CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Circuit City - Scam

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Mon Feb 28, 2005 6:23 pm    Post subject: Circuit City - Scam
Reply with quote

As displayed:

From: AmazingOffers <tyreepemberton@jipad.attractivegoodnews.com>
To: XXXXXXX@escapees.com
Subject: Delivery Confirmation #3658-VACC6735
Date: Sun, 27 Feb 2005 23:47:49 -0800 (Mon, 00:47 MST)

CustomerService
Customer Incentive Promotions
14545 J Military Tr. #189
Delray Beach, FL 33484, USA.

-----------------------------------------------------------
CircuitCity GiftCard OrderConfirmation #3658-VACC6735
To: Member #4031
-----------------------------------------------------------

To receive your gift, please click on or cut and paste:

"http://bakom.approvedgoodnews.com/circi"

We have been trying to reach you in order to deliver your free Circuit City Gift Card.

Please verify your shipping address and zipcode.

Consumer Incentive Promotions has given you this $250 Circuit City Gift Card just for answering a 3-minute survey and following instructions on our website.

Please visit our website and verify your zipcode:

"http://bakom.approvedgoodnews.com/circi"

Thank you and ENJOY!

Sincerely,

Mary Henderson
Customer Service Rep.
Customer Incentive Promotions



This limited time promotion is sponsored by Consumer Incentive Promotions and subject to Terms, Conditions and Restrictions. See site for details. The trademark owners have not endorsed this promotion, nor are they affiliated or connected with this promotion. If you no longer wish to receive Consumer Incentive Promotions emails, visit the unsubscribe page on the Consumer Incentive Promotions site, or you can write us at: Consumer Incentive Promotions, 14545 J Military Tr. #189, Delray Beach, FL 33484, USA.

To unsubscribe, go to:
"http://bakom.approvedgoodnews.com/circi/tr.cgi? " (encoded tag removed)

QAAA.net
122 N. 2nd St. Ste A-408
Phoenix, AZ 85004

hangemuth xulendist neu.xxx rotaxus ftdbqfft-dpn lenitevecaf lucosahue nonogi kuzocoshade revamiluhi biruu ndocazi
A Fly and a Flea in a Flue
A Fly and a Flea in a Flue
Were imprisoned, so what could they do?
Said the fly, "Let us flee!"
"Let us fly!" said the flea,
And they flew through a flaw in the flue.

===========================

Looked pretty good until the last bit!

Spamcop's opinion:

Tracking message source: 61.78.37.115:
Routing details for 61.78.37.115
[refresh/show] Cached whois for 61.78.37.115 : ip@ns.kornet.net abuse@kornet.net
Using best contacts abuse@kornet.net


61.78.37.115 not listed in dnsbl.njabl.org
61.78.37.115 not listed in dnsbl.njabl.org
61.78.37.115 listed in cbl.abuseat.org ( 127.0.0.2 )
61.78.37.115 is an open proxy
61.78.37.115 not listed in query.bondedsender.org
61.78.37.115 not listed in iadb.isipp.com

Finding links in message body
Parsing HTML part
Resolving link obfuscation
"http://bakom.approvedgoodnews.com/circi/?" (tag removed)
host bakom.approvedgoodnews.com (checking ip) = 61.78.37.67
host 61.78.37.67 (getting name) no name
"http://bakom.approvedgoodnews.com/circi/tr.cgi?" (tag removed)
host bakom.approvedgoodnews.com (checking ip) = 61.78.37.67
host 61.78.37.67 (getting name) no name
Tracking link: "http://bakom.approvedgoodnews.com/circi/?" (tag removed)
No recent reports, no history available
Resolves to 61.78.37.67
Routing details for 61.78.37.67
[refresh/show] Cached whois for 61.78.37.67 : ip@ns.kornet.net abuse@kornet.net
Using best contacts abuse@kornet.net
Tracking link: "http://bakom.approvedgoodnews.com/circi/tr.cgi?" (tag removed)
No recent reports, no history available
Resolves to 61.78.37.67
Routing details for 61.78.37.67
[refresh/show] Cached whois for 61.78.37.67 : ip@ns.kornet.net abuse@kornet.net
Using best contacts abuse@kornet.net

==================

So much for my visions of a new toy for free!

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Feb 28, 2005 7:10 pm    Post subject:
Reply with quote

I feel your pain Stan. Removing the tag from the unsubscribe link seems not to have worked, though. I followed the link without the tag and was immediately informed that I had successfully unsubscribed and that my email address would be removed from their list within 72 hours. Not bad, since they don't even know what it is.

Seriously, playing with that took me to two sites in the US (different hosting companies) and one in Korea. Quite a mesh they have going there.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10635

Premium

PostPosted: Mon Feb 28, 2005 8:07 pm    Post subject:
Reply with quote

What is the RFC for sending C4 via TCP/IP?

Except tor the Bayesian buster this one looked very good in the preview window, thought it deserved a spotlight here.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Feb 28, 2005 9:06 pm    Post subject:
Reply with quote

It looks like I am going to have to get ahold of MWP somehow just to play with.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Mon Feb 28, 2005 10:08 pm    Post subject:
Reply with quote

http://www.firetrust.com/products/pro/free.php

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer