PDA

Click to See Complete Forum and Search --> : Another Email Scam


HTRegz
February 12th, 2005, 04:31 AM
Hey Hey,

When I first suggested this forum, one of the things I said I envisioned was a repository of Phishing Attempts and Scams..... this was met with both positive and negative feedback and left me debating how to deal with it. I personally would like to see every scam.... every phish show up in this forum... Be it a single thread or multiple threads... So I'm going to make an attempt to start that sort of repository here... If it fails, I'll abandon it (or create a single thread to catalogue all the attempts)... but for now let's see what happens with this.


Mail Headers
Return-path: <vaslam_williams@virgilio.it>
Envelope-to: ht@XXXXXXXXX
Delivery-date: Fri, 11 Feb 2005 10:43:33 -0500
Received: from vsmtp3alice.tin.it ([212.216.176.143] helo=vsmtp3.tin.it)
by epsilon.main-hosting.com with esmtp (Exim 4.44)
id 1CzcxA-0005Ll-46
for ht@seeminglyrandom.info; Fri, 11 Feb 2005 10:43:32 -0500
Received: from ims2c.cp.tin.it (192.168.70.102) by vsmtp3.tin.it (7.0.027)
id 420C747D000359A8; Fri, 11 Feb 2005 16:40:17 +0100
Received: from [192.168.70.226] by ims2c.cp.tin.it with HTTP; Fri, 11 Feb 2005 16:40:16 +0100
Date: Fri, 11 Feb 2005 16:40:16 +0100
Message-ID: <4200073C0008CA41@ims2c.cp.tin.it>
From: "Mr.Vaslam Williams" <vaslam_williams@virgilio.it>
Subject: I WAIT TO HEAR FROM YOU MY FRIEND
Reply-To: vaslamwilliams@hotmail.com
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-15"
Content-Transfer-Encoding: quoted-printable
X-Originating-IP: 213.255.218.243



Original Message
Name: Williams Vaslam
Phone:(24 hours): 234-8035213929
Email:vaslamwilliams@hotmail.com

I am the chairman of the contract award committee of the oil ministry here in Nigeria, for security reasons, I may not wish to disclose how I got your email address for now.

After due deliberation with my partner, I decided to Forward to you this business proposal, we want you to assist us receive the sum of Thirty eight million, six hundred thousand united state bills (us38.6m) into your account.
This fund resulted from an over-invoiced contract awarded by us under the budget allocation to my ministry and the bill was approved for payment by the concerned ministries.The contract was executed, commissioned and the contractor was paid his actual cost of the contract. Now, we are left with the balance of us38.6m as the over invoiced amount, which we have deliberatelyover estimated for our own use. Please note that the law forbids civil servants to operate or own foreign accounts hence this contact, we have agreed to share the money in the following percentages:30 for you, 60 for us 10 for tax as may be required by your government.

Note that this transaction is very much free from all sorts of risk hence the business was carefully planned before it was successfully executed and we the officials involved in the deal have put many years in service to our ministry. We have been exercising patience for this privilege for so long not until the presidential announcement last week, that all foreign contractors owed be paid forthwith, this will enable the presidency reconcile our debt ratio with the outside world and to most of us, this is a lifetime blessing we cannot afford to miss. Upon indication of your interest to fully co-operate with Us, a payment application/information form will be sent to you via email for completion.

Note that the following information: a) banker?s name and address, b) account number and account name and c) your private phone number and email address will enable us seek/secure approval of the fund from the Concerned government quarters/ministries within 3-4 banking days.

As soon as we confirm receipt of this money in your nominated bank account, my partner and I will come over to your country to arrange for our own share and possibly invest part of this money in your country.

Let honesty and trust be our watchword throughout this transaction. I shall furnish you with some details about myself. Your prompt reply will be highly appreciated.

Best regards,

Eng Williams Vaslams.


I'm also curious to see what happens as I sent this response:


Hello,

I'm very interested in your proposition, however since I will be taxed much higher than 10% I don't believe the 60:40(30:10) split is fair... I'd like to see a more even 50:50 split, if this is going to work.

HT


Anyways, we'll see what happens....


Peace,
HT

zencoder
February 12th, 2005, 06:36 AM
LMAO, I love how you respond to the message. ;)

HTRegz
February 12th, 2005, 06:29 PM
Hey Hey,

I've gotten a response now :)


Mail Headers
Return-path: <vaslamwilliams@hotmail.com>
Envelope-to: ht@XXXXXXXXXXX
Delivery-date: Sat, 12 Feb 2005 08:54:12 -0500
Received: from bay15-f14.bay15.hotmail.com ([65.54.185.14] helo=hotmail.com)
by epsilon.main-hosting.com with esmtp (Exim 4.44)
id 1Czxit-0000VE-Dp
for ht@XXXXXXXX; Sat, 12 Feb 2005 08:54:11 -0500
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
Sat, 12 Feb 2005 05:54:00 -0800
Message-ID: <BAY15-F142AC854F1BDAC87122389C3680@phx.gbl>
Received: from 81.199.108.12 by by15fd.bay15.hotmail.msn.com with HTTP;
Sat, 12 Feb 2005 13:53:18 GMT
X-Originating-IP: [81.199.108.12]
X-Originating-Email: [vaslamwilliams@hotmail.com]
X-Sender: vaslamwilliams@hotmail.com
In-Reply-To: <MC6-F23jCjWEF0HG0an0002f434@MC6-F23.hotmail.com>
From: "Williams Vaslam" <vaslamwilliams@hotmail.com>
To: ht@computerdefense.org
Bcc:
Subject: I WAIT TO HEAR FROM YOU
Date: Sat, 12 Feb 2005 14:53:18 +0100
Mime-Version: 1.0
Content-Type: text/plain; format=flowed
X-OriginalArrivalTime: 12 Feb 2005 13:54:00.0504 (UTC) FILETIME=[4DF2F380:01C5110A]



Original Message
DEAR FRIEND, [H.T]


I UNDERSTAND YOUR WORRY, BUT YOU MUST UNDERSTAND THAT THIS DEAL DOES NOT BELONG TO ME ALONE. SOME OTHER GORVERNMENT OFFICIALS ARE ALSO INVOLVED IN THE DEAL.

THAT NOT WITHSTANDING, OUR MAIN WORRY IS KNOWING YOUR ABILITY TO [1] , HANDLE THIS TRANSACTION WELL WITH OUT SHAKING [2] , KEEP THIS TOP SECRET EVEN FROM YOUR WIFE AND BEST FRIEND IF POSSIBLE. [THIS IS BECAUSE WE ARE STILL SERVING UNDER THE GORVERNMENT AND IF DISCOVERD, MIGHT HAMPER OUR FUTURE AND POSSIBLY LAND US IN JAIL]

FINALLY, WE SHALL ENSURE THAT ALL THE NECCESSARY DOCUMENTS ARE LEGALLY PROCURED IN YOUR FAVOUR TO AVOID HITCHES. WE ARE READY TO CO-OPERATE WITH YOU BUT SHOW US YOUR ABILITY AND SINCERITY BY GIVING US ALL YOUR DATA. AS SOON AS THIS IS DONE ,YOU SHALL HAVE MY PASSPORT AND MY HOUSE ADDRESS INCLUDING ALL RELEVANT IMFORMATION ABOUT THE TRANSFER.

I SHALL BE HAPPY TO HEAR FROM YOU SOON AS TIME IS NOT OUR FRIEND

REGARDS

WILLIAMS VASLAM.


Note the difference in the email address (replay-tos) and also the originating IPs... Both originating IPs however, according to AOs IP Locator, are in the Netherlands.

Any opinions on how I should procede?

Peace,
HT

MrLinus
February 12th, 2005, 06:34 PM
a) banker?s name and address, b) account number and account name and c) your private phone number and email address will enable us seek/secure approval of the fund from the Concerned government quarters/ministries within 3-4 banking days.

Get someone to play this. ;) So when they complain about the fact that the "money" didn't go through you can say that the banker wants in.. :D

HTRegz
February 12th, 2005, 06:38 PM
Hey Hey,

That would be humerous... however, I first need a bank account... Anyone got one they want to donate?

HT

Soda_Popinsky
February 12th, 2005, 07:13 PM
HT- I may write a tutorial on this...

For now, they will want a few things eventually.

License
Address
Tel and Fax
Bank info


Heres how you respond. Google images for a license, change the photo and addy info in photoshop. For an address, make up some BS. They won't check the addy because they won't use it, it's too personal for them too. Tel and Fax, go to k7.net for a transparent number. Bank info, tell them you are setting up a "joint charitable account". If they ask why the doc is so simple, tell them it's very quick and transparent for the benefit of the transaction and that charity accounts are great for this sort of thing. Or whatever.

Edit- to be interesting, tell them to print and hand write the "Joint" section, and scan and return it. It really wastes their time. The whole point of this is to waste time. Just wait until they have their "lawyer" contact you... and their "mom" and their "foo" and their "bar" too.

If you haven't asked them for proper identification yet, get movin! They'll send you all kinds of crap if you request it, just play it cool and waste their time so they can't hurt others.

I'm working 7 419 scammers, 2 tsunami scammers, and 1 lottery scammer right now, only 2 are any interesting right now. If they turn out good I'll post them.



PS Don't send word docs, they contain some info about you in the metadata. Be careful with other software too.

edit: virus check everything... they want bank info, I haven't seen it yet but I bet one of these punks will try a jpeg vuln on me ;)

HTRegz
February 12th, 2005, 07:43 PM
Hey Hey,

I've got the a K7 number... anyone got any suggestions for a decent sounding message?

Peace,
HT