Friday, January 30, 2015

SINCERELY, GOD BLESS YOU AS YOU HELP

My name is Jeniffer, I am happy to know you, but God knows you better and he knows why he has directed me to you at this point in time so do not be afraid. I saw your contact email at ministries of commerce and foreign trade departments. I am writing this mail to you with heavy sorrow in my heart. And am contacting you because I don’t have any other option than to tell you as I was touched to open up to you, I am with Libyan embassy in London for ten years before he died in the year 2005.we were married for eleven years without a child. He died after a brief illness that lasted for only five days. & i have 8.5 million dollars to transfer to you in charity name to help poor in your place, contact me here.(jenniffer.edward@mail.com)

Sincerely.
Jeniffer Mauller Edward.

jenniffer.edward@mail.com

Saudin Farooq fmf

AUTHORIZATION TO REMIT YOUR FUND
FEDERAL MINISTRY OF FINANCE
128, JAKONDE AVENUE V/ISLAND LAGOS
PO BOX 2704 FEDERAL REPUBLIC OF NIGERIA
COMMITTEE ON FOREIGN PAYMENT
AUTHORIZATION TO REMIT YOUR FUND
Our Ref: RTG /SNT/STB

ATTN: Beneficiary,

We, the entire members of the Federal Ministry of Finance, on behalf of the Federal Republic of Nigeria, Under the auspices of the ECOWAS Head of States, comprising 16 countries these includes Nigeria, Ghana, Togo, Benin, Senegal, Mali, Burkina Faso, cote d’ Ivoire and so on, We held a meeting last week concerning payment , both foreign and local contractors/inheritance funds which has been abandon by our banks in all West African countries. Furthermore, On going through files Friday last week, we discovered that your name and email address was dumped untreated, so at this juncture, we apologize for the delay of your payment and please stop communicating with any office now and attention to this office only for you to receive your payment of $5m (Five- Million United States Dollars) accordingly . Now your new Payment Reference No.-35460021, Allocation No: 674632 Password No : 339331 , Pin Code No: 55674 and your Certificate of Merit Payment No : 103, Released Code No: 0763; Immediate Telex confirmation No: -1114433 ; Secret Code No: XXTN013, Having received these vital payment number, therefore You are qualified now to received and confirm Now you are directed to contact this Office immediately so that we will instruct you on what to do , this is to avoid mistake while transferring your overdue payment. Contact us now for immediate release of your fund and forward your Details to our office to avoid transfer mistake.

Reconfirm to us the following information immediately

Full names:
Current Address:
Mobile:
Occupation:
Your Valid ID Card:
Age:
Nationality:
Next of Kin:

NOTE: We have mounted our security network to monitor every in-coming call,if we still find out that you are still dealing with all those fraudsters that have been frustrating our efforts and defrauding beneficiaries, We shall stop and cancel your payment immediately.

Best Regards

MR. Saudin Farooq
Secretary Resolution Panel on Contract / Inheritance fund Payment
Federal Ministry of finance.
CC: Honorable Minister of Finance
Cc: Senate President.
Cc: All Foreign Payment Offices.
Cc: Board of Directors [Fbg].
Cc: Accountant General Of The Federation
fedminoffinplc@gmail.com
farooqfmfs@yahoo.pt

MR JAMES IBE THE DELIVERY MAN I SENT HAS ARRIVED ,CALL HIM NOW(+16465689774)?

FROM THE EXECUTIVE GOVERNOR,
CENTRAL BANK OF NIGERIA (CBN)
GOV.SANUSI LAMIDO
E-mail: sanusilamido228@yahoo.com.hk

URGENT NOTICE,
ATTENTION: BENEFICIARY

This is to inform you that your delivery man has arrived with your inheritance cash trunk boxes value $8.3 million dollars in John F. Kennedy International Airport New York as their transit. I want you to know that you have 24 hours to call him now with this line (+16465689774) or email (jamesibe18@yahoo.com.ph ),then ask to speak to the diplomatic deliveryman in person of Mr.James Ibe in the United States.Let us know if you are still interested to get your two trunk boxes delivered to you today? As he has been waiting to hear from you to enable him get to your home address without missing his way. For your information, the deliveryman with your package is not aware of the content of the boxes for security purpose. Please do not tell him to avoid running away with your funds.On no account should you let him know about the content of the consignment to avoid evil intention. Most importantly you are advised to send your full data to him,which include your Full Name,Current Residential Address, Direct Cell Number,and A copy of any identity card to verify that you are the right receiver to avoid mistakes. Note that you must call me as soon as you receive this email for more discussion, Also reconfirm your full current address and valid phone number to the Delivery officer via his above email address once you receive this email to enable him deliver your cash consignment boxes to your house without any further delay or mistake. You are advised not to waste his time at the airport,so that he would not be stranded in any way because he will return if he finds out that you are not doing anything to get him over to your house.

CONGRATULATIONS.
MALLAM SANUSI LAMIDO AMINU,
EXECUTIVE GOVERNOR,
CENTRAL BANK OF NIGERIA
Gov.inf1@live.com
governorsanusil@yahoo.com.hk

riichardhii

Hello Friend, I am Richard Hii and i am requesting for your partnership in Re-profiling funds with the bank i work in. Contact me for more details (riichardhii@gmail.com)

Regards
Richard Hii

Email analysis :

NOTE : riichardhii@gmail.com
NOTE : test@ECLECTICSL.COM
NOTE : Received : from [221.207.62.202] (port=53335 helo=User)
NOTE : by server.kirokom.com with esmtpa (Exim 4.84)

Fax = Trojan

Fax message (Fax #0086091)

http://79.96.148.163/.~NEW_RECEIVED_FAX/incoming.html
Sent date: Thu, 22 Jan 2015 15:00:49 +0000

Fax message (Fax #0458849)

http://pristineusa.com/~_RECEIVED~FAX~MESSAGES/incoming.html
Sent date: Thu, 22 Jan 2015 15:13:35 +0000

Fax message (Fax #3457735)

http://hifafarah.com/._RECEIVED.MESSAGES/incoming-fax_letter.html
Sent date: Thu, 22 Jan 2015 15:26:03 +0000

Fax message (Fax #4644306)

http://89.161.234.149/-_NEW_RECEIVED.FAX_MESSAGES/incoming.fax~letter.html
Sent date: Thu, 22 Jan 2015 15:08:31 +0000

Fax message (Fax #6410561)

http://www.get-the-best.com/~_RECEIVED.FAX_MESSAGES/incoming.html
Sent date: Thu, 22 Jan 2015 15:16:23 +0000

Email analysis for 5 emails :

NOTE : Received : from unknown (HELO my-fax.com) (85.133.33.10)
NOTE : Received : from unknown (HELO my-fax.com) (40.131.4.2)
NOTE : Received : from unknown (HELO my-fax.com) (91.183.230.243)
NOTE : Received : from unknown (HELO my-fax.com) (66.203.160.26)
NOTE : Received : from unknown (HELO my-fax.com) (64.20.199.98)

pristineusa.com whois :

Registrant Name: PRISTINE SOFTWARE
Registrant Organization: PRISTINE SOFTWARE
Registrant Street: 1411 W. Covell Blvd Ste 106
Registrant City: Davis
Registrant State/Province: CA
Registrant Postal Code: 95616
Registrant Country: US
Registrant Phone: +1.5307584484
Registrant Phone Ext.:
Registrant Fax:
Registrant Fax Ext.:
Registrant Email: mmadani@pristineusa.com

hifafarah.com whois :

Registrant Name: PERFECT PRIVACY, LLC
Registrant Organization:
Registrant Street: 12808 Gran Bay Pkwy West
Registrant City: Jacksonville
Registrant State/Province: FL
Registrant Postal Code: 32258
Registrant Country: US
Registrant Phone: +1.9027492701
Registrant Phone Ext.:
Registrant Fax:
Registrant Fax Ext.:
Registrant Email: 24ebf0cf0a16123311014b9d998ad564@domaindiscreet.com

get-the-best.com whois :

Registry Admin ID: Admin Name: Lentz, Eduardo
Admin Organization: Get The Best, Inc.
Admin Street: P.O. Box 18630
Admin City: Boulder
Admin State/Province: CO
Admin Postal Code: 80308
Admin Country: US
Admin Phone: (303) 941-2118
Admin Fax: 999 999 9999
Admin Email: gtbusa@IX.NETCOM.COM

Analysis of link

- CLICK LINK
- DOWNLOAD FILE : (fax_message72933.zip)
- EXTRACT FILE : fax_message23055.exe
- PAGE REDIRECTED TO FAX SERVICE WEBSITE.

Analysis of file

ALYac : Trojan.Upatre.J
AVG : Downloader.Generic14.IJZ
AVware : Trojan-Downloader.Win32.Upatre.ao (v)
Ad-Aware : Trojan.Upatre.J
Agnitum : Trojan.Staser!
AhnLab-V3 : Win-Trojan/Downloader.38400.FA
Antiy-AVL : Trojan/Win32.Staser
Avast : Win32:Trojan-gen
Avira : TR/Dldr.Kryptik.pza
BitDefender : Trojan.Upatre.J
ByteHero : Virus.Win32.Heur.c
CAT-QuickHeal : (Suspicious) - DNAScan
Comodo : TrojWare.Win32.TrojanDownloader.Waski.BA
Cyren : W32/Trojan.NMXE-6820
DrWeb : Trojan.Upatre.125
ESET-NOD32 : Win32/TrojanDownloader.Waski.F
Emsisoft : Trojan.Upatre.J (B)
F-Prot : W32/Trojan3.NHH
F-Secure : Trojan-Downloader:W32/Upatre.J
Fortinet : W32/Kryptik.CWCJ!tr
GData : Trojan.Upatre.J
Ikarus : Trojan-Downloader.Waski
Jiangmin : Trojan/Staser.amk
K7AntiVirus : Trojan-Downloader ( 0049d22b1 )
K7GW : Trojan-Downloader ( 0049d22b1 )
Kaspersky : Trojan.Win32.Staser.awvp
Malwarebytes : Trojan.Email.FakeDoc
McAfee : Upatre-FAAJ!3B474BAEAC5F
McAfee-GW-Edition : BehavesLike.Win32.Autorun.nt
MicroWorld-eScan : Trojan.Upatre.J
Microsoft : TrojanDownloader:Win32/Upatre
NANO-Antivirus : Trojan.Win32.Kryptik.dmuguo
Norman : Upatre.FN
Sophos : Troj/Dyreza-AT
Symantec : Downloader.Upatre!gen8
TheHacker : Trojan/Kryptik.cwaa
TotalDefense : Win32/Upatre.IVVGEBC
TrendMicro : TROJ_UPATRE.SMNC
TrendMicro-HouseCall : TROJ_UPATRE.SMNC
VIPRE : Trojan-Downloader.Win32.Upatre.ao (v)
nProtect : Trojan/W32.Agent.38400.XP

Wednesday, January 28, 2015

Scammers

"a_braznell@yahoo.com" , "abigailaryee19@yahoo.com" , alberta okine , "alhassanissaka91@yahoo.com" , "amadaashitey@yahoo.com" , "amanda.mattew@yahoo.com" , "amandaashitey@yahoo.com" , "amartei_joseph@yahoo.com" , ampomah ulla , "amsingle2014amsingle2014@yahoo.com" , angel cooke , "angelayeboah787@yahoo.com" , Anna Bills , "annstillion47@yahoo.com" , "Augustinasmith600@yahoo.com" , "awuah.nancy@yahoo.com" , "badmuslisa@yahoo.com" , "bayebaba71@yahoo.com" , beatrice thomas , becca klean , "berlidaeknaadusei@yahoo.com" , Berton Coxon , Beverly k Clement , "Bonitasmith694@yahoo.com" , "bridgeteyre@yahoo.com" , "camaraduncan1000@hotmail.com" , "ceciliaxidan@ymail.com" , "christiana_love772@yahoo.com" , cindy rockson , "cindyrockson119@yahoo.com" , "cynthiapatrick77@yahoo.com" , "destiny.zainab@yahoo.com" , "diana_hmed@yahoo.com" , "dianahmed@yahoo.com" , "dixcy_k28@yahoo.com" , donald amy , dorothy kwarteng , edwina love , "elizabethwhyte72@yahoo.com" , "Ellenwhite119@yahoo.com" , "Euniceoforiwa448@yahoo.com" , fait love , "fatilove786@yahoo.com" , "fredayfishes@yahoo.com" , "geroselyn7@yahoo.com" , gladys solomon , gladys solomon , "gwesling47@yahoo.com" , Hannah Kitson , "harrietlove500@yahoo.com" , henery lobe , "honestbaby88@yahoo.com" , "Humugirl2012@yahoo.com" , "indomie123@yahoo.com" , "irene.love89@yahoo.com" , "irenemorgan10@yahoo.com" , "jenifaashley@yahoo.com" , jennifer mallon , "jenniferrudson@yahoo.com" , jessica mintah , "Johnmary840@yahoo.com" , joice otu , "joyce_bee@ymail.com" , "joyce.boateng83@yahoo.com" , "joycelove14@yahoo.com" , "jselina16@yahoo.com" , "julie.love60@yahoo.com" , "kaseemfati@yahoo.com" , kelly afun , kelly deemer , kelly rowland , "kellybannks@yahoo.com" , "krystaelmore@yahoo.com" , Lanisha Prigett , "larry_love58@yahoo.com" , "lbrew34@yahoo.com" , "lilio.rose@yahoo.com" , linda brown , linda nartey , "Linda_dufielld@yahoo.com" , "linda.hanson61@yahoo.com" , "lindadanson88@gmail.com" , "lindahuda14@yahoo.com" , "lindalawe@yahoo.com" , Lisa Jones , "loeceleste@yahoo.com" , "looking800@ymail.com" , love wet , Lovely Angel , lovely yak , "lovelystella700@yahoo.com" , "lovensexxxx@yahoo.com" , "loviaboateng2@gmail.com" , "lovnadiza1z@yahoo.com" , "lucyosei01@yahoo.com" , "malimenadazzo@yahoo.com" , "mandy_rose96@yahoo.com" , "mariam4u09@yahoo.com" , "mary.god80@yahoo.com" , "marywashington203@yahoo.com" , "me.2244@yahoo.com" , "michelle_stidham82@yahoo.com" , "minashreal@yahoo.com" , "miss_jenifer42@yahoo.fr" , "miss_kath86@yahoo.com" , "mrsgladis@yahoo.com" , "muareeneric@yahoo.com" , "natasha_belle82@yahoo.com" , "oojult@yahoo.com" , "oseilucy222@yahoo.com" , Peanut Mariya , "philippa_maughan@yahoo.com" , "pink_divaboo@yahoo.com" , "prettyboo90@yahoo.com" , "prettyqueen4real1980@yahoo.com" , "Rahina_baby@yahoo.com" , "reallove.gladys@yahoo.com" , "rose_love_abotchii@yahoo.com" , "Rose.smith674@yahoo.com" , "rosemond116@yahoo.com" , "saidatu.ismail@ymail.com" , "SainuziAbdullah@jkr.gov.my" , "sallycool210@yahoo.com" , "samiratu_umar@yahoo.com" , "sandralou1982@yahoo.com" , "sandramaboubaby1@hotmail.com" , "sandrascott2299@yahoo.com" , Sara Collins , Scam cz , "serwaalinda95@yahoo.com" , "shelbylambert70@yahoo.com" , "sherryjudd@yahoo.com" , Sidney J , "smithsandra776@yahoo.com" , Solomon Ihedioha , sophia linda , "sschneck@yahoo.com" , "sweet.kandy20@yahoo.com" , "sweethumble315613@yahoo.com" , "sweetqueen385@gmail.com" , Terran Snyder , "Theresacolema52@yahoo.com" , "theresahdanso89@yahoo.com" , "tillsunrise4u@yahoo.com" , "v_atakora@yahoo.com" , victoria wood , "vidadonu@yahoo.com" , "winslovemanu60@yahoo.com" , "yemitunde883@yahoo.com" , "your.lizzy@yahoo.com" , Zulfija