<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; scam</title>
	<atom:link href="http://blog.mxlab.eu/tag/scam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Sat, 04 Feb 2012 17:44:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; scam</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Google Picasa scam</title>
		<link>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/</link>
		<comments>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/#comments</comments>
		<pubDate>Fri, 10 Jun 2011 08:49:38 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[Google Picasa]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1419</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, reported earlier regarding emails that offer an alternative to the official Adobe PDF Reader and the VOIP add ons for Skype. It now seems that Google Picasa is the next victim of the same type of scam. We intercepted a few messages with the subject &#8220;The iTunes of Photo Organization&#8221; coming for the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1419&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, reported earlier regarding emails that offer <a href="http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/" target="_blank">an alternative to the official Adobe PDF Reader</a> and <a href="http://blog.mxlab.eu/2010/09/14/malicious-spam-campaign-regarding-adobe-acrobat-2010-pdf-reader-and-voip-addons-for-skype/" target="_blank">the VOIP add ons for Skype</a>.</p>
<p>It now seems that Google Picasa is the next victim of the same type of scam. We intercepted a few messages with the subject &#8220;The iTunes of Photo Organization&#8221; coming for the email address Picture Tools &lt;megantivir@aphyet.com&gt;. This is the message:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_1.jpg" alt="" width="450" height="582" /></p>
<p>The message has a download URL in the format hxxp://aphyet.com/re.php?lnk=1203683910&amp;e=****.****@****.be. Following the link takes us to hxxp://officialversion.su/pics/1/index.asp?aff=11677&amp;camp=esp_may09hld_picasa_jun10 with the following web site:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_2.jpg" alt="" width="450" height="419" /></p>
<p>Notice the button on the right &#8220;Download Picasa&#8221; now and the mention of 24/7 support. This is very familiar and did ring a bell at the MX Lab HQ. We started to investigate the web site further.</p>
<p>We found a registration and order process very similar to the past cases with the Adobe PDF Reader 2011 and the VOIP add ons for Skype.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_3.jpg" alt="" width="450" height="347" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_4.jpg" alt="" width="450" height="345" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110610_google_picasa_5.jpg" alt="" width="450" height="399" /></p>
<p>The payment transaction appears to be processed on an unsecure HTTP connection but a look into the HTML learns us that the payment form in embedded in an &lt;iframe&gt; and the form is processed by hxxps://secure-signupway.com/p06/?siteid=6882. This domain is know for fraudulent payment processing so your credit card details will end up in the wrong hands.</p>
<p>As expected, the domain license details are protected and the domain is registered a few days ago.</p>
<pre>Domain Name: APHYET.COM 

Registrant:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Creation Date: 06-Jun-2011
Expiration Date: 06-Jun-2012

Domain servers in listed order:
    ns1.reg.ru
    ns2.reg.ru

Administrative Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Technical Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

Billing Contact:
    PrivacyProtect.org
    Domain Admin        (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note - All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676</pre>
<p>Our recommendation is not to fill in any credit card details &#8211; your credit card details will likely be abused &#8211;  and download this software. Please note that for the real Picasa you need to go to the Google web site at <a href="http://picasa.google.com/" target="_blank">http://picasa.google.com/</a>. And it&#8217;s free.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1419/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1419/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1419/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1419&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/06/10/google-picasa-scam/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_3.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_4.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110610_google_picasa_5.jpg" medium="image" />
	</item>
		<item>
		<title>Receive a bonus of 2000 € &#8211; not everything is what it looks like</title>
		<link>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/</link>
		<comments>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/#comments</comments>
		<pubDate>Sun, 03 Apr 2011 16:17:41 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[SMS scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1364</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, intercept a large spam campaign what in fact appears to be an SMS scam system. Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine. Many different subjects in the French language are being used to get some attraction: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.eu" target="_blank">http://www.mxlab.eu</a>, intercept a large spam campaign what in fact appears to be an SMS scam system.</p>
<p>Email messages are sent from no-reply-xxx@finance-magazine.eu, where the XXX stands for random numbers. The domain finance-magazine.eu is from the The European CFO Magazine.</p>
<p>Many different subjects in the French language are being used to get some attraction:</p>
<p>Une offre qou vous ne pouvez pas refuser<br />
Une opportunite unique d&#8217;une vie<br />
Faire de l&#8217;argent n&#8217;a jamais ete aussi facile!<br />
Etes-vous interesse ?<br />
&#8230;</p>
<p>This is the email content:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" alt="" width="450" height="223" /></p>
<p>The embedded URLs directs visitors to hxxp://berborso.com/c/8D1DB23B.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" alt="" width="450" height="362" /></p>
<p>On this landing page you will need to fill in your details including your mobile phone number.</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" alt="" width="450" height="468" /></p>
<p>When your details are submitted, you&#8217;ll receive an SMS with an activation code. This code needs to be filled in again on this webform together with some additional details.</p>
<p>I haven&#8217;t filled in my real phone number but I&#8217;m pretty sure that this is a complete SMS scam. I wouldn&#8217;t be suprised if you receive more SMS messages later on that are credited on your phone bill later on.</p>
<p>This domain name is registered in the Ukraine:</p>
<pre>Service Provided By: Center of Ukrainian Internet Names
Website: http://www.ukrnames.com
Contact: +380.577626123

Domain Name: BERBORSO.COM

Creation Date: 28-Mar-2011
Modification Date: 28-Mar-2011
Expiration Date: 28-Mar-2012

Domain servers in listed order:
ns1.hahray.in
ns2.hahray.in

Registrant:
Son Svan hdgi-domains@gmail.com
WATER STREET 45/54
CHRIST CHURCH, BB17056
BARBADOS
+1.24615566596</pre>
<p>Be carefull if you receive offers like this.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1364/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1364/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1364/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1364&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/03/receive-a-bonus-of-2000-e-not-everything-is-what-it-looks-like/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110403_SMS_scam_3.jpg" medium="image" />
	</item>
		<item>
		<title>Download Adobe Reader 10 Alternative scam</title>
		<link>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/</link>
		<comments>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/#comments</comments>
		<pubDate>Fri, 01 Apr 2011 05:58:20 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Adobe reader]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[PDF 2011]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1353</guid>
		<description><![CDATA[MX Lab reported earlier on regarding a malicious spam campaign regarding an offer to download and buy PDF Reader/Writer for Windows and Mac in the articles Malicious spam campaign regarding Adobe Acrobat 2010 PDF Reader and VOIP Addons for Skype and Emails offering PDF Reader 2010 lead to unsecure payment site. MX Lab noticed a new version [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1353&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mxlab.eu" target="_blank">MX Lab</a> reported earlier on regarding a malicious spam campaign regarding  an offer to download and buy PDF Reader/Writer for Windows and Mac in  the articles<a href="http://blog.mxlab.eu/2010/09/14/malicious-spam-campaign-regarding-adobe-acrobat-2010-pdf-reader-and-voip-addons-for-skype/" target="_blank"> Malicious spam campaign regarding Adobe Acrobat 2010 PDF Reader and VOIP Addons for Skype</a> and<a href="http://blog.mxlab.eu/2010/07/27/emails-offering-pdf-reader-2010-lead-to-unsecure-payment-site/" target="_blank"> Emails offering PDF Reader 2010 lead to unsecure payment site</a>.</p>
<p>MX Lab noticed a new version that will offer the latest PDF Reader. The emails have the subject &#8220;Download Adobe Reader 10 Alternative&#8221;  with the email address dailynews_dec09@m120.redmediaone.com.</p>
<p>This is the body of the email:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_1.jpg" alt="" width="450" height="591" /></p>
<p>Following the link to the web site will lead us here:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_2.jpg" alt="" width="450" height="321" /></p>
<p>When clicking on the download button we have the following screen that looks very familiar:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_3.jpg" alt="" width="450" height="325" /></p>
<p>Okay, let&#8217;s go throught the registration process:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_4.jpg" alt="" width="450" height="351" /></p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_5.jpg" alt="" width="450" height="381" /></p>
<p>The registration transactions are performed on the domain secure-signupway.com. This domain is know for fraudulent payment processing so your credit card details will end up in the wrong hands.</p>
<p>Now, this is also interesting. The domain from where the message is sent, redmediaone.com, has protected registrant details in the WHOIS.</p>
<pre>Registrant:
   redmediaone.com
   c/o Whois Privacy Service
   PO BOX 501610
   San Diego, CA 92150-1610
   US

   Domain Name: REDMEDIAONE.COM

   Administrative Contact, Technical Contact, Zone Contact:
      redmediaone.com
      c/o Whois Privacy Service
      PO BOX 501610
      San Diego, CA 92150-1610
      US
      (619) 393-2111
      whois@emailaddressprotection.com

   Domain created on 18-May-2010
   Domain expires on 17-May-2012
   Last updated on 25-Mar-2011

   Domain servers in listed order:

      NS1.DOMAINDISCOVER.COM
      NS2.DOMAINDISCOVER.COM
</pre>
<p>In the message is the download URL and an unsubscribe URL present that is handled by http://list.onemediaclick.com/. And also iin this case, the registrant details are protected.</p>
<pre>Domain Name: ONEMEDIACLICK.COM
Registrar: MONIKER

Registrant [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US

Administrative Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Billing Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Technical Contact [3559862]:
        Moniker Privacy Services ONEMEDIACLICK.COM@domainservice.com
        Moniker Privacy Services
        20 SW 27th Ave.
        Suite 201
        Pompano Beach
        FL
        33069
        US
        Phone: +1.9549848445
        Fax:   +1.9549699155

Domain servers in listed order:

        NS1.DOMAINSERVICE.COM         208.73.210.41
        NS2.DOMAINSERVICE.COM         208.73.211.42
        NS3.DOMAINSERVICE.COM
        NS4.DOMAINSERVICE.COM

        Record created on:        2011-02-14 12:05:30.0
        Database last updated on: 2011-02-14 12:05:32.93
        Domain Expires on:        2012-02-14 12:05:31.0
</pre>
<p>The web site of  Onemediaclick:</p>
<p><img class="alignnone" src="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_6.jpg" alt="" width="450" height="426" /></p>
<p>These guys are, according to the address on the site, located in Switzerland. When trying to contact them through the web form, nothing happens. The &lt;form&gt; tags are not included in the web form when looking at the source. Seems to me that this whole business can not be trusted.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1353/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1353/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1353/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1353&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/04/01/download-adobe-reader-10-alternative-scam/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_1.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_2.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_3.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_4.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_5.jpg" medium="image" />

		<media:content url="http://img.blog.mxlab.eu/2011/20110401_AdobePDF_6.jpg" medium="image" />
	</item>
		<item>
		<title>Japan earthquake exploited by scammers</title>
		<link>http://blog.mxlab.eu/2011/03/18/japan-earthquake-exploited-by-scammers/</link>
		<comments>http://blog.mxlab.eu/2011/03/18/japan-earthquake-exploited-by-scammers/#comments</comments>
		<pubDate>Thu, 17 Mar 2011 23:12:20 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[earthquake]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[Japanese scams]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1289</guid>
		<description><![CDATA[As with all major events worldwide, spammers and scammers are exploiting these events to get their message delivered into your inbox. Now with the earthquake, the tsunami and problems in the nuclear powerplants in Japan it is not different. MX Lab, http://www.mxlab.eu/, has intercepted some emails where scammers want to exploit the generosity of people. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1289&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As with all major events worldwide, spammers and scammers are exploiting these events to get their message delivered into your inbox. Now with the earthquake, the tsunami and problems in the nuclear powerplants in Japan it is not different.</p>
<p>MX Lab, <a href="http://www.mxlab.eu/" target="_blank">http://www.mxlab.eu/</a>, has intercepted some emails where scammers want to exploit the generosity of people. Here we have an example with the subject &#8220;JAPANESE EARTHQUAKE VICTIMS!&#8221;:</p>
<blockquote><p>Dear Sir/Madam,</p>
<p>I am Kasumi Umeko resident in Spain. We have other japanese families living as a community here in Spain. Our family members were severely affected by the recent Tsunami earthquake that happened in the pacific ocean that devasted Tokyo and led to the lost over 13,000 lives and properties worth billions of Dollars.</p>
<p>We implore to help the earthquake victims that lack food and shelter. We have established a distribtion channel to these victims. You can send your gifts and aids as cash by western union money transfer system to our division responsible for the distribution of food, shelter and medical assistance using the information stated below:</p>
<p>FIRST NAME: SHIZUKA<br />
LAST NAME:TADASHI<br />
ADDRESS: CALLE VELAZQUEZ 8<br />
28010 MADRID.</p>
<p>After making the payment send the payment details to the Assistance Distribution Section as stated below:</p>
<p>SENDER&#8217;S DETAILS:<br />
FIRST NAME:<br />
LAST NAME:<br />
MONEY TRANSFER CONTROL NUMBERS. (MTCN)<br />
COUNTRY:<br />
ADDRESS:<br />
Email: <a href="mailto:japvictimsesp@yahoo.co.jp">japvictimsesp@yahoo.co.jp</a></p>
<p>Thanks for your assistance to the need of humanity of the Japanese people. May God richly blessed and also expand your territory in any field of your endevour.</p>
<p>Yours truly,<br />
Susumu Takumi</p></blockquote>
<p>Now, please, do not fall for such scams. You will only transfer funds to people who have no intensions whatsoever  helping the Japanese people. When emails like this one mention &#8220;western union money transfer system&#8221; you should be very carefull and it is even better to delete the message immediatly.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1289/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1289&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2011/03/18/japan-earthquake-exploited-by-scammers/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Malicious spam campaign regarding VOIP Addons for Skype &#8211; the story goes on</title>
		<link>http://blog.mxlab.eu/2010/09/30/malicious-spam-campaign-regarding-voip-addons-for-skype-the-story-goes-on/</link>
		<comments>http://blog.mxlab.eu/2010/09/30/malicious-spam-campaign-regarding-voip-addons-for-skype-the-story-goes-on/#comments</comments>
		<pubDate>Thu, 30 Sep 2010 13:10:59 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[Skype scam]]></category>
		<category><![CDATA[Skype spam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1130</guid>
		<description><![CDATA[MX Lab, http://www.mxlab.eu, reported earlier on regarding a malicious spam campaign regarding an offer to get Skype VOIP Addons. We have been following the campaigns and what is quite stunning is that the authors of this campaign are using different ESPs &#8211; or Email Service Providers &#8211; in order to get the message to their [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1130&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab, <a href="http://www.mxlab.e" target="_blank">http://www.mxlab.eu</a>, reported earlier on regarding a malicious spam campaign regarding an offer to <a href="http://blog.mxlab.eu/2010/09/14/malicious-spam-campaign-regarding-adobe-acrobat-2010-pdf-reader-and-voip-addons-for-skype/">get Skype VOIP Addons</a>.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100914_skype_offer_1.jpg" alt="" width="450" height="440" /></p>
<p>We have been following the campaigns and what is quite stunning is that the authors of this campaign are using different ESPs &#8211; or Email Service Providers &#8211; in order to get the message to their subscription database.</p>
<p>In the past we&#8217;ve seen messages coming from:</p>
<ul>
<li>Emailsparkle.com &#8211; owned by Dotster</li>
<li>digioffice-mail.be &#8211; owned by Mario Vleugels from West Technologies, located in Belgium</li>
<li>createsend1.com &#8211; owned by  Campaign Monitor</li>
</ul>
<p>Today we have the messages coming from Stream Send and the senders email address is newsletter@skype&#8211;2010.com. As you can notice, a new domain name is also present. This is used to avoid spam engines with the intent analysis technology where filtering is based on URLs inside the message.</p>
<p>The body of the email:</p>
<blockquote><p>Dear Skype Users,</p>
<p>This is to notify that new updates have been released for Skype. Following are major new features:</p>
<p>- Talk more for free via Voice Over IP (VoIP)<br />
- Lower cost when connecting to landlines (much cheaper than Calling Card)<br />
- Record your conversation (better than telephone quality)<br />
- Instant messaging &amp; file-sharing, video calls<br />
- Now available on PSP!</p>
<p>To check and upgrade, go to Skype Updates Center</p>
<p>Skype has changed the way we think of telecommunications.</p>
<p>Thank you for choosing us.</p>
<p>With best regards,<br />
Mike Pickman<br />
Skype Support<br />
Copyrights Skype 2010 &#8211; All Rights Reserved</p></blockquote>
<p>If you notice a change in email delivery, please post it in the comments.</p>
<p><strong>[Update 01-01-2010 20:32]</strong></p>
<p><strong></strong>We got a reply from the abuse department of Stream Send:</p>
<blockquote><p>&#8220;Thank you for contacting us. We&#8217;ve reviewed the information that you have sent us and have taken action against the account holder that sent out this email.&#8221;.</p></blockquote>
<p>Great, down again but for how long.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1130/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1130/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1130/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1130&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/09/30/malicious-spam-campaign-regarding-voip-addons-for-skype-the-story-goes-on/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100914_skype_offer_1.jpg" medium="image" />
	</item>
		<item>
		<title>Emails with the URL anoniemberichtje.com is a phishing attempt and you will get a expensive SMS subscription</title>
		<link>http://blog.mxlab.eu/2010/09/15/emails-with-the-url-anoniemberichtje-com-is-a-phishing-attempt-and-you-get-an-expensive-sms-subscription/</link>
		<comments>http://blog.mxlab.eu/2010/09/15/emails-with-the-url-anoniemberichtje-com-is-a-phishing-attempt-and-you-get-an-expensive-sms-subscription/#comments</comments>
		<pubDate>Tue, 14 Sep 2010 23:26:15 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=1081</guid>
		<description><![CDATA[MX Lab intercepted some emails with the subject &#8220;Lees ffkes mn bericht&#8221; &#8211; can be translated to &#8220;read my message&#8221;. This message is written in the Dutch language &#8211; some words in a dialect &#8211; and it is targeting Dutch email users  - and is notifying the recipient that a private  messages is waiting to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1081&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab intercepted some emails with the subject &#8220;Lees ffkes mn bericht&#8221; &#8211; can be translated to &#8220;read my message&#8221;.</p>
<p>This message is written in the Dutch language &#8211; some words in a dialect &#8211; and it is targeting Dutch email users  - and is notifying the recipient that a private  messages is waiting to be read.</p>
<p>The message appears to be coming from a Hotmail.com account and is sent from one of the Hotmail servers with the IP 65.55.111.173. The IP seems to be a valid IP address being used by Hotmail.</p>
<p>IP Address: <a href="http://cqcounter.com/traceroute/?query=65.55.111.173">65.55.111.173<br />
</a>Host: blu0-omc4-s34.blu0.hotmail.com<br />
Location: US, United States<br />
Organization:  Microsoft Corp</p>
<p>The body of the email:</p>
<blockquote><p>Ik heb u juist een anoniem berichtje gestuurd, kunde da ffkes lezen?</p>
<p>Klik op onderstaande link om het berichtje te zien.</p>
<p>hxxp://www93.anoniemberichtje.com/?message=3191332f9645ad23fc538e1932cd936d</p>
<p>Wij zijn de enigste die het berichtje kunnen zien.</p>
<p>Stuurt ge wa terug?</p></blockquote>
<p>Translated to English:</p>
<blockquote><p>I just send you an anonymous message, can you read it?</p>
<p>Click on the link below to see the message.</p>
<p>hxxp://www93.anoniemberichtje.com/?message=3191332f9645ad23fc538e1932cd936d</p>
<p>We are the only one who can see the message.</p>
<p>Do you send something back?</p></blockquote>
<p>When following the URL you will get the following screen.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100915_pers_bericht_1.jpg" alt="" width="438" height="286" /></p>
<p>Great, you will need to fill in your Windows Live account details on a non Microsoft web site. This looks to me like a genuine phishing attempt in the first place.</p>
<p>We filled in some dummy email address and password combination and the webpage becomes visible.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100915_pers_bericht_2.jpg" alt="" width="450" height="277" /></p>
<p>It&#8217;s all in Dutch but I will give you an idea of what this page is about. &#8220;You have received 1 private message&#8221; and you will need to fill in your mobile number in the webform. From that point on, you will receive an SMS and you will need to confirm your mobile number.</p>
<p>After that, the private message for you will be visible and you can also send unlimited private messages.</p>
<p>The web site also states &#8220;Are you under 18? Ask permission from your parent or guardian&#8221; and to the right, the black box with 3355 &#8211; which is a special mobile SMS number &#8211; and 28.00 € / week does make it appear that you will subscribe to a sort of SMS service for that amount each month.</p>
<p>Now, the domain anoniemberichtje.com is registered with the following details.</p>
<pre>Domain Name      : anoniemberichtje.com
PunnyCode        : ANONIEMBERICHTJE.COM
Creation Date    : 2010-09-02 13:59:22
Updated Date     : 2010-09-14 09:32:35
Expiration Date  : 2011-09-02 13:59:19

Registrant:
  Organization   : wu ling
  Name           : wuling
  Address        : ShangHai
  City           : Shang Hai
  Province/State : Shanghai
  Country        : cn
  Postal Code    : 200085

Administrative Contact:
  Name           : wuling
  Organization   : wuling
  Address        : ShangHai
  City           : Shang Hai
  Province/State : Shanghai
  Country        : cn
  Postal Code    : 200085
  Phone Number   : 86-755-12345678
  Fax            : 86-755-12345678
  Email          : lixing763@yahoo.cn

Technical Contact:
  Name           : wuling
  Organization   : wuling
  Address        : ShangHai
  City           : Shang Hai
  Province/State : Shanghai
  Country        : cn
  Postal Code    : 200085
  Phone Number   : 86-755-12345678
  Fax            : 86-755-12345678
  Email          : lixing763@yahoo.cn

Billing Contact:
  Name           : wuling
  Organization   : wuling
  Address        : ShangHai
  City           : Shang Hai
  Province/State : Shanghai
  Country        : cn
  Postal Code    : 200085
  Phone Number   : 86-755-12345678
  Fax            : 86-755-12345678
  Email          : lixing763@yahoo.cn</pre>
<p>So, the conclusion is that you better do not attempt to fill in your mobile number or your Windows Live account details.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/1081/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/1081/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/1081/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=1081&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/09/15/emails-with-the-url-anoniemberichtje-com-is-a-phishing-attempt-and-you-get-an-expensive-sms-subscription/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100915_pers_bericht_1.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100915_pers_bericht_2.jpg" medium="image" />
	</item>
		<item>
		<title>Directory scam: Registration of the World Business Directory 2010/2011</title>
		<link>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/</link>
		<comments>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 10:05:14 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[directory scam]]></category>
		<category><![CDATA[EU Business Services Ltd]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[World Business Directory]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=778</guid>
		<description><![CDATA[MX Lab reported in 2009 about the misleading marketing trick that the World Business Directory uses. Guess what, they are back! MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract. The email comes from info@companyworld2010.com, with the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=778&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab reported in 2009 about <a href="http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/" target="_blank">the misleading marketing trick that the World Business Directory uses</a>. Guess what, they are back!</p>
<p>MX Lab received a new registration form from the World Business Directory and again, we want to point out a few things before you sign their contract.</p>
<p>The email comes from info@companyworld2010.com, with the subject &#8220;Registration of the World Business Directory 2010/2011&#8243; and this is the email content:</p>
<blockquote><p>Dear Madam/Sir,</p>
<p>In order to have your company registered in the World Business<br />
Directory for 2010/2011, please print, complete and return the<br />
enclosed form (PDF file) to the following address:</p>
<p>World Business Directory<br />
Suite 149 &#8211; Rosden House &#8211; 372 Old Street<br />
EC1V 9AU / London &#8211; United Kingdom<br />
E-mail: office@companyworld2010.com<br />
Fax: +44 207 806 8157</p>
<p>Updating is free of charge!</p>
<p>To unsubscribe, please send an email to<br />
unsubscribe@companyworld2010.com</p></blockquote>
<p>Attached is a PDF file named world-businessdirectory.pdf.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir.gif" alt="" width="450" height="619" /></p>
<p>The 1st point that needs your attention is the text block 1:</p>
<blockquote><p>To update your company profile, please print, complete and return<br />
this form (Updating is free of charge). Only sign if you want to<br />
place an insertion.</p></blockquote>
<p>As you can read, updating is free of charge but if you want your company get listed in this directory you will need to sign and have to pay.</p>
<p>What is the price of this directory you may ask yourself? Well, you have to go to text block 2 with the very small letters and this includes:</p>
<blockquote><p>I WILL HAVE AN INSERTION INTO ITS DATA BASE FOR THREE YEARS. THE PRICE PER YEAR IS GBP 980.</p></blockquote>
<p>And there you have it, this contract will cost your business a total amount of GBP 2940 over 3 years. After the 3 years subscription you can stop your contract if you inform them on time:</p>
<blockquote><p>THE SUBSCRIPTION WILL BE AUTOMATICALLY EXTENDED EVERY YEAR FOR ANOTHER YEAR, UNLESS SPECIFIC WRITTEN NOTICE IS RECEIVED BY THE SERVICE PROVIDER OR THE SUBSCRIBER TWO MONTHS BEFORE THE EXPIRATION OF THE SUBSCRIPTION.</p></blockquote>
<p>A few arguments from our side that this is a scam:</p>
<p>The from email address contains the domain companyworld2010.com and when trying to see if there is a site online we got the notification &#8220;This account has been suspended&#8221;. We might see new emails from the World Business Directory appear with other domains.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" alt="" width="450" height="208" /></p>
<p>When getting some WHOIS information on the domain we got the following:</p>
<table border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td></td>
<td colspan="4">
<pre>Registrant:
 international group c/o Free Private Reg
 P.O. Box 81024
 Burnaby, BC V5H 4K2
 CA

 Domain name: COMPANYWORLD2010.COM

 Administrative Contact:
    boot, cornelis  companyworld2010.com@freeprivateregistration.com
    P.O. Box 81024
    Burnaby, BC V5H 4K2
    CA
    852-3594-1708
 Technical Contact:
    Hostmaster, Domain  hostmaster@doteasy.com
    Suite 210 - 3602 Gilmore Way
    Burnaby, BC V5G 4W9
    CA
    (604) 434-4307    Fax: (604) 608-6832

 Registrar of Record: In2net Network Inc.
 Record last updated on 05-Mar-2010.
 Record expires on 05-Mar-2011.
 Record created on 05-Mar-2010.

 Domain servers in listed order:
    DNS8.DOTEASY.COM   65.61.199.14
    DNS7.DOTEASY.COM   65.61.198.14

 Domain status: clientTransferProhibited
                clientUpdateProhibited</pre>
</td>
</tr>
</tbody>
</table>
<p>The registrant information is rather vague and points to a PO Box and the administrative contact has the same address. The domain freeprivateregistration.com in the email address of the administrative contact is just a domain alias from doteasy.com. These details must be fake.</p>
<p>In 2009, the PDF document needed to be returned to an address in The Netherlands, in this 2010/2011 edition it needs to be returned to an address in London, UK.</p>
<p>When visiting their site at <a href="http://www.world-businessdirectory.com/" target="_blank">http://www.world-businessdirectory.com/</a> on the &#8216;About us&#8217; page we found the following text:</p>
<blockquote><p>The World Business Directory online is product of EU Business Services Ltd, a corporation organized and existing under the laws of Nevis, West Indies.</p></blockquote>
<p>We also  found the UK address on the &#8216;Contact us&#8217; page.</p>
<p>Our recommendation is: <strong>don&#8217;t sign the document and don&#8217;t do business with this company</strong>.</p>
<p>Follow these guidelines if  you are a victim of this directory scam:</p>
<ul>
<li>Do not pay, even if they imply to take your case to court.</li>
<li>If you have paid a certain amount, stop the next payments. Expect that you won&#8217;t get a refund either.</li>
<li>Send them a letter informing them you have been misled and telling them to cancel the contract.</li>
<li>If possible, report to (local) authorities.</li>
</ul>
<p>Additional information:</p>
<p><a href="http://stopecg.org/world_business_directory.htm" target="_blank">Stop EU Business Services Ltd Trading As World Business Directory</a><br />
<a href="http://www.stopwbd.za.org/" target="_blank">Stop world-businessdirectory.com</a></p>
<p>On the <a href="http://www.richardcorbett.org.uk/directoryscams.htm" target="_blank">web site of Richard Corbett</a> you can find some background information about directory scams and what to do when you are a victim of such a scam.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/778/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/778/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/778/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=778&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/feed/</wfw:commentRss>
		<slash:comments>83</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir.gif" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20100309_wbdir_2.gif" medium="image" />
	</item>
		<item>
		<title>Phishing PayPal email includes web form</title>
		<link>http://blog.mxlab.eu/2009/06/03/phishing-paypal-email-includes-web-form/</link>
		<comments>http://blog.mxlab.eu/2009/06/03/phishing-paypal-email-includes-web-form/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 12:46:03 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=477</guid>
		<description><![CDATA[One of the latest phishing emails with the subject &#8220;PayPal Forma ID PP697&#8243; caught our attention because of the fact that it included a complete HTML form inside the email. The phishing is regarding a refund request and the amount would be transferred to your credit card within 5 or 7 days. The form seduces you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=477&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the latest phishing emails with the subject &#8220;PayPal Forma ID PP697&#8243; caught our attention because of the fact that it included a complete HTML form inside the email. The phishing is regarding a refund request and the amount would be transferred to your credit card within 5 or 7 days.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090603_paypal_form_email.jpg" alt="" width="450" height="412" /></p>
<p>The form seduces you to submit not only your credit card details but also your email and PayPal password. This could directly lead to the hacking and abuse of your PayPal account.</p>
<p>The form sends the filled in details to the host hxxp://www.swisstools.net/mailform.asp and when processed it will redirect you to the Italian PayPal web site. When we tested this we got a Microsoft OLE DB Provider for ODBC Driver error as a result.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/477/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/477/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/477/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=477&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/03/phishing-paypal-email-includes-web-form/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090603_paypal_form_email.jpg" medium="image" />
	</item>
		<item>
		<title>World Business Guide is using misleading marketing trick</title>
		<link>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/</link>
		<comments>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/#comments</comments>
		<pubDate>Wed, 03 Jun 2009 11:14:54 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Various]]></category>
		<category><![CDATA[directory]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[World Business Guide]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=470</guid>
		<description><![CDATA[Today, MX Lab received an email regarding the &#8220;World BusinessGuide&#8221; directory. At first there seems nothing wrong with the mailing but when looking further there are some points that need your attention. The messages is from &#8220;World Business Register&#8221; with different email addresses in use: info@easyhomecorporation.com info@easycitycorporation.com info@bigorganization4you.com www@companyregpro.net www@companyregstore.net www@easycompregonline.com www@bestcompregpro.com The subject is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=470&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today, MX Lab received an email regarding the &#8220;World BusinessGuide&#8221; directory. At first there seems nothing wrong with the mailing but when looking further there are some points that need your attention.</p>
<p>The messages is from &#8220;World Business Register&#8221; with different email addresses in use:</p>
<p>info@easyhomecorporation.com<br />
info@easycitycorporation.com<br />
info@bigorganization4you.com<br />
www@companyregpro.net<br />
www@companyregstore.net<br />
www@easycompregonline.com<br />
www@bestcompregpro.com</p>
<p>The subject is &#8220;Business Registration 2009/2010&#8243;. The body of the email:</p>
<blockquote><p>Ladies and Gentlemen.</p>
<p>In order to have your company inserted in the registry of World Businesses<br />
for 2009/2010 edition, please print, complete and submit the enclosed<br />
form (PDF file) to the following address:</p>
<p>WORLD BUSINESS GUIDE<br />
P.O. Box 2021<br />
3500 GA Utrecht<br />
The Netherlands</p>
<p>email: register@wbgtoday.net<br />
FAX: +31 20 524 8107</p>
<p>Updating is free of charge!</p>
<p>If you are not the intended recipient, please submit an email to<br />
unsubscribe@wbgtoday.net<br />
Your request shall be dealt with accordingly.</p></blockquote>
<p>Attached is a PDF document that needs to be printed, filled in and sent to an PO Box address in The Netherlands.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20090603_wbguide.jpg" alt="" width="450" height="637" /></p>
<p>When reading the PDF document carefully you can find the following:</p>
<blockquote><p>I WILL HAVE AN INSERTION INTO ITS DATA BASE FOR THREE YEARS. THE PRICE PER YEAR IS EURO 995.</p></blockquote>
<p>While the email itself states &#8220;<strong>Updating is free of charge!</strong>&#8221; you will have to pay <strong>€ 995 each year</strong> with a minimum 3 year period by signing the document. This is quite misleading if you ask me.</p>
<p>A few more observations that should warn you about a possible scam:</p>
<ul>
<li>the email is sent from easyhomecorporation.com while there is no web site on this place so the registration of this domain is purely for spoofine the real origin.</li>
<li>and more important, the document needs to be sent to a PO Box in The Netherlands while the company is International Directories Group Ltd  located in Spain according to the document.</li>
</ul>
<p>In the past we have received similar letters by regular post here in Belgium and some organisations like Unizo have <a href="http://www.unizo.be/viewobj.jsp?id=385661" target="_blank">instructions</a> (in Dutch) on how to report the illegal and deceptive practices to the authorities.</p>
<p>If you have received such a email, or regular mail, don&#8217;t sign the document, sent it to the trash or report to your local authorities.</p>
<p>[Update March, 9th 2010] MX Lab received a new registration PDF from the World Business Directory. <a href="http://blog.mxlab.eu/2010/03/09/registration-of-the-world-business-directory-20102011/">Read the article</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/470/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/470/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/470/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=470&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/06/03/world-business-guide-is-using-misleading-marketing-trick/feed/</wfw:commentRss>
		<slash:comments>40</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20090603_wbguide.jpg" medium="image" />
	</item>
		<item>
		<title>Belgian court condemns 18 persons regarding Nigerean spam</title>
		<link>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/</link>
		<comments>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/#comments</comments>
		<pubDate>Mon, 18 May 2009 21:46:15 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Spam]]></category>
		<category><![CDATA[Various]]></category>
		<category><![CDATA[nigerean spam]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.mxlab.eu/?p=455</guid>
		<description><![CDATA[The correctional court of Brugges, Belgium, condems 18 persons with prison sentences from 2 to 6 years for sending out fraudulent spam between Februay 2007 and November 2008. In the Nigerian spam emails they claimed to have a fund in Ghana where a substantional amount of money was blocked after a woman died in a car accident. The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=455&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The correctional court of Brugges, Belgium, condems 18 persons with prison sentences from 2 to 6 years for sending out fraudulent spam between Februay 2007 and November 2008.</p>
<p>In the Nigerian spam emails they claimed to have a fund in Ghana where a substantional amount of money was blocked after a woman died in a car accident. The small fortune of 35 million Euro could be released with the help and a contribution of the addressee.</p>
<p>The police could arrest the gang after a tip and a thorough investigation of mobile phone conversations.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/455/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/455/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/455/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&amp;blog=574486&amp;post=455&amp;subd=mxlab&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2009/05/18/belgian-court-condemns-18-persons-regarding-nigerean-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
	</channel>
</rss>
