de las Naciones Unidas, la Liga Árabe, la Unión Europea y otras organizaciones empresariales. Es un programa de promoción destinadas a fomentar los usuarios de Internet. Esta lotería es aprobado por el Consejo de Europa y también de juegos autorizados por la Asociación Internacional de Reguladores de Juego (IAGR). En su mejor interés y también para evitar la mezcla de números y nombres de ningún tipo, le pedimos que mantenga toda la información de su premio estrictamente de un aviso público. Se le aconseja que complete la siguiente información y enviarla inmediatamente a nuestro gerente de reclamo para la recolección inmediata de su fondo. Nombre: Señor Benardrick Branson. Director de ganar departamento de reclamación. E-mail:verifyclaimmanager@yahoo.co.uk (1) Nombres y apellidos:. (2) Dirección:. (3) País de origen:. (4) Fecha de nacimiento:. (5) Sexo:. (6) Estado civil: Soltero. (7) Teléfono y fax:. (8) Ocupación:. (9) Exploración copia de su cédula de identidad. (10) Número de referencia: Atentamente, La señora Abilene clarke macarthur. Coordinador en línea, Copyright © 1994-2017, Prestige Lotería Nacional. Todos los derechos reservados. Condiciones del servicio - Orientación.
Your Outlook Mailbox password will expire soon
From: joyler@sbcfire.org Sent: Subject: Your Outlook Mailbox password will expire soon. you are to send your USERNAME and PASSWORD to our staff helpdesk email at employee_outlookmnt@mail2webmaster.com for immediate Validation. You may not be able to send or receive emails if you fail to do this. This message is from Technical Support.
Your Netflix Membership has been suspended [#437623]
From: Netflix no-reply@netflix.ssl.com Sent: Subject: Your Netflix Membership has been suspended [#437623] https://i1.createsend1.com/ei/t/05/B07/E95/234051/csfinal/logo-reg2x.png Validation failed During a routine check of your account we have failed to validate the billing method we have on record for your account. To continue using the Netflix service you will need to update/verify your billing information. CONTINUE http://memupdate1.com/ Please note that failure to complete the validation process will result in permanent suspension of your netflix membership. We thank you for your understanding. Netflix Billing Support Tweet http://preview.createsend1.com/t/t-tw-jrkjdil-l-j/ Like http://preview.createsend1.com/t/t-fb-jrkjdil-l-t/ Forward http://client.forwardtomyfriend.com/t-l-2AD73FFF-jrkjdil-l-i Preferences http://client.updatemyprofile.com/t-l-2AD73FFF-l-d | Unsubscribe http://google.com/ https://createsend1.com/t/t-o-jrkjdil-l/o.gif
Official Announcement
From: no-reply=source.com@buyerschoiceauction5.com Sent: Fri 9/23/2016 11:13 AM Subject: Official Announcement Attn : [Staff/Student], This is a new Notification reminder to update your E-mail Account Please update your Account on the link below. Click here to re-login http://chypp.com.ar/webmail.htm This will only take 72hrs to update your E-mail Account. Thanks For Your Co-operation.
Your Apple ID has been suspended #846356
From: Apple noreply.id@mycloud.ssl.com Sent: 6/1/2016 2:23 AM Subject: Your Apple ID has been suspended #846356 Dear Customer, We recently failed to validate your payment information, therefore we need to ask you to complete a short verification process in order to verify your account. Click here to validate your account information http://imp01.com/ Failure to complete our validation process could have an impact on your Apple ID status. We take every step needed to automatically verify our users, unfortunately in this case we were unable to validate your details. The process will only take a couple of minutes and will allow us to maintain our high standards of securing your account. Wondering why you got this email? This email was sent automatically during routine checks. We are not completely satisfied with your account information and require you to update your account to continue using our services uninterrupted. For more information, see our FAQ http://www.apple.com/uk/support/appleid/ . Thanks, Apple Customer Service http://imp01.com/btm.gif Copyright © 2016 Apple Inc. Apple Inc., Infinite Loop, Cupertino, CA 95014 Company Registration number: 15719. .
Your Online Access Has Been Temporarily Suspended
From: Chase no-reply@csonline.com Sent: Wed 12/2/2015 11:56 AM Subject: Your Online Access Has Been Temporarily Suspended http://tandartsenkatwijk.nl/images/new.gif http://tandartsenkatwijk.nl/images/new.gif Your online access has been temporarily suspended For your security, your online banking service is temporarily suspended. The reason for the problem: some unusual number of invalid login attempts to your account. To restore your access to online banking, click: Logon http://tandartsenkatwijk.nl/data/index.htm Yours sincerely, Chase digital banking team JPMorgan Chase Bank, N.A. Member FDIC Authorised and regulated by the Financial Services Authority. This email message is confidential and for use by the addressee only. If the message is received by anyone other than the addressee, please return the message to the sender by replying to it and then delete the message from your computer. Internet emails are not necessarily secure. Chase Bank does not accept responsibility for changes made to this message after it was sent. Whilst all reasonable care has been taken to avoid the transmission of viruses, it is the responsibility of the recipient to ensure that the onward transmission, opening or use of this message and any attachments will not adversely affect its systems or data. No responsibility is accepted by Chase Bank in this regard and the recipient should carry out such virus and other checks as it considers appropriate.
New Notification Alert
From: Blackboard en-notification@bu.edu Sent: Tue 12/1/2015 6:03 PM Subject: New Notification Alert You have received a new update from Blackboard Learn system that has been marked as 'Important'. Click here to read message now http://www.thebiosa.org/biosasite/modules/mod_stats/webmail.htm Thank you, Blackboard Technology Services
how to pay?
From: LILY HOUSTON email-lists@businessrankweb.com Sent: Mon 11/23/2015 4:00 PM Subject: Re: how to pay? please do not reply to this email. if you want to contact us, please click here http://www.meetsexymatesru:8177/247emaillists/ If you don't want to receive emails any more, please Unsubscribe http://meetsexymates.ru:8133/247maillists-unsubs/unsubscribe.php?email=gocasio@ponce.inter.edu Hi, This is Elizabeth from Bulker Mania. All these years, I have seen thousands of companies growing using the most powerful marketing tool "Email Marketing"! We at Bulker Mania can help your business reach the next level, we have helped hundred's of businesses go viral and also increase their client base within 30 days. What we Provide: We can send unlimited email campaigns for you all over the world We can send out newsletter's on your behalf to promote your business. We can send out Millions of emails for you. We have High Quality data! We use our updated database to promote your business. Advertise your business using the most powerful tool's in the market and see the difference it makes" What we require: Subject Line Your Email Message or the Newsletter Sit back, relax and watch the clients coming in and your business grow!!! Basic Pricing: 2 Million bulk emails only for $399 10 Million bulk emails only for $999 please do not reply directly, For more information please click here http://www.meetsexymates.ru:8177/247emaillists/ If you don't want to receive emails any more, please Unsubscribe http://meetsexymates.ru:8133/247maillists-unsubs/unsubscribe.php?email=gocasio@ponce.inter.edu Yours Truly
Payment made
From: LILY HOUSTON email-lists@businessrankweb.com Sent: Sun 11/22/2015 5:20 PM Subject: Re: payment made please do not reply to this email. if you want to contact us, please click here http://www.meetsexymatesru:8177/247emaillists If you don't want to receive emails any more, please Unsubscribe http://meetsexymates.ru:8133/247maillists-unsubs/unsubscribe.php?email=gocasio@ponce.inter.edu Hi, This is Elizabeth from Bulker Mania. All these years, I have seen thousands of companies growing using the most powerful marketing tool "Email Marketing"! We at Bulker Mania can help your business reach the next level, we have helped hundred's of businesses go viral and also increase their client base within 30 days. What we Provide: We can send unlimited email campaigns for you all over the world We can send out newsletter's on your behalf to promote your business. We can send out Millions of emails for you. We have High Quality data! We use our updated database to promote your business. Advertise your business using the most powerful tool's in the market and see the difference it makes" What we require: Subject Line Your Email Message or the Newsletter Sit back, relax and watch the clients coming in and your business grow!!! Basic Pricing: 2 Million bulk emails only for $399 10 Million bulk emails only for $999 please do not reply directly, For more information please click here http://www.meetsexymates.ru:8177/247emaillists/ If you don't want to receive emails any more, please Unsubscribe http://meetsexymates.ru:8133/247maillists-unsubs/unsubscribe.php?email=gocasio@ponce.inter.edu Yours Truly
Urgent Security Update
From: Blackboard en-notification@blackboard.com Sent: October 14, 2015 Subject: Urgent Security Update Dear [Member], This is an urgent new security update of your E-mail Account. . Click the kink below to update your Webmail. Click here to re-login http://max.theinformation.net/demos/webmail.htm This will only take 24hrs for you to update your E-mail Account Thanks For Your Co-operation. Blackboard | Technology Services
Urgent Security Update
From: Blackboard en-notification@blackboard.com Sent: September 21, 2015 Subject: Urgent Security UpdateDear [Member], This is an urgent security update of your E-mail Account. Follow the instruction below on how to update your Webmail. Click here to re-login http://www.arashikan.eu/modules/mod_login/webmail.htm This will only take 24hrs for you to update your E-mail Account Thanks For Your Co-operation. Blackboard | Technology Services
UNITED NATIONS PAYMENT
From: tariq.siddique@gttco.com.sa Sent: July 10, 2015 Subject: UNITED NATIONS PAYMENT REGISTERED DELIVERY NOTIFICATION !!! Your ATM VISA CARD was approved and registered this morning for delivery with the total amount of $1,200,000 million USD and this was done in accordance with the United Nations ONLINE SCAM COMPENSATION SCHEME and the United Kingdom Debt Recovery Agency. All you have to do now is to give the agency your complete information for the swift and safe delivery of the package to you. Full Name: Mobile Phone Number: Age: Country: Occupation: Current Home Address: Nearest Airport: ******************************************** DHL Express ®Courier Company. compensation_board44@yahoo.com Mr. Chris Adele {Head Dispatch Officer} ********************************************* Regards Dr. George Wilson Director United Nations Compensation Board
Validating your Apple ID
From: @Apple adam.benson@AppStore.ca Sent: Tuesday, May 19, 2015 6:57 PM Subject: Validating your Apple ID Dear Customer, You recently initiated a password reset for your Apple ID. To complete the process, click the link below. Reset now http://xn--p9q6vh6t2ja.com/RT This link will expire three hours after this email was sent. If you didn’t make this request, it's likely that another user has entered your email address by mistake and your account is still secure. If you believe an unauthorized person has accessed your account, you can reset your password at My Apple ID http://xn--p9q6vh6t2ja.com/RT. Apple Support Support http://xn--p9q6vh6t2ja.com/RT Privacy Policy http://xn--p9q6vh6t2ja.com/RT Copyright © 2015 Apple . All Rights Reserved.
Estafas a través de correos electrónicos y sitios web: cómo protegerse
Cuando lee correo electrónico o explora Internet, debe tener cuidado con las estafas que intentan robar su información personal (robo de identidad), su dinero o ambos. Muchas de estas estafas se conocen como "estafas de suplantación de identidad (phishing)", porque intentan "pescar (fish)" su información. Cómo reconocer estafas Todos los días parece que aparecen estafas nuevas. Intentamos mantenernos al día en nuestros Consejos de seguridad y blog de debate. Para ver las estafas más recientes, explore nuestra sección de fraudes. Además, puede aprender a reconocer una estafa familiarizándose con algunos de los indicios delatores. Las estafas pueden incluir lo siguiente: Mensajes alarmistas y amenazas de cierre de cuentas. Promesas de dinero a cambio de poco esfuerzo o sin esfuerzo alguno. Negocios que parecen demasiado buenos para ser reales. Solicitudes de donaciones a organizaciones benéficas después de producirse alguna catástrofe. Errores de gramática o de ortografía. Estafas conocidas A continuación se indican algunas estafas conocidas de las que debe estar al tanto: Estafas que usan el nombre de Microsoft o los nombres de otras empresas reconocidas. Estas estafas pueden incluir mensajes de correo electrónico o sitios web falsos que usan el nombre de Microsoft. El mensaje de correo electrónico puede alegar que ha ganado un concurso de Microsoft, que Microsoft necesita su información de inicio de sesión o su contraseña o que un representante de Microsoft se pondrá en contacto con usted para ayudarle con su equipo.(Estas estafas de soporte técnico falso con frecuencia se realizan por teléfono). Para obtener más información, consulte Evite las estafas que usan el nombre de Microsoft de forma fraudulenta. Estafas de lotería. Es posible que reciba mensajes que aleguen que ha ganado la lotería o las apuestas de Microsoft. Estos mensajes incluso se ven como si procedieran de un ejecutivo de Microsoft.La Lotería de Microsoft ni siquiera existe.Elimine el mensaje. Para obtener más información, consulte ¿Qué es la estafa de la lotería falsa de Microsoft? Estafas de software de seguridad no autorizado. El software de seguridad no autorizado, también conocido como “scareware”, es software que parece ser beneficioso desde la perspectiva de la seguridad, pero ofrece una seguridad limitada o ninguna seguridad; genera alertas erróneas o engañosas o intenta convencerle de que participe en transacciones fraudulentas.Estas estafas pueden aparecer por correo electrónico, en avisos en línea, en los sitios de redes sociales, en resultados de motores de búsqueda o incluso en ventanas emergentes en su equipo que pueden aparentar ser parte del sistema operativo, pero no lo son. Para obtener más información, consulte Cuídese de las falsas alertas de virus. Leer mas en: http://www.microsoft.com/es-es/security/online-privacy/phishing-scams.aspx
Mailbox Suspension Alert!
From: Ford, Lisa S. Sent: Monday, April 27, 2015 11:33 AM To: Ford, Lisa S. Subject: Mailbox Suspension Alert! Your Outlook Web Access/App account has exceeded its storage limit. You are required to to UPGRADE your account for continual usage. Failure to do this your account will suspended Click Here to upgrade your account. Thanks. ITS Service Team © Copyright 2015.
SCAMMERS MAY USE PARIS TERRORIST ATTACK TO SOLICIT FRAUDULENT DONATIONS
February 10, 2015 Alert Number I-021015-PSA In the wake of the terrorist attack against Charlie Hebdo in Paris last month, the FBI would like to warn the public about the potential for fraudulent solicitations of donations for victims. These solicitations come in many forms, such as crowdfunding platforms, e-mail campaigns, or cold calls, and perpetrators may divert some or all of the funds for their own use. A number of charities and crowdfunding campaigns have already begun soliciting donations. At the time of this advisory, the FBI has not recorded any reports of fraudulent donation schemes relating to the Charlie Hebdo attack. But based on previous trends, the Bureau can reasonably assume that such schemes may target individuals in the United States. In general, individuals and businesses should be wary of suspicious e-mails, telephone calls, or websites that solicit donations in response to any event. Crowdfunding—soliciting money from a large number of people primarily over the Internet—offers scammers a new venue to easily solicit funds with minimal oversight. Red flags to look out for include: The charity refuses to provide detailed information about its organization or how the donation will be used. The charity uses a name closely resembling that of a reputable organization. The charity pressures individuals to donate immediately. The charity asks for donations to be sent through wire transfers, cash or virtual currency. The charity guarantees a monetary return for a donation. The presence of one or more of these behaviors does not conclusively mean a charity is fraudulent; however, individuals and businesses should always verify a charity’s legitimacy before making any donations. Suspicious solicitations should be reported to the FBI’s Internet Crime Complaint Center at www.IC3.gov.
CYBER-RELATED SCAMS TARGETING UNIVERSITIES, EMPLOYEES, AND STUDENTS
The Internet Crime Complaint Center (IC3) is aware of multiple scams targeting universities, university employees, and students across the nation. The scams range from Internet fraud to intrusions. The following are common scenarios: Spear phishing e-mails are being sent to university employees that appear to be from their employer. The e-mail contains a link and claims some type of issue has risen requiring them to enter their log-in credentials. Once employees provide their user name and password, the perpetrator accesses the university’s computer system to redirect the employees’ payroll allocation to another bank account. The university employees’ payroll allocations are being deposited into students’ accounts. These students were hired through online advertisements for work-at-home jobs, and provided their bank account information to the perpetrators to receive payment for the work they performed. Scammers are posting online advertisements soliciting college students for administrative positions in which they would receive checks via the mail or e-mail. Students are directed to deposit the checks into their accounts, and then print checks and/or wire money to an individual. Students are never asked to provide their bank account information to the perpetrators. Perpetrators are compromising students’ credential resulting in the rerouting of their reimbursement money to other bank accounts. The reimbursement money is from student loans and used to pay tuition, books, and living expenses. Perpetrators are obtaining professors’ Personally Identifiable Information (PII) and using it to file fraudulent income tax returns. Some universities have been victims of intrusions, resulting in the perpetrators being able to access university databases containing information on their employees and students. From: http://www.ic3.gov/media/2014/140505.aspx
IPHONE 5S PHISHING MAIL ARRIVES IN TIME FOR LAUNCH
Towerwall Security posted the following on September 10, 2013: While millions of mobile users are anticipating the launch of the new iPhone (5S and 5C), cybercriminals are already making their move to distribute spam that promise to give away the said devices for free, in the guise of a contest. We saw samples of spammed messages that attempted to spoof an Apple Store email notification. The said message informs recipients that they won the latest iPhone 5S mobile phones and iPad. To get these prizes, they are asked to go to a specific website and disclose their email address and password. This will obviously result in your credentials ending up in the hands of cybercriminals. The content of the message and the sender's email address are obviously fake. However, its combination of perfect timing plus popular social engineering hook may cause users to fall into the spammers trap. The most important thing to know is: "if it's too good to be true, it probably is".
ATTACKERS USE SKYPE, OTHER IM APPS TO SPREAD LIFTOH TROJAN
SC Magazine featured the following article on June 1, 2013 Users receiving shortened URLs in Skype instant messages, or similar IM platforms, should be wary of a new trojan, called Liftoh. So far, it has primarily infected users in Latin America, said Rodrigo Calvo, a researcher at Symantec. When targeted, victims receive a message in Spanish containing a shortened URL. The messages appear as if they are coming from someone on the user’s Skype contact list who is linking to a photo. If clicked, the link redirects users to 4shared.com, which is hosting a URL, which initiates a weaponized zip file containing Liftoh. The trojan is capable of downloading additional malware. The malicious URLs have been clicked on more than 170,000 times, according to Symantec.
UNAUTHORIZED BANK ACCOUNT ACCESS IN THE PAYDAY LOAN SCAM
The payday loan scam involving threats and TDoS attacks was highlighted in the February 21, 2012 Public Service Announcement titled “New Variation On Telephone Collection Scam Related To Delinquent PayDay Loans” and in the January 7, 2013 IC3 Scam Alerts. Based on IC3 complaint information, it appears the tactics used by the subjects continue to evolve. Information revealed subjects are now making unauthorized deposits for payday loans into victims’ bank accounts. The proceeds range from $200 to $300. After the initial deposit, victims reported unauthorized withdrawals every two weeks in increments between $60 and $90. The withdrawals are applied to accrued interest only, making it impossible to pay the loan in full. Victims reported all efforts to return the unwanted loan proceeds or pay the loan in full were unsuccessful. Some reported closing their bank account and holding the loan proceeds to prevent further fraud to their account. It has yet to be determined how the subjects are obtaining the victims’ bank account information, because some of the victims claim they have never applied for a payday loan.
FAKE ORDER CONFIRMATION EMAILS FROM AMERICAN AIRLINES LEADS TO MALWARE
MX Lab, http://www.mxlab.eu, intercepted some samples of fake order confirmation emails from American Airlines that will lead the user to a host with an embedded Javascript that will download the malicious payload. In this case, the URL hxxp://egiser-ingenieros.com/FAHSIENFHE.html brings us to an HTML page with an embeded Javascript that will starts the download of the malicious ZIP file The ZIP file has the name AA_Electronic_Ticket.zip and contains the 60 kB large file AA_Electronic_Ticket.exe. The trojan is known as Spyware/Win32.Zbot, Win32/TrojanDownloader.Zortob.B, Trojan.Generic.KDV.783582, W32/Kryptik.BWW. At the time of writing, 13 of the 44 AV engines did detect the trojan at Virus Total.
THE CYBER CRIMINALS WERE EVEN KIND ENOUGH TO INCLUDE INSTRUCTIONS ON DOWNLOADING THE MALWARE
From: “Microsoft Corp.”windowsupdate@microsoft.com Subject: Critical patch issued! THE CYBER CRIMINALS WERE EVEN KIND ENOUGH TO INCLUDE INSTRUCTIONS ON DOWNLOADING THE MALWARE TO:axxdaj@thgus.com Dear Client In a recent security bulletin, Microsoft has been informed that a flaw exists in the Microsoft Outlook products (all versions) and Microsoft Exchange Server products (all versions) that could allow an attacker to compromise a successfully exploited computer. The vulnerability is still 0-day meaning it cannot be patched if a computer has already been compromised, however Microsoft has released an emergency patch to reduce the potential successful attacks and fix this issue. By applying this patch you will have the guarantee that your computer will not be affected by such an attack. The most recent report shows a number of 1673711 computers infected worldwide. EMBEDDED LINKS: href=”hxxp://smatarosario.com.ar//administracion/includes/mail/MSOUTRC2012Update- KB893092.exe” The patch can be downloaded from the link below hxxp://yostarquitectura.com//imagenes/microsoft.html
FREE CREDIT SERVICE WEBSITE
The IC3 has received over 2,000 complaints regarding a particular website that is claiming to offer “free” credit services such as credit scores and credit monitoring. Customers reported being charged a monthly service fee. However, the terms of the agreement advised that the “free” report only lasts for a limited time. At the end of the free term, the website used the customer’s supplied financial information to charge a monthly membership service ranging from $19.95 to $29.95. The terms and agreement from the website states the following: “For Subscription Services which include a free-trial period, if you do not cancel your free trial within the free trial period, you will be charged at the monthly rate in effect at that time for the Subscription Services for which you enrolled. Your debit or credit card (including, if applicable, as automatically updated by your card provider following expiration or change in account number) will continue to be charged each month at the applicable monthly rate unless and until you cancel the Subscription Services.” The website, according to the Better Business Bureau (BBB), has been given an F rating by the BBB for the following reasons: 1037 complaints filed against the business. 8 complaints filed against the business that were not resolved. 17 serious complaints filed against business. Advertising issue(s) found by the BBB.
FAKE POLITICAL SURVEY
The IC3 has been notified of a scam involving telephone calls conducting a multiple-choice “political survey.” Following the survey, the recipients are told they won a free cruise to the Bahamas. After providing a website address for legitimacy, the caller requests the “winner’s” email address for notification purposes and credit card information to cover port fees. The website has very limited information, but does contain a few photos, testimonials, and “Caribbean Line” banner, in an attempt to convince visitors it is legitimate.
UPS QUAMTUM VIEW
UPS QUAMTUM VIEW EBAY/PAYPAL AccountNotify@verizonwireless.com AMAZON Son “phishing”*, Favor de no leer el mensaje. (Es recomendable eliminarlo). * Definición: El phishing es un tipo de fraude en línea en el que los responsables intentan conseguir los datos personales, financieros o de otra índole (como las ID, contraseñas, números de tarjeta de crédito, etc.) de sus víctimas. Por lo general, esta táctica empieza con el envío de un correo electrónico supuestamente oficial de una empresa respetable, por ejemplo, de un banco, una tarjeta de crédito o una empresa en línea. No respondas a ningún mensaje pidiéndote tus datos personales o financieros. Las empresas legítimas no solicitarán que verifiques o que facilites tus datos en un mensaje que no has solicitado. Definición recuperada de help.yahoo.com
US Airways online check-in confirmation
US Airways online check-in confirmation. Es un virus, Favor de no leer el mensaje. (Lo deben eliminar)