• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

Post up and share your examples of spam phishing emails messages #scamaware

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Now this one's a first for me, just arrived. The linky was to a zip file that no doubt would have contained something juicy inside.

    I've not used faxes in over 10 years!
    INCOMING FAX REPORT : Remote ID: 973-899-3996
    From: Incoming Fax <no-reply@flamingparrot>
    To: flamingparrot
    Date:
    28/05/2014 15:53
    ************************************************** *******
    INCOMING FAX REPORT
    ************************************************** *******

    Date/Time: Wed, 28 May 2014 09:10:04 GMT
    Speed: 4839bps
    Connection time: 03:04
    Pages: 7
    Resolution: Normal
    Remote ID: 973-899-3996
    Line number: 6
    DTMF/DID:
    Description: Internal only

    To download / view file please click here

    ************************************************** *******

    Leave a comment:


  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Phishing email of the day. I've never had an account with the Nationwide and, by the looks of it, neither have they! :lol: :lol:
    Dear Nationwide Account Holder,

    There is a pending Credit payment into you account from our account department for security reasons invalid records we would require you to confirm your account status and profile on file with us before this transfer can be completed.

    This can be done in 2 simple steps using the reference provided below.

    Confirm Incoming Payment - Linky went to steadcraftdulcimers.com/wp-includes/js/jcrop/default.php

    Please accept our apologies for any inconvenience this action may have caused

    Yours sincerely,
    Online Customer Service

    Leave a comment:


  • leclerc
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    I regularly get emails from overseas addressed to "Professor" and my full name. I would add that I work at Cambridge University so it goes direct to my email addy. Had they bothered to take not of the english word for "Domestic Staff" they might work out that I might be a professor of Flash(not the weirdo type) and I might be able to teach the duster a few things but I am definitely not a "Professor".

    I'm currently getting spam telling me about the fact that I am due in court in various states of the US which is SPAM.

    I'd post em up but I just delete them without looking.

    Leave a comment:


  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Originally posted by Tools View Post
    You have send me a link to that one, pleeeease
    Are you asking me to send you the email address of the email I posted above? Or was this addressed at CrazyCouncil? :confused2:


    Below is today's latest installment, it was headed URGENT BUSINESS FROM SPAIN.

    Dear Friend.,

    I am Cristian Balcells an Attorney at Law, working with the above named law firm in Barcelona, Spain.

    Initially, I tried to contact you through an email but it returned undelivered probably due to incomplete address; hence I decided using normal letter posting as the only option unexplored.

    I am writing to notify you of the INVESTMENT PROPOSITION of Firas Tlass, son of Mustafa Tlass, the former defense minister under Hafez al Assad – who defected on 12 March 2012 to Paris.

    My client Firas Mustafa Tlass, is a Syrian business tycoon and a member of a significant Sunni family who had close relations with former Syrian President Hafez al-Assad, but defected to the Syrian opposition during the Syrian civil war.

    He has surplus funds for investment in the amount of twelve million; five hundred thousand United States Dollars (US$12.5 Million) currently kept under trust with a financial institution in Spain. This institution will be made known to you if you deem my proposal satisfactory.

    We are compelled to taking this step as the present regime in Syria is presently hunting the investments of both civilians and military personnel who have lost fate with the BASIR Al ASAD government.

    Now that my client is presently on political asylum in France, there is little or nothing he can do to handle huge investment funds as because of corruption probes of associates of the Bashir Al Asad Regime abroad.

    It is in this regard that I decided to solicit your assistance, by presenting you with this investment proposal so that you can be appointed as the investment partner of Firas Mustafa Tlass who will take possession of the deposit in Spain for onward investment in any viable business in any part of you world that you deem safe.

    NB: This transaction is very confidential and 100% risk free as I prepare the Investment Management Agreement and proper letter of authority backed by affidavit of change of beneficiary to enable you act as the manager of the deposited funds in Spain.

    This transaction shall be executed under legitimate and legal procedures that will protect you from any breach of both local and international Laws.

    Therefore, do not hesitate to revert back to me, either via fax or email, with the following details if my proposal interests you: A signed copy of this letter, reconfirmation of your address, your telephone and fax numbers.

    Best regards,
    Cristian Balcells
    Abogado(Attorney At Law)

    Leave a comment:


  • Tools
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    You have send me a link to that one, pleeeease

    Leave a comment:


  • Crazy council
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Flaming porrot....... I am soooo tempted to contact them thats in yours..... I love 419ers.... I dont get sent them anymore..... 9*out of ten 419ers are traceable. Becuase
    1. They all used hacked versions of windows ( could teach my dog to acsess remotely )
    2. There are inherently stupid and are money drunk...
    3. They generally have no idea how to secure there own systems... i love phone number on scam mails..

    I watched a live hack on one of these last year and was side splittingly funny.... A call was made, a loaded email was sent to them, the fools opened the email, acess was gained to the camera on the laptop while the guy was on the phone., and acsess to the router that they were all connecting with.. :tinysmile_aha_t:

    Shininigans was the order of the day... after a few days of playing with them,, and getting there data... we flashed an Mi5 notice across there screens, with there pictures, a google map of were they were, telling them that operatives were on route.... and watching there faces through there inbuilt webcams was making it hard to get air we was laughing so much.....

    Leave a comment:


  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    I am Mr. Algoth Cyprian, an Accountant with Lloyds Bank, I am the personal Account Manager to Late Mr. Enevald Helmut.

    On the 21st of April 2008, Mr. Enevald Helmut (Herein after shall be referred to as my client), his wife and their two children were involved in a car accident in London. Unfortunately they all lost their lives in the event of the accident, since then I have made several inquiries to locate any of my client's extended relatives, this has also proved unsuccessful. After these several Unsuccessful attempts, I decided to trace his relatives over the Internet, to locate any member of His family but of no avail, hence I contacted you to stand as his next of kin.

    I contacted you to assist in repatriating the money in addition, property left behind by my client before they get Confiscated or declared unserviceable by the bank where this huge deposits were lodged. Particularly, Lloyds Tsb Bank Plc, where the deceased had an account valued at about Six hundred thousand Great British Pounds. Consequently, the bank issued me a notice to provide the Next of Kin or have the account confiscated within the next twenty official working days.

    Since I have been unsuccessful in locating the relatives for over 2 years now I seek your consent to present you as the next of kin of the deceased based on the fact that you are a foreigner so that the proceeds of this account valued at about six hundred thousand Great British Pounds can be paid to you and then you and I can share the money. 50% to me and 40% to you, while 10% should be for expenses or tax as your government may require. An attorney will be contracted to help re-validate and notarize all the necessary legal documents that can be used to back up any claim we make. All I require is your honest cooperation to enable us sees this deal through. I guarantee that this will be executed under a legitimate arrangement that will protect you from any breach of the law.

    To enable us discuss further, I would like you to send me the following information so I can open up a next of kin file on your behalf here in the bank.

    1. Name in full:
    2. Address:
    3. Nationality:
    4. Age/Sex:
    5. Occupation:
    6. Direct Phone number:

    Best regards,
    Mr. Algoth Cyprian
    +44-703-196-3049
    Being a 'foreigner' automatically makes me the deceased's next of kin! msl: msl: msl:

    I wonder how he found that out... :confused2: :noidea:

    Leave a comment:


  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Originally posted by Tools View Post
    They seem to hack a lot of vulnerable wp sites or just random sites with easy server access, the last zip file I safely unpacked even included a list of IP's which if detected went straight to a " **** You! " page, obviously they have a few Law enforcement Ip's stashed away too
    Originally posted by Crazy council View Post
    Sorry for the long post but i just though some of you might be interested in how the mechanics of these scam emails actually work and how they are done.

    The people that have done the above, have don it so all there traffic initially goes through a legitimate site, thus avoiding spam servers, and thats why such obvious scam mail like this dont get noticed by the servers as spam..... becuase there route is a known legit one
    One of the servers I use was hacked in November 2012, via Wordpress. I had some sites I'd set up just as demos that I wasn't really worried about so I'd left the login as 'admin'. They went through one of them and injected code into several web pages, causing them to automatically redirect to spammy sites. The hosting company contacted me, asking me to clean or remove certain files, only when I went through the cPanel file manager, there were no files there! :scared: It turns out they had removed permissions after receiving complaints about the sites, only they went too far and removed my permissions too. It was all sorted and they've not been hacked since, however, that particular hosting company disabled all WP logins on and off last year. :mad2:

    The sites were hacked by international spammers, sites redirected mostly to Russian sites.

    Leave a comment:


  • Crazy council
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Wp is great but people dont update it regularly, and some of the widget get hijacked. Older versions of WP you can inject code to escalate privileges easily, and i can graft a google search to find 100s of vulnerable sites, run an injector against them ( i dont and would not do that ), then any pc that has IE uppached that visits it, is open to whatever i want to driveby-install..... thats the easyest way to build up a bot army ( i dont do that )....... Thats what i look through the scam mail for.... people trying to build botnets....so i can have a nose around...... :tinysmile_twink_t2:....

    he last zip file I safely unpacked even included a list of IP's which if detected went straight to a " **** You! " page, obviously they have a few Law enforcement Ip's stashed away too
    so funny, i have seen code with specific messages to law enforcement departments in america, taunting them... the more modern ones pull an IP avoid or attack lists from servers just prior to attack.. thus being impossible to understand what its trying to attack prior the attack starting, unless you can find the feeder server,
    Last edited by Crazy council; 26th May 2014, 20:23:PM. Reason: adding stuff

    Leave a comment:


  • dogtired
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Had two in junk one of the "notice to appear" identical to one posted earlier.
    The other an invite to invest in " a new oppertunity to invest in web design"
    Sorry not worked out how to post or copy here.
    Reported to e mail host and deleted

    Leave a comment:


  • Tools
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    They seem to hack a lot of vulnerable wp sites or just random sites with easy server access, the last zip file I safely unpacked even included a list of IP's which if detected went straight to a " **** You! " page, obviously they have a few Law enforcement Ip's stashed away too

    Leave a comment:


  • Crazy council
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Apparently i have a voice mail,:tinysmile_aha_t: just need to unzip this dodgy file first. BUT I WENT DIGGING

    You have a new Voice Message!Sender: +07768 101341
    Date: 2014.05.24 15:24:17 UTC
    ID: 2014.05.26_D244413DC



    voice_message_2014.05.26_D244413DC.zip (101 KB)

    Archive Name: voice_message_2014.05.26_D244413DC.zip
    Archive File Size: 75647 bytes
    File Count: 1 file

    Attributes Size Modified Date Method Ratio
    --------------------------------------------------------------------------
    ---- 119296 26-May-2014 15:24 Deflated 63.1%
    --------------------------------------------------------------------------
    The email source shows sender %%%%%@leandergroup.co.uk.spam.spam

    But, the website looks legit, a building services co, name registered in 2005 and the whois looks legit........

    mmmmm, me thinks, apart from very old virus in the ZIp, why would they point to a legit site.... Then i looked at the source code for the site...

    <link href="style/patches/patch_sliding_door.css" rel="stylesheet" type="text/css" />
    <![endif]-->
    </head>
    <body>
    <p style="position:absolute; left:-2250px; top:-1150px;">We provide services in <a href="pamspamspam" title="replica handbags"><b>replica handbags</b></a>,We work closely with <a href=pamspamspam" title="rolex replica uk"><b>rolex replica uk</b></a>,We have the ability to offer <a href=pamspamspam" title="replica watches"><b>replica watches</b></a>,2014 new products come,please visit <a href=pamspamspam title="2014 new replica watches">replica watches</a>,Buy good exact Swiss <a title="replica watches" href=pamspamspam"><strong>replica watches</strong></a> ,uk replica watches online store,please visit <a href=pamspamspam>replica watches</a></p>
    <div id="page_margins">
    <div id="page">
    <div id="header">
    <div id="title" class="center">
    Further down the page, there are about 20 other links like this

    <a href=----deleted spam -->louis vuitton outlet</a>
    And i bet the site owners dont know thats been injected in there....

    am just having a look around the site because the source of the email has what looks like a hook in the return address, and am looking through the source of all site pages to find the trigger.......so i can follow it...... :doggieyes: am using a secure browser, i would not visit that site with IE, the exploit on the fist page is for IE browser only.....

    Sorry for the long post but i just though some of you might be interested in how the mechanics of these scam emails actually work and how they are done.

    The people that have done the above, have don it so all there traffic initially goes through a legitimate site, thus avoiding spam servers, and thats why such obvious scam mail like this dont get noticed by the servers as spam..... becuase there route is a known legit one
    Last edited by Crazy council; 26th May 2014, 19:20:PM. Reason: left spammy links in by mistake

    Leave a comment:


  • FlamingParrot
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    Dear Customer,

    Suspicious Debit Card Activity,
    We have suspended your natwest debit card.Follow the link below to verify your account with us before your debit card can be re-opened for use.

    Verify Your account immediately.
    Thank You,

    NatWest Security Department.

    Linky removed by me but went to: romannoti.com/wp-content/themes/twentytwelve/inc/wp.htm. Obviously a subsidiary of NatWest! msl: msl: msl:

    Besides, my only association with NatWest would have been to have been working next to Tower42 until 2003!:rofl:

    Leave a comment:


  • Crazy council
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    hi

    DDoS ?
    .

    that just annoys people and only really any use on sites that take payments or have large amounts of visits, but was fun for the likes of playstation/paypal ect.

    With scams like this, my friend ( cough cough ), tends to try and track down there email servers, then encrypt all there records. its the least illegal way to deal with these type people... I suppose what's more interesting for me is what type of trojans and browse hacks they are using, it sort of tells you how competent they are..... and wither they have just copied know exploits thatr are in the wild, or are buying unpublished ones......

    Leave a comment:


  • Nibbler
    replied
    Re: Post up and share your examples of spam phishing emails messages #scamaware

    May be hijacking of an innocent 3rdy party with a spoofed sender/refereces to gain limited legitimacy, to get people to open the attachment and infect their system.

    Whole thing is geared to that in the end. Which has likely nothing to do anything mentioned in the email.

    Leave a comment:

View our Terms and Conditions

LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
Working...
X