CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Looks Very Suspicious to Me

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
SpotCheckBilly

1st Responder


Joined: Jul 13, 2004
Posts: 158

1st Responders

PostPosted: Wed Oct 31, 2007 9:38 pm    Post subject: Looks Very Suspicious to Me
Reply with quote

Return-Path: <info@fpcltd.com>
Received: from rrcs-mgw-01b.hrndva.rr.com ([172.28.193.154])
by rrcs-fep-02.hrndva.rr.com with ESMTP
id <20071031023215.SDHC27528.rrcs-fep-02.hrndva.rr.com@rrcs-mgw-01b.hrndva.rr.com>
for <My Address.com>; Tue, 30 Oct 2007 22:32:15 -0400
Received: from qmail2.america.net (HELO 24hoursupport.com) ([69.60.172.232])
by rrcs-mgw-01b.hrndva.rr.com with SMTP; 30 Oct 2007 22:33:44 -0400
Received: (qmail 11707 invoked by uid 1000); 31 Oct 2007 02:32:12 -0000
Received: from unknown (HELO localhost) (smtpwebmail@america.net@127.0.0.1)
by qmail2.24hoursupport.com with SMTP; 31 Oct 2007 02:32:12 -0000
Received: from 207.179.67.248 ([207.179.67.248]) by webmail.russellma.net
(Horde MIME library) with HTTP; Tue, 30 Oct 2007 22:19:55 -0400
Message-ID: <20071030221955.kp7m7iw5m0dckw8o@webmail.russellma.net>
IMP-Mailbox: coachjones@russellma.net
Date: Tue, 30 Oct 2007 22:19:55 -0400
From: FEILONG PLASTIC COMPANY LTD <info@fpcltd.com>
Reply-to: companyjoboffer_info@yahoo.com.cn
To: undisclosed-recipients:;
Subject: Representatives/Agents Needed Urgently
MIME-Version: 1.0
Content-Type: text/plain;
charset=ISO-8859-1;
DelSp="Yes";
format="flowed"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
User-Agent: Internet Messaging Program (IMP) H3 (4.1.2)



ATTENTION!!!!

This mail is serving as an invitation to treat Urgently. I will not fail to
state that I am sorry for encroaching in your privacy. Feilong Plastic Compa=
ny
located in Zhejiang China, produces colour printing and multi-laminating
plastic packing bag for packing any kinds of products in China, some of them
are foil bags.

Due to the increase in demand of our products in America and Canada, we have
decided to move our products fully into the continent of America. We wish to
crave your indulgence that we are searching for reliable persons/companies i=
n
the United States, Canada, South America and Europe who can act as RECEIVING
OFFICER who will act as medium of reach between our customers and us in thei=
r
area. Note that, if finally aprroved as our Representative, you will be
entitled to 5% of
whatever amount you receive from customers who are making payments for
outstanding invoices on behalf of the company. Our account officer will conv=
ey
to you the medium which you will use to remit any funds received on =20
our behalf.
If you are interested in being a REPRESENTATIVE OFFICER in the above locatio=
n
and your locality, please fill out this form below:

Full name:
Residential Address:
Phone:
Occupation:
Country
Company name/Position (if any):
Gender:
Age:
Email:

Do you have an exclusive relationship with another China based =20
company? YES /NO
Note: You don't have to leave your present job for this since it is on part-
time basis. It is not time/ energy comsuming.

Thank you for your time.

Respectfully Submitted,
Contact Person: Ye Junpei
Email:companyjoboffer_info@yahoo.com.cn


__________ NOD32 2630 (20071031) Information __________

This message was checked by NOD32 antivirus system.
http://www.eset.com

Source edited to remove my actual e-mail address.

Back to top
View users profile Send private message AIM Address
brewt

SIRT Handler
Premium Member

Joined: May 29, 2007
Posts: 792
Location: USA
MIRT Premium

PostPosted: Wed Oct 31, 2007 10:16 pm    Post subject:
Reply with quote

99% chance it's fraud (and like 86% of of statistics, I just made that up).

you can report it to
1) spamcop to get the zombie taken care of
and
2) yahoo (by forwarding full headers and message body) to ask them to examine the yahoo email address for complicity in fraud

forward email to: network-abuse
with fqdn: cc.yahoo-inc.com

Quote:
Although the attached message was not sent using yahoo, a yahoo account appears be used in complicity with the email scam as a point of contact.
Please investigate and take punitive action as necessary against user: companyjoboffer_info@yahoo.com.cn
You can verify that this is a real, live email address by checking out the profile.
http://profiles.yahoo.com/companyjoboffer_info
(which redirects to http://cn.profiles.yahoo.com/companyjoboffer_info )
It will 404 if you put in an invalid uname,
e.g.
http://profiles.yahoo.com/runtothepills
http://profiles.yahoo.com/nomorepies
http://profiles.yahoo.com/hollowedbethighname

[edit] the above email is not technically "phishing" (and therefore, should not be submitted to PIRT)
the term "phishing" has become so specific that mere fraud which attempts to fool a user into supplying the fraudster with personal information is not considered "phishing."

here's my paraphrase of the criteria to be considered phishing:
deceiving a user into thinking a web site belongs to a recognizable, known-legitimate institution, and into divulging their personal information (i.e. login, password, mother's maiden name, etc.).

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Thu Nov 01, 2007 3:58 am    Post subject:
Reply with quote

This kind of scam with Yahoo contact addresses are easiest reported via the online report form http://help.yahoo.com/l/us/yahoo/mail/yahoomail/abuse.html

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1087
Location: USA

PostPosted: Thu Nov 01, 2007 3:01 pm    Post subject:
Reply with quote

yahoo takes reports quite seriously, I've gotten responses from humans within 24 hours (sometimes faster) regarding report spam, that contained @yahoo.* (to include .com .co.uk, .hk, etc...)

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
SpotCheckBilly

1st Responder


Joined: Jul 13, 2004
Posts: 158

1st Responders

PostPosted: Thu Nov 01, 2007 9:28 pm    Post subject:
Reply with quote

Thanks everyone. Good thing that I posted the entire thing here (although I can no longer forward it anywhere) so at least I can pass it on to the links suggested. I didn't report it to PIRT because it didn't ask for any specific personal information. I will probably get this one again -- this is the second time I've received it and if I do I'll go ahead and forward as advised. The second time around it was different because in the first one I asked for the name of my bank but no account numbers etc.

I recognized it as a probable scam and have alerted my friends and family to watch out for it. I'll give them in the same information I got here as to where they can report/forward.

Thanks again. -- SCB

Back to top
View users profile Send private message AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Sun Nov 04, 2007 7:48 pm    Post subject:
Reply with quote

Recommended reading
http://en.wikipedia.org/wiki/Money_mule

Back to top
View users profile Send private message Visit posters website AIM Address
Lightscribe

Lieutenant
Lieutenant


Joined: Nov 03, 2007
Posts: 207
Location: South_Africa

PostPosted: Mon Nov 05, 2007 12:41 pm    Post subject: Another sucker born each day...
Reply with quote

Apart from the "money mule" aspect, it's also a case of straight forward money laundering.

When I did contract work for a major casino group (my girlfriend worked in admin. for them), I was told by the general manager, during a lghthearted discussion in the office, that:
"We don't care if a MVG (Most Valued Guest) signup account shows that the person earns 4,000,00 Dollars a month from their government dept. job, but gambles away 50,000,00 a day, day after day, at the casino. It's not our job to police the guests. If they steal the money from their workplace, they will probably be caught at some stage. In the meantime, it's revenue for the company..." Confused

Also said was: "We, just like casino's worldwide, even have people that launder money through the casino system, because it's basically an almost guaranteed minimum 18% payback on the money they gamble away. That means it is money they are legally allowed to have, since they won it from a casino. Many win much more than the minimum..." Shocked

What makes me wonder, is why the Tax offices of various countries, do not have a team at each casino in the world, doing their own surveillance of guests...Then again, perhaps they do... Razz


_________________
"The greatest thing you could ever learn, is just to love...and be loved in return."
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer