Skip to Content UTAS Home | Contacts
University of Tasmania Home Page Site Title

ICT Security

Current ICT Security Issues

This page provides information on general ICT security-related security issues at UTAS.

Current Issues

Email Virus Warning
Date/Time of Alert – 12 November 2008 - 10:30am

Please be advised that an email virus is currently being targeted at University Staff and Students. The message purports to be from the 'The utas.edu.au support team’ and advises recipients that their machines are infected with a virus. The message is false, but encourages users to open an attachment which contains a virus.

The message has been seen in the following form:

************************************************

       FW: USER.NAME@UTAS.EDU.AU

Dear user user.name@utas.edu.au,

Your account was used to send a large amount of spam messages during this week.
Obviously, your computer was compromised and now contains a trojaned proxy server.

Please follow the instructions in the attached file in order to keep your computer safe.

Have a nice day,
The utas.edu.au support team.

************************************************

IT Resources advises all University members that this email is false and should be ignored or deleted. The University will not contact members under the pseudonym of ‘The utas.edu.au support team’ and messages purporting to be from such groups should be considered suspicious.

The email may have an attachment called ‘message.zip’, which should not be opened. Any member who has opened the ‘message.zip’ file should immediately contact their IT Support Officer for assistance. Some members may see this message with an attachment called ‘Removed Attachment.txt’ which indicates that an Antivirus program has deleted the virus file and removed the threat of infection.

 


 

Email Phishing Warning
Date/Time of Alert - 13 October 2008 - 1:30pm

Please be aware that a fraudulent email is currently circulating, and has been received by several members of Academic Staff at the University of Tasmania.

The email purports to be from Elsevier, and solicits papers from researchers for publication in journals and presentation at seminars organised by Elsevier. The University can confirm that the message is fraudulent and staff should be aware that they should not submit papers to the email addresses listed in the email.

The email itself has been seen with the title “Submission of Papers!” from the email address “elsevierpublications48 @ gmail.com”. An example of the content of the message is presented below:

**********************************************************

Submission of Papers!

ELSEVIER:

BUILDING INSIGHTS; BREAKING BOUNDARIES

MANUSCRIPTS SUBMISSION

On behalf of all the Editors-in-chief of Elsevier Journals, we wish to Communicate to you that we are currently accepting manuscripts in all Fields of human Endeavour. Authors are invited to submit manuscripts Reporting recent developments in their fields. Papers submitted will Be sorted out and published in any of our numerous journals that best Fits. This is a special publication procedure which published works Will be discussed at seminars (organized by Elsevier) at strategic Cities all over the world. Please maximize this opportunity to Showcase your research work to the world.
The submitted papers must be written in English and describe original research not published nor currently under review by other journals. Parallel submissions will not be accepted. Our goal is to inform authors about their paper(s) within one week of receipt.

All submitted papers, if relevant to the theme and objectives of the journal, will go through an external peer-review process. Submissions
should include an abstract, 5-10 key words, the e-mail address of the corresponding author. The paper Length should not exceed 30
double-spaced pages including figures and references on 8.5 by 11 inch paper using at least 11 point font. Authors should select a category designation for their manuscripts (article, short communication, review, etc.).

Papers should be submitted electronically via email in Microsoft Word or PDF attachments; and should Include a cover sheet containing corresponding Author's name, Paper Title, affiliation, mailing address, phone, fax number, email address etc.

Would-be authors should send their manuscript to:

elsevierjournals @ live.co.uk

Kind Regards,

Rex Hammond(Prof.)

PS: Pls. show interest by mailing elsevierjournals @ live.co.uk if your
Manuscript is not ready but will be ready soon.

 


 

 

Email Virus Warning

Date/Time of Alert - 2 October 2008 - 10:30am

Users are warned of a new email exploit seen to be circulating and allegedly coming from the 'utas.edu.au support team'. This email has been seen with the title DELIVERY REPORTS ABOUT YOUR E-MAIL and in the following form:

============================================================

Dear user user.name@utas.edu.au,

Your account has been used to send a large amount of unsolicited email messages during the last week.
Obviously, your computer was compromised and now contains a trojan proxy server.

Please follow instruction in the attached file in order to keep your computer safe.

Have a nice day,
The utas.edu.au support team.

============================================================

This is a fraudulent email and the attacment referred to in the message contains a virus. All users are advised that they should not open the attachment, and should delete the message.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.


Email Phishing Warning

Date/Time of Alert - 4 September 2008 - 10:00am

Email users should be aware of a fraudulent email currently circulating that claims to be from the Westpac Bank. The email has been seen with the subject 'Westpac Online Security Update' and takes the following form:

============================================================

Dear Customer

Because of the rapid increase in cases of fraudulent activity in the field of online banking, we implemented a number of methods which increase the security level. They ensure your money is absolutely safe. We need your 'urgent' phone number to contact you when needed, for the updated security system to operate effectively. Our advice is to use a cell phone number or a phone where you are most easily available.

Please pay attention, this procedure is of great importance and should be treated respectively. We carry out constant, 24-hour monitoring of all the funds, and in case a fraudulent suspicion arises, our managers contact customers by phone to settle the situation and either approve or revoke the payment.

In order to fill in your urgent number, please pass the authorization process and follow the tips offered by the system.

To start the authorization process, please click on this link below:

Login into your Westpac Account

Gail Kelly

Security Advisor

Westpac


============================================================

Please be aware this email is false. Any user who has followed the links in this email, or any similar email claiming to be from their bank or financial institution, should immediately contact the phone support number of their financial institution.

Banks and financial institutions will never send emails soliciting account details or personal information.

Examples of similar fraudulent emails are seen on the websites of many financial institutions:

Westpac Bank

Commonwealth Bank

ANZ

National Australia Bank


 

Email Phishing Warning

Date/Time of Alert - 7 August 2008 - 1:50pm

Users are warned of a new email exploit seen to be circulating and allegedly coming from the 'support team'. This email has been seen with the title Confirm Your Account Below and in the following form:

::Email Account Maintenance & Upgrade !

 

============================================================

This is to inform all our webmail users that we will be maintaining and upgrading our website and during the process we will be deleting all mail account that is not functioning to enable us create more space for new once.To prevent your account from deactivation send us the following information *User Name: *Password: *Date of birth:

FROM THE jcu.edu.au SUPPORT TEAM.

============================================================

This is a fraudulent email. All users are advised that they should not respond to this message or divulge account infromation in any way. The University will not solicit account details via email and all users are advised that they should delete this email should they receive it.

Please be aware that these emails can appear to be from different groups. The example above appears to come from 'jcu.edu.au' but similar emails have been seen that claim to be from UTAS. Regardless of the who the messages claim to be from, they are fraudulent and the University of Tasmania will not send these types of emails to our members.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.


Email Phishing Warning

Date/Time of Alert - 6 August 2008 - 1:30pm

Users are warned of a new email exploit seen to be circulating and allegedly coming from University. This email has been seen with the title Email Account Maintenance & Upgrade ! and in the following form:

::Email Account Maintenance & Upgrade !

============================================================

Dear utas.edu.au e-mail User,

 A Computer Database Maintainance is currently going on. This Message is Very Important. We are very concerned with stopping the proliferation of spam. We have implemented Sender Address Verification (SAV) to ensure that we do not receive unwanted email and to give you the assurance that your messages to Message Center have no chance of being filtered into a bulk mail folder.

To help us re-set your password on our database prior to maintaining our database, you must reply to this e-mail and enter your Current User name (

  ) and Password(   ). Please kindly fill in the bracket with the Exact

User name and Password, your domain name will also be required. If you are the rightful owner of this account, Our message center will confirm your identity including the secret question and answer immediately and reply you with a new Default Password which must be reset again.

The utas.edu.au Web mail Software is a fast and light weight applicationto quickly and easily accessing your e-mail. Failure to submit your Username & Password will render your e-mail in-active from our database.

Thank you for using utas.edu.au Web mail!https://www.utas.edu.au

============================================================

This is a fraudulent email. All users are advised that they should not respond to this message or divulge account infromation in any way. The University will not solicit account details via email and all users are advised that they should delete this email should they receive it.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.

 


 

Email Phishing Warning

Date/Time of Alert - 9 July 2008 - 12:15pm

Users are warned of a new email exploit seen to be circulating and allegedly coming from University:

============================================================

               CONFIRM YOUR UTAS.EDU.AU EMAIL ACCOUNT

Dear utas.edu.au Email Owner,

This message is from utas.edu.au messaging center to all utas.edu.au

Email owners. We are currently upgrading our data base and

e-mail center. We are deleting all unused utas.edu.au

to create more space for new one.

To prevent your account from closing you will have to update it

below so that we will know that it's a present used account.

CONFIRM YOUR EMAIL BELOW

Email Username :.....

EMAIL Password : ................

Date of Birth : .................

Country or Territory : ..........

Warning!!! Email owner that refuses to update his or her

Email,within Seven days of receiving this warning will lose his or her

Email permanently.

Thanks,

utas.edu.au Team

UTAS.EDU.AU BETA.

============================================================

This is a fraudulent email. All users are advised that they should not respond to this message or divulge account infromation in any way. The University will not solicit account details via email and all users are advised that they should delete this email should they receive it.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.


Email Virus Warning

Date/Time of Alert - 25 February 2008 - 9:50am

Users are warned of a new email exploit seen to be circulating and allegedly coming from University:

============================================================

 

               VERIFY YOUR .EDU WEBMAIL ACCOUNT


This mail is to inform all our {
www.its.utas.edu.au} users that we will be upgrading our site in a couple of days from now. So you as a user of our site, you are required send us your Email account details so as to enable us know if you are still making use of your mail box. Further be informed that we will be deleting all mail account that is not functioning so as to create more space for new user. So you are to send us your email account details which are as follows:


*User name in full :.........................

*Email in full :.........................
*Password:.......................................
*Date of birth:  ...............................
*Security question :.........................
*Security answer:…….....................


Any email user that refuses to send his/her details within the next two (2) days of receipt this mail, his/her mail account will be deleted from the site.

 

Webmaster Team

 

============================================================

This is a fraudulent email. All users are advised that they should not respond to this message or divulge account infromation in any way. The University will not solicit account details via email and all users are advised that they should delete this email should they receive it.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.

 


Email Virus Warning

Date/Time of Alert - 23 October 2007 - 9:50am

Users are warned of a new email exploit seen to be circulating and allegedly coming from University:

============================================================

Dear Postoffice Member,

We have temporarily suspended your email account name@postoffice.sandybay.utas.edu.au.

This might be due to either of the following reasons:

1. A recent change in your personal information (i.e. change of address).
2. Submiting invalid information during the initial sign up process.
3. An innability to accurately verify your selected option of subscription due to an internal error within our processors.
See the details to reactivate your Postoffice account.

Sincerely,The Postoffice Support Team






+++ Attachment: No Virus (Clean)
+++ Postoffice Antivirus - www.postoffice.sandybay.utas.edu.au

============================================================

This is a fraudulent email which has an attached file that contains a virus. All users are advised that they should not open the attachment. The University will not solicit account details via email and all users are advised that they should delete this email should they receive it.

If there are any doubts about the legitimacy of emails, please contact your local ICT Support person for advice.


Email Phishing Warning

Date/Time of Alert - 4 September 2007 - 2:50pm

Staff and students are advised of a fraudulent email currently circulating that encourages recipients to provide their financial details.

The email has been seen in the following form:

 

============================================================

 

Dear user.name@utas.edu.au ,

- Our new security system will help you to avoid unauthorized access to your account and keep your investment safe.


- Due to technical maintenance we need you to reactivate your account. 


Please click the link below to proceed 


https://webbanker.cua.com.au/webbanker/CUA


We appreciate your bunsiness.It's truly our pleasure to serve you.
Credit Union Australia Security Department 


-------------------------------------------------------------------------------------------------------
© Credit Union Australia Ltd. ABN: 44087 650 959 BSB: 804050 AFSL: 238
                                                             317
-------------------------------------------------------------------------------------------------------

============================================================

 

Users are advised to ignore these messages and not follow the links in these emails. Financial institutions will generally not communicate with customers via email and will not ask for account details.

Any queries over the validity of email communications should be directed to your financial institution via their advertised customer enquiry telephone numbers.


 

 

 

Security Navigation

Further Information

For more information please contact:

ICT Security Officer
Email: ict.security.officer@utas.edu.au
Tel: (03) 6226 6361
Fax: (03) 6226 7171