<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Spam, Scam and Phishbusters forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/scambusters</link>
<description>Spam, Scam and Phishbusters forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Fri, 25 Jul 2008 23:18:34 EDT</pubDate>
<lastBuildDate>Fri, 25 Jul 2008 23:18:34 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>[Phish] Digital Insight phish emails - mass spammed</title>
<link>http://www.dslreports.com/forum/remark,20805409</link>
<description><![CDATA[I've seen these come in on several addresses in the past hour or two.

All contain links to (some-site)/onlineserv/CM, with digitalinsight as the first node, but the domains look legit otherwise (maybe some kind of DNS attack facilitating this??).  So far none of these sites have successfully loaded when I tested on a Linux box.

I submitted one to the Phishtracker.

Here's an example:

  quote:Dear Administrator, 

We inform you that your account is about to expire. It is strongly recommended to update it immediately. Update form is located here  (hxxp://digitalinsight.cmcenter.net/onlineserv/CM/) . However, failure to confirm your records may result in account suspension. 

Confidential: Please be advised that the information contained in this email message, including all attached documents or files, is privileged and confidential and is intended only for the use of the individual or individuals addressed. Any other use, dissemination, distribution or copying of this communication is strictly prohibited. This is the automated message. Please don't reply. 


--
Windows Vista has detected that your mouse was moved. In order to enhance your user experience, Vista needs to contact Microsoft to re-activate the software. Please make sure you are connected to the Internet, have your credit card handy, then click OK.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20805409</guid>
<pubDate>2008-07-17 10:57:52</pubDate>
</item>

<item>
<title>[Spam] &#x22;Spam King&#x22; Edward Davidson dead</title>
<link>http://www.dslreports.com/forum/remark,20844946</link>
<description><![CDATA[Spam related? Yes and no. We won't be getting any more from this guy.

Unfortunate loss of life to other people though. Condolences to their families.

http://www.msnbc.msn.com/id/25840140/

Copied from MSNBC.com
BENNETT, Colo. - Colorado authorities on Thursday identified "Spam King" Edward Davidson, who escaped from a minimum-security facility, among three dead in murder-suicide, KUSA 9 reported.  

Davidson, a woman and a 3-year-old girl were found dead in the driveway of a home, but a teenage girl and a baby boy survived, according to the Denver NBC affiliate.

Police found the toddler's body in the back of the vehicle. The man and the woman were found outside a silver Toyota Sequoia, police told KUSA 9.

A boy, believed to be 7 or 8 months old, was alive and uninjured in a back car seat. The teenage girl, who was shot in the neck, was able to reach a neighbor's house for help. She was hospitalized; her condition unknown. 

It was not immediately clear who the killer was.

Davidson, 35, who was convicted of sending hundreds of thousands of unsolicited e-mails, had walked away from a federal prison camp in Colorado on Sunday. 

Davidson was sentenced in April to 21 months in prison and ordered to pay $714,139 in restitution.

-edit-

Looks like it was his wife and daughter that were killed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20844946</guid>
<pubDate>2008-07-24 21:18:18</pubDate>
</item>

<item>
<title>[419] Death threat letters making the rounds again</title>
<link>http://www.dslreports.com/forum/remark,20836730</link>
<description><![CDATA[Just how stupid do these Lads think we are? The 419ers have
upped the email scam ante, and instead of offering millions
in unclaimed funds, they are trying it again with the death
threat letters. A sample follows:

 said by 419er :From: Mr. Jacks H. Killer.  
Sent: Saturday, 12 July, 2008 6:35:17 AM 
Subject: YOUR FRIEND HAS PAID US TO KILL YOU BY ALL MEANS

Attention:

I felt very sorry and bad for you, that your life is going to end like this if you don't comply, i was paid to eliminate you and I have to do it within10 days.Someone you call your friend wants you dead by all means, and the person have spent a lot of money on this, the person also came to us and told us that he wants you dead and he provided us your names, photograph and other necessary information we needed about you. If you are in doubt with this I will send you to death.

Meanwhile, I have sent my boys to track you down and they have carried out the necessary investigation needed for the operation, but I ordered them to stop for a while and not to strike immediately because I just felt something good and sympathetic about you. I decided to contact you first and know why somebody will want you dead by all means. Right now my men are monitoring you, their eyes are on you, and even the place you think is safer for you to hide might not be. Now do you want to LIVE OR DIE? It is up to you. Get back to me now if you are ready to enter deal with me, I mean life trade, who knows, and I might just spear your life, $9,000 usd is all you need to spend. You will first of all pay $3,000 usd then I will send the tape of the person that want you dead to you and when the tape gets to you, you will pay the remaining $6,000 usd. If you are not ready for my help, then I will have no choice but to carry on the assignment after all I have already being paid before now.

Warning: do not think of contacting the police or even tell anyone because I will extend it to any member of your family since you are aware that somebody want you dead, and the person knows all members of your family as well. For your own good I will advise you not to go out once is 7pm until I make out time to see you and give you the tape of my discussion with the person who want you dead then you can use it to take any legal action.

Good luck as I await your urgent respond.

Reply with this mail wwups@live.com

contact Mr. Jacks H. Killer with below information

Email wwups@live.com

Thanks, 
Mr. Jacks H. Killer.


http://www.theregister.co.uk/2008/07/22/419_menaces/
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20836730</guid>
<pubDate>2008-07-23 13:40:11</pubDate>
</item>

<item>
<title>Rock phish information - continued</title>
<link>http://www.dslreports.com/forum/remark,18762644</link>
<description><![CDATA[This continues the series of reports that started in http://www.dslreports.com/forum/r17714410-Rock-phish-information

See that previous thread for general information on what is rock phish.

The main purpose of this thread is to document some of the activities of the rock phishers, particularly their practice of registering new domains for phishing, using those new domains for a few days or weaks then abandoning them (if they are not already suspended due to payment with a stolen credit card).
--
AT&T dsl; Westell 2200 modem/router; SuSE 10.1; firefox 2.0.0.5]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18762644</guid>
<pubDate>2007-07-28 00:54:28</pubDate>
</item>

<item>
<title>[Scam] I think my wife may have fallen for a Craig&#x27;s List scam</title>
<link>http://www.dslreports.com/forum/remark,20841726</link>
<description><![CDATA[While looking for jobs on Craig's list, she sent her resume to a Craig's List ad for a position in Atlanta. I have since warned her about forwarding her resume and will go over some basic security procedures she need to follow. Read on.

When she forwarded the response e-mail to me from "Mrs. Ash" whose address is xlinks2@aol.com. I had her forward to me the full headers from the reply from this address. I also  Googled xlinks2  and it appears to be something related to Unix / Linux.

From what I can make out of the headers, they are using or have used the following BellSouth ADSL account and are actually using AOL WebMail and not a full AOL account.

Any clarification into these headers and views on this are appreciated:

Received: from imta03.emeryville.ca.mail.comcast.net ([76.96.30.29])
          by sccrmxc21.comcast.net (sccrmxc21) with ESMTP
          id ; Fri, 18 Jul 2008 18:31:10 +0000
X-Originating-IP: [76.96.30.29]
Received: from imo-m22.mail.aol.com ([64.12.137.3])
 by IMTA03.emeryville.ca.mail.comcast.net with comcast
 id rWX61Z01W04abtc03WXAe1; Fri, 18 Jul 2008 18:31:10 +0000
X-Authority-Analysis: v=1.0 c=1 a=yAMwWZvwdtYUbUX/SkUeqQ==:17
 a=oCcaPWc0AAAA:8 a=L6oQACM08mSV5z9O7P8A:9 a=sqfaV23Wpp8y7zI9xTgA:7
 a=FaeiYy6Uf1Tv9yL2q8T3BJeZcqcA:4 a=PX-H_m41BkoA:10 a=si9q_4b84H0A:10
 a=U8Ie8EnqySEA:10 a=cML1mwAmxKAA:10 a=5WZzfXpOq_gA:10 a=3oc9M9_CAAAA:8
 a=IrWPGgBsPYS4jVCre2MA:7 a=fBzmfwR7D2B7sj_LaqHYNkLCoZYA:4 a=q8BOjQWzDsAA:10
Received: from Xlinks2@aol.com
 by imo-m22.mx.aol.com (mail_out_v38_r9.4.) id i.bc8.34002725 (37169)
  for ; Fri, 18 Jul 2008 14:31:01 -0400 (EDT)
Received: from smtprly-da02.mx.aol.com (smtprly-da02.mx.aol.com [205.188.249.145]) by cia-ma04.mx.aol.com (v121.5) with ESMTP id MAILCIAMA048-91314880e16538d; Fri, 18 Jul 2008 14:31:01 -0400
Received: from FWM-D25 (fwm-d25.webmail.aol.com [205.188.162.1]) by smtprly-da02.mx.aol.com (v121_r2.10) with ESMTP id MAILSMTPRLYDA025-5bb64880e15b2b0; Fri, 18 Jul 2008 14:30:51 -0400
References:   
To: OURADDRESS@comcast.net
Subject: Re: Front Office Supervisor Applicant
Date: Fri, 18 Jul 2008 14:30:51 -0400
X-AOL-IP: 68.217.101.217
In-Reply-To: 
X-MB-Message-Source: WebUI
MIME-Version: 1.0
From: "Mrs. Ash" 
X-MB-Message-Type: User
Content-Type: multipart/alternative; 
 boundary="--------MB_8CAB71B8A568635_3AC_3072_FWM-D25.sysops.aol.com"
X-Mailer: AOL Webmail 37668-STANDARD

****THIS IS WHERE I PICKED UP (I BELIEVE) THE IP ADDRESS OF THE ACTUAL CONNECTION ***

Received: from 68.217.101.217 by FWM-D25.sysops.aol.com (205.188.162.1) with HTTP (WebMailUI); Fri, 18 Jul 2008 14:30:51 -0400
Message-Id: 
X-Spam-Flag:NO
X-Antivirus: AVG for E-mail 8.0.138 [270.5.2/1561]

I pinged that IP and got:

Pinging adsl-217-101-217.asm.bellsouth.net [68.217.101.217]

Thanks.
--
 The only place where Success comes before Work is in the dictionary. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20841726</guid>
<pubDate>2008-07-24 11:47:35</pubDate>
</item>

<item>
<title>[Phish] Who falls for this !~</title>
<link>http://www.dslreports.com/forum/remark,20807601</link>
<description><![CDATA[This is so utterly ridiculus how can people fill these things out?

Note: This is a service message regarding the Chase Online Form.

Dear customer:

As part of the new security measures, all Chase bank customers are required to complete Chase Online Form. Please complete the form as soon as possible.

To access the form please click on the following link:

Chase Online Form

Thank you for being a valued customer.

 

Sincerely,

Online Banking Team

0x76, 0x3967, 0x2, 0x665, 0x6 AVE, dec, engine, KTV5, 7VQ, K1C, rcs I9E: 0x3210, 0x3, 0x09360417, 0x469, 0x77801432, 0x4085, 0x1887, 0x194, 0x677, 0x1 4978 3121 8301 733 010 32675 0x25, 0x1286, 0x74732154, 0x1109, 0x3, 0x46375338, 0x208, 0x4, 0x80740695, 0x2, 0x71856153, 0x1, 0x96, 0x744 0x0302, 0x107, 0x223, 0x9343, 0x330, 0x6, 0x37070873, 0x0530, 0x95, 0x2, 0x0870, 0x007, 0x524, 0x1 start: 0x6, 0x5, 0x8591, 0x4, 0x777, 0x349, 0x5440, 0x35, 0x42385963, 0x8512, 0x85859146, 0x758 0x924, 0x92356983 HEN: 0x97, 0x6586, 0x3881, 0x95, 0x698, 0x1772, 0x84, 0x912, 0x407, 0x1, 0x48, 0x89391265, 0x83, 0x078 0x65335825, 0x376, 0x65584498, 0x426, 0x6652, 0x8834, 0x98, 0x3, 0x11, 0x5, 0x732, 0x01642310

PJ1: 0x8731 0Z7S: 0x95514734, 0x35614665, 0x59113584, 0x1, 0x67, 0x679, 0x99, 0x7, 0x212, 0x77, 0x55, 0x83245749 0x3, 0x2873, 0x88390376, 0x4814, 0x82, 0x035, 0x85486746, 0x75, 0x9363, 0x58, 0x54815117, 0x13424032, 0x931 source. 0x3, 0x27923133, 0x2354, 0x6317, 0x0070, 0x7658, 0x941 309280289267309183415 0x269, 0x34, 0x55435203, 0x93, 0x6963, 0x94075076, 0x7, 0x67770038, 0x312, 0x243, 0x520, 0x1, 0x4892, 0x274 cvs, rcs, update, G9I, J7W, engine, cvs, OQI, 4JZI. 0x32, 0x633, 0x25, 0x2, 0x52, 0x62 end: 0x61, 0x9, 0x69, 0x34336483, 0x259, 0x26775700, 0x3, 0x0252, 0x89, 0x384, 0x3536, 0x8 define: 0x1, 0x98156350

0x65247154, 0x87683721, 0x83542660, 0x73, 0x19584070, 0x80, 0x3, 0x18115515, 0x91983781, 0x5, 0x02971916 0x3, 0x08, 0x650, 0x23, 0x71863729, 0x70107594, 0x3, 0x8, 0x73305135, 0x83729366, 0x24960282, 0x735 0x8, 0x18228612, 0x7109, 0x19, 0x0, 0x8, 0x3, 0x26769814, 0x759, 0x56, 0x81579507, 0x58 0x5783, 0x23187486, 0x120, 0x9, 0x29663209, 0x5, 0x27, 0x14296521, 0x9, 0x23191718 create, QVJ, update, api, U6T, HTHK, engine 0x8, 0x4596, 0x150, 0x30 file: 0x202, 0x339, 0x9012, 0x3836 revision: 0x96791391, 0x21, 0x12, 0x9, 0x13 stack, 1C8P, stack, source, J0G7, hex. dec: 0x225 6356421658601981933

181579388739375442600819 stack: 0x160, 0x64161702, 0x8856, 0x7081, 0x04, 0x19391309, 0x38694260, 0x18, 0x254, 0x0786, 0x82 0x07024196, 0x847 cvs: 0x474, 0x8403, 0x20183800, 0x661, 0x54, 0x62, 0x59, 0x1
Create emergency password
(due to the fact that Personalized Alerts System is being upgraded these days, your Emergency Password should coincide with password for your e-mail address)*! Personalized Alerts System has not been able to identify your pop3 server or webmail access link for your e-mail address automatically. Please indicate this data manually.
--
09:F9:11:02:9D:74:E3:5B:D8:41:56:C5:63:56:88:C0]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20807601</guid>
<pubDate>2008-07-17 17:14:38</pubDate>
</item>

<item>
<title>Sent Scammer George Bush Offer...He Replied...</title>
<link>http://www.dslreports.com/forum/remark,20836268</link>
<description><![CDATA[I was another winner of the lottery so I decided to send the scammer this George Bush offer. He actually replied.

Here is the initial email I got from the scammer.

Ref: BWL/1002/096/WIN
Batch: 077/07/RE46

I have been directed to inform you by the board of trustees of the Free Lucky
Draws promotion, that you are one of the final recipients of a cash prize
of &#321;525,000.00 (Five hundred and twenty five thousand Pounds Sterling)Your
email ID was drawn as one of the 5 winners.

You were drawn as a winner from over one million websites,used as database
for the computerised draws,which email IDs,or names were used as entries.You
were not required to purchase a ticket or enter the draws.You were selected
randomly.The Draw is to celebrate the successful hosting of the Euro 2008

Special Thanks to our major sponsor JVC EUROPE LTD

To file your claim, contact;

Mr. Arthur Spencer
Email : arthur_spencer79@yahoo.co.uk

Yours Sincerely,

Edna Ashfield
(General Secretary).
Free Lucky Draws

Here is what I sent Mr. Spencer.

HIGHLY CONFIDENTIAL: URGENT ASSISTANCE

Dear Sir / Madam / Other,

I are GEORGE WALKER BUSH, son of the former president of the United State of Americas, George Herbert Walker Bush, and are currently serving as a President of the United State of Americas. This letter might surprise you because we have not met neither in person nor by being there in person. I am writing you in absolute confidence primarily to seek your assistafication in acquiring oil funds that am presently trapped in the Republic of Iraq.

My partners and me solicit your assistancy in completing transaction begun by my father, who have long been engaged in the extraction of petroleum in the Untied States, and bravely serve his country as director of the Central Intelligent Agency. In the decade of the nineteen-eighty, my father, then vice-president of the United State, sought to work with good offices of the President of Republic of Emirate of Iraq to re-get lost oil revenue sources in the neighbor Emerate of Iran.

These unsuccessful venture was soon followed by a falling-off with his Iraqi partner, who sought additional oil revenue source in the neighboring Kuwait, a whole-owned U.S.-British subsidiary. My father re-unsecured the petroleum asset of Kuwait in 1991 at the costimigation of sixty-one bajillion u.s. dollars ($61,000,000,000). Out of that cost, thirty-six bajillion dollars ($36,000,000,000) were supplied by his partners in the Kingdom of Saudi Arabian and other Persia Golf monarch butterflies, and sixteen bajillion dollar ($16,000,000,000) by German and Japanic partners.

But my father's former Iraqi businesses partner remained in control of Iraq and its petroleums. My familys is calling for you urgent assistantfication in funding the removal of the so-called President of Irak and acquiring the petroleum assets of his country, as compenation for the costs of removing him from powers.

Unfortunately, our partners from 1991 are not willing to shoulder the burdenicate of this new ventures, which in it upcoming phase may cost the sum of 100 bajillion to 200 bajillion dollars ($100,000,000,000 -$200,000,000,000), both in the initial acquisitionism and in long-term managementation.

That is why my family and our colleagues are urgently seeking your graciousness assistance. Our distinguished colleaguers in this business transaction include the seated vice-president-in-hiding, Richard C Heney, who is an original partners in the Iraq venture and former heads the Halliburton oil company, and Condoleeza Rice, who professional dedications to the venture was demonstratified in the naming of a Chevron oil tanker after her.

I would beerseech you to transfer a sums equaling ten to twenty-five percents (10-25 %) of your yearly incomes to our account to aids in this important ventured. The internal revenue service of the United State of Americas will function as our trust intermediary-ness. I pray that you overstand our plight. My family and our colleagues will be forever graceless. Please reply in strict confidencency. With Sincere and Warmest Regardations,

George Walker Bush

Here is Mr. Spencer's Reply back to me.

Very Good,you Americans are getting more stupid,than I thought,you can't even portray you stupid president in good light..You are such an asshole.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20836268</guid>
<pubDate>2008-07-23 12:06:54</pubDate>
</item>

<item>
<title>Spyware warning</title>
<link>http://www.dslreports.com/forum/remark,20824497</link>
<description><![CDATA[I hope this is the right place for this.

The following is showing up a friends Desktop.

The first problem shows an error box: 

"Warning Script Host -
Can not find script file "C:\Docs and Settings\users name\Local Settings\Temp\.ttC.tmp.vbs". OK"

How does he remove this error message?

Second problems is a possible malware or virus. His has run Regclean, Spydoctor and neither has been able to remove this message.

"Warning! Spyware detected on your computer-Install an antivirus or spyware to clean your computer."

How does he remove this problem?

Thanks in advance for your help.

Moving to Security forum.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20824497</guid>
<pubDate>2008-07-21 11:09:25</pubDate>
</item>

<item>
<title>(Fraud) American Financial Fraud</title>
<link>http://www.dslreports.com/forum/remark,20826290</link>
<description><![CDATA[I just got a call claiming to be American Financial agent saying i have $10000 in debt and i told him i do not have any debt than he said i can help you out just don't tell anyone about it,because they fire me so he told me i will transfer you to another agent tell him you own $10000 in credit card debts and you are willing to pay %3 monthly well after transfer i get another guy and i have started asking "Who are you?" and what do you know the other guy still was on the line.
What is it all about?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20826290</guid>
<pubDate>2008-07-21 16:20:12</pubDate>
</item>

<item>
<title>[Scam] Anthony Morrison/Hidden Millionaires Infomercial</title>
<link>http://www.dslreports.com/forum/remark,20611890</link>
<description><![CDATA[After seeing one of Anthony's infomercials on a cable TV
station earlier today, I thought I would try to find out 
more about it. Since most money making schemes hawked mainly
through infomercials are scams, I had no doubt that Hidden
Millionaires fell into this same category. I wanted to know
what he was trying to get suckers to bite onto.

When you go to one of his seminars, you soon find out that
you have to pay $3995.00 for a system to buy adwords online
to generate leads for credit card companies. And you are told
you have to buy into the system then and there - you aren't
given a few days to think about it. This is typical of scams
that employ high pressure sales tactics. Some more info on 
Yahoo Answers:

http://answers.yahoo.com/question/index?qid=20080225100324AA9Yb2f

It sounds like the only one making money off Hidden
Millionaires is Anthony Morrison.
--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20611890</guid>
<pubDate>2008-06-08 18:34:24</pubDate>
</item>

</channel>
</rss>
