Monday, March 23, 2015

Brussels Airport,Belgium (Airport Scam)

Attn:Sir/Madam,

I am Mr.Dominique F.Clark,the Assistant Director Facility Inspection Unit,Brussels Airport,Belgium.A forfeited consignment from a secured Shipping Company was brought to our facility few days ago,during my routine checks at the Airport Facility Storage Vault, I discovered an abandoned shipment . When scanned,it revealed an undisclosed sum of money in two Metal Trunk Boxes weighing approximately 25kg each. The consignment was abandoned because the shippers are avoiding United Nations Inspection Agents,whose duty is to check all consignments that arrives at the airport.Also,the Contents of the consignment was not properly declared by the consignee as "MONEY" rather it was declared as personal effects,as it is not properly declared. I have to contact you to know if you can partner with me and sponsor the normalization of the "Bill of Entry" as the consignment will be shipped to your door step at your expense.

I will require the following;

1. Your Full Name:
2. Home phone & Cell Phone:
3. Home delivery address:
4. Any form of Identification either Drivers license or International Passport:

Send me email as soon as you receives this to signify your interest.

Please keep secret.

Best Regard.

Mr.Dominique F.Clark
Brussels Airport,
A201, 1930 Zaventem,
Belgium

Email analysis :

NOTE : d_niquck0116@yahoo.com
NOTE : DomClark119@merrell.jp
NOTE : Received : from User (unknown [88.85.112.207]) by vcsunny.ocn.ne.jp (Postfix)

Do You Authorize Chan­ge of Beneficiary Account­?? (Bank Of America Scam)

Dear Beneficiary, In our office today was the presence of One Mr. John T. Pullen of 122 Fitch Way, Sacramento,CA.USA 95864, filing application contrary to your pending fund transfer. The above mentioned person visited this Bank yesterday with a power of attorney given in his favor by you, granting him the benefit to process and claim your inheritance of $2,500,000.00(Two Million, Five Hundred Thousand United States Dollars) for personal reasons. He further stated that the online account will be terminated while the fund should be wired to his bank immediately; Bank Name;Bank Of America, Account Number # 12908576457 Routing Number# 121000358. We ask Mr. John T. Pullen, to return back to the bank within 48 hours to enable us have a personal confirmation from you being hitherto the beneficiary. We are sorry to have delayed your instruction in giving out this fund since we must adhere to the Modus Operandi of this honorable bank by making sure this request is verified and confirmed by the beneficiary and his existing attorney. Your confirmation to the above will be appreciated. We look forward to hear from you soon. Reply to this email address; Email; standardchbankng100@pisem.net Dr. GM Gardner (A/G) Foreign Remittance Director Regards, Mr Eugene Gomi Manager,Standard Chartered Bank Victoria I/S Lagos.Tel:+2347016786464.

Email analysis :

NOTE : standardchbankng100@pisem.net
NOTE : bassnbaycharters@bassnbaycharters.com
NOTE : Received : from bassnbaycharters.com (67.212.225.148)
NOTE : Received : (from bassnbaycharters@localhost) by bassnbaycharters.com (8.13.1/8.13.1)
NOTE : X-Mailer : www.bassnbaycharters.com

SAVE LIFE (Diamond Bank Scam)

My dear frieind,

Money in to your count but they are the roung people so i can only adveise you to stop, until i work to give you the right information for you to climb the money from diamond bank, im working in diamond bank as a messenger so i know the trute and the lies going one, i can only adveise you to give me some days to find out trute about you are transaction with diamond bank, i hope if everething work out i have something from you to give me,.

Thanks.
From mr Ubah.

Email analysis :

NOTE : savelifeu@gmail.com

FW: Important documents (Bank Of America Virus)

Cash Pro logo
Cash Pro logo
Important account documents

Reference: C85
Case number: 4690473

Please scan attached document and fax it to +1 (888) 589-3716.

Please note that the Terms and Conditions available below are the Bank's most recently issued versions. Please bear in mind that earlier versions of these Terms and Conditions may apply to your products, depending on when you signed up to the relevant product or when you were last advised of any changes to your Terms and Conditions. If you have any questions regarding which version of the Terms and Conditions apply to your products, please contact your Relationship Manager.

Yours faithfully

Signature Image

Rosalyn Chavez
Senior Manager
Bank of America Commercial Banking
Rosalyn.Chavez@bankofamerica.com

Calls may be monitored or recorded in case we need to check we have carried out your instructions correctly and to help improve our quality of service.

2014 Bank of America Corporation. All rights reserved. CashPro is a registered trademark of Bank of America Corporation.

AccountDocuments.zip

Email analysis :

NOTE : Rosalyn.Chavez@bankofamerica.com
NOTE : yvx@blaudieck.com
NOTE : User-Agent : Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
NOTE : Received : from unknown (HELO ACSKURDN) (83.231.81.43)


Virus analysis :

OPEN : AccountDocuments.zip
RESULT : AccountDocuments.zip is a VIRUS

ALYac : Trojan.GenericKD.2234787
AVG : Generic_s.ELW
AVware : Win32.Malware!Drop
Ad-Aware : Trojan.GenericKD.2234787
Antiy-AVL : Trojan[Downloader]/Win32.Upatre
Avast : Win32:Trojan-gen
Avira : TR/Crypt.Xpack.166918
Baidu-International : Trojan.Win32.Upatre.vlt
BitDefender : Trojan.GenericKD.2234787
CAT-QuickHeal : TrojanDownloader.Upatre.r4
ClamAV : Win.Trojan.Upatre-582
Comodo : TrojWare.Win32.UMal.~A
Cyren : W32/Trojan.ZDMF-2227
DrWeb : Trojan.DownLoad3.35985
ESET-NOD32 : Win32/TrojanDownloader.Waski.F
Emsisoft : Trojan.GenericKD.2234787 (B)
F-Secure : Trojan-Downloader:W32/Dalexis.B
Fortinet : W32/UPATRE.F!tr
GData : Trojan.GenericKD.2234787
Ikarus : Trojan-Downloader.Win32.Upatre
K7AntiVirus : Trojan ( 7000000c1 )
K7GW : Trojan ( 7000000c1 )
Kaspersky : Trojan-Downloader.Win32.Upatre.vlt
Malwarebytes : Trojan.Upatre
McAfee : Suspect-BW!0D6F95F76EEC
McAfee-GW-Edition : Suspect-BW!0D6F95F76EEC
MicroWorld-eScan : Trojan.GenericKD.2234787
Microsoft : TrojanDownloader:Win32/Upatre.AZ
NANO-Antivirus : Trojan.Win32.Upatre.dpimul
Norman : Upatre.FT
Panda : Trj/CI.A
Qihoo-360 : HEUR/QVM19.1.Malware.Gen
Sophos : Troj/Invo-Zip
Symantec : Downloader.Upatre
Tencent : Win32.Trojan-downloader.Upatre.Hfr
TrendMicro : TROJ_UPATRE.SMNC
TrendMicro-HouseCall : Suspicious_GEN.F47V0319
VIPRE : Win32.Malware!Drop
ViRobot : Trojan.Win32.A.Downloader.28928.D[h]
nProtect : Trojan.Upatre.Gen.2

JP Morgan Access Secure Message (Virus)

Please check attached file(s) for your latest account documents regarding your online account.

Alex Puckett
Level III Account Management Officer
817-283-1539 office
817-878-6079 cell Alex.Puckett@jpmorgan.com
Investments in securities and insurance products are:
NOT FDIC-INSURED/NO BANK-GUARANTEES/MAY LOSE VALUE
2015 JPMorgan Chase & Co.

CONFIDENTIAL NOTICE: The contents of this message, including any attachments, are confidential and are intended solely for the use of the person or entity to whom the message was addressed. If you are not the intended recipient of this message, please be advised that any dissemination, distribution, or use of the contents of this message is strictly prohibited. If you received this message in error, please notify the sender. Please also permanently delete all copies of the original message and any attached documentation. Thank you.

JP Morgan Access - Secure.zip

Email analysis :

NOTE : service@jpmorgan.com
NOTE : tenqvist@cc.oulu.fi
NOTE : User-Agent : Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
NOTE : Received : from 108-84-212-41.lightspeed.hstntx.sbcglobal.net (108.84.212.41)


Virus analysis :

OPEN : JP Morgan Access - Secure.zip
RESULT : JP Morgan Access - Secure.zip is a VIRUS

ALYac : Trojan.GenericKD.2234787
AVG : FakeAlert
AVware : Win32.Malware!Drop
Ad-Aware : Trojan.GenericKD.2234787
Antiy-AVL : Trojan[Downloader]/Win32.Upatre
Avast : Win32:Trojan-gen
Avira : TR/Crypt.Xpack.166918
Baidu-International : Trojan.Win32.Upatre.vlt
BitDefender : Trojan.GenericKD.2234787
CAT-QuickHeal : TrojanDownloader.Upatre.r4
ClamAV : Win.Trojan.Upatre-582
Comodo : UnclassifiedMalware
Cyren : W32/Trojan.ZDMF-2227
DrWeb : Trojan.DownLoad3.35985
ESET-NOD32 : Win32/TrojanDownloader.Waski.F
Emsisoft : Trojan.GenericKD.2234787 (B)
F-Secure : Trojan-Downloader:W32/Dalexis.B
Fortinet : W32/UPATRE.F!tr
GData : Trojan.GenericKD.2234787
Ikarus : Trojan-Downloader.Win32.Upatre
K7AntiVirus : Trojan ( 7000000c1 )
K7GW : Trojan ( 7000000c1 )
Kaspersky : Trojan-Downloader.Win32.Upatre.vlt
Malwarebytes : Trojan.Upatre
McAfee : Upatre-FAAR!05E6E33D4259
McAfee-GW-Edition : Upatre-FAAR!05E6E33D4259
MicroWorld-eScan : Trojan.GenericKD.2234787
Microsoft : TrojanDownloader:Win32/Upatre.AZ
NANO-Antivirus : Trojan.Win32.Upatre.dpimul
Norman : Upatre.FT
Qihoo-360 : HEUR/QVM19.1.Malware.Gen
Sophos : Troj/Upatre-JB
Symantec : Downloader.Upatre
Tencent : Win32.Trojan-downloader.Upatre.Fhz
TrendMicro : TROJ_UPATRE.SMNC
TrendMicro-HouseCall : Suspicious_GEN.F47V0320
VIPRE : Win32.Malware!Drop
ViRobot : Trojan.Win32.A.Downloader.28928.D[h]
nProtect : Trojan.Upatre.Gen.2

Rép :Hello (Cambodia Jail Scam)

Hello, i hope this email gets to you, my name is Heng Pov, former municipal police chief of cambodia,

i got your details from an extensive online search,

I want you to work with my lawyer to receive my funds in Cambodia Bank here. Due to some politically motivated problems i had with the Prime minister, I'm serving a 93 years sentence in cambodia Jail since 2006, but with the help of my Lawyer Kao Soupha, i have appeased the prime minister through a book i wrote to his glory and praise, the prime minister is considering my release through a royal/ premier pardon.

I want you to help me invest the sum of Twelve million united states dollars in your country, which i kept in the bank before my problems , you will get forty percent of all investments, as soon as i'm released from jail, i will come to meet you in your country and as well take my sixty percent, please keep this a secret as no one else knows except my lawyer and my Financial account manager.

If you want to help out , contact my lawyer immediately with this email kaosoupha@yahoo.com.hk

Yours faithfully,
Heng Pov.

Email analysis :

NOTE : kaosoupha@yahoo.com.hk
NOTE : hengpov68@yahoo.com
NOTE : Received : from v157-7-121-66.z1d15.static.cnode.jp (HELO WIN-CSOJ1NVO7GS) (157.7.121.66)


NOTE : Received : from User ([36.37.199.103]) by WIN-CSOJ1NVO7GS