Fake banks, couriers, law firms, escrow and other fake sites used in scams.
#90901 by Terminator5 Mon Mar 19, 2012 12:31 pm
B2B Alibaba Purchase Scam with Fake Website under development .

www.motioninvestmentinc.com

Active page , www.motioninvestmentinc.com/Re-EscrowPayment/index.php contains a generic email phishing page .


Source IP Address 41.15.217.169

South Africa



Begin Scam Email:

Dear Customer,

Your have received a B2B express escrow payment.
You now have to view and confirm this email to receive the amount in your account.

Click here to view your payment.


If you have any purchasing requirements in the future, please do not hesitate to contact me for help.
It's easy. Just provide the following information:

1. Product Name:
2. Min. Order Quantity:
3. Annual Purchase Volume:
4. Detailed Purchasing Requirements:
5. Product Photo: Please attach it with your email to us
To submit your purchasing request to us, you can also

I will help to match you with the right supplier as soon as I receive the information above. Thank you.

Wishing you the very best of business,

Horatio

Alibaba.com Sourcing Assistant
This email was sent automatically please do not respond.

End Scam Email





Header Details:

Delivered-To: xxxxxx
Received: by 10.180.101.135 with SMTP id fg7csp2520wib;
Mon, 19 Mar 2012 02:04:37 -0700 (PDT)
Received: by 10.68.234.41 with SMTP id ub9mr37757050pbc.106.1332147876300;
Mon, 19 Mar 2012 02:04:36 -0700 (PDT)
Return-Path: <[email protected]>
Received: from icarus.vdpwebsites.com.au (icarus.vdpwebsites.com.au. [203.98.84.170])
by mx.google.com with ESMTPS id p3si16023227pbb.106.2012.03.19.02.04.35
(version=TLSv1/SSLv3 cipher=OTHER);
Mon, 19 Mar 2012 02:04:36 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 203.98.84.170 as permitted sender) client-ip=203.98.84.170;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 203.98.84.170 as permitted sender) [email protected]
Received: from apache by icarus.vdpwebsites.com.au with local (Exim 4.69)
(envelope-from <[email protected]>)
id 1S9YW1-0004UY-B1
for xxxxxx; Mon, 19 Mar 2012 09:04:33 +0000
To: xxxxxx
Subject: Your Payment
X-PHP-Script: betterwebbusinesses.netmate.co/wp-conte ... [email protected] for 41.15.217.169
From: Horatio Enot <[email protected]>
Reply-To: [email protected]
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <[email protected]>
Date: Mon, 19 Mar 2012 09:04:33 +0000

Daniel 8 :25
Advertisement

#93617 by Terminator5 Sun Apr 01, 2012 1:25 pm
Scam Alibaba Website .

Source IP Address 65.75.128.68 . Redwood City , USA

http://www.audiolicious.net/wp-includes/Alibaba.htm


Begin Scam Email:

New Security Features
Important account update notice!







Resolution Center:
This is an improtant account verification update notice.
Please login below to update your account details

Log in



Thank you for using Alibaba.com


End Scam Email



Header Details:

Delivered-To: xxxxxx
Received: by 10.180.98.132 with SMTP id ei4csp18998wib;
Sat, 31 Mar 2012 21:24:42 -0700 (PDT)
Received: by 10.50.153.165 with SMTP id vh5mr2623679igb.4.1333254281416;
Sat, 31 Mar 2012 21:24:41 -0700 (PDT)
Return-Path: <[email protected]>
Received: from server.websitedomainhost.net ([65.75.128.68])
by mx.google.com with ESMTPS id el4si14115376icb.75.2012.03.31.21.24.40
(version=TLSv1/SSLv3 cipher=OTHER);
Sat, 31 Mar 2012 21:24:41 -0700 (PDT)
Received-SPF: neutral (google.com: 65.75.128.68 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=65.75.128.68;
Authentication-Results: mx.google.com; spf=neutral (google.com: 65.75.128.68 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Received: from daddictc by server.websitedomainhost.net with local (Exim 4.69)
(envelope-from <[email protected]>)
id 1SBT6q-0002CC-9D
for xxxxxx; Sat, 24 Mar 2012 11:42:28 -0400
To: xxxxxx
Subject: Important Account Update Notice
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: Alibaba.com <[email protected]>
Message-Id: <[email protected]>
Date: Sat, 24 Mar 2012 11:42:28 -0400
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server.websitedomainhost.net
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [594 591] / [47 12]
X-AntiAbuse: Sender Address Domain - server.websitedomainhost.net

Daniel 8 :25

Who is online

Users browsing this forum: No registered users and 18 guests