Sponsored by..

Showing posts with label Money Mule. Show all posts
Showing posts with label Money Mule. Show all posts

Thursday 20 October 2011

Fake jobs: canada-newjob.com, netherlandjobb.com and newjobrecruit.com

Another bunch of domains being used to peddle fake jobs:

canada-newjob.com
netherlandjobb.com
newjobrecruit.com

These domains form part of this long running scam. You may find that the emails appear to come from your own email address (here's why).

The domain registrant details are no doubt fake:

    Adolf Nureng
    Email: adolfnureng@yahoo.dk
    Organization: Adolf Nureng
    Address: Spellingevej 3 Ro
    City: Gudhjem
    State: Gudhjem
    ZIP: 3703
    Country: DK
    Phone: +45.70225632

The jobs offered will actually be criminal activities such as money laundering. If you have any examples of emails using these domains, please consider sharing them in the Comments. Thanks!

Here is one example:

Date: 20 October 2011 13:17
Subject: Huidige vacature

Wij werven aan!

Wij bieden part-time of full-time posities in de EU.
Momenteel is onze team van specialisten is het ontwikkelen van vooruitstrevende en innovatieve
manier van samenwerking met onze klant dus breiden we ons netwerk van vertegenwoordigers in heel Europa.

Wij bieden volledig betaalde trainingen om u te begeleiden door uw werk, competitief salaris,
vrij werk schema en andere voordelen die uw samenwerking met ons zeer aangenaam.
Wilt u bij ons bedrijf te sluiten, moet u ervoor zorgen dat u houdt de Europese verblijf
en je bezit een sterk verlangen om te werken.

Als je eenmaal hebt besloten om ons aan te sluiten, gelieve ons dan uw contactgegevens
en wij nemen zo spoedig contact met u op om een interview te plannen.

Onze contactgegevens: Rolland@netherlandjobb.com

Hartelijk dank voor uw interesse!

In this case, the email originated from 178.172.136.117 in Belarus.

Wednesday 12 October 2011

Fake jobs: it-jobsearch.com

Another fake job domain, it-jobsearch.com follows on directly from these two reported yesterday. The domain is registered to the same fake address in France as yesterday.

As usual, the email soliciting replies to this domain is trying to recruit people for money laundering. The email may appear to come from your own email address (here's why).

If you have example emails soliciting replies to this domain, please consider sharing them in the Comments. Thanks!

Tuesday 11 October 2011

Fake jobs: new-jobaccess.com and simple-jobneed.com

Two new fake job domains, forming part of the long-running "Lapatasker" scam.

new-jobaccess.com
simple-jobneed.com

Emails from these domains may appear to be from your own email address (here's why). They are registered to a no-doubt fake registrant:

Luc Metteran
    Email: lucmetteran@yahoo.fr
    Organization: Luc Metteran
    Address: 6, avenue Kennedy
    City: Paris
    State: Paris
    ZIP: 17880
    Country: FR
    Phone: +33.0156402315 


The "jobs" on offer are illegal activities such as money laundering. If you have any examples of spam using these domains to solicit replies, please consider sharing them in the Comments. Thanks!

Wednesday 5 October 2011

Fake jobs: all-cajobs.com, all-ukjobs.com and alleur-positions.com

Here we go again.. three new domains that form part of this long-running scam.

all-cajobs.coma
all-ukjobs.com
alleur-positions.com

The "jobs" offered are actually illegal activities such as money laundering. You may note that the email appears to come from yourself (here's why).

The domains are registered to a no-doubt fake registrant:

    Hose Sanches
    Email: hosesancges@yahoo.com
    Organization: Hose Sanches
    Address: Campo Grande, 83 1749-812
    City: Lisboa
    State: Lisboa
    ZIP: 1749-812
    Country: PT
    Phone: +35.1217982140

If you have any examples of emails soliciting replies to these domains, please consider sharing them in the Comments. Thanks!

Monday 3 October 2011

Fake jobs: firstjob-market.com, tech-newposition.com and ukjob-market.com

Three new fake job domains today, apparently forming part of this long running scam.

firstjob-market.com
tech-newposition.com
ukjob-market.com

Emails send soliciting replies to these domains may appear to come from your own email address (here's why). The so-called jobs being offered are actually criminal activities such as money laundering.

The no-doubt-fake registrant details are:

    Lucia Geleca
    Email: lucpolema@yahoo.fr
    Organization: Lucia Geleca
    Address: 12 rue des Camelias
    City: Alfortville
    State: Alfortville
    ZIP: 94141
    Country: FR
    Phone: +33.0148934367

Although the address is genuine, it almost definitely bogus.

If you have any examples of spam emails "from" these domains, please consider sharing them in the Comments. Thanks!

Sunday 25 September 2011

Fake jobs: hire-position.com and work-position.net

Two new fake job domains with a twist, possibly the same scammers who are behind this long-running spam/scam campaign.

hire-position.com
work-position.net

Domains were registered just yesterday via a Russian registrar to an address in Spain which is most likely fake:

    Ivan Gonsalez
    Email: ivan4gonzalez@yahoo.es
    Organization: Ivan Gonsalez
    Address: P. de Extremadura 151
    City: Madrid
    State: Madrid
    ZIP: 28011
    Country: ES
    Phone: +34.914641145 

This rabbit hole goes a bit deeper than usual, because the ivan4gonzalez@yahoo.es email address has been used before, for the domain girsland.ru

domain: GIRSLAND.RU
nserver: ns1.strategy-recruiting.org.
nserver: ns2.strategy-recruiting.org.
state: REGISTERED, DELEGATED, UNVERIFIED
person: Private Person
e-mail: ivan4gonzalez@yahoo.es
registrar: REGTIME-REG-RIPN
created: 2011.07.26
paid-till: 2012.07.26
source: TCI

Girsland.ru has a reputation for being spammy and it looks like a typical romance scam site. As with hire-position.com and work-position.net, it's odd that a Spanish address is being used for domains that are either Russian TLD or are being registered through a Russian registrar.

Girsland.ru is hosted on 173.234.8.215 at Ubiquity Server Solutions Atlanta, although it looks like the IP block might be rented out to a company called Nobis Technology Group LLC in Arizona.There are some nasty things going on in that IP neighbourhood according to SiteVet.

What else can we find on 173.234.8.215? It turns out that there's a rich vein of nastiness here.

actionfg.com - "Action Financial. All of your financial services in one place."
Chinese registrar, fake WHOIS details. Fake check scam. [1] [2]
Michael L. Walter
Michael Walter MichaelLWalter@teleworm.com
314-849-7082 fax: 314-849-7011
2523 Ash Avenue
Saint Louis MO 63126
us
NS: ns1.wapcco.net and ns2.wapcco.net

adena-job.com.
Chinese registrar, fake WHOIS details. Fake job offers. [3]
Name: Ana Bates
Organization: Ana N. Bates
Address: 789 Pinchelone Street
City: Herndon
Province/state: VA
Country: us
Postal Code: 22090
Email: AnaNBates@ymail.com
NS: ns1.needafishingboat.net and ns2.needafishingboat.net

adenafinance.com - "Adena Finance. All of your financial services in one place."
Chinese registrar, fake WHOIS details.

Eric M. Dillinger
Eric Dillinger EricMDillinger@gmail.com
+1.5305125808 fax: +1.5305125808
1467 Hill Croft Farm Road
Sacramento CA 95814
us
NS: ns1.needafishingboat.net and ns2.needafishingboat.net

arrowfg.com - "Arrow Financial Group"
Chinese registrar, fake WHOIS details. Money mule scam [4] [5]
William K. Breen
William Breen WilliamKBreen@teleworm.com
606-542-3946 fax: 606-542-3922
62 Meadowcrest Lane
Flat Lick KY 40982
us
NS: ns1.careerhiring-solutions.org and ns2.careerhiring-solutions.org

freeblogpro.org - "Surprise!!!"
Chinese registrar, fake WHOIS details. Malware distribution. [6] [7]
Registrant ID:TOD-42629838
Registrant Name:Gertrude Mcmillan
Registrant Organization:Gertrude D. Mcmillan
Registrant Street1:250 Reynolds Alley
Registrant Street2:
Registrant Street3:
Registrant City:Long Beach
Registrant State/Province:CA
Registrant Postal Code:90808
Registrant Country:US
Registrant Phone:+1.5623772946
Registrant Phone Ext.:
Registrant FAX:+1.5623772946
Registrant FAX Ext.:
Registrant Email:GertrudeDMcmillan@gmail.com
NS: NS1.SLOWSTATUS.NET and NS2.SLOWSTATUS.NET

krokodilius8.com
Chinese registrar, fake WHOIS details. Malware distribution. [8]

Richard J. Aguilar
Richard Aguilar RichardJAguilar@gmail.com
+1.2523933705 fax: +1.2523933705
3458 Green Acres Road
Swansboro NC 28584
us
NS: ns1.barcellons.com and ns2.barcellons.com

rdm-gool.net - "Surprise!!!"
Chinese registrar, fake WHOIS details. Probably malware distribution.
Lincoln P. Miller
Lincoln Miller LincolnPMiller@gmail.com
+1.4156774378 fax: +1.4156774378
813 Boring Lane
San Francisco CA 94108
us
NS: ns1.slowstatus.net and ns2.slowstatus.net

recruitarrowfg.com
Chinese registrar, fake WHOIS details. Fake job offers [9] [10]
Name: Fletcher Leach
Organization: Fletcher C. Leach
Address: 180 Deer Ridge Drive
City: Millburn
Province/state: NJ
Country: us
Postal Code: 07041
Email: FletcherCLeach@aol.com
NS: ns1.careerhiring-solutions.org and ns2.careerhiring-solutions.org

superblogonline.org - "Surprise!!!"
Chinese registrar, fake WHOIS details. Malware distribution [11] [12]
Registrant ID:TOD-42637428
Registrant Name:Ernest Thomas
Registrant Organization:Ernest R. Thomas
Registrant Street1:228 Riverside Drive
Registrant Street2:
Registrant Street3:
Registrant City:Athens
Registrant State/Province:GA
Registrant Postal Code:30606
Registrant Country:US
Registrant Phone:+1.7068186834
Registrant Phone Ext.:
Registrant FAX:+1.7068186834
Registrant FAX Ext.:
Registrant Email:ErnestRThomas@aol.com
NS: NS1.SLOWSTATUS.NET and NS2.SLOWSTATUS.NET

thebloggin.net - "Surprise!!!"
Chinese registrar, fake WHOIS details. Malware distribution [13] [14]
Justin R. Martinez
Justin Martinez JustinRMartinez@aol.com
+1.3235224026 fax: +1.3235224026
2898 Evergreen Lane
Pomona CA 91766
us
NS: ns1.slowstatus.net and ns2.slowstatus.net

yourtraveldiary.net - "Surprise!!!"
Chinese registrar, fake WHOIS details. Malware distribution [15]
Name: Paula Huerta
Organization: Paula A. Huerta
Address: 3993 Payne Street
City: Hillsville
Province/state: VA
Country: us
Postal Code: 24343
Email: PaulaAHuerta@gmail.com
NS: ns1.slowstatus.net and ns2.slowstatus.net

Querying the namesevers reveals some more domains that look worth blocking as well. In total, blocking the following related domains will probably be a very good thing to do.

actionfg.com
adenafinance.com
adena-job.com
admnxm.com
adxreport.com
arrowfg.com
barcellons.com
betononasos228.net
careerhiring-solutions.org
club-bork.com
computer-giga.net
com-watch-id2181222ooo.info
dramchinatea.net
estatediary.com
findepotdirect.com
finwizonline.com
forfreeblog.net
freebloghub.com
freeblogpro.org
freetrialmail.com
friendsadirect.com
fun-bork.com
generalcreate.net
girsland.ru
hire-position.com
hostfrontpage.com
krokodilius8.com
latinitjobs.com
needafishingboat.net
obellisk.com
ouroldfriends.com
rdm-gool.net
recruitarrowfg.com
slowstatus.net
superblogonline.org
thebloggin.net
trialreg.com
wapcco.net
workasite.com
work-position.net
yourtraveldiary.net

Thursday 22 September 2011

Fake jobs: totaljob-us.com

Another fake job offer, part of this long-running series of spam/scam emails.

From: Spam Victim
Sent: 21 September 2011 20:18
To: Spam Victim
Subject: Current Vacancy

Urgente!

Solicitamos personal de cofianza para trabajo a largo plazo en la seccion financiera.
Estudiantes, amas de casa etc...
tambien pueden conseguir trabajo en la empresa, el trabajo no toma mucho tiempo, requiere de mucha responsabilidad.

No es marqueting! Ni nada parecido.
Trabajamos con mas de 10 paises del mundo para hacer nuestras transferencias.
La empresa se dedica a hacer transferencias de dinero local y internacional.

Sus datos personales favor enviar al correo electronico: Ana@totaljob-us.com

Deje su telefono movil para que nuestro operador se contacte con usted.

En espera de sus curriculums,  Ana Sykes

The email appears to come "from" the spam victim (here's why). The domain was registered just yesterday to an "Alexey Kernel" at a fake address in the Ukraine.

Some other "reply to" addresses are:
Casandro@totaljob-us.com
Gad@totaljob-us.com
Prospero@totaljob-us.com
Martirio@totaljob-us.com
Guy@totaljob-us.com
Melvis@totaljob-us.com
Muneca@totaljob-us.com

Subjects include "Current Vacancy", "Job Offer - Flexible Hours", "Get a New Job Today", "Current Open Position", "Administrative Assistant Vacancy" and "Employment Opportunity". Oddly, the subject is in English even though the body of the message is in Spanish.

The jobs offered will be money laundering and other illegal activities. If you have any samples that are different, please consider sharing them in the Comments. Thanks!

Saturday 17 September 2011

Fake jobs: careers-consult.com, europe-career.com and usa-newcareer.com

Three new domains used to adveritise bogus jobs (which will actually be money laundering or other criminal activities)

careers-consult.com
europe-career.com
usa-newcareer.com


The approach is the same as the domains registered two days ago, and indeed this has been going on for several years. The spam may appear to come from your own email address (here's why).

If you have any sample emails using this domain to solicit replies, please consider sharing them in the Comments. Thanks!

Thursday 15 September 2011

Fake jobs: ca-jobcareer.com, uk-jobcareer.com and usa-jobcareer.com

Three new domains offering fake jobs, targeting US, UK and Canadian victims:

ca-jobcareer.com
uk-jobcareer.com
usa-jobcareer.com

The "jobs" on offer are typically money laundering and other illegal activities, and form part of this long running scam. The emails may appear to have been sent from your own account (here's why).

The domains were registered two days ago to "Alexey Kernel" in Kiev, although this is probably a fake name and address.

If you have samples of spam emails using these domains, please consider sharing them in the comments. Thanks!

Tuesday 6 September 2011

Fake jobs: allworld-career.com, greece-newcareer.com, new-joboffers.com and worldjob-career.com

Four new domains offering a variety of fake and illegal jobs, part of a very long running series of scam emails.

allworld-career.com
greece-newcareer.com
new-joboffers.com
worldjob-career.com


These fake domains have been set up to solicit replies to bogus job offers, including money laundering and other illegal activities. The emails may appear to have been sent from your own account, but this is a simple forgery and does not mean that your email account has been compromised.

The registrant details are no doubt fake:

    Alexey Kernel
    Email: johnkernel26@yahoo.co.uk
    Organization: Alexey Kernel
    Address: Kreshchatyk Street 34
    City: Kiev
    State: Kiev
    ZIP: 01090
    Country: UA
    Phone: +38.00442794512 

All these domains have been registered in the past couple of days.

If you have a sample spam with one of these in, please consider sharing it in the Comments. Thanks!

Saturday 3 September 2011

Fake jobs: usa-newcareers.com

usa-newcareers.com is another domain being used for offer fake jobs (usually criminal activities such as money laundering). Is is part of this long running scam and is essentially just a variant of us-newcareer.com registered a few days ago. The domain was registered yesterday to a presumably fake registrant.

One feature of these scam emails is that they appear to come from yourself, this is just a simple forgery and it does not mean that your mail account has been compromised. If you have any examples of spam using this domain, please consider sharing it in the comments.

Monday 29 August 2011

Fake jobs: consult-position.com, instant-job.com, newweb-career.com, uk-bestjob.com and web-newcarer.com

A new set of domains pushing illegal money laundering jobs and other criminal activities as part of this long running operation.

consult-position.com
instant-job.com
newweb-career.com
uk-bestjob.com
web-newcarer.com


Typically, these emails will appear to be "from" you as well as "to" you.. this is just a forgery and it doesn't mean that your mail is hacked.

Don't be tempted by the jobs on offer, typical positions are for money mules, reshipping scams or sometimes back-office functions such as translating emails or signing paperwork. Don't bother replying to the email as no good will come of it.

If you have an example of any emails using this address, please consider sharing it in the Comments. Thanks!

Friday 26 August 2011

Fake jobs: us-newcareer.com

Operating the same money laundering scam/spam as this batch of domains, and forming part of this very long running scam, the domain us-newcareer.com was freshly registered two days ago.

The jobs offered by anyone soliciting replies to this email address are all criminal activities and should be avoided. The spam email messages may appear to be coming from your own email address, but this is a simple forgery and it does not mean that your computer or mail account is compromised.

If you have examples of spam emails using the domain, please consider sharing them in the Comments. Thanks!

Wednesday 24 August 2011

Fake jobs: greece-career.com, il-career.com, mc-jobs.com and oae-career.com

Four new domains peddling fake jobs today, forming part of this very long running scam.

greece-career.com
il-career.com
mc-jobs.com
oae-career.com

The "jobs" offered are actually criminal activities such as money laundering. It may be that the email appears to come "from" you as well (the from address is trivially easy to fake, it doesn't mean that your machine is infected with anything).

Domains were registered two days ago to "Alexey Kernel", which is no doubt a fake name.

greece-career.com presumably targets Greek nationals, and il-career.com looks to be targeting Israelis. The other two are less clear, but our best guess is that mc-jobs.com might be targeting Macedonia (but the TLD is .mk) and oae-career.com might be the UAE and is just a typo. This continues the pattern of going after non-English speaking victims who might be fooled more easily by a scam email in their own language.

If you have any examples of this spam, please consider sharing them in the Comments. Thanks!

Thursday 11 August 2011

Fake jobs: unionhire.net, wugcareer.com and wugoffers.net

Three new fake job domains registered in the past couple of days to the fake "Alexey Kernel" registrant, forming part of this very long running scam.

unionhire.net
wugcareer.com
wugoffers.net


As before, there is a series of spam messages advertising so-called "jobs" from these companies, but in reality they are criminal activities such as money laundering.

If you have a sample email, please consider sharing it in the Comments. Thanks!


Monday 1 August 2011

Fake jobs: careers-canada.com

One fake job domain today, and the scammers seem to have shifted to a new target - Canada. This time, the domain is careers-canada.com, registered only yesterday to the fictitious "Alexey Kernel" in the Ukraine.

The standard approach with these scammers is to spoof an email "from" the target's email address (don't worry if you see this, your email account has not been compromised) and the emails offer a variety of illegal jobs including money laundering. It forms part of this long-running scam.

If you have any examples of emails using this domain, please consider sharing them in the Comments.. thanks!

Saturday 30 July 2011

Fake job domains 30/7/11

Six new fake job domains today to avoid:

allnew-careers.com
argentina-hire.com
career-lists.com
career4your.com
world-career.com
your-careers.com


The recent approach has been to spam out emails that appear to be "from" the recipient. Sometimes the emails are poorly translated into Spanish, Portuguese or Greek.

The "jobs" on offer are illegal activities such as money laundering and form part of this very long running scam that has been going on for at least two years.

The domain registrant details are fake:

Alexey Kernel
    Email: johnkernel26@yahoo.co.uk
    Organization: Alexey Kernel
    Address: Kreshchatyk Street 34
    City: Kiev
    State: Kiev
    ZIP: 01090
    Country: UA
    Phone: +38.00442794512 

Mail for these domains is being routed through mx.yandex.ru in Russia.

These job offers are completely bogus and could land you in serious trouble with the police. If you have an example email using one of these domains, please consider sharing it in the Comments. Thanks!

Friday 29 July 2011

Fake jobs: chile-hh.com, cl-joblists.com, pt-joblist.com and spain-joblist.com

Four new fake job domains today, targeting victims in South America, Spain and Portugal.

chile-hh.com
cl-joblists.com
pt-joblist.com
spain-joblist.com

These domains were all registered in the past few days. The standard email approach seems to be "from" the victim, and they are often badly translated into Portuguese and Spanish.

The "jobs" on offer are not jobs at all, they usually involve money laundering and other criminal activities. They form part of this very long running scam that has been going on for years.

Three of the four domains have a new (fake) registrant that we haven't seen before:

Alexey Kernel
    Email: johnkernel26@yahoo.co.uk
    Organization: Alexey Kernel
    Address: Kreshchatyk Street 34
    City: Kiev
    State: Kiev
    ZIP: 01090
    Country: UA
    Phone: +38.00442794512 

If you have an example email, please consider sharing it in the comments.

Thursday 28 July 2011

Fake jobs: trabajo-lista.com

A single fake domain today, trabajo-lista.com uses the same approach as yesterday's domains, again targeting Spanish language speakers with money laundering jobs and other illegal activities.

Emails will most likely appear to be "from" yourself. This particular scam has been going on now for several years.

If you have a sample, please consider sharing it in the Comments. Thanks!

Wednesday 27 July 2011

Fake jobs: chile-hh.com, cv-trabalho.com, espana-hh.com and worldjoblists.com

These domains are being used to advertise fake jobs and appear to be targeting Spanish and Portuguese speakers. They form part of this long-running series of domains associated with fake job offers.

chile-hh.com
cv-trabalho.com
espana-hh.com
worldjoblists.com


The jobs being offered are typically money laundering (lavado de dinero / lavagem de dinheiro) which are highly illegal. It is possible that some other jobs offered may be "back office" functions, including translation into local languages.

The domains are very new, registered in the past two days to:

Ricardo Lopez
    Email: ricardolip2@yahoo.com
    Organization: Ricardo Lopez
    Address: ul. Liivalaia 34-10
    City: Tallin
    State: Tallin
    ZIP: 15040
    Country: EE
    Phone: +3.726317190 

If you have any examples of mail using these domains, please consider sharing them in the Comments section. Thanks.