Upgrade and Secure Your Mashreq Bank Account Now! Fake + Phishing

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-17-2010

A little more sophisticated than the usual phishing scam. I like the virtual keyboard explanation. Nice touch. Of course, I keep my secret millions in the Cayman Islands so I knew this was fake right away.

Dear Mashreq Bank Customer,

Due to our system upgrade to grant you maximum security. Your access to Online Services has been suspended. To enable you continue accessing your online account, click the attachment given to update your account.

Update your account to resolve the problem by clicking the attachment given.

Mashreq Bank.

fake mashreq banking account spam

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

You have deactivated your Facebook account…Huh? Doh, It’s another Virus!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-06-2010

Sure makes total sense. I deactivated my Facebook account yet have no memory of it. This fake notice first takes you to “outhousepublishing.net/granville.html” where it probably tries to install a trojan virus (just guessing on that one as I didn’t get my usual warning) before forwarding you to “totaleach.com” to buy some Viagra. Weeee…what fun!

facebook cancellation notice fake email scamfacebook

Hi,
You have deactivated your Facebook account. You can reactivate your account at any time by logging into Facebook using your old login email and password. You will be able to use the site like you used to.
Thanks,
The Facebook Team
To reactivate, follow the link below:

http://www.facebook.com/home.php

VN:F [1.8.7_1070]
Rating: 5.0/5 (2 votes cast)

Best of Digg Weekly is really a …Phishing/Virus Attack

1

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-01-2010

Doh! I’m ashamed to say I fell for this one. The links take you to suiteescapesalons.com before forwarding you too Ye Old Canadian Pharmacy at najzefpegpe.com. Pretty soon nobody is going to open or click on anything anymore.

best of digg spam email

Email not displaying correctly? View it in your browser.
Digg Digest
The best of Digg from the last 7 days

Thu, 1 Jul 2010 21:01:50 +0300

Shuttle launch as seen by skydivers (pic)

http://suiteescapesalons.com/ —
5738 Diggs in Science – Submitted Jun 21, 2010 12:10 pm
Minor Differences – The Oatmeal

http://suiteescapesalons.com/ — An illustrated meditation on capslock, cereal, crossbows, FruityBlergs cereal, and babies on fire.
4262 Diggs in Entertainment – Submitted Jun 22, 2010 11:24 am
What I remember most about LEGOs – The Oatmeal

http://suiteescapesalons.com/ — The Oatmeal makes a pie chart
3712 Diggs in Top Image – Submitted Jun 21, 2010 10:23 am
Shopped

http://suiteescapesalons.com/ —
3478 Diggs in Technology – Submitted Jun 22, 2010 09:28 am
USA pulls off an unexpected victory on the last minute

http://suiteescapesalons.com/ — USA pulls off an unexpected victory in the very last minutes to survive the qualifying round and go in the top 16.
3314 Diggs in Sports – Submitted Jun 23, 2010 08:55 am
Epic News Headline…(pic)

http://suiteescapesalons.com/ —
3122 Diggs in Offbeat – Submitted Jun 23, 2010 01:40 pm
USA! USA! USA! (Video of Winning Goal)

http://suiteescapesalons.com/ — Landon Donovan’s goal in extra time is going to go down as one of the best American sports moments in history. Done and done.
2371 Diggs in Top Video – Submitted Jun 23, 2010 09:08 am
Trash talking kid gets owned by robot on XBL [VID]

http://suiteescapesalons.com/ — I’m sure you’ve had your experience with such kids who threaten that they will hack your account unless you play by their rules, just watch and learn how to tackle these fake posers.
2266 Diggs in Gaming – Submitted Jun 25, 2010 06:34 pm
What Happens to Your Body If You Drink a Coke Right Now

http://suiteescapesalons.com/ — Have you ever wondered why Coke comes with a smile? Because it gets you high. They removed the cocaine almost 100 years ago. Why? It was redundant.
2104 Diggs in Lifestyle – Submitted Jun 22, 2010 08:28 am
Judge who overturned Obama oil moratorium owns drill stock

http://suiteescapesalons.com/ — The federal judge who overturned Barack Obama’s offshore drilling moratorium appears to own stock in numerous companies involved in the offshore oil industry—including Transocean, which leased the Deepwater Horizon drilling rig to BP prior to its April 20 explosion in the Gulf of Mexico—according to 2008 financial disclosure reports
1846 Diggs in World & Business ;- Submitted Jun 22, 2010 01:07 pm
VN:F [1.8.7_1070]
Rating: 4.0/5 (2 votes cast)

Wikipedia e-mail address confirmation (duh, it’s a phishing scheme)

1

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 07-01-2010

A new angle on the old “confirm your account” phishing scam. This one goes to cruzdealba.es/wiki.html before taking you to the ever popular Canadian Pharmacy at pullkeep.com

Someone from the IP address 93.84.75.95 has registered the account “clay” with this e-mail address on the English Wikipedia.

To confirm that this user account really does belong to you and to activate e-mail features on Wikipedia, please open this URL in your browser:

http://en.wikipedia.org/wiki/Special:ConfirmEmail/2157xu7717ww72240b6mb10190o60216

If you did not recently register for Wikipedia (or if you registered with a different e-mail address),

click the following link to cancel the confirmation:

http://en.wikipedia.org/wiki/Special:Invalidateemail/1157je4251pd46810u0dj23981o29482

This confirmation e-mail will automatically expire at Thu, 1 Jul 2010 15:12:52 +0200

~Wikipedia, the free encyclopedia

http://en.wikipedia.org

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

123greetings.com just sent you an ecard…Bitch!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-30-2010

More 123greetings.com scam emails. This one however takes you to a phishing site at sonda.co.kr/index2.html. Got a lot of these today.

Rosemary [jibl@royalsupreme.com] just sent you an ecard from 123Greetings.com

Seth [reactivatedp@riddickinc.com] just sent you an ecard from 123Greetings.com

Christy [monopolizingp25@rjsunday.com] just sent you an ecard from 123Greetings.com

You can view it by clicking here:

http://www.123greetings.com/send/view/05631010514011606136

You can also copy & paste the above link into your browser’s address bar.
Or if you prefer, you can go to http://www.123greetings.com/ and type your
ecard number (05631010514011606136) in the “Search Box” at the top right of the page.

Your ecard is going to be with us for the next 30 days.

If you need any help in viewing your ecard or any other assistance,
please visit our Help/ FAQ section at: http://help.123greetings.com/

We hope you enjoy your ecard,

Your friends at 123Greetings.com

http://www.123greetings.com

We respect your privacy. You will not be receiving any promotional emails from us
because of this ecard. To view our privacy policy, click on the link below:

http://info.123greetings.com/company/privacy_policy.html

Note: This is an auto generated mail. Please do not reply.

If you have any other problem please contact us by clicking on the following link:

http://help.123greetings.com/contact_us.html

This email was sent by 123Greetings.com, Inc., 1674 Broadway, New York, NY 10019.

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

ICANN – Your Domain Has Been Suspended! Uh, not really…just a trojan virus.

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-23-2010

Just when I thought these spammers had finally gotten their shit together,they send out this crap. I mean, come on, they don’t even mask the sketchy URL and it’s the same one from today’s fake Amazon order. Lazy ass mother fuckers. I’m sooo disappointed.

Letter from ICANN (the Internet Corporation for Assigned Names And Numbers)
Your Domain Has Been Suspended.

Click here for more information: http://booksalon.kr/index2.html

Please contact billing/support center A.S.A.P
Billing@yourdomain.com

VN:F [1.8.7_1070]
Rating: 2.0/5 (2 votes cast)

Fake: Your Amazon.com Order is Really Phishing and Trojan Virus

11

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-23-2010

Very nice work here. These phishing and virus attack scams are getting better all the time. There are getting greedy though. If they made most of the links legitimate but had only the most important ones fake, it would come off as far more legit.

This one takes you to booksalon.kr/index2.html where it tries to install a trojan virus before redirecting you to the infamous Canadian Pharmacy at occurleast.com

fake amazon order email spam

Thanks for your order, clay@claytowne.com

Did you know you can view and edit your orders online, 24 hours a day? Visit Your Account.

Order Information:
E-mail Address: clay@claytowne.com

Order Grand Total: $ 59.99

Earn 3% rewards on your Amazon.com orders with the Amazon Visa Card. Learn More
Order Summary:
Details:
Order #: D80-3421214-0586684
Subtotal of items: $ 62.99
——
Total before tax: $ 33.99
Sales Tax: $ 0.00
——
Total for this Order: $ 82.99


The following item was ordered:

Click here and see items, Price: $ 08.99
By: Click here
Sold by: Amazon Digital Services, Inc.
VN:F [1.8.7_1070]
Rating: 4.8/5 (10 votes cast)

Fake Digg Support Password Reset Email

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-22-2010

Poor alumicool.com. There site has been hacked and is hosting a phishing scheme among other nonsense like their gloriously defaced contact page here ( http://www.alumicool.com/contact.htm ) Ouch! And if they ever fix it here’s a PDF archive of the page for your viewing pleasure.

Digg Support

Account verification

Click on the link below to change your password.

Password Change

VN:F [1.8.7_1070]
Rating: 4.0/5 (2 votes cast)

Your chase-paymentech account is frozen due to multiple failed login attempts.

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-21-2010

Ye olde phishing scheme. The landing page for this one looks better than some, but still has a sketchy URL. I’m sure a few people will be giving up their logins and passwords today. The link goes to servicechase-paymentech.net

Fake Chase Logo Phishing Scheme
Dear customer,
Your chase-paymentech account is frozen due to multiple failed login attempts.
Please click-here to restore your online access.

Another version that goes to 2chasepaymentech.com

Fake Chase Logo Phishing Scheme

Dear Paymentech customer,
Your online account is frozen due to unusual activities.
Please click to restore your online account access, and prevent suspension. Thank you.

VN:F [1.8.7_1070]
Rating: 2.5/5 (2 votes cast)

We have reasons to beleive that your account may have been accessed by someone else. Please open attached file (open.html) and Follow instructions.

3

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-11-2010

Ho hum. Same old phishing/attack site scam. I only included this because I got like a dozen of these last night and I found it humorous to get an email telling me my email has been blocked. The statements and the action contradict each other. Kind of like receiving a phone call that tells you your phone isn’t working.

Dear Customer,

This e-mail was send by youremail@yourdomainname.com to notify you that we have temporarily prevented access to your account.

We have reasons to beleive that your account may have been accessed by someone else. Please open attached file (open.html) and Follow instructions.

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

FIFA World Cup South Africa… bad news

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-11-2010

Bah! Same old scam. Click on the HTML attachment and it takes you to an attack site so you can get a really cool virus of some sort or perhaps be subjected to a phishing scheme. Too lazy to figure out which but I’ll trust my Kaspersky on this one. Booooring.

Hello!!
FIFA World Cup 2010 scandal news, read attached document

VN:F [1.8.7_1070]
Rating: 3.0/5 (4 votes cast)

Angelina Jolie invited you to join Facebook…

2

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-07-2010

Dude I’m already like BFF with Jennifer Aniston. Didn’t Angelina check out my friends list first? How tacky!

fake angelina jolie facebook friend scam

Hi,
The following person invited you to be their friend on Facebook:
Angelina Jolie    Angelina Jolie
Invite sent:
Sun, 6 Jun 2010 18:25:29 -0500

Facebook is a great place to keep in touch with friends, post photos, videos and create events. But first you need to join! Sign up today to create a profile and connect with the people you know.
Thanks,
The Facebook Team

Already have an account? Add this email address to your account here.

VN:F [1.8.7_1070]
Rating: 4.4/5 (5 votes cast)

Someone was trying to steal your Twitter account password!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 06-07-2010

This one’s hilarious. Got about a dozen of these last night. Twitter is a third party remotely hosted platform. Even if someone was trying to steal your password (which doesn’t even make sense) the solution would be on their end not yours. Installing a “security module” on your computer would make about as much sense as installing a deadbolt on your front door because the bank told you someone tried to break into their vault last night. Where does the link ultimately take me to? A virus? A phishing scheme? Does it matter? I don’t care I just know it’s going to be bad.

twitter password stealing virus spam

Hi, clay@claybutler.com

Attention! We detected that someone was trying to steal your Twitter account password.

We strongly recomended you to download our secure module to protect account!

Please click on the link below:

http://twitter.com/Twitter_security_model_setup.zip

The Twitter Team

If you received this message in error and did not sign up for a Twitter account, click not my account.

Please do not reply to this message; it was sent from an unmonitored email address. This message is a service email related to your use of Twitter. For general inquiries or to request support with your Twitter account, please visit us at Twitter Support.

VN:F [1.8.7_1070]
Rating: 5.0/5 (6 votes cast)

Customer PayPal Satisfaction Survey ID: CDUEOCZVWU

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 05-28-2010

Looks like this one’s all the rage right now. First this site was hacked and now this one is hacked by the same group. Looks like ye olde phishing scheme. Bummer.

Dear Customer, 

CONGRATULATIONS !!!

You have been chosen by |"_Pay`Pal_"| Online department to take part in our
quick and easy 5 question survey.
In return we will credit $100 to your account - Just for your time!

Helping us better understand how our customers feel benefits everyone.
With the information collected we can decide to direct a number of changes
to improve and expand our online service.
The information you provide us is all non-sensitive and anonymous -
No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days while
we process the results of this nationwide survey.

We kindly ask you to spare two minutes of your time in taking
part with this unique offer!

To Continue click on the link below:
http://www.newlifechurchinternational.com/stats/update-au/index.php

© Copyright © 1999-2010 |"_Pay`Pal_"|. All rights reserved 

ID:

KWROOYKYTKPSSWZEJPIZOKSUEQVJHXUIQIBPKV

These guys are busy. Got another one this morning

Dear Customer, 

CONGRATULATIONS !!!

You have been chosen by |"_Pay`Pal_"| Online department to take part in our
quick and easy 5 question survey.
In return we will credit $100 to your account - Just for your time!

Helping us better understand how our customers feel benefits everyone.
With the information collected we can decide to direct a number of changes
to improve and expand our online service.
The information you provide us is all non-sensitive and anonymous -
No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days while
we process the results of this nationwide survey.

We kindly ask you to spare two minutes of your time in taking part
with this unique offer!

To Continue click on the link below:
http://www.irion.com.br/~ccrj/cgi-local/survey/index.php

© Copyright © 1999-2010 |"_Pay`Pal_"|. All rights reserved 

ID:

YBKLKJRFVMKWFOSKRLRELREOUVCTEWFXHXVKKL

How about one more…this time with feeeling.

Identifying Unauthorized Logon Attempts on 01/08/2010: (Error Message NO.
ALPNLLAOPRKJSLDKE)
Your account access has been limited for the following reason(s):
______________________________________________________________________________
1. We would like to ensure that your account was not accessed by an unauthorized
third party.
Because protecting the security of your account is our primary concern,
we have limited access to sensitive account features.
______________________________________________________________________________
2. Unusual account activity has made it necessary to limit account access
until additional verification information can be collected.
______________________________________________________________________________
3. If your account was hijacked, the account attached is vulnerable too. Please
respond as soon as possible!

4. Confirmation link: http://www.ecigroup.com.tw/product_htm/img/survey/index.php
______________________________________________________________________________
Once you complete all of the checklist items, your case will be reviewed
by one of our Account Specialists.
We will send you an email with the outcome of the review.

Document Reference: ID :

FOKWKFZWLPFDCJIUJOQMLWCIKODEQLCHXQKWTX
VN:F [1.8.7_1070]
Rating: 4.2/5 (5 votes cast)

OMFG! My Imaginary Standard Bank Account is Going to Be Suspended!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 04-28-2010

I love it when the Nigerian scammers try really, really, hard not to fuck up their English and it stills comes out wrong. Not super, duper wrong, but wrong enough to trip your BS detector. My favorite part are the last two sentences that cancel each other out. Doh!

Public Announcement from Standard Bank.

Please note that due to recent complains from our customers we have decided to add a little more security to our customers online banking experience. To enjoy this you are hereby advised to update your online account to add more security to your online banking account.

In order for your online account to remain active, You would have to upgrade your online account. please Use the button below to update your online banking account.

Update my Online Account

Failure to adhere to this warning will cause your online banking account to be suspended within 48hrs. Please do not log into your account until 48hrs from now so your account can be fully updated.

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

You have (1) Message from Navy Federal Credit Union Email ID: HEGIPBXOYJ

1

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 04-27-2010

Here’s a new twist to a classic phishing scam. Just sign on to get your new message! The sender and return email is rudysepdes@aol.com. Now that’s fucking funny. A baker using “his” personal email address for company communications.

Bank messages

My inbox 1 unread message(s)

We’d like to inform you that your secure mailbox has 1 new message(s).

Please visit Web Banker in order to read this message(s) from our secure location.

Navy Federal Credit Union: Account Access Sign On

View all messages

Bank messages will be automatically deleted after 6 months. If you have more than 100 bank messages, only the 100 most recent ones will be displayed.

Copyright © 2010 Navy Federal Credit Union

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

TD Bank Online Banking Account is About to Expire! OMFG!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 04-24-2010

My knowledge of obscure online banks has greatly increased thanks to these wonderful  Nigerian phishing schemes. Seriously, I though TD Bank was made up until I looked it up.

TD Bank Logo

Dear customer,

Please note that your TD Bank online banking account is about to expire.
It is strongly recommended to update it immediately.
Update form is located here:

http://access.tdbank.com/core/appid=17309/login.aspx?RedirectUrl=AccountUpdate

Sincerely, TD Bank Administration.

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

Imaginary Bank Midwest Internet Banking Account is Facing Suspension!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 04-21-2010

Oh no, another non-existent account is in jeopardy! I wondered why these things keep slipping by my spam filter so I looked at the code of the original email. Check out all this extra nonsense. All the text between the <!– and the –> tags are commented, meaning they can be read by a machine or a human looking at the code but will be hidden from regular viewing. My spam filters read the entire code and can’t figure out what to do with it.

<span style=3D"FONT-SIZE: 45px;">B</span><span style=3D"FONT-SIZE: 35px;"=
>ank<!--But you have had a little luck. You know you do. Yet perhaps this=
 was fitting. Her answer came quick and sharp.--></span> &nbsp;=A0=A0=A0=
=A0=A0=A0
<span style=3D"FONT-SIZE: 45px;">M</span><span style=3D"FONT-SIZE: 35px;"=
>idwest<!--What rating did you hold? You have not laughed once. It is my =
honor. Look at this!--></span>

</div>
<div style=3D"FONT-FAMILY: TIMES NEW ROMAN; FONT-SIZE: 12px; width: 470px=
; margin: 7px; padding-top: 10px;padding-left: 5px;padding-right: 10px; p=
adding-bottom: 10px;"><span style=3D"COLOR: #000000; font-family:arial, s=
ans-serif">
As a Bank <!--Perhaps you don't care for the brand. You told us to obey h=
er.-->Midwest customer, your privacy and<!--When will supper be ready? Ro=
bert Jordan thought. But Maria has been good.--> security always come fir=
st. We have<BR>
been dedicated<!--Slote was rejected. I'll start him for you. And who is =
Golz? Nobody ever did.--> to customer safety and protection, and our <!--=
Try a pinch. Won't you come too?-->mission remains as<BR>
strong as ever.<BR>

We inform<!--What is the matter with you? There is no tie between us. One=
 feels so free in it.--> you that your Bank<!--All knew what was coming. =
I'm glad to hear him talking straight. When I saw that No.--> Midwest Int=
ernet <!--You've turned me a point or two. Let us wait. He passed his han=
d over his forehead.-->banking <!--We don't mean any mischief. Do I kiss =
thee better? They had no males to cater to.-->account is about to expire.=
<BR>
It is strongly <!--It may be more useful now. Can you catch! Imagine my h=
orror! This is the Bay of Funchal.-->recommended to update<!--There were =
no ladies and no children. At twenty you stole horses.--> it immediately.=
 Update form is<!--Then the matter is at an end. Who is he? There is the =
window. Hurrah my boy!--> located here:<BR>
<BR>
<A HREF=3D"http://low.cc/CG9ZE" style=3D"color: #002CA1"><span style=3D"f=
ont-family: TIMES NEW ROMAN; font-size: 12px">http://bankmw.com/formid=3D=
1280514/update.aspx?ReturnUrl=3D<BR>
PBI_PBI1961/?%EBC1961.asp?Rt=3D101006699&LogonBy=3DConnect3&<BR>
PRMAccess=3DAccountUpdate</span></A><BR>
<BR>
However,<!--He seems very fond of her. That's what I think of him. You dr=
ive me out of the house.--> failure to confirm your records may result in=
 account<!--At last my turn came. That was because he was safely dead. Bu=
t I am jealous. It always happens so.--> suspension.<BR>
This is an automated <!--Damned if it hasn't. It was just like a new auth=
or.-->message. Please, do not reply.<BR>
<BR>
<BR>
<B><span style=3D"COLOR: #000000; font-family:arial, sans-serif; padding-=
left:220px">Sincerely, Bank<!--Hurrah my boy! Pearson is the senior. But =
he has nice tastes. It is so dark.--> Midwest administration.<span></B>
</span></div>
</BODY></HTML>

Bank Midwest

As a Bank Midwest customer, your privacy and security always come first. We have been dedicated to customer safety and protection, and our mission remains as strong as ever.

We inform you that your Bank Midwest Internet banking account is about to expire. It is strongly recommended to update it immediately. Update form is located here:

http://bankmw.com/formid=1280514/update.aspx?ReturnUrl=

PBI_PBI1961/?%EBC1961.asp?Rt=101006699&LogonBy=Connect3&
PRMAccess=AccountUpdate

However, failure to confirm your records may result in account suspension.
This is an automated message. Please, do not reply.

Sincerely, Bank Midwest administration.

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Dear HSBC Bank Customer Please Fill Out Our Fraudulent Form

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 03-26-2010

Translation: “We’re hoping you have an account with HSBC and will click on this link. We further hope you will ignore the fact that the URL is http://sip.plc.la/webps/ and an obvious forgery and fill out our form anyway.”

Dear HSBC Bank Customer,

Your Internet Banking security code was entered incorrectly more than 3 times.
For the protection of your account we have suspended access to it.
To restore access please Log In correctly.
Previous notifications have been sent.

Thank you for choosing HSBC Bank UK..
Copyright HSBC Bank UK PLC 2010. All rights reserved.

VN:F [1.8.7_1070]
Rating: 5.0/5 (3 votes cast)

First National Bank’s “Compulsary” Phishing Scheme

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 03-26-2010

Damn, now my imaginary FNB account is having issues.

Dear FNB Customer,
Due to the fraudulent activities noticed on our Internet banking system,
we have decided to make an Update page for you, your account(s) and
for security reasons. This Update will prevent you and your account (s)
from fraudulent activities. This account update is compulsory.
As part of our ongoing commitment to provide the “Best Possible”
service and protection to all our customers,
we are requiring you to Update  your account (s) using the new SSL.
Please Update your online banking account (s) by clicking on the below link now.
click here to update your banking session

Online Banking Security Team
© 2010 First National Bank Online Customer Service
VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

ABSA BANKING UPDATE SCAM

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 03-26-2010

Wow! I’m really liking ABSA’s new “scheme”. The link takes you to a forged website (abassakandasolu.com) so you can conveniently give the spammer’s all your personal info. Awesome!

Do you know that with Absa Internet banking, you can eliminate the cost of receiving and transferring funds from or to your account?

Absa has introduced a new scheme for all account holders to receive a return on incurred charges over the year.
This benefit is available to all internet banking subscribers with a minimum balance of R1000.

You are hereby advised to verify your account in other to qualify for this benefit.

Click here to verify

ABSA BANK
Internet Banking Team

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

New Alert Notice American Express Phishing Scam

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 03-13-2010

Glad their “technical service department” is on top of these things.

Dear Customer,

Our technical service department has recently discovered that your information on file with us is incomplete.

Your American Express on file with us is: 37xxxxxxxxxxxxxx .

Please update your American Express account on our secured server below:
(If you cannot click on the link, please copy and paste it into your browser’s address bar).

Continue To Online Update Form

We appreciate your prompt attention to this important matter.
*If you account information is not updated within 48 hours then your ability to access your account will be restricted.

Thank you

American Express Company.


Copyright The products, account packages, promotional offers and services described on this website may not apply to customers of International Personal Banking (IPB) or Global Executive Banking (GEB). IPB customers should visit the IPB Web site and GEB customers should visit the GEB Web site to obtain such information.
Copyright © 2010 American Express Company.
VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Another Fake MoneyGram Notice to Reactivate Your Account.

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 02-26-2010

What a clumsy phishing attempt. Check out the crazy URL! But hey, if you want to give your personal info to criminals, then go for it!

Notification – Your eMoneyGram account has become inactive.

To avoid losing your online services, you have to reactivate your MoneyGram account now.
Please visit our website located at:

http://p8159-ipbfp403oomichi.oita.ocn.ne.jp/mg/eMoneyGram-com/eMoneyTransfer/

to login and reactivate your online account on file with us.

As the primary contact, you have to reactivate these services or you will no longer be able to use them.
We apologize for any inconvenience this may have caused.

Thank you for using MoneyGram.

Regards,
eMoneyGram Customer Service

____________
You are receiving this email notification because this email address is listed as the administrative contact email for your MoneyGram account.
Please do not reply to this email. This mailbox is not monitored and you will not receive a response. For assistance, log in to your account and click the Help link.
?005 – 2010 MoneyGram. All rights reserved.

CQTHMCPCKEHSZDZBVINWDIXDXRQOVDPVTYKYSO

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Fake PayPal Account Warning Plus You Won a BONUS CODE 2010!

3

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 02-02-2010

This is one messed up phishing scheme. The subject is a winning announcement and the body is a fake PayPal warning.

Subject: You won a BONUS CODE 2010/

From: Accounts2010up@security.com

Identifying Unauthorized Logon Attempts on February. 01, 2010:
(Error Message No.
FE09POQVHAK48)
Your account access has been limited for the following reason(s):
______________________________________________________________________________
1. We would like to ensure that your account was not accessed by an
unauthorized third party.
Because protecting the security of your account is our primary concern,
we have limitedaccess to sensitive PayPal account features.
_____________________________________________________________________________
2. Unusual account activity has made it necessary to limit account access
until additional verification information can be collected.
_____________________________________________________________________________
3. If your account was hijacked, the PayPal account attached is
vulnerable too. Please respond as soon as possible!
PayPal Confirmation link:

http://www.dealfarm.com/paypal/payments/update-pay-pal/index.php

Once you complete all of the checklist items, your case will be
reviewed by one of our Account Specialists.
We will send you an email with the outcome of the review.
If, after reviewing your PayPal account information, you seek
further clarification regarding your
account access, please contact PayPal Online Banking by
visiting the Help Center and clicking "Contact Us".

Thank you.
PayPal Team.

02/02/2010

Copyright ? 1999-2010 PayPal. All rights reserved
______________________________________________________________________
Copyright Sandstone Technology Pty Ltd [ 2.0.63 7CFD 2144 FBEE ]
This email has been scanned by the MessageLabs Email Security System.
______________________________________________________________________ 

ICZPJVMRMPINELRIDTBEEHUJROMXJLWXNBBBZB
VN:F [1.8.7_1070]
Rating: 4.0/5 (4 votes cast)

Damn, My Visa Card Really Gets Around!

1

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-21-2009

This is what makes having so many email addresses fun. Got these within hours of each other. Tajikistan, Monaco, and Brazil…somebody’s sure been busy. Two came to the same address. Doh!

Dear VISA card holder,A recent review of your transaction history determined that your card was used at an ATM located in Tajikistan, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card at:

http://alerts.visa.com/cards/alerts/transactions.php?ref=122853337849500567172857778191580285819398744573107987044294120&email=clay@claytowne.com

VISA Cards Support

Message ID: JN23MVTLQ709NYEFAE72B07YLFR6VWIPE11CTB9YR46A40NCOOTEROW5EM

————————————————————————————————-
Dear VISA card holder,A recent review of your transaction history determined that your card was used at an ATM located in Monaco, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card at:

http://sessionid_HZ056KWMX62ND2.visa.com/cards/alerts/transactions.php?ref=9787082376456043491507719988651263270352044197840170593699117950&email=clay@claytowne.com

VISA Cards Support

ID: X3RIGYKTK5FZVD1M5N0Z3NDO

————————————————————————————————-
Dear VISA card holder,A recent review of your transaction history determined that your card was used at an ATM located in Brazil, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card at:

http://sessionid-9Z4M7AYJ.visa.com/cards/alerts/transactions.php?ref=3026959053374990132252786405449661288439199148695496226731&email=clay@claybutler.com

VISA Cards Support

id: LG581NBX94P20RDEUJB37243SC9PNVZ7TDLJ

VN:F [1.8.7_1070]
Rating: 3.7/5 (3 votes cast)

State Vaccination H1N1 Program Phishing Scheme

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-02-2009

And after you do this be sure to help transfer millions of dollars from that abandoned account in Africa.

You have received this e-mail because of the launching of State Vaccination H1N1 Program.

You need to create your personal H1N1 (swine flu) Vaccination Profile on the cdc.gov website. The Vaccination is not obligatory, but every person that has reached the age of 18 has to have his personal Vaccination Profile on the cdc.gov site. This profile has to be created both for the vaccinated people and the not-vaccinated ones. This profile is used for the registering system of vaccinated and not-vaccinated people.
Create your Personal H1N1 Vaccination Profile using the link:

Create Personal Profile

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

IRS Can’t Decide How Big My Refund Is!

0

Posted by Mr Spamalicious | Posted in Computer Virus Spam - Open the Attachment or Follow a Link to Get Infected by a Trojan, Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-02-2009

Well this is a no brainer. Of course I’m going for the $821.73 refund. That’s more than twice as much as the $401.49 one!

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 401.49$ tax refund under section 501(c) (15) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

————————————————

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 302.36$ tax refund under section 501(c) (20) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

————————————————

Internal Revenue Service
United States Department of the Treasury
After the last annual calculations of your fiscal activity we have determined that you are eligible to receive 821.73$ tax refund under section 501(c) (17) of the Internal Revenue Code. Please submit the Tax Refund Request Form and allow us 3-9 days to process it.

Yours faithfully,
Sarah Hall Ingram, Commissioner

This notification has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

You have to change the security mode of your account, from standart to secure….Uh, Ok.

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 12-02-2009

Well this is a good idea. I had no idea my account was set to “standart”. What a dummy I am. That doesn’t even make sense. I’m going to log in and give them all my private information right now!

Dear owner of the clay@claytowne.com mailbox,
You have to change the security mode of your account, from standart to secure.
Please change the security mode by using the link below:

http://accounts.claytowne.com.dirddrf.be/webmail/settings/noflash.php?mode=

standart&id=06941183650052151850794798913980915326868225045369503
31663899731508&email=clay@claytowne.com

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Laziest Phishing Scheme Ever!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 09-04-2009

Wow, this has got to be the most lazy phishing attempt ever. They’re not even trying to spoof a real ISP. It’s like a murder holding out a knife and asking the victim to fall on it because working his arm back and forth is just too much trouble. Gotta love how the future password is “optional”.

Subject: Please Ready Very Carefully And Reply.

Dear Email Account User,

We are advising you to change the password on your email account
in order to prevent any unauthorised account access following the
network instruction we previously communicated, all Mailhub systems
will undergo regularly scheduled maintenance. Access to your e-mail
via the Webmail client will be unavailable for some time during this
maintenance period.

We are currently upgrading our data base and e-mail account center
i.e homepage view. We shall be deleting old email accounts which
are no longer active to create more space for new accounts users.
we have also investigated a system wide security audit to improve
and enhance our current security.

In order to continue using our services you are require to update
and re-comfirmed your email account details as requested below.

To complete your account re-comfirmation,you must reply to this
email immediately and enter your account details as requested below.

Username : (**************)
E-mail Login ID(**********)
Password : (**************)
Date of Birth :( **************)
Future Password :( **************)(Option)

Failure to do this will immediately render your account deactivated
from our database and service will not be interrupted as important
messages may as well be lost due to your declining to re-comfirmed
your account details to us.

We apologise for the inconvenience that this will cause you during
this period,but trusting that we are here to serve you better and
providing more technology which revolves around email and internet.

It is also pertinent,you understand that our primary concern is
for our customers, and for the security of their files and data.

COMFIRMATION CODE: -/93-1A388-480 Technical Support Team.

VN:F [1.8.7_1070]
Rating: 5.0/5 (1 vote cast)

Security and Confidentiality and Are at The Heart of The Associated Bank ;)

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 09-04-2009

Well, OK, If you say so. It is compulsory.

associated_bank

Dear eManagerPlus client,

Security and confidentiality are at the heart of the Associated Bank. Your details (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.

We would like to notify you that Associated Bank carries out client details confirmation procedure that is compulsory for all our customers. This procedure is attributed to a routine banking software update.

Please visit our Customer Confirmation Form using the link below and follow the instructions on the screen.

http://bolb5.associatedbank.com/web_bank/confirm.asp?driver=19bvezkDkyctnhurdOhsa

Associated Bank eManagerPlus Customer Service

VN:F [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Trouble at Sterling Bank!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 09-02-2009

Now my non-existant Sterling Bank account is going to be suspended! I’m spending half of every day just making sure all my imaginary bank accounts stay open!

STERLING
SAVINGS BANK

As a Sterling Savings Bank customer, your privacy and security is
a primary task for us. We have been dedicated to customer safety
and protection and our mission remains as strong as ever.

We inform you that your Net Banking account is about to expire.
It is strongly recommended to update it immediately.
Update form is located here:

http://updates.sterlingsavingsbank.com/onlineserv/CM

However, failure to confirm your records may result in account suspension.
This is an automated message. Please do not reply.
Sincerely, Sterling Savings Bank Administration
VN:R_U [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Help! Imaginary Bell Canada Account Compromised!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 09-01-2009

Dammit! Now my non-existent Canadian Bell account is being compromised!

lg_bell

Dear Customer,

This e-mail was sent by Bell Canada to notify you that we have temporarily prevented access to your account.

We have reasons to believe that your account may have been accessed by someone else. Please verify your details by following the link below :

https://www.bell.ca/account-activation?id=539933

© Bell Canada

( Please do not reply to this e-mail , this account is not monitored. Follow the instructions in the e-mail )

VN:R_U [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)

Help! Unusual and High Risk Activity on my Bank of America Account!

0

Posted by Mr Spamalicious | Posted in Gone Phishing Spam - Identity Theft, Bogus Errors, and Fake Warnings | Posted on 09-01-2009

I’m getting so fed up with all the unusual and potential high risk activity with my B of A account! I’m going to call them up and give them a piece of my mind! You think a major bank like B of A would have better security!

alertboalogo

As part of our security measures, we regularly screen activity in the system.
We recently contacted you after noticing an issue on your account.
We requested information from you for the following reason:
We have observed activity in this account that is unusual or potentially high risk.

Please download the form attached to this email and open it in a web browser.
Once opened, you will be provided with steps to restore your account access.
We appreciate your understanding as we work to ensure account safety.
Sincerely,
Bank of America Account Review Department
VN:R_U [1.8.7_1070]
Rating: 0.0/5 (0 votes cast)