|
|
|
|
July 9th, 2012, 13:30 GMT · By Eduard Kovacs
ADP Digital Certificate Expiration Emails Point to Malware Hosted on Hijacked Sites |
|
|
|
|
SHARE:
Adjust text size: 
|
|
Last week we reported that fake ADP Security Management emails were making the rounds, luring users to malware-serving websites.
Today, on July 9, a new variant has been spotted, warning recipients that their certificates are about to expire.
Apparently originating from adp_netsecure@adp.com, the shady notifications bear the subject “ADP Generated Message: First Notice - Digital Certificate Expiration.”
Here’s what the body of the message looks like:
This e-mail has been sent from an automated system. PLEASE DO NOT REPLY. If you have any questions, please contact your administrator for assistance.
Digital Certificate About to Expire
The digital certificate you use to access ADP's Internet services is about to expire. If you do not renew your certificate by the expiration date below, you will not be able to access ADP's Internet services.
Days left before expiration: 2
Expiration date: Jul 11 23:59:59 GMT-03:59 2012
The recipient is then urged to visit a couple of links that allegedly lead to webpages where the certificate can be renewed. Also, the notice contains instructions on “deleting your old digital certificate.”
In this case, the fraudsters try to induce a state of urgency by warning potential victims that there are only two days left.
While links comprised in the email apparently point to adp.com domains, in reality they lead to compromised websites that serve a Trojan identified by ESET as TrojanDownloader.HackLoad.AH. The sample we’ve analyzed involves the site of a Canadian law firm.
We have contacted the company in question and their webmaster will hopefully address this issue as soon as possible. In the meantime, users are advised to beware of such emails.
They may appear to be highly legitimate, but in reality, they can cause a lot of problems for those who fall victims in the traps they set.
|
|
|
|
|
 |
22,539 hits
· 45 comments
Link to this article
· Print article
· Send to friend
|
MUST-READ RELATED ARTICLES:
READER COMMENTS: |
| Comment #1 by: shadko on 09 Jul 2012, 14:43 UTC | reply to this comment | Thanks, I just got this very email (went to my Spam file) this morning. I didn't open it up but did a Google search and came across your very timely warning. |
| Comment #2 by: lwendland on 09 Jul 2012, 16:30 UTC | reply to this comment | Same here - I just got this email in my spam. Googled it and found this article. Sick of all these spam emails!! |
| Comment #3 by: BN on 09 Jul 2012, 18:39 UTC | reply to this comment | I just got this email but it seemed suspicious so I did a search and found this site. Thanks for the warning. |
| Comment #4 by: DJ on 09 Jul 2012, 20:38 UTC | reply to this comment | I opened it up by accident, then closed it quickly when I saw a malware looking popup shoot out. Will I have a problem now? What should I look for? |
| Comment #5 by: evert0n on 10 Jul 2012, 01:30 UTC | reply to this comment | I received one of these emails and deleted it.
I forwarded it to my IT guy and he referred me to your website. |
| Comment #6 by: mikee on 25 Jul 2012, 18:43 UTC | reply to this comment | They are still with us. Got this one just this morning, 7/25/12. |
| Comment #7 by: Michelle on 02 Aug 2012, 17:47 UTC | reply to this comment | Thanks for the information. I received an e-mail from them today. Glad I read your warning. |
| Comment #9 by: mel on 03 Aug 2012, 14:12 UTC | reply to this comment | still receiving this email as of august 3, 2012 |
| Comment #10 by: Carl on 06 Aug 2012, 10:18 UTC | reply to this comment | one of my users received one of these, 02/08/2012. thanks for the heads up. |
| Comment #11 by: Biggi on 27 Aug 2012, 13:22 UTC | reply to this comment | August 27, 2012 - I just got the e-mail mentioned above. Thanks for the warning. I didn't think that the e-mail was legitimate. |
| Comment #12 by: Marian on 27 Aug 2012, 23:24 UTC | reply to this comment | Yep, this is still around. Got one today (Aug 27, 2012). |
| Comment #12.1 by: Greg on 06 Sep 2012, 16:26 GMT | We just got it also, still around. |
| Comment #13 by: Alex on 14 Sep 2012, 12:35 UTC | reply to this comment | Just got one today, but this variant appeared to have a zip file with the 'new certificate' in it. 9/14/2012 |
| Comment #13.1 by: Prairiehammer on 14 Sep 2012, 15:47 GMT | Ditto. Received the same today. |
| Comment #13.2 by: Krystal on 14 Sep 2012, 17:41 GMT | I also received one this morning on 9/14 with the zip file attached. I deleted it. |
| Comment #13.3 by: Susan on 14 Sep 2012, 19:16 GMT | Just got this new version, too. |
| Comment #13.4 by: Tashie on 14 Sep 2012, 19:24 GMT | Same. Circulated around clients office today with a one day expiry warning and a zip file. ESET caught it |
| Comment #13.5 by: antoine62 on 14 Sep 2012, 21:50 GMT | how do we remove this if it was clicked. it seems to be wrecking havoc to my java. |
| Comment #14 by: Bob on 14 Sep 2012, 14:13 UTC | reply to this comment | I got one too, googled it because it looked fishy... |
| Comment #15 by: John on 14 Sep 2012, 16:27 UTC | reply to this comment | got it today 9-15-12. Thanks for the warning, but since I don't use ADP I knew it was crap. |
| Comment #16 by: H Thomas on 14 Sep 2012, 17:23 UTC | reply to this comment | Thanks for sharing this because I just received an email about this and had no idea who they are. Cheers! |
| Comment #17 by: FrozenHam on 19 Sep 2012, 14:59 UTC | reply to this comment | I received this yesterday. The email did not contain any links, but it did contain a bogus zip file. I opened it, but my computer rendered a message that said the file was not valid for a security certificate. I hope it didn't screw anything up. |
| Comment #18 by: Pkan on 19 Sep 2012, 20:30 UTC | reply to this comment | A new variation just appeared in my spam filter, subject line "ADP Funding Notification - Debit Draft". It states "transaction reports" have been uploaded to the web site, and my bank account will be debited within one banking day for the amounts shown. Thanks for your site telling me about these. If I actually used ADP, I might have clicked the link without checking. |
| Comment #19 by: dog lover on 11 Oct 2012, 15:30 UTC | reply to this comment | thank you. I just received such an email Oct 11th and promptly deleted. |
| Comment #21 by: MORRIS R on 11 Oct 2012, 18:35 UTC | reply to this comment | I AM GLAD I READ THIS. I WAS ONE OF THOSE PEOPLE PANICKING BECAUSE OF THE QUANTITY OF SECURITY COMPANIES WE DEAL WITH, FROM HOME SECURITY TO COMPUTER SECURITY TO BUSINESS SECURITY. WHAT A RELIEF. |
| Comment #22 by: helen on 11 Oct 2012, 21:39 UTC | reply to this comment | The following is a new message that I received:
Your latest ADP Services Invoice is now available to view or pay online at ADP Online Invoice Management .
To protect the security of your data, you will need to enter your ID and password, then click on Access your Online Invoice Management Account.
Total amount due by October 11, 2012
$48033.96
If you have already sent your payment please disregard this friendly reminder and Thank you for choosing ADP.
Questions about your bill?
Contact your ADP administrator by Secure Mail.
Note: This is an automated email. Please do not reply. |
| Comment #23 by: pedler on 12 Oct 2012, 09:19 UTC | reply to this comment | This mail is 4 months later still in circulation! I have just received one dated Fri Oct 12 11:10:36 2012 with the following text:
Your latest ADP Services Invoice is now available to view or pay online at ADP Online Invoice Management .
To protect the security of your data, you will need to enter your ID and password, then click on Access your Online Invoice Management Account.
Total amount due by October 11, 2012
$46252.14
If you have already sent your payment please disregard this friendly reminder and Thank you for choosing ADP.
Questions about your bill?
Contact your ADP administrator by Secure Mail.
Note: This is an automated email. Please do not reply. |
| Comment #24 by: bakulas on 15 Oct 2012, 22:27 UTC | reply to this comment | agree with comment#23.
Subject: ADP Invoice Reminder
From: ADP_Netsecure@adp.comAdd to Contacts
Sent: Thu, Oct 11, 2012 at 12:17 pm
Your latest ADP Services Invoice is now available to view or pay online at ADP Online Invoice Management .
To protect the security of your data, you will need to enter your ID and password, then click on Access your Online Invoice Management Account.
Total amount due by October 11, 2012
$40467.24
If you have already sent your payment please disregard this friendly reminder and Thank you for choosing ADP.
Questions about your bill?
Contact your ADP administrator by Secure Mail.
Note: This is an automated email. Please do not reply.
----------------------------
this email is still in circulation, please be high alert and dont send any payments.
thank you. |
| Comment #25 by: dgc on 27 Nov 2012, 12:14 UTC | reply to this comment | I today have also recieved such an email. I am always careful when there is something i don't know who it is from and put the title of the email into google & this site came up telling me what this is and it will now be marked as spam
It is thanks to sites like yourself that we all manage to stay safe online |
| Comment #25.1 by: NightRelic on 27 Nov 2012, 14:20 GMT | I just got one too, identical to this one on 11/27/12. I have also received a couple of a different ADP emails in the past month, which I believe were also bogus. Instead of a zipped file, they had a couple of links. I did a web search for this one. There were half a dozen sites that came up first that just repeated the text of the e-mail. They never bothered to state the e-mail was bogus as you did, so they look just as bogus as the e-mail itself, perhaps misleading users into not taking action they need to. Thanks for doing the whole job and actually letting us know the e-mails are a scam and giving us a useful forum to track this. |
| Comment #25.2 by: Joep on 27 Nov 2012, 16:07 GMT | Also received this email just today. Always trying to be focussed on what's right and what could be suspicious. Came across this site googling for the ADP certificate as I didn't know where it points at.
Thanks for the heads up. There are quite some of these emails goin' around these days. Already received 4 or more regarding ING home banking.
Stay alert ... |
| Comment #25.3 by: Stingem on 27 Nov 2012, 21:02 GMT | I got this email this morning as well. I'm usually careful about these things, but it's coming to the end of the year and I think my payroll contract is about to expire, so I extracted the zip file. Nothing seems to be wrong with my comp yet, but does anyone have suggestions on what I can do to make sure my computer is clean? |
| Comment #25.4 by: nakrohtap on 29 Nov 2012, 15:34 GMT | I received this on 11/27 as well. Used the ADP site yesterday with no issue.
Today, I can't get into the site. I didn't open the email, but I thought of it when I am unable to view my account now in ADP. |
| Comment #26 by: MRWD on 27 Nov 2012, 20:13 UTC | reply to this comment | Received one for the first time Nov 27, 2012.
Oakville Canada |
| Comment #27 by: mikemc on 28 Nov 2012, 06:07 UTC | reply to this comment | I just got the message and as it looked sus. I googled it and found your warning. Thanks |
| Comment #28 by: lsk on 28 Nov 2012, 08:00 UTC | reply to this comment | thank God I see this before I download the attachment. I got the exact same email! You just save me. thank you ! |
| Comment #29 by: TA in IS on 28 Nov 2012, 15:18 UTC | reply to this comment | Received this message as well this morning , dated Tue, 27 Nov 2012 17:50:29 with a stated certificate expiration date of the the exact date & time! It helped that we have never used ADP services but did a quick search anyway and find this article. Kudos for posting the warning. |
| Comment #29.1 by: kajenn on 28 Nov 2012, 21:36 GMT | Received the same today, Wed 28 nov 2012 at 14:42 UTC. Googled, found this site and deleted the message. |
| Comment #30 by: vijay on 28 Nov 2012, 19:32 UTC | reply to this comment | Just now got this type of mail. Thanx. |
| Comment #31 by: tc on 24 Jan 2013, 18:03 UTC | reply to this comment | A co-worker just received this. It's still going around as of 1/24/13. |
| Comment #32 by: JC on 24 Jan 2013, 18:57 UTC | reply to this comment | Just got this email this morning. Thanks for the heads up. |
| Comment #33 by: Shea.H on 24 Jan 2013, 19:55 UTC | reply to this comment | I just got this email. Thanks for the info. |
| Comment #34 by: Anne on 25 Jan 2013, 03:10 UTC | reply to this comment | Thank you! I just got this email and it is hard to tell what to open or ignore. | |
Copyright © 2001-2013 Softpedia. Contact/Tip us at 
|
|