<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Joe Wein's blog &#187; spam</title>
	<atom:link href="http://www.joewein.net/blog/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.joewein.net/blog</link>
	<description>Comments from Yokohama, Japan</description>
	<lastBuildDate>Sat, 07 Aug 2010 14:29:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Vir7remover_2009_b2.exe / defend6-pc.com scareware</title>
		<link>http://www.joewein.net/blog/2010/04/10/vir7remover_2009_b2-exe-defend6-pc-com-scareware/</link>
		<comments>http://www.joewein.net/blog/2010/04/10/vir7remover_2009_b2-exe-defend6-pc-com-scareware/#comments</comments>
		<pubDate>Sat, 10 Apr 2010 04:35:02 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[Fraud]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=695</guid>
		<description><![CDATA[While researching some information, I came across a Google hit that looked like what I was looking for, but when I opened the page, none of the text in the preview paragraph was there. Somebody must have fed bogus contents to GoogleBot to attract searches.
Instead of the expected information I found myself on a scareware [...]]]></description>
			<content:encoded><![CDATA[<p>While researching some information, I came across a Google hit that looked like what I was looking for, but when I opened the page, none of the text in the preview paragraph was there. Somebody must have fed bogus contents to GoogleBot to attract searches.</p>
<p>Instead of the expected information I found myself on a scareware site called defend6-pc.com that was then trying to coerce me into downloading and installing their fake security software. A pop-up dialog asked me whether I wanted to scan my computer with their software. It didn&#8217;t matter if I clicked OK or Cancel, a download would always start. Only by closing the browser Window could I get rid of their nasty popup dialogs.</p>
<p>I&#8217;m using Mozilla FireFox, which does not offer to run downloaded EXEs directly. I did not click on the downloaded &#8220;Vir7remover_2009_b2.exe&#8221;, instead I ran it through <a href="http://www.virustotal.com/analisis/9b36053a5703131b8ff8e3b97788bd381cce9c295d125b859001158562f09459-1270866553">the VirusTotal.com online malware scanner</a> (highly recommended!) and products by four companies diagnosed it as malicious or suspicious:</p>
<ul>
<li> Microsoft (1.5605) says it&#8217;s a &#8220;Trojan:Win32/FakeXPA&#8221; </li>
<li> Sophos (4.52.0) says it&#8217;s &#8220;Mal/FakeAV-CX&#8221; </li>
<li> VBA32 (3.12.12.4) says it&#8217;s &#8220;BScope.Trojan.MTA.0157&#8243; </li>
<li> Panda (10.0.2.2) calls it a &#8220;&#8221;Suspicious file&#8221; </li>
</ul>
<p>&#8220;Mal/FakeAV-CX&#8221; indicates &#8220;<a href="http://en.wikipedia.org/wiki/Scareware">scareware</a>&#8220;, software that pretends to be an anti-virus / malware scanner that scares you with bogus alerts of malware on your harddisk into installing and or purchasing the software. Such software can include Trojans (as you would suspect from &#8220;Trojan:Win32/FakeXPA&#8221;  and &#8220;BScope.Trojan.MTA.0157&#8243;) that take over your machine and can give someone else full control over your machine for malicious activities.</p>
<p>The following domains are all hosted on the same server as defend6-pc.com (IP address 93.174.95.154) and this list probably is not complete. I definitely would not recommend installing any software from any of these sites:</p>
<ul>
<li> 10scanantispyware.com</li>
<li> 20scanantispyware.com</li>
<li> 2scanantispyware.com</li>
<li> 30scanantispyware.com</li>
<li> 3scanantispyware.com</li>
<li> 50virus-scanner.com</li>
<li> 5scanantispyware.com</li>
<li> 60scanantispyware.com</li>
<li> 7scanantispyware.com</li>
<li> 80scanantispyware.com</li>
<li> 8scanantispyware.com</li>
<li> 90virus-scanner.com</li>
<li> antispy-scan200.com</li>
<li> antispy-scan400.com</li>
<li> antispy-scan600.com</li>
<li> antispy-scan700.com</li>
<li> antispy-scan800.com</li>
<li> antispywarehelp002.com</li>
<li> antispywarehelp004.com</li>
<li> antispywarehelp008.com</li>
<li> antispywarehelp010.com</li>
<li> antispywarehelp022.com</li>
<li> antispywarehelpk0.com</li>
<li> antispywarehelpk2.com</li>
<li> antispywarehelpk4.com</li>
<li> antispywarehelpk6.com</li>
<li> antispywarehelpk8.com</li>
<li> antivirus-inet01.com</li>
<li> antivirus-inet31.com</li>
<li> antivirus-inet41.com</li>
<li> antivirus-inet51.com</li>
<li> antivirus-scan200.com</li>
<li> antivirus-scan400.com</li>
<li> antivirus-scan600.com</li>
<li> antivirus-scan700.com</li>
<li> antivirus-scan900.com</li>
<li> antivirus-test88.com</li>
<li> antivirus10scanner.com</li>
<li> antivirus900scanner.com</li>
<li> av-scanner200.com</li>
<li> av-scanner300.com</li>
<li> av-scanner400.com</li>
<li> av-scanner500.com</li>
<li> av-scanner700.com</li>
<li> defend-computer10.com</li>
<li> defend-computer30.com</li>
<li> defend-computer50.com</li>
<li> defend-computer70.com</li>
<li> defend-computer82.com</li>
<li> defend-computer83.com</li>
<li> defend-computer84.com</li>
<li> defend-computer85.com</li>
<li> defend-computer86.com</li>
<li> defend-computer88.com</li>
<li> defend-computer90.com</li>
<li> defend-pc100.com</li>
<li> defend-pc130.com</li>
<li> defend-pc150.com</li>
<li> defend-pc170.com</li>
<li> defend2-pc.com</li>
<li> defend5-pc.com</li>
<li> defend6-pc.com</li>
<li> inetproscan001.com</li>
<li> inetproscan031.com</li>
<li> inetproscan061.com</li>
<li> inetproscan081.com</li>
<li> inetproscan091.com</li>
<li> insight-scan20.com</li>
<li> insight-scan40.com</li>
<li> insight-scan60.com</li>
<li> insight-scan80.com</li>
<li> insight-scan90.com</li>
<li> insight-scanner2.com</li>
<li> insight-scanner5.com</li>
<li> insight-scanner7.com</li>
<li> insight-scanner8.com</li>
<li> insight-scanner9.com</li>
<li> internet-scan020.com</li>
<li> internet-scan040.com</li>
<li> internet-scan050.com</li>
<li> internet-scan070.com</li>
<li> internet-scan090.com</li>
<li> internet-scanner020.com</li>
<li> internet-scanner030.com</li>
<li> internet-scanner050.com</li>
<li> internet-scanner070.com</li>
<li> internet-scanner090.com</li>
<li> net-02antivirus.com</li>
<li> net-04antivirus.com</li>
<li> net-05antivirus.com</li>
<li> net-07antivirus.com</li>
<li> net001antivirus.com</li>
<li> net011antivirus.com</li>
<li> net021antivirus.com</li>
<li> net111antivirus.com</li>
<li> net222antivirus.com</li>
<li> novirus-scan00.com</li>
<li> novirus-scan01.com</li>
<li> novirus-scan22.com</li>
<li> novirus-scan31.com</li>
<li> novirus-scan33.com</li>
<li> novirus-scan41.com</li>
<li> novirus-scan55.com</li>
<li> novirus-scan61.com</li>
<li> novirus-scan81.com</li>
<li> novirus-scan88.com</li>
<li> spyware-stop01.com</li>
<li> spyware-stopb1.com</li>
<li> spyware-stopm1.com</li>
<li> spyware-stopn1.com</li>
<li> spyware-stopz1.com</li>
<li> spyware200scan.com</li>
<li> spyware500scan.com</li>
<li> spyware800scan.com</li>
<li> spyware880scan.com</li>
<li> spywarescan010.com</li>
<li> spywarescan013.com</li>
<li> spywarescan015.com</li>
<li> spywarescan017.com</li>
<li> spywarescan018.com</li>
<li> stop-all-virus1.com</li>
<li> stop-all-virus3.com</li>
<li> stop-all-virus6.com</li>
<li> stop-all-virus9.com</li>
<li> stop-virus-01a.com</li>
<li> stop-virus-01b.com</li>
<li> stop-virus-01d.com</li>
<li> stop-virus-01e.com</li>
<li> stop-virus-01f.com</li>
<li> stop-virus-03b.com</li>
<li> stop-virus-03u.com</li>
<li> stop-virus-03y.com</li>
<li> stop-virus-03z.com</li>
<li> stop-virus-040.com</li>
<li> stop-virus-070.com</li>
<li> stop-virus-090.com</li>
<li> stop-virus-091.com</li>
<li> stop-virus-099.com</li>
<li> stopvirus-scan11.com</li>
<li> stopvirus-scan13.com</li>
<li> stopvirus-scan16.com</li>
<li> stopvirus-scan18.com</li>
<li> stopvirus-scan33.com</li>
<li> stopvirus-scan66.com</li>
<li> stopvirus-scan88.com</li>
<li> stopvirus-scan99.com</li>
<li> virus77scanner.com</li>
<li> virus88scanner.com</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/04/10/vir7remover_2009_b2-exe-defend6-pc-com-scareware/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Spam from hacked hotmail accounts sent from China</title>
		<link>http://www.joewein.net/blog/2010/04/03/spam-from-hacked-hotmail-accounts-sent-from-china/</link>
		<comments>http://www.joewein.net/blog/2010/04/03/spam-from-hacked-hotmail-accounts-sent-from-china/#comments</comments>
		<pubDate>Sat, 03 Apr 2010 03:03:46 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=690</guid>
		<description><![CDATA[A bit over a year ago I wrote here about the &#8220;New Shopping, new life&#8221; spam that was sent from hacked free webmail accounts to advertise fake Chinese online shops. Recently I am seeing a lot more spam like that, mostly using hacked Hotmail accounts. Here is a typical example:

hello：
Please forgive us to disturb your [...]]]></description>
			<content:encoded><![CDATA[<p>A bit over a year ago I wrote here about the <a href="http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/">&#8220;New Shopping, new life&#8221;</a> spam that was sent from hacked free webmail accounts to advertise fake Chinese online shops. Recently I am seeing a lot more spam like that, mostly using hacked Hotmail accounts. Here is a typical example:</p>
<blockquote><p>
hello：<br />
Please forgive us to disturb your valued time.<br />
This is a big wholesale company in china, sell electronic products to all the world,such as laptop, camera, phone and so on. We can offer the low price and high quality to you. If you have free    time, please  to visit our official website:  <code>http://lezucker.com</code><br />
if you have any other questions, please be free  contact us by email or msn at any time.<br />
Yours Sincerely,</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Not got a Hotmail account? Sign-up now &#8211; Free </p></blockquote>
<p>The emails accounts appear to be accessed from IP addresses in China such as these:</p>
<ul>
<li> 60.4.32.231 (3220 emails)
<li> 116.7.20.191 (1974 emails)
<li> 121.35.79.35 (1865 emails)
<li> 60.4.153.48 (326 emails)
<li> 121.35.79.16 (265 emails)
</ul>
<p>The email counts are for a period of about 60 hours and are only for my spam traps and external spam feeds, not the total sent from those addresses. What&#8217;s more, it&#8217;s not just a large number of emails per IP address but also per mail account (full address obscured for privacy reasons):</p>
<ul>
<li> XXamari35@hotmail.com (2645 emails)
<li> XXpsychling@hotmail.com (1994 emails)
<li> XXishacarroll@hotmail.com (1215 emails)
<li> XXbgreene27@hotmail.com (671 emails)
<li> XXedina723@hotmail.com (575 emails)
<li> XXgmo@hotmail.com (326 emails)
<li> XXroxd1@hotmail.com (294 emails)
</ul>
<p>I find it surprising that Hotmail would allow a single free mail account to send out thousands of spams a day without getting it shut down. I can only guess what the total number is, as the above are only spam that I have received copies of. Clearly Microsoft will have to improve its mechanisms to catch such abuse.</p>
<p>Here are some of the domains advertised via these scammers:</p>
<ul>
<li> lezucker.com (4189 emails)</li>
<li> ebroun.com (2645 emails)</li>
<li> hgbet.com (329 emails)</li>
</ul>
<p>The IP address seem to be mostly but not exclusively from providers in the South of China, in Henan and Guangdong provinces:</p>
<blockquote><p>inetnum:      115.48.0.0 &#8211; 115.63.255.255<br />
netname:      UNICOM-HA<br />
descr:        China Unicom Henan province network<br />
descr:        China Unicom<br />
country:      CN</p></blockquote>
<blockquote><p>inetnum:      123.8.0.0 &#8211; 123.15.255.255<br />
netname:      UNICOM-HA<br />
descr:        China Unicom Henan province network<br />
descr:        China Unicom<br />
country:      CN</p></blockquote>
<blockquote><p>inetnum:      123.52.0.0 &#8211; 123.55.255.255<br />
netname:      MAINT-CHINANET-HA<br />
descr:        CHINANET HENAN PROVINCE NETWORK<br />
descr:        henan Telecom Corporation<br />
descr:        97# Zhongyuan Street, Zhengzhou,henan,Chinese<br />
country:      CN</p></blockquote>
<blockquote><p>inetnum:      121.32.0.0 &#8211; 121.35.255.255<br />
netname:      CHINANET-GD<br />
descr:        CHINANET Guangdong province network<br />
descr:        China Telecom<br />
descr:        No.31,jingrong street<br />
descr:        Beijing 100032<br />
country:      CN</p></blockquote>
<blockquote><p>inetnum:      219.128.0.0 &#8211; 219.137.255.255<br />
netname:      CHINANET-GD<br />
descr:        CHINANET Guangdong province network<br />
descr:        Data Communication Division<br />
descr:        China Telecom<br />
country:      CN</p></blockquote>
<blockquote><p>inetnum:      123.112.0.0 &#8211; 123.127.255.255<br />
netname:      UNICOM-BJ<br />
descr:        China Unicom Beijing province network<br />
descr:        China Unicom<br />
country:      CN</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/04/03/spam-from-hacked-hotmail-accounts-sent-from-china/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Haiti disaster attracts Nigerian scammers</title>
		<link>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/</link>
		<comments>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 06:05:07 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=643</guid>
		<description><![CDATA[It happened after the Indian ocean tsunami and after Hurricane Katrina. It&#8217;s happening again with the earthquake in Haiti that has killed tens of thousands and left hundreds of thousands injured, homeless, hungry or without medical treatment: Scammers in Nigeria and elsewhere are stealing money meant for victims of the disaster. 
If you think there [...]]]></description>
			<content:encoded><![CDATA[<p>It happened after the Indian ocean tsunami and after Hurricane Katrina. It&#8217;s happening again with the earthquake in Haiti that has killed tens of thousands and left hundreds of thousands injured, homeless, hungry or without medical treatment: Scammers in Nigeria and elsewhere are stealing money meant for victims of the disaster. </p>
<p>If you think there is a line that such scammers won&#8217;t cross, think again. </p>
<p>Here is an email soliciting donations on behalf of &#8220;HAITI CITIZENS LIVING IN THE UNITED KINGDOM&#8221; with relatives living in Haiti, but really originating from an IP address in Nigeria, West Africa:</p>
<blockquote><p>PASTOR JOHN BROMA<br />
HAITI CITIZENS IN UNITED KINGDOM<br />
23 BEN AVENUE S/W,LONDON<br />
UNITED KINGDOM</p>
<p>DEAR SIR/MADAM</p>
<p>WE ARE HAITI CITIZENS LIVING IN THE UNITED KINGDOM WHOM THEIR FAMILIES<br />
ARE AFFECTED BY THE RECENT EARTQUAKE,WE HAVE BEEN TRYING TO RAISE MONEY<br />
TO HELP THE HAITI CITIZENS WHO ARE WITHOUT FOODS,DRUG AND SHELTER,SO WE<br />
PLEAD THAT YOU SUPPORT US WITH WHAT EVER YOU CAN.</p>
<p>ALL DONATIONS SHOULD BE SEND THROUGH WESTERN UNION MONEY TRANSFER<br />
BECAUSE OF THE URGENT ATTENTION NEEDED.DO SEND IT TO THE INFORMATIONS BELOW.</p>
<p>PASTOR JOHN BROMA</p>
<p>HAITI CITIZENS IN UNITED KINGDOM<br />
23 BEN AVENUE S/W,LONDON<br />
UNITED KINGDOM</p>
<p>PLEASE MAKE SURE THAT YOU FORWARD THE WESTERN UNION INFORMATIONS SUCH AS<br />
SENDERS NAME,AMOUNT SEND AND THE MTCN.WE PRAY THAT ALMIGHTY GOD WILL<br />
BLESS AS YOU HELP THE SUFFERING HAITI CITIZEN.</p>
<p>THANKS FOR YOUR HELP</p>
<p>PASTOR JOHN BROMA(SECRETARY)</p>
</blockquote>
<p>Looking at the message headers we see:</p>
<blockquote><p>Received: from User ([82.128.33.35] RDNS failed) by mail.westnet.com<br />
with Microsoft SMTPSVC(6.0.3790.3959); Fri, 15 Jan 2010 19:13:32 +0900<br />
Reply-To: &lt;pastorjohnbroma@yahoo.com&gt;<br />
From: HIATI CITIZENS IN UNITED KINGDOM&lt;pastorjohnbroma@yahoo.com&gt;<br />
Subject: HELP FOR HAITI<br />
Date: Sat, 16 Jan 2010 11:21:10 -0800
</p></blockquote>
<p>IP address 82.128.33.35 belongs to a cell phone provider in Nigeria:</p>
<blockquote><p>inetnum:        82.128.32.0 &#8211; 82.128.63.255<br />
netname:        INET-MLTL<br />
descr:          CDMA 1x/EVDO Dial up pool<br />
country:        NG<br />
admin-c:        RIA27<br />
tech-c:         RIA27<br />
status:         ASSIGNED PA<br />
mnt-by:         MLTL-INT-MNT<br />
mnt-lower:      MLTL-INT-MNT<br />
source:         AFRINIC # Filtered<br />
parent:         82.128.0.0 &#8211; 82.128.127.255</p>
<p>person:       IP Admin-RIPE<br />
address:      Multilinks Telecommunications Limited<br />
address:      231 Adeola Odeku Str.<br />
address:      Victoria Island, Lagos, Nigeria
</p></blockquote>
<p>The criminal who sent this mail must be one of their customers.</p>
<p>If you want to make a donation to help those affected by the disaster, send it to the Red Cross or another well established relief organization. Beware of any stranger who asks you to wire money by Western Union or MoneyGram, because these instant wire transfer services are essentially anonymous and untraceable and there are no safeguards whatsoever against abuse by criminal recipients, who can not be traced. That is precisely why scammers prefer you to send money that way.</p>
<p>If hell exists there must be a special place there waiting for these scammers, who even make money out of the orphans and dying in Haiti.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Broken link suggestion spam, a new twist on link exchange spam</title>
		<link>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/</link>
		<comments>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 07:48:39 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=634</guid>
		<description><![CDATA[Since Google ranks sites primarily by how many other pages and sites link to them, unethical people have been trying to boost their site rankings by tricking others into creating links to them. 
Link exchange spam, i.e. unsolicited offers to reciprocally create links to each other&#8217;s sites, has been around for many years. Recently I [...]]]></description>
			<content:encoded><![CDATA[<p>Since Google ranks sites primarily by how many other pages and sites link to them, unethical people have been trying to boost their site rankings by tricking others into creating links to them. </p>
<p>Link exchange spam, i.e. unsolicited offers to reciprocally create links to each other&#8217;s sites, has been around for many years. Recently I came across a new twist, broken link suggestion spam. You&#8217;ll receive a personal looking email like the following that tells you about a broken link on a page on one of your sites, with an suggestion for a replacement link target (boldface added by me):</p>
<blockquote><p><b>Hi</b> Joe!<br />
<b>Sorry to bother you, my name is</b> Kate Austen, <b>I&#8217;m a</b> teaching assistant for a sociology class. <b>I&#8217;ve been doing some research online for an</b> upcoming lesson on the urban legends, myths, and hoaxes, <b>and your page was very helpful. Thanks so much!</b></p>
<p><b>I noticed that on your page</b> (http://www.joewein.de/hoax.htm) <b>you have a broken link</b> http://www.urbanlegends.com/index.html <b>(an old page about</b> urban legends<b>)&#8230; May I offer a thought on a possible replacement?</b> http://www.costumesupercenter.com/csc_inc/html/static/btarticles/urbanlegendsandmyths.html <b>It has some great information about</b> several urban legends and myths. <b>I found it to be a great resource during my research, and it would be a great fix to your broken link. I&#8217;ve added it to my bookmarks, along with your site</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Just thought I&#8217;d let you know</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Take Care, </b><br />
Kate<br />
kate@professor-research.org</p></blockquote>
<p>I plugged some phrases from the above email into Google and it found the following similar email (boldface also added by me, please compare the two):</p>
<blockquote><p>Crystal Sawyer<br />
crystal@studentresearchers.org</p>
<p><b>Hi!<br />
Sorry to bother you, my name is</b> Crystal Sawyer, <b>I&#8217;m an</b> education major from upstate New York. <b>I&#8217;ve been doing some research online for a</b> class project <b>and your pages were very helpful. Thanks so much</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>I noticed that on your page</b> (http://www.apfn.org/apfn/mmm.htm) <b>you have a broken link</b> http://www.nara.gov/exhall/charters/declaration/decmain.html <b>(an old page about</b> science projects<b>)&#8230; May I offer a thought on a possible replacement?</b> http://legalmetro.com/library/historic-us-documents-the-charters-of-freedom.html <b>It has some great information about</b> teaching children how to do experimental science projects. <b>I found it to be a great resource during my research, and it would be a great fix to your broken link. I&#8217;ve added it to my bookmarks, along with your site</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Just thought I&#8217;d let you know</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Take Care,</b><br />
Crystal<br />
crystal@studentresearchers.org</p></blockquote>
<p>The number of identical phrases is far to high to be a coincidence. Looking at the sender domains professor-research.org and studentresearchers.org, the registrant on both is hidden behind the anonymization service domainsbyproxy.com. </p>
<p>I would say chances are good that both &#8220;Kate&#8221; and &#8220;Crystal&#8221; are the same person and that this person works for a company offering paid search engine optimization (SEO) services to boost their customers&#8217; website rankings. They add some editorial contents to the customer website and then deceptively ask owners of sites with a high Page rank (PR) to replace broken links with links to these new pages by posing as students and researchers with no obvious commercial interest in the link target site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Dial +44 70 (UK number) for international online fraud</title>
		<link>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/</link>
		<comments>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 03:28:47 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=480</guid>
		<description><![CDATA[A few years ago I created the Scam-O-Matic (www.scamomatic.com), a website that every month has helped thousands of people worldwide by automatically diagnosing online fraud emails that people have submitted to it. Scamomatic.com recognizes fake lotteries, &#8220;dead customer&#8221; scams, &#8220;dying widow&#8221; scams and many other common formats from scammers from Nigeria that you may have [...]]]></description>
			<content:encoded><![CDATA[<p>A few years ago I created the <a href="http://www.scamomatic.com">Scam-O-Matic</a> (<a href="http://www.scamomatic.com">www.scamomatic.com</a>), a website that every month has helped thousands of people worldwide by automatically diagnosing online fraud emails that people have submitted to it. Scamomatic.com recognizes fake lotteries, &#8220;dead customer&#8221; scams, &#8220;dying widow&#8221; scams and many other common formats from scammers from Nigeria that you may have seen in your inbox before. Even when it can&#8217;t pinpoint the exact type of scam, it often recognizes it as a generic scam format, largely thanks to the presence in the email of <b>UK phone numbers that start with +44 70</b>. These numbers are everywhere in Nigerian online scams, regardless of the precise scam format. The +44 70 prefix might as well be called the country code of Nigerian scammers.</p>
<p><strong>If you receive any email that mentions any +4470 phone number, do not reply to it! You can submit the body of any suspicious email message to</strong> <a href="http://www.scamomatic.com">www.scamomatic.com</a> <strong>for instant feedback about what kind of scam it might be.</strong></p>
<p>These +4470 numbers are a gift to online scammers by British phone regulators. They are primarily owned by obscure British phone companies offering an anonymous call forwarding service. The economic model of these services is simple: The caller dials a rather expensive UK number and the UK service provider forwards the incoming call to a somewhat less expensive to call international number (for example a Nigerian mobile phone, which remains hidden from the caller), pocketing the difference between the call rates. For example, the caller might pay 50 cents per minute to call a +44 70 number and the call will then be forwarded to a Nigerian mobile phone that costs 25 cents per minute, leaving 25 cents per minute as a net margin for the service operator. The more successful the scammers are, the more money the phone company makes. Who ever said crime doesn&#8217;t pay? </p>
<p>These UK phone numbers are very attractive to scammers: When people can be made to believe that they are dealing with a bank, lawyer or government official in London, UK when they&#8217;re actually talking to a scammer on his cell phone in an Internet cafe in Lagos, Nigeria then they are much more easily defrauded by criminals.</p>
<p>As far as I can tell these numbers aren&#8217;t really being used for any other purpose than to enable international online crimes to be committed. In some nine years of tracking Nigerian scam emails, I have yet to come across a single legitimate user of a +44 70 number. I really don&#8217;t understand why the British government has allowed those services to continue to operate.</p>
<p>Now, of course the service operators can claim that they don&#8217;t know that their services are being used for criminal purposes unless someone tells them about it. On the other hand, they are not exactly making it easy to report abuse and the high prices of these services means that it&#8217;s unlikely that they&#8217;ll get much legitimate use, if any.</p>
<p>There are several ways to curb abuse, other than suspending +44 70 numbers altogether and I would encourage the UK government to seriously consider them:</p>
<ul>
<li> The UK regulators could make it a requirement that calls via this service either originate in the UK or terminate in the UK, i.e. to prevent unrestricted global relaying, with say calls from India or the US being forwarded to Nigeria or C&ocirc;te d&#8217;Ivoire.</li>
<li> The UK regulators could require service providers to announce the country name of the phone number to which the call is being forwarded if the destination number is not a UK number.</li>
<li> The UK regulators could require service providers to block forwarding to mobile phone numbers in certain countries, e.g. Nigeria</li>
</ul>
<p>Below is a sample list of +44 70 numbers that appeared in Nigerian scams reported to Scam-O-Matic over the course of the last seven days. These roughly 60 phone numbers per day are only the tip of the iceberg:</p>
<blockquote><p>+447005801505<br />
+447005802020<br />
+447005810692<br />
+447005934945<br />
+447005942459<br />
+447005963237<br />
+447005977097<br />
+447006001100<br />
+447006002121<br />
+447006002413<br />
+447006029116<br />
+447006062478<br />
+447010023307<br />
+447010027439<br />
+447010027978<br />
+447010027983<br />
+447010028455<br />
+447010030769<br />
+447010285923<br />
+447010306559<br />
+447010476294<br />
+447010786457<br />
+447011120379<br />
+447011120510<br />
+447011120524<br />
+447011121450<br />
+447011121596<br />
+447011128170<br />
+447011129280<br />
+447011129286<br />
+447011129446<br />
+447011130062<br />
+447011130670<br />
+447011130769<br />
+447011131077<br />
+447011131152<br />
+447011133259<br />
+447011140499<br />
+447011140945<br />
+447011140989<br />
+447011146747<br />
+447011146830<br />
+447011147295<br />
+447011149054<br />
+447011152991<br />
+447011153129<br />
+447011162749<br />
+447011163186<br />
+447011163846<br />
+447011164243<br />
+447011182522<br />
+447011183455<br />
+447011184113<br />
+447011196412<br />
+447011197245<br />
+447011197787<br />
+447014225697<br />
+447014232391<br />
+447014232411<br />
+447014232442<br />
+447014236733<br />
+447014244984<br />
+447014275175<br />
+447014275728<br />
+447017026507<br />
+447017430128<br />
+447017769494<br />
+447017848035<br />
+447023011587<br />
+447023056559<br />
+447023058575<br />
+447023069806<br />
+447023086665<br />
+447023087509<br />
+447023092593<br />
+447024010876<br />
+447024010915<br />
+447024011554<br />
+447024012660<br />
+447024013770<br />
+447024014859<br />
+447024016712<br />
+447024017968<br />
+447024018504<br />
+447024018707<br />
+447024018725<br />
+447024018963<br />
+447024019584<br />
+447024019588<br />
+447024021204<br />
+447024021389<br />
+447024023138<br />
+447024023643<br />
+447024024530<br />
+447024024914<br />
+447024024938<br />
+447024025942<br />
+447024028606<br />
+447024029852<br />
+447024032255<br />
+447024033542<br />
+447024034362<br />
+447024034768<br />
+447024035958<br />
+447024036606<br />
+447024037907<br />
+447024038051<br />
+447024038950<br />
+447024041571<br />
+447024041989<br />
+447024042397<br />
+447024043571<br />
+447024045842<br />
+447024046548<br />
+447024047607<br />
+447024047708<br />
+447024051081<br />
+447024051604<br />
+447024053655<br />
+447024054764<br />
+447024056650<br />
+447024056684<br />
+447024057656<br />
+447024057695<br />
+447024059725<br />
+447024061362<br />
+447024061659<br />
+447024061805<br />
+447024062162<br />
+447024063633<br />
+447024063645<br />
+447024064180<br />
+447024065549<br />
+447024066713<br />
+447024066858<br />
+447024067752<br />
+447024068617<br />
+447024069933<br />
+447024070671<br />
+447024071597<br />
+447024071804<br />
+447024071867<br />
+447024072603<br />
+447024072995<br />
+447024073988<br />
+447024074220<br />
+447024074568<br />
+447024074742<br />
+447024075722<br />
+447024075954<br />
+447024077025<br />
+447024078351<br />
+447024079530<br />
+447024079908<br />
+447024080526<br />
+447024080571<br />
+447024080634<br />
+447024082668<br />
+447024082680<br />
+447024082728<br />
+447024083093<br />
+447024083705<br />
+447024084762<br />
+447024084918<br />
+447024084994<br />
+447024086967<br />
+447024087401<br />
+447024087599<br />
+447024087905<br />
+447024091678<br />
+447024091701<br />
+447024091706<br />
+447024092775<br />
+447024092795<br />
+447024092863<br />
+447024095774<br />
+447024095778<br />
+447024095878<br />
+447024096802<br />
+447024096869<br />
+447024097854<br />
+447024098802<br />
+447024098874<br />
+447024099606<br />
+447031740924<br />
+447031742574<br />
+447031744227<br />
+447031744980<br />
+447031744994<br />
+447031745967<br />
+447031746067<br />
+447031746887<br />
+447031747046<br />
+447031747509<br />
+447031749721<br />
+447031801246<br />
+447031801866<br />
+447031803498<br />
+447031803820<br />
+447031808512<br />
+447031809778<br />
+447031814575<br />
+447031814720<br />
+447031815436<br />
+447031816735<br />
+447031818230<br />
+447031821851<br />
+447031822608<br />
+447031823431<br />
+447031824330<br />
+447031825003<br />
+447031826670<br />
+447031830878<br />
+447031833248<br />
+447031833760<br />
+447031834660<br />
+447031835615<br />
+447031835762<br />
+447031837227<br />
+447031843396<br />
+447031844360<br />
+447031845639<br />
+447031846542<br />
+447031850801<br />
+447031851126<br />
+447031855107<br />
+447031855527<br />
+447031858919<br />
+447031859268<br />
+447031859327<br />
+447031859972<br />
+447031861174<br />
+447031861534<br />
+447031865718<br />
+447031877392<br />
+447031877975<br />
+447031880502<br />
+447031885537<br />
+447031890014<br />
+447031891762<br />
+447031894541<br />
+447031898197<br />
+447031903871<br />
+447031906765<br />
+447031908701<br />
+447031909751<br />
+447031911974<br />
+447031913322<br />
+447031915331<br />
+447031918554<br />
+447031918592<br />
+447031918698<br />
+447031918840<br />
+447031920863<br />
+447031928723<br />
+447031930960<br />
+447031931805<br />
+447031934581<br />
+447031938867<br />
+447031940670<br />
+4470319419882<br />
+447031943771<br />
+447031954666<br />
+447031956661<br />
+447031958680<br />
+447031960513<br />
+447031964131<br />
+447031971731<br />
+447031971766<br />
+447031972833<br />
+447031972850<br />
+447031973785<br />
+447031974969<br />
+447031978795<br />
+447031979858<br />
+447031982694<br />
+447031983660<br />
+447031983882<br />
+447031984862<br />
+447031988864<br />
+447031993596<br />
+447031993967<br />
+447031996818<br />
+447032334576<br />
+447035900183<br />
+447035900344<br />
+447035900914<br />
+447035901588<br />
+447035902188<br />
+447035902683<br />
+447035910276<br />
+447035911140<br />
+447035912873<br />
+447035913994<br />
+447035915768<br />
+447035922616<br />
+447035923742<br />
+447035924448<br />
+447035927916<br />
+447035928180<br />
+447035931142<br />
+447035937446<br />
+447035939194<br />
+447035939320<br />
+447035940617<br />
+447035944729<br />
+447035944779<br />
+447035947431<br />
+447035950853<br />
+447035951254<br />
+447035951405<br />
+447035954295<br />
+447035955376<br />
+447035956312<br />
+447035959966<br />
+447035960942<br />
+447035965038<br />
+447035966176<br />
+447035966188<br />
+447035966289<br />
+447035966480<br />
+447035968588<br />
+447035969249<br />
+447035969496<br />
+447035969754<br />
+447035969801<br />
+447035969823<br />
+447035972572<br />
+447035973164<br />
+447035973821<br />
+447035977317<br />
+447035978042<br />
+447035978343<br />
+447035978550<br />
+447035983963<br />
+447035988651<br />
+447035988847<br />
+447035989086<br />
+447035992118<br />
+447035996148<br />
+447035997215<br />
+447035997533<br />
+447035998886<br />
+447035999080<br />
+447040110515<br />
+447041743214<br />
+447045702581<br />
+447045704323<br />
+447045704570<br />
+447045705126<br />
+447045705374<br />
+447045706975<br />
+447045707234<br />
+447045707660<br />
+447045708253<br />
+447045709129<br />
+447045709292<br />
+447045710531<br />
+447045710917<br />
+447045711325<br />
+447045712243<br />
+447045712434<br />
+447045712662<br />
+447045712816<br />
+447045712993<br />
+447045713815<br />
+447045714219<br />
+447045719541<br />
+447045720546<br />
+447045721125<br />
+447045721617<br />
+447045722125<br />
+447045724094<br />
+447045725176<br />
+447045727388<br />
+447045729804<br />
+447045733035<br />
+447045733518<br />
+447045736862<br />
+447045742669<br />
+447045743467<br />
+447045747569<br />
+447045748609<br />
+447045754338<br />
+447045759317<br />
+447045767521<br />
+447045768060<br />
+447045770961<br />
+447045776356<br />
+447045780693<br />
+447045782120<br />
+447045783777<br />
+447045785147<br />
+447045785239<br />
+447045790181<br />
+447045791709<br />
+447045795051<br />
+447045798638<br />
+447045799030<br />
+447053491702<br />
+447053492393<br />
+447075158182<br />
+447092849621<br />
+447092861761<br />
+447092864823<br />
+447092980578<br />
+447092981646<br />
+447092981769<br />
+447092982175
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/feed/</wfw:commentRss>
		<slash:comments>55</slash:comments>
		</item>
		<item>
		<title>Domain appraisal scam</title>
		<link>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/</link>
		<comments>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 08:24:57 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=361</guid>
		<description><![CDATA[Be careful if you receive an email like the following:
We are interested to buy your domain name YOUR-DOMAIN-HERE and offer to buy it from you for 80% of the appraised market value.
As of now we accept appraisals from either one of the following leading appraisal companies:
- fleos.com
- sedo.com
If you already have an appraisal please forward [...]]]></description>
			<content:encoded><![CDATA[<p>Be careful if you receive an email like the following:</p>
<blockquote><p>We are interested to buy your domain name <em>YOUR-DOMAIN-HERE</em> and offer to buy it from you for 80% of the appraised market value.</p>
<p>As of now we accept appraisals from either one of the following leading appraisal companies:</p>
<p>- fleos.com<br />
- sedo.com</p>
<p>If you already have an appraisal please forward it to us.</p>
<p>As soon as we have received your appraisal we will send you our payment (we use paypal for amounts less than $2,000 and escrow for amounts above $2,000) as well as<br />
further instructions on how to complete the transfer of the domain name.</p>
<p>We appreciate your business,</p>
<p>Yours truly,</p>
<p>Mark Evans</p></blockquote>
<p>The offered percentage or the alias of the sender may be different. The list of appraisal companies may vary too and the catch is in the requested appraisal: Whereas sedo.com is a well established company dealing in domain resale and appraisal, domains fleos.com, flyrating.com and others are new:</p>
<blockquote><p>Domain Name: FLEOS.COM<br />
Registrar: WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC<br />
Whois Server: whois.webnic.cc<br />
Referral URL: http://www.webnic.cc<br />
Name Server: NS1.EZYDOMAIN.COM<br />
Name Server: NS2.EZYDOMAIN.COM<br />
Status: clientDeleteProhibited<br />
Status: clientTransferProhibited<br />
Status: clientUpdateProhibited<br />
Updated Date: 04-jul-2009<br />
Creation Date: 04-jul-2009<br />
Expiration Date: 04-jul-2010</p>
<p>Registrant Contact:<br />
        Modern Outlook Sdn Bhd<br />
        Modern Outlook Sdn Bhd  (reg_460127@whoisprotection.cc)<br />
        Lot 13-01A, Level 13 (East Wing) Berjaya Times Square, No.1, Jalan Imbi<br />
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 55100<br />
        P: +603.21491999         F: +603.21431685
</p></blockquote>
<p>This one was used earlier than in the above sample:</p>
<blockquote><p>Domain Name: FLYRATING.COM<br />
Registrar: WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC<br />
Whois Server: whois.webnic.cc<br />
Referral URL: http://www.webnic.cc<br />
Name Server: NS1.EZYDOMAIN.COM<br />
Name Server: NS2.EZYDOMAIN.COM<br />
Status: clientDeleteProhibited<br />
Status: clientTransferProhibited<br />
Status: clientUpdateProhibited<br />
Updated Date: 26-may-2009<br />
Creation Date: 26-may-2009<br />
Expiration Date: 26-may-2010</p>
<p>Registrant Contact:<br />
        Modern Outlook Sdn Bhd<br />
        Modern Outlook Sdn Bhd  (reg_449229@whoisprotection.cc)<br />
        Lot 13-01A, Level 13 (East Wing) Berjaya Times Square, No.1, Jalan Imbi<br />
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 55100<br />
        P: +603.21491999         F: +603.21431685
</p></blockquote>
<p>Notice how they&#8217;re both registered via the same registrar. If anyone checks out the fees they&#8217;ll find that not coincidentally these no-names charge less than Sedo.com for their service, so they might easily get picked by domain owners hoping to make quick cash. </p>
<p>Your guess is as good as mine who sends out those buy offer spams that drive business to those cookie cutter domain appraisal firms, who take $22.95 from anyone falling for this scam.</p>
<p><strong>Unless you enjoy getting scammed, avoid any domain purchase offer in which the would be buyer does not come up with an offer price on his own but asks you to get an appraisal from a third party and promises to pay you a percentage of the appraised value!</strong></p>
<p>Other &#8220;appraisal company&#8221; domains used:</p>
<ul>
<li> nameorange.com </li>
<li> pedma.com </li>
<li> pozde.com </li>
<li> podzz.com </li>
<li> domainexplorer.org </li>
<li> pddomains.com </li>
</ul>
<p>See also:</p>
<ul>
<li> <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">pedma.com domain appraisals? (dynamoo&#8217;s blog)</a></li>
<li> <a href="http://www.dynamoo.com/blog/2009/07/piradiusnet-yohostorg-black-hat-hosting.html">Piradius.net / Yohost.org &#8211; black hat hosting? (dynamoo&#8217;s blog)</a></li>
</ul>
<p><em>Last updated: 2009-08-10</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>&#8220;&#8230;, has added you as a friend on SiliconIndia&#8221; scam emails</title>
		<link>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/</link>
		<comments>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 02:58:39 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=353</guid>
		<description><![CDATA[Over the past year I&#8217;ve been getting a steady trickle of &#8220;friend requests&#8221;, i.e. invitations to join a service, for a website called SiliconIndia. Virtually all the supposed senders were women from India. Job titles included Software Engineer, Business Analyst and HR Executive. Most were very pretty. By that I mean not just better than [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past year I&#8217;ve been getting a steady trickle of &#8220;friend requests&#8221;, i.e. invitations to join a service, for a website called SiliconIndia. Virtually all the supposed senders were women from India. Job titles included Software Engineer, Business Analyst and HR Executive. Most were very pretty. By that I mean not just better than average looking, more like the portfolio of a modeling agency.</p>
<p>Because of my volunteer work against online scams, some email accounts of mine end up in address books of thousands of people who over time have forwarded me samples of questionable mails. Consequently, I also receive a lot of requests to join online networking and other websites, many of which make it too easy to invite everyone in your address book to join a particular service when you join. One mail folder that I keep exclusively for such invitations from people I don&#8217;t recognize currently contains over 1,100 examples. </p>
<p>When I received another SiliconIndia invitation yesterday, I decided to take a closer look and a very interesting picture evolved. I had 42 invitations going back to February 2008. Nine of them (originating with three indivuals) did not include a photograph and almost all of those were from the first month. They may have been real invitations. The interesting thing about the other 33 invitations was that the senders were all female. Not one guy! 23 of these were sent from Gmail accounts and 10 from AOL or AIM accounts. One picture I received from both a Gmail and an AOL account. It wasn&#8217;t just that these emails had AOL or Gmail sender addresses, they also did not come from a SiliconIndia mail server as one might expect for regular &#8220;tell a friend&#8221; invitations. All were sent from regular personal Gmail and AOL accounts through the respective mail servers. </p>
<p>What this tells me is that someone is manually making up invitation mails, using pictures of pretty women to attract mostly male job seekers to join that service. And somebody somewhere is making money out of people who respond.</p>
<p>Out of curiosity I joined the service under an assumed identity. The profile for the person who had invited me the day before had a list of 456 &#8220;friends&#8221;. If she were to &#8220;stay in touch&#8221; with all of them as it said in the invitation, she&#8217;d be a pretty busy lady. So next time you get an invitation to join SiliconIndia to connect with some pretty woman, don&#8217;t delude yourself. Most likely some guy somewhere is being paid a few rupees to mail pictures of pretty girls to thousands of guys in order to drive traffic to a commercial website.</p>
<p><center><img src="/img/siliconindia-invitation.png"></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>The &#8220;new shopping new life&#8221; spam</title>
		<link>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/</link>
		<comments>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 23:32:23 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=257</guid>
		<description><![CDATA[For about a year I have been receiving spam emails like this one below. They all look like they&#8217;ve been sent by private individuals somewhere in the world (usually from Yahoo or Hotmail accounts) but advertise companies in China:
hi:
New shopping new life!
  How are u doing these days?Yesterday I found a web of a [...]]]></description>
			<content:encoded><![CDATA[<p>For about a year I have been receiving spam emails like this one below. They all look like they&#8217;ve been sent by private individuals somewhere in the world (usually from Yahoo or Hotmail accounts) but advertise companies in China:</p>
<blockquote><p>hi:<br />
New shopping new life!<br />
  How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.<br />
Look forward to your early reply!<br />
The Web address: www.vanigo.com<br />
E-mail: vanigo@188.com<br />
MSN : vanigo@msn.cn </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Få en billig laptop. Se Kelkoos gode tilbud her!
</p></blockquote>
<p>Looking at the mail headers, it had come from the mail account of a Danish Yahoo user, but originated from an IP address in China (details edited to protect the privacy of the account owner):</p>
<blockquote><p>Received: from [<b>124.118.179.157</b>] by web26101.mail.ukl.yahoo.com<br />
 via HTTP; Wed, 11 Feb 2009 19:54:29 GMT<br />
X-Mailer: YahooMailWebService/0.7.260.1<br />
Date: Wed, 11 Feb 2009 19:54:29 +0000 (GMT)<br />
From: uffe #####sen &lt;uf###2@yahoo.dk&gt;<br />
Reply-To: uf###2@yahoo.dk<br />
Subject: hi:<br />
To: undisclosed recipients: ;
</p></blockquote>
<p>IP address 124.118.179.157 belongs to China Telecom:</p>
<blockquote><p>inetnum:      124.118.0.0 &#8211; 124.119.255.255<br />
netname:      CHINANET-XJ<br />
descr:        CHINANET Xinjiang province network<br />
descr:        China Telecom<br />
descr:        No1,jin-rong Street<br />
descr:        Beijing 100032<br />
country:      CN</p></blockquote>
<p>What appears to have happened is that spammers know the passwords to these mail accounts and are using them to send that spam to everyone in the mail account&#8217;s address book. </p>
<p>This is a very effective way to get through spam filters, as many recipients are likely to also have the sender in their address book and address book entries are automatically whitelisted by many spamfilters.</p>
<p>If you receive an email like that, alert the &#8220;sender&#8221; that their account has been compromised. They need to immediately change their email password to something more secure. </p>
<p>This abuse of stolen passwords illustrates the potential of password harvesting scams such as <a href="http://www.joewein.net/blog/2008/08/11/flapstatecom-mdanclubcom-wayizercom/">this one</a> I documented in August 2008, which is still going on.</p>
<p>Here are some Google searches related to the hacked webmail spam:</p>
<ul>
<li><a href="http://www.google.com/search?q=%22New+shopping+new+life%22">&#8220;New shopping new life&#8221;</a></li>
<li><a href="http://www.google.com/search?q=%22good+company+who+trades+mainly+in+electornic+products%22">&#8220;good company who trades mainly in electornic products&#8221;</a></li>
</ul>
<p>Here is a (probably incomplete) list of websites advertised this way:</p>
<ul>
<li>gvccn.com</li>
<li>ibvcn.com</li>
<li>jvccn.com</li>
<li>tvtcn.com</li>
<li>szfac.com</li>
<li>cxkeg.com</li>
<li>yaier.com</li>
<li>mmhdf.com</li>
<li>ixicb.com</li>
<li>vanigo.com</li>
<li>wabada.com</li>
<li>bj-trade.com</li>
<li>store-168.com</li>
<li>ele-motors.com</li>
<li>electronics-brand.com</li>
<li>exciting-zone.com</li>
</ul>
<p>Common subject lines:</p>
<ul>
<li>New shopping new life</li>
<li>Good shopping good mood!</li>
<li>Good web site</li>
<li>Have a great shopping!</li>
<li>good website!</li>
<li>Hi,Thank you!</li>
<li>Hi,</li>
<li>Dear friend</li>
</ul>
<p><b>Good passwords and bad passwords</b></p>
<p>A strong password should be the first line of defense against such criminals, but what makes a password good? It should contain a mixture of all of the following: </p>
<ul>
<li>lower case letters</li>
<li>upper case letters</li>
<li>digits</li>
<li>at least one non-alphanumeric character</li>
</ul>
<p>This makes it hard to break the password through brute force or through dictionary attacks. </p>
<p>Also the password should not be too short (8 characters or more) and should be reasonably easy to memorize, so you don&#8217;t have much need to write it down. Some examples:</p>
<ul>
<li>45Knife%Cabbage</li>
<li>4F5g6H&#038;j</li>
<li>J0hn1945-07-31</li>
</ul>
<p>Bad choices are passwords that consists of any word found in a dictionary, proper names, digits-only dates, adjacent keys on the keyboard or repeated characters. Never use anything like these:</p>
<ul>
<li>secret</li>
<li>qwerty</li>
<li>xxxx</li>
<li>john45</li>
</ul>
<p>It is <b>very important</b> not to use the exact same password for different purposes. </p>
<p>If spammers manage to trick you into revealing your password for one site (e.g. by getting you to create a new account at a site they control or by breaking into the database of another site where you&#8217;re a customer) then you&#8217;ve effectively handed them the key to the candy store. They can get access to your email account, in which they may find login information, password reminders, etc. of many other sites you&#8217;ve signed up for. At the very least they can harvest all your email contacts.</p>
<p>Beyond using different passwords for every site and service, it&#8217;s also a good idea to use a different password schema for &#8220;core&#8221; sites that you trust and depend upon (such as your email provider and webhost) and another for sites to which you sign up more casually (such as various forums, online shopping, etc.). Thus if one of the latter is compromised, it does not give criminals any clues what your more critical passwords may look like.</p>
<p><b>Who is behind this spam?</b></p>
<p>The sites advertised from the hacked email accounts constantly vary. They usually have been created only a few weeks or months earlier. For example, the domain in the above example was created two months ago:</p>
<blockquote><p>Domain name: vanigo.com</p>
<p>Registrant Contact:<br />
   wuxianj<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Administrative Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Technical Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Billing Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>DNS:<br />
ns1.4everdns.com<br />
ns2.4everdns.com</p>
<p>Created: 2008-12-08<br />
Expires: 2009-12-08
</p></blockquote>
<p>Considering the highly illegal way the companies advertised, what are the chances that any order you make at those sites would ever get shipped to you? For sure, they will gladly take your cash by (untraceable, unsafe) Western Union or take your credit card number, expiration date and security code. Never use Western Union to send money to people you don&#8217;t know from real life in person. Never enter your credit card on a site that doesn&#8217;t have SSL access (indicated by a URL starting with https:// and a padlock icon in the browser status bar) with a proper certificate.</p>
<p>Even more basic: Never do business with spammers. By sending you spam, they have already proven to you that they lack any morals. You have no reason to trust them and every reason to be alert!</p>
<p>If you have received similar spams, feel free to post them below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/feed/</wfw:commentRss>
		<slash:comments>77</slash:comments>
		</item>
		<item>
		<title>&#8220;Please respond or Some Stranger will think you said no :(&#8220;</title>
		<link>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/</link>
		<comments>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 09:35:10 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=246</guid>
		<description><![CDATA[I never really got used to the idea of MySpace &#8220;friends&#8221; and Facebook &#8220;friends&#8221;, a concept that seems to appeal mostly to teenagers seeking peer-approval. Friends are not objects you collect like others collect postal stamps or or sports memorabilia. Real friends are there for each other when we need someone. With my friends, years [...]]]></description>
			<content:encoded><![CDATA[<p>I never really got used to the idea of MySpace &#8220;friends&#8221; and Facebook &#8220;friends&#8221;, a concept that seems to appeal mostly to teenagers seeking peer-approval. Friends are not objects you collect like others collect postal stamps or or sports memorabilia. Real friends are there for each other when we need someone. With my friends, years may pass without us meeting, but when we see each other again we pick up just like we last saw each other only yesterday. I know them and they know me and we don&#8217;t have to explain much. I would never think of showing them off on a website like others show off their gold chains and SUV to boost their self image. This is not at all what friendship is about.</p>
<p>For over two years I&#8217;ve been receiving emails coaxing me to join a website called tagged.com, supposedly sent by people who consider me their &#8220;friend&#8221;, but who I invariably do not recognize. I suppose they have my email address in their address book because they probably reported Nigerian scams to me before (I collect several hundred reports per day, most of which get processed automatically), but I could not possibly have had a two way email exchange with more than a small fraction of them, let alone built a friendship.</p>
<p>Here is a typical example:</p>
<blockquote>
<p><tt>Firstname</tt> has added you as a friend on Tagged.</p>
<p>Is <tt>Firstname</tt> your friend?</p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Click here to unsubscribe from Tagged, P.O. Box 193152 San Francisco, CA 94119-3152
</p></blockquote>
<p><B>Invitation spam</b></p>
<p>The tagged.com mails are just one example of a category of what I consider invitation spam, because they server no real purpose other than getting me to join a website that I have no interest in joining. The supposed sender already has my address and can contact me any time if he has something to tell me and if we really were friends, chances are I would already have his email too.</p>
<p>What I find particularly annoying about the Tagged.com emails is how they try to pressure the recipient into clicking the &#8220;Yes&#8221; link by exploiting people&#8217;s considerate nature. Most of us don&#8217;t unnecessarily want to hurt other people&#8217;s feelings. Therefore this line gets really on my nerves:</p>
<blockquote><p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p></blockquote>
<p>Interestingly, the same annoying phrase (either including the colon, left bracket frowning negative smiley or a positive smiley) started appearing in several other invitation spams that don&#8217;t mention Tagged.com:</p>
<p>From imvu.com, August 2007:</p>
<blockquote><p>Hey Joewein,</p>
<p><tt>Firstname</tt> has added you as a friend on IMVU.</p>
<p>Is <tt>Firstname</tt> your friend?</p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</p></blockquote>
<p>From MyYearBook.com, November 2007:</p>
<blockquote><p><tt>Firstname</tt> has added you as a friend<br />
Is <tt>Firstname</tt> your friend? </p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> will think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  </p>
<p>Click Here to block all emails from myYearbook, 280 Union Square Dr., New Hope, PA 18938</p></blockquote>
<p>From Yaari.com, February 2008:</p>
<blockquote><p><tt>Firstname Lastname</tt> wants you to join Yaari! </p>
<p>Is <tt>Firstname</tt> your friend? </p>
<p>Yes, <tt>Firstname</tt> is my friend!      No, <tt>Firstname</tt> isn&#8217;t my friend. </p>
<p>Please respond or <tt>Firstname</tt> might think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  </p>
<p>Thanks,<br />
The Yaari Team </p>
<p>____<br />
You are receiving this message because someone you know registered for Yaari and listed you as a contact.<br />
If you prefer not to receive this email tell us here.<br />
If you have any concerns regarding the content of this message, please email abuse@yaari.com.<br />
Yaari LLC, 358 Angier Ave, Atlanta, GA 30312
</p></blockquote>
<p>To this day I am receiving a mix of Tagged.com, MyYearbook, Yaari and IMVU emails from various people.</p>
<p>The only party who really gets anything out of this type of (probably automated) email is the website owner. It actually doesn&#8217;t matter whether you click &#8220;Yes&#8221; or &#8220;No&#8221; on those spams, either way you&#8217;ll end up on a web form to provide personal details to join the site. </p>
<p>Many social networking sites ask for access to your Yahoo, Hotmail, Outlook or other address book when joining. They then send everyone in your address book invitations in your name. Thus the game continues as long as address books aren&#8217;t empty and at least some people click on either &#8220;Yes&#8221; or &#8220;No&#8221;.</p>
<p>When I receive such emails, I usually archive them to a folder in my mail cabinet that I named &#8220;Plaxo-Ringo&#8221; after the first two websites that spammed me like that in significant volume. I archive them for research purposes, but if you&#8217;re not a spam researcher like me you might as well delete them.</p>
<p>Just like on Facebook and MySpace I never act on &#8220;friend&#8221; invitations unless I have a genuine personal relationship with the sender, and neither should you. There is no need to feel guilty about discarding spam that is meant to sell commercial websites, even if it masquerades as something much more personal and precious, like friendship.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Groups spam &#8211; abuse reporting broken</title>
		<link>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/</link>
		<comments>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 10:09:06 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=214</guid>
		<description><![CDATA[You can tell that an anti-spam tool is becoming too effective when spammers start trying to work around it. 
Such is the case with Spam URL Blacklists (SURBLs), which list domains advertised via spam. Spamfilters will intercept emails that mention blacklisted domains used in clickable links. The spammers can use fake sender addresses and send [...]]]></description>
			<content:encoded><![CDATA[<p>You can tell that an anti-spam tool is becoming too effective when spammers start trying to work around it. </p>
<p>Such is the case with Spam URL Blacklists (SURBLs), which list domains advertised via spam. Spamfilters will intercept emails that mention blacklisted domains used in clickable links. The spammers can use fake sender addresses and send email from cracked hosts and cracked third party mail accounts, but they still get caught as soon as they mention their websites. This hurts spammers because they only make money when people go to their websites and hand over their credit card details to order fake Rolexes, pills, porn, etc.</p>
<p>To get around this, spammers have been using pages created at free webhosting services and other third party sites where content can be uploaded. The links only mention the free hosting site, which then redirects to the final spam site.</p>
<p>One service abused for this is Google Groups. Other services recently seen used are Google Docs, Microsoft Spaces Live and Geocities. In the case of Google Groups the spammers create mailing lists and upload a spam link to the home page of the new group. They never use the groups for their intended purpose, i.e. mailing lists. This effectively makes it impossible to report the abuse via Google&#8217;s abuse handling procedures: Any archived posting or uploaded document on the Google Groups service has an abuse reporting link, but the home page of the group itself does not! Obviously, Google never envisaged that spammers would create groups only to have one page of web content that can be advertised via spam.</p>
<p>Here is an example of a spam:</p>
<blockquote><p>Received: from host34.net215.omkc.ru (HELO host34.net215.omkc.ru) [217.25.215.34]<br />
  by <tt>mymailhost</tt> (mx077) with SMTP; 21 Jan 2009 04:21:47 +0100<br />
Message-ID: &lt;47940FC9.1016287@verizon.net&gt;<br />
Date: Mon, 21 Jan 2008 03:21:45 GMT<br />
From: arturo &lt;arturo.matthews1@verizon.net&gt;<br />
User-Agent: Thunderbird 2.0.0.19 (Windows/20081209)<br />
MIME-Version: 1.0<br />
To: <tt>mymailbox</tt><br />
Subject: Brighten Your Day<br />
Content-Type: text/plain; charset=ISO-8859-1; format=flowed<br />
Content-Transfer-Encoding: 7bit</p>
<p>After trying out tooth whitening system AT NO COST TO YOU you&#8217;ll realize that your smile is irresistably contagious! <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>http://groups.google.com/group/fkvrqzzzjckhj</p>
<p>(Add S+H)
</p></blockquote>
<p>The page advertises &#8220;Click Here &#8211; Free Credit Score &#038; Debt Help&#8221; which is a spam link using the domain <tt>white-teeth2009.com</tt> hosted on IP address 220.164.144.205 in China. It is listed on four sub-lists of SURBL (WS, OB, AB and JP). Its name servers are ns1.dckfdc.com and  ns2.dckfdc.com. Other domains by the same spammers are whiten-your-smile2009.com and smile-really-great.com.</p>
<p>At the very least Google should add an abuse reporting link to its Google Group pages. It would be even better if they were to check uploaded Google Group content and checked any URLs in it against spam blacklists such as SURBL. This would stop the spammers in their tracks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
