Phishing and Spam Alerts
What is E-mail Spam and Phishing?
E-mail spam are messages sent to many people, often simultaneously, that either contain web links to Internet websites that host malware or contain executable malware within the message designed to infect the computer when opened. These messages are also called junk e-mail.
Phishing is the term for messages sent to individuals via e-mail or text message with the intent to fool unsuspecting recipients into providing personal information, such as user names, passwords and financial account information. They often employ social engineering tactics by creating messages that appear to be legitimate. These messages can also lure individuals to malware-hosting websites.
Spear phishing differs from phishing in that it targets a specific department, division or college, seeking unauthorized access to protected information. These messages allegedly come from IT support staff or other professionals in a position of authority from within the targeted department, division or college. As with phishing, these e-mails will attempt to trick users into divulging personal or financial information, or their credentials, or entice them into clicking on a link that could install malware on the computer.
ITS provides this website to help campus users identify illegitimate messages. The samples below are actual messages that are currently, or were previously, circulated on our campus.
If you have any questions related to the legitimacy of an e-mail message that you have received, please contact the ITS Help Desk at helpdesk@calstatela.edu or call them at 323-343-6170.
Other Resources:
April 4, 2013
---------------- Phishing E-mail ----------------
From: helpdesk@calstatela.edu [dxxx.lxxx@maine.edu]
To: info@calstatela.edu
Subject: ***URGENT: Incoming EMails Pending***
This is to inform you that we have added new features to our Mail Service and this have caused your incoming messages to be pending
Login to view incoming emails.
Once you have logged on, please wait for a response from our server to retrieve the list of pending emails and redirect to your inbox
April 4, 2013
---------------- Phishing E-mail ----------------
From: [scanner@calstatela.edu]
To: Recipient
Subject: Re: Scan from a Hewlett-Packard ScanJet 5434473
A document was scanned and sent to you using a Hewlett-Packard HP73598081
Sent to you by: LORAINE
Pages : 1
Filetype(s): Images (.jpeg) View
March 28, 2013
---------------- Phishing E-mail ----------------
From: California State University - Webmail Services [mxxxxxxx@pace.edu]
To: undisclosed-recipients
Subject: 1 New Message:-
You Have 1 New Important Mail Message,
Press The Link Below To View Message.
Press here to View Message
California State University, Los Angeles - Webmail Services
March 8, 2013
---------------- Phishing E-mail ----------------
From: Mercado Mxxxx [MMercadoxx@schools.nyc.gov]
To: undisclosed-recipients
Subject: FW: System Administrator Last Warning Before Your Account Being De-activated
Attachments: System Administrator1.docx
See To The File Attachment, Open and Fill The Form
________________________________
From: Mercado Melanie
Sent: Fri 3/8/2013 8:04 AM
Subject: System Administrator Last Warning Before Your Account Being De-activated
See To The File Attachment, Open and Fill The Form
March 7, 2013
---------------- Phishing E-mail ----------------
From: American Express [AmericanExpress@welcome.aexp.com]
To: Recipients
Subject: Your American Express Forgotten User ID
March 7, 2013
---------------- Phishing E-mail ----------------
From: LogMeIn.com Auto-Mailer [do-not-reply@logmein.com]
To: Recipient
Subject: LogMeIn Account Notification - Account locked
Dear LogMeIn User,
Your LogMeIn.com account has been locked due to several unsuccessful login attempts.
Event: Account locked
Source: Website
At: 3/6/2013 4:46 AM
From: 42.12.172.6
To unlock your account, you will need to complete the following unlock form :
https://secure.logmein.com/download.asp?action=unlock&form_id=6482653
After the form has been completed, forward a scanned copy to security@logmein.com.
(Please do not reply to this email, as it's sent from an address that's not monitored.)
If you need additional help, visit LogMeIn Support at:
http://help.logmein.com/SelfServiceTicketSupportSales?support=1&lang=en
Regards,
LogMeIn.com Support
March 6, 2013
---------------- Phishing E-mail ----------------
From: US Postal Service [tracking@usps.com]
To: Recipient
Subject: Missed package delivery!
Dear client ,
We attempted to deliver your item at 09:48 am on Mar 5th, 2013.
The delivery attempt failed because nobody was present at the shipping address, so this notification has been automatically sent.
You may arrange redelivery by visiting the link below or pick up the item at the U.S. Post Office indicated on the receipt.
If the package is not scheduled for redelivery or picked up within 48 hours, it will be returned to the sender.
Label/Receipt Number: 9205596901015300557981
Expected Delivery Date: Mar 5th, 2013
Class: Package Services
Service(s): Delivery Confirmation
Status: eNotification sent
To download the shipping receipt, in PDF format, visit:
http://www.usps.com/go/tools/apps/track/findInvoiceByTracking.aspx?id=9205596901015300557981
To check on the delivery status of your mailing or arrange redelivery please visit the following URL:
https://tools.usps.com/go/pages/trackconfirm/quick-track.html
Thank you,
© 2013 Copyright© 2013 USPS. All Rights Reserved.
*** This is an automatically generated email, please do not reply ***
March 4, 2013
---------------- Phishing E-mail ----------------
From: DELTA CONFIRMATION [dGEhXVAYOBwilN@studiovermaas.nl]
To: Recipient
Subject: Your Receipt and Itinerary
Thank you for choosing Delta. We encourage you to review this information before your trip.
If you need to contact Delta or check on your flight information, go to delta.com/itineraries
Now, managing your travel plans just got easier. You can exchange, reissue and refund electronic tickets at delta.com/itineraries.
Take control and make changes to your itineraries at delta.com/itineraries.
Speed through the airport. Check-in online for your flight.
Check-in
Flight Information
DELTA CONFIRMATION #: D1AA59CE
TICKET #: 00324576694122
Bkng Meals/ Seat/
Day Date Flight Status Class City Time Other Cabin
--- ----- --------------- ------ ----- ---------------- ------ ------ -------
Mon 11MAR DELTA 372 OK H LV NYC-KENNEDY 820P F 19C
AR SAN FRANCISCO 8211P COACH
Fri 15MAR DELTA 1721 OK H LV LOS ANGELES 1145P V 29A
AR NYC-KENNEDY 812A# COACH
Check your flight information online at delta.com/itineraries
March 1, 2013
---------------- Phishing E-mail ----------------
From: California State University Support Admin [noreply@calstate.edu]
To: Recipients
Subject: ***Email Service Support***
Access to this server is available from your location through the Universal Resource Locator Click or Copy the below link to a browser and fill the required information's: https://docs.google.com/forms/d/12Ek8YenfWuvQPAaGaIzwEpDhwWfpmlu2VqQQ5-D0buY/viewform?sid=6e62975e77fb582d&token=76OtKT0BAAA.tuzEcKM0WSde0Izh6qIdLw.0Qy50bccgyazjIDwhi-dTA
February 26, 2013
---------------- Phishing E-mail ----------------
From: Dxxxxx, Jennifer [jdxxxxx@FCPS1.ORG]
To: [user39@calstatela.edu]
Subject: INFO.
Dear Email User,
This to inform you that you have almost exceeded your mailbox size in our database. You have used 19.2GB out of your allocated 20.5Gb. You will be unable to send/receive mails as soon as you reach your mailbox limit. Please delete your sent items and empty your deleted items (thrash) to free up some space in your mail box, you are also required to upgrade to our new 25GB Webmail. Click UPGRADE NOW below to automatically upgrade your mailbox.
UPGRADENOW
This will automatically reset/upgrade your mailbox size into the new 25GB faster and better webmail system.
You will be notified as soon as upgrade is completed.
Thanks for your co-operation.
System Administrator.
Powered by Microsoft Outlook JSU Department.
***********************************************************************************************
Do not reply to this email, click on the link to automatically upgrade your mailbox.
***********************************************************************************************
February 25, 2013
---------------- Phishing E-mail ----------------
From: Trustwave [fasten4497@trustwave.com]
To: Recipients
Subject: TrustKeeper Network Scan Notification
February 15, 2013
---------------- Phishing E-mail ----------------
From: [Wxxxxxxx@CALSTATELA.EDU]
To: Recipients
Subject: From Friends
My dear Madam:
check this out
January 30, 2013
---------------- Phishing E-mail ----------------
From: Customer Service (D&B iUpdate) [donotreply@iupdate.dnb.com]
To: Recipients
Subject: D&B iUpdate : Company Order Request
Attachments: CompanyInfo.zip
D&B iUpdate : Company Request
Thank you,
Your request has been successfully processed by D&B.
All information has been reviewed and validated by D&B.
Please Find your Order Information attached.
iUpdate is D&B's Internet-based service that allows business principals to view, print, and request updates their company information.
CONFIDENTIALITY: The information contained in this transmission may contain privileged and confidential information. It is intended only for the use of the person(s) named above, who is an user of D&B - iUpdate service. If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution or duplication of this communication, and the information contained in it, is strictly prohibited. If you are not the intended recipient, please contact D&B and immediately destroy all copies of the original message.
This is an automated mail. Please do not reply to this message.
Dun & Bradstreet, Inc., 2000-2013. All rights reserved.
January 23, 2013
---------------- Phishing E-mail ----------------
From: Corporate eFax [message@inbound.efax.com]
To: Recipients
Subject: Corporate eFax message - 2 pages
January 22, 2013
---------------- Phishing E-mail ----------------
From: [sales1@exchange.calstatela.edu]
To: Recipients
Subject: Re: Fwd: Update for your banking account.
Dear Online Account Operator,
Your ACH transactions have been
temporarily disabled.
View details
Best regards,
Security department
January 22, 2013
---------------- Phishing E-mail ----------------
From: Xerox WorkCentre [xerox.device1@calstatela.edu]
To: Recipients
Subject: Scanned Image from a Xerox WorkCentre
Attachments: Scan_01-22-2013-820621362.zip
Reply to: Xerox.WorkCentre@calstatela.edu
Device Name: Not Set
Device Model: MX-8183N
Location: Not Set
File Format: PDF (Medium)
File Name: Scan_01-22-2013-820621362.zip
Resolution: 200dpi x 200dpi
Attached file is scanned image in PDF format.
Adobe(R)Reader(R) can be downloaded from the following URL: http://www.adobe.com/
January 15, 2013
---------------- Phishing E-mail ----------------
From: Discover [no-reply@disco.com]
To: undisclosed-recipients
Subject: Your account has been temporarily limited. W15012013
January 14, 2013
---------------- Phishing E-mail ----------------
From: Technical Team [info@live.com]
To: Recipients [info@live.com]
Subject: Storage Limit Exceeded Upgrade Your Email Quota
Dear members,
Storage limit on your mailbox exceeded you can't receive new mail click, bit.ly/13xq4Em
Regards,
Technical Team.
December 19, 2012
---------------- Phishing E-mail ----------------
From: Admin [info@mail.com]
To: undisclosed-recipients
Subject: Account Verification Update
The Helpdesk Program that periodically checks the size of your space email is sending you this information. The program runs weekly to ensure your inbox does not grow too large, preventing you from receiving or sending new email. As this message is being sent, you have 18 megabytes (MB) or more stored in your inbox.
To help us reset your space in our database, enter your current username
(___________) Password (_________) You will receive a periodic alert if your inbox size is between 18 and 20 MB. If the mailbox size is 20 MB, a program on your Webmail will move your oldest email to a folder in your home directory to ensure that you can continue to receive incoming emails. You will be notified that happened.
If your inbox grows to 25 MB, you will not be able to receive new emails and it will be returned to sender. These are all programmed to ensure your e-mail continues to work well. Thanks for your Desk cooperation.Help.
Important: Update email account verification!
December 5, 2012
---------------- Phishing E-mail ----------------
From: DocuSign Support via DocuSign [dse@docusign.net]
To:
Subject: Confidential - to ALL Employees


