Current Status

This blog is not frequently updated because most case-by-case scam reports are now listed in subordinate blogs. At this point in time, most of my efforts are targeted at documenting employment scams in the Suckers Wanted blog.

2005-05-07

Payment Processing Job Scam: Gallery of modern art

This particular spam doesn't provide much in the way of detail, but I'd be willing to wager that it's another payment processing job scam. "Job offers" via spam: Just Say "No". This one was sent to an ".au" address from 69.173.187.227 (69-173-187-227.sbtnvt.adelphia.net) on Sat, 7 May 2005 05:04:48 +1000 (note Australian timezone). The contact telephone number is in the Netherlands.

Need Extra Income?


New opportunities for you - today!
«Gallery of modern art» invites you to cooperation.
  • You are responsible and accurate
  • You are from 20 till 60 year old
  • You are Resident of Australia (preferably)
  • You have free time (2-4 hours daily)

Contact us, your job is waiting for you!


e-mail: galleryartmodern@aol.com

fax: +31-20-524-8539


galleryartmodern@aol.com

2005-05-05

Payment Processing Job Scam: Airgid Lingus

When phishers steal money, they prefer it to be laundered by a middle-man. Most people don't want to be involved in criminal money laundering, particularly when the money trail leads rather obviously to them, so the phishers tell big fat lies about "employment opportunities" instead. The basic job description is always the same: receive money, take your cut, forward the rest to someone else overseas (usually via Western Union). Only when the police come a-knocking at your door do you discover you're an accomplice to a crime.

This particular spam was received from 85.136.53.29 (apparently a cable modem in Spain) on Wed, 4 May 2005 19:50:17 -0000. The story in this case is you're an "escrow agent", which is fairly obvious bull in my opinion, but I'm sure there are people who are sufficiently ignorant and tempted by the lucre to get sucked right in without further thought. A search for "Airgid Lingus" shows that the same spam turned up on a web-archived mailing list on April 23, but has since been deleted by the list administrator. The reply address domain, "airgidlingus.com", presently resolves to 218.201.44.159, which is in China.

Airgid Lingus is looking for proactive and motivated prospects to fill
in a part-time position of Escrow Agent. The prospective candidate
should be a responsible and committed person with some multi-task
ability. Prior experience in the field of finance or accounting is
an advantage, but is not essential. Your compensation commission
based, and your commission depends solely on your performance and
efficiency. You should be able to get a substantial additional income
at the expense of just 4-8 hours per week.

WHO WE ARE
Airgid Lingus Private Equity Partners (Plc) is a venture capital
firm investing in Ireland and the United Kingdom. Established in
1994, it now has ˆ60 million under management. Our firm has a strong
focus on investing in early stage technology companies, and we have
made over 50 investments in such sectors as information technologies,
biotech and healthcare.

Given the recent decline of the European financial market, we are now
looking to attract investors from around the world, particularly the
Commonwealth countries. We are eager to provide our investment advice
and expertise to individual investors by offering stakes at Airgid
Private Equity Fund I.

JOB DESCRIPTION
We strive to provide the most efficient service on the highly
competitive global private equity market. Due to the tax and
legislative barriers set by many countries, the price of establishing
permanent office abroad may be forbearing. That is why we are looking
for energetic and disciplined accounts receivable managers to
establish cash flow between our investors and the Investment Fund
under close supervision of our financial management team.

Essentially, your duty will be to receive funds from our investors
and forward them to the investment and trust accounts designated by
your supervisor. This job is no rocket science, but it is rather
demands some responsibility and accuracy. It is in your own hands
to build a skyrocketing career on this solid basis.

OUR REQUIREMENTS
In order to qualify, you must be an individual aged 21 and above,
committed and good with numbers. You should also have a bank account
set up in your name or your business name. You should be looking at
dedicating 4-8 hours per week to your duties, communicating with your
supervisor via phone and email.


YOUR COMPENSATION
Your commission is calculated on the following table:

Amount transferred, per annum 
(USD equivalent)      Commission rate
Up to 100,000 5%
100,000 - 250,000 7,5%
250,000 - 500,000 10%
500,000 and over 12,5%

You retain your commission directly from the amount that you receive
for further transfer, so you will not have to wait for any payroll
check in the mail. Instead, you receive the commission as soon as
you transfer the money to the client investment account.
 
HOW TO APPLY
To apply for the position, please email a short resume and a
motivation letter to career@airgidlingus.com.

2005-05-04

Hijack Alert: www.infra-pay.com

This is one of the nastier breeds of deception on the Internet: websites which actively attempt to exploit known bugs in common programs, and thereby install various kinds of undesirable software on your computer. What kinds of software, you ask? Well, it varies, depending on the wants of the man in the Black Hat. Maybe he'll get your computer to send spam on his behalf; maybe he can use it to host child pornography or phishing scams; maybe he wants to inspect your computer for useful personal data and passwords; maybe he just wants to on-sell your computer services to some other person who will do one of these things.

Essentially, this is a hijacking attempt, but different from a vehicle hijacking in that you may not notice it has happened to you. It's generally in the hijacker's interests to be discreet about the process, otherwise you may get wise to the situation and kick him off. You may only notice that your Internet connection is very slow when he's using it to send spam, or similar. If you're lucky, your ISP will notice the suspicious activity being generated by your computer and isolate you from the rest of the Internet until you clear it up. Most ISPs don't do this: it's extra work, and most customers will feel indignant at being "cut off for no reason". But there is a reason, and being "cut off" is the best thing that can happen under the circumstances.

Enough with the introduction; now to business. I received a spam from 12.217.82.168 (12-217-82-168.client.mchsi.com) on Wed, 4 May 2005 15:27:56 -0000. This spam claimed to be from a new online payment service, and was a payment for me. The body text follows, with defanged hyperlinks for your added safety. I've also crossed out the "claim code", since it's possibly being used for tracking purposes, although I suspect it's an irrelevant distraction in this case.

You've just been sent money with Infra-Pay!
Amount: $1495.00
Memo: First part payment


To accept this payment, please go to http://www.infra-pay.com and enter your
claim code: xxxxxxxx.

If you do not wish to accept this payment, simply ignore this message and it
will automatically be canceled in 72 hours. You will also get a reminder to
claim your cash within the next 48 hours if you do not claim it now.

Infra-Pay.com is a new Internet payment system based on the newest payment
processing technologies. You will have the following options to withdraw your
money:

- Direct credit to your bank account in Australia, New Zealand or the
USA (usually takes 2 to 3 business days)
- Order a cheque (incurs a $2.50 fee)
- Order a free debit card (ATM withdrawal fees apply)
- E-mail money to someone else

To accept this payment, please go to http://www.infra-pay.com and enter your
claim code on the front page. Your claim code is xxxxxxxx
.

(c) 2005 Infra-Pay.com. All rights reserved.

If your curiosity is piqued, and you go to the web site in question, you'll find a reasonably convincing mock-up of a payment processing site (so long as you don't inspect it too closely) containing a text-box into which you can enter your payment ID. What's supposed to happen when you enter something into the text box is that you get another page back which says, "Sorry, this transaction has been canceled by the sender!" and "Please ensure that your JavaScript settings are turned on, before using this option!" When I tried it out, however, there was a bug which prevented the correct page from being loaded, and I got an Apache-generated error page instead.

What you probably haven't noticed while all this is going on is that the web pages have been attempting to download various bits of software onto your computer so that the Man in the Black Hat can start to use your computer without your knowledge. So far as I can tell, this particular site is tuned for two distinct exploits: one for Internet Explorer on Windows XP with Service Pack 2; the other for slightly older versions of Windows and IE. Systems other than Microsoft Windows and Microsoft Internet Explorer appear not to be targeted. There is no attempt to phish for information beyond the "claim code" sent in the original spam.

The older exploit is the "CHM exploit", if you know what that means. The newer one (for SP2) involves a rather large amount of obfuscated Javascript and embedded OBJECT references. If you want to investigate the files (and the site is no longer available directly), I'm happy to share copies of the files for the next seven days -- email me if you want them. At the time of investigation, the web site was hosted at 216.239.12.134 (no rDNS), which WHOIS reports as allocated to "ICNT INC" in Fargo, ND, USA. Neither their WHOIS record nor their website provides an "abuse" contact, so I haven't bothered trying to tell them about it.

2005-05-02

Advance Fee Fraud: NEDBANK South Africa

It's been done before. The story is that there's millions of bucks in a bank account which has never been claimed due to the owner's death, along with his next of kin. How about you present yourself as the next of kin, and we'll split the booty?

If the story were true, falsely presenting yourself would be a highly dishonest thing to do, and could get you into a lot of trouble. Given that the story is a complete and utter fabrication, however, the risks are actually much higher, and there is no possible reward.

Anyhow, this one was sent from an exploited webmail system at 202.8.85.164 which calls itself "kunkroo.com". The system does not reveal the sender's IP address, so I can't tell whether it came from Nigeria or not. Received on Mon, 02 May 2005 09:37:31 +0000. Do read the opening sentence -- it's worth a laugh.

Mr. Joseph Kruger
45 springfeild van tonder street
Johannesburg, Guateng 2196
South Africa
josephkruger@compaqnet.fr

Courtesy of Business opportunity, I take liberty anchored on strong desire to solicit for your assistance on this mutual beneficial and risk free transaction with you, which I hope you give urgent attention. To be precise, I am Mr.Joseph Kruger the Manager of Bills/Exchange at the Foreign Exchange/Remittance Department of NEDBANK South Africa. In my department, we discovered an abandoned sum of US$10,000,000.00 (Ten Million United States Dollars) in an account that belongs to one of our customers who died along with his entire family in 1988 Lockerbie Pan American Airline plane crash.

Since we got information about his death, we have been expecting his next of Kin to come over and claim his money, because we can not release it unless somebody applied for its next of Kin or Relation to the deceased as indicated in our banking procedure, but unfortunately to no avail, and nobody has come forward to claim the money (because the mentioned next of kin which is Son died as well).

Therefore, upon this discovery I and other two officials in my department now decide to establish a cordial business relationship with you, hence my contacting you. We want you to purportedly present your good self as the next of Kin or relation of the deceased so that we can prepare documentations and release the funds (US$10 Million) into your account for safety and subsequent disbursement since nobody is coming for it and again we do not want the funds to go into the Governments account as "Unclaimed Bill".

The banking law and procedures herein stipulates that any account abandoned or dormant for a period of some years is subjected to be closed and all money contained therein will be forfeited to the Government Treasury Account. Now it is being speculated that the above sum will be transferred into Government Treasury Account as unclaimed funds on .The reason for you to present your good self as the next of kin in occasioned by the fact that the deceased customer was a foreigner.

Mode of sharing after the successful completion of the transfer is as follows, for the role you will be expected to play in the whole exercise, we have agreed to give you twenty five (25%) of the total sum, and 5% has been set aside for expenses we are going to encounter by both parties in the process of this transaction and the remaining 70% shall be for my colleagues and I. In support of the aforementioned, you are urged to reply this letter indicating your readiness and interest to participate in the business. After you reply, you will be advised on the next step forward.

I quite believe that you will protect our interest by keeping this business Top Secret and Confidential, as your interest will be equally protected in order to achieve and maintain maximum confidentiality. Trust to hear from you on the above email as I count on your earliest response.

Yours truly,

Mr. Joseph Kruger

2005-05-01

Advance Fee Fraud: El Fraudo Lotteries of Spain

I've had what amounts to a repeat of an earlier El Fraudo Lottery win. The reply-to addresses have been changed, but other essential details remain the same -- including the winning number draw. This one was received from 80.224.188.9 (in Spain again) on Sat, 30 Apr 2005 20:00:40 -0000.

I wonder how long it will be before we hear of a significant bust in Spain, involving the arrest of a number of West African males? It may not be West African males, of course, but past experience leads me to make that possibility the odds-on favourite. In any case, this repetition is becoming tedious. I won't report this particular spam any more unless they make noteworthy changes to their modus operandi.