Tuesday, 28 September 2010

MS10-070 - don't panic.. on second thoughts.. PANIC

Those of you who know Microsoft patch levels probably already treat "Important" patches with a shrug, because the really important ones are always "Critical". So when Microsoft does an out-of-band patch only rated as "Important" then there's something not right going on.

Well, MS10-070 is one such patch, and to be brutally brief it means that IIS servers are vulnerable to an information disclosure attack.. very bad news if you are running IIS.

The ISC have more here, but be sure to read the comments.. because this one is looking like a complete fragging disaster zone..

Monday, 27 September 2010

"United Nation Bonded Warehouse Wales" scam

An obvious scam, but one that's really quite stupid:

From: AHMED SALEH ABDUL KHALEQ SLAEH ALAFIFI <info@khaliq.com>
Reply-To: khaliqalifi@iol.pt
Subject: ASSALAMUALAIKUM
 
From AHMED SALEH ABDUL KHALIQALIFI,.
United Nation Bonded Warehouse wales Branch.Office..........

What? Where? Actually, the UN does run warehouses, primarily for aid efforts (there's a list of jobs here) usually in areas suffering from disasters or war.. I don't think a Friday night in Swansea counts. But a bonded warehouse is not the same thing at all..

SALAM,

Dried sausage to you, too.

This is AHMED SALEH ABDUL KHALIQALIFI ,  Presently stationed with the possition of  assistant Manager as a trusted store-keeper herein United Nation Bonded WareHouse Wales Branch ..Office, Division in South West of  Great Brintain  . I will like to share some very vital information that would bring some good financial returns to us in just a few weeks or days depending on how fast we pursue the matter.I am seeking your assistance to evacuate unclaimed valuable property to your safe custody, as long as I can be assured that it will be safe in your care until i complete my service here
Why do I think that "trusted" is not the right word when you are basically offering me something that you have stolen? And Wales is in the "South West of  Great Brintain"? That's somebody who has a very badly spelled atlas that they don't really understand. Oh yes, and if you're in Wales, why is the sending IP address 110.159.18.181 in Malaysia?

This may not be the best medium to make this kind of contact because of the numerous scam offers transmitted through the Internet, but it is all I have access to for now.

Well, I'm glad you pointed that out because I totally believe that it's not a scam now. Tell you what, Wales is a couple of hours drive.. why don't I pop over with a van or something?

I will be very grateful if you can give me the opportunity to discuss this matter with you by assuring me that you will not use any part of it against me in anyway, I hope you understand my limitations here. I will await a mail from you.
What. like publishing your pathetic scamming effort onto teh interwebs?

Sincere Regards,

AHMED SALEH ABDUL KHALIQALIFI.
I think you need to double check the meaning of "sincere.."

Friday, 24 September 2010

position-gb.com / position-west.com fake job offer

Part of a long series of fake job offers, this one uses the domains position-gb.com and position-west.com to solicit replies. In this case "bank account operations" is money laundering, "transportation and logistics" is most likely a parcel reshipping scam and "private enterprise service" could be one of a number of criminal activities. Avoid.

Date: 24 September 2010 12:56
Subject: Re: CV 62

Greetings

I am a manager of the HR department of a large multinational company.

Our enterprise is connected with a great number of various activities, like:
-property
- bank account operations
- transportation and logistics
- private enterprise service
- etc.

We need employees in Europe:
- salary 2.500 euro + bonus
- 1 - 2 working hours per day

- free timetable


If our offer is interesting for you email us the required information: Chandra@position-gb.com
Name:
Surname:
City:
E-mail:
Telephone Number:



Note! We are searching Europeans only!

Wednesday, 22 September 2010

Evil network: VLine Ltd / VLINERU2-NET AS39150 (109.196.128.0/20)

A malware run in progress today using the arestyute.com domain made me look at VLine Ltd, a Moscow based host well-known for supporting criminal activities. The question is.. does VLine actually host any legitimate sites? The answer.. probably not.

An analysis of the netblock 109.196.128.0/20 (109.196.128.0 - 109.196.143.255) which forms AS39150 shows a collection of fake pharma sites, malware sites, fake banks and shipping companies, illegal downloads, fake passports and various other organised criminal activities.

A scan of the netblock using the MyWOT API shows a lot of very bad sites with a few rated "40" which shows that the MyWOT system has rated them automatically. You can see the ratings for all sites in the range in this CSV.

Google's Safe Browsing diagnostic for AS39150 is damning:

Safe Browsing
Diagnostic page for AS39150 (VLTELECOM)


What happened when Google visited sites hosted on this network?

    Of the 567 site(s) we tested on this network over the past 90 days, 33 site(s), including, for example, cgm.ru/, gigalife.info/, kastrade.ru/, served content that resulted in malicious software being downloaded and installed without user consent.

    The last time Google tested a site on this network was on 2010-09-21, and the last time suspicious content was found was on 2010-09-21.

Has this network hosted sites acting as intermediaries for further malware distribution?

    Over the past 90 days, we found 109 site(s) on this network, including, for example, 109.196.134.0/, webserviceftp.ru/, webservicelupa.ru/, that appeared to function as intermediaries for the infection of 3232 other site(s) including, for example, madonnaonline.com.br/, veloplus.ch/, skihutonline.nl/.

Has this network hosted sites that have distributed malware?

    Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 165 site(s), including, for example, 109.196.134.0/, webserviceftp.ru/, webserivcessh.ru/, that infected 7766 other site(s), including, for example, madonnaonline.com.br/, homeandi.com/, ishrae.in/.

There's no reason not to block the entire range permanently, or if you want the individual domains check the CSV or copy and paste from below.

Zoma.ru
All4roof.ru
Minirank.ru
Chem-prom.ru
Dias-design.ru
Tile-world.ru
Airways-pro.ru
Mountain-air.ru
Office-ready.ru
Copyterra.ru
Home-building.ru
Vcam-security.ru
Find-furniture.ru
Air-free.ru
Office-interior.ru
Altioma.ru
Artellab.ru
Teplicy-volya.ru
Smirl.ru
Furniture-catalog.ru
Minipr.ru
Plastistrong.ru
Amalgamator.ru
Best-ceramics.ru
Vorota-avto.ru
Building-window.ru
Ccwater.ru
Smbuilding.ru
Home-interior.ru
Fertilize.ru
Light-breeze.ru
Sol-system.ru
Funny-holidays.ru
Furnbox.ru
Eco-bus.ru
Parquet4all.ru
Diesel-electric.ru
Sliding-gates.ru
Kamin-pro.ru
Gloomyandspy.com
Sultanpalase.com
Tdom1.ru
Aruspemedic.com
Atacmedic.com
Ballemed.com
Barblmedic.com
Bumedicine.com
Clayemed.com
Cupharmacy.info
Demornmedic.com
Dilimedic.com
Displimedic.com
Dns4life.com
Doctoraxon.com
Doctorpi.info
Doctorte.info
Draymedic.com
Drugstoremp.com
Gardmedic.com
Gatmedic.com
Ghostemed.com
Haemed.com
Hymedicine.com
Inlmedic.com
Inspidoctor.com
Izedrugs.com
Jestumed.com
Jolynbmedic.com
Kalsmed.com
Kedrugs.com
Lamilmed.com
Locumimed.com
Logdrugs.com
Lomedicine.com
Lumedicine.com
Mablmedic.com
Medalea.com
Medalee.com
Medalinve.com
Medaltype.com
Medalyssa.com
Mediardbi.com
Mediatear.com
Mediccu.com
Mediceday.com
Medicerly.com
Medicgant.com
Medicht.com
Medicineax.com
Medicinece.com
Medicineck.com
Medicineie.com
Medicineir.com
Medicinele.com
Medicinta.com
Mediclace.com
Mediclder.com
Medicmile.com
Medicnl.com
Medicorer.com
Medicsh.com
Medictu.com
Mediculio.com
Medicwe.com
Mediuling.com
Mediuro.com
Medulerac.com
Mestinmed.com
Nepharmacy.com
Nidrugs.com
Obamedic.com
Pharmacybp.com
Pharmacydg.com
Pharmacyec.com
Pharmacyha.com
Pharmacyji.com
Pharmacyna.com
Pharmacyou.com
Pharmacyri.com
Pharmacyta.com
Pharmacyty.com
Romannmed.com
Shormed.com
Site1dns.com
Staimed.com
Tommedic.com
Toucmedic.com
Towmedic.com
Unfmedic.com
Weemedic.com
Dnsupport4site.com
Frmedic.com
Golmedic.com
Grmedic.com
Agemedic.com
Balatmedic.com
Boulatomedic.com
Boumedic.com
Busbmmedic.com
Citelmedic.com
Clipmedic.com
Cofmedic.com
Cotmedic.com
Critrmed.com
Curragmed.com
Czkarmed.com
Drugsbr.com
Drugsdo.com
Drugsin.com
Drugski.com
Newnshome.com
Pharmacybw.com
Agammed.com
Alfmedic.com
Anodormed.com
Bapharmacy.com
Bromedic.com
Cartonlinesite.com
Caumedic.com
Doctorrnes.com
Doctorrteeny.com
Drugsab.com
Fiendemed.com
Sandpimed.com
Bilmedic.com
Socmdoctor.com
Anadoctor.com
Aprdoctor.com
Beldoctor.com
Cormedic.net
Cosadoctor.com
Cytdoctor.com
Decadoctor.com
Diadoctor.com
Doctorcitr.com
Doctordefu.com
Doctordnes.com
Doctorelig.com
Doctoresia.com
Doctorglos.com
Doctorlg.com
Doctorni.com
Doctoround.com
Doctorrman.com
Doctorsele.com
Doctorsour.com
Doctorsterca.com
Doctorstri.com
Doctorsust.com
Doctortelamy.com
Doctorusab.com
Doctorwnee.com
Dymedic.net
Esdoctor.com
Eurdoctor.com
Evemedic.net
Exdoctor.com
Faxedoctor.com
Flidoctor.com
Hodoctor.com
Idodoctor.com
Inamedic.net
Karldoctor.com
Lasdoctor.com
Lordoctor.com
Matmedic.net
Momedic.net
Pomedic.net
Prmedic.net
Prydoctor.com
Rodoctor.com
Sarmedic.net
Shimedic.net
Shmedic.net
Sigdoctor.com
Sumedic.net
Toudoctor.com
Tumedic.net
Wrmedic.net
Yeadoctor.com
Agefeskousavd.com
Baguntalput.com
Bandlobhepe.com
Doctoramro.com
Doctoraubr.com
Evercavsuv.com
Everuvdredsovg.com
Feremokerfeve.com
Kalkfallpoxeble.com
Kougsapelex.com
Kownamemavy.com
Laghtbukstap.com
Lekboxover.com
Lupharmacy.com
Mevbeforeday.com
Okworldadd.com
Perapsalfkvow.com
Pestendblask.com
Sallfapestpong.com
Seemalwayxame.com
Sekevak.com
Somekurvcar.com
Svowkooleskev.com
Swedoctor.com
Thousandbondepoff.com
Voecesoutree.com
Vowelvortevg.com
Wakerkesedurevg.com
Welebodyuvdred.com
Weskarereal.com
Wycerkaevsek.com
Yesqueskeovabove.com
Afmedicine.com
Ammedicine.com
Chmedicine.com
Medicalmoisdw.com
Medicalmoisdw1.com
Medicalmoisdw10.com
Medicalmoisdw2.com
Medicalmoisdw3.com
Medicalmoisdw4.com
Medicalmoisdw5.com
Medicalmoisdw6.com
Medicalmoisdw7.com
Medicalmoisdw8.com
Medicalmoisdw9.com
Medicineds.com
Medicinels.com
Medicinemi.com
Medicinena.com
Medicinend.com
Medicineoi.com
Am-way.ru
Sheathing.ru
Zakonoma.ru
Inmoble.ru
Crosswall.ru
Auto-wash.ru
Service-stroy.ru
Pure-air.ru
Window-tech.ru
Aeroventa.ru
Jackcond.ru
Ullte.com
Mp3fiesta.com
Setyupdates.com
Netspart.net
Myupdates.biz
Headboong.com
Myupdateswindows.biz
Bestandxast.com
Besternax.com
Erterzan.com
Joprestons.net
Ralaxanteras.com
Russian-post.net
Slikanddik.com
Trafallbest.com
Xalentarna.net
Zalevaka.com
Zaskupalt.com
Fdsdorgan.com
Freefdsvoip.com
Jastli.com
Qlepa.in
Infinitelivin.tw
Vviv.ru
Audo20s.in
Music9star.com
Nostalgictitation1.info
Pixelateder.info
Reducedilonion.info
Music9star.org
Video4gamle.org
Budulay.net
Ak2o.info
Bioloom.info
Cd3o.info
Dkm5.info
Drone2556yb5.info
Ek5k.info
Gambolsfhsw5.info
Jingoisticth65.info
Joculartuu7.info
L1nn.info
Largessff.info
Tjkd.info
Vaqp.info
Ymso.info
Globalstream.info
Xwealthglobal.com
Xwestprivate.com
Partnerandassist.com
Representativesuk.com
Tinygimme.info
Alm-career.com
Gdm247.com
Kadewsq.com
Kahlier.com
Myservster.com
Old-crash.com
Onlinesexytube.com
Vipnakurka.com
Asderbit.com
Ilaydiy.com
Ilovelasvegas.ru
X5vsm5.ru
Godfast.info
Haycorn.info
Lercuw.info
Winkum.info
Ukada.ru
Careerbuildjobs.com
Astraphs.com
Jarntauiuva91.com
Banktrustservice.com
Staffsecurecheck.com
Vseravnopidersii.net
Aatrgroup.com
Accentincolor.com
Prodesgroup.com
Kse-advertising.com
Sysport-1.com
Vlnet.ru
Intlos.org
Atomicc.com
Cern-a.com
Xbasex.com
Upslabels.cc
Securixp.com
Securixp.net
Addthiss.cn
Addthiss.net
Addthiss.org
Countinfo.com
Free-ns.org
Searchits.org
Searchnew.net
Top-analitics.com
Qweda.cn
Ameriprise-careers.eu
Piccinirealestate.eu
Sniping.biz
Your-usa-address.com
Gitrest.net
Utromesa.net
Yarostt.net
Absolutefinancegroup.com
C339.net
Freehost21.tw
Keller-services.com
Llwql.com
Parcelforwardingservice.com
Ticketalfa.com
Ticketbravo.us
Babaevo.com
Bestinsurancequotesinfo.com
Detoxhot.com
Freestarcraft2guide.info
Googlesecrets.biz
Guitar-beginners-guide.com
Insuranceproquotes.com
Pokeralpha.net
Agency-sunsea.com
Aslrr.com
Avelectronics.org
Buyfakepassport.cc
Buyfakepassports.com
Cargoex.info
Fakepassportsale.cc
Mbe-kerriere.com
Myhotlot.com
Oem-buy-soft.com
Oem-soft-buy.com
Raggaperfibra.net
Silverstarf.net
Whoismansheck.com
Yahoo-statistic.com
Geo-tour.org
Zeoxmark.com
Zeoxmark.net
Time-sync.net
Acfinc.eu
Banking-security.org
Lnterhome.biz
New-crash.com
Storetablets.net
Vipnakurka.net
Wallst-news-line.com
Sexyshowmovies.info
Sexyshowvideo.info
Allow-strike.ru
Allowstrike.ru
Antituta.ru
Awm-magazine.ru
Enterteiment-wizrd.ru
Enterteimentwizrd.ru
Julyrelax.ru
Magazineawm.ru
Magazineshare.ru
Nanovoice.ru
Protray.ru
Relax-july.ru
Relaxjuly.ru
Ros-tec.ru
Sensationworld.ru
Shareawm.ru
Sharks-devision.ru
Sharkstux.ru
Traypro.ru
Tuta-anti.ru
Tutaanti.ru
Tutavir.ru
Vir-tuta.ru
Viranti.ru
Virtuta.ru
Visitthermal.ru
Voice-nano.ru
Voicecontrol.ru
Wizrd-enterteiment.ru
Wizrdenterteiment.ru
Combicorm.com
Dertentazner.com
Notersils.com
Rerasterk.com
Westtrafficanser.com
Wrtumenter.com
Arestyute.com
Rtttins.com
Trrrasret.com
Ukklomk.com
Bibblea.com
Trawqe.com
Uttere.com
Yterast.com
Capitalmarktservice.com
Dangerousteens.com
Mrxbase.com
Sweetpornobabes.com
Sweettiny.com
The-snake-jewellery.com
Tight-slits.com
Tinysweet.com
Youngsweat.com
Zedexpost.com
Gkkotre.com
Letyasheypohodkoymoraleswtf.info
Mindwor.com
Promojoyswif.net
Tristan-express.com
Vain-and-ryan.com
Vain-ryan.com
Weslisnaps.info
Samsclearancerainbow.com
Samsclearancewebers670.com
Samsclubclearance.cc
7crack.com
7newmails.com.ua
9ladiesmails.com.ua
Abruzzonelblues.com
Alina-sp.com.ua
Alinamails-jl.com.ua
Allmails-1u.com.ua
Anastasia-mails7.com.ua
Annamail-jl.com.ua
Ckinter.ru
Contacts4u-sp.com.ua
Crack-info.com
Crack-key.com
Crack-keygen-serial.com
Crack-news.com
Crack-software.com
Crack-warez.com
Crackblogs.com
Cracknews.info
Dates-eva.com.ua
Download-url.com
Drcrack.com
Evadates.com.ua
Evamass-pa.com.ua
Evanews-pa.com.ua
Evanotes.com.ua
Evatease.com.ua
Free-key.net
Freecrack.net
Girlfriend-re.com
Julia-mails.com.ua
Julia-mails7.com.ua
Julia-sp.com.ua
Katerina-sp.com.ua
Ladies-re.com
Mails4u-pa.com.ua
Maria-mails7.com.ua
Marina-sp.com.ua
Matches-re.com
Messages4u-sp.com.ua
Mila-sp.com.ua
Nadya-sp.com.ua
Notes4u-pa.com.ua
Olganotes.com.ua
Search-crack.com
Serials-keys.com
Teaseville-sp.com.ua
Thecrack.name
Warez-crack.com
Wincrack.info
Yeva4u-pa.com.ua
Search-841.com

Tuesday, 21 September 2010

FirearmsForYou.com and the Chinese connection

Automated link exchange requests are annoying, but usually easily dealt with by binning them. This idiot decided to send me the same spam 25 times..

From: James <linkmanager@firearmsforyou.com>
Subject: Link Exchange Proposal from FirearmsForYou.com

Hello Webmaster,

I am seeking out possible link partners to offer as a resource to our site's visitors. I've found your website http://www.dynamoo.com and its information and advice to be a great service and I am interested in exchanging links with you.

Please consider adding our link to your site on the following page:
http://www.dynamoo.com/orange/links.htm

Our linking details:

Anchor text: Guns Online

URL: http://www.firearmsforyou.com/

Description: Buy guns online from a trusted source. Firearms For You has the largest selection of firearms and accessories.

[snip]

Guns Online Buy guns online from a trusted source. Firearms For You has the largest selection of firearms and accessories.

Your link will be added in the best category here http://www.firearmsforyou.com/resources/index.html

Please send me your site details and I will add your link as soon as possible.

I hope for an early and positive response from you.

Best Regards,
James
FirearmsForYou.com
9831 E. Bell Road Suite 110
Scottsdale, AZ 85260

Note: If you would like not to receive any further communications from me, please paste this link into your browser: http://www.firearmsforyou.com/resources/unsubscribe.html?id=[snip]

Or simply respond to this email with Remove as the subject.

OK, he's an idiot who sells assault rivals, but Scottsdale is over 5000 miles away, so I feel quite safe calling "James" (if that is his name) an idiot.

Now, if Americans want to take pot shots at each other with military grade weapons then it is up to them, pro-gun people will argue that it's their constitutional right to bear arms as American citizens.

But dig a little deeper, and these emails originate from 202.181.174.45 in Hong Kong.. which is part of China.. who are Communists, remember? It all looks a bit un-American to me..

Monday, 20 September 2010

The incredibly dangerous world of browser prefetch

Perhaps I've been living under a rock, but this apparently has been a suicidally stupid feature built into Firefox for some time, but it seems to be seldom used.

It started with a short spam apparently advertising a fairly well known black hat forum for hackers and illicit trades. It's not the sort of place that would choose to advertise itself though (it is strictly by invitation only), so quite possibly this is a Joe Job by one set of black hatters against another.

Now I guess that many recipients will have done the same thing, and typed the name of the site into Google to find out about it.. under the assumption that they'll find something that doesn't involve visiting the spamvertised site itself. But if you're using Firefox (and this possibly applies to IE8 and IE9 too, then the following message pops up:


Secure Connection Failed

-----------.com:443 uses an invalid security certificate.

The certificate is not trusted because it is self signed.

(Error code: sec_error_untrusted_issuer)

It could be a problem with the server's configuration or it could be someone trying to impersonate the server.

If you have connected to this server successfully in the past the error may be temporary and you can try again later.
Right at this point I kicked myself because I thought I had accidentally clicked through. But no... the certificate error was showing on the Google search page and I hadn't clicked through at all.. so why was Google trying to load the page and showing the HTTPS error because of the invalid certificate?

The answer lies in prefetch - a combination of a tag on the site, Google and the default browser configuration meant that the browser tried to automatically load content from the bad site just by Googling for something.

Link prefetching (and how to turn it off) is explained in this FAQ or this HOWTO guide.. if you are using a Mozilla based browser then go and turn if off NOW by going into about:config and setting network.prefetch-next to false.

So why is it so dangerous? Have there been any cases of malware using link prefetching to spread? Not as I know.. although it might be theoretically possible. The danger is that you have just revealed your IP address without knowing it..

Let's look at a particular scenario where this can be used. Let's say the attacker is targetting a victim who is using an unidentifiable email address, and the attacker wants to find that victim's IP to tie them down to a location or organisation. In this scenario, the victim is not stupid.. they don't click on links in spam, they don't reply to untrusted messages, never send read receipts and they don't load external images in their mail client.. but the attacker uses social engineering to send an email with details that the victim might Google (for example a telephone number). The victim may then search for references on Google and even without clicking on anything, the prefetch may reveal their IP address.

Alternatively, prefetch could be used to download illegal content onto a target machine without the victim knowing about it, or there are probably several other ways in which it can be abused.

So it's hard to tell if the original spam was a Joe Job, or someone using prefetch to collect IP addresses for evil purposes. But I'll bloody well keep the prefetch switched off in future..

Sunday, 19 September 2010

"hello / how are you?" mystery spam

I'm probably not alone in receiving a shedload of spam with the subject "hello" and the only content of "how are you?" A quick look at my spam filters shows hundreds of these with a small number getting through, presumably because filters are having a hard time blocking on this little data.

It's hard to be sure exactly what it is, but it reminds me the the mystery "podmena traffica test" spam from last year that appeared to be a widescale enumeration of mail systems that allowed spoofing, and those that blocked it. So, this could well be something similar.. an enumeration attempt to see which mailboxes DON'T reject a tiny, simple message like this, and then to use that data in the future to target those mailboxes.

"OK", you may be asking.. "why would you do that if you have the almost unlimited computing power of a botnet at your hands? Why would you need to be selective in your spamming when it does cost you anything?"

One good reason to attack only valid mailboxes with spam and not go for a scattergun "directory harvesting" attack is that mail spam filters specifically look for directory harvesting attacks and then block them and use the data to identify the characteristics of the spam attack. By acting more stealthily, it might be possible to avoid detection for longer and get a higher deliverability rate for spam.

Well, that's a theory anyway.. the best that I can come up with. Any ideas?

Added: here's another idea - the spammer could be looking for vulnerable mail servers to exploit later, this is  a data collection phase to be followed by something evil. Or it could just be a weird prank, of couse.

Friday, 17 September 2010

Networking4Africa.com - scam, spam or Joe Job?

Update: networking4africa.com's response is at the bottom of this post

One of the more interesting things that popped into my spam filter today was this.. at first glance it appears to be some sort of MLM scam spam:
From: steve@networking4.africa.com
Reply-To: steve@networking4.africa.com
Date: 17 September 2010 10:41
Subject: WOW 6 grand a month from your home

STOP!!! what your doing...do you know 3 people that have  $15.00?

And do those people know 3 people that have $15.00?

and what about those people and the ones after that? Join Me With 3 subscribers

and when each subscriber does the same through 10 levels

your income would be $63,982.50 per month

http://www.networking4africa.com

Join Now Pay Nothing Until  September 1st.

just get in now before we open to the public.

What if you just did 10% of that.
could you use and extra $6300.00 a month?****
all that for $15.00....
WoW that's the power of People Knowing People, Knowing People Knowing People....

www.networking4africa.com

Steven McGregor Owner and Ceo of www.Networking4africa.com and www.networking4afica.net
[personal address redacted]
+27.[personal number redacted]

Chat with me on face book http://www.facebook.com/smcgregor3

www.networking4africa.com

Please Note You will get Very rich with This program
So wtf is this? It looks like it is promoting a site called networking4africa.com (and networking4africa.net) which does exist (but more of that in a moment). But there are a couple of anomalies (highlighted) where the domain is quoted wrongly.. kind of odd for a promotional message. Oh, and September 1st is long gone..

Another odd thing is the inclusion of a telephone number and full postal, because be in no doubt that this email is spam. Typically we see this sort of thing when a Joe Job is in progress.. in other words, the spam is being sent maliciously by a third party and the telephone number is included to cause harassment for the victim.

The email originates from 216.59.18.30 which is a dedicated server some outfit called WebExxpurts who are assigned 216.59.18.0/24. A look around the netblock shows something interesting though, a site called iunmetered.com a few IPs away at 216.59.18.10 which is an anonymous VPN service. Given that the originating IP for the spam is a dedicated server (which appears to have no active web sites)  then there's a fair possibility that someone is using iunmetered.com to mask their IP address. But why mask your IP address if you are including a telephone number? It seems bizarre, and again perhaps evidence that "Steven McGregor" did not send the email.

Networking4Africa.com itself is hosted on 12.201.193.120 (a completely different network from the email sender), and the WHOIS details do largely match the ones in the spam, but that proves nothing. But now the plot thickens..

12.201.193.120 is in an IP address range which is allocated to "TEK CHANNEL CONSULTING LLC DBA WHOLSALE BANDWITH" (sic). Tek Channel / Wholesale Bandwidth are a very well known spam-friendly firm that has a ROKSO file at Spamhaus. This range has then been reassigned again to Global Virtual Opportunities Inc of Schert, Texas. This range forms part of AS46549 which has been fingered by Google as being pretty evil:

What happened when Google visited sites hosted on this network?

    Of the 2755 site(s) we tested on this network over the past 90 days, 371 site(s), including, for example, dontforward.com/, helpfulbackpaintips.com/, ultimatesneakers.com/, served content that resulted in malicious software being downloaded and installed without user consent.

    The last time Google tested a site on this network was on 2010-09-17, and the last time suspicious content was found was on 2010-09-16.

Has this network hosted sites acting as intermediaries for further malware distribution?

    Over the past 90 days, we found 16 site(s) on this network, including, for example, latenightwarriors.com/, tricitieslifeinsurance.com/, networkonlinereviews.com/, that appeared to function as intermediaries for the infection of 67 other site(s) including, for example, ccll-gtyarmouth.co.uk/, rogersvillelifeinsurance.com/, mediascout.kr/.

Has this network hosted sites that have distributed malware?

    Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 16 site(s), including, for example, aardvarkville.com/, extraganancias.com/, latenightwarriors.com/, that infected 253 other site(s), including, for example, meb.gov.tr/, anakku.com/, tottochan.jp/.


In other words, this doesn't  look like the sort of place a legitimate web site would want to be hosted.
But then what about networking4africa.com itself? Does it tally with the ridiculous "get rich quick" scheme outlined in the email?

It turns out that the site offers an MLM program which gives part of its proceeds to charity. Now, I've never come across any MLM program that is not some sort of scam.. either an out-and-out Ponzi or something that simply fails to deliver what it seems to be promising.

The basic deal is that you join up for $15 of which $5 goes into a fund called the "Helping Portion" which is meant to eventually help children in Africa. What you get for this is unclear, but on the "Products" page are a couple of eBooks (you know the sort of thing).The idea is that if you sign up enough people then you can make a shedload of cash, and some of this will go to the "helping portion".

It gives an example that if 88,572 joined, then it woudl generate $442,860.00 a month for these good causes. But then if 88,572 people simply ponied up $5 a month to Oxfam or a similar charity then it would also generate $442,860.00 a month without participating in some crappy MLM scheme.

And yes.. it is a crappy MLM scheme that is little other than a pyramid scam, according to its own description:

Commissions are paid through a simple unlimited width, 10 level matrix.

This means that you can introduce as many Subscribers as you want and they will appear on your level 1. The subscribers that they refer will be on your level 2 and so on.

You will receive commissions at the following rates for each level:
Level 1 - $2.00
Level 2 - $0.75
Level 3 - $0.75
Level 4 - $0.50
Level 5 - $0.50
Level 6 - $0.50
Level 7 - $0.50
Level 8 - $0.50
Level 9 - $0.75
Level 10 - $0.75

As an example, if you were to only introduce 3 Subscribers and each Subscriber did the same through 10 levels, your income would be $63,982.50 per month. Results will vary from person to person but with a deep matrix your income can be very stable and with unlimited width your potential income is unlimited. 
That's 1 - 3 - 9 - 27 - 81 - 243 - 729 - 2187 - 6561 - 19683 - 59049. Having difficulties visualising that? Well, it looks like this:

..wait, isn't that one of these..?

..yup, it looks like a Pyramid to me.

Now, I don't know South African law and I have absolutely no idea to the legality of this scheme.. but legal or not, it is certainly bullshit and dangling the carrot of starving African children is nothing short of dispicable.

Which brings us full circle to the spam email.. it does bear all the hallmarks of a Joe Job, but the target site is a stain on the Internet anyway..

Update: Steven McGregor emailed me to say:

I apologise for the spam e-mail that you received. We have been under attack by a spammer based in the Philippines who has been trying to shut us down, but I believe that we have put a stop to it now.
Just a couple of points:

    * The email address that you show in the article does not exist and never has.
    * If you look at the full header of the e-mail you will notice that it did not originate from our domain or IP.
    * We have authentication protection so it you contact our provider they will verify the above.
    * If it was a marketing e-mail their would have been a referral link.
    * If I was going to spam I would not include my personal contact details.



[...] We have had everything that we are doing confirmed by an actuary and I don't really care to go into details. The site and our actions cover this sufficiently.[...] Network Marketing is a completely legal business model and not a pyramid scheme.

Thursday, 16 September 2010

Krebs pwnage

Brian Krebs is on the trail of some questionable activities involving an outfit called ePassporte. Now, for those of you who don't know who Brian Krebs is, he's a former Washington Post journalist.. and when he publishes things, things happen.. so the articles are always worth a read if you're interested in information security.

What caught my eye though was this part: "Elias declined to give me his e-mail address, saying I should be able to find it if I really were an investigative reporter."

You can probably guess what happens next..

Thursday, 9 September 2010

Evil network: MAXHOSTING Services, kfppp.com and the BBC Radio 3 compromise

MAXHOSTING are a fairly prolific evil network that I profiled last month, so it isn't a huge surprise to see that the evilness continues as normal.

But one thing that made MAXHOSTING stand out today was their involvement in an apparent compromise on the BBC's website, as reported by The Register.  Google have labelled the BBC's Radio 3 subsite as being potentially dangerous:

Safe Browsing
Diagnostic page for bbc.co.uk/radio3

What is the current listing status for bbc.co.uk/radio3?

    Site is listed as suspicious - visiting this web site may harm your computer.

    Part of this site was listed for suspicious activity 2 time(s) over the past 90 days.

What happened when Google visited this site?

    Of the 15 pages we tested on the site over the past 90 days, 4 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-09-09, and the last time suspicious content was found on this site was on 2010-09-09.

    Malicious software is hosted on 1 domain(s), including kfppp.com/.

    1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including z145235.infobox.ru/.

    This site was hosted on 1 network(s) including AS2818 (BBC).

Has this site acted as an intermediary resulting in further distribution of malware?

    Over the past 90 days, bbc.co.uk/radio3 did not appear to function as an intermediary for the infection of any sites.

Has this site hosted malware?

    No, this site has not hosted malicious software over the past 90 days.

How did this happen?

    In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.

So, what do we know about kfppp.com? Well, it was registered one day ago via black hat domain registrar BIZCN to a fake recipient, and is hosted on a server at 77.78.240.253, which is in Maxhosting's range.. so obviously this is nothing good.

The trouble is that the BBC site seems clean and it is not apparent where the infection is coming from, but the BBC site does carry ad banners for non-UK visitors, and it seems possible that a malvertisement somewhere is to blame. Although Google does sometimes make false positives, this particular report is very specific and I tend to believe that the BBC Radio 3 site is (or was) compromised with malicious code.

A full breakdown of current sites, IP addresses and MyWOT reputations can be downloaded from here.

The best advice is to completely block traffic to 77.78.239.x and 77.78.240.x (or better still, the 77.78.224.0/19 parent block), or block traffic to the domains below.

Divambee35.net
Eagen85.net
Forceclub-us.com
Forceclub-us.net
Indep29.com
Investbabaika.com
Janoodle6.net
Levelin29-online.com
Levelin29-web.com
Levelin29.biz
Levelin29.com
Levelin29.net
Levelin29.org
Levelin29.us
Secsslup.com
Trazi.in
Zabil.in
Search-static.org
Vostokgear.org
The-funny-world.info
Francecore.com
Genreystick.com
Grand-vitaro-club.com
Odistanyachts.com
Statxonline.com
Xsbot.net
Planopetroleumteam.com
Acunetxweb.net
Gvist.org
Gvistello.net
Dottasink.net
Nowisisdudescars.com
Vancouvererrorsonfile.com
Whereisdudescars.com
Zettapetta.net
Google-server09.info
Google-server10.info
Google-server11.info
Google-server12.info
Google-server14.info
Google-server29.info
Google-server31.info
Google-server41.info
Google-server42.info
Google-server43.info
Jhuiuhxfgxhlfkjhjth.info
Jhuiuhxfgxhtfkjhjth.info
Jhuluhxfgxhlfkjhjth.info
Top-teen-porn.info
Traxbax.com
Gumile.in
Pro100-soft.net
Geerht.com
Ruslan7777.com
Hyporesist.com
Installs.tv
Thefriends-place.info
Thefunny-world.info
Easy-answers.info
Theeasy-answers.info
Vstils.ru
Clickwebanalitick.com
Hotporncatalog.com
Ns3emeringo.com
Thevipbuyconterst.com
Youngirlsactions.com
Ciougmxehgjesk.com
Kingdol.com
Pcf-osow.com
Pw2.info
Reservus.com
Server90.org
Homesiteuk.com
Narmedic.org
Pp24.biz
403403.net
Firmar.org
Cebere.net
Cebere.org
Ceberz.net
Ceberz.org
Ceterz.biz
Eccinput.com
Faststat.biz
Mainstatserver.com
Bestviewbar.net
Thestatserver.com
Angelx.info
Deltav.info
Fantasyv.info
Fantasyx.info
Francisx.info
Freel.info
Freev.info
Jeffreyl.info
Lmailing.info
Millionsincomingfrom.biz
Weaponx.info
Xcorps.info
Checkege.ru
Otvetege.ru
Sdalege.ru
Stylysxvk.ru
Vkxstile.ru
1-aa.com
Atringroup.com
Awejkgf.com
Winterleaf.org
Free-pac.net
Tsbd1984.com
Fornaticumlili.biz
Dwnld0020.com
Spmfb2299.com
Thephotos-galleries.info
Hosting-backup.org
Darksiti.net
Asmatrin.com
Mvk.net.ru
Mvk.net.ru
Mynewspages.com
Newsdownloads.cn
Nvk.net.ru
Nvk.net.ru
Rsite.net.ru
Rsite.net.ru
Supercarsinfo.net
Vkhost.net.ru
Vkhost.net.ru
Webvk.net.ru
Webvk.net.ru
Sec-stats.org
Eu-analytics.com
Google-stat.org
Auto-russo-trah.com
55echosend.com
66kooum.com
Avilantup.com
Bytrin.com
Club-world-auto.org
Erityng.com
Govenablog.org
Grebtiklop.com
Hercegovinablog.org
Horsebloggovena.org
Horseblogovena.org
Horsegovena.org
Janesblog.org
Nikranox.org
Roxenda.com
Zrefkilops.com
Activateoursoft.com
Graymageds.com
Orangeosol.com
Yellowaven.com
3423254353446.org
Myteen2011.com
Onrpg-cdn.com
Sed-machinery.com
Helpsupport.biz
Connectionsupport.org
Cansbass.com
Cheni.in
Coani.in
Decdo.in
Jaddf.com
Baffyko.com
Ddret.com
Fgtre.com
Gddff.com
Kkrrn.com
Poiiu.com
Rtyyv.com
Ssadf.com
Ssweq.com
Yyeed.com
Yyutr.com
Ghdre.com
Kvxxr.com
Rchjj.com
Krnnt.com
Kvccg.com
Rcggu.com
Rcsss.com
Wrrrt.com
1host4me.ru
Fun-gsm.ru

Monday, 6 September 2010

Tainted network: InterWeb Media / Gogax.com AS21793 (76.76.96.0/19)

Trading under various names including Gogax, InterWeb Media and Exist Hosting , this Canadian company mixes some extremely dangerous sites with links to organised crime with legitimate businesses.

Gogax's business model appears to be to delegate small chunks of its IP address range to third parties, while presumably hosting the servers for them.  In this case of this this $600,000 fraud the IP addresses were delegated by Gogax to a company called Krutikservers in Azerbaijan.

There are also several fake and/or illegal pharmaceutical sites in the address range, which makes it odd that a legitimate organisation like the Swedish Covenant Hospital should choose to host in the same IP range as criminals.

Google's safe browsing diagnostic is pretty damning:

Safe Browsing
Diagnostic page for AS21793 (GOGAX)

What happened when Google visited sites hosted on this network?

    Of the 595 site(s) we tested on this network over the past 90 days, 35 site(s), including, for example, ajvar.com/, freezlylo.com/, no-ip.be/, served content that resulted in malicious software being downloaded and installed without user consent.

    The last time Google tested a site on this network was on 2010-09-05, and the last time suspicious content was found was on 2010-09-05.

Has this network hosted sites acting as intermediaries for further malware distribution?

    Over the past 90 days, we found 225 site(s) on this network, including, for example, nakedfridaydresscode.com/, lykqug.cn/, hejaza.cn/, that appeared to function as intermediaries for the infection of 3632 other site(s) including, for example, rubensf.com/, rebeccaflinn.com/, jesus-messiah.com/.

Has this network hosted sites that have distributed malware?

    Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 207 site(s), including, for example, nakedfridaydresscode.com/, lykqug.cn/, hejaza.cn/, that infected 3270 other site(s), including, for example, rubensf.com/, jesus-messiah.com/, ottomiller.com/.



The full list of domains, MyWOT ratings, delegations and a prognosis as to whether it's the sort of site you might want to visit can be found here, below is a summary of some of the more suspect delegates (note that some of the delegate names could be forgeries):

Abdto He
China
Counterfeit Goods

Allen Jason
United States
HYIP schemes

Cecile Dagorne (Possible forged name)
France
Malware distribution

Emil Vdovin
Russia
Fake / illegal pharmaceuticals & counterfeit goods

Global
Argentina
Fake / illegal pharmaceutical

Gogax
Canada / US
Rogue anti-virus, malware distribution, fake / illegal pharamceuticals

James Schumaker (Possible forged name)
US
Fake / illegal pharamceuticals

Krutikservers
Azerbaijan
Fake jobs / money laundering

Loyalty Servers
Russia
Fake / illegal pharamceuticals, malware distribution, hardcore pornography, illegal software downloads

Michael Chekin
Russia
Fake / illegal pharamceuticals

Paule Uvinekov
Ukraine
Child pornography (reference)

Saman Mazaheri
Iran
HYIP schemes

Telekurs Holding (possible forged name)
Switzerland
Malware distribution

Valeria Duarte
Argentina
Fake / illegal pharamceuticals

Vlad Rybak
Ukraine
Fake / illegal pharamceuticals

Weiliang Zhang
China
Counterfeit goods

WellHost
Ukraine
Fake / illegal pharamceuticals, malware distribution

The bad stuff on this network easily outnumbers the legitimate stuff, blocking the entire 76.76.96.0/19 (76.76.96.0 - 76.76.127.255) will probably not cause significant problems. And if you are a legitimate site operator hosting with Gogax.. they it might well be time to change hosts before the whole lot gets blackholed.

Update: 23/5/11

Gogax claims that the block is now clean. However, the MyWOT rankings for this block still show some sites with very poor reputations (you can see a list of domains and ratings here).

Friday, 3 September 2010

Tainted network: Serverconnect.se / serverconnect-dedicateserver-net AS49770 (95.143.193.0/23)

Not a fully evil network, but AS49770 (owned by Serverconnect.se) has been abused by the bad guys for a long, long time. This particular /23 includes fake ad networks, counterfeit goods, torrents, pornography and a suspiciously large number of .ru domains for a Swedish web host.

Known bad domains currently hosted and in the past include:

  • Bellasinteractive.com [1]
  • Mazcostrol.com [2]
  • Nonstopacc.com [3]
  • Jumpmanlocker.com [4]
  • Timoton.com [5]
  • Tomitt.com [6]
  • Atstatec.com [7]
  • Luxor-groupinc.cc and others [8]
  • Tunedads.com and others [9]
  • Wowtribes.com [10]
  • Transworldlife.com [11]
  • Eurotransbiz.com [12]
MalwareURL lists lots of bad activity in this block, MalwareDomainList has more,  and Google's opinion on the block is not good at all.

Safe Browsing
Diagnostic page for AS49770 (SERVERCONNECT)

What happened when Google visited sites hosted on this network?

    Of the 288 site(s) we tested on this network over the past 90 days, 5 site(s), including, for example, roditelskyi-dvor.ru/, sicko.se/, klybvolvo.ru/, served content that resulted in malicious software being downloaded and installed without user consent.

    The last time Google tested a site on this network was on 2010-09-03, and the last time suspicious content was found was on 2010-08-31.

Has this network hosted sites acting as intermediaries for further malware distribution?

    Over the past 90 days, we found 21 site(s) on this network, including, for example, mainsyql.com/, elisegm.com/, mediafasts.co.cc/, that appeared to function as intermediaries for the infection of 21 other site(s) including, for example, adrants.com/, thepiratebay.org/, rlslog.net/.

Has this network hosted sites that have distributed malware?

    Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 2 site(s), including, for example, mediafasts.co.cc/, wowtribes.com/, that infected 4 other site(s), including, for example, rlslog.net/, golfreview.com/, mtbr.com/.

There's very little of significant value here, although not all sites are malicious. Blocking 95.143.193.0/23 (95.143.193.0 - 95.143.194.255) will most likely do more good than harm and I suggest you consider it.

You can download a full set of domains, IPs and MyWOT ratings from here. The highest priority domains to block are below:

Mazcostrol.com
Nonstopacc.com
Allregioncode.com
Balmain-discount.com
Balmain-dresses.com
Balmain-jacket.com
Balmain-jeans.com
Balmain-leather.com
Balmain-michael-jackson.com
Balmain-mj.com
Balmain-online-shop.com
Balmain-shirt.com
Balmain-shop.com
Balmain-store.com
Balmain-suede-dress.com
Cheap-balmain.com
Dvdboxset2010.com
Fridaydvdstore.com
Ghdhairsales-uk.com
Hi-tvshows.com
Hi-tvshows.net
I-dvdforsale.com
I-dvdforsale.net
I-herveleger.com
I-manoloblahnik.com
I-manoloblahnik.net
I-moncler.com
Just-moncler.com
Mondaydvdstore.com
My-balmain-store.com
My-balmain.com
My-manolo-blahnik.com
Myshoesbus.com
Onlydvdforsale.com
Onlydvdforsale.net
Onsalegolf.com
Saturdaydvdstore.com
Sundaydvdstore.com
Thursdaydvdstore.com
Tuesdaydvdstore.com
Wensdaydvdstore.com
Wesaledvd.net
Yourtopsales.us
Yourtoryburch.com
Youruggshoes.com
Yslshoes-uk.com
Buy-moncler-coat.com
Buy-moncler-jacket.com
Daily-moncler.com
Discount-moncler-onsale.com
Discount-moncler-shop.com
Discount-moncler-store.com
Moncler-2010.com
Moncler-classics.com
Moncler-downjackets.com
Moncler-everyday.com
Moncler-online-mall.com
Moncler-online-store.com
Moncler-today.com
Moncler-zone.com
Monclerfeatherdress.com
Monclerwinterclothes.com
Monclerwinterdress.com
My-moncler-store.com
Newh0tdvd.com
Rosetta4u.info
5fingerstoreonline.info
5fingerstores.info
5fingerstoresite.info
60daysstore.info
90-mall.info
90day-mall.info
90daymall.info
90daymallnow.info
90daymallonline.info
90daymalls.info
90daymallshop.info
90daymallsite.info
90daymallstore.info
90daymalltoday.info
90daysonline.info
90daysworkoutonline.info
90daysworkouts.info
90daysworkoutsite.info
90daysworkoutstore.info
90mall.info
90mallnow.info
90mallonline.info
90malls.info
90mallshop.info
90mallsite.info
90mallstore.info
90malltoday.info
Abercrombiefitchonline.info
Abercrombiefitchonsale.com
Abercrombiefitchsite.info
Abercrombieonline.info
Abercrombies.info
Abercrombiesite.info
Allfitstore.info
Apparelwholesale.info
Beach-body-insanity.info
Beachbodyinsanitynow.info
Beachbodyinsanityshop.info
Beachbodyinsanitystore.info
Beachbodyinsanitytoday.info
Best90daymall.info
Best90days.info
Best90mall.info
Bestabercrombiefitch.info
Bestbeachbodyinsanity.info
Bestmallonline.info
Bestmbtshoes.info
Bestp90mall.info
Besttshirt.info
Bestvibramshoes.info
Bestworkoutnow.info
Bestworkoutonline.info
Bestworkoutshop.info
Bestworkoutsite.info
Bestworkoutstore.info
Buybagsshop.info
Buybrandbags.info
Buyshoesnow.info
Buyshoesstore.info
Buyshoestoday.info
Dvdboxsetonline.info
Dvdsetsnow.info
Ecb2b.info
Ecb2c.info
Edhardyfactory.com
Extremehomefit.info
Forwholesale.info
Free90daymall.info
Free90daysworkout.info
Free90mall.info
Freebeachbodyinsanity.info
Freebuybags.info
Freedvdsets.info
Freembtshoes.info
Freep90mall.info
Freep90xreview.info
Freetshirt.info
Get-bags.info
Globalsourcesite.info
Globalsourcestore.info
Honestmall.info
Honestshop.info
Insanitysite.info
Inverterwholesale.com
Jersey-supply.com
Letsbuyshoes.info
Lotslinksoflondon.com
Mac-makeups.com
Mbtantishoesonline.info
Mbtdiscountstore.info
Mbtliquidation.info
Mbtretail.info
Mbtshoesnow.info
Mbtshoesshop.info
Mbtshoessite.info
Mbtshoesstore.info
Mbtshoestoday.info
Mbtsonsale.com
Mbtstoresite.com
Mbttoday.info
My5fingerstore.info
My90daymall.info
My90daysworkout.info
My90mall.info
Mybagsonsale.com
Mybestworkout.info
Mydvdboxset.info
Mymbtantishoes.info
Mymbtshoes.biz
Mymbtshoes.info
Myp90mall.info
Myvibram5finger.info
New90daymall.info
New90daysworkout.info
New90mall.info
Newabercrombie.info
Newabercrombiefitch.info
Newbeachbodyinsanity.info
Newbuyshoes.info
Newglobalsource.info
Newmbtshoes.info
Newp90mall.info
Newtees.info
Newvibramshoes.info
Newwholesale.info
Newwholesaleplatform.info
Newworkoutsonsale.info
Nfl-nhljersey.com
Officalp90x.info
Onlinebuydvds.info
Onlinebuyshoes.info
Onlinewholesale.info
Onlywholesaleprice.info
P90mallonline.info
P90mallshop.info
P90mallsite.info
P90mallstore.info
P90xfitnessdvds.com
P90xmall.com
P90xreviewnow.info
P90xreviewonline.info
P90xreviews.info
P90xreviewshop.info
P90xworkoutmallsale.com
Pandorajewellrysale.com
Purchasebags.info
Teesnow.info
Teesonline.info
Teessite.info
Teesstore.info
The5fingerstore.info
The90daymall.info
The90daysworkout.info
The90mall.info
Theabercrombie.info
Theabercrombiefitch.info
Thebestworkout.info
Thehomeworkout.info
Theinsanity.info
Thembtantishoes.info
Thembtshoes.info
Theoffical-p90x.info
Thep90mall.info
Thep90xreview.info
Theshoesshop.info
Thetees.info
Thetshirt.info
Thevibram5finger.info
Theworkoutsonsale.info
Totally-fit.info
Tshirtsite.info
Vibram5finger.info
Vibram5fingersite.info
Vibramshoesnow.info
Vibramshoesonline.info
Vibramshoesshop.info
Vibramshoessite.info
Vibramshoesstore.info
Watchestimes.com
Wholesaleelectronic.info
Wholesalefromhere.info
Wholesalemac.info
Wholesalenet.info
Wholesaleplatform.info
Wholesalestart.info
Workoutsonsale.info
Workoutsonsales.info
Newhotdvd.com
Newrosetta.info
Rosetta-shop.info
Rosetta-store.info
Rosettapro.info
Rosettasoft.info
Rosettstone.info
21ugg.com
21uggboots.com
9webshoe.com
9webshop.com
Air-max-90-shoes.com
Amazonuggs.com
Anynfljerseys.com
Anyugg.com
Aubootsky.com
Aubootsonline.com
Australiaboot.net
Ausuggbootssale.com
Bbbshoe.com
Bendmoon.com
Bhdtrade.com
Bootsgame.com
Bootshead.com
Bootsinbox.us
Bootslove.com
Bootsstreet.com
Cheapsuprashoes.us
Clothesscoop.com
Cosyboots.net
Ebay-cigarettes.com
Ebayuggs.com
Finishboots.com
Fleeceboot.com
Fugems.com
Ghostshoe.com
Gonnaspace.com
Govipshop.com
Hgshoe.com
Hottestuggboots.com
Inbootstock.com
Ineedboots.com
Jumpmanlocker.com
Jumpmanlocker.com.cn
Jumpmanlocker.com.cn
Lacosteralphlauren.com
Lacosteralphlauren.us
Lock-ugg.com
Lolsaleshop.com
Look4clothing.com
Lovesuggs.com
Macktrade.com
Mybootsgame.com
Mybootsid.com
Mybootstrade.com
Mytonyboots.com
Net-ugg.com
New-ugg.com
Nfl007.us
Nfljerseynfl.com
Nike-shoes.com.cn
Nike-shoes.com.cn
Nike99bar.com
Niketrading.com
Nikezone23.com
Nonoshoe.com
Okhairs.com
Pickuggshop.com
Pikmart.com
Pkuggboots.com
Pkuggboots.net
Pololacosteshop.com
Pololatecosshop.com
Pop-ugg.com
Ralphlaurenpolosale.com
Rock-ugg.com
Ruimachina.com
Sellaaa.com
Sheepskinbootsid.com
Sheepskinbootsky.com
Shoeshive.com
Shoeshive.net
Shoestrade.biz
Shoestrade168.cn
Snowboots4sales.com
Snowbootsid.com
Star-ugg.com
Storeboot.com
Tallboot.net
Topcredittrade.com
Topcredittrade3.com
Topcredittrade6.com
Ugg-up.com
Uggbootscheapsales.com
Uggbootsoutletuk.com
Uggbootsuksales.com
Ugglink.com
Uggtopshop.cn
Uggtopshop.com
Uggtopshop.org
Uglyugg.com
Usugg.com
Wholesalemarket168.com
Wiresea.com
World-credittrade.com
Chighdwholesale.com
Pickuggshops.com
Adphil.com
Inshout.com
Timoton.com
Tomitt.com
Tribudd.com
Wifell.com
Ghdonsaleh.com
Ghdsaley.com
Ghdstore2010.com
Mbtsalea.com
Mbtsaleb.com
Mbtstorea.com
Uggonlinei.com
Rseeting.com
Torpalis.com
Daxitymb.com
Quoines.com
Cheratic.com
Clarbt.com
Punnin.com
Sconect.com
Skeptor.com
Ectomor.com
Risoton.com
Expiage.com
2010ugg-uk.com
Branduggonline.com
Chi-chioutlet.com
Chi-store2010.com
Chi-topshop.com
Chivipstore.com
Ghdbrandstore.com
Ghdmylove.com
Masaiantishoes.com
Mbtuk-outlet.com
Mbtuk-outlet.net
Mbtus-outlet.com
Mbtus-outlet.net
Mbtus-store.com
Myuggstreet.com
Outlet-northface.com
Outlet-uggs.com
Outletchi.com
Sparknew.com
Specialuggstore.com
Uggbranchshop.com
Uggbranchstore.com
Uggchainshop.com
Uggcredibleoutlet.com
Uggdirectshops.com
Uggflagshipstores.com
Ugghigh-leveloutlet.com
Uggoutlet-aus.com
Uggoutlet-branch.com
Uggreliantoutlet.com
Uggschain-store.com
Uggsoutletstore.com
Uk-uggs-outlet.com
Discountbrand-online.com
Discountshop-online.com
Monclercoatsite.com
Supermoncler.com
Branduggline.com
Specailuggstore.com
Uggchain-store.com
Ugghigh-lveloutlet.com
Fashiontruereligion.com
Maxchausures.com
Bellasinteractive.com
Ghcanada.com
Dishroe.com
Issector.com
Elisegm.com
Telyware.com
Blasteriox.com
Barathr.com
Pnewum.com
Rasuma.com
Enyki.com
Pravendita.com
Nmtsm.com
Smtpst.com
Admt2.com
Huciv.com
Bexbyz.com
Hiehost.com
Mainsyql.com
Xbevs.com
Niklip.com
Aisviv.com
Hiskweb.com
Debtsle.com
Hornium.com
Liegan.com
Phillacy.com
Sulandry.com
Cathypo.com
Colpint.com
Doxoni.com
Pegbow.com
Margant.com
Examah.com
Leastive.com
Pierran.com
Togueno.com
Honettee.com
Ophori.com
Mattoft.com
Rogloard.com
Epholo.com
Veraph.com
Landsm.com
Rismit.com
Velmace.com
Dedicot.com
Requild.com
Atstatec.com




    nl-position.com fake job offer

    In what appears to be an update of this fake job offer, there is now a spam run soliciting replies to nl-position.com for "representatives" who will most likely be handling stolen money and goods.

    Date: 3 September 2010 06:30
    Subject: Welcoming speech

    Dear Sir/Madam!

    The Company would like to offer you extra opportunity to get part-time position.
    Today we open offices in some countries of Europe and need "Representatives".

    Responsibilities:
    - Work with clients and partners
    - Collecting information
    - Paper work
    - Online monitoring

    Principle of work:
    - Home office position

    Salary:
    - 60.000 euro per year + bonuses for transactions

    Minimal requirments:
    - Location: Holland
    - Age: +23
    - Secondary education
    - Responsibility

    Wait for your applications to the following address: cv@nl-position.com

    Do not hesitate to contact us and know more.
    Look forward to your applications!

    Best wishes!

    Don Tennant
    Manager of HR department


    The nl-position.com was registered just three days ago to a no doubt fake address:

    Julia Morgan
        Email: info@JuliaNewYork76.com
        Organization: MDS LTD
        Address: 201 Varick Street
        City: New York
        State: NY
        ZIP: 10014
        Country: US
        Phone: +1.8668402756 

    The name servers are ns1.nameself.com and ns2.nameself.com, both based in Russia and commonly used by scammers. Unusually the JuliaNewYork76.com domain is also fake. Both domains have their mail handled by Google.

    These other domains also seem to belong to the same crew, any "job offer" from them can safely be regarded as bogus:

    ca-position.com
    es-position.net
    europ-position.com
    gb-new-position.com
    ms-positions.com
    nl-position.com
    east-europ.com
    inc-europ.com
    it-europ.net
    north-europ.com
    pt-europ.com
    uk-europ.com
    trabajo-europ.com
    west-europ.com