Monday, September 24, 2012

Internet Scam: Fake Shipping Notification Scam

The below email got my attention more for the text at the bottom which you wouldn't see because it was white text on a white background, but when I selected the text - there it was. Very weird, though I figure it's purpose is to randomize that text to avoid the spam filters, which worked, because it got through to me.

Also notice the FROM email. That is a technique spammers use to trick people who aren't paying attention. ups-support.com is NOT an UPS domain name. It's not the same. But scammers are hoping you don't notice that.

And of course, this email had the expected malicious attachment payload (the attached file was named UPS_Label_Copy_US_ID45555.zip - which doesn't even match the ID number in their subject line, but whatever - scammers don't care about the details, they are seeking someone not paying attention) that, had I opened them (and I knew not to), would have probably installed a virus or spyware on my computer to monitor my keystrokes and look for passwords when I type them in.

Even if you DID have a package in route from UPS, these emails are NOT the way to check out the status. Go to the website yourself in a new browser window and look up the tracking number. Or call them.
Received: from ups-support.com ([80.123.214.210])
From: "UPS Customer Service" [international@ups-support.com]
Subject: UPS shipment status ID#5578

Notification,

We couldn’t deliver your parcel.

Status: Postal code isn’t specified.
LOCATION OF YOUR ITEM:Miami
STATUS OF YOUR ITEM: not delivered
SERVICE: Express Mail
NUMBER OF YOUR PARCEL:U452061644 NU
FEATURES: No

Postal label is enclosed to the letter.
Print a label and show it at your post office.

Important information!
If the parcel isn’t received within 30 working days our company will have the right to claim compensation from you for it's keeping in the amount of $21.26 for each day of keeping over limited time.

You can find the information about the procedure and conditions of parcels keeping in the nearest office.

Thank you for attention.
UPS Global Mail.

Evil spirits murder family jailed

Egypt-Israel accord may change over Sinai raids

Global growth fears creep into financial markets

Congo allows firm to hunt for oil in Virunga park

1 comment:

  1. Here is one I just got. It pretends there is some UPS invoice and a user might want to click on it but I've shown the actual links in brackets below, which one would only see if they passed their mouse over the links without clicking on them:

    Return-path: [2F589492B@eq2exploits.com]
    From: "UPSBillingCenter" [2F589492B@eq2exploits.com]
    Subject: Your UPS Invoice is Ready

    This is an automatically generated email. Please do not reply to this email address.

    Dear UPS Customer,

    New invoice(s) are available for the consolidated payment plan(s) / account(s) enrolled in the UPS Billing Center

    Please visit the UPS Billing Center[Links to http://raptureprotection.clanteam.com/LcxvP4W/index.html] to view and pay your invoice.

    Discover more about UPS:

    Visit ups.com[Links to http://snipdiva.com/8seaq7VE/index.html]

    ReplyDelete