Latest Email Scams

MALWARE ALERT! MWALWARE scam email from HSBC hsbcservces6@host61.registrar-servers.com www.hsbcservces.cf

DO NOT CLICK ON THE LINK IN THIS EMAIL!  This email IS NOT FROM HSBC BANK and the link DOES NOT TAKE YOU TO THE HSBC BANK WEBSITE!  The link takes you to http://hsbcservces.cf/clientsdata/Policy.doc.exe which is an executable program that contains MALWARE which can infect your computer and/or device!  If you have clicked or downloaded this file, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

Originating IP: 129.56.97.25
Originating ISP: As-natcom
City: Abuja
Country of Origin: Nigeria

from: Hsbc <hsbcservces6@host61.registrar-servers.com> via hsbcservces.cf 
reply-to: Hsbc <admin@hsbcservces.ml>
to: 
date: Mar 1, 2019, 1:31 AM
subject: Hsbc
mailed-by: hsbcservces.ml
signed-by: hsbcservces.cf

HSBC

Dear Client OF HSBC Bank,

A sudden change has been noticed on your “secure key app”
it is Advised that you review immediately,We do advise you to proceed to confimation on customer data using the referral button.

Please Do Note This Instruction Has Been Sent Also To Customers Of Similar Issue And You Are Advised To Review Immediately
Failure To So Permits Account Suspension

www.hsbc.com

From the .html of the email:
Failure To So Permits Account Suspension

www.hsbc.com ( http://hsbcservces.cf/clientsdata/Policy.doc.exe )

( http://hsbcservces.cf/clientsdata/Policy.doc.exe )
<a href=”http://hsbcservces.cf/q/index.php?option=com_acymailing&no_html=1&ctrl=url&urlid=1&mailid=9&subid=3703″>www.hsbc.com</a>
<p>&nbsp;</p>
<a href=”http://hsbcservces.cf/q/index.php?option=com_acymailing&no_html=1&ctrl=url&urlid=1&mailid=9&subid=3703″ target=”empty”><input type=”button”
value=”REFERRAL” /></a></blockquote><img alt=”” src=”http://hsbcservces.cf/q/index.php?option=com_acymailing&ctrl=stats&mailid=9&subid=3703&no_html=1″
 border=”0″  height=”1″  width=”50″ />

🔍 Exposing Online Scams – One Email at a Time

This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

There is no prize. No inheritance. No secret fortune.
It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

💬 Have you received a suspicious email?
Forward it to emailscamalerts@gmail.com and we’ll help investigate.
Together, we can make the internet a safer place — SCAM- and SPAM-free.

You might also like:

    MALWARE ALERT! Malware email from WARNING@mailadmin.com https://nsjsta.com/uu/viralert/index.php

    DO NOT CLICK ON THE LINK IN THIS EMAIL!  The link may contain MALWARE that can be harmful to your device.  If you have clicked or downloaded this file, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

    Originating IP: 129.205.113.13
    Originating ISP: Globacom-as
    City: Dambatta
    Country of Origin: Nigeria

    from: WARNING@mailadmin.com 
    to: 
    date: Tue, Jun 19, 2018 at 3:56 AM
    subject: WARNING: Virus Alert!!!

    Your email is infected.
    To keep your account safe, Click Here and run a Quick Email Scan now

    If you ignore this warning, we will shutdown your account without further notice,
    and all data will be permanently lost.

    We regret the inconvenience, but this exercise is aimed at helping us protect your account.

    From the HTML of the email:

    <a href=”https://nsjsta.com/uu/viralert/index.php“><b>Click Here</b></a>

    🔍 Exposing Online Scams – One Email at a Time

    This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

    There is no prize. No inheritance. No secret fortune.
    It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

    💬 Have you received a suspicious email?
    Forward it to emailscamalerts@gmail.com and we’ll help investigate.
    Together, we can make the internet a safer place — SCAM- and SPAM-free.

    You might also like:

      Loan scam email & MALWARE Alert from Mrs. Helen J. Anderson Loan Service Desk Prestige Finance Loan tester432@tandemservice.ru prestigefinanceloan02@gmail.com +27-840499150 +27-785758753

      *** The .pdf attachment that came with this email was flagged as containing a virus by my email client.

      from: Prestige Finance Loan <tester432@tandemservice.ru> 
      reply-to: prestigefinanceloan02@gmail.com
      to: 
      date: Fri, May 11, 2018 at 12:13 PM
      subject: GET QUICK LOAN FROM PRESTIGE FINANCE AT 5% FIXED INTEREST RATE
      mailed-by: tandemservice.ru

      Dear Valued Customer,

      Prestige Finance Loan is a registered financial services provider focused on partnering with individuals and cooperate bodies, by developing  opportunities for the small-medium-large businesses that drive South Africa’s economy. The offer is open to those who are blacklisted and those with bad credit records. We offer all types of loan and our interest rate is fixed for the entire duration of the loan.

      Prestige Finance Loan is made to suit each individual’s financial needs, helping them to achieve financial freedom and escape the trap of bad debt. Our simple three-step process to financial independence means our loan approval for qualified applications are granted within 48 hours.

      Prestige Finance Loan is committed to providing personal loans, Business Loans, Car Loans, Home loan and debt consolidation loans for only 5% per annum, products that enable the responsible use of credit as part of a structured financial plan.

      Too many South Africans fall prey to loan sharks. The loans they get from these unscrupulous lenders aren’t designed around their situations and have high repayments.

      Type of Loan And Loan Range

      *Loan Duration 1year to 20years for personal and business loan

      *Platinum Package Loan:…..R30,000,000.00 ,*Gold Package Loan…………..R20,000,000.00

      *Premium Package Loan:…..R10,000,000.00 ,*Large Scale Business Loan: R1,000,000.00

      *Mortgage/Home Loan:……..R500,000.00 and Above., *Small Scale Business Loan:. R200,000.00 and Above.

      Applying for a loan is quick and easy!

      To benefit from our tremendous offer, email the required details below to the following address; prestigefinanceloan02@gmail.com

      Full Names: ID Number: Cell Number: E-mail: Occupation: Monthly Salary:

      See attached file for loan application form

      Kind Regards,

      Mrs. Helen .J. Anderson
      (Loan Service Desk)
      Tel.: +27 840499150, +27 785758753

      attachment; filename=”Prestige Finance Loan Application Form.pdf”;

      🔍 Exposing Online Scams – One Email at a Time

      This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

      There is no prize. No inheritance. No secret fortune.
      It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

      💬 Have you received a suspicious email?
      Forward it to emailscamalerts@gmail.com and we’ll help investigate.
      Together, we can make the internet a safer place — SCAM- and SPAM-free.

      You might also like:

        MALWARE ALERT! MALWARE scam email from UPS Ups@purdue.edu www.ups-tracking.website

        DO NOT CLICK ON THE LINK IN THIS EMAILThis email is not from UPS and the link does not take you to the UPS website!  The link takes you to http://ups-tracking.website/label.jar and has been flagged by engines as MALWARE that can infect your computer!

        http://trafficlight.bitdefender.com/info?url=http://ups-tracking.website

        Stop! This website is not safe
        This website contains malware that may harm your computer
        This website contains elements classified as malware: software that can harm your computer or operate without your consent. Visiting a site that contains malware can infect your computer.


        If you have clicked on this link, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

        Originating IP: 128.210.5.16
        Originating ISP: Purdue University
        City: West Lafayette
        Country of Origin: United States

        from: UPS <Ups@purdue.edu> 
        to: “ig.com.br,” 
        date: Fri, Dec 1, 2017 at 8:52 PM
        subject: Package out for delivery
        mailed-by: purdue.edu

        UPS 

        To get an estimated delivery time for UPS packages, Download Shipping Label

        You have a package coming.

        Scheduled Delivery Date:  Saturday 12/02/2017

        Download

        UPS 
        Change Delivery
        Manage Preferences
        View Delivery Planner

        This message was sent to you at the request of the shipper to notify you that the shipment information below has been transmitted to UPS. The physical package may or may not have actually been tendered to UPS for shipment. To verify the actual transit status of your shipment, click on the tracking link below.

        Shipment Details

        From: Amazon, LLC

        Tracking Number:
        1Z3689Y603666787

        UPS Service: UPS GROUND
        Number of Packages: 1
        Package Weight: 17.8 LBS
        Scheduled Delivery: 12/02/2017
        Reference Number 1: 1081966

        Download the UPS mobile app

        © 2017 United Parcel Service of America, Inc. UPS, the UPS brandmark, and the color brown are trademarks of United Parcel Service of Amercia, Inc. All rights reserved.

        All trademarks, trade names, or service marks that appear in connection with UPS’s services are the property of their respective owners.

        Please do not reply directly to this e-mail. UPS will not receive any reply message.
        For more information on UPS’s privacy practices, refer to the UPS Privacy Notice.
        For questions or comments, visit Contact UPS.

         This communication contains proprietary information and may be confidential. If you are not the intended recipient, the reading, copying, disclosure or other use of the contents of this e-mail is strictly prohibited and you are instructed to please delete this e-mail immediately.

        UPS Privacy Notice
        Contact UPS 

        🔍 Exposing Online Scams – One Email at a Time

        This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

        There is no prize. No inheritance. No secret fortune.
        It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

        💬 Have you received a suspicious email?
        Forward it to emailscamalerts@gmail.com and we’ll help investigate.
        Together, we can make the internet a safer place — SCAM- and SPAM-free.

        You might also like:

          MALWARE ALERT! Malware email from Scammer Posing as UPS ups@purdue.edu 832-772-2139 www.upss.website

          DO NOT CLICK ON THE LINK IN THIS EMAIL!  The link in the email is http://www.upss.website/ups.jar and has been flagged by multiple engines as MALWARE that can infect your computer!

          http://trafficlight.bitdefender.com/info?url=http://upss.website

          Stop! This website is not safe
          This website contains malware that may harm your computer
          This website contains elements classified as malware: software that can harm your computer or operate without your consent. Visiting a site that contains malware can infect your computer.


          From Google:

          This site may harm your computer
          Malicious software can allow unwanted programs to steal passwords and credit card numbers, slow down your computer, or change your search results. We recommend that you don’t visit the site until this message disappears from the search result.


          If you have clicked on this link, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

          Originating IP: 17.11.20.15
          Originating ISP: Apple Inc.
          City: Cupertino
          Country of Origin: United States

          from: ups <ups@purdue.edu> 
          to: 
          date: Mon, Nov 20, 2017 at 5:47 PM
          subject: Order Shipped.
          mailed-by: purdue.edu

          Dear,

          Your order has been shipped via Ups.. Click here to view receipt and tracking number.

          Thank you for your order. If you have any question,

          Please call me at 832-772-2139 or email me

          Please contact us immediately if you are unable to view.

          From the HTML of the email:

          <A HREF=”http://www.upss.website/ups.jar“>Click here</A>

          🔍 Exposing Online Scams – One Email at a Time

          This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

          There is no prize. No inheritance. No secret fortune.
          It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

          💬 Have you received a suspicious email?
          Forward it to emailscamalerts@gmail.com and we’ll help investigate.
          Together, we can make the internet a safer place — SCAM- and SPAM-free.

          You might also like:

            MALWARE ALERT! MALWARE email from Bates Randy grantj@gvsu.edu cp.my

            DO NOT OPEN THE DOCUMENT ATTACHED TO THIS EMAIL AND DO NOT CLICK ON THE LINK IN THE DOCUMENT!  The link takes you to https://cp.my/robots.php which has been flagged by BitDefender as containing MALWARE!

            http://trafficlight.bitdefender.com/info?url=http://cp.my

            Stop! This website is not safe
            This website contains malware that may harm your computer
            This website contains elements classified as malware: software that can harm your computer or operate without your consent. Visiting a site that contains malware can infect your computer.

            If you have clicked this link, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

            Originating IP: 218.61.3.229
            Originating ISP: China Unicom China169 Backbone
            City: Shenyang
            Country of Origin: China

            from: Bates Randy <grantj@gvsu.edu> 
            to: 
            date: Thu, Oct 5, 2017 at 4:56 AM
            subject: Telegraphic Transfer Receipt
            mailed-by: gvsu.edu
            signed-by: gvsu5.onmicrosoft.com

            We have made payment of $35,600 USD today as promised.  Find T/T receipt attached.

            Thank you,
            Bates Randy

            attachment; filename=”TT_Receipt.docx”
            The link text shows an adobe link, but the actual link takes you to https://cp.my/robots.php

            Bates Randy shared a file using Adobe cloud.  Click on the link below to download.

            https://www.adobe.com/cloud/yMLvNa6UU563tKZdENCKKCZ8/

            File Description: Telegraphic Transfer Receipt

            Date: 5th October, 2017

            File Size: 256kb

            Thank you for using Adobe.

            🔍 Exposing Online Scams – One Email at a Time

            This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

            There is no prize. No inheritance. No secret fortune.
            It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

            💬 Have you received a suspicious email?
            Forward it to emailscamalerts@gmail.com and we’ll help investigate.
            Together, we can make the internet a safer place — SCAM- and SPAM-free.

            You might also like:

              MALWARE ALERT! MALWARE scam email from Naresh Shirsath Nobel Hygiene Pvt. Ltd. Executive-Operations sales1@ellistoncaravanpark.com.au

              DO NOT OPEN THE FILE ATTACHED TO THIS EMAIL!  The order.doc file attached to this email contains MALWARE!  If you have clicked/downloaded this file, run a full virus scan as soon as possible.  You can download free versions from safe websites such as https://www.malwarebytes.org/ and http://free.avg.com/us-en/homepage

              from: Naresh Shirsath <sales1@ellistoncaravanpark.com.au> 
              reply-to: Naresh Shirsath <sales1@ellistoncaravanpark.com.au>
              to: 
              date: Mon, May 1, 2017 at 7:04 AM
              subject: Order

              Dear Sir / Madam,

              Please find the attached purchase order. Please check and get back to us asap.

              Thanks & Regards,
              Naresh Shirsath
              Executive-Operations
              Nobel Hygiene Pvt. Ltd.
              A – 70, MIDC, Malegaon, Sinnar, Nashik – 422 113 (MH)
              Mobile: 7385089006.

              attachment; filename=order.doc;

              🔍 Exposing Online Scams – One Email at a Time

              This blog is dedicated to unmasking Advance Fee Fraud scams. Every suspicious or scammy email I receive gets posted here—not because you’re special, but to show you the truth:

              There is no prize. No inheritance. No secret fortune.
              It’s just a scam, and if you reply, you’ll soon be asked to pay a “processing fee”… then they vanish.

              💬 Have you received a suspicious email?
              Forward it to emailscamalerts@gmail.com and we’ll help investigate.
              Together, we can make the internet a safer place — SCAM- and SPAM-free.

              You might also like: