Sponsored by..

Wednesday 21 July 2010

Hotbar.com deceptive installation.. again.

Hotbar.com probably needs no introduction as an unpleasant piece of Slimeware, picked up from the ruins of Zango by a Washington State company calling itself Pinball Corporation. Traditionally, companies like Zango and Pinball work on a pay-per-install basis for their software, and recruit affiliates to get the software installed on end user's machines. Anyone who deals with affiliate marketing knows that the actions of your affiliates reflect on the company itself.. you don't want dodgy affiliates tarnishing your reputation.

This particular affiliate of Pinball Corporation does seem to be pretty deceptive though, targeting naive users who don't check what they are downloading properly.

Here is an example, coming up on a search for Google Earth:

The first result reads:
G.Earth Free Download
EarthI0-3D.com/GEarth-Download      New G.Earth. A True 3D Digital. Fly Anywhere On Earth. For Free!
Is earthi0-3d.com Google? Of course not! But it relies on users not to check before they click through..

Google's logo is displayed prominently on the landing page, the whole page really does look like it is from Google, but scrolling down reveals the truth.. in pale grey text on a white background to make it difficult to spot:



This website has no partnership whatsoever with the owner or manufacturer of this software program, and provides ONLY a link to the program.
New computer users should find our services valuable, and a time saver. If you are an advanced computer user, you probably don't need our services. 
Well, it doesn't just provide a link to download the program.. clicking "Free Download" reveals the payload of a mixture of HotBar, ShopperReports, Blinkx and QuestDNS adware.

..but you have the read the small(ish) print. The Google Earth logo is still prominently displayed, along with a great big "Start" button. Now, to be fair it is all spelled out in black and white with links to the EULA, but displayed in a much smaller and less prominent manner than the Google logo.

The download is pretty widely detected as adware by many AV programs. Some of the components are particularly insidious, including QuestDNS that installs all sorts of operating system hooks.

It's not just Google Earth that is targeted in this way, the server that hosts earthi0-3d.com, 174.121.90.107 [ThePlanet.com], also hosts a shedload of other domains that masquerade as well-known applications. (Sorry, it's a long list.. but there's more after it).


0perai0.com
7zip2010.com
Adaware10-uk.com
Adaware10-us.com
Adawarepro10.com
Adobereader10-pro.com
Adobereader2010.com
Adobe-readeruk.com
Adobe-reader-uk.com
Adobe-readerus.com
Adobe-reader-us.com
Ares10.com
Ar-proversion.com
Audacityi0.com
Babelfish10-uk.com
Babelfish10-us.com
Bearshare10-prodownloads.com
Bearsharefast.com
Bit10-cometpro.com
Bitcometfast.com
Bitcometi0.com
Bitcometpro.com
Biti0-latest-comet.com
Bitlordfast.com
Bitlordi0.com
Bitnewcomet.com
Bit-new-comet.com
Bitnewlord.com
Bit-new-lord.com
Century21games.com
C-new-cleaneri0.com
Convertxtodvdpro.com
Corelpaint2010.com
Descarga-activex.com
Divx10-uk.com
Divx10-us.com
Div-xi0.com
Downsoftloads.com
Earth-20i0.com
Earthi0-3d.com
Emulenouveau-fr.com
Eplig.com
Fastnewlime.com
F-frostwirei0-pro.com
Flash-playerdownloads.com
Flashplayernew2010.com
Flashplayernew-uk.com
Flashplayerpro10.com
Flashplayeruk.com
Flashplayer-us.com
Freezonlinetvpro.com
F-reviewfrostwirei0.com
Frost10-prowire.com
Frost10-wire.com
Frostfreewire.com
Frost-profrostwire.com
Frostpro-wire.com
Frost-pro-wire10.com
Frost-prowire-2010.com
Frost-review.com
Frost-us-prowire.com
Frost-us-wire.com
Frostwire10-frostdownloads.com
Frost-wire10-pro.com
Frost-wirei0-frostpro.com
Gamescentury.com
G-earthi0.com
Getactivex.com
Getdirectx.com
Getnetframework.com
Girlstar-fun.com
Googleearth10.com
Internetdownmanagerpro.com
Irfanviewpro.com
Itunespro10.com
Jetaudiopro.com
Justfree-screensavers.com
Kidstoys-fun.com
Latestopenoffice.com
Limewireeasy.com
Live-messenger-windows.com
Live-msn10-messenger.com
Live-newmessenger-promsn.com
Liveprodownloads.com
Liveprotube.com
Live-torrents.com
Livetube-pro.com
Livetvnowpro.com
Messenger10-livepro-newmsn.com
Messenger-msni0-live.com
Messenger-msn-live.com
Messengerplus-live-msn10.com
Messengerpro-live-msn2010.com
Monfirefoxonline.com
Msn10-live-messenger.com
Msn-live10-messenger.com
Msn-messenger-new.com
Msn-messenger-windows.com
Myfrostwire10.com
Myfrost-wire10-pro.com
Mylimewire10.com
Mylimewirepro10.com
Mylivelimewire10.com
Mymariobrosfree.com
Mymessenger-live-promsn.com
Mymsn-live-newmessenger10.com
Myworldlime.com
Ner0-burni0.com
Newadobe-proreader.com
Newadobe-readerpro.com
Newadreaderpro.com
Newbit-comet-2010.com
Newbitcometi0.com
Newbittornado10.com
Newbit-torrent10.com
Newcoreldraw2010.com
Newdivxpro10.com
Newfastlime10.com
Newflash-playepro.com
Newflash-proplayer.com
Newlimefast.com
Newlimefree.com
Newlimeworld.com
Newmessenger-live-promsn.com
Newoffice10.com
Newopenoffice2010.com
Newopen-proofficeuk.com
Newopen-proofficeus.com
Newovernet10.com
Newphotoscape2010.com
Newpicasapro.com
Newshareaza10.com
Newsoulseek10.com
Newutorrent-free.com
Of-suite3-officei0.com
Openi0-latest-office.com
Openoffice10-officedownloads.com
Openofficenew2010.com
Openofficenewuk.com
Openofficenew-uk.com
Openofficenewus.com
Openofficenew-us.com
Playlegends.com
Play-mario-free.com
Play-mario-now.com
Proadobe10.com
Proadobereader10.com
Proadvancedsystemcare.com
Proaudacity10.com
Probitcomet.com
Probitcomet10.com
Probitlord10.com
Procamfrog10.com
Proccleaner10.com
Proflvplayer.com
Progommediaplayer.com
Proicq2010.com
Pro-lime-wire.com
Prolivetvnow.com
Promirc2010.com
Promocion-aba.com
Pro-nero-10.com
Pro-newutorrent.com
Proopenoffice10.com
Proorbit10.com
Propowerdvd.com
Proquicktime10.com
Prosopcast10.com
Prospybot2010.com
Pro-utorrent10.com
Pro-web-solutions.com
Prowinrar10.com
Prowinzip2010.com
Proytdownloader.com
Quicknewtime.com
Quicktime10-uk.com
Quicktime10-us.com
Rankdriven.com
Schnellfirefox10.com
Seo-sem-worldwide.com
Skype10.com
Smartdefragpro.com
Speedylime10.com
Suite3-office.com
Suite-office3.com
Suite-office3.net
Suiteprooffice-2010.com
Superlime10.com
Teamviewerpro2010.com
Trilliani0.com
Ufreetorrent.com
Uklimefree.com
Uprotorrent-2010.com
U-reviewbitcomet.com
U-reviewfrostwire.com
U-reviewsuiteoffice3.com
U-reviewtorrent.com
U-review-torrent.com
Uslimewire10.com
Utorrent10-udownloads.com
Utorrent-free.com
Utorrenti0.com
Vafdrivers.com
Vafscanner.com
Vaftv.com
Virtualdjpro-uk.com
Virtualdjpro-us.com
Virtualnewdj.com
Virtual-new-dj.com
Virtualnewdj.info
Virtual-newdj-2010.com
Virtuals-dj2010.com
Vlcmediaplayerpro.com
Vlcpro-vdownloads.com
Vlc-videolan-fr.com
V-virtual-prodj.com
Winamp10-uk.com
Winamp10-us.com
Winmediaplayer-fr.com
Winmoviemaker.com
Winrar10-uk.com
Winrar10-us.com
Winzip10-uk.com
Winzip10-us.com
W-media-player.com
Wmedia-playerdownloads.com
W-media-playerpro.com
Worldlime10.com
Youfreetube-loader.com
Youlive-tube.com
You-pro-tube.com
Ytdownloader-uk.com
Ytdownloader-us.com


Most domains have some sort of anonymous registration, but not all.. and one points the finger at a company in the Canary Islands:

Company: Payments interactive S.L.U
Name: fuentes martins de souza vicente alan
Address: camino de la fallera 1
City: santa cruz de tenerife
Country: CANARY ISLANDS
Postal Code: 38789
Phone: +34669061555
Fax:
Email: daniel.hylander@paymentsint.com
We can track down paymentsint.com to a server at 67.19.106.170 [ThePlanet.com] and there are a whole load of other domains you might want to avoid too.. (another long list, sorry)

Apuestadeporte.es
Audiobooks21.com
Bestfarmvilleapp.com
Bestfarmvilletoolbar.com
Bestfarmvilletricks.com
Bestwebhostingtop.com
Casinosypoker.es
Conocer-gente.es
Debelleza.es
Deseguros.es
Easyfarmvilleapp.com
Easyfarmvilletips.com
Easyfarmvilletoolbar.com
Easyfarmvilletricks.com
Economiayfinanzas.es
Emule10-italy.com
Emule10.com
Emule2010site.com
Emulenow.com
Evonynow.com
Farmappextreme.com
Farmtipsrextreme.com
Farmtoolbarextreme.com
Farmtricksrextreme.com
Fastestbrowsers.com
Fastfirefox10.com
Firefox-us.com
Flashgames2010.com
Flashplayernew.com
Flaviocoiro.com
Freenewares.com
Freenewutorrent.com
Freeopenoffice10.com
Freewinrar10.com
Fungamesgirls.com
Generar-ingresos-extra.com
Getfarmville.com
Haiti-foundation.org
Idolnew.com
Isoftware.es
Lastopenoffice.com
Latestnewinternetexplorer.com
Megauploadpro.com
Melollevo.net
Melosllevo.com
Melosllevo.es
Mininovaonline.com
Morpheusnow.com
Msnmessenger-fr.com
Mybitcomet10.com
Mybitlord10.com
Myedonkey10.com
Myexploreronline.com
Myfirefox10.com
Myfirefoxfast.com
Myfirefoxworld.com
Myfrostwirepro.com
Mygnutella10.com
Mymorpheus10.com
Napsternow.com
Neuenfirefoxonline.com
Newadobepro.com
Newadobereader.com
Newadobereaderpro.com
Newares10.com
Newbabelfish.com
Newbearsharepro.com
Newbitcomet.com
Newbitlord.com
Newbittorrent.com
Newedonkeypro.com
Newfarmville.com
Newfarmvilleapp.com
Newfarmvilletips.com
Newfarmvilletoolbar.com
Newfarmvilletricks.com
Newfirefoxpro.com
Newfirefoxworld.com
Newgnutellapro.com
Newgoogleearth10.com
Newrapidsharepro.com
Newreaderpro.com
Newskype2010.com
Newtvidol.com
Newutorrent10.com
Newvcdplayer.com
Newvirtualdj.com
Newwindowsmediaplayerpro.com
Ofertaturismo.es
Outlet-foto.com
Outlet-sport.com
Paymentsint.com
Photofiltrenew.com
Proadobeflashplayer.com
Proadobereader.com
Prolimewirenow.com
Prowirelime.com
Qualityblogs.es
Quecompras.es
Registryscanner-pc.com
Reviews21.com
Revistatv.es
Solococina.es
Solosalud.es
Speedyfirefox10.com
Theluckyhoroscope.com
Thunderbirdnow.com
Todoinfantil.es
Topconsolas.es
Topillsreviews.com
Tuguu.com
Tvtopchannel.com
Uklimefast.com
Usfirefoxbrowser.com
Utorrentfast.com
Vafdriver.com
Virtualdjnow.com
Virtualgirlfree.com
Web-uk-hosting.com
Web-us-hosting.com
Wmediaplayernow.com

You can probably safely block these IPs and all of these sites, there doesn't seem to be anything of value here.

This is definitely a somewhat deceptive approach to installation, but it does rely on a fair degree of user stupidity too. However, any IT person will probably tell you that there are a hard core of users who really are daft enough to fall for something like this, and really the best thing that you can do it pre-emptively block the whole lot.

There is a very questionable use of trademarks here, and perhaps some of those trademark owners might like to take some action of their own...

Saturday 17 July 2010

"Pollux Enterprise Ltd" money mule scam

Pollux Enterprise Ltd appears to be a genuine company in Hong Kong. This email claims to be from Pollux Enterprise Ltd, but isn't.. it's a Money Mule scam which is basically money laundering. Email originates from 95.154.240.2 which appears to be Turkish, not Hong Kong. Avoid.

From: Pollux Enterprise Ltd pollux.recruit@gmail.comReply-To: pollux.recruit@gmail.com
Date: 17 July 2010 20:15
subject: Job and recruitment available ( Your present job not affected ).
   

If you have access to a computer, and have up to three hours spare time per-
week, would you like to work part or full time online from
home and get paid weekly? If yes, then please read carefully.
_____________________________________________________________________
ABOUT US
______________________________________________________________________
Pollux Enterprise Ltd was Established in 1999 in Hong Kong and we specializes
in worldwide export of fashion accessories, hair ornaments and fashion jewelry.
We strive to market chic and trendy accessories that intrigue fashion-conscious
ladies around the globe.

Backed by the vast manufacturing base in China and the East-West sensibility
uniquely found in Hong Kong,
______________________________________________________________________
JOB POSITION
_______________________________________________________________________
We are currently seeking part/full time employees for our ever-growing
Foreign Payment Receiving Officer. Through extensive demographic research, we
have discovered a wealth of untapped human resources that, for one reason or
another, need the freedom to work from home and consider becoming part of our company.
as part of our ongoing Multi Level Marketing Network, we seek capable individuals to work for
us as our representative.You can easily make $500 - $2,000 or more in a week by
working for us as Sub-contractor in your geographical location, you will be in charge
of collecting payment on behalf of our affiliates and Smallbusine ss organizations
that are registered under us. Note that no form of investment is needed from you and this job will take
only 1-3 hours of your time per week.
______________________________________________________________________
JOB RESPONSIBILITY
_______________________________________________________________________
The position of Foreign Payment Receiving Officer entails the following duties:
coordinate payments from our clients, receive payments which come in form of Certified
Check, process payments at your local bank, and forward 90% of funds
received to the proper branch office, as instructed.
The remaining 10% is your gratuity. Since this position
is need-based, you will have plenty of free time while enjoying a good income.
_______________________________________________________________________
RENUMERATION
_______________________________________________________________________
Ev ery assignment in form of payment received from clients, you're entitled to
10% which excludes the cost of processing western union to any regional office
accountant Also you get a monthly salary of $1500 which comes at the end of every
month, plus other incentives and benefits that accrue, which includes tax holidays.
________________________________________________________________________
INTERESTED APPLICANTS (HOW TO APPLY)
________________________________________________________________________
Interested applicants should reply with:

Full Name:-
Contact Address:-
Gender:-
Occupation:-
Phone Number(s):-
E-mail Address(Optional):-

Our Human Resource Managers can contact you via email, with further details if the management
decides you're a successful candidate.

We look forward to working with you.

NB: Ignore this mail if you are not interested in this offer.

Mr. Alfred Tsang
Unit 7-9, 6/F Yale Industrial Centre
61-63 Au Pui Wan Street, Shatin

Mystery Shopper Scam from "Shoppers Guide Ltd"

Mystery shopper scams aren't exactly rare, but they're not as obvious a scam as some others. The basic idea is that once you get roped in, then eventually the sting will come with you laundering stolen money or an advanced fee fraud. There are some details about typical mystery shopper scams here.

The spam originates from 82.128.2.21 in Nigeria.

From: ADAM SCOTT mystery.shopperonline33415@yahoo.com
Reply-To: mystery.shopperonline33415@yahoo.com
Date: 17 July 2010 15:39
Subject: JOB OFFER

Hello,

         We are a company that conduct surveys and evaluate other companies. We get hired to go to other peoples companies and act like customers in order to know how the staffs are handling their services in relation to their  customers. once we have a contract to do so, you would be directed to the company or outlet, and you would be given the funds you need to do the job(either purchase things or require services), after which you would write a  comment on the staffs activities and give a detailed record of your experience

Examples of details you would forward to us are :

1) How long it took you to get services.
2) Smartness of the attendant
3) Customer service professionalism
4) Sometimes you might be required to upset the attendant, to see how they react to clients when they get tensed.

 And we turn the information over to the company executives and they would  carry out their own duties in improving there services.

   Most companies employ our assistance when people give complains about their services, or when they feel there are needs for them to improve their customer service. your Identity would be kept confidential as the job states (secret shopper) you would be paid $300 for every duty you carry out, and bonus on your transportation allowance, and funds would be given to you if you have to dine as part of the duty.

  Your job will be to evaluate and comment on customer service in a wide variety of shops, stores, restaurant and services in your area. No commitment is made on this job, and you would have flexible hours as it suits you. We will be sending you check for any of your assignments which you will cash at your financial institution and you use the money to carryout the assignment. You do not have to use any money from your pockets. So we will provide you the money for all your assignments.If you are interested

The following information below will be needed :
Full Name:
Address (no Po Box):
City:
State:
Zip code:
Phone Number(s):
Email Address:
Age:
Occupation:

 So we can look at your distance from the locations which you have to put your service into, and your address would also be need for your payments.

Thanks.

Adam Smith
shoppers Guide Ltd
mystery.shopperonline33415@yahoo.com

Thursday 15 July 2010

"Put your PC in your pocket and use it anywhere, anytime!"

I don't normally republish press releases, but this looks pretty cool. I've used Paragon software before and it seems to do what it says on tin. What this appears to be a a fully featured VM package which consumers can use for free, so it definitely might be worth trying out..

 IRVINE, CA, July 12, 2010 – It’s time to upgrade to a new operating system, but the thought of all the unknown issues may hold you back.  What if your favourite applications haven’t been updated to work with the new OS? There may be unintentional software glitches or bugs that will damage your host computer. One solution would be to create a virtual clone of your current computing environment to test any changes or upgrades before going live on your own PC, but migration to a virtual machine might be too complex and expensive for an average home user. How do you even begin to go virtual?
Paragon Software Group (PSG), the technology leader in innovative data security and data management solutions, invites you to Paragon Go Virtual with the new easy-to-use, free migration tool created for PC users who want to work in a virtual environment without technical risk. How does it work? Paragon Go Virtual allows you to make a virtual clone of your PC in three easy steps: http://www.paragon-software.com/home/go-virtual/how_it_works.html
Availability:
Paragon Go Virtual is available for immediate download, free of charge: http://www.paragon-software.com/home/go-virtual/index.html
 Social Media:
 
 We would like you to leave us a comment here letting us know what you think about it. We value all of  your feedback on our blog  


The BBC News site sucks

I've kept schtum about the BBC News redesign for a couple of days as I suspected that my dislike of it was just because it was different from the layout that they've had for some time (I moaned about the last redesign too).

It does seem that I'm not alone though as a comment on the bottom of this Reg article indicates:

Widespread criticism of the redesign in the blogsphere over its confusing layout, unappealing appearance and the bone-headed decision to demote the prominence of sports coverage is another thing altogether.
Exactly.. the navigation used to be very simple and clear but is now a confused jumble, there's an inexplicable amount of whitespace about the place, there's a stupid panel part way down with your local news that appears to have been designed by a different team entirely, and an overall inefficient use of space with unimportant elements being too visually intrusive. It's Web 2.0 crap in other words.. hell, it's almost as bad as Sky News!

(and before anyone comments, I know that this blog template doesn't work very well in Internet Explorer either, but then I haven't pissed away stacks of public cash on it either).

More unfavourable comments here

Tuesday 13 July 2010

"Your craiglist account requires attention!!"

A fairly obvious phish:

From: noreply@craigslists.org
Date: 13 July 2010 08:29
Subject: Your craiglist account requires attention!!
   
Please follow the link bellow to avoid expiration of your Account https://www.craigslist.org/account/update

Thank you for using our services
The link in the email actually goes through your.totalinternethost.com/bb.html before bouncing to accounts.craiglist.org.postifedelta.com/icons/crg/ - I'm guessing that the domains are legitimate but their domain admin account has been hacked.

The mail itself is "from" craigslists.org (i.e. more than one list) rather than craigslist.org which is a clue, and also the subject is mis-spelled as craiglist .. usually signs that something it going wrong (and a couple of things that you could block if you roll your own mail filters).

If you click through, then you get a convincing looking login page which is an exact copy of the real thing:

This is the fake one (click to enlarge):


Fill in the login details, and the fake page harvests them and sends you on to the REAL page (pictured below) which looks identical. Presumably, victims are meant to think that their login has failed in some way.

The catch? Both the real and fake pages have an identical warning:

WARNING:  scammers may try to steal your account by sending an official-looking email with a link to a fake craigslist login page that looks like this page, hoping you'll type in your username and password.

example of valid craigslist address Look carefully at the web address near the top of your browser to make sure you are on the real craigslist login page, https://accounts.craigslist.org

The safest way to login is go to the craigslist homepage directly by typing in the web address, and then clicking on the 'my account' link.
Both fake and real pages even have a picture to show you what to look for:

On the fake page, the URL in the browser bar clearly does not match the one on the page. But how many people actually read it? Any sysadmin will tell you that there's a hard core of users who don't read or unstand warnings, and obviously there are enough of them to make this scam worthwhile.

Just for the record, these are the IPs in this particular phish:
accounts.craiglist.org.postifedelta.com 
116.12.52.25
Usonyx, Singapore

your.totalinternethost.com
64.191.40.21
Burstnet, Scranton

Sunday 11 July 2010

I received this mail "from" a contact's web mail account.. well, I say "from", it was actually a dial-up account in Nigeria (41.155.100.234 in this case).


Subject:  HELP!!!

Hello,

      I'm sending this short email with panic in my heart, the situation of things here right now seems so tensed and frighting because I'm  stranded here, apparently l was stuck here in LONDON ENGLAND with family because we were held by muggers on KENTISH TOWN ROAD  yesterday after shopping at the city mall, our wallets were taken from us which has our credit cards and bank cards in it, but we already canceled  them now, our passports were taken as well but the embassy are working on it trying to fix a way to get us an ID that will be valid for us to get  on flight back home but seems like it will take couple of days or three but right now i need a quick loan from you which is very urgent,  so we can use for our upkeep for the next 3days, l promise to pay you back, as soon as i'm back home, l give you my word on that, please email  me as soon as you get this to confirm and let me know if you can be of help.

God bless you. 

What has happened here is that the victim recently received a message from their webmail provider that said that their account might be shut down because of a lack of capacity.. and please could you confirm that it was still in use by sending back the login details. THAT gave the scammers the username and password, and then they raided the contacts to send this plea.

So.. if you receive a mail message like this, then it's a scam.. but don't ignore it, the best thing to do is tell your contact that their mail account has been compromised and that they need to change their password (if they can) and also review any banking or financially sensitive emails that they store, because it is possible that the scammers could have compromised those as well.

Dear Robert Allen and Bob Gatchel.. please shove it where the sun don't shine.

I guess it was naive of me to think that I wouldn't see any more Bob Gatchel spam, but this great big steaming turd of a spam ended up in my inbox promotion some other crap.

From: robertallen1 robertallen1@ewiadvisor.com
Reply-to: jan@multiplestreamsofincome.com
Date: 25 June 2010 04:21
subject    [Redacted], Your Mining Gold with Ebay CD At Absolutely No Cost From Robert Allen
   
 Hi [Redacted],

Robert Allen here with some AWESOME news!  I’m very excited to tell you that my good friend, mentor and online marketing expert - Bob Gatchel - just completed a brand-new program that could show you how to explode your income! 
EXPLODE MY INCOME! AWSEOME!
Do you remember me telling you how I made $94,000 in 24 hours, sitting at home on my computer?  Well … it was Bob Gatchel who made that possible!  He’s a genius when it comes to making money on the Internet. 
No I don't.. I remember someone telling me that they were watching 2Girls1Cup when their mom walked in. Was that you?

Well, Bob has done it again! 
Whatever happened to Britney Spears?

This time he’s revealing how anyone can make $300 to $3,000 a month “mining for gold” on eBay. Ebay?  Yes, Ebay!   You see … due to the recent financial crisis & this “new economy” - Ebay online auctions are in SUPER demand!  This massive demand has created a virtual “online gold rush” … and fortunes are being made because of it!   Bob reveals exactly how anyone can capitalize on this MASSIVE trend right now … even if you never participated on Ebay before!
Wow.. Bob has discovered what people have been doing on eBay for years. Buying stuff that's underpriced and reselling it for a profit! It's not as if you can just Google for ebay tips.. oh wait, maybe you can.

And here is the best part – he’s literally GIVING away this information to anyone who wants it!

That’s right; he’s going to send you the “Mining Gold with eBay” Audio program absolutely free.  I’m talking NO cost, not even shipping and handling. 
So it's a free lunch, is it?

Simply call 1-888-876-1988 and you’ll be connected with my staff that will confirm your address and rush out a copy of this audio to your door.  It’s that easy.

No thanks.

Here are a few things you can expect to learn from this amazing audio program:

• Expert secrets to making a Fortune on eBay
• How to research and analyze your competition to increase profits
• How to create a massive bidding frenzy, every time
• The art of sniping…to get what you want at the price you need
• Perfect your auction timing to maximize earnings
• How to create raving eBay fans and get 100% positive feedback
• A secret technique all sellers must know that can literally make you thousands
• And much, much more
What about "there's no such thing as a free lunch"?
So, if you’d like harness the power of eBay to add another stream of income to your life, just wait until you learn all of these incredible, cutting edge techniques!  And, the best part is that you can do this without spending ANY money upfront.
Wait... what do you mean about "without spending any money upfront"? That's not quite the same as "free" is it? That kind of implies that you send it to me for free and I have to pay for it later.
Again, all you have to do is call 1-888-876-1988 and tell my staff where you want me to send this incredible audio training program.   Don’t miss out … you’ll kick yourself if you don’t take advantage of this offer!
Dear Robert and staff: please take your incredible audio training program and send it up your arse.

To Your Massive Success!

Robert G. Allen
Wicked.

Please not that product prices and availability are limited time offers and are subject to change.  We respect your privacy.  To remove yourself from this mailing list, click http://www.ewimail.com/unsubscribe.aspx or reply to this message with “unsubscribe” as the subject line or write us at Enlightened Wealth Institute, LC, 5072 N 300 W Provo, UT 84604
Well, at least you managed to include valid unsubscribe details rather than the last Bob Gatchel crap you sent. But you know, I don't think that I'm going to confirm my email address by clicking your so-called "unsubscribe" link.

Incidentally, in the US the BBB rates this lot with a miserable D+ rating  on a scale of A to F. Hardly inspires confidence, does it?

Evil network: Pegashosting Network / pegashosting.com 178.162.135.0/24 (AS28753)

This summary is not available. Please click here to view the post.

hiring-westunion.com scam email

This scam email is recruiting people for money laundering and other criminal activities using the fraudulent domain hiring-westunion.com:

From: Molly Leary
Date: 11 July 2010 01:23
subject: Open Positions

Greetings


I’m addressing you on behalf of the HR department of a large company. Our company covers a wide range of businesses:
- real estate
– accounts opening
– undertaking services
– etc.

We need a person to fill the vacancy of a regional manager in Europe:
- salary 2.400 euro + bonus
- 2–3 working hours per day
- flexible work time


If you are ready to work as a regional manager in Europe send us the below information on email:
c v @ h i r i n g - w e s t u n i o n . c o m [please delete spaces before sending]
Full name:
Country:
E-mail:
Mobile phone-number:



Note! We are searching Europeans only!

Please, write your name and Telephone Number so that our manager could contact you and conduct an interview. 
This domain attempts to pass itself off as the legitimate Western Union company, it was registered a few days ago to what appears to be a real address but is almost definitely fake too:

Domain name: hiring-westunion.com

Registrant Contact:
   PBsoft, inc
   Harry Bishop Harry.PBishop@yahoo.com
   818372-9865 fax: 818372-9865
   2850 Luna Pl
   Granada Hills CA 91344-1644
   us

Administrative Contact:
   Harry Bishop Harry.PBishop@yahoo.com
   818372-9865 fax: 818372-9865
   2850 Luna Pl
   Granada Hills CA 91344-1644
   us

Technical Contact:
   Harry Bishop Harry.PBishop@yahoo.com
   818372-9865 fax: 818372-9865
   2850 Luna Pl
   Granada Hills CA 91344-1644
   us

Billing Contact:
   Harry Bishop Harry.PBishop@yahoo.com
   818372-9865 fax: 818372-9865
   2850 Luna Pl
   Granada Hills CA 91344-1644
   us

DNS:
ns1.pegas-dns.org
ns2.pegas-dns.org

Created: 2010-06-22
Expires: 2011-06-22

The registrar is the scammer's favourite, BIZCN.com of China. The web server and mail is hosted on 178.162.135.108 on PegasHosting Network in the Ukraine. Email originated from 201.246.77.170, an ADSL subscriber in Chile.

This is not a real job, anything that they offer is likely to be some sort of criminal activity such as money laundering, parcel reshipping and other fraudulent back office functions.

Update 19/7/10: the spam is being sent out again, now hosted on 79.119.213.2 in Romania along with  Westunionhiring.com - if you get this, send an abuse complain to the host at abuse -at- rcs-rds.ro

Wednesday 7 July 2010

Tuesday 6 July 2010

"Blackberry Storm Promotion" scam email

is fake email appears to have been created to flood an innocent party's mailbox with spam and generate unwanted phone calls (the number may well be a real one belonging to RIM in South Africa). BlackBerry / Research In Motion are nothing to do with this email, it is a hoax.. please ignore it and do not try to contact "Amanda". More on this scam here.


Subject: Blackberry Storm Promotion.


http://www.mobilegazette.com/handsets/blackberry/blackberry-9500/blackberry-storm-9500-combo.jpg
 
Dear All,

 
Blackberry is giving away  free phones as part of their promotional drive.

 
All you need to do is send a copy of this email to 8 people; and you will receive your phone in less than 24 hrs.

Please note that if you send to more than 20 people you will receive two phones.

 
 
Please do not forget to send a copy to: amanda.lee@blackberry.com
 
With Regards,

 
Amanda Lee (Marketing Manager)

Office Number: 0027 11 7838512


Evil network: AS49544 (195.78.108.0/23) / GlobalRouting.eu

AS49544 is a network with IP addresses ranging from 195.78.108.1 - 195.78.109.255 which claims to be in the Netherlands, but may actually be in the Ukraine. The WHOIS details for the range are suspect as they refer to a domain globalrouting.eu which actually appears to be a legitimate weather forecasting service. Everything about the domain registration details smells of a hijack.. I would strongly suggest that contacting ipadmin@globalrouting.eu would be counter-productive in this instance, it may even be dangerous.

Out of the /23 there seem to be exactly zero legitimate sites, many of them are involved in malware distribution. It is probably worth blocking the entire IP address range. Google's safe browsing diagnostic for the AS is damning:

What happened when Google visited sites hosted on this network?

Of the 4157 site(s) we tested on this network over the past 90 days, 96 site(s), including, for example, stimulus.nu/, turisticki-aranzmani.com/, webconsulenti.net/, served content that resulted in malicious software being downloaded and installed without user consent.

The last time Google tested a site on this network was on 2010-07-05, and the last time suspicious content was found was on 2010-07-05.

Has this network hosted sites acting as intermediaries for further malware distribution?

Over the past 90 days, we found 73 site(s) on this network, including, for example, skottles.com/, baidustatz.com/, pinalbal.com/, that appeared to function as intermediaries for the infection of 9529 other site(s) including, for example, managerz.nl/, 189ppc.com/, czonline.net/.

Has this network hosted sites that have distributed malware?

Yes, this network has hosted sites that have distributed malicious software in the past 90 days. We found 182 site(s), including, for example, convart.com/, skottles.com/, augami.net/, that infected 11610 other site(s), including, for example, managerz.nl/, forosdz.com/, 189ppc.com/.
The suspect WHOIS details for the range are:


inetnum:        195.78.108.0 - 195.78.109.255
netname:        GlobalRouting-NL-NET
mnt-routes:     SERVERBOOST-MNT
remarks:        Global Routing
remarks:        i3d rotterdam route
remarks:        for abuse please contact ipadmin@globalrouting.eu
org:            ORG-POIS1-RIPE
country:        EU
admin-c:        greu
tech-c:         greu
status:         ASSIGNED PI
mnt-by:         RIPE-NCC-END-MNT
mnt-by:         globalrouting
mnt-lower:      RIPE-NCC-END-MNT
mnt-routes:     globalrouting
mnt-domains:    globalrouting
source:         RIPE # Filtered
descr:          PI Obodovsky Ivan Sergeevich

organisation:   ORG-POIS1-RIPE
org-name:       Global Routing
org-type:       OTHER
address:        Piet Paaltjensplein 70, 3030 TZ Rotterdam, The Netherlands
e-mail:         ipadmin@globalrouting.eu
mnt-ref:        globalrouting
mnt-by:         globalrouting
source:         RIPE # Filtered

role:           GlobalRouting contact role
address:        Piet Paaltjensplein 70, 3030 TZ Rotterdam, The Netherlands
mnt-by:         globalrouting
e-mail:         ipadmin@globalrouting.eu
admin-c:        rkgr
tech-c:         rkgr
nic-hdl:        greu
source:         RIPE # Filtered

route:          195.78.108.0/23
descr:          GLOBALROUTING
origin:         AS49544
mnt-by:         SERVERBOOST-MNT
source:         RIPE # Filtered

Sites hosted on the range include:

8porn-tube-free.info
All-tube-porn.biz
All-tube-porn.com
All-tube-porn.info
All-tube-porn.net
All-tube-porn.org
Free-checker-spyware.com
Free-checker-spyware.net
Free-checker-spyware.org
Free-download-host.info
Free-porn-tube8.biz
Free-spyware-checker.biz
Free-tube-adult.com
Free-tube-porn.net
Hot-porn-online.com
Hot-porn-tube.biz
Hot-porn-tube.info
Hot-porn-tube.net
Hot-porn-tube.org
Hot-tube-porn.com
Jeasoftware.info
My-adult-tube.com
My-free-tube.com
Now-download-host.com
Now-download-host.info
Now-download-host.net
Now-download-host.org
Now-download-hosting.biz
Now-download-hosting.com
Now-download-hosting.info
Now-download-hosting.net
Now-download-hosting.org
Online-porn-tube.com
Online-tube-porn.com
Pohsoft.info
Porn-tube-adult.com
Porn-tube-free.com
Porn-tube-free.info
Porn-tube-free.net
Porn-tube-free.org
Porn-tube8-free.biz
Porn-tube8-free.com
Porn-tube8-free.info
Porn-tube8-free.net
Porn-tube8-free.org
Retdownload.info
Riupdate.info
Spyware-checker.org
Spyware-free-checker.biz
Spyware-free-checker.com
Spyware-free-checker.info
Spyware-free-checker.net
Spyware-free-checker.org
Tmclean.info
Turboshare.biz
Goodelizrl.info
Kenyeiiaiqmyrick.info
Ligiaglrrandi.info
Milionarybook.info
Mynewgf.biz
Newgetpayday.com
Nyrmurrayriaci.info
Peierqqvangelena.info
Shopiping.com
Thissdomainwassoldd.com
Enrierrarell.info
Ath8net.com
Messorg.com
Adskape.biz
Adskape.com
Adskape.info
Adskape.net
Adskape.ru
Iner.kz
Misa.kz
Zragore.info
Afran.org
Augami.net
Otilard.com
Btgwert.net
Download-host-free.biz
Download-host-free.com
Download-host-free.org
Download-host-now.biz
Free-checker-malware.com
Free-checker-malware.net
Free-checker-malware.org
Free-checker-spyware.biz
Free-checker-spyware.info
Free-malware-checker.info
Free-malware-checker.net
Free-porn-tube8.info
Free-porn-tube8.net
Free-tube8-porn.com
Free-tube8-porn.info
Jkeowq.in
Kterot.in
Ktoewp.in
Kyjoer.in
Kypync.in
Kyuorr.in
Kyuwew.in
Leotpu.in
Lkctjo.in
Malware-checker-free.org
Malware-free-checker.com
Malware-free-checker.net
Malware-free-checker.org
Uwfjti.in
Myitunesclub.com
Mytunesclubs.com
Camption.com
Icpa-network.com
Matsion.com
Newitunesclub.com
Bogleanalytics.net
Pop-under.ru
Popunder.ru
4vodka.ru
Bastion.in
Bestgoldshow.com
Favarote.com
Freeodnoklassniki.info
Fullgsmcontrol.com
Goldsdirect.com
Homeinteriorview.com
Lastingviewestates.com
Mobiread.info
Myodnoklassniki.info
Odspy.com
Odspy.net
Odspy.org
Oknolens.info
Phonereader.ru
Proguard.in
Secretodnoklassniki.com
Sexsekret.com
Shpionodnoklassniki.com
Shpionvkontakte.com
Spy-odnoklassniki.com
Spy-vkontakte.com
Spyod.com
Spyvkontakte.info
Syserror.ru
Theodnoklassniki.info
V2kontakte.info
Viewbarworld.com
Vkontaktespy.info
Vkontaktus.ru
1000-ga.ru
1000-gektar.ru
1000g.ru
1001-ga.ru
1designs.ru
5vn.ru
B2b-site.ru
Chudomira.ru
Diplom-vam.ru
G1000.ru
Gek1000.ru
Gotovki77.ru
Hombrus.ru
Images-web.ru
Imagesweb.ru
Karkas-2900.ru
Karkas4dom.ru
Kredit-russia.info
Logvian.ru
M505.net
Mnogo-vakansii.ru
Mnogvak.ru
Netpost.su
Nsvp.ru
Prdomen.mobi
Prestiged.ru
Rabota-dlya-vas.ru
Royalmall.ru
Seminartut.ru
Uznaiseo.ru
Vam-pismo.su
Vip-osobnyak.ru
Yandex-top10.ru
Yandextop10.com
Z303.net
Liveinjamaika.info
Looking4reserve.com
Antivirus-on-line.net
Updates-online.net
Widnow-scanning-online.net
Golivnik.com
Ndnsgw.net
2u-panama.com
Big-push2010.com
Digitalway10.net
Drain-brain2.com
Foxcox555.com
Grainstudy.com
Kexpex123.com
Realdream4me.com
Admikasdom.com
Formgrabb.com
Kislota2010.com
Msmsmm.com
Noloader.com
Nowm32.com
Se-code.net
Secbanking.com
The-goodlike.com
Wstat.cn

Your best bet is to block the entire IP range and/or monitor for client traffic going to it.

Thursday 1 July 2010

ultrasantifa.blogspot.com apparent Joe Job

This strange looking email plopped into my mailbox:

Date: 1 July 2010 07:31
subject: hola
   
We are european fascists ! Fight for racial purity ! Our time begins! We are strong and can build new Reich! Join to us! We call on all people visit out sites. On them you will find information about war against system! Sieg heil fascist, nordic nazi! Adresses of our sites you can see below: http://ultrasantifa.blogspot.com
Given that fascists rarely seem to advertise themselves via spam and the whole language seems over the top I thought it looked a but suspect and worth of some further investigation.

ultrasantifa.blogspot.com is (or rather was) a blog entitled "Antifa Ultras and Hooligans". Antifa means "anti-fascist", and this Russian language blog featured radical anti-fascist ideas and football, usually both at the same time. The blog linked to some other sites that might well be advocating violence, but there was certainly no way that this was a pro-fascist blog.

So, this appears to be a Joe Job and it also appears to have been successful as ultrasantifa.blogspot.com is currently 404ing. So, presumably neither Google (who hosted the blog) nor the people complaining about the spam actually checked the site..

Just for the record the email originated from 41.145.224.130, an IP address in South Africa, but I guess it's just part of a botnet-for-hire.

Sagade Ltd is still evil

I blogged about AS6851 / Sagade Ltd / ATECH-SAGADE a little while ago. A Java-based drive-by download from one of their servers brought them to my attention again.

Basically, 91.188.59.0 - 91.188.59.255 is completely evil and has no legitimate use as far as I can see. Block this range if you can. At the moment the following sites are hosted, none of which appear to be good:

AS6851
1zabslwvn538n4i5tcjl.com
Urodinam.net
A-fast.com
Td0.ru
Fgavno.ru
Kerrimckeetq.info
Marguriiexyhamlin.info
Privatetechnology.biz
Systemcodec.net
Traffcash.biz
Maiamaribeihlv.info
Fastglobosearch.com
Kimirleonarda.info
Fastprosearch.com
Nitrosearch.info
Syscodec.net
System-codec.com
Mokato.com
Viasot.com
Brenz.pl
Chura.pl
Ghura.pl
Lometr.pl
Trenz.pl
Zief.pl
Best-web-365.com
Better-web-247.com
Better-web-365.com
Better-web-777.com
My-best-web.com
Pakwer.com
Facebook-hacking.com
Hack-vk.ru
Hacked-facebook.com
Hacks-centre.com
Icq-hk.com
Icq-lom.ru
Message-history.ru
Myspace-hk.com
Polomali.ru
Twitter-hk.com
Vk-lom.ru
Vzlomaem-kontakt.ru
Vzlomaem-vk.ru
Hitstable.com
Macromediasetup.com
Dewesan.cn
Domen-zaibisya.com
Get-money-now.net
Webgetsmart.com
Webmovedesigns.com
Mediagotech.com
Networkget.com
Webgetwisdom.com
Websitecoolgo.com
Edscorpor.com
Edsctrum.com
Edsletter.com
Edsnewter.com
Edsogos.com
Edsprofit.com
Edsrise.com
Edsspectr.com
Edstofee.com
Engduates.com
Blogslivehost.in
Freeblogshost.in
Mysuperblogs.in
Freeliveblog.in
Blogs4free.in
Host4blogs.in
Freehomeblogs.in
Myhomeblog.in
Webblog4you.in
Getfreeblog.in
Blogservice.in
Freejournal.in
Billsolutions.net
Fastsecurebilling.com
Fast-payments.com
Easypayments-online.com
Billingonline.net
Manytis.com
Winepsy.com
Yourprofitclub.net
Yourerolive.com
Bombastats.com
Happyinstalls.com
Pornowars.info
Superspuperporn.com
Pornopeace.info
Smackmybitch.info
Hnarmettis.com
Mnuyetsgrr.com
Nuvolokijj.com
Smackbybitch.com
Videosite1.com
Fuck-studies.com
Ns00ns11.com
Sys-mesage.com
Syssmessage.com
Sysstem-mesage.com
Traffic-server1.org
Traffic-source.org
Traffic-source1.org
Trafficserver1.org
Trafic-source.org
Traficserver.org
Viiistifor1.com
Visiocarii1l.net
Skachivay.com
Eupharmacie.eu
Propeciacheappills.com
Allforyouplus.net
Asianrapemovies.com
Hotfilesfordownload.com
Hotquickiefuck.com
Rape-rape-rape.com
Rapepornrape.com
Sasha-blonde.com
You-porn-movies.com
Youfoundporn.com
Youpornfiles.com
Allforil1i.com
Alltubeforfree.com
Allxtubevids.net
Downloadfreenow.in
Freeanalsextubemovies.com
Freetube06.com
Freeviewgogo.com
Homeamateurclips.com
Hotxtube.in
Hotxxxtubevideo.com
Iil10oil0.com
Ilio01ili1.com
Illinoli1l.in
Porn-tube-video.com
Porntube2000.com
Porntubefast.com
Viewnowfast.com
Viewxxxfreegall.net
Xhuilil1ii.com
Youvideoxxx.com
Cern-a.com
Xbasex.com
Asspuc.com
Bux.kz
Kinorik.com
Pussylover.in
Conikor.com
Igottrafa.in
Life-dvd.ru
Maydaydom1.in
Magnabent.com
Gillestmh.com
Gillestmh.info
Indyvettes.info
Perviewguide.com
Perviewguide.info
Tesmundo.info
Todostes.info
Allhomeinfo.com
Allhomeinfo.net
Cheapsoftware.cc
Deswelt.com
Deswelt.net
Rodfirst.com
Solaruploaderz.com
Kdjkfjskdfjlskdjf.com
Stablednsstuff.com

These sites are either involved in illegal activities or malware distribution, avoid them.

Read this, install this.

Read this, install this.

FIVE STARS GOLD MINING CO. LTD

Sometimes the dangers of fraud are worse than just losing money. This particular scam email seems to be designed to tempt you to travel to Ghana, where there's a fair chance that you might be kidnapped (as happened in this case). Although Nigeria has the worst reputation for fraud and kidnap in Africa, Ghana is not far behind.

A couple of other telltale signs that this particular spam is not legitimate are that it was sent to a nonexistant email address from a computer in Japan that had been compromised with a virus.

Gold costs about $40,000 per kilo, this scam email is offering 250 kg of quite pure gold for $24,000 when the true value would be closer to $10 million. Note that if you actually do travel to Ghana to inspect this "bargain gold" then you are also effectively saying that you have at least $24,000 in cash assets in the back.. you may as well write KIDNAP ME on your forehead!


From: FROM: FIVE STARS GOLD MINING CO. LTD.)
Reply-To: 5xminingoldaccra@discuz.org
Date: 30 June 2010 19:42
Subject: FROM: FIVE STARS GOLD MINING CO. LTD.)
Attention:

we are agent to FIVE STARS GOLD MINING CO. LTD. We are located in Accra, the Capital city of Ghana. We are a certified and duly registered agent dealing with a Gold Company in the Republic of Ghana. They have mining concessions in the Kumasi region and Western Regions of Ghana.

Their monthly product is between 275kgs to 325kgs. They have over 1000MT of Gold in our Storage.

At Present, we have Commodity: Gold (AU) Nuggets in Ghana
Origin: Ghana
Quantity: 250kgs
Quality: 23+ carat
Purity: 98% ++
Price: $24,000USD
Delivery: Buyers destination.

we write to inform you that in other to proceed with our offer, we need the following information for necessary legal documentation.

1: Your Full Names.
2: Your Mailing Address
3: A scan copy of your international passport.
4: Your Direct Mobile Number.

However, you will be require to make a contingent trip to Ghana to see the Gold. Kindly let us know how many kilos you are willing to buy at this time.

We will be happy to hear your desire to doing business with us. We can assure you that we will give you an appreciable offer. your passport this week. Hope to hear from you soon.
Attach is a copy of the pictures.

Have a good day.

Mrs Joyce Kate.