2013 e-scams-ISP Alerts

2013 e-scams

The following email messages are examples of actual email phishing scams or attempts to deliver a virus via email. Most of these examples appear to have been sent by your Internet Service Provider (ISP).

You may also receive this type of email scam that appears to have been sent by Facebook, Twitter, Amazon, Ebay, Paypal, or a familiar 
credit card or bank.

If you do receive one of the following emails or a similar email message 
in your inbox, please avoid opening any attachments and delete 
the email.

NOTE: If you receive a questionable email and it is not listed here 
do not assume that the email is valid. This list is simply a small sample of the large amount of scam emails that are circulating.

12/04/13 Malware Infected Link

From: Single Parent Holidays [mailto:Ethan.Gutierrez@teagibtow.com] 
Sent: Wednesday, December 4, 2013 8:12 AM
To: email@yourdomain.com
Subject: Holiday Traditions: The Holiday Kit for every parent

Good Parenting
#1 Gift for Your Child
(Posted December 03, 2013)
 
The Holiday Kit for Every Parent

We recently did a study, with adults 25-40. 
In summary, we found that most adults could not recall gifts that they received on Christmas.
However they could recall memories of Christmas morning and letters from Santa Claus.

We want to help you be a good Parent. That's why we are telling you about Letters from Santa. 

You will feel fulfilled . . . And your kids will have memories to last them a lifetime.

Happy Holidays

-Good Parenting-

11/21/13 Malware Infected Link

From: Sam's Club Reward [mailto:DanielStevenson@sobpit.com]
Sent: Thursday, November 21, 2013 12:06 PM
To: customer@yourdomain.com
Subject: Sam's rewards: Details on your club card #6787

Sam's Club Card Bonus

 Details on your Sam's card are listed below.

whether you have never shopped at Sam's before or are a current member they have everything you need to stock up on. Please use this Sam's reward card to shop for anything that you need.

Card #172298

http://www.sobpit.com/samsclub/card/4355647345432523.acct

Looking for new things to make with hamburger we eat alot,of it

November Blog:

Things You Should Buy in Bulk:

•             Cereal

•             Toothbrushes and toothpaste

•             Dried Beans and Pasta

•             Toilet Paper and Paper Towels

•             Office Supplies

•             Non-perishable Foods

•             Diapers


10/20/13 Malware Infected Link

From: Marc Andersen [mailto:research@hpcomputerlabs.com]
Sent: Sunday, October 20, 2013 6:53 AM
To: Seth Engel
Subject: Advisory: HP Security

Good day

 This is Marc Andersen head of the R and D section for HP Computers. We sincerely apologize for this unsolicited email. However, as the official research and development team for HP, we feel it is our sole responsibility to issue this advisory not only to our loyal customers but to all computer users as well.

We have been getting reports over the last week of the sudden emergence of a new version of the Blackmal computer virus. This virus infects the computer's core and deletes files with such precision that even the most popular security program out there can't prevent or even detect.

As of the moment we have received over a million confirmed reports of total computer data wipe out without the chance of file recovery. Please be aware that besides HP computers, we have also received reports coming from other brand users as well.

This is very serious.

Currently, there are only a very few antivirus software that are capable in blocking this virus - 3 to be exact. So we took it upon ourselves to test and research the capabilities of each antivirus program. Rigorous split testing has been done on each program and based on our findings we have found out that Kaspersky Antivirus is the only one capable of deleting the virus in the core processor.

So at this point we highly advise that you secure a copy of the software ASAP. We want to stress out that we are not in any way affiliated with Kaspersky. The reason for our recommendation solely revolves around our best efforts to protect all computer users. If you already own the Kaspersky antivirus program, you may still need to update. You can get your copy via the link below.

http://hpcomputerlab.com/kasperskyblackmalversion

It is very important that you install the program as soon
as possible as your computer's information and security are at stake. If you have questions or clarifications, please don't hesitate to email us at
research@hpcomputerlab.com.

Please add our email address to your contact list to make sure that you will be receiving our updates in the next few weeks. Furthermore, please forward this email to your friends and relatives to spread the word of this issue. Rest assured we are doing everything we can to resolve this, and we highly appreciate your patience and cooperation during these times.


9/19/13 Phishing Scam

 From: Ayisi, Kingsley [mailto:Kingsley.Ayisi@ul.ac.za

Sent: Wednesday, September 18, 2013 12:25 PM
Subject:

 Your mailbox is almost full.

20GB

 

23GB


Your mailbox needed to update now (Click Update Here) Update it now,and Increase your Mail Quota.
IT Services Help Desk.

 DISCLAIMER *** This message and any attachments are confidential and intended solely for the addressee. The following link will display the full disclaimer: http://www.ul.ac.za/disclaimer.jpg *** 



9/11/13 Malware Infected LInk

From: Case Number HOZ4-9672 [mailto:AbigailLuna@gutbop.com]
Sent: Wednesday, September 11, 2013 11:32 AM
To: customer@yourdomain.com
Subject: Re: Your MortgagePayments are now reduced. View Notification -

- - - - - - - - start notice- - - - - - - - -

*************************************************************

Notification #47e2dff827065213edb2b308ac2cdb92

*************************************************************

TO: customer@yourdomain.com

*************************************************************

---------------------------------------------------------------------------------

One (1) New Message Received - Latest Correspondence

---------------------------------------------------------------------------------

U.S. homeowners' monthly home payments are now cut.

This new alteration will benefit potential and current homeowners alike.

You will now be eligible to get a rate of only 2.801% due to this rate drop.

That means your current monthly payment would be cut in half.

Find out more here - http://www.gutbop.com/findyour/newrate.html

This will only take a couple minutes and can cut your present monthly
payment in HALF.

- - - - - - - finish notice- - - - - - - -


8/29/13 Phishing Scam

From: PayPal [mailto:service@int.paypal.com] 
Sent: Thursday, August 29, 2013 8:46 AM
To: customer@yourdomain.com
Subject: Identity Issue #PP-266-142-242-519

We are writing you this email in regards to your PayPal account. In accordance with our "Terms and Conditions", article 3.2., we would like to kindly ask you to confirm your identity by completing the attached form.

Please print this form and fill in the requested information. Once you have filled out all the information on the form please send it to verification@paypal.com along with a personal identification document (identity card, driving license or international passport) and a proof of address submitted with our system ( bank account statement or utility bill ).

For more details please see on the page View all details

Your case ID for this reason is PP-CFJ04NHK55HS

For your protection, we might limit your account access. We apologize for any inconvenience this may cause.

Thanks,

PayPal

CONFIDENTIALITY NOTICE:

This electronic mail transmission and any attached files contain information intended for the exclusive use of the individual or entity to whom it is addressed and may contain information belonging to the sender (PayPal , Inc.) that is proprietary, privileged, confidential and/or protected from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any viewing, copying, disclosure or distributions of this electronic message are violations of federal law. Please notify the sender of any unintended recipients and delete the original message without making any copies. Thank You

PayPal Email ID PP58968


7/17/13 Malware infected links

From: Marriott Hotels & Resorts Reservation
Sent: Wednesday, July 17, 2013 6:59 AM
To: customer@yourdomain.com
Subject: Houston Marriott Westchase Reservation Confirmation #73499792

Houston Marriott Westchase 2900 Briarpark Dr.,
Houston, Texas 77042 USA Phone: 1-713-978-7400
Fax: 1-713-735-2726

Reservation for customer@yourdomain.com

Confirmation Number: 73499792
•             Check-in: Sunday, July 21, 2013 (03:00 PM)
•             Check-out: Wednesday, July 24, 2013 (12:00 PM)

Modify or Cancel reservation
View hotel website  
Maps & Transportation
Reservation Confirmation

Dear Visitor,

We are pleased to confirm your reservation with Marriott. Below is a summary
of your booking and room information. We look forward to making your stay
gratifying and memorable. When you're traveling away from home
you can always count on Marriott.

Houston Marriott Westchase
Planning Your Trip

•             See what's happening in Houston during your stay Check
out some of Houston's top attractions

•             Book with Hertz: Save up to 35% and Earn 500 Rewards Points

•             Book Cars, Tours & More - get great rates on local tours and attractions

Reservation Details

•             Confirmation Number: 73499792

•             Your hotel: Houston Marriott Westchase

•             Check-in: Sunday, July 21, 2013 (03:00 PM)

•             Check-out: Wednesday, July 24, 2013 (12:00 PM)

•             Room type: Guest room, 1 King or 2 Queen

•             Number of rooms: 1

•             Guests per room: 1

•             Guest name: Hayden Cox

•             Reservation confirmed: Wednesday, July 16, 2013 (23:55:00 GMT)

•             Guarantee method: Credit card guarantee, VISA

Special request(s):

•             •2 Queen Beds, Guaranteed

•             •High Floor Room, Request Noted

•             •I.D. Required, Request Noted

Summary of Room Charges          Cost per night per room (USD)
Sunday, July 21, 2013 - Wednesday, July 24, 2013 ( 3 nights=20 ) 115.02
Govt/military rate, federal government ID required              
Estimated government taxes and fees      18.53
Total for stay (for all rooms)         387.79

•             Complimentary on-site parking

•             Valet parking, fee: 14 USD daily

•             Changes in taxes or fees implemented after booking will affect
the total room price.

You may modify or cancel your reservation online (see details below),
or call our worldwide telephone numbers.
Contact us if you have questions about your reservation.
Canceling Your Reservation

•             You may cancel your reservation for no charge until Friday,
July 19, 2013
(1 day[s] before arrival).

•             Please note that we will assess a fee of 127.53 USD
if you must cancel after this deadline.

If you have made a prepayment, we will retain all or part of your prepayment. If not, we will charge your credit card.

Modifying Your Reservation

•             Please note that a change in the length or dates of your reservation may result in a rate change.

•             Please be prepared to show proof of eligibility for your rate
(such as a membership card, corporate or government identification card,
or proof of your age).

Rewards Account Information
Your Rewards level: Silver
Your Rewards number: 642268841
As a Silver Elite member, you can enjoy the following benefits during your stay (may vary by hotel):

•  20% Bonus on your Marriott Rewards base points

•  Priority Late Checkout

•  Guaranteed Room Type
Sign in to view account

•             Sign up for eFolio to receive your hotel bill by email after each stay in the USA and Canada

•   Plan events, earn rewards with Rewarding Events.

•   50,000 Bonus Points

Earn 50,000 Bonus Points and an Annual Free Night with
No Annual Fee the First Year. More Rewards, Faster with the
Marriott Rewards Premier Credit Card.

Learn More and Apply

Travel Alerts

•      Download the Marriott Mobile App.

  • The Perfect Travel CompanionTM

•         Please Note: All Marriott hotels in the USA and Canada, are committed to a smoke-free policy.

Learn more

•        The Responsible Tourist and Traveler

A practical guide to help you make your trip an enriching experience

Look No Further You've received the best possible rate - guaranteed.

Privacy, Authenticity and Opting Out

Your privacy is important to us. Please visit our Privacy Statement for full details.

This email confirmation is an auto-generated message. Replies to automated messages are not monitored. Our Internet Customer Care team is available to assist you 24 hours per day, 7 days per week. Contact Internet Customer Care.

Promotional email unsubscribe

If you provided us with your email address for the first time, we will send you a follow-up email to welcome you. We will also send you periodic emails with information about your account balance, member status, special offers and promotions.
An opt-out link will be included in each of these emails so that you can
change your mind at any time.

If you would prefer to opt out of such emails from Marriott International,
Marriott Rewards or The Ritz-Carlton Rewards, you may do so here. In addition,
you may unsubscribe from The Ritz-Carlton email community here

Please note: Should you unsubscribe from promotional email, we will
continue to send messages for transactions such as reservation confirmation, point redemption, etc.

Confirmation Authenticity

We're sending you this confirmation notice electronically for
your convenience.
Marriott keeps an official record of all electronic reservations.
We honor our official record only and will disregard any alterations
to this confirmation that may have been made after we sent it to you.

If you have received this email in error, please let us know.

Terms of Use::Internet Privacy Statement

©1996-2013 Marriott International, Inc. All rights reserved. Marriott proprietary information.


7/11/13 Malware infected links

From: Dealership Source [mailto:Cameron.Logan@mx10.standgod.net]
Sent: Thursday, July 11, 2013 9:41 AM
To: customer@yourdomain.com
Subject: Select a 2013 model car -- Dealership Clear-out
---------------------------------------------------------------------
Dealership Clearance
Select a 2013 Model
---------------------------------------------------------------------
Do you know what dealerships do with overstock?
They let you search for it right here -
http://www.standgod.net/approve/involve/<< BAD LINK
-_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_-

Notice: 2013 stock is becoming very limited. Now is your chance to see what is left.
-_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_--_
Participants:
Toyota ~ Ford ~ Honda ~ Chevrolet ~ Volvo ~ Dodge ~ And More
Dealership Supplier ID: 65b63bb3b29d3246f226451abbcd6835


7/10/13 Malware infected links

From: Local Rates [mailto:Katelyn.Mendez@a.wryrec.com] 
Sent: Wednesday, July 10, 2013 7:44 AM
To: customer@yourdomain.com
Subject: Mortgage-rates are now 2.5% - Review today - July Update #445

|----------------------------------------------------
|Wednesday July 10th
|ATTN: customer@yourdomain.com
|Status: Obtain a 2.5% Home Rate
----------------------------------------------------
Home rates are becoming lower in your area. Take Advantage while
you can.

Simply provide the minimal information and we will show all your options.
=================================================
2.5% available --  http://www.wryrec.com/rate/area/ << MALICIOUS LINK
=================================================
=================================================
The current 2.5% (lower then average) rate is based on your area.
They may fluctuate day to day so be sure to act while they are low in your
area.
=================================================
---------------------------------
Area ID: 3234793
-----------
Rates last checked: 07-09-2013 21:32:19
---------------------------------


7/10/13 Malware infected links

From: Credit Report Center [mailto:DavidLee@tutosrag.net]
Sent: Wednesday, July 10, 2013 8:51 AM
To: customer@yourdomain.com
Subject: RE: Your Score was Updated - Please Read

-----------------------------------------------
RE: Your Score Updates
-----------------------------------------------

Greetings customer@yourdomain.com

We are reachign out to you today is to inform you that your score has recently been updated due to certain changes.

If you would like to find out how these alterations to your score may affect you, go here - http://www.tutosrag.net/m/568-tsd <<<<<MALICIOUS LINK HERE

-----------------------------------------------------------------------
***The Current Generation Time for your Personal Score is 41 Seconds***

We appreciate your time.

Regards,

The Score-Report Team
-----------------------------------------------
Message ID#b623cc23dbf905616e4a6cc6bce0aa8d


7/09/13 Malware infected links

From: Authorize.Net [mailto:emailreceipts@clients.authorize.net] 
Sent: Tuesday, July 9, 2013 8:47 AM
To: customer@yourdomain.com
Subject: Successful Credit Card Settlement Report.

Your Authorize.Net ID is: 1263577
Dear customer@yourdomain.com,

The following is your Credit Card settlement report for Sunday, July 09, 2013.

Transaction Volume Statistics for Settlement Batch dated 9-Jul-2013 22:0:09 PDT:
Batch ID: 269401518
Business Day: 09-Jul-2013
Net Batch Total: 6,138.90 (USD)
Number of Charge Transactions: 354
Amount of Charge Transactions: 6,138.90
Number of Refund Transactions: 20
Amount of Refund Transactions: 66.43

Warning! Your Batch limits for July exceeded!

To find more information, please click here to log into the Merchant Interface.

If you have any questions regarding this settlement report, please contact your bank or you can contact Customer Support at feedback form.

Thank You,

Authorize.Net

*** You received this email because you chose to be a Credit Card Report recipient. You may change your email options by logging into the Merchant Interface. Click on Settings and Profile in the Main Menu, and select Manage Contacts from the General section. To edit a contact, click the Edit link next
to the contact that you would like to edit. Under Email Types, select or deselect the Email types you would like to receive. Click Submit to save any changes. Please do not reply to this email.


7/05/13 Malware infected links and attachment

From: EBC_EBC1961Registration@ucbecorp.com [mailto:EBC_EBC1961Registration@ucbecorp.com]
Sent: Friday, July 5, 2013 5:29 AM
To: customer@yourdomain.com
Subject: Password Reset Confirmation

Your EBC Online Banking password was successfully changed on 07/05/2013.
If you did not make this change, or if you have any questions, please contact EBC Technical Support by clicking here.

Support is available Monday - Friday, 8 AM to 8 PM PST.

This is an automated message, please do not reply. Your message will not be received.

************************************************************

This communication, including attachments, is for the exclusive use of
addressee and may contain proprietary, confidential and/or privileged
information. If you are not the intended recipient, any use, copying, disclosure, dissemination or distribution is strictly prohibited. If you are not the intended recipient, please notify the sender immediately by return e-mail, delete this communication and destroy all copies.

************************************************************

6/24/13 Phishing Scam

From: Clayton UTZ [mailto:mlhuhner@cableone.net]
Sent: Monday, June 24, 2013 12:43 AM
To: customer@yourdomain.com
Subject: Details of Fund

Please confirm that you have receive details of your bequeathed fund. If not, details will be provided to you.  Be advise to add our address to your address book for better communication.
__________________________________

Regards,
Darryl McDonough
Clayton Utz Law Firm
__________________________________
Open Access Ads: journal paper publication


6/21/13 Malware infected links ln this message

From: Visa Anti-Fraud [mailto:beaconskc08@ema1lsits.adpmail.com]
Sent: Friday, June 21, 2013 9:31 AM
To: customer@yourdomain
Subject: Suspicious business card activity

We 've detected unusual activity in your business Visa account.

Please click here to view details

Your Case ID is: 6259203356044966

Look for unexpected charges or questionable activity, and if you see anything suspicious,don't wait to act.

This added security is to prevent any additional fraudulent charges from taking place on your account.

Notice: This Visa communication is furnished to you solely in your capacity
as a customer of Visa Inc. (or its authorized agent) or a participant in the
Visa payments system. By accepting this Visa communication, you acknowledge that the information contained herein (the "Information") is confidential and subject to the confidentiality restrictions contained in Visa's operating regulations, which limit your use of the Information. You agree to
keep the Information confidential and not to use the Information for any
purpose other than in your capacity as a customer of Visa Inc. or a
participant in the Visa payments system. The Information may only be disseminated within your organization on a need-to-know basis to enable your participation in the Visa payments system.

Please be advised that the Information may constitute material nonpublic information under U.S. federal securities laws and that purchasing or selling securities of Visa Inc. while being aware of material nonpublic information
would constitute a violation of applicable U.S. federal securities laws. This information may change from time to time. Please contact your Visa representative to verify current information. Visa is not responsible for errors in this publication. The Visa Non-Disclosure Agreement can be obtained from your Visa Account Manager or the nearest Visa Office.

This message was sent to you by Visa, P.O. Box 8999, San Francisco, CA 94128. Please click here to unsubscribe.

6/05/13 Malware infected links ln this message

From: eFax Corporate [mailto:wonderedwt124@emlreq.efax.net] 
Sent: Wednesday, June 5, 2013 7:33 AM
To: customer@yourdomain.com
Subject: Corporate eFax message from "IRS-2210"

You have received a 5 page(s) fax from at 2013-06-05 5:08:14 CST.

* The reference number for this fax is 3BY29_CD7PF-6183491910-3163291860-30.

* The sender for this fax is IRS-2210.

Please visit www.efaxcorporate.com/corp/twa/page/customerSupport if
you have any questions regarding this message or your service. You may
also e-mail our corporate support department .

Thank you for using the eFax Corporate service!

2013 j2 Global, Inc. All rights reserved.

eFax Corporate is a registered trademark of j2 Global, Inc.


5/23/13 Malware infected links ln this message

From: Data Processing Service [mailto:nodulesxo@complains.amazonmail.com]
Sent: Thursday, May 23, 2013 7:04 AM
To: customer@yourdomain.com
Cc: customer@yourdomain.com
Subject: ACH file ID "525.537" has been aborted

Files Processing Service

PROCESSING STATUS Note

We have successfully complete ACH file 'ACH2013-05-14-66.txt' (id '525.537') submitted by user 'wheelert' on '2013-05-14 18:27:36.8'.

FILE SUMMARY:

Item count: 9
Total debits: $12,917.76
Total credits: $12,917.76
For more details    browse this link

------=extPart_000_002B_01C7559G.XIE5DIX0--


5/22/13 Phishing Scam

Subject: Re: Your score has been updated. Please review

Date:     2013-05-22 01:03 PM
From:    CreditReportCenter Adrianna.Payne@pieceunderneath.com
To:         customer@yourdomain.com
Reply-To: <Adrianna.Payne@pieceunderneath.com>

----------------------------------------------
Customer: customer@yourdomain.com

5/20/13

Re: Credit-Score Updates
----------------------------------------------
Notice: Your score has been updated as a result of recent updates.

* View updates to your score now: http://www.pieceunderneath.com/score/changes

ID - #51270c84f4fd74bcf011b5824e870b6a

* See your updated score as of May 22th, 2013 here: http://www.pieceunderneath.com/score/changes.html

Current score generation time: 22 Seconds

Sincerely,

The Score-Report Team


5/22/13 Malware infected links in this message

Subject: Your State Board of Regents Background Verification for Customer Name

Date: 2013-05-13 15:54
From: HireRight Customer Support customersupport@hireright.com
To: Customer Name <customer@yourdomain.com>

Dear Customer Name,

Your State Board of Regents has partnered with HireRight, a leading provider
of on-demand employment screening solutions, to manage your background verification.
This message describes how to access their secure website to provide the information that will expedite your verification. Please carefully follow all instructions and accurately enter the data as required. Also, please respond quickly to HireRight requests for more information.

To access the secure website, please click this link and use the case-sensitive credentials:
https://ows01.hireright.com/in.html?key= <<malicious link

Login: customer@yourdomain.com
Password: 2430a95f (a user-defined password will be established after login)

Important: Your login and password is active for 30 day(s) from the
date of receipt. Bookmark the link and remember your credentials because
they are required to access this secure website.

If you need support, HireRight Customer Service is available 5 days a
week from Sunday 5 p.m. until Friday 7 p.m. Pacific Time by phone (toll
free in the U.S.) at (866) 521-6995, or by a toll call elsewhere at +1 (949) 428-5804.

Sincerely,

Beth Clapp


5/21/13 Phishing Scam

From: la-caixa bank [mailto:online-londondesks@la-caixa.co.uk] 
Sent: Tuesday, May 21, 2013 3:30 AM
To: sysadmin@yourdomain.net
Subject: your confidence

La Caixa, United Kingdom
16 Waterloo Place
London, SW1Y 4AR

Dear Sir,

I have a deal to carry out with you, please confirm your interest for more information.

Thank you.

Greg Moore
Foreign Remittance Dept.
La Caixa Bank, U.K
Direct Line: (44)-792-455-1323


5/20/13 Malware infected links in this message

Subject  Identity Issue PP-001-544-375
From      PayPal
To          customer@yourdomain.com
Date      Mon 07:36 PM
Case ID Number PP-001-544-375.htm

Dear PayPal Customer,

On MAY 20, 2013, We recently have determined that different computers have logged in your PayPal account.

And multiple password failures were present before the logo's. We now need
you to re-confirm your account information to us.

If this is not completed by ,29, 05, 2013, we will be forced to suspend your account indefinitely.

Case ID Number : PP-001-544-375

To restore your account, Please download the attached form to verify your
Profile information and restore your account access.

Make sure you enter the information accurately, and according to the formats required.

Fill in all the required fields.

It's usually pretty easy to take care of things like this. Most of the time, we
just need a little more information about your account or latest transactions.

To help us with this and to see what you can and can't do with your account
until the issue is resolved, log in to your account and go to the

Resolution Center.

Yours sincerely,
PayPal
----------------------------------------------------------------------
Help Center: https://www.paypal.com/eg/cgi-binhelp < bad link
Security Center: https://www.paypal.com/eg/security < bad link

Please do not reply to this email because we are not monitoring this inbox.
To get in touch with us, log in to your account and click "Contact Us" at the
bottom of any page.

Copyright © 2013 PayPal Inc. All rights reserved.

Consumer advisory: PayPal Pte Ltd, the Holder of the PayPal™ payment
service stored value facility, does not require the approval of the Monetary Authority of Singapore. Consumers (users) are advised to read the terms and conditions: https://www.paypal.com/eg/sg/cgi-bin/webscr?cmd=p/gen/ua/ua-outside carefully. 

PayPal Email ID  PP076


5/16/13 Malware infected links in this message - note the misspelling of Walmart.

From: Wallmart.com [mailto:coerceswh9@ema1lsrv71.wallmart.net]
Sent: Thursday, May 16, 2013 7:45 AM
To: username@yourdomain.net
Subject: Thanks for your Walmart.com Order 9790266-576621

Visit Walmart.com  |
Help  |
My Account  |
Track My Orders

username@yourdomain.net

Thanks for ordering from Walmart.com. We're currently processing your order.

Items in your order selected for shipping

• You'll receive another email, with tracking information, when your order ships.

• If you're paying by credit card or Bill Me Later®, your account will not be charged until your order ships. If you see a pending charge on your account
prior to your items shipping, this is an authorization hold to ensure the funds
are available. All other forms of payment are charged at the time the order is placed.

Shipping Information

Ship to Home                   
Olivia Johnson
1573 Chestnut Ridge Dr
Los Altos, NC 68025-3157
USA         

Walmart.com     Order Number: 9790266-576621
Ship to Home - Standard

Items     Qty         Arrival Date         Price

Samsung UN48EH3040 50" 1080p 600Hz Class LED (Internet Connected) 3D HDTV  1                Arrives by Tue., May 21
Eligible for Free Standard Shipping to Home.          $898.00
Subtotal:              $898.00
Shipping:              Free
Tax:       $62.86

See our Returns Policy or contact Customer Service

Walmart.com Total:        $960.86

Order Summary
Order Date:         05/15/2013
Subtotal:              $898.00
Shipping:              Free
Tax:       $62.86
Order Total:        $960.86
Credit card:         $960.86              
Billing Information
Payment Method:
Credit card

If you have any questions, please refer to help.walmart.com or reply to this
email and let us know how we can help.

Thanks,

Your Walmart.com Customer Service Team
www.walmart.com
Sign Up for Email Savings and Updates

Have the latest Rollbacks, hot new releases, great gift ideas and more sent
right to your inbox!
©Walmart.com USA, LLC, All Rights Reserved.

               Recommended for You
* Prices and availability are subject to change.
Sanyo 46" Class LCD 1080p 60Hz Internet Connected HDTV $499.98

SANYO 42" Class LCD 1080p 60Hz HDTV,DP42841  $378.00

Vizio 42" Class LCD 1080p 120Hz refresh rate HDTV, E422VLE  $478.00

VIZIO 42" Class LCD 1080p 60Hz HDTV, E421VO  $378.00

Vizio 55" Class LCD 1080p 120Hz refresh rate HDTV, E552VLE  $798.00

PlayStation 3 160GB Console  $259.96

Vizio 42" Class LED 1080p 120Hz refresh rate HDTV, (1.9" ultra-slim) M420SL  $538.00

VIZIO 37" Class LCD 1080p 60Hz HDTV, E371VL  $348.00


5/01/13 Malware infected links in this message

From: BBB Customer Service [mailto:continuums@complains.domain.org]
Sent: Wednesday, May 1, 2013 9:12 AM
To: user@yourdomain.net
Subject: Better Business Beareau Pretense No. S3321802

Sorry, your e-mail does not support HTML format. Your messages can be
viewed in your browser

Better Business Bureau ©
Start With Trust ©
Thu, 30 Apr 2013
RE: Case # S3321802

user@yourdomain.net

The Better Business Bureau has been entered the above mentioned
reclamation from one of your clientes in respect to their business contacts
with you. The details of the consumer's disturbance are available at the link below.
Please pay attention to this point and communicate with us about your
sight as soon as possible.

We politely ask you to overview the PLAINT REPORT to reply on this claim letter.

We awaits to your prompt response.

Yours respectfully

Sarah Watson
Dispute Consultant
Better Business Bureau
________________________________________
________________________________________

Better Business Bureau
3023   Wilson Blvd, Suite 600  Arlington, VA 27001
Phone: 1 (703) 276.0100  Fax: 1 (703) 525.8277

This information was sent to user@yourdomain.net. Don't want to receive
these emails anymore? You can unsubscribe ------=extPart_000_002B_01CAY0W9.GUGRFHG0--


4/18/13 Malware infected links in this message

From: notify@ema3lsrv003982.csiweb.com [mailto:notify@ema3lsrv003982.csiweb.com] On Behalf Of Jordan.Martin@csiweb.com
Sent: Thursday, April 18, 2013 9:02 AM
To: username@yourdomain.net
Subject: New Secure Message Received from Jordan.Martin@csiweb.com

New Secure Private Message - www.csiesafe.com

Hello username@yourdomain.net,

You have received a new secure message from Jordan.Martin@csiweb.com.

If you are using the Secure Message Plugin in Lotus Notes this message will
be in your SecureMessages Inbox folder.

If you are NOT using the Secure Message Plugin, you are able to view it by clicking https://www.csiweb.com/maliciouslink to retrieve your secure
message or to begin using the convenient Novell Plugin.

WBR,
CSIeSafe


4/16/13 Malware infected links in this message

From: NACHA - The Electronic Payments Association email@nacha.org 
Sent: Tuesday, April 16, 2013 10:44 AM
To: username@yourdomain.com
Cc: this line may include multiple email addresses at your domain
Subject: ACH transaction canceled

ACH transaction canceled

The ACH transaction (ID: 71940795953789), recently sent from your account
(by you or any other person), was rejected by the other financial institution.

More details  << Malicious Link

Rejected transfer

Transaction ID: 71940795953789

Rejection Reason:      See detailed information in the statement below

Transaction Report:  report_71940795953789.doc (Microsoft Office Word Document) << Malicious LInk

Find more information and status updates by clicking here  << Malicious Link

NACHA - The Electronic Payments Association

13450 Sunrise Valley Drive, Suite 100, Herndon, VA 20171

Ph: 703-561-1100 | Fx: 703-787-0996 | email@nacha.org

www.maliciouslink.org << Malicious Link

Unsubscribe here.

13450 Sunrise Valley Drive, Suite 100, Herndon, VA 20171

NACHA does not send communications of any type to persons or
organizations about individual ACH transactions that they originate or receive.
If you or your customer has received a communication of this nature that
purports to come from NACHA, it is fraudulent. Visit NACHA's website at maliciouslink.org for more industry information on fraud, email phishing, and corporate account takeover including resources from the FDIC and the FTC. NACHA does not sell or release email addresses.


4/16/13 Malware infected links in this message

From: Alex King [mailto:alex.king@domain.com]
Sent: Tuesday, April 16, 2013 9:01 AM
To: username@yourdomain.com
Subject: Introduction

Hi John,

I’d like to introduce myself and our video agency.

We create two-minute videos that communicate to your target audience to
elicit a response. We’re known for writing great copy that gets the viewer to respond which helps drive sales.

For a brief explanation please click on this link: http://vimeo.com/42780286

If you’d like a little more information, let me know and I will send it over.

Best,

Alex King
Business Development
Richter10.2 Media Group
Tel +1 818 284 6605
Mobile +1 503 999 4325
Fax +1 727 213 6386
alex.king@richter10point2.com
http://richter10point2.com
http://r102video.com

SAN JOSE | LOS ANGELES | CLEARWATER | TORONTO | SEATTLE


4/15/13 Phishing Scam

From: Your ISP [mailto:help.desk@yourdomain.net]
Sent: Monday, April 15, 2013 3:20 AM
To: Recipients
Subject: [Bulk] Verify.
Importance: Low

Dear Account User

We are detected some unusual massage from your Your ISP email account,to avoid you loosing your Your ISP email account or suspention,you are to re-confirm your Your ISP email account for us to know that you are the rightfull owner of this email account.You are therefore required to provide your
Your ISP email account identities listed below to enable us verify and perform maintenance in your email account with our new system upgrading software. Failure to provide your valid information, your account will be suspended temporarily from our services.

Full name:
Full Email:
Password:
Date Of Birth:

© 2013 Your ISP Name. ALL RIGHTS RESERVED.


4/10/13 Malware infected links in this message

From: AT&T Online Services
To: username@yourdomain.com
Cc: username@yourdomain.com
Sent: Wednesday, April 10, 2013 11:15 AM
Subject: Your outstanding AT&T online bill

att.com | Support | My AT&T Account

Your online bill is ready to be downloaded

Dear Esteemed Customer,

A new bill for your AT&T services is prepared.

Any transactions completed after your bill period expires will not be reflected
in the bill amount listed directly below. If you have made a recent payment, please refer to the current balance on the Account Overview and the Bill & Payments pages.

               www.badlink.com/managemyaccount.

Log in to online account management to view your bill, maintain your email account or make a payment.

Thank you for choosing AT&T. We value your business and look forward to serving you!

Thank you,

AT&T Online Services
www.att.com 

Contact Us 
AT&T Support - quick & easy support is available 24/7.
Moving Soon?
Stay connected with AT&T. Visit us online at att.com/move.

AT&T Online Services

Get more time to do what you want. What would you do?
Show me how
Automatic Payments

Save time and pay your monthly bill automatically!
Sign up now
Special Offers

Visit our Special Offers to check out our best promotions.

Learn more
Online Information
AT&T Community
Repair
Home Phone
Special Offers
________________________________________

PLEASE DO NOT REPLY TO THIS MESSAGE

All replies are automatically deleted. For questions regarding this message,
refer to the contact information listed above.
©2013 AT&T Intellectual Property. All rights reserved. AT&T, the AT&T logo
and all other AT&T marks contained herein are trademarks of AT&T Intellectual Property and/or AT&T affiliated companies. All other marks contained herein
are the property of their respective owners.

Privacy Policy 


4/08/13 Malware infected links in this message

From: user@aol.com [mail
to:username@aol.com]
Sent: Monday, April 08, 2013 4:59 PM
To: username@yourdomain.com
Subject: www.sufferpeople.net

Thank you for writing us! We appreciate your interest in our company!

Per your request, we included below a quick description of the job.

We are currently interested in hiring US residents for our USA Wire Service

•                 Your job will be forwarding payments to our European clients

•                 You will need a personal bank account (you can open a
       new one, to use just with us).

•                 We are offering you a 10% commission

•                 This is a great money making opportunity, as this requires
      little of your time

•                 Your expected income will be around $2500-$3000 a month
      by working at home less than 2 hours a day.

•                 We are a legitimate company

•                 NO CHECKS SENT for you to cash

•                 NO SELLING

•                 NO REJECTIONS

To apply for this position please visit the Careers page on our website: www.sufferpeople.net

Start making $2500-$3000 a month by working at home less than 2 hours a
day NOW!
Click on this link if your browser does not automatically redirect you in 15 seconds


4/05/13 Malware infected links in this message

From: Amazon.com [mailto falseaddress@amazon.com]
Sent: Friday, April 5, 2013 5:02 AM
To: username@yourdomain.com
Subject: Fwd: LIGIA - Copies of Policies

Unfortunately, I cannot obtain electronic copies of the SPII policy.
Here is the Package and Umbrella,

and a copy of the most recent schedule.

LIGIA Simpson, 


4/02/13 Malware infected links in this message

From: noreply@boxbe.com [mailto:noreply@boxbe.com] 
Sent: Tuesday, April 2, 2013 4:27 AM
To: Application for shopper
Subject: Re: Rewarding part time job is available (Action Requested)

Hello Application for shopper,

Your message about "Rewarding part time job is available" was waitlisted.

Please add yourself to my Guest List so your messages will be delivered to
my Inbox. Use the link below.

Click here to deliver your message

Thank you,

falseemail@googlemail.com 
Powered by Boxbe -- "End Email Overload"

Boxbe, Inc. | 65 Broadway, Suite 601 | New York, NY 10006 
Privacy Policy


3/27/13 Malware infected links in this message

Subject: Ðàññûëêà  âàøåé ðåêëàìû! Äåëàåì òåñò!!! Ãàðàíòèÿ ðåçóëüòàòà!
Date: 2013-03-27 23:26
From: "E-mail marketing" falseaddress@rmo-maroc.com
To: customer@yourdomain.com

Ýôôåêòèâíûå ðåêëàìíûå ðàññûëêè ïî þð è ôèç ëèöàì 
Ìîñêâû èëè Ðîññèè! Öåíà 3 000ð ïî ëþáîé áàçå! Ðåçóëüòàò ãàðàíòèðóåì! Äåëàåì òåñò çà 1500 ðóáëåé íà 3 000 000 àäðåñîâ èç ëþáîé áàçû! Îò 3õ ðàññûëîê îòëè÷íûå

ñêèäêè! ! Ïåðâè÷íûå çàÿâêè ïðèíèìàåì  íà ýë  ïî÷òó:   org@yahoo.com


3/21/13 Malware infected links in this message

From: Data Processing Service
To: customer@yourdomain.com
Sent: Thursday, March 21, 2013 8:58 AM
Subject: ACH file ID "631.202" has been complete

ACH Processing Service

SUCCESS Information

We have successfully complete ACH file 'ACH2013-03-20-7.txt' (id '631.202') submitted by user 'customer' on '2013-03-20 19:22:18.1'.

FILE SUMMARY:
Item count: 16
Total debits: $36,794.00
Total credits: $36,79400

For addidional info    visit this link 


2/14/13 Malicious attachments included in this message

From: KeyBank KeyBank@info.key.com
To: customers@yourdomain.com
Subject: Security Update from KeyBank

Protect Yourself Against Online Fraud

To our valued clients,

This email is being sent to inform you that you have been granted a
NEW Digital Certificate for use with Key Total Treasury (KTT) Online.

The digital certificate is an additional security enhancement that is required
when performing Wire Transfers, ACH, Self Service or Foreign Draft
transactions. The certificate is applied for annually, and is stored on your PC. The digital certificate is linked to your login ID and PC to allow Key to authenticate the user.

Steps to Install NEW Digital Certificate

    1. Please open the attachment.

    2. An enrollment form will appear for you to register. Your name, email address, and user ID will be pre-filled in the appropriate boxes. On the
enrollment form you will need to enter a Challenge Phrase (which serves as
an additional password). Then click on "submit".

    3. After you click "submit", a window will appear asking you to confirm your email address. If your email address is correct, click OK and proceed to
step 4. If the email address is incorrect, click cancel, which will return you to
the enrollment screen. At this point, you will need to contact
Commercial Client Services Internet Support at 800-539-9039 to have your
email address corrected.

    4. Once you click OK to verify your email address, a window will appear
with the title "Generate A Private Key". If you would like information on the Private Key, click the button labeled "more info", otherwise click OK.

Note: Internet Explorer users will have the option to set their security level.
This should be pre-set to medium. If it is not, please change the security
level to medium then Click OK.

    5. This step is only for Firefox users. Another window will appear titled
"Setting up Your Communicator Password". This is an additional security
feature to protect your digital certificate from unauthorized use. At this point,
you will enter in a password, and re-enter it to confirm. Then click OK.

    6. The next screen that will appear will be a screen that says "Please wait while the Digital ID is being issued" This means that we are in the process of issuing the certificate.

    7. The final screen you will see is a confirmation that the certificate was issued to you. Click on the "Home" tab located near the top to return to the Internet application.

    8. You will need to close your browser and re-open it before using the digital certificate to access the Wire Transfers, ACH, Self Service or Foreign Draft Modules.

If you have any questions or concerns about new digital certificate, please contact your Client Administrator.

Member FDIC.2013 KeyCorp. All Rights Reserved.  KeyBank |
127 Public Square | Cleveland, OH, 44114 | 1-800-KEY2YOU 


2/11/13 Malware infected links in this message

Welcome to (Your ISP Name).

________________________________________

WEBMAIL LOG                    

Most Recent Webmail Log

Your account has been temporarily restricted because your account has
expired.

Click to update your Online Account << (Malicious Link)

________________________________________

©2006 (Your ISP Name). All Rights Reserved. Website


2/04/13 Malware infected links in this message

Click here if the e-mail below is not displayed correctly.
Follow us:                                                                      
Your Amazon.com            Today's Deals     See All Departments      

Respective Amazon.com Customer,         

Thanks for your order, customer@yourdomain.com!

Did you know you can view and edit your orders online, 24 hours a day?

Visit Your Account.

Order Information:
E-mail Address: customer@yourdomain.com
Billing Address:
261 CROSSING CRK N Road
Los Altos OH 47625-0469
United States
Phone: 614-670-3815
Order Grand Total: $ 84.99

Earn 3% rewards on your Amazon.com orders with the Amazon Visa Card. Learn More

Order Summary:
Details:
Order #:               W27-6760096-5626654
Subtotal of items:             $ 84.99
------
Total before tax:              $ 84.99
Tax Collected:    $0.00
------
Grand Total:       $ 80.00
Gift Certificates:               $ 4.99
------
Total for this Order:         $ 84.99

Find Great Deals on Millions of Items Storewide

We hope you found this message to be useful. However, if you'd rather not receive future e-mails of this sort from Amazon.com, please opt-out here.
© 2012 Amazon.com, Inc. or its affiliates. All rights reserved. Amazon, Amazon.com, the Amazon.com logo and 1-Click are registered trademarks of Amazon.com, Inc. or its affiliates. Amazon.com, 466 Larry St. N.,
Seattle, CA 93751-5123. Reference: 78262940

Please note that this message was sent to the following e-mail address: customer@yourdomain.com


1/24/13 Phishing Scam reported by the FTC

The Federal Trade Commission (FTC) is warning small businesses that an 
e-mail with a subject line "NOTIFICATION OF CONSUMER COMPLAINT" is
not from the FTC. The e-mail falsely states that a complaint has been filed with the agency against their company. The FTC advises recipients not to click on any of the links or attachments with the e-mail. The FTC's advice is to delete
the email. Learn more about how to prevent malicious software (malware).