<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Joe Wein's blog &#187; spam</title>
	<atom:link href="http://www.joewein.net/blog/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.joewein.net/blog</link>
	<description>Comments from Yokohama, Japan</description>
	<lastBuildDate>Sun, 28 Feb 2010 00:11:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Haiti disaster attracts Nigerian scammers</title>
		<link>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/</link>
		<comments>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 06:05:07 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=643</guid>
		<description><![CDATA[It happened after the Indian ocean tsunami and after Hurricane Katrina. It&#8217;s happening again with the earthquake in Haiti that has killed tens of thousands and left hundreds of thousands injured, homeless, hungry or without medical treatment: Scammers in Nigeria and elsewhere are stealing money meant for victims of the disaster. 
If you think there [...]]]></description>
			<content:encoded><![CDATA[<p>It happened after the Indian ocean tsunami and after Hurricane Katrina. It&#8217;s happening again with the earthquake in Haiti that has killed tens of thousands and left hundreds of thousands injured, homeless, hungry or without medical treatment: Scammers in Nigeria and elsewhere are stealing money meant for victims of the disaster. </p>
<p>If you think there is a line that such scammers won&#8217;t cross, think again. </p>
<p>Here is an email soliciting donations on behalf of &#8220;HAITI CITIZENS LIVING IN THE UNITED KINGDOM&#8221; with relatives living in Haiti, but really originating from an IP address in Nigeria, West Africa:</p>
<blockquote><p>PASTOR JOHN BROMA<br />
HAITI CITIZENS IN UNITED KINGDOM<br />
23 BEN AVENUE S/W,LONDON<br />
UNITED KINGDOM</p>
<p>DEAR SIR/MADAM</p>
<p>WE ARE HAITI CITIZENS LIVING IN THE UNITED KINGDOM WHOM THEIR FAMILIES<br />
ARE AFFECTED BY THE RECENT EARTQUAKE,WE HAVE BEEN TRYING TO RAISE MONEY<br />
TO HELP THE HAITI CITIZENS WHO ARE WITHOUT FOODS,DRUG AND SHELTER,SO WE<br />
PLEAD THAT YOU SUPPORT US WITH WHAT EVER YOU CAN.</p>
<p>ALL DONATIONS SHOULD BE SEND THROUGH WESTERN UNION MONEY TRANSFER<br />
BECAUSE OF THE URGENT ATTENTION NEEDED.DO SEND IT TO THE INFORMATIONS BELOW.</p>
<p>PASTOR JOHN BROMA</p>
<p>HAITI CITIZENS IN UNITED KINGDOM<br />
23 BEN AVENUE S/W,LONDON<br />
UNITED KINGDOM</p>
<p>PLEASE MAKE SURE THAT YOU FORWARD THE WESTERN UNION INFORMATIONS SUCH AS<br />
SENDERS NAME,AMOUNT SEND AND THE MTCN.WE PRAY THAT ALMIGHTY GOD WILL<br />
BLESS AS YOU HELP THE SUFFERING HAITI CITIZEN.</p>
<p>THANKS FOR YOUR HELP</p>
<p>PASTOR JOHN BROMA(SECRETARY)</p>
</blockquote>
<p>Looking at the message headers we see:</p>
<blockquote><p>Received: from User ([82.128.33.35] RDNS failed) by mail.westnet.com<br />
with Microsoft SMTPSVC(6.0.3790.3959); Fri, 15 Jan 2010 19:13:32 +0900<br />
Reply-To: &lt;pastorjohnbroma@yahoo.com&gt;<br />
From: HIATI CITIZENS IN UNITED KINGDOM&lt;pastorjohnbroma@yahoo.com&gt;<br />
Subject: HELP FOR HAITI<br />
Date: Sat, 16 Jan 2010 11:21:10 -0800
</p></blockquote>
<p>IP address 82.128.33.35 belongs to a cell phone provider in Nigeria:</p>
<blockquote><p>inetnum:        82.128.32.0 &#8211; 82.128.63.255<br />
netname:        INET-MLTL<br />
descr:          CDMA 1x/EVDO Dial up pool<br />
country:        NG<br />
admin-c:        RIA27<br />
tech-c:         RIA27<br />
status:         ASSIGNED PA<br />
mnt-by:         MLTL-INT-MNT<br />
mnt-lower:      MLTL-INT-MNT<br />
source:         AFRINIC # Filtered<br />
parent:         82.128.0.0 &#8211; 82.128.127.255</p>
<p>person:       IP Admin-RIPE<br />
address:      Multilinks Telecommunications Limited<br />
address:      231 Adeola Odeku Str.<br />
address:      Victoria Island, Lagos, Nigeria
</p></blockquote>
<p>The criminal who sent this mail must be one of their customers.</p>
<p>If you want to make a donation to help those affected by the disaster, send it to the Red Cross or another well established relief organization. Beware of any stranger who asks you to wire money by Western Union or MoneyGram, because these instant wire transfer services are essentially anonymous and untraceable and there are no safeguards whatsoever against abuse by criminal recipients, who can not be traced. That is precisely why scammers prefer you to send money that way.</p>
<p>If hell exists there must be a special place there waiting for these scammers, who even make money out of the orphans and dying in Haiti.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/01/16/haiti-disaster-attracts-nigerian-scammers/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Broken link suggestion spam, a new twist on link exchange spam</title>
		<link>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/</link>
		<comments>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 07:48:39 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=634</guid>
		<description><![CDATA[Since Google ranks sites primarily by how many other pages and sites link to them, unethical people have been trying to boost their site rankings by tricking others into creating links to them. 
Link exchange spam, i.e. unsolicited offers to reciprocally create links to each other&#8217;s sites, has been around for many years. Recently I [...]]]></description>
			<content:encoded><![CDATA[<p>Since Google ranks sites primarily by how many other pages and sites link to them, unethical people have been trying to boost their site rankings by tricking others into creating links to them. </p>
<p>Link exchange spam, i.e. unsolicited offers to reciprocally create links to each other&#8217;s sites, has been around for many years. Recently I came across a new twist, broken link suggestion spam. You&#8217;ll receive a personal looking email like the following that tells you about a broken link on a page on one of your sites, with an suggestion for a replacement link target (boldface added by me):</p>
<blockquote><p><b>Hi</b> Joe!<br />
<b>Sorry to bother you, my name is</b> Kate Austen, <b>I&#8217;m a</b> teaching assistant for a sociology class. <b>I&#8217;ve been doing some research online for an</b> upcoming lesson on the urban legends, myths, and hoaxes, <b>and your page was very helpful. Thanks so much!</b></p>
<p><b>I noticed that on your page</b> (http://www.joewein.de/hoax.htm) <b>you have a broken link</b> http://www.urbanlegends.com/index.html <b>(an old page about</b> urban legends<b>)&#8230; May I offer a thought on a possible replacement?</b> http://www.costumesupercenter.com/csc_inc/html/static/btarticles/urbanlegendsandmyths.html <b>It has some great information about</b> several urban legends and myths. <b>I found it to be a great resource during my research, and it would be a great fix to your broken link. I&#8217;ve added it to my bookmarks, along with your site</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Just thought I&#8217;d let you know</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Take Care, </b><br />
Kate<br />
kate@professor-research.org</p></blockquote>
<p>I plugged some phrases from the above email into Google and it found the following similar email (boldface also added by me, please compare the two):</p>
<blockquote><p>Crystal Sawyer<br />
crystal@studentresearchers.org</p>
<p><b>Hi!<br />
Sorry to bother you, my name is</b> Crystal Sawyer, <b>I&#8217;m an</b> education major from upstate New York. <b>I&#8217;ve been doing some research online for a</b> class project <b>and your pages were very helpful. Thanks so much</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>I noticed that on your page</b> (http://www.apfn.org/apfn/mmm.htm) <b>you have a broken link</b> http://www.nara.gov/exhall/charters/declaration/decmain.html <b>(an old page about</b> science projects<b>)&#8230; May I offer a thought on a possible replacement?</b> http://legalmetro.com/library/historic-us-documents-the-charters-of-freedom.html <b>It has some great information about</b> teaching children how to do experimental science projects. <b>I found it to be a great resource during my research, and it would be a great fix to your broken link. I&#8217;ve added it to my bookmarks, along with your site</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Just thought I&#8217;d let you know</b> <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><b>Take Care,</b><br />
Crystal<br />
crystal@studentresearchers.org</p></blockquote>
<p>The number of identical phrases is far to high to be a coincidence. Looking at the sender domains professor-research.org and studentresearchers.org, the registrant on both is hidden behind the anonymization service domainsbyproxy.com. </p>
<p>I would say chances are good that both &#8220;Kate&#8221; and &#8220;Crystal&#8221; are the same person and that this person works for a company offering paid search engine optimization (SEO) services to boost their customers&#8217; website rankings. They add some editorial contents to the customer website and then deceptively ask owners of sites with a high Page rank (PR) to replace broken links with links to these new pages by posing as students and researchers with no obvious commercial interest in the link target site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2010/01/15/broken-link-suggestion-spam-a-new-twist-on-link-exchange-spam/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Dial +44 70 (UK number) for international online fraud</title>
		<link>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/</link>
		<comments>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/#comments</comments>
		<pubDate>Sun, 08 Nov 2009 03:28:47 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[419]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=480</guid>
		<description><![CDATA[A few years ago I created the Scam-O-Matic (www.scamomatic.com), a website that every month has helped thousands of people worldwide by automatically diagnosing online fraud emails that people have submitted to it. Scamomatic.com recognizes fake lotteries, &#8220;dead customer&#8221; scams, &#8220;dying widow&#8221; scams and many other common formats from scammers from Nigeria that you may have [...]]]></description>
			<content:encoded><![CDATA[<p>A few years ago I created the <a href="http://www.scamomatic.com">Scam-O-Matic</a> (<a href="http://www.scamomatic.com">www.scamomatic.com</a>), a website that every month has helped thousands of people worldwide by automatically diagnosing online fraud emails that people have submitted to it. Scamomatic.com recognizes fake lotteries, &#8220;dead customer&#8221; scams, &#8220;dying widow&#8221; scams and many other common formats from scammers from Nigeria that you may have seen in your inbox before. Even when it can&#8217;t pinpoint the exact type of scam, it often recognizes it as a generic scam format, largely thanks to the presence in the email of <b>UK phone numbers that start with +44 70</b>. These numbers are everywhere in Nigerian online scams, regardless of the precise scam format. The +44 70 prefix might as well be called the country code of Nigerian scammers.</p>
<p><strong>If you receive any email that mentions any +4470 phone number, do not reply to it! You can submit the body of any suspicious email message to</strong> <a href="http://www.scamomatic.com">www.scamomatic.com</a> <strong>for instant feedback about what kind of scam it might be.</strong></p>
<p>These +4470 numbers are a gift to online scammers by British phone regulators. They are primarily owned by obscure British phone companies offering an anonymous call forwarding service. The economic model of these services is simple: The caller dials a rather expensive UK number and the UK service provider forwards the incoming call to a somewhat less expensive to call international number (for example a Nigerian mobile phone, which remains hidden from the caller), pocketing the difference between the call rates. For example, the caller might pay 50 cents per minute to call a +44 70 number and the call will then be forwarded to a Nigerian mobile phone that costs 25 cents per minute, leaving 25 cents per minute as a net margin for the service operator. The more successful the scammers are, the more money the phone company makes. Who ever said crime doesn&#8217;t pay? </p>
<p>These UK phone numbers are very attractive to scammers: When people can be made to believe that they are dealing with a bank, lawyer or government official in London, UK when they&#8217;re actually talking to a scammer on his cell phone in an Internet cafe in Lagos, Nigeria then they are much more easily defrauded by criminals.</p>
<p>As far as I can tell these numbers aren&#8217;t really being used for any other purpose than to enable international online crimes to be committed. In some nine years of tracking Nigerian scam emails, I have yet to come across a single legitimate user of a +44 70 number. I really don&#8217;t understand why the British government has allowed those services to continue to operate.</p>
<p>Now, of course the service operators can claim that they don&#8217;t know that their services are being used for criminal purposes unless someone tells them about it. On the other hand, they are not exactly making it easy to report abuse and the high prices of these services means that it&#8217;s unlikely that they&#8217;ll get much legitimate use, if any.</p>
<p>There are several ways to curb abuse, other than suspending +44 70 numbers altogether and I would encourage the UK government to seriously consider them:</p>
<ul>
<li> The UK regulators could make it a requirement that calls via this service either originate in the UK or terminate in the UK, i.e. to prevent unrestricted global relaying, with say calls from India or the US being forwarded to Nigeria or C&ocirc;te d&#8217;Ivoire.</li>
<li> The UK regulators could require service providers to announce the country name of the phone number to which the call is being forwarded if the destination number is not a UK number.</li>
<li> The UK regulators could require service providers to block forwarding to mobile phone numbers in certain countries, e.g. Nigeria</li>
</ul>
<p>Below is a sample list of +44 70 numbers that appeared in Nigerian scams reported to Scam-O-Matic over the course of the last seven days. These roughly 60 phone numbers per day are only the tip of the iceberg:</p>
<blockquote><p>+447005801505<br />
+447005802020<br />
+447005810692<br />
+447005934945<br />
+447005942459<br />
+447005963237<br />
+447005977097<br />
+447006001100<br />
+447006002121<br />
+447006002413<br />
+447006029116<br />
+447006062478<br />
+447010023307<br />
+447010027439<br />
+447010027978<br />
+447010027983<br />
+447010028455<br />
+447010030769<br />
+447010285923<br />
+447010306559<br />
+447010476294<br />
+447010786457<br />
+447011120379<br />
+447011120510<br />
+447011120524<br />
+447011121450<br />
+447011121596<br />
+447011128170<br />
+447011129280<br />
+447011129286<br />
+447011129446<br />
+447011130062<br />
+447011130670<br />
+447011130769<br />
+447011131077<br />
+447011131152<br />
+447011133259<br />
+447011140499<br />
+447011140945<br />
+447011140989<br />
+447011146747<br />
+447011146830<br />
+447011147295<br />
+447011149054<br />
+447011152991<br />
+447011153129<br />
+447011162749<br />
+447011163186<br />
+447011163846<br />
+447011164243<br />
+447011182522<br />
+447011183455<br />
+447011184113<br />
+447011196412<br />
+447011197245<br />
+447011197787<br />
+447014225697<br />
+447014232391<br />
+447014232411<br />
+447014232442<br />
+447014236733<br />
+447014244984<br />
+447014275175<br />
+447014275728<br />
+447017026507<br />
+447017430128<br />
+447017769494<br />
+447017848035<br />
+447023011587<br />
+447023056559<br />
+447023058575<br />
+447023069806<br />
+447023086665<br />
+447023087509<br />
+447023092593<br />
+447024010876<br />
+447024010915<br />
+447024011554<br />
+447024012660<br />
+447024013770<br />
+447024014859<br />
+447024016712<br />
+447024017968<br />
+447024018504<br />
+447024018707<br />
+447024018725<br />
+447024018963<br />
+447024019584<br />
+447024019588<br />
+447024021204<br />
+447024021389<br />
+447024023138<br />
+447024023643<br />
+447024024530<br />
+447024024914<br />
+447024024938<br />
+447024025942<br />
+447024028606<br />
+447024029852<br />
+447024032255<br />
+447024033542<br />
+447024034362<br />
+447024034768<br />
+447024035958<br />
+447024036606<br />
+447024037907<br />
+447024038051<br />
+447024038950<br />
+447024041571<br />
+447024041989<br />
+447024042397<br />
+447024043571<br />
+447024045842<br />
+447024046548<br />
+447024047607<br />
+447024047708<br />
+447024051081<br />
+447024051604<br />
+447024053655<br />
+447024054764<br />
+447024056650<br />
+447024056684<br />
+447024057656<br />
+447024057695<br />
+447024059725<br />
+447024061362<br />
+447024061659<br />
+447024061805<br />
+447024062162<br />
+447024063633<br />
+447024063645<br />
+447024064180<br />
+447024065549<br />
+447024066713<br />
+447024066858<br />
+447024067752<br />
+447024068617<br />
+447024069933<br />
+447024070671<br />
+447024071597<br />
+447024071804<br />
+447024071867<br />
+447024072603<br />
+447024072995<br />
+447024073988<br />
+447024074220<br />
+447024074568<br />
+447024074742<br />
+447024075722<br />
+447024075954<br />
+447024077025<br />
+447024078351<br />
+447024079530<br />
+447024079908<br />
+447024080526<br />
+447024080571<br />
+447024080634<br />
+447024082668<br />
+447024082680<br />
+447024082728<br />
+447024083093<br />
+447024083705<br />
+447024084762<br />
+447024084918<br />
+447024084994<br />
+447024086967<br />
+447024087401<br />
+447024087599<br />
+447024087905<br />
+447024091678<br />
+447024091701<br />
+447024091706<br />
+447024092775<br />
+447024092795<br />
+447024092863<br />
+447024095774<br />
+447024095778<br />
+447024095878<br />
+447024096802<br />
+447024096869<br />
+447024097854<br />
+447024098802<br />
+447024098874<br />
+447024099606<br />
+447031740924<br />
+447031742574<br />
+447031744227<br />
+447031744980<br />
+447031744994<br />
+447031745967<br />
+447031746067<br />
+447031746887<br />
+447031747046<br />
+447031747509<br />
+447031749721<br />
+447031801246<br />
+447031801866<br />
+447031803498<br />
+447031803820<br />
+447031808512<br />
+447031809778<br />
+447031814575<br />
+447031814720<br />
+447031815436<br />
+447031816735<br />
+447031818230<br />
+447031821851<br />
+447031822608<br />
+447031823431<br />
+447031824330<br />
+447031825003<br />
+447031826670<br />
+447031830878<br />
+447031833248<br />
+447031833760<br />
+447031834660<br />
+447031835615<br />
+447031835762<br />
+447031837227<br />
+447031843396<br />
+447031844360<br />
+447031845639<br />
+447031846542<br />
+447031850801<br />
+447031851126<br />
+447031855107<br />
+447031855527<br />
+447031858919<br />
+447031859268<br />
+447031859327<br />
+447031859972<br />
+447031861174<br />
+447031861534<br />
+447031865718<br />
+447031877392<br />
+447031877975<br />
+447031880502<br />
+447031885537<br />
+447031890014<br />
+447031891762<br />
+447031894541<br />
+447031898197<br />
+447031903871<br />
+447031906765<br />
+447031908701<br />
+447031909751<br />
+447031911974<br />
+447031913322<br />
+447031915331<br />
+447031918554<br />
+447031918592<br />
+447031918698<br />
+447031918840<br />
+447031920863<br />
+447031928723<br />
+447031930960<br />
+447031931805<br />
+447031934581<br />
+447031938867<br />
+447031940670<br />
+4470319419882<br />
+447031943771<br />
+447031954666<br />
+447031956661<br />
+447031958680<br />
+447031960513<br />
+447031964131<br />
+447031971731<br />
+447031971766<br />
+447031972833<br />
+447031972850<br />
+447031973785<br />
+447031974969<br />
+447031978795<br />
+447031979858<br />
+447031982694<br />
+447031983660<br />
+447031983882<br />
+447031984862<br />
+447031988864<br />
+447031993596<br />
+447031993967<br />
+447031996818<br />
+447032334576<br />
+447035900183<br />
+447035900344<br />
+447035900914<br />
+447035901588<br />
+447035902188<br />
+447035902683<br />
+447035910276<br />
+447035911140<br />
+447035912873<br />
+447035913994<br />
+447035915768<br />
+447035922616<br />
+447035923742<br />
+447035924448<br />
+447035927916<br />
+447035928180<br />
+447035931142<br />
+447035937446<br />
+447035939194<br />
+447035939320<br />
+447035940617<br />
+447035944729<br />
+447035944779<br />
+447035947431<br />
+447035950853<br />
+447035951254<br />
+447035951405<br />
+447035954295<br />
+447035955376<br />
+447035956312<br />
+447035959966<br />
+447035960942<br />
+447035965038<br />
+447035966176<br />
+447035966188<br />
+447035966289<br />
+447035966480<br />
+447035968588<br />
+447035969249<br />
+447035969496<br />
+447035969754<br />
+447035969801<br />
+447035969823<br />
+447035972572<br />
+447035973164<br />
+447035973821<br />
+447035977317<br />
+447035978042<br />
+447035978343<br />
+447035978550<br />
+447035983963<br />
+447035988651<br />
+447035988847<br />
+447035989086<br />
+447035992118<br />
+447035996148<br />
+447035997215<br />
+447035997533<br />
+447035998886<br />
+447035999080<br />
+447040110515<br />
+447041743214<br />
+447045702581<br />
+447045704323<br />
+447045704570<br />
+447045705126<br />
+447045705374<br />
+447045706975<br />
+447045707234<br />
+447045707660<br />
+447045708253<br />
+447045709129<br />
+447045709292<br />
+447045710531<br />
+447045710917<br />
+447045711325<br />
+447045712243<br />
+447045712434<br />
+447045712662<br />
+447045712816<br />
+447045712993<br />
+447045713815<br />
+447045714219<br />
+447045719541<br />
+447045720546<br />
+447045721125<br />
+447045721617<br />
+447045722125<br />
+447045724094<br />
+447045725176<br />
+447045727388<br />
+447045729804<br />
+447045733035<br />
+447045733518<br />
+447045736862<br />
+447045742669<br />
+447045743467<br />
+447045747569<br />
+447045748609<br />
+447045754338<br />
+447045759317<br />
+447045767521<br />
+447045768060<br />
+447045770961<br />
+447045776356<br />
+447045780693<br />
+447045782120<br />
+447045783777<br />
+447045785147<br />
+447045785239<br />
+447045790181<br />
+447045791709<br />
+447045795051<br />
+447045798638<br />
+447045799030<br />
+447053491702<br />
+447053492393<br />
+447075158182<br />
+447092849621<br />
+447092861761<br />
+447092864823<br />
+447092980578<br />
+447092981646<br />
+447092981769<br />
+447092982175
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/11/08/dial-44-70-uk-numbers-for-international-fraudsters/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
		</item>
		<item>
		<title>Domain appraisal scam</title>
		<link>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/</link>
		<comments>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 08:24:57 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=361</guid>
		<description><![CDATA[Be careful if you receive an email like the following:
We are interested to buy your domain name YOUR-DOMAIN-HERE and offer to buy it from you for 80% of the appraised market value.
As of now we accept appraisals from either one of the following leading appraisal companies:
- fleos.com
- sedo.com
If you already have an appraisal please forward [...]]]></description>
			<content:encoded><![CDATA[<p>Be careful if you receive an email like the following:</p>
<blockquote><p>We are interested to buy your domain name <em>YOUR-DOMAIN-HERE</em> and offer to buy it from you for 80% of the appraised market value.</p>
<p>As of now we accept appraisals from either one of the following leading appraisal companies:</p>
<p>- fleos.com<br />
- sedo.com</p>
<p>If you already have an appraisal please forward it to us.</p>
<p>As soon as we have received your appraisal we will send you our payment (we use paypal for amounts less than $2,000 and escrow for amounts above $2,000) as well as<br />
further instructions on how to complete the transfer of the domain name.</p>
<p>We appreciate your business,</p>
<p>Yours truly,</p>
<p>Mark Evans</p></blockquote>
<p>The offered percentage or the alias of the sender may be different. The list of appraisal companies may vary too and the catch is in the requested appraisal: Whereas sedo.com is a well established company dealing in domain resale and appraisal, domains fleos.com, flyrating.com and others are new:</p>
<blockquote><p>Domain Name: FLEOS.COM<br />
Registrar: WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC<br />
Whois Server: whois.webnic.cc<br />
Referral URL: http://www.webnic.cc<br />
Name Server: NS1.EZYDOMAIN.COM<br />
Name Server: NS2.EZYDOMAIN.COM<br />
Status: clientDeleteProhibited<br />
Status: clientTransferProhibited<br />
Status: clientUpdateProhibited<br />
Updated Date: 04-jul-2009<br />
Creation Date: 04-jul-2009<br />
Expiration Date: 04-jul-2010</p>
<p>Registrant Contact:<br />
        Modern Outlook Sdn Bhd<br />
        Modern Outlook Sdn Bhd  (reg_460127@whoisprotection.cc)<br />
        Lot 13-01A, Level 13 (East Wing) Berjaya Times Square, No.1, Jalan Imbi<br />
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 55100<br />
        P: +603.21491999         F: +603.21431685
</p></blockquote>
<p>This one was used earlier than in the above sample:</p>
<blockquote><p>Domain Name: FLYRATING.COM<br />
Registrar: WEB COMMERCE COMMUNICATIONS LIMITED DBA WEBNIC.CC<br />
Whois Server: whois.webnic.cc<br />
Referral URL: http://www.webnic.cc<br />
Name Server: NS1.EZYDOMAIN.COM<br />
Name Server: NS2.EZYDOMAIN.COM<br />
Status: clientDeleteProhibited<br />
Status: clientTransferProhibited<br />
Status: clientUpdateProhibited<br />
Updated Date: 26-may-2009<br />
Creation Date: 26-may-2009<br />
Expiration Date: 26-may-2010</p>
<p>Registrant Contact:<br />
        Modern Outlook Sdn Bhd<br />
        Modern Outlook Sdn Bhd  (reg_449229@whoisprotection.cc)<br />
        Lot 13-01A, Level 13 (East Wing) Berjaya Times Square, No.1, Jalan Imbi<br />
        Kuala Lumpur, Wilayah Persekutuan, Malaysia 55100<br />
        P: +603.21491999         F: +603.21431685
</p></blockquote>
<p>Notice how they&#8217;re both registered via the same registrar. If anyone checks out the fees they&#8217;ll find that not coincidentally these no-names charge less than Sedo.com for their service, so they might easily get picked by domain owners hoping to make quick cash. </p>
<p>Your guess is as good as mine who sends out those buy offer spams that drive business to those cookie cutter domain appraisal firms, who take $22.95 from anyone falling for this scam.</p>
<p><strong>Unless you enjoy getting scammed, avoid any domain purchase offer in which the would be buyer does not come up with an offer price on his own but asks you to get an appraisal from a third party and promises to pay you a percentage of the appraised value!</strong></p>
<p>Other &#8220;appraisal company&#8221; domains used:</p>
<ul>
<li> nameorange.com </li>
<li> pedma.com </li>
<li> pozde.com </li>
<li> podzz.com </li>
<li> domainexplorer.org </li>
<li> pddomains.com </li>
</ul>
<p>See also:</p>
<ul>
<li> <a href="http://www.dynamoo.com/blog/2009/03/pedmacom-domain-appraisals.html">pedma.com domain appraisals? (dynamoo&#8217;s blog)</a></li>
<li> <a href="http://www.dynamoo.com/blog/2009/07/piradiusnet-yohostorg-black-hat-hosting.html">Piradius.net / Yohost.org &#8211; black hat hosting? (dynamoo&#8217;s blog)</a></li>
</ul>
<p><em>Last updated: 2009-08-10</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/07/30/domain-appraisal-scam/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>&#8220;&#8230;, has added you as a friend on SiliconIndia&#8221; scam emails</title>
		<link>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/</link>
		<comments>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 02:58:39 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=353</guid>
		<description><![CDATA[Over the past year I&#8217;ve been getting a steady trickle of &#8220;friend requests&#8221;, i.e. invitations to join a service, for a website called SiliconIndia. Virtually all the supposed senders were women from India. Job titles included Software Engineer, Business Analyst and HR Executive. Most were very pretty. By that I mean not just better than [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past year I&#8217;ve been getting a steady trickle of &#8220;friend requests&#8221;, i.e. invitations to join a service, for a website called SiliconIndia. Virtually all the supposed senders were women from India. Job titles included Software Engineer, Business Analyst and HR Executive. Most were very pretty. By that I mean not just better than average looking, more like the portfolio of a modeling agency.</p>
<p>Because of my volunteer work against online scams, some email accounts of mine end up in address books of thousands of people who over time have forwarded me samples of questionable mails. Consequently, I also receive a lot of requests to join online networking and other websites, many of which make it too easy to invite everyone in your address book to join a particular service when you join. One mail folder that I keep exclusively for such invitations from people I don&#8217;t recognize currently contains over 1,100 examples. </p>
<p>When I received another SiliconIndia invitation yesterday, I decided to take a closer look and a very interesting picture evolved. I had 42 invitations going back to February 2008. Nine of them (originating with three indivuals) did not include a photograph and almost all of those were from the first month. They may have been real invitations. The interesting thing about the other 33 invitations was that the senders were all female. Not one guy! 23 of these were sent from Gmail accounts and 10 from AOL or AIM accounts. One picture I received from both a Gmail and an AOL account. It wasn&#8217;t just that these emails had AOL or Gmail sender addresses, they also did not come from a SiliconIndia mail server as one might expect for regular &#8220;tell a friend&#8221; invitations. All were sent from regular personal Gmail and AOL accounts through the respective mail servers. </p>
<p>What this tells me is that someone is manually making up invitation mails, using pictures of pretty women to attract mostly male job seekers to join that service. And somebody somewhere is making money out of people who respond.</p>
<p>Out of curiosity I joined the service under an assumed identity. The profile for the person who had invited me the day before had a list of 456 &#8220;friends&#8221;. If she were to &#8220;stay in touch&#8221; with all of them as it said in the invitation, she&#8217;d be a pretty busy lady. So next time you get an invitation to join SiliconIndia to connect with some pretty woman, don&#8217;t delude yourself. Most likely some guy somewhere is being paid a few rupees to mail pictures of pretty girls to thousands of guys in order to drive traffic to a commercial website.</p>
<p><center><img src="/img/siliconindia-invitation.png"></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/06/20/has-added-you-as-a-friend-on-siliconindia-scam-emails/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>The &#8220;new shopping new life&#8221; spam</title>
		<link>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/</link>
		<comments>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 23:32:23 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=257</guid>
		<description><![CDATA[For about a year I have been receiving spam emails like this one below. They all look like they&#8217;ve been sent by private individuals somewhere in the world (usually from Yahoo or Hotmail accounts) but advertise companies in China:
hi:
New shopping new life!
  How are u doing these days?Yesterday I found a web of a [...]]]></description>
			<content:encoded><![CDATA[<p>For about a year I have been receiving spam emails like this one below. They all look like they&#8217;ve been sent by private individuals somewhere in the world (usually from Yahoo or Hotmail accounts) but advertise companies in China:</p>
<blockquote><p>hi:<br />
New shopping new life!<br />
  How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.<br />
Look forward to your early reply!<br />
The Web address: www.vanigo.com<br />
E-mail: vanigo@188.com<br />
MSN : vanigo@msn.cn </p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Få en billig laptop. Se Kelkoos gode tilbud her!
</p></blockquote>
<p>Looking at the mail headers, it had come from the mail account of a Danish Yahoo user, but originated from an IP address in China (details edited to protect the privacy of the account owner):</p>
<blockquote><p>Received: from [<b>124.118.179.157</b>] by web26101.mail.ukl.yahoo.com<br />
 via HTTP; Wed, 11 Feb 2009 19:54:29 GMT<br />
X-Mailer: YahooMailWebService/0.7.260.1<br />
Date: Wed, 11 Feb 2009 19:54:29 +0000 (GMT)<br />
From: uffe #####sen &lt;uf###2@yahoo.dk&gt;<br />
Reply-To: uf###2@yahoo.dk<br />
Subject: hi:<br />
To: undisclosed recipients: ;
</p></blockquote>
<p>IP address 124.118.179.157 belongs to China Telecom:</p>
<blockquote><p>inetnum:      124.118.0.0 &#8211; 124.119.255.255<br />
netname:      CHINANET-XJ<br />
descr:        CHINANET Xinjiang province network<br />
descr:        China Telecom<br />
descr:        No1,jin-rong Street<br />
descr:        Beijing 100032<br />
country:      CN</p></blockquote>
<p>What appears to have happened is that spammers know the passwords to these mail accounts and are using them to send that spam to everyone in the mail account&#8217;s address book. </p>
<p>This is a very effective way to get through spam filters, as many recipients are likely to also have the sender in their address book and address book entries are automatically whitelisted by many spamfilters.</p>
<p>If you receive an email like that, alert the &#8220;sender&#8221; that their account has been compromised. They need to immediately change their email password to something more secure. </p>
<p>This abuse of stolen passwords illustrates the potential of password harvesting scams such as <a href="http://www.joewein.net/blog/2008/08/11/flapstatecom-mdanclubcom-wayizercom/">this one</a> I documented in August 2008, which is still going on.</p>
<p>Here are some Google searches related to the hacked webmail spam:</p>
<ul>
<li><a href="http://www.google.com/search?q=%22New+shopping+new+life%22">&#8220;New shopping new life&#8221;</a></li>
<li><a href="http://www.google.com/search?q=%22good+company+who+trades+mainly+in+electornic+products%22">&#8220;good company who trades mainly in electornic products&#8221;</a></li>
</ul>
<p>Here is a (probably incomplete) list of websites advertised this way:</p>
<ul>
<li>gvccn.com</li>
<li>ibvcn.com</li>
<li>jvccn.com</li>
<li>tvtcn.com</li>
<li>szfac.com</li>
<li>cxkeg.com</li>
<li>yaier.com</li>
<li>mmhdf.com</li>
<li>ixicb.com</li>
<li>vanigo.com</li>
<li>wabada.com</li>
<li>bj-trade.com</li>
<li>store-168.com</li>
<li>ele-motors.com</li>
<li>electronics-brand.com</li>
<li>exciting-zone.com</li>
</ul>
<p>Common subject lines:</p>
<ul>
<li>New shopping new life</li>
<li>Good shopping good mood!</li>
<li>Good web site</li>
<li>Have a great shopping!</li>
<li>good website!</li>
<li>Hi,Thank you!</li>
<li>Hi,</li>
<li>Dear friend</li>
</ul>
<p><b>Good passwords and bad passwords</b></p>
<p>A strong password should be the first line of defense against such criminals, but what makes a password good? It should contain a mixture of all of the following: </p>
<ul>
<li>lower case letters</li>
<li>upper case letters</li>
<li>digits</li>
<li>at least one non-alphanumeric character</li>
</ul>
<p>This makes it hard to break the password through brute force or through dictionary attacks. </p>
<p>Also the password should not be too short (8 characters or more) and should be reasonably easy to memorize, so you don&#8217;t have much need to write it down. Some examples:</p>
<ul>
<li>45Knife%Cabbage</li>
<li>4F5g6H&#038;j</li>
<li>J0hn1945-07-31</li>
</ul>
<p>Bad choices are passwords that consists of any word found in a dictionary, proper names, digits-only dates, adjacent keys on the keyboard or repeated characters. Never use anything like these:</p>
<ul>
<li>secret</li>
<li>qwerty</li>
<li>xxxx</li>
<li>john45</li>
</ul>
<p>It is <b>very important</b> not to use the exact same password for different purposes. </p>
<p>If spammers manage to trick you into revealing your password for one site (e.g. by getting you to create a new account at a site they control or by breaking into the database of another site where you&#8217;re a customer) then you&#8217;ve effectively handed them the key to the candy store. They can get access to your email account, in which they may find login information, password reminders, etc. of many other sites you&#8217;ve signed up for. At the very least they can harvest all your email contacts.</p>
<p>Beyond using different passwords for every site and service, it&#8217;s also a good idea to use a different password schema for &#8220;core&#8221; sites that you trust and depend upon (such as your email provider and webhost) and another for sites to which you sign up more casually (such as various forums, online shopping, etc.). Thus if one of the latter is compromised, it does not give criminals any clues what your more critical passwords may look like.</p>
<p><b>Who is behind this spam?</b></p>
<p>The sites advertised from the hacked email accounts constantly vary. They usually have been created only a few weeks or months earlier. For example, the domain in the above example was created two months ago:</p>
<blockquote><p>Domain name: vanigo.com</p>
<p>Registrant Contact:<br />
   wuxianj<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Administrative Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Technical Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>Billing Contact:<br />
   xiaos wu zhongfm@it5.cn<br />
   0592-5861837 fax: 0592-5861834<br />
   beijin<br />
   beijin beijin 100000<br />
   cn</p>
<p>DNS:<br />
ns1.4everdns.com<br />
ns2.4everdns.com</p>
<p>Created: 2008-12-08<br />
Expires: 2009-12-08
</p></blockquote>
<p>Considering the highly illegal way the companies advertised, what are the chances that any order you make at those sites would ever get shipped to you? For sure, they will gladly take your cash by (untraceable, unsafe) Western Union or take your credit card number, expiration date and security code. Never use Western Union to send money to people you don&#8217;t know from real life in person. Never enter your credit card on a site that doesn&#8217;t have SSL access (indicated by a URL starting with https:// and a padlock icon in the browser status bar) with a proper certificate.</p>
<p>Even more basic: Never do business with spammers. By sending you spam, they have already proven to you that they lack any morals. You have no reason to trust them and every reason to be alert!</p>
<p>If you have received similar spams, feel free to post them below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/02/12/the-new-shopping-new-life-spam/feed/</wfw:commentRss>
		<slash:comments>70</slash:comments>
		</item>
		<item>
		<title>&#8220;Please respond or Some Stranger will think you said no :(&#8220;</title>
		<link>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/</link>
		<comments>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 09:35:10 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=246</guid>
		<description><![CDATA[I never really got used to the idea of MySpace &#8220;friends&#8221; and Facebook &#8220;friends&#8221;, a concept that seems to appeal mostly to teenagers seeking peer-approval. Friends are not objects you collect like others collect postal stamps or or sports memorabilia. Real friends are there for each other when we need someone. With my friends, years [...]]]></description>
			<content:encoded><![CDATA[<p>I never really got used to the idea of MySpace &#8220;friends&#8221; and Facebook &#8220;friends&#8221;, a concept that seems to appeal mostly to teenagers seeking peer-approval. Friends are not objects you collect like others collect postal stamps or or sports memorabilia. Real friends are there for each other when we need someone. With my friends, years may pass without us meeting, but when we see each other again we pick up just like we last saw each other only yesterday. I know them and they know me and we don&#8217;t have to explain much. I would never think of showing them off on a website like others show off their gold chains and SUV to boost their self image. This is not at all what friendship is about.</p>
<p>For over two years I&#8217;ve been receiving emails coaxing me to join a website called tagged.com, supposedly sent by people who consider me their &#8220;friend&#8221;, but who I invariably do not recognize. I suppose they have my email address in their address book because they probably reported Nigerian scams to me before (I collect several hundred reports per day, most of which get processed automatically), but I could not possibly have had a two way email exchange with more than a small fraction of them, let alone built a friendship.</p>
<p>Here is a typical example:</p>
<blockquote>
<p><tt>Firstname</tt> has added you as a friend on Tagged.</p>
<p>Is <tt>Firstname</tt> your friend?</p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p>Click here to unsubscribe from Tagged, P.O. Box 193152 San Francisco, CA 94119-3152
</p></blockquote>
<p><B>Invitation spam</b></p>
<p>The tagged.com mails are just one example of a category of what I consider invitation spam, because they server no real purpose other than getting me to join a website that I have no interest in joining. The supposed sender already has my address and can contact me any time if he has something to tell me and if we really were friends, chances are I would already have his email too.</p>
<p>What I find particularly annoying about the Tagged.com emails is how they try to pressure the recipient into clicking the &#8220;Yes&#8221; link by exploiting people&#8217;s considerate nature. Most of us don&#8217;t unnecessarily want to hurt other people&#8217;s feelings. Therefore this line gets really on my nerves:</p>
<blockquote><p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p></blockquote>
<p>Interestingly, the same annoying phrase (either including the colon, left bracket frowning negative smiley or a positive smiley) started appearing in several other invitation spams that don&#8217;t mention Tagged.com:</p>
<p>From imvu.com, August 2007:</p>
<blockquote><p>Hey Joewein,</p>
<p><tt>Firstname</tt> has added you as a friend on IMVU.</p>
<p>Is <tt>Firstname</tt> your friend?</p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> may think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</p></blockquote>
<p>From MyYearBook.com, November 2007:</p>
<blockquote><p><tt>Firstname</tt> has added you as a friend<br />
Is <tt>Firstname</tt> your friend? </p>
<p>[ Yes]    [ No ]</p>
<p>Please respond or <tt>Firstname</tt> will think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  </p>
<p>Click Here to block all emails from myYearbook, 280 Union Square Dr., New Hope, PA 18938</p></blockquote>
<p>From Yaari.com, February 2008:</p>
<blockquote><p><tt>Firstname Lastname</tt> wants you to join Yaari! </p>
<p>Is <tt>Firstname</tt> your friend? </p>
<p>Yes, <tt>Firstname</tt> is my friend!      No, <tt>Firstname</tt> isn&#8217;t my friend. </p>
<p>Please respond or <tt>Firstname</tt> might think you said no <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  </p>
<p>Thanks,<br />
The Yaari Team </p>
<p>____<br />
You are receiving this message because someone you know registered for Yaari and listed you as a contact.<br />
If you prefer not to receive this email tell us here.<br />
If you have any concerns regarding the content of this message, please email abuse@yaari.com.<br />
Yaari LLC, 358 Angier Ave, Atlanta, GA 30312
</p></blockquote>
<p>To this day I am receiving a mix of Tagged.com, MyYearbook, Yaari and IMVU emails from various people.</p>
<p>The only party who really gets anything out of this type of (probably automated) email is the website owner. It actually doesn&#8217;t matter whether you click &#8220;Yes&#8221; or &#8220;No&#8221; on those spams, either way you&#8217;ll end up on a web form to provide personal details to join the site. </p>
<p>Many social networking sites ask for access to your Yahoo, Hotmail, Outlook or other address book when joining. They then send everyone in your address book invitations in your name. Thus the game continues as long as address books aren&#8217;t empty and at least some people click on either &#8220;Yes&#8221; or &#8220;No&#8221;.</p>
<p>When I receive such emails, I usually archive them to a folder in my mail cabinet that I named &#8220;Plaxo-Ringo&#8221; after the first two websites that spammed me like that in significant volume. I archive them for research purposes, but if you&#8217;re not a spam researcher like me you might as well delete them.</p>
<p>Just like on Facebook and MySpace I never act on &#8220;friend&#8221; invitations unless I have a genuine personal relationship with the sender, and neither should you. There is no need to feel guilty about discarding spam that is meant to sell commercial websites, even if it masquerades as something much more personal and precious, like friendship.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/02/03/please-respond-or-some-stranger-will-think-you-said-no/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Groups spam &#8211; abuse reporting broken</title>
		<link>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/</link>
		<comments>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/#comments</comments>
		<pubDate>Wed, 21 Jan 2009 10:09:06 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=214</guid>
		<description><![CDATA[You can tell that an anti-spam tool is becoming too effective when spammers start trying to work around it. 
Such is the case with Spam URL Blacklists (SURBLs), which list domains advertised via spam. Spamfilters will intercept emails that mention blacklisted domains used in clickable links. The spammers can use fake sender addresses and send [...]]]></description>
			<content:encoded><![CDATA[<p>You can tell that an anti-spam tool is becoming too effective when spammers start trying to work around it. </p>
<p>Such is the case with Spam URL Blacklists (SURBLs), which list domains advertised via spam. Spamfilters will intercept emails that mention blacklisted domains used in clickable links. The spammers can use fake sender addresses and send email from cracked hosts and cracked third party mail accounts, but they still get caught as soon as they mention their websites. This hurts spammers because they only make money when people go to their websites and hand over their credit card details to order fake Rolexes, pills, porn, etc.</p>
<p>To get around this, spammers have been using pages created at free webhosting services and other third party sites where content can be uploaded. The links only mention the free hosting site, which then redirects to the final spam site.</p>
<p>One service abused for this is Google Groups. Other services recently seen used are Google Docs, Microsoft Spaces Live and Geocities. In the case of Google Groups the spammers create mailing lists and upload a spam link to the home page of the new group. They never use the groups for their intended purpose, i.e. mailing lists. This effectively makes it impossible to report the abuse via Google&#8217;s abuse handling procedures: Any archived posting or uploaded document on the Google Groups service has an abuse reporting link, but the home page of the group itself does not! Obviously, Google never envisaged that spammers would create groups only to have one page of web content that can be advertised via spam.</p>
<p>Here is an example of a spam:</p>
<blockquote><p>Received: from host34.net215.omkc.ru (HELO host34.net215.omkc.ru) [217.25.215.34]<br />
  by <tt>mymailhost</tt> (mx077) with SMTP; 21 Jan 2009 04:21:47 +0100<br />
Message-ID: &lt;47940FC9.1016287@verizon.net&gt;<br />
Date: Mon, 21 Jan 2008 03:21:45 GMT<br />
From: arturo &lt;arturo.matthews1@verizon.net&gt;<br />
User-Agent: Thunderbird 2.0.0.19 (Windows/20081209)<br />
MIME-Version: 1.0<br />
To: <tt>mymailbox</tt><br />
Subject: Brighten Your Day<br />
Content-Type: text/plain; charset=ISO-8859-1; format=flowed<br />
Content-Transfer-Encoding: 7bit</p>
<p>After trying out tooth whitening system AT NO COST TO YOU you&#8217;ll realize that your smile is irresistably contagious! <img src='http://www.joewein.net/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>http://groups.google.com/group/fkvrqzzzjckhj</p>
<p>(Add S+H)
</p></blockquote>
<p>The page advertises &#8220;Click Here &#8211; Free Credit Score &#038; Debt Help&#8221; which is a spam link using the domain <tt>white-teeth2009.com</tt> hosted on IP address 220.164.144.205 in China. It is listed on four sub-lists of SURBL (WS, OB, AB and JP). Its name servers are ns1.dckfdc.com and  ns2.dckfdc.com. Other domains by the same spammers are whiten-your-smile2009.com and smile-really-great.com.</p>
<p>At the very least Google should add an abuse reporting link to its Google Group pages. It would be even better if they were to check uploaded Google Group content and checked any URLs in it against spam blacklists such as SURBL. This would stop the spammers in their tracks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2009/01/21/google-groups-spam-abuse-reporting-broken/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Domain registration scam in China</title>
		<link>http://www.joewein.net/blog/2008/12/08/domain-registration-scam-in-china/</link>
		<comments>http://www.joewein.net/blog/2008/12/08/domain-registration-scam-in-china/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 06:39:35 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=169</guid>
		<description><![CDATA[Various companies in China are trying to scare domain owners in other countries into registering Chinese variants of their domain names by claiming some other party was trying to register these variants. Examples of this scam have been reported widely throughout 2008, involving the domains asiaton.cn, erimut.com, erimart.com, erimart-domains.com.cn, hknsc.hk, hongkongnet.org, hk-net.org.cn, hknetwork.hk.cn and others [...]]]></description>
			<content:encoded><![CDATA[<p>Various companies in China are trying to scare domain owners in other countries into registering Chinese variants of their domain names by claiming some other party was trying to register these variants. Examples of this scam have been reported widely throughout 2008, involving the domains asiaton.cn, erimut.com, erimart.com, erimart-domains.com.cn, hknsc.hk, hongkongnet.org, hk-net.org.cn, hknetwork.hk.cn and others (erimut.com, erimart.com, erimart-domains.com.cn and hknsc.hk are linked by IP address).</p>
<p>Here is one that I received on 2008-12-08, originating from IP 58.38.209.249:</p>
<blockquote><p>From: &#8220;andy&#8221; &lt;andy@asiaton.cn&gt;<br />
To: &#8220;joewein&#8221; &lt;joewein@pobox.com&gt;<br />
Sent: Monday, December 08, 2008 14:11<br />
Subject: Urgent-Notification of intellectual property</p>
<p>Dear CEO, </p>
<p>   We are Asiaton Network Service Co., Ltd, which is the Internet Trademark&#038;domain name register center in China. I have something need to confirm with you. We have received an formal application. An international company named &#8220;ROB GmbH&#8221; wants to apply &#8220;joewein&#8221; for its own Internet Trademark and CN domain name on Dec 8, 2008 in china. We need to know your opinion because the Internet Trademark And CN domain name may relate to the copyright of your company name on internet. If your company do not intervene in it,we will formally consent their registration<br />
because the registration principle is that &#8220;Every company or individual can register the domain name and Internet Trademark which is not registered,and who registers first who owns first.&#8221;<br />
we would like to get the affirmation of your company. If you have any question,please contact us by telephone or email as soon as possible! </p>
<p>Best Regards !</p>
<p>Andy</p>
<p>Principal of Checking Department </p>
<p>Overseas Registration Organization </p>
<p>Tel:+(86)731-8187 729</p>
<p>Fax:+(86)731-8187 739</p>
<p>Mobile:+(86)731 6735 121</p>
<p>Skype:chinaregistry</p>
<p>E-mail:andy@asiaton.cn</p>
<p>web:www.asiaton.cn</p>
<p>2008-12-08
</p></blockquote>
<p>Such email solicitations are fraudulent, because you can safely assume that the same email, with other domains substituted for yours, has gone out to thousands of domain owners. I found an almost identical email (listing the same third party supposedly trying to register a domain) in <a href="http://kah-yoong.blog.friendster.com/2008/11/china-domain-scam/">another blog</a>. Somebody obviously thinks being a registrar is a license to milk foreigners.</p>
<p>Don&#8217;t fall for this scam, they&#8217;re playing on fear. </p>
<p>If you own a .com, .net or national TLD (.co.uk, de., .fr, etc) domain but are not planning to set up a Chinese office or not even doing any business in China you have no reason to spend money on a domain registration with a Chinese registrar. Also, trademarks and domains are largely separate issues. You don&#8217;t become a trademark owner merely by registering a domain and vice versa.</p>
<p>The only domains that really count for your business are .com/.net/.org (depending on the nature of your organisation) and/or the country code top level domain (ccTLD, such as .co.uk or .jp) if you&#8217;re based outside the USA.</p>
<p>Below are other examples of domain registration spams / scams that I have received before. I am sure there are a lot more out there.</p>
<p><strong>Received on 2008-03-18 from 221.221.167.121:</strong></p>
<blockquote><p>From: &#8220;Bruce.li&#8221; &lt;Bruce.li@erimut.com&gt;<br />
To: &#8220;jwspamspy&#8221; &lt;jwspamspy@pobox.com&gt;<br />
Sent: Tuesday, March 18, 2008 12:53<br />
Subject: Jwspamspy Domain Name </p>
<p>Dear joewein.de LLC,</p>
<p>   We are Beijing Erimut Network Information Technology Co., Ltd in China, which is the domain name registration centre here. A formal application from the company called ChengGuang Investment (China) Co.,Ltd is to register &#8221; jwspamspy &#8221; as their domain name and internet keyword on Mar 17th 2008. Since this involves your company name or trade mark, in no time do we inform you of this. Please contact us timely if a first registration is needed to protect the domain names and internet keywords. </p>
<p>Kind Regards<br />
Bruce.Li </p>
<p>Tel: +86-10-62667420 ext.602<br />
Fax: +86-10-62667460</p>
<p>Email: Bruce.li@erimut.com<br />
Beijing Erimut Network Information Technology Co.,Ltd<br />
Website: www.erimut.com</p>
<p>2008-03-18 </p>
<p>Bruce.li </p></blockquote>
<p><strong>Received on 2008-7-30 from 123.127.123.173:</strong></p>
<blockquote><p> From: &#8220;thomas.zhang&#8221; &lt;thomas.zhang@erimart-domains.com.cn&gt;<br />
To: &#8220;419&#8243; &lt;419@419scam.org&gt;<br />
Sent: Wednesday, July 30, 2008 12:55<br />
Subject: Joewein Domain name &#038; Internet keyword </p>
<p>July 30, 2008 </p>
<p>Joewein      </p>
<p>Domain name &#038; Internet keyword</p>
<p>Dear Sir/Madam,           </p>
<p>We are Beijing Erimart Network Service Co., Ltd which is the domain name register center in China. We received a formal application from a company who is applying to register “joewein” as their domain name and Internet keyword on July 27, 2008.Since after our investigation we found that this word has been in use by your company, and this may involve your company name or trade mark, so we inform you in no time. If you consider these domain names and internet keyword are important to you and it is necessary to protect them by registering them first, contact us soon. Thanks for your co-operation and support.</p>
<p>Kind Regards,         </p>
<p>Thomas.Zhang</p>
<p>Tel: +86-10-62961631-8017</p>
<p>Fax: +86-10-82780671</p>
<p>Email: thomas.zhang@erimart-domains.com.cn</p>
<p>Beijing Erimart Network Service Co, Ltd </p>
<p>http://www.erimart.com</p>
<p>2008-07-30 </p>
<p>thomas.zhang </p></blockquote>
<p><strong>Received on 2008-11-07 from IP 58.38.209.249:</strong></p>
<blockquote><p>
From: &#8220;jackey.zhuang&#8221; &lt;jackey.zhuang@hongkongnet.org&gt;<br />
To: &#8220;419&#8243; &lt;419@419scam.org&gt;<br />
Sent: Friday, November 07, 2008 18:10<br />
Subject: 419scam Notice</p>
<p>Dear Sir/Madam,</p>
<p>    We are Hong Kong Network service Company Limited, the an official domain name registration center.</p>
<p>    On Nov 06, we received an application from another company for the domain names “419scam”  , but later we found your company is their original owner and this may involve your company name or trade mark and  this may cause confusion between your products and others’ , and bring about negtive effect on your company.</p>
<p>    Therefore we decided to inform you of this and check out your attitude toward thismatter.That is, do you want to protect these domain names by registrering them ahead or not? We would appreciate if you can spare some precious time to settle this issue.</p>
<p>Thank you for your cooperation and looking forwards to your early reply.</p>
<p>Kind Regards,</p>
<p>Jackey.zhuang </p>
<p>Tel: +852-31757930 ext.8012</p>
<p>Fax:+852-31757932</p>
<p>Email:jackey.zhuang@hongkongnet.org</p>
<p>Hong Kong Network Service Co. Ltd </p>
<p>Website:www.hknsc.hk
</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2008/12/08/domain-registration-scam-in-china/feed/</wfw:commentRss>
		<slash:comments>112</slash:comments>
		</item>
		<item>
		<title>Beware of fake Kaspersky beta installer emails</title>
		<link>http://www.joewein.net/blog/2008/09/22/beware-of-fake-kaspersky-beta-installer-emails/</link>
		<comments>http://www.joewein.net/blog/2008/09/22/beware-of-fake-kaspersky-beta-installer-emails/#comments</comments>
		<pubDate>Mon, 22 Sep 2008 00:24:55 +0000</pubDate>
		<dc:creator>Joe Wein</dc:creator>
				<category><![CDATA[malware]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.joewein.net/blog/?p=83</guid>
		<description><![CDATA[Today I received a Trojan email that bears the same handwriting as the recent fake Google Chrome installer emails. Both emails are in German, offer an attached RAR file with what supposedly is an installer for a beta test version of new software from a well-established software company:

Sehr geehrter Nutzer,
heute möchten wir Sie zu unserem [...]]]></description>
			<content:encoded><![CDATA[<p>Today I received a Trojan email that bears the same handwriting as the recent <a href="http://www.joewein.net/blog/2008/09/08/beware-of-fake-google-chrome-installer-emails/">fake Google Chrome installer emails</a>. Both emails are in German, offer an attached RAR file with what supposedly is an installer for a beta test version of new software from a well-established software company:</p>
<blockquote>
<p>Sehr geehrter Nutzer,</p>
<p>heute möchten wir Sie zu unserem Aktuellen Betatest des neuen Kaspersky© 9.5.710 einladen.<br />
Unser neues Produkt besticht durch seine überarbeitete Scanroutine sowie die schnelle und effektive<br />
Aufspürung von Viren, Trojaner und anderer böswilliger Maleware.</p>
<p>Für ihren persönlichen Zugang haben wir ihnen ein Beta Account eingerichtet welchen Sie bei der<br />
Installation angeben müssen, um den Webinstaller sowie das Programm an sich nutzen zu können.</p>
<p>Benutzername: kis_aX9535<br />
Passwort: c3VF5gg8</p>
<p>Diese Daten werden bei der Installation abgefragt. Notieren Sie sich diese Daten bitte genau,<br />
da diese auch für ihren Zugang auf unserer Seite erforderlich sind.</p>
<p>Zum Ende des Betatests bekommen Sie eine Volllizenz und können somit Kaspersky© ein<br />
Jahr kostenlos für ihre Sicherheit nutzen.</p>
<p>Sollten Sie Fragen oder Probleme haben, so schreiben Sie und eine Mail an: beta-team@kaspersky.de</p>
<p>Wir wünschen Ihnen nun viel Spass mit unserem neuem Produkt und hoffen auf eine Positive Wertung<br />
von ihnen auf unserer Website.</p>
<p>Mit freundlichen Grüßen<br />
Ihr Kaspersky Beta Team</p>
<p>Copyright © 1997 &#8211; 2008 Kaspersky Lab </p>
<p>Industry Leading Antivirus Software</p></blockquote>
<p>Message headers:</p>
<p><code>Received: from mo-p05-ob.rzone.de (mo-p05-ob.rzone.de [81.169.146.182])<br />
	by mail.joewein.net (Ogose Mail Daemon) with ESMTP id 818CC10DCC78<br />
	for <419@419scam.org>; Sun, 21 Sep 2008 21:43:45 +0000 (UTC)<br />
X-RZG-CLASS-ID: mo05<br />
X-RZG-AUTH: :L2MKYUGrb9+s7Ys+/C6cdNboKaxR22vZQHQdVrAeYnDdBsCFdpW1J0sdHw==<br />
Received: from [77.21.44.13] ([62.159.230.93])<br />
	by post.webmailer.de (fruni mo40) (RZmta 17.4)<br />
	with ESMTP id L03273k8LKd8yb for <419@419scam.org>;<br />
	Sun, 21 Sep 2008 23:43:17 +0200 (MEST)<br />
	(envelope-from: <beta-team@kaspersky.de>)<br />
Date: Sun, 21 Sep 2008 23:40:54 +0200<br />
Mime-version: 1.0<br />
Subject: [PR] Kaspersky Betatester Programm<br />
From: Matthias Franken <beta-team@kaspersky.de><br />
To: <419@419scam.org><br />
Message-Id: <9212340.EDWNJLIN@kaspersky.de><br />
Original-recipient: rfc822;419@419scam.org<br />
Content-Type: multipart/mixed; Boundary="--=BOUNDARY_9212340_SIIK_IDLO_OFNM_KSKB"<br />
</code></p>
<p>At the time of writing this blog posting, Kasperksy&#8217;s online malware scanner did not yet recognize the Trojan Kaspersky.9.5.7.1.exe in archive file Kaspersky.9.5.7.1.rar.</p>
<p>As I already stated in my posting about the fake Google Chrome installer, do not install software attached to or linked from emails you didn’t request.</p>
<p>The real Kaspersky software is highly regarded and trial versions are available on the Kasperky website.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joewein.net/blog/2008/09/22/beware-of-fake-kaspersky-beta-installer-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
