Fanbox Scam – Calvin sent a tiny youtube video to you

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-18-2010

I don’t really know what the specifics are but these Fanbox phishing emails stink to high heaven. I get them all the time and sometimes from people who’ve tried to friend me on Facebook or LinkedIn. So I have no idea if it’s random email scrapping or these people really are that fucking stupid and sign up for this crap. Either way, avoid like the plague.

Calvin wants you see this tiny youtube video. Launch

This message was intended for clay@claybutler.com and was sent as a notification, invitation or reminder (digital goods subject to change in reminders) of an event initiated by Calvin using a third-party or platform application and may contain promotional materials and/or services for sale including digital goods received.

To control messages sent to or from you, your contacts and/or FanBox, click here.

Our offices are located at: FanBox – 255 G Street, Ste 723, San Diego, CA 92101
Click on the link and you get a very suspect prompt for your cell phone number:

fanbox video link scam
VN:F [1.9.17_1161]
Rating: 4.3/5 (20 votes cast)

You Have 1, 2, 3, 4, or 5 Urgent Unread Direct Messages on Twitter Biotch!

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 10-23-2010

So many urgent messages, so little time…

Hi, clay.

You have 1 unread direct messages from Twitter!
http://twitter.com/account/messages/clay/EX6BB-2LLCV-119376

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

—————————————-

Hi, clay.

You have 2 unread direct messages from Twitter!
http://twitter.com/account/messages/clay/3G8Y1-CIV6T-954179

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

—————————————-

Hi, clay.

You have 3 unread direct messages from Twitter!
http://twitter.com/account/messages/clay/TZW6V-X4188-885892

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

—————————————-

Hi, clay.

You have 4 unread direct messages from Twitter!
http://twitter.com/account/messages/clay/K72UI-DAERJ-426652

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

—————————————-

Hi, clay.

You have 5 unread direct messages from Twitter!
http://twitter.com/account/messages/clay/GKTN4-C4PTP-756575

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

VN:F [1.9.17_1161]
Rating: 3.6/5 (11 votes cast)

UPS Logistics Service Virus Scam

14

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 10-16-2010

These two kick ass. The gibberish below was supposed to be invisible to the recipient, Oooops! Plus they left the list of recipients visible instead of undisclosed. Sloppy, sloppy, sloppy.

Hello

The parcel was sent to your home address. And it will arrive within 3 business days.
More information and the tracking number are attached in document below.

Thank you for your attention.
UPS Customer.

UPS_Document_NR7524.zip

The day had begun so early that it was still morning when Melas and the Twins left the house of Pericles and took their way toward the Agora, which was the business and social center of Athens. Here were the markets where everything necessary to the daily life of the Athenians was sold. The Twins had never dreamed there were so many things to be found in the world. Not only were there fruits, meats, fish, vegetables, and flowers, but there were stalls filled with beautiful pottery or with dyed and embroidered garments gorgeous in color, and even with books. The books were not bound as ours are. They were written on rolls of parchment and were piled up in the stalls like sticks of wood. Around the marketplace there were arcades supported by marble columns, and ornamented by rows of bronze statues. In the center stood a magnificent altar to the twelve Gods of Olympus, whom the people of Hellas believed to be the greatest of their many Gods.

Good afternoon.

The parcel was sent to your home address. And it will arrive within 3 business days.
More information and the tracking number are attached in document below.

Thank you.
UPS Logistics Services.

UPS_Document_NR3429.zip

Luise (nach einem qualvollen Kampf mit einiger Festigkeit). Vater! Hier ist meine Hand! Ich will–Gott! Gott! Was thu ich? was will ich? –Vater, ich schwoere–wehe mir, wehe! Verbrecherin, wohin ich mich neige! –Vater, es sei! –Ferdinand–Gott sieht herab! –So zernicht ich sein letztes Gedaechtniss. (Sie zerreisst ihren Brief. ) Miller (stuerzt ihr freudetrunken an den Hals). Das ist meine Tochter! –Blick auf! um einen Liebhaber bist du leichter, dafuer hast du einen gluecklichen Vater gemacht. (Unter Lachen und Weinen sie umarmend. ) Kind! Kind! das ich den Tag meines Lebens nicht werth war! Gott weiss, wie ich schlechter Mann zu diesem Engel gekommen bin! –Mein Luise, mein Himmelreich! –O Gott! ich verstehe ja wenig vom Lieben, aber dass es eine Qual sein muss, aufzuhoeren–so was begreif ich noch. Luise.

VN:F [1.9.17_1161]
Rating: 4.8/5 (10 votes cast)

UPS Online Service. Error delivery address number 2896 – Virus Attachment!!!

4

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 10-16-2010

Awesome. They can’t find my house, but by golly, they have my email address and the address label. Apparently a whole shitload of packages couldn’t be delivered.

Dear client

Your parcel has arrived at the post office on October 2. Our Driver was unable to deliver the parcel to your address.
To receive a parcel you must go to the nearest UPS office and show your mailing label.
Mailing label is attached to this letter.

You need to print mailing label, and show it in UPS office to receive the parcel.

Thank you.
UPS International Services.

Label_UPS_Nr11373.zip

Dear client

Your parcel has arrived at the post office on October 5. Our Driver was unable to deliver the parcel to your address.
To receive a parcel you must go to the nearest UPS office and show your mailing label.
Mailing label is attached to this letter.

You need to print mailing label, and show it in UPS office to receive the parcel.

Thank you for your attention.
UPS Customer.

Dear client

Your parcel has arrived at the post office on October 6. Our Driver was unable to deliver the parcel to your address.
To receive a parcel you must go to the nearest UPS office and show your mailing label.
Mailing label is attached to this letter.

You need to print mailing label, and show it in UPS office to receive the parcel.

Thank you.
UPS Customer.

Dear client

Your parcel has arrived at the post office on October 9. Our Driver was unable to deliver the parcel to your address.
To receive a parcel you must go to the nearest UPS office and show your mailing label.
Mailing label is attached to this letter.

You need to print mailing label, and show it in UPS office to receive the parcel.

Thank you for your attention.
UPS Customer.

Dear customer

Your parcel has arrived at the post office on October 11. Our Driver was unable to deliver the parcel to your address.
To receive a parcel you must go to the nearest UPS office and show your mailing label.
Mailing label is attached to this letter.

You need to print mailing label, and show it in UPS office to receive the parcel.

Thank you.
UPS Customer.

VN:F [1.9.17_1161]
Rating: 4.4/5 (18 votes cast)

Apartment for rent… and a free virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 09-16-2010

Uh, ok I guess. I’m 44 and my parents are in their 60’s, but if I need them to co-sign…

Hi ,

We would like to proceed with your application with a couple of additional requests.

#1. Would it be possible to have your parents sign as guarantors on the lease?
#2. We need $20 to process the credit report.

Attached is a blank application for your guarantor to fill out.
Please let me know if you are still interested and we will process this right away.

Thank you very much for your patience.

Best Regards,
Karin Frederick

Attachment: Application to rent.html
VN:F [1.9.17_1161]
Rating: 3.5/5 (4 votes cast)

FedEx Tracking Number 300636756 and Bonus Virus Attachment!

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 09-13-2010

This ones pretty awesome. They can’t deliver my package because of an address error, so they send me the address label in a zip file to my email address which they magically have though they can’t find my house. And where do I go to pick up the package with the improper address. At my local post office of course! Because that’s were FedEx dumps all the shit they don’t know what to do with. Didn’t you know that?

Dear customer.

We were not able to deliver your package to your address.

Reason: Error in delivery address.

Attention!
Get your parcel in your local post office.
The postal label is attached to this e-mail.
We kindly ask you to print it and take it to the post office to pick up the package.

Thank you!
FedEx Express Freight.

Attachment: FedEx_postal_label_Nr5181.zip

VN:F [1.9.17_1161]
Rating: 3.6/5 (5 votes cast)

Fedex Invoice copy, I mean Fedex Tracking number, wait I mean Fedex Item Status

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-29-2010

This one rocks! Use a severely degraded JPG with a nonsensical phrase at the end to get past the spam filter. FAIL!

Comes with a cool zip attachment with a surprise virus inside! (FEDEXInvoice.zip)

fake_fed_ex_shipping_order

Report: Military needs new office to stem suicides

fake_fed_ex_shipping_order

Colombia volcano placed on red alert

fake_fed_ex_shipping_order

Obama to press: ‘We’re buying shrimp, guys’

fake_fed_ex_shipping_order

Cops: NY Cabbie Is Asked If He’s Muslim, Stabbed

VN:F [1.9.17_1161]
Rating: 4.0/5 (4 votes cast)

Vistaprint Canadian Tax Invoice Virus Thingy

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-29-2010

Ooops. I suspect the spammer didn’t expect it to render like this.

Vistaprint Canadian Tax Invoice ({DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}) Tax Invoice (Vistaprint USA)

Order Date: {DATE}
Invoice Date: {DATE}
Invoice #: {DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}{DIG}
Order #: 30CCM-8A588-0C9

Vistaprint USA, B.V.
Tax Registration # 85826 3296 RT0001

Note:  Vistaprint Tax invoices are provided per shipment. For a complete order view, please refer to your Order Confirmation email.

Attachment: Tax Invoice.html

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

Project Declaration (see attachment MSpec.zip)

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-23-2010

9 out of 10? Fuck you Norman! You can take you comments and your zip file and stick them up your animated GIF mother fucker!

From: Norman Dillard

Hello,

I have read and graded your project declaration.  
You received 9 out of 10 points on the paper.  
This means your paper has been approved and you can proceed as planned.  
Attached are my comments and/or suggestions for the paper.  
Please note, these are suggestions and it is up to you 
to decide if you want to use these or not.

Please let me know if I can assist you as you begin to work on your project.

Attachment: MSpeck.zip
VN:F [1.9.17_1161]
Rating: 5.0/5 (5 votes cast)

End Of Rotation…Bummer Dude!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-23-2010

“Rotation” is a sexual slang term among gay men to refer to a particularly harsh blow job that incorporates an “Indian rope burn” technique. MMC is a Roman themed bathhouse in the Castro and “feedback form” is slang for a sheet of Extacy. I tell you this because without that information this email doesn’t make much sense when you read it.

Thank you for such a great rotation.
Here's the feedback form you asked for.
I'll send you another email with BBQ dates so I can send it to Dr too.

Until, the next time I have a rotation at MMC- take care.

Attachment: Rotation Input Sheet.zip
VN:F [1.9.17_1161]
Rating: 4.2/5 (5 votes cast)

David Beckham Died…and Alicia Keys, Tom Cruise, Madonna, and Cameron Diaz…Oh, and 34 other people nobody really cares about.

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-23-2010

It’s so shocking when you get news like this. I just can’t believe it. I had lunch with Alicia yesterday and I was going to play golf with Beckham next week. And poof, just like that, they are gone. Alicia fell in love with Croatia while she was touring there and went back frequently just for the Goulash and čurke (blood sausages). She was so quirky that way.

Alicia Keys died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group
on a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

Please see attachment

news.html (http://paniplus.com.mx/1.html)

OMFG It gets worse! All the coolest people in the world were on that flight!

Gwen Stefani died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

J.K. Rowling died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

Beyonce Knowles died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

Jay-Z died along with 34 other people when the
Air Force CT-43 "Bobcat"  passenger plane carrying the group on
a trip crashed into a mountainside  while approaching the
Dubrovnik airport in Croatia during heavy rain  and poor visibility. 

Ronaldinho died along with 34 other people when the
Air Force CT-43  "Bobcat" passenger plane carrying the group on
a trip crashed into a  mountainside while approaching the
Dubrovnik airport in Croatia during  heavy rain and poor visibility. 

Tiger Woods died along with 34 other people when the
Air Force CT-43  "Bobcat" passenger plane carrying the group on
a trip crashed into a  mountainside while approaching the
Dubrovnik airport in Croatia during  heavy rain and poor visibility.

Jennifer Aniston died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

Angelina Jolie died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.

Justin Timberlake died along with 34 other people when the
Air Force CT-43 "Bobcat" passenger plane carrying the group on
a trip crashed into a mountainside while approaching the
Dubrovnik airport in Croatia during heavy rain and poor visibility.
VN:F [1.9.17_1161]
Rating: 4.4/5 (8 votes cast)

Residency Happy Hour: SOP_POLICIES

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-23-2010

Doh! I totally forgot all about this. Thanks for the reminder LL!

P4s (and anyone else interested) -

Reminder about Happy Hour tomorrow from 4:30 - 5:25 in
room 1102 (SIUe) and 109 (Springfield).

This is the first of several discussions about
post graduate training. Attached is an updated schedule.

Hope you can make it. LL

Attachment: ResidencyPrep.zip
VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Employee Orientation (AKA: Employee Dis-orientation “NH ESS Access Guidelines (2).zip”)

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Fuck you Chrystal, Jenna, Ken and Mariana. You sent this on the 11th and my first day of work isn’t until the 19th! WTF! I’ll be damned if I’m going to wait until January 2011 to enroll in the ESS program. That’s the main reason I took the job. See you on the 19tht when I go on a fucking rampage and gun down your whole redundant, over-staffed HR department biotch!

Hi

We will be scheduling new employee orientation in the next couple of weeks, however I wanted you to have an opportunity to review our benefits ahead of time since you only have 30 days from your hire date to enroll in our benefits.  I have attached the information on how you can access our benefit information on line and how to enroll in the plan options through Employee Self Service (ESS).
You must enroll in our benefits no later than August 15, 2010 or your next opportunity to enroll would be January 1, 2011.  I will return from vacation on Monday, August 16 so if you have any questions regarding the benefits I can assist you at that time which is before the deadline of August 16, 2010.

I will be here today till 5pm if you have any questions.

Chrystal Rollins | Human Resources Coordinator

Hi

We will be scheduling new employee orientation in the next couple of weeks, however I wanted you to have an opportunity to review our benefits ahead of time since you only have 30 days from your hire date to enroll in our benefits.  I have attached the information on how you can access our benefit information on line and how to enroll in the plan options through Employee Self Service (ESS).
You must enroll in our benefits no later than August 15, 2010 or your next opportunity to enroll would be January 1, 2011.  I will return from vacation on Monday, August 16 so if you have any questions regarding the benefits I can assist you at that time which is before the deadline of August 16, 2010.

I will be here today till 5pm if you have any questions.

Jenna Elmore | Human Resources Coordinator

Hi

We will be scheduling new employee orientation in the next couple of weeks, however I wanted you to have an opportunity to review our benefits ahead of time since you only have 30 days from your hire date to enroll in our benefits.  I have attached the information on how you can access our benefit information on line and how to enroll in the plan options through Employee Self Service (ESS).
You must enroll in our benefits no later than August 15, 2010 or your next opportunity to enroll would be January 1, 2011.  I will return from vacation on Monday, August 16 so if you have any questions regarding the benefits I can assist you at that time which is before the deadline of August 16, 2010.

I will be here today till 5pm if you have any questions.

Ken Lovett | Human Resources Coordinator

Hi

We will be scheduling new employee orientation in the next couple of weeks, however I wanted you to have an opportunity to review our benefits ahead of time since you only have 30 days from your hire date to enroll in our benefits.  I have attached the information on how you can access our benefit information on line and how to enroll in the plan options through Employee Self Service (ESS).
You must enroll in our benefits no later than August 15, 2010 or your next opportunity to enroll would be January 1, 2011.  I will return from vacation on Monday, August 16 so if you have any questions regarding the benefits I can assist you at that time which is before the deadline of August 16, 2010.

I will be here today till 5pm if you have any questions.

Mariana Price | Human Resources Coordinator

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

You Are No Longer Welcome at Our Thursday Night Fun Bunch. Please Get Help.

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Ok guys, get this straight. You can’t find the playoff set up because I never sent it to you. The rest of the gang discussed it and you are no longer invited to our Thursday Night Fun Bunch activities. Once you’ve proven you can control your drinking then maybe you’ll be invited back. Until then we highly recommend AA.

I was wondering, whenever you get a chance, if you could e-mail me the rules and regulations as well as playoff setup that we received a few weeks ago for the Thursday Night Fun Bunch? We can’t find the copy you gave us anywhere.
Thanks clay,
Naomi Smart

I was wondering, whenever you get a chance, if you could e-mail me the rules and regulations as well as playoff setup that we received a few weeks ago for the Thursday Night Fun Bunch? We can’t find the copy you gave us anywhere.
Thanks clay,
Bertie Yarbrough

I was wondering, whenever you get a chance, if you could e-mail me the rules and regulations as well as playoff setup that we received a few weeks ago for the Thursday Night Fun Bunch? We can’t find the copy you gave us anywhere.
Thanks clay,
Ty Whitfield

I was wondering, whenever you get a chance, if you could e-mail me the rules and regulations as well as playoff setup that we received a few weeks ago for the Thursday Night Fun Bunch? We can’t find the copy you gave us anywhere.
Thanks clay,
Joann Lambert

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Another candidate brought to you by….

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

For the last time, the position is closed. Please stops sending me your resumes! And by the way Hubert and Alexis, you need to stop applying for the same exact jobs. It looks a bit suspicious.

Hi,

This is Alexis Johns working as a Technical Team Lead in IBM with over 10 years of solid mainframe development experience. I am confident that my skills will match for this requirement.

Please find the resume as a word attachment. I am available at 404-353-1786 for a discussion. BTW I am in EST time zone.

Looking forward to work with you.

Thanks
Alexis

Attachment: resume.zip

———————————————

Hi,

This is Hubert Blanco working as a Technical Team Lead in IBM with over 10 years of solid mainframe development experience. I am confident that my skills will match for this requirement.

Please find the resume as a word attachment. I am available at 404-353-8387 for a discussion. BTW I am in EST time zone.

Looking forward to work with you.

Thanks
Hubert

Attachment: resume.zip

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

Lance Armstrong Paper – Dude, Wrong Assignment!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Smooth move Nickolas! You’re supposed to be working on the Michael Jordan paper not the Lance Armstrong one you doofus. Looks like you’re getting an F on this one sucker.

Hello,

As you know, I car-pool with Jayesh due to the fact that my car is being
repaired.  And now his car is in the shop.  I am unable to make it to todays
class.  I live across the street from the campus and can drop off a hard copy
of my paper if you like.  A copy is also attached.

Thank you and I apologize,

Nickolas Major
Finance/Marketing Intern

Attachment: lance armstrong.zip

VN:F [1.9.17_1161]
Rating: 4.5/5 (2 votes cast)

First Birthday Invitation (invitation.zip…Duh, it’s a virus)

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Fuck her elder brother’s imaginary child. I got a plane to Nigeria to catch!

Hello All,

Please treat this as my personal invitation , Grace the occasion with your presence and bless my elder brother’s daughter on her first birthday.

Date: Sunday, August 15

Please find the venue details in the attachment.

Thanks,

Jeannine Tanner

Attachment: invitation.zip

VN:F [1.9.17_1161]
Rating: 2.8/5 (5 votes cast)

Financials (financials.zip) – Do I have to Tell You It’s Like Totally a Virus?

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

I’m glad Jesus was finally able to attach the files. We all know how difficult that can be.

Hi,

I was able to attach the financials.  Please call if you have any questions.
Thanks,

Jesus Goldman

Attachment: financials.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Wedding Contract for Hotel Viking (right next to Hotel California)

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Ah yes, the infamous Hotel Viking. Next time we’re definitely going with the exclusive rental. Our last wedding was in the non-exclusive rental area and all the seats were already taken by squatters before the reception started….and then they ate all our food! Total bullshit!

Hello,

Attached are the contract and credit card authorization for your review and signature. Please sign/initial the highlighted areas and return to me at your earliest convenience. I think I covered everything except the brunch, which can be added at any time. We typically charge $500 for a non-exclusive rental, meaning that you and your guests would have a private area, but it would still be open to the public. If you prefer an exclusive rental (closed to the public) the rental is $1,000.

Thanks!

Dee Hurley | Senior Catering Sales Manager

The Hotel Viking

Noble House Hotels & Resorts

One Bellevue Avenue | Newport, RI  02840

email: ninjasxd@rlmlawfirm.com

Office 401.848.4809 | Fax 401.849.0749 |

Attachment: Wedding 8-6-11.zip

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

Status on DVD’s and Blu-Rays Burning Job Thingy

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

Arggg. I’ve told Antonia like a million times I don’t have a DVD player…VHS only! Plus I’ve seen enough of his wife ( wink,wink, nudge, nudge…know what I mean? Say no more!)

Hi,

I have your DVD’s ready but I’m burning the Blu-Ray’s today. I expect them to be ready for tomorrow.

Here is a pictures of my wife and I at my wedding since you had mentioned you’d like to see a picture.

Antonia

IMG_1746.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

Picture sizes (i.e. pricing.zip with really cool virus)

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-16-2010

I’m digging this new series of virus attachments in a zip file. I supposed if I had just inquired about print sizes from someone then this would trip me up…but anyone else…hmmmm, not so sure.

Attached is an example of pricing to give you an idea of what things cost.  Below is a complete list of standard print sizes:

20×24
20×30
22×28
24×24
24×30
24×36
30×30
30×40

Let me know if you have any questions.

Thank you

Bernardo Boykin

pricing.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

Zappos:Your Order Confirmation That Looks Almost Real!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-09-2010

Now we’re talking. A realist looking “from” address (customerservice@zappos.com) and stealing the images directly from the Zappos servers so the image URL’s look authentic. Now if they could just fix their little glitch with the ASCII characters (ÒÇ) they’d really have something. This one takes you to kumprepami.com/x.html so you can install a really killer virus. Your choice. Just saying.

fake zappos email order spam

Text:

Zappos.com     FREE Shipping Both Ways ÒÇ 365-Day Return Policy
CUSTOMER SERVICE 1-800-927-7671 ÒÇ 24 Hours & 365 Days A Year
Shoes     Clothing     Bags And Handbags     New Arrivals     Clearance     Brands     More Departments

Your Order Confirmation

Hello

We are delighted to inform you that your order with Zappos.com has been received successfully and is in the process of being carefully plucked from our shelves.

Here is your order reference number:
Order Reference Number: 27312388

Your Order Information:
Item Ordered: 1
Total Charged: $182.00

Your Billing and Shipping Information:
Shipping Method: Next Day Shipping
Date Ordered: Mon, 9 Aug 2010 23:02:55 +0200

Your Gift Message:
Your Order Summary:
Promiscuous: Heida     Promiscuous: Heida
SKU# 7635167
Size: 10
Color: Purple
Width: B – Medium     $502.00
Subtotal (1 Item):
Next Day Shipping:
Sales Tax:
63.00
25.00
0.00
Total Charged: $052.00

VN:F [1.9.17_1161]
Rating: 4.0/5 (2 votes cast)

Thank you for registering with IKEA! And a big fuck you to you too!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-09-2010

Ok. I give up. Just assume any order/confirmation you get from ANY company over the next couple of weeks is a fake. These guys are so fucking prolific I just can’t keep up. This is a fake Ikea one and it takes you to clinique-fuer-schoene-haut.de/x.html.

It seems that the x.html efile extension is all the rage with virus spam these days.

fake ikea registration spam

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

You have received a file via YouSendIt…Wait it’s really a virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-09-2010

Interesting concept using YouSendIt as a ruse to get you to open a virus attachment.

Tod Lutz  has sent you the following via YouSendIt

File attached to this letter.

YouSendIt, Inc. | Privacy Policy
1919 S. Bascom Ave., Campbell, CA 95008

Ayttachment: YouSendIt_reader.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

Software QA Engineer – 3+ Experience…with viruses and stuff ;)

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-07-2010

Wow, Rahul is a totally excellent Software Engineer. His virus attachment executed flawlessly. Good job Rahul!

DEAR SIR\ MADAM,

I am confident that my combination of practical knowledge and solid
educational background will provide your office with a highly productive
employee.

I am working as a QA Engineer with* *PTC software (INDIA)Pvt Ltd. , PUNE**
with total work Ex
of *3 years*

I received *B.E (mechanical) in July’2006* from M.I.T Mandsaur (R.G.P.V.
BHOPAL) (M.P) with *First Class 70%*. I have well-developed written and oral
communication skills which will enable me to communicate with the other team
members and people outside the organization effectively.

I would welcome the opportunity to discuss my suitability for the position.
Please find the attached copy of my resume.
Thank You.

Sincerely
Rahul Bhoraskar – Software QA Engineer
PTC Softwares : Product Lifecycle Management (PLM) Software Solutions
*Mobile: 9766678612*

Rahul_Bhoraskar.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Final Moments of Air France…Please open my virus attachment…pretty pleeeeeease!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-07-2010

WTF? Have the spammer finally lost their collective minds?

HI
Please have a look at these photos from Air france crash.
Avnish
18930071889

Jillian

Final_moments_of_Air_France_-_Incredible_Photos.zip

VN:F [1.9.17_1161]
Rating: 3.7/5 (3 votes cast)

Solve this if you could…!!!! The Ultimate Virus Attachment Challenge!!!!!!

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-07-2010

This one rocks! A virus attachment that’s presented as a challenge. Too funny. Kind of like a “bet you can’t stab your hand with this knife” dare.

Hi,

For all Math’s champs, Accounting Experts & Number Numbssss…
(including future champs too)

Find the 6th Number

1, 2, 6, 42, 1806, ____?

6th number is the password of the attachment.

If u could solve it…. add your Name in the attached file…& pass
on..to your friends & colleagues!!
You will find my name also in it 😉

Have solving…!!

Do reply me if you solve it, I will be happy to see your name in XLS sheet.

Thanks & Regards,

Genaro Poe
Engineer – Application Development
CSC, India (Indore)

Contact me @ Solved.zipSolved.zipSolved.zipSolved.zipSolved.zip-Solved.zipSolved.zipSolved.zipSolved.zipSolved.zip

“Love The Heart That Hurts You, But Never Hurt The Heart That Loves You”
“I lik 2 walk in d rain as no 1 can c me crying”
“Live life to fullest coz u never know whats around the next corner”
“Everything happens for a reason. Nothing happens by chance or by means of luck .. ”
“If you wanna un-subscribe to my mails then just send a blank mail with subject UN-SUBSCRIBE”

VN:F [1.9.17_1161]
Rating: 3.3/5 (7 votes cast)

Old Navy Shipment Notification for Order #44485 Virus Thingy

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-07-2010

The links on this fake Old Navy receipt take you to forumjogging.be/x.html. where a virus will be installed that will melt your C drive, wipe out your registries, steal all of your contacts from your email client, and then finish off with a cocaine fueled rampage through your house to destroy all your furniture.

old navy fake order virus spam

Dear clay@abnormalgrowth.org,

Thanks for shopping at oldnavy.com.

Your order #13SXXFM has been shipped.

You may check the status of your order by clicking here, or by clicking the Order Status link at the top of any page on our site.
Here’s a summary of the order you placed on Jun 13, 2010 01:29:00 EDT:
Ship To
Ivars Bezdechi
1624 Plantation Way
El Cajon, CA 92019-3603

Shipped Today
Package #: 00004200100099919453
Ship Carrier: UPSN
Ship Type: GROUND
Tracking #: 1ZF103440368938048

Item
Description
Size Unit
Price
Qty Total Return
Type

Men’s Striped Western Shirts
Brown Stripe
XL 19.50 1 19.50

Men’s Beach-Graphic Tees
Ink Blue
XL 8.00 1 8.00
Summary of Charges for Package # 00004200100099919453

Shipment Subtotal: 27.50
Shipping & Handling: 7.00
Tax: 3.02
Shipment Total: 37.52
Payment Info

VISA: XXXXXXXXXXXX4954 $37.52
This email is for your records only and cannot be used as a receipt for in-store returns. To receive a full refund, you must bring the invoice included in your shipment to the store.

If we may be of further assistance, please contact us at custserv@oldnavy.com or 1-800-OLD-NAVY (1-800-653-6289).

New: Our return policy has changed. Return or exchange oldnavy.com merchandise within 45 days of the original online purchase date. To view the entire online returns and exchanges policy, CLICK HERE.

Sincerely,

oldnavy.com Customer Service

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

NYCEDC Employment Application Virus Thingy

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-07-2010

We’re living in strange days indeed. NYCEDC stands for New York City Economic Development Corporation. The only way I can see this working is if someone actually did just talk to Helena Burke about a job. Or perhaps the spammers hope that curiosity will get the best of you and you’ll open the zip file?

Hello,

It was nice talking with you yesterday. Attached is the NYCEDC Employment Application. It’s an interactive PDF form so you should be able to type directly into it. If you could bring a completed copy with you to the interview, that would be great.  Please let me know if you have any questions.

Best,
Best,
Helena Burke

Attachment : File_13671.zip

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

Proposal: Prix fixe menus and a credit card authorization form virus thingy

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-06-2010

It’s getting weirder by the minute. A virus attachment disguised as prix fixe menu with mismatched  names and email address. Huh?

Hi ,

It was a pleasure to meet you last night, and thank you ! As per our conversation, please find attached a preliminary proposal, including various prix fixe menus and a credit card authorization form. Also attached is our current wine list, in case you would like to pre-select any wine for this event. Please let me know if you have any questions, as it would be my pleasure to assist you.

Thanks and best,

Cynthia

Sophia Pool

Event Coordinator

Benjamin Steakhouse

52 E 41st Street

New York, NY 10017

T: 212-297-9177

F: 212-297-9146

commanderse@rothracing.com

Attachment: CURRENT_WINE.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

Your Target.com order has shipped – More Bullshit Virus Scams

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-06-2010

Fancy! But still lagging with a lame from email (cubicw@richards-zeta.com). Links take you to togoandnogo.co.uk/x.html…and you know that can’t be good.

fake target order scam

clay@picslive.com, we thought you’d like to know that we shipped your items today and that your order is now complete. Please review your shipment information below.

Order Number: 602-6598251-4576202

Shipped to:
Maya King King
Wish List or Registry
address hidden for
privacy           Shipping method(s):
UPS Standard Shipping (3-5 business days)
Track your package
Please note that tracking information may not be available immediately.

Items in this shipment:

No picture available         Miracle Blade 11-pc. Knife Set

Quantity Shipped: 1
$19.99

Item Subtotal:           $19.99
Shipping:           $4.99
Gift Wrap:           $5.95
Sales Tax*:           $2.59
ORDER TOTAL:           $33.52

You might also like:
temporary price cut

Chefmate 51-pc. Kitchen Gadget Set

$24.99
free shipping

J.A. Henckels International Fine Edge Synergy 15-pc. Block Set
$69.99

Kitchen 3-pc. Cutting Board Set
$19.99

Hampton Forge Continental 15-pc. Cutlery Set
$49.99

Oneida Stainless Steel Performance 14-pc. Knife Set with Block
$69.99

Architec Gripperwood Wooden Cutting Board – Set of 2
$19.99

This e-mail was sent from a notification-only address that cannot accept incoming e-mail. Please do not reply to this message.

If you would like to print a gift receipt or need to return an item, you can do this and more in My Account. If you have other questions about your order, please visit our Help department. Please note that the refund value for each item returned will be reduced to reflect value of free gift or discount.

Target items are sold by Target.com (a division of Target Corporation) or ITC Sales and Procurement, LLC(a subsidiary of Target Corporation).

Prefer not to receive HTML e-mails? Visit My Account to change your e-mail format preferences.

Please be aware that items in this order may be subject to California’s Electronic Waste Recycling Act. If any items in this order are subject to that Act, the seller of that item has elected to pay any fees due on your behalf.

Please note that a signature may be required for the delivery of any package. If no one will be available to sign for this package, you may wish to make alternate delivery arrangements with the carrier.

Sale prices are available for a limited time and may end without notice.

*Why has sales tax been applied? See tax and seller information for order 602-6598251-4576202.

Shipped to:
Maya King King
Wish List or Registry
address hidden for
privacy
Shipping method(s):
UPS Standard Shipping (3-5 business days)
Track your package
Please note that tracking information may not be available immediately.

Items in this shipment:
No picture available Miracle Blade 11-pc. Knife Set

Quantity Shipped: 1
$19.99

Item Subtotal: $19.99
Shipping: $4.99
Gift Wrap: $5.95
Sales Tax*: $2.59
ORDER TOTAL: $33.52

You might also like:
temporary price cut

Chefmate 51-pc. Kitchen Gadget Set

$24.99

free shipping

J.A. Henckels International Fine Edge Synergy 15-pc. Block Set

$69.99

Kitchen 3-pc. Cutting Board Set

$19.99

Hampton Forge Continental 15-pc. Cutlery Set

$49.99

Oneida Stainless Steel Performance 14-pc. Knife Set with Block

$69.99

Architec Gripperwood Wooden Cutting Board – Set of 2

$19.99

This e-mail was sent from a notification-only address that cannot accept incoming e-mail. Please do not reply to this message.

If you would like to print a gift receipt or need to return an item, you can do this and more in My Account. If you have other questions about your order, please visit our Help department. Please note that the refund value for each item returned will be reduced to reflect value of free gift or discount.

Target items are sold by Target.com (a division of Target Corporation) or ITC Sales and Procurement, LLC(a subsidiary of Target Corporation).

Prefer not to receive HTML e-mails? Visit My Account to change your e-mail format preferences.

Please be aware that items in this order may be subject to California’s Electronic Waste Recycling Act. If any items in this order are subject to that Act, the seller of that item has elected to pay any fees due on your behalf.

Please note that a signature may be required for the delivery of any package. If no one will be available to sign for this package, you may wish to make alternate delivery arrangements with the carrier.

Sale prices are available for a limited time and may end without notice.

*Why has sales tax been applied? See tax and seller information for order 602-6598251-4576202.

VN:F [1.9.17_1161]
Rating: 5.0/5 (4 votes cast)

Chase -Thank you for scheduling your online payment virus scam

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-06-2010

Getting better all the time. Now if they would just get better at spoofing the from email (this one was wieldingn20@rodneyb.com…Doh!) then they could really do some damage. The links take you to nlcottrell.net/x.html where I’m sure all sorts of wickedness awaits you.

fake chase autopay scam
Dear clay@claybutler.com,

Thank you for scheduling your recent credit card payment online. Your ($USD) $117.00 payment will post to your credit card account (CREDIT CARD) on 08/06/2010.

Now that you’re making your payment online, are you aware of all the convenient ways you can manage your account online?

Just log on to www.chase.com/creditcards today. Using the “I’d like to…” links for your credit card account, you can access more than a dozen features, including links to:

* See statements – Choose to stop receiving paper statements, and see up to six years of your statements online.
* See automatic payments – Set up monthly payments to be made automatically.
* Transfer a balance – Transfer a balance to your credit card account.
* Go to Personalized Alerts – Schedule Alerts to remind you of key account activity.

You can also see past payments you’ve made online by logging on to www.chase.com/creditcards and clicking “See/cancel payments” under “I’d like to …”

If you have questions, please call the Customer Service number on the back of your credit card.

Thanks again for using online payments.

Sincerely,
Cardmember Services

E-mail Security Information

E-mail intended for your account ending in: 2229.

If you are concerned about the authenticity of this message, please click here or call the phone number on the back of your credit card. If you would like to learn more about e-mail security or want to report a suspicious e-mail, click here

Note: If you are concerned about clicking links in this e-mail, the Chase Online services mentioned above can be accessed by typing www.chase.com/creditcards directly into your browser.

ABOUT THIS MESSAGE:
This service message was delivered to you as a Chase Credit Card customer to provide you with account updates and information about your card benefits.

If you want to contact Chase, please do not reply to this message, but instead go to www.chase.com/creditcards. For faster service, please enroll or log in to your account. Replies to this message will not be read or responded to.

Your personal information is protected by state-of-the-art technology. For more detailed security information, view our Online Privacy Policy. To request in writing: Chase Privacy Operations, 451 Florida Street, Fourth Floor, LA2-9376, Baton Rouge, LA 70801

® 2010 JPMorgan Chase & Co.

VN:F [1.9.17_1161]
Rating: 4.5/5 (4 votes cast)

Your Order with Amazon.com…Uh, Wait, I Mean Your Social Security Statement

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-05-2010

Ooops. Sloppy, sloppy sloppy.I guess when you’re a scumbag retard sending out millions of infected emails you’re bound to mix up your scams now and then.

Subject: Your Order with Amazon.com

Due to possible calculation errors, your annual Social Security statement may contain errors.

Open attachment to review your annual Social Security statement.

———————————————————————–

This e-mail has been sent from an auto-notification system that cannot accept incoming e-mail.

Attachment; statement.zip

VN:F [1.9.17_1161]
Rating: 5.0/5 (3 votes cast)

Tax Commissar: You are in a higher tax bracket biotch!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-05-2010

Yeah, I’m rich, but I just didn’t know it!

Dear taxpayer,

The Federal income tax is a progressive tax, meaning that the more you earn, the higher your tax rate. Your tax rate depends not just upon your taxable income, but also upon your filing status (single, married filing jointly, etc.).

You’re in a higher tax bracket because:
– your annual income for the last tax year has increased.

Please review your annual tax report immediately at:
(Please find attached file – tax report.zip)

VN:F [1.9.17_1161]
Rating: 3.0/5 (2 votes cast)

“Your Internet Access is Going to Get Suspended” Declares The Internet Service Provider Consorcium

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-04-2010

Apparently, due to the economy, The Internet Service Provider Consorcium has been forced to eliminate spell check from it’s budget.

Your internet access is going to get suspended

The Internet Service Provider Consorcium was made to protect
the rights of software authors, artists.
We conduct regular wiretapping on our networks, to monitor criminal acts.

We are aware of your illegal activities on the internet 
wich were originating from

You can check the report of your activities in the past 6 month 
that we have attached. We strongly advise you to stop your activities 
regarding the illegal downloading of copyrighted material of your 
internet access will be suspended.

Sincerely
ISPC Monitoring Team

Attachment: report.zip
VN:F [1.9.17_1161]
Rating: 5.0/5 (5 votes cast)

Subject: Hello/Report (report.zip) – Shortest Virus Attack Explaination Ever (at least this month)

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-03-2010

Short and sweet.

Subject: Hello
Please find attached the new Word document.
report.zip
VN:F [1.9.17_1161]
Rating: 4.8/5 (4 votes cast)

Your Flight Ticket 28163 – Fake Midwest Airlines Invoice Thingy

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 08-02-2010

What? I didn’t order these tickets! I’m going to open up this zip file right now and a demand a refund. Fuuuuck! It’s really a virus! I’m such an idiot!

Good morning,
Thank you for using our new service “Buy airplane ticket Online” on our website.
Your account has been created:

Your login: clay@claytowne.com
Your password: CFDSAQZ1

Your credit card has been charged for $780.35.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!
Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Midwest Airlines

Invoice_viewer.zip

VN:F [1.9.17_1161]
Rating: 4.6/5 (7 votes cast)

Welcome to “Joomla!”…Enjoy Your New Virus!

10

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-26-2010

I guess I’m supposed to go “Hey, I didn’t sign up for Joomla” and then click on the  most obviously bogus hyperlink. Usually they hide the true nature of these links. Must be getting cocky. Maybe next time they’ll send one that just says “click here to infect your computer”. I bet their click through rate would be about the same anyway.

Welcome to Joomla! forums

Please keep this e-mail for your records. Your account information is as
follows:

----------------------------
Username: haymixer

Board URL: http://cambridge-narrows.ca/
----------------------------

Please visit the following link in order to activate your account:

http://cambridge-narrows.ca/

Your password has been securely stored in our database and cannot be
retrieved. In the event that it is forgotten, you will be able to reset it
using the email address associated with your account.

Thank you for registering.

--
Thanks,
Joomla! Community Forum

Another version

Welcome to Joomla! forums

Please keep this e-mail for your records. Your account information is as
follows:

----------------------------
Username: clay

Board URL: http://restlessstreet.com/
----------------------------

Please visit the following link in order to activate your account:

http://restlessstreet.com/

Your password has been securely stored in our database and cannot be
retrieved. In the event that it is forgotten, you will be able to reset it
using the email address associated with your account.

Thank you for registering.

--
Thanks,
Joomla! Community Forum
http://restlessstreet.com/
VN:F [1.9.17_1161]
Rating: 3.4/5 (5 votes cast)

An unauthorized transaction billed from your bank account…Yeahhhh right.

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-23-2010

This one tries to install the same virus as this previous post. This one takes you to lonngren.co.uk who apparently had their account hacked. Ho-hum, same ole’ same ole’.

Dear bank account holder,

The ACH transaction, recently initiated from your bank account, was rejected by the Electronic Payments Association. Please review the transaction report by clicking the link below:

Unauthorized ACH Transaction Report

——————————————————————

Copyright ©2010 by NACHA – The Electronic Payments Association

VN:F [1.9.17_1161]
Rating: 4.8/5 (5 votes cast)

Thank you for registering with ImageShack – Enjoy Your Virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-23-2010

Poor Foresight, they had their site hacked and now it’s distributing viruses. Bummer dude.

---------------------------------------------------
Thank you for registering with ImageShack.
---------------------------------------------------

Your username: sakaicm
Your password: 09900438
Your registration link: http://www.forsight.com.au/

Please read this email carefully, it contains important 
information about your ImageShack account.

Please do not reply to this email, this mailbox is not checked. 
To report problems use support section of the web site.

---------------------------------------------------
HOW DO I LOGIN?
---------------------------------------------------

Click the 'Login' button located at the top of ImageShack pages in order to login.
Type here your username and password located in this email.

Once you are logged in, you will be presented with your Image Panel.


---------------------------------------------------
HOW CAN I CHANGE MY PASSWORD?
---------------------------------------------------

If you want to change your password, use the following link:
http://www.forsight.com.au/
If you have forgot your password, use the following link:
http://www.forsight.com.au/

---------------------------------------------------
HOMEPAGE
---------------------------------------------------

Your friends can access your public images and 
slideshows at http://www.forsight.com.au/

---------------------------------------------------
COMMON QUESTIONS
---------------------------------------------------
Answers to common questions: http://www.forsight.com.au/

Sincerely,
The ImageShack Team
VN:F [1.9.17_1161]
Rating: 4.3/5 (12 votes cast)

Wire Invoice Verification – Ye Old Trojan Virus Executable

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-22-2010

Hmmmm, I know I accidentally wired $11,372 to a total stranger yesterday (shit happens) but definitely not $11,448.  They must have the wrong person. What a weird coincidence!

Hello. We have received an $11,448 wire transfer from your company. We have no idea how this transfer was placed in our account but your email address was in the note for beneficiary section. Attached is a copy of the incoming transfer provided by our bank.Please reply and let us know for what services was the transfer sent to our account…

http://sonda.co.kr/rep_request.exe

VN:F [1.9.17_1161]
Rating: 4.0/5 (3 votes cast)

Amazon.com: Please verify your new e-mail address..Is a Virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-18-2010

Poor Amazon – so many spammers and so little time to chase them all. This one takes you to caveidea.ru:8080/index.php?pi=d=3D14 where one would assume, from past exerience, that a script will try to install a trojan virus. Either that or give you cookies and milk and a pat on the back. On the fence on that one.

Verify Your New E-mail Address

Dear clay@claytowne.com,

You recently changed your e-mail address at Amazon.com. Since you are a subscriber of Amazon.com Delivers E-mail Subscriptions, you will need to verify your new e-mail address

Please verify that the e-mail address clay@claytowne.com belongs to you. You can click on the link below to complete the verification process.

Alternatively, you can type or paste the following link into your Web browser:
http://www.amazon.com

fake amazon email notice spam

VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

Scan from a Xerox WorkCentre Pro #5004716…Spam+Virus=Trouble

24

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-16-2010

Odd little virus trick. The file is XeroxN4495.zip and was sent by “Guest” so you know it’s trouble. I guess I’m supposed to be impressed that it was made using “Xerox WorkCentre Pro”.

Please open the attached document. It was scanned and sent to you using a Xerox
WorkCentre Pro.

Sent by: Guest
Number of Images: 1
Attachment File Type: ZIP [DOC]

WorkCentre Pro Location: machine location not set
Device Name: XRX4723AA7ACDB49135879

For more information on Xerox products and solutions, please visit
http://www.xerox.com

VN:F [1.9.17_1161]
Rating: 4.4/5 (11 votes cast)

FROM Gwendolyn Coulter or Roslyn Flores or…

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-15-2010

Uh, ok. I don’t know you…but ok, since you’re asking. Hey, this file called “document.zip” is really a virus! You are so mean Gwendolyn Coulter!

PLEASE,

KINDLY READ THE ATTACHED DOCUMENT AND GET BACK TO ME.

Gwendolyn Coulter


Version #2

PLEASE,

KINDLY READ THE ATTACHED DOCUMENT AND GET BACK TO ME.

Roslyn Flores

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Your Funds Will Be Transfered – Laziest Virus Attack Ever

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-15-2010

What a lazy and totally sad attempt to infect my computer with a virus. The amount doesn’t even make sense…$69.292?

Hello

I am able to complete the funds transfer late night

$69.292 was sent with MTCN VALUE 034 439 0031

Copies of the payment is being attached

Version #2

Hello

I am able to complete the funds transfer late night

$76.541 was sent with MTCN VALUE 113 496 5561

Copies of the payment is being attached
VN:F [1.9.17_1161]
Rating: 5.0/5 (3 votes cast)

Postal Tracking #FDD4Q22514LDU4N – Fake UPS Tracking Code

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-13-2010

This one comes with an HTML attachment (FDD4Q22514LDU4N .html) that probably does all sorts of wicked cool stuff that I’m not eager to find out about. Plus look at that date. What lazy ass spammers. At least update your code now and then. Recycling old code is not very professional.

Hello!

We were not able to deliver postal package you sent on the 14th of March in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at our office.

Your United Parcel Service of America
VN:F [1.9.17_1161]
Rating: 3.5/5 (6 votes cast)

Western Union Transfer MTCN:2048922446 is Like Totally Fake and Stuff

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-13-2010

The file  “048922446.html” is of course malicious. Does it launch a virus? Not sure. Does it matter? Not really. This ones aimed at greedy bastards who think they’re going to get some free money by claiming cash they didn’t even send.

Western Union Transfer MTCN: 2048922446

Dear customer! The money transfer you have sent on the Tue, 13 Jul 2010 13:53:53 -0800 wasn’t collected by the recipient. According to the Western Union regulation the transfers which are not collected in 15 days are to be returned to sender. To collect money you need to print the invoice attached to this e-mail and visit the nearest Western Union agency. Thank you!

VN:F [1.9.17_1161]
Rating: 3.6/5 (15 votes cast)

User hoaxingyw7 suggests you to become friends on YouTube – Eeeek it’s a Virus!

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-08-2010

Now of course this is a drive by trojan virus attack. The user’s name is “Hoaxing” after all. Weird to see malicious spamming scum balls like this act all cheeky. The attachment “Youtube Message.html” launches a site that tries to run a java executable and install a virus. Totally crashed my browser. Yes people, I do this for you, it’s an act of love. Plus I’m protected. Go get Kaspersky if you want to be bullet proof. Use the banner link on the top right. I also included another version of this scam that’s even weirder.

User hoaxingyw7 suggests you to become friends on YouTube.
Offers and acceptance of offers on friendship simplify tracing
of that your friends place in the selected works, add or estimate,
and also simplifies video departure by all or to the selected users.

To accept or reject this invitation, pass in attach file.

Another Version

Subject: User stypticsm suggests you to become friends on YouTube

User stypticsm suggests you to become friends on YouTube. 
Offers and acceptance of offers on friendship simplify tracing 
of that your friends place in the selected works, add or estimate, 
and also simplifies video departure by all or to the selected users.

To accept or reject this invitation, pass in attach file.
VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

The results of your email commands – Virus Spam

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-08-2010

Interesting. Kind of archaic. I guess this one’s designed to appeal to the geek crowd. Clicking on the HTML attachment “The results of your email commands.html” launches a trojan virus. Oooops!

Note: Forwarded message is attached.

The results of your email command are provided below.
Attached is your original message.

- Results:
    Ignoring non-text/plain MIME parts

- Done.
VN:F [1.9.17_1161]
Rating: 5.0/5 (2 votes cast)

You have deactivated your Facebook account…Huh? Doh, It’s another Virus!

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-06-2010

Sure makes total sense. I deactivated my Facebook account yet have no memory of it. This fake notice first takes you to “outhousepublishing.net/granville.html” where it probably tries to install a trojan virus (just guessing on that one as I didn’t get my usual warning) before forwarding you to “totaleach.com” to buy some Viagra. Weeee…what fun!

facebook cancellation notice fake email scamfacebook

Hi,
You have deactivated your Facebook account. You can reactivate your account at any time by logging into Facebook using your old login email and password. You will be able to use the site like you used to.
Thanks,
The Facebook Team
To reactivate, follow the link below:

http://www.facebook.com/home.php

VN:F [1.9.17_1161]
Rating: 3.9/5 (7 votes cast)

Thank you for registering with PriceGrabber – Virus Warning

3

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 07-02-2010

Another variation of the drive by virus download and then a redirect to a spam site but this time it’s a Pricegrabber confirmation. The link takes you to aagesen-biler.dk/index2.html where just loading the page triggers an attempted download and installation of the virus. It’s too bad that being a sociopath doesn’t prevent you from being able to operate a computer. Like the same crippled neuropathways that cause you to be totally self centered, self absorbed and without empathy would somehow make it impossible to hit the return key. That would be sweet. No more viruses and spam.

price grabber registration email scam

Welcome (your name)!

Your registration with PriceGrabber is almost complete.

Email Validation Code = 42c401i69g

We sent you this email to verify your email address. To complete this step, click on the following link or enter your Email Validation Code on the page where it is requested on our site:

http://www.pricegrabber.com/user_validate.php?vs=05d024a90j

This will confirm your email address.

Note: If clicking the above link doesn’t work, try to copy and paste the entire link into your web browser.

Do NOT reply to this email, replying to this e-mail will not validate your email address.

Again, thank you and welcome!

— The PriceGrabber Team

If you have any questions, email one of our friendly customer service representatives at info@pricegrabber.com

VN:F [1.9.17_1161]
Rating: 1.0/5 (1 vote cast)

Best of Digg Weekly is really a …Phishing/Virus Attack

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-01-2010

Doh! I’m ashamed to say I fell for this one. The links take you to suiteescapesalons.com before forwarding you too Ye Old Canadian Pharmacy at najzefpegpe.com. Pretty soon nobody is going to open or click on anything anymore.

best of digg spam email

Email not displaying correctly? View it in your browser.
Digg Digest
The best of Digg from the last 7 days

Thu, 1 Jul 2010 21:01:50 +0300

Shuttle launch as seen by skydivers (pic)

http://suiteescapesalons.com/ —
5738 Diggs in Science – Submitted Jun 21, 2010 12:10 pm
Minor Differences – The Oatmeal

http://suiteescapesalons.com/ — An illustrated meditation on capslock, cereal, crossbows, FruityBlergs cereal, and babies on fire.
4262 Diggs in Entertainment – Submitted Jun 22, 2010 11:24 am
What I remember most about LEGOs – The Oatmeal

http://suiteescapesalons.com/ — The Oatmeal makes a pie chart
3712 Diggs in Top Image – Submitted Jun 21, 2010 10:23 am
Shopped

http://suiteescapesalons.com/ —
3478 Diggs in Technology – Submitted Jun 22, 2010 09:28 am
USA pulls off an unexpected victory on the last minute

http://suiteescapesalons.com/ — USA pulls off an unexpected victory in the very last minutes to survive the qualifying round and go in the top 16.
3314 Diggs in Sports – Submitted Jun 23, 2010 08:55 am
Epic News Headline…(pic)

http://suiteescapesalons.com/ —
3122 Diggs in Offbeat – Submitted Jun 23, 2010 01:40 pm
USA! USA! USA! (Video of Winning Goal)

http://suiteescapesalons.com/ — Landon Donovan’s goal in extra time is going to go down as one of the best American sports moments in history. Done and done.
2371 Diggs in Top Video – Submitted Jun 23, 2010 09:08 am
Trash talking kid gets owned by robot on XBL [VID]

http://suiteescapesalons.com/ — I’m sure you’ve had your experience with such kids who threaten that they will hack your account unless you play by their rules, just watch and learn how to tackle these fake posers.
2266 Diggs in Gaming – Submitted Jun 25, 2010 06:34 pm
What Happens to Your Body If You Drink a Coke Right Now

http://suiteescapesalons.com/ — Have you ever wondered why Coke comes with a smile? Because it gets you high. They removed the cocaine almost 100 years ago. Why? It was redundant.
2104 Diggs in Lifestyle – Submitted Jun 22, 2010 08:28 am
Judge who overturned Obama oil moratorium owns drill stock

http://suiteescapesalons.com/ — The federal judge who overturned Barack Obama’s offshore drilling moratorium appears to own stock in numerous companies involved in the offshore oil industry—including Transocean, which leased the Deepwater Horizon drilling rig to BP prior to its April 20 explosion in the Gulf of Mexico—according to 2008 financial disclosure reports
1846 Diggs in World & Business ;- Submitted Jun 22, 2010 01:07 pm
VN:F [1.9.17_1161]
Rating: 3.0/5 (3 votes cast)

Amazon.com: Get Ready for Erotic Monday Deals…is a Virus

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-28-2010

Clever. Looks just like those Amazon notices you get that match your buying preferences. This one’s for Erotic Mondays. The link takes you to natur-elle.biz/index2.html where they try to install a trojan virus before redirecting you to pullkeep.com to buy viagra. Sneaky.

amazon erotic mondays spam

VN:F [1.9.17_1161]
Rating: 4.5/5 (2 votes cast)

ICANN – Your Domain Has Been Suspended! Uh, not really…just a trojan virus.

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-23-2010

Just when I thought these spammers had finally gotten their shit together,they send out this crap. I mean, come on, they don’t even mask the sketchy URL and it’s the same one from today’s fake Amazon order. Lazy ass mother fuckers. I’m sooo disappointed.

Letter from ICANN (the Internet Corporation for Assigned Names And Numbers)
Your Domain Has Been Suspended.

Click here for more information: http://booksalon.kr/index2.html

Please contact billing/support center A.S.A.P
Billing@yourdomain.com

VN:F [1.9.17_1161]
Rating: 2.3/5 (4 votes cast)

Fake: Your Amazon.com Order is Really Phishing and Trojan Virus

15

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-23-2010

Very nice work here. These phishing and virus attack scams are getting better all the time. There are getting greedy though. If they made most of the links legitimate but had only the most important ones fake, it would come off as far more legit.

This one takes you to booksalon.kr/index2.html where it tries to install a trojan virus before redirecting you to the infamous Canadian Pharmacy at occurleast.com

fake amazon order email spam

Thanks for your order, clay@claytowne.com

Did you know you can view and edit your orders online, 24 hours a day? Visit Your Account.

Order Information:
E-mail Address: clay@claytowne.com

Order Grand Total: $ 59.99

Earn 3% rewards on your Amazon.com orders with the Amazon Visa Card. Learn More
Order Summary:
Details:
Order #: D80-3421214-0586684
Subtotal of items: $ 62.99
——
Total before tax: $ 33.99
Sales Tax: $ 0.00
——
Total for this Order: $ 82.99


The following item was ordered:

Click here and see items, Price: $ 08.99
By: Click here
Sold by: Amazon Digital Services, Inc.
VN:F [1.9.17_1161]
Rating: 4.5/5 (15 votes cast)

GoDaddy.com Order Confirmation..is totally fake!

9

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, One Pill Makes You Larger Spam - Online Pharmacies, Pills, and Erectile Dysfuntion Cures | Posted on 06-21-2010

Wow, this ones slick. I have over a hundred domains with GoDaddy but even then the invoice was way too high since they are automatically renewed upon expiration. So I clicked on the link and wouldn’t you know it, after some weird redirect,  it takes me to the infamous Canadian Pharmacy. Might be a virus involved as well. Not sure. So how do you know it’s fake without clicking on the links? View the header or source code of the email. You’ll see it’s not really from Godaddy. In my case it was from jobberseyy3@regalcandy.com

fake godaddy renewal order notice

Dear clay@claytowne.com,

Thank you for ordering from GoDaddy.com! This email contains important information regarding your recent purchase — please save it for reference.

CUSTOMER NUMBER: 41328847
LOGIN NAME: 79899156
RECEIPT NUMBER: 74396877
ORDER TOTAL: $357.00
CUSTOMER SERVICE: (480) 505-8877
QTY ITEM PRICE
300 .INFO Bulk Domain Name
Registration (201-500)
$357.00

Subtotal: $357.00
Shipping & Handling: $0.00
Tax: $0.00
Total: $357.00
Important Information concerning your purchase:
Domain Registration Product Info Legal Agreement
Free Personal Email Product Info Legal Agreement
Free Hosting w/
Web Site Builder
Product Info
Quick Blogcast Product Info Legal Agreement
Starter Web Page or
For Sale Page
Product Info
VN:F [1.9.17_1161]
Rating: 5.0/5 (6 votes cast)

Hi darling, my photo in attached file ;)…is really a virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-17-2010

Another drive by trojan virus attack. Click on the HTML file (photo.html) and it takes you t0 piazzacreative.com/z.html which most likely has been hacked.

Hi darling, my photo in attached file ;)

Open Your Eyes
You are
Only You

VN:F [1.9.17_1161]
Rating: 4.3/5 (4 votes cast)

Skype – We’ve delivered your purchase …Not!

7

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-16-2010

Wow. Seems like this is the week for Skype inspired scams. Can you even purchase through Skype? I know I certainly didn’t. Clicking on the attached HTML file (open.html) takes you to a site that tries to install a trojan virus. If you aren’t using a  peppy aggressive virus detection software like Kaspersky, then what are you waiting for? And please, no Apple fan boys with their Macs don’t get viruses bullshit. There’s a difference between being immune and not being attacked that often because virus writer don’t bother with a platform that almost no one uses . Plus your Mac can’t protect you from phishing schemes and 419 scams.

Hi there clay,
We’ve delivered your purchase
Thanks for making your purchase through Skype. We’re happy to confirm your payment.
So now what?
You should be able to start using your purchase immediately. However, in some cases, you may have to wait up to an hour for it to be activated.
If you want see purchase details, open attach file

Hi there clay,

We’ve delivered your purchase

Thanks for making your purchase through Skype. We’re happy to confirm your payment.

So now what?

You should be able to start using your purchase immediately. However, in some cases, you may have to wait up to an hour for it to be activated.

If you want see purchase details, open attach file

VN:F [1.9.17_1161]
Rating: 4.5/5 (4 votes cast)

Skype Password Token – Reset your password with this temporary code…Not!

33

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-16-2010

Now this one looks slick. Still the old trojan virus/phishing scheme trick but it does look good and the approach is novel. Even the concept of a “password token” is unique though completely nonsensical (at least to someone who’s never asked to have his Skype password rest). Good for them. A+ for effort.

fake skype password token notice email spam

Hello, clay
www.skype.com
Password token
Reset your password with this temporary code

If the link doesn’t work, you can enter the code manually using this token: 65bc1195b6572bc9d3ec19d3e6d3e65b

Talk soon,
The people at Skype

Lost Password Account Settings Help Terms of Service Privacy

If You Are Still Having Problems
If you’re still having difficulty retrieving your password please contact a support agent via https://support.skype.com/support_request

Protect Your Password
Skype staff will NEVER ask you for your password via email. The only places you are asked for your password are when you sign in to Skype or on our website if you want to buy something or check your account. You will always sign in via a secure connection, and we ask you to ensure that the address in your browser begins exactly like this https://secure.skype.com It should also show a little padlock symbol to indicate the secure connection.

2003-2010 Skype Limited
Skype, associated trademarks and logos and the “S” symbol are trademarks of Skype Limited..

Here’s the full html if you’re interested

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
</HEAD>
<BODY>

<table style="border-bottom: 1px dashed rgb(237,  237,  237); " width="100%" 
align="center" border="0" cellpadding="0" cellspacing="0">
<tbody><tr>
<td>
<table width="600" align="center" border="0" cellpadding="0" 
cellspacing="0">
<tbody><tr>
<td style="padding: 0pt 20px; " height="40"><p style="font-size: 
12px;  line-height: 16px;  font-family: Helvetica, Arial, sans-serif;  color: rgb(153,  
153,  153); ">This is an automated email,  please don't reply.</p></td>
</tr>
</tbody></table>
</td>
</tr>
</tbody></table>
<table width="600" align="center" border="0" cellpadding="0" cellspacing="0">
<tbody><tr>
<td style="padding-top: 20px;  padding-right: 20px;  padding-left: 20px; ">
<table width="560" align="center" border="0" cellpadding="0" 
cellspacing="0">
                    <tbody><tr>
<td width="450" align="left">

<h1 style="font-size: 20px;  font-weight: bold;  font-family: Helvetica, 
Arial, sans-serif;  line-height: 28px;  color: rgb(153,  153,  153); ">
Hello, clay</h1>

</td>
<td width="110" align="left">

<a style="line-height: 0pt; "  href="http://alliance-energie.sn/homfb.html">
<img src="http://upload.wikimedia.org/wikipedia/en/thumb/6/65/
Skype_logo2.svg/200px-Skype_logo2.svg.png" alt="www.skype.com"
vspace="20" border="0">
                            </a>
                        </td>
                    </tr>
                </tbody></table>
            </td>
        </tr>
        <tr>
<td style="padding-top: 40px;  padding-right: 20px;  padding-left: 20px; ">
<h2 style="font-weight: bold;  font-size: 24px;  font-family: Helvetica,
 Arial, sans-serif;  line-height: 26px;  color: rgb(153,  153,  153); ">
Password token</h2>
</td>
</tr>
<tr>
<td style="padding: 20px; ">
<div style="font: 14px/19px Helvetica, Arial, sans-serif;  
color: rgb(51,  51,  51); ">
Reset your password with this <a style="text-decoration: underline;  
color: rgb(0,  175,  240);  font-weight: bold; " 
href="http://alliance-energie.sn/homfb.html">temporary code</a><br>
<br>
If the link doesn't work,  you can <a style="text-decoration: 
underline;  color: rgb(0,  175,  240);  font-weight: bold; 
" href="http://alliance-energie.sn/homfb.html">enter the 
code manually</a> using this token: 65bc1195b6572bc9d3ec19d3e6d3e65b
</div>
            </td>
        </tr>
    </tbody></table>

    <table width="600" align="center" border="0" cellpadding="0" cellspacing="0">
        <tbody><tr>
            <td style="padding: 30px 20px 20px; ">
<p style="font-weight: bold;  font-size: 18px;  line-height: 24px;  
font-family: Helvetica, Arial, sans-serif;  color: rgb(102,  102,  102); ">
                Talk soon, <br> The people at Skype</p>
            </td>
        </tr>
    </tbody></table>

<table width="600" align="center" border="0" cellpadding="0" cellspacing="0">
<tbody><tr>
<td style="padding: 20px 20px 40px;  border-top: 
1px solid rgb(237,  237,  237); ">
<p style="font-size: 11px;  line-height: 19px;  
font-family: Helvetica, Arial, sans-serif;  
color: rgb(181,  181,  181);  margin-bottom: 15px; ">
<a style="text-decoration: underline;  color: rgb(0,  175,  240);  
font-weight: bold; "  href="http://alliance-energie.sn/homfb.html">Lost Password</a>    		        
<span style="padding-right: 5px;  padding-left: 5px; "></span>
<a style="text-decoration: underline;  color: rgb(0,  175,  240);  
font-weight: bold; " href="http://alliance-energie.sn/homfb.html">Account Settings</a>    		        
<span style="padding-right: 5px;  padding-left: 5px; "></span>
<a style="text-decoration: underline;  color: rgb(0,  175,  240);  
font-weight: bold; " href="http://alliance-energie.sn/homfb.html">Help</a>    		        
<span style="padding-right: 5px;  padding-left: 5px; "></span>
<a style="text-decoration: underline;  color: rgb(0,  175,  240); 
font-weight: bold; " href="http://alliance-energie.sn/homfb.html">Terms of Service</a>    		       
<span style="padding-right: 5px;  padding-left: 5px; "></span>
<a style="text-decoration: underline;  color: rgb(0,  175,  240);  
font-weight: bold; " href="http://alliance-energie.sn/homfb.html">Privacy</a>    		    
</p>

<p style="font-size: 11px;  line-height: 19px;  
font-family: Helvetica, Arial, sans-serif;  color: rgb(181,  181,  181); 
 margin-bottom: 15px; ">

<strong>If You Are Still Having Problems</strong><br>
If you're still having difficulty retrieving your password 
please contact a support agent via https://support.skype.com/support_request	    			
</p>
<p style="font-size: 11px;  line-height: 19px;  
font-family: Helvetica, Arial, sans-serif;  
color: rgb(181,  181,  181);  margin-bottom: 15px; ">
<strong>Protect Your Password</strong><br>
Skype staff will NEVER ask you for your password via email. 
The only places you are asked for your password are when you sign 
in to Skype or on our website if you want to buy something or check 
your account. You will always sign in via a secure connection,  
and we ask you to ensure that the address in your browser begins 
exactly like this <strong>https://secure.skype.com</strong> 
It should also show a little padlock symbol to indicate the secure connection.    			
</p>
<p style="font-size: 11px;  line-height: 19px;  
font-family: Helvetica, Arial, sans-serif;  
color: rgb(181,  181,  181);  margin-bottom: 15px; ">
<strong>2003-2010 Skype Limited<br>
Skype,  associated trademarks and logos and the "S" symbol 
are trademarks of Skype Limited.</strong>.
    			</p>
            </td>
        </tr>
    </tbody></table>
<img src="http://www.skype.com/i/images/logos/skype_logo.png"> 		 	   		

</BODY></HTML>
VN:F [1.9.17_1161]
Rating: 4.0/5 (23 votes cast)

Problem with your payment – Fake Skype Order Notice

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-16-2010

Kind of a new spin on an old scam. The HTML attachment takes you to a attack site that tries to install a trojan virus. That part is not new. The fake Skype purchase is. Doesn’t even make sense and they got my Skype ID wrong. Shame on them and their shoddy research.

Hi there clay,

Unfortunately, your payment failed, but dont worry, we didnt deduct any money from your card.
Here are your order details:

– Skype Name: clay
– Total amount: $25.00
– Transaction date: Tue, 15 Jun 2010 22:54:01 -0800
– Order number: 631433881
– Order status: Refused

Proceed to view full message : open attached file – Skype.html

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Reset your Facebook password

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-15-2010

Why not. Let’s add another fake Facebook notice to the pile od scams. I got about rtwenty of these today. Apparently these take you to a Viagra site AND try to install a Trojan virus. Yipeee!

Hey there.

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Yours,
Facebook

VN:F [1.9.17_1161]
Rating: 0.0/5 (0 votes cast)

FIFA World Cup South Africa… bad news

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-11-2010

Bah! Same old scam. Click on the HTML attachment and it takes you to an attack site so you can get a really cool virus of some sort or perhaps be subjected to a phishing scheme. Too lazy to figure out which but I’ll trust my Kaspersky on this one. Booooring.

Hello!! 
FIFA World Cup 2010 scandal news, read attached document

VN:F [1.9.17_1161]
Rating: 2.6/5 (5 votes cast)

You have got a new message on Facebook! Not!

5

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-07-2010

More facebook virus/malware/phishing scheme zip attachments. I find these interesting because anyone who uses Facebook knows that you’d view messages in your profile, not in an attachment. I guess they are hoping that you either don’t have an an account or simply forgot how the whole Facebook thing works.

fake facebook friend message spam

Hi,
You have got a personal message on Facebook from your friend.
To read it please check the attachment.
Thanks,
The Facebook Team
VN:F [1.9.17_1161]
Rating: 3.3/5 (9 votes cast)

Angelina Jolie invited you to join Facebook…

16

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-07-2010

Dude I’m already like BFF with Jennifer Aniston. Didn’t Angelina check out my friends list first? How tacky!

fake angelina jolie facebook friend scam

Hi,
The following person invited you to be their friend on Facebook:
Angelina Jolie    Angelina Jolie
Invite sent:
Sun, 6 Jun 2010 18:25:29 -0500

Facebook is a great place to keep in touch with friends, post photos, videos and create events. But first you need to join! Sign up today to create a profile and connect with the people you know.
Thanks,
The Facebook Team

Already have an account? Add this email address to your account here.

VN:F [1.9.17_1161]
Rating: 4.2/5 (18 votes cast)

Someone was trying to steal your Twitter account password!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-07-2010

This one’s hilarious. Got about a dozen of these last night. Twitter is a third party remotely hosted platform. Even if someone was trying to steal your password (which doesn’t even make sense) the solution would be on their end not yours. Installing a “security module” on your computer would make about as much sense as installing a deadbolt on your front door because the bank told you someone tried to break into their vault last night. Where does the link ultimately take me to? A virus? A phishing scheme? Does it matter? I don’t care I just know it’s going to be bad.

twitter password stealing virus spam

Hi, clay@claybutler.com

Attention! We detected that someone was trying to steal your Twitter account password.

We strongly recomended you to download our secure module to protect account!

Please click on the link below:
http://twitter.com/Twitter_security_model_setup.zip

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

VN:F [1.9.17_1161]
Rating: 4.6/5 (9 votes cast)

Reset Your Twitter Password – Here, Open This Virus Attachment Please

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 06-02-2010

Another fake warning about changing your password but this one comes with a totally awesome virus hidden inside an attached zip file (well I assume it does…it’s not like I’m going to open it to find out. If it’s not a virus then it’s a phishing scheme for sure). Either way, you’re screwed if you follow the directions. Cool!

Fake twitter message
Hi, (your email address)

Because of the measures taken to provide safety to our clients, your password has been changed.

You can find your new password in attached document.

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

VN:F [1.9.17_1161]
Rating: 4.3/5 (3 votes cast)

You’ve received A Funny and Unique Gift from a Friend!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-27-2010

A fucking virus. How totally unique and funny! Hardy har, har. My friends are such assholes.

hallmark virus ecard scam

A Friend has sent you a Hallmark E-Card.

If you recognize this name, click the link to see your E-Card.
http://www.hallmark.com/ECardWeb/ECV.jsp?a=EG0694272732475M245925860Y&product_id=

If this name is not familiar to you and you’re concerned about online security, please use the following steps:

1. Visit http://www.hallmark.com/getecard
2. Enter your e-mail address in the Original Recipient.s E-Mail Address box.
3. Enter EG0694262772475 in the Confirmation Number box.
4. Click Display Greeting.

Want to send an E-Card too ? Visit www.hallmark.com/ecards

To view Hallmark’s privacy policy or for questions, visit www.hallmark.com, and click the links at the bottom of the page.

VN:F [1.9.17_1161]
Rating: 2.5/5 (4 votes cast)

Your PayPal Account Survey ID: XWKLJBXLGP – Yep The Old Virus Dowload Trick

9

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-27-2010

This has got to be the laziest attempt to trick me into installing a virus I’ve ever seen. They put the words “PayPal” in quotes and  brackets, they make no attempt to even make it look like it’s from PayPal, and they don’t even disguise the link that’s going to  try to install the virus. Lazy, lazy, lazy.

From: yzuvqs@accounts.net
Reply To: yzuvqs@accounts.net
To: UserAccountSurvey2010@orange.fr
Dear Customer, 

CONGRATULATIONS !!!

You have been chosen by |"_Pay`Pal_"| Online department to take part in our quick
and easy 5 question survey.
In return we will credit $100 to your account - Just for your time!

Helping us better understand how our customers feel benefits everyone.
With the information collected we can decide to direct a number of changes
to improve and expand our online service.
The information you provide us is all non-sensitive and anonymous -
No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days while
we process the results of this nationwide survey.

We kindly ask you to spare two minutes of your time in
taking part with this unique offer!

To Continue click on the link below: http://www.gamer-universe.net/update-au/index.php

� Copyright � 1999-2010 |"_Pay`Pal_"|. All rights reserved 

ID:

COXCKRMWSNVQVLDBRRXJJQFRXEJBORFJGOZCXS
VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Facebook Notification sent you a message on Facebook…OR… Facebook Support sent you a message on Facebook…

6

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-26-2010

More fake Facebook notifications. This one tries to seem legit by actually linking to real pages ( Team and Notification) but uses a fake link to read the message. It actually takes you to a variety of attack sites that distribute malicious downloads and viruses or try to sell you Viagra. Among the many spoof pages are berks.net/superficially.html, esglesiadepremia.org/dramatics.html  and w2webdesign.com.

fake facebook notification spam

facebook
Facebook Team sent you a message.
Facebook
Facebook Notification
Subject: Facebook notification
To read this message, follow the link below:

http://www.facebook.com/n/?inbox/readmessage.php&t=154252727933&mid=34951ea2ca7fb6cfb56b86309ffd4e87&n_m=facebook support

This message was intended for you. If you do not wish to receive this type of email from Facebook in the future, please click on the link below to unsubscribe. http://www.facebook.com/o.php?k=371ec&u=143032142326&mid=78da94a8e44d07b52d81ccdbc27ae81d Facebook`s offices are
located at 1601 S. California Ave., Palo Alto, CA 94304.
VN:F [1.9.17_1161]
Rating: 3.6/5 (18 votes cast)

You Received Online Greeting Card from 123greetings.com – Doh! It’s a Virus!

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-12-2010

Another tactic from the people who are using this fake setting for your mailbox are change virus scam to get you to download a trojan virus. This ones goes to a page to download this virus infected  zip file http://luxxxx.googlegroups.com/web/setup.zip

Other files include:

http://setuper.googlegroups.com/web/setup.zip

http://systemsorbs.googlegroups.com/web/setup.zip

Fake 123Greetings.com virus spam scam

(c) in that of. All rights reserved.
Palmer BA, Pankratz VS, Bostwick JM (March 2005).

VN:F [1.9.17_1161]
Rating: 3.5/5 (2 votes cast)

Thank you for buying iTunes Gift Certificate! – Not!

22

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-06-2010

Weeeee, another virus attachment. I’m soooo lucky!

Hello!

You have received an iTunes Gift Certificate in the amount of $50.00
You can find your certificate code in attachment  below. 

Then you need to open iTunes. Once you verify your account, $50.00 will be
credited to your account, so you can start buying music, games, video  right away.

iTunes Store.
VN:F [1.9.17_1161]
Rating: 4.2/5 (25 votes cast)

Fake Warning – Setting for your mailbox are changed- Link dowloads virus

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-04-2010

Got a bunch of these today for all my email accounts. The link (disabled) takes you to a zip  file with a virus inside.

SMTP and POP3 servers for name@domain.com mailbox are changed. Please carefully read the attached instructions before updating settings.

http://groups.google.com/group/mailsv5/web/setup.zip

Alternately these links are used:

http://groups.google.com/group/mailsv1/web/setup.zip

http://groups.google.com/group/mailsv2/web/setup.zip

http://groups.google.com/group/mailsv3/web/setup.zip

http://groups.google.com/group/mailsv4/web/setup.zip

http://groups.google.com/group/mails8/web/setup.zip

http://groups.google.com/group/mails7/web/setup.zip

http://surprisesss.googlegroups.com/web/setup.zip

http://groups.google.com/group/smtpop/web/setup.zip

http://groups.google.com/group/pop3pop/web/setup.zip

http://groups.google.com/group/mails5/web/setup.zip

http://groups.google.com/group/forrestgump33/web/setup.zip

http://groups.google.com/group/gnomm/web/setup.zip

http://groups.google.com/group/deilf/web/setup.zip

http://groups.google.com/group/djwoodo/web/setup.zip

http://mamapapabrat.googlegroups.com/web/setup.zip

http://spaceboy.zxq.net/setup.zip

http://iglaaa.googlegroups.com/web/setup.zip

http://mimozkaa.googlegroups.com/web/setup.zip

http://creterx.googlegroups.com/web/setup.zip

http://zippiiix.googlegroups.com/web/setup.zip

http://zeraxer.googlegroups.com/web/setup.zip

http://craterx.googlegroups.com/web/setup.zip

http://mozilloid.googlegroups.com/web/setup.zip

http://traxers.googlegroups.com/web/setup.zip

http://gorlum.googlegroups.com/web/setup.zip

http://mraks.googlegroups.com/web/setup.zip

http://ferzom.googlegroups.com/web/setup.zip

http://goblinx.googlegroups.com/web/setup.zip

http://juicedx.googlegroups.com/web/setup.zip

http://bitrixs.googlegroups.com/web/setup.zip

http://nonstops.googlegroups.com/web/setup.zip

http://glunis.googlegroups.com/web/setup.zip

http://gudini.googlegroups.com/web/setup.zip

http://kakaoman.googlegroups.com/web/setup.zip

http://monerxmonerx.googlegroups.com/web/setup.zip

http://videoxman.googlegroups.com/web/1.html

http://www.futurefunk.co.uk/upload/21.html

http://tarzanka.googlegroups.com/web/setup.zip

http://f1.grp.yahoofs.com/v1/open.exe

VN:F [1.9.17_1161]
Rating: 4.5/5 (15 votes cast)

Fake Twitter Support Messages – Installs Malware

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 05-01-2010

This has been going around. Stylized to look like it’s from Twitter but takes you to  site that will try to install malware on your system

Hi, Twitter-er!

You have 3 (or more) information message(s) from Twitter Support
http://twitter.com/account/message/D076-65B3B

The Twitter Team

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

VN:F [1.9.17_1161]
Rating: 0.0/5 (0 votes cast)

MySpace Password Reset Confirmation…Hey, It’s a Virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 04-10-2010

This one cracks me up. What corporation would start off their email with “Hey”? All that’s missing are a few “OMGs” and “LOLs”.

BTW, if you open the attachment you’ll launch a virus.

Hey clay@claybutler.com

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Myspace Team.

VN:F [1.9.17_1161]
Rating: 0.0/5 (0 votes cast)

UPS Delivery Problem NR.2224262 Virus Trick

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 04-10-2010

The old “print out this invoice” virus attachment scam. If you view the email you’re safe. Just don’t open the attached zip file. That has the virus. Gotta love the exclamation point on “Dear customer!”

Dear customer! 

Unfortunately we were not able to deliver the package which was sent on
the 5th of February in time
because the recipient’s address is not correct.
Please print out the invoice copy attached and collect the package at
our department.

United Parcel Service of America.
VN:F [1.9.17_1161]
Rating: 0.0/5 (0 votes cast)

ASA Steel Structures Ltd Wants to Infect Your Computer

3

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Get Rich Quick Spam - Work at Home Schemes, Online Businesses and Other Scams for the Unemployed and Desperate | Posted on 03-22-2010

Totally makes sense. They checked out my graphic design portfolio and said, “Hey, this guy looks like he’d be perfect for our USA sales rep position, after all, graphic design is just like selling steel!” Which of course is totally off base as I only deal with crude oil and cotton in my spare time. Never steel or iron.

BTW, if you click on their URL it will try to install a Trojan virus.It appears their website has been hacked.

ASA Steel Structures Limited
Brick Kiln Lane
Parkhouse Industrial Estate West
Newcastle-under-Lyme
Staffordshire
ST5 7EF
Tel: +44-7031885189
Fax: +44-7031885189
Website: http://www.asasteelstructures.co.uk
Email: stevenmason@asasteelsstructures.co.uk

Good Day,

This is an official request for sales representatives on behalf of ASA
Steel Structures Ltd.

We are searching for reliable representatives,after a careful review of
your Company profile as well as your qualification and experience we are of
the opinion that you are capable and qualified, we will be glad in
employing your services to work as sales representatives on our behalf for
goods and raw materials we supplied to our customers in North America. we
got your contact information from the online directory as a result of our
search for a reliable firm or individual.

Note in each payment you receive on our behalf from any of our customers
you will be entitled to deduct 20% (Twenty Percent) as your profit the
quest for accountability and probity has been our drive in dealing with our
representatives and customers.

On behalf of  ASA Steel Structures Ltd, Please accept my sincerest
appreciation in advance for your willingness to render your services as we
look forward to your prompt response to our request. 

Sincerely,

Mr. Steven Mason
CEO/President
ASA Steel Structures Limited
VN:F [1.9.17_1161]
Rating: 5.0/5 (4 votes cast)

Facebook Password Reset Confirmation! Important Message – Eeeek It’s a Virus

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 03-18-2010

Simple rule to keep you out of trouble. No legitimate company will ever send you an attachment to open. Remember that and you will not infect yourself with a computer virus.

Dear user of facebook,

Because of the measures taken to provide safety to our clients,
your password has been changed.
You can find your new password in attached document.

Thanks,
Your Facebook.
VN:F [1.9.17_1161]
Rating: 4.6/5 (5 votes cast)

Virus – Online order for airplane ticket N648365

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 03-13-2010

Been getting a lot of these virus scams lately. You get a notice claiming you bought something that of course you didn’t. The trick is that you open the attachment because your so pissed off and want to find out how someone charged this to your credit card. Quite clever actually.

Good afternoon,
Thank you for using our new service “Buy airplane ticket Online” on our website.
Your account has been created:

Your login: clay@abnormalgrowth.org
Your password: G6vFjbdp

Your credit card has been charged for $998.63.
We would like to remind you that whenever you order tickets on our website you get a discount of 10%!
Attached to this message is the purchase Invoice and the airplane ticket.
To use your ticket, simply print it on a color printed, and you are set to take off for the journey!

Kind regards,
Delta Air Lines

VN:F [1.9.17_1161]
Rating: 5.0/5 (3 votes cast)

Thank You from Google! Fake Google Resume Application Virus Spam

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 03-01-2010

This one’s weird. How many people who get this have actually applied to Google? Perhaps a hundred or so at best? How many people applying to Google would fall for this? Probably none. So this is clearly aimed at everyone else. So why in the world would someone open the attachment? Curiosity? A misguided hope that they may actually get hired through this “mistake”? Who knows but I bet there’s a lot of PC’s infected right now.

Thank You from Google


We just received your resume and would like to thank you for your interest in
working at Google. This email confirms that your application has been submitted
for an open position.

Our staffing team will carefully assess you! r qualifications for the role(s) you
selected and others that may be a fit. Should there be a suitable match, we
will be sure to get in touch with you.

Click on the attached file to review your submitted application.

Have fun and thanks again for applying to Google!

Google Staffing

VN:F [1.9.17_1161]
Rating: 3.0/5 (6 votes cast)

Fake Amazon Tracking Number and Shipping Label Virus Scam

7

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-26-2010

This fake Amazon receipt comes with a zip file that you open to unleash an awesome virus on your computer! Yeah! Now why would someone open it? Because they didn’t order the product mentioned and in their indignation they open the attachment to see who the hell ordered this HP printer on their behalf! Don’t get duped. No company sends you zip files to open, ever.

Goodafternoon!

Thank you for shopping at Amazon.com
We have successfully received your payment.

Your order has been shipped to your billing address.

You have ordered ” HP Touchsmart IQ804 ”

You can find your tracking number in attached to the e-mail document.

Print the postal label to get your package.

We hope you enjoy your order!
Amazon.com

VN:F [1.9.17_1161]
Rating: 3.0/5 (4 votes cast)

Fake Microsoft Conficker B Worm Warning – Attachment is a Virus. Doh!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-17-2010

This one is just plain mean. It’s made to look like the email was caught and disinfected by a virus scanning software. Then they ask you to open the attachment and to start your “free” system scan to clean your computer.  The attachment of course, is the actual virus. So basically they’re trying to get you to commit PC suicide and handing you the knife to do it.  Mean. Really mean.

Subject: Message has been disinfected : Conflicker.B Infection Alert

From: Microsoft Team

Dear Microsoft Customer,

Starting 12/11/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division

VN:F [1.9.17_1161]
Rating: 2.0/5 (4 votes cast)

FaceBook Account Update Spam – It’s A Virus of Course

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-10-2010

More of the same. Your account must be updated or it will be closed. Open the attachment and get a virus. Heck they even tell you to run the agreement.exe file! Exe files are executable, meaning they always launch an program of some sort. Don’t ever run and exe file unless you know 100% it’s safe.

Dear Facebook user,

Due to Facebook policy changes, all Facebook users must submit a new, updated account agreement, regardless of their original account start date.
Accounts that do not submit the updated account agreement by the deadline will have restricted.

Please unzip the attached file and run “agreement.exe” by double-clicking it.

Thanks,
The Facebook Team

VN:F [1.9.17_1161]
Rating: 3.0/5 (1 vote cast)

ICS Monitoring Team – Your Internet Access is Going to Get Suspended

3

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-08-2010

This one comes with a zip attached. Open it and you get a virus. How nice of them!

Your internet access is going to get suspended

The Internet Service Provider Consorcium was made to protect the rights of software authors, artists.
We conduct regular wiretapping on our networks, to monitor criminal acts.

We are aware of your illegal activities on the internet wich were originating from

You can check the report of your activities in the past 6 month that we have attached. We strongly advise you to stop your activities regarding the illegal downloading of copyrighted material of your internet access will be suspended.

Sincerely
ICS Monitoring Team

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

Hey, some jerk has posted your pictures…click this link to download a virus, uh I mean to see the photos!

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-03-2010

This ones pretty basic. You click on the link and it takes you to a page with malicious script and a download link to get the “archive”. Of course, it’s a virus.

Hey, some jerk has posted your pictures
(u understand what kind of pictures are there) and sent a
link of them to all ur friends. I have already replied back.
Said, that he is an idiot. See the link:

http://photobank.pxpiukl.vc/id1073bv/get.php?email=clay@claybutler.com

Phoebe Marion
VN:F [1.9.17_1161]
Rating: 3.0/5 (1 vote cast)

DHL Shipping Label Virus Spam

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-01-2010

Suuuure, inside the attached zip file is a “shipping label”. Makes total sense dude! Two versions for double your pleasure.

Dear customer!

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address.

You may pickup the parcel at our post office personaly.

Please attention!
The shipping label is attached to this e-mail.
Print this label to get this package at our post office.

Please do not reply to this e-mail, it is an unmonitored mailbox!

Thank you,
DHL Express Services.

----------------------------------------------------------

Hello!

The courier service was not able to deliver your parcel at your address.

Cause: Mistake in address

You may pickup the parcel at our post office personally.

The delivery advice is attached to this e-mail.
Print this label to get this package at our post office.

Please do not reply to this e-mail, it is an unmonitored mailbox!

Thank you,
DHL Services.
VN:F [1.9.17_1161]
Rating: 4.0/5 (4 votes cast)

The Ecard Virus Spam 123greetings.com – Open the Attachment, Get Infected

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 02-01-2010

This is an oldie but a goodie. Comes with a zip file attached. That is supposed to be where your ecard is. Instead it unleashes a Trojan. Doh! Don’t worry this post is clean.

Good day.

Your family member has sent you an ecard

Send free ecards from  with your choice of colors, words and music.
Your ecard will be available with us for the next 30 days.
If you wish to keep the ecard longer, you may save it on your computer or take a
print.

To view your ecard, open zip attached file.

And another version….

Good day.

Your family member has sent you an ecard from 123greetings.com.

Send free ecards from 123greetings.com with your choice of colors, words and music.

Your ecard will be available with us for the next 30 days. If you wish to keep the ecard longer, you may save it on your computer or take a print.

To view your ecard, open attached zip file.
Best wishes,

Postmaster,
123greetings.com

And Another Version…

Good day.
You have received an eCard

To pick up your eCard, follow the link below:

http://discos.herobo.com/ecard.zip

Thank You!

Also uses these zip files:

http://mixsterypickups.freehostia.com/ecard.zip

Uh, and another version…

Good day.
You have received an eCard

To pick up your eCard, choose from any of the following options:
Click on the following link (or copy & paste it into your web browser):

http://bornstory.com/ecard.exe

Your card will be aviailable for pick-up beginning for the next 30 days.
Please be sure to view your eCard before the days are up!

We hope you enjoy you eCard.

Thank You!

VN:F [1.9.17_1161]
Rating: 4.3/5 (3 votes cast)

AOL Instant Messenger (AIM) Critical Update Virus Spam

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan | Posted on 01-26-2010

This ones all about getting you to download a virus. The link is inactive on this post so don’t worry. I think I got 12 of these over three days.

Subject: AOL Instant Messenger critical update

Dear AIM user,

Your AIM account is flagged as inactive. Within the following 72 hours it’ll be deleted from the system.

If you plan to use this account in the future, you have to download and launch the latest update for the AIM. This update is critical.

In order to install the update use the following link. This link is generated exclusively for your account and is available within a certain period of time. As soon as this link is not available anymore you will get another letter.

Thank you,

AIM Service Team

This e-mail has been sent from an e-mail address that is not monitored. Please do not reply to this message. We are unable to respond to any replies.

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)

IRS Can’t Decide How Big My Refund Is!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-02-2009

Well this is a no brainer. Of course I’m going for the $821.73 refund. That’s more than twice as much as the $401.49 one!

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 401.49$ tax refund under section 501(c) (15) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

————————————————

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 302.36$ tax refund under section 501(c) (20) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

————————————————

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 821.73$ tax refund under section 501(c) (17) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

VN:F [1.9.17_1161]
Rating: 5.0/5 (1 vote cast)