An
Email with the Subject "[Bulk?]ADP Generated Message: First Notice - Digital Certificate Expiration" was
received in one of Scamdex's honeypot email accounts on Thu, 02 Aug 2012 13:27:58 -0700
and has been classified as a Generic Scam Email.
The sender shows as "ADP_Netsecure@adp.com" <ADP_Netsecure@adp.com>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
assistancecontactwinserviceinternetaccessprocesssecuresentmail will [bulk?]https://netsecure.adp.com...https://netsecure.adp.com...for assistance
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[envelope-to:] => mc_mxw@o7e.net
[delivery-date:] => Thu, 02 Aug 2012 13:27:58 -0700
[received:] => Array
(
[0] => from c2mds.mailcentro.com ([208.67.179.143]:60056)by lester.newsblaze.com with esmtp (Exim 4.77)(envelope-from )id 1Sx1zx-0000q2-Fpfor mc_mxw@o7e.net; Thu, 02 Aug 2012 13:27:58 -0700
[1] => from [194.79.62.7] (194.79.62.7.alchevsk.net [194.79.62.7] (may be forged))by c2mds.mailcentro.com (8.13.8(MC-AXH/MJD-001)/8.13.8.axh-mjd) with ESMTP id q72KRt4g007214for ; Thu, 2 Aug 2012 13:27:55 -0700
[2] => from apache by adp.com with local (Exim 4.67)(envelope-from )id 6YX2WQ-HH97AO-ARfor
)
[x-mc-sender:] => ADP_Netsecure@adp.com
[x-mc-ipaddr:] => 194.79.62.7.alchevsk.net [194.79.62.7] (may be forged)
[cc:] => Array
(
[0] => , ; Thu, 2 Aug 2012 22:27:55+0200@c2mds.mailcentro.com
[1] => ,
)
[to:] =>
[subject:] => [Bulk?]ADP Generated Message: First Notice - Digital Certificate Expiration
[x-php-script:] => adp.com/sendmail.php for 194.79.62.7
[from:] => "ADP_Netsecure@adp.com"
[x-sender:] => "ADP_Netsecure@adp.com"
[x-mailer:] => PHP
[x-priority:] => 1
[mime-version:] => 1.0
[content-type:] => multipart/alternative;boundary="------------07030300501010806080202"
[message-id:] =>
[date:] => Thu, 2 Aug 2012 22:27:55 +0200
[x-mc-filter:] => 7.6.9
[x-mc-filter-antivirus:] => Scanned for virus - Status 0
[x-mc-deliveryid:] => 130
[x-mc-ctfilter:] => CT RefID = str=0001.0A010202.501AB7C0.0033,ss=3,sh,fgs=0 - Class:Bulk - Virus Threat:Unknown - Phishing Threat:Low
[x-mc-filterskip:] => 0
[x-mc-spamscore:] => 40 T 49
[x-spam-status:] => No, score=1.0
[x-spam-score:] => 10
[x-spam-bar:] => +
[x-ham-report:] => Spam detection software, running on the system "lester.newsblaze.com", hasidentified this incoming email as possible spam. The original messagehas been attached to this so you can view it (if it isn't spam) or labelsimilar future email. If you have any questions, seethe administrator of that system for details.Content preview: This e-mail has been sent from an automated system. PLEASE DO NOT REPLY. If you have any questions, please contact your administrator for assistance. Digital Certificate About to Expire The digital certificate you use to access ADP's Internet services is about to expire. If you do not renew your certificate by the expiration date below, you will not be able to access ADP's Internet services. Days left before expiration: 2 Expiration date: Jul 11 23:59:59 GMT-03:59 2012 Renewing Your Digital Certificate1. Go to this URL: https://netsecure.adp.com/pages/cert/register2.jsp 2. Follow the instructions on the screen. 3. Also you can download new digital certificate at https://netsecure.adp.com/pages/c! ert/pickUpCert.faces. Deleting Your Old Digital Certificate After you renew your digital certificate, be sure to delete the old certificate. Follow the instructions at the end of the renewal process. [...] Content analysis details: (1.0 points, 4.0 required) pts rule name description---- ---------------------- -------------------------------------------------- 1.0 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail) 0.0 HTML_MESSAGE BODY: HTML included in message
[x-spam-flag:] => NO
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
This e-mail has been sent from an automated system. PLEASE DO NOT REPLY. If you have any questions, please contact your administrator for assistance.
--------------------------------------------------------------------- Digital Certificate About to Expire --------------------------------------------------------------------- The digital certificate you use to access ADP's Internet services is about to expire. If you do not renew your certificate by the expiration date below, you will not be able to access ADP's Internet services.
Days left before expiration: 2 Expiration date: Jul 11 23:59:59 GMT-03:59 2012
-------------------------------------------------------------------- Renewing Your Digital Certificate --------------------------------------------------------------------- 1. Go to this URL: https://netsecure.adp.com/pages/cert/register2.jsp 2. Follow the instructions on the screen.
3. Also you can download new digital certificate at https://netsecure.adp.com/pages/cert/pickUpCert.faces.
--------------------------------------------------------------------- Deleting Your Old Digital Certificate --------------------------------------------------------------------- After you renew your digital certificate, be sure to delete the old certificate. Follow the instructions at the end of the renewal process.