Kansas State University

search

Scams

Month: January 2019

Phishing Scam – 1/29/19 – Latest INVOICE from *******

URL blocked at the border and Trend is already blocking.

From: ******* <******@ksu.edu>
Sent: Tuesday, January 29, 2019 3:01 PM
To: ******* <******@ksu.edu>
Subject: Latest INVOICE from *******
I just left a voicemail message, however wanted to send an email as well.
On your January Reconciliation report your beginning amount of $7,132.55 does not match either of the January invoices in the FTP HUB.
Please let us know the difference of the $672.75 so we can begin working your payment.

please Click here to get the invoice directly from our website. <http://kuoying.net/UltAl_ln-VWbCg/qU/Payments/01_19>

*********
*******@ksu.edu

Phishing Scam – 1/30/19 – Service Update on 30 January, 2019 ID: #47JLQG#

Sent to Trend.

From: Ksu Support-Team <czx@cnhlnd.com>
Sent: Wednesday, January 30, 2019 10:04 AM
Cc: *******
Subject: Service Update on 30 January, 2019 ID: #47JLQG#
HI *******,
Your office-365 email is out of date, and you won’t be able to send or receive new messages. We recommend you confirm your update within 12hours to avoid being deactivate.
CONFIRM NOW [https://www.shahent.co.in/.d/?email=*******@ksu.edu]
Note: failure to confirm your mailbox will result to permanent disable.
Regards,
Micrοsοft Suρροrt
This email was sent to *******@ksu.edu.
AccID : ##7951916

Phishing Scam – 01/30/19 – Service Update on 30 January, 2019 ID: #N5KOJ0#

URL is blocked at the border, sent to Trend. Web Host notified.

From: Ksu Support-Team
Sent: Wednesday, January 30, 2019 9:14 AM
Cc: ****** ****** <******@ksu.edu>
Subject: Service Update on 30 January, 2019 ID: #N5KOJ0#
HI ******,
Your office-365 email is out of date, and you won’t be able to send or receive new messages. We recommend you confirm your update within 12hours to avoid being deactivate.
CONFIRM NOW [https://www.shahent.co.in/.d/?email=******@ksu.edu]
Note: failure to confirm your mailbox will result to permanent disable.
Regards,
Micrοsοft Suρροrt
This email was sent to ******@ksu.edu [mailto:******@ksu.edu].
AccID : ##6906796

Phishing Scam – 1/25/2019 – Latest INVOICE from Tracy McIntyre

This is a baiting type of scam. Blocked at the border, Trend classified as dangerous, webhost notified.

From: Travel Section Information List on behalf of ******** ******
Sent: Tuesday, January 29, 2019 3:00 PM
To: travel-l@listserv.ksu.edu
Subject: Latest INVOICE from ****** *******
I just left a voicemail message, however wanted to send an email as well.
On your January Reconciliation report your beginning amount of $7,132.55 does not match either of the January invoices in the FTP HUB.
Please let us know the difference of the $672.75 so we can begin working your payment.
please Click here to get the invoice directly from our website. [http://kuoying.net/UltAl_ln-VWbCg/qU/Payments/01_19]

Phishing Scam- 1/29/2019 – Copy Invoice From

Baiting type of scam. URL blocked at border, Trend classified as dangerous.

From: ****** ******* <*****@ksu.edu>
Sent: Tuesday, January 29, 2019 5:07 PM
To: ****** *********
Subject: Copy Invoice from ****** ******* 01/30/19
Here is the invoicae you requested. Please let me know if there is anything else I can help you with.
Download DOC. [http://new.kgc.ac.bd/kfra_Kj-C/w9I/Clients_information/01_19]
****** *******
*****@ksu.edu

********
********

Phishing Scam-1/29/2019- Caution! Attack hackers to your account!

Reply to Scam.

From: ***********@ksu.edu <***********@ksu.edu>
Sent: Tuesday, January 29, 2019 3:53 PM
To: ******* ******
Subject: Caution! Attack hackers to your account!
 Hello!
I have very bad news for you.
12/10/2018 – on this day I hacked your OS and got full access to your account ***********@ksu.edu
So, you can change the password, yes… But my malware intercepts it every time.
How I made it:
In the software of the router, through which you went online, was a vulnerability.
I just hacked this router and placed my malicious code on it.
When you went online, my trojan was installed on the OS of your device.
After that, I made a full dump of your disk (I have all your address book, history of viewing sites, all files, phone numbers and addresses of all your contacts).
A month ago, I wanted to lock your device and ask for a not big amount of btc to unlock.
But I looked at the sites that you regularly visit, and I was shocked by what I saw!!!
I’m talk you about sites for adults.
I want to say – you are a BIG pervert. Your fantasy is shifted far away from the normal course!
And I got an idea….
I made a screenshot of the adult sites where you have fun (do you understand what it is about, huh?).
After that, I made a screenshot of your joys (using the camera of your device) and glued them together.
Turned out amazing! You are so spectacular!
I’m know that you would not like to show these screenshots to your friends, relatives or colleagues.
I think $634 is a very, very small amount for my silence.
Besides, I have been spying on you for so long, having spent a lot of time!
Pay ONLY in Bitcoins!
My BTC wallet: 145SmyE7DBEQExsnXZobojbQqr5UdgbCHh
You do not know how to use bitcoins?
Enter a query in any search engine: “how to replenish btc wallet”.
It’s extremely easy
For this payment I give you two days (48 hours).
As soon as this letter is opened, the timer will work.
After payment, my virus and dirty screenshots with your enjoys will be self-destruct automatically.
If I do not receive from you the specified amount, then your device will be locked, and all your contacts will receive a screenshots with your “enjoys”.
I hope you understand your situation.
– Do not try to find and destroy my virus! (All your data, files and screenshots is already uploaded to a remote server)
– Do not try to contact me (this is not feasible, I sent you an email from your account)
– Various security services will not help you; formatting a disk or destroying a device will not help, since your data is already on a remote server.
P.S. You are not my single victim. so, I guarantee you that I will not disturb you again after payment!
 This is the word of honor hacker
I also ask you to regularly update your antiviruses in the future. This way you will no longer fall into a similar situation.
Do not hold evil! I just do my job.
Have a nice day!

Phishing Scam – 01/29/2019 – latest INVOICE 01/30/19

Baiting type of scam. URL blocked at the border, Trend classified as dangerous. Webhost notified.

From: ******* <*******>
Date: Tuesday, January 29, 2019 at 5:17 PM
To: ******* <*******>
Subject: latest INVOICE 01/30/19
Please see attached and thanks!
Click here to view your invoice. [http://www.hopealso.com/fMgs_IzfYE-SwvIHElf/l7r/Clients_information/2019-01]

*******
*******

Phishing Scam – 01/29/2019 – receipt INVOICE

Baiting type of scam. Blocked at the border, Trendmicro classified as dangerous. Webhost notified.

From: ******* <*******>
Sent: Tuesday, January 29, 2019 12:17 PM
To: *******
Subject: receipt INVOICE
Thank you for your help. Please see the attached.
please Click here to get the invoice directly from our website. [http://handle.com.tw/Ashj_1WG-gwG/yAd/Clients/2019-01]

*******
*******

Phishing Scam – 01/29/2019 – Reminder: Invoice from *******

This is a baiting type of scam. Blocked at the border, Trend classified as dangerous, webhost notified.

From: ******* <******* [mailto:*******]>
Sent: Tuesday, January 29, 2019 2:59 PM
To: *******
Subject: Reminder: Invoice from *******
Please advise when we can expect payment of the attached invoice. Thank you.
Download DOC. [http://bancakoi.net/NLjx_IPcrY-wobOo/glf/Clients/012019]

*******
******* [mailto:*******]