<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: funds]]></title>
    <link>http://securityratty.com/tag/funds</link>
    <description></description>
    <pubDate>Wed, 02 Jul 2008 13:11:42 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Best Western Hotel Online Booking Breached, 8 Million Victims In Personal Data Theft]]></title>
      <link>http://securityratty.com/article/1e268670aae5d79f21ac2627114fd3b4</link>
      <guid>http://securityratty.com/article/1e268670aae5d79f21ac2627114fd3b4</guid>
      <description><![CDATA[Criminal gang has stolen the identities of an estimated eight million people in a hacking raid that could ultimately net more than 2.8billion in illegal funds. Thursday night, an unknown hacker,...]]></description>
      <content:encoded><![CDATA[Criminal gang has stolen the identities of an estimated eight million people in a hacking raid that could ultimately net more than £2.8billion in illegal funds. Thursday night, an unknown hacker, possibly indian, successfully breached the IT defences of the Best Western Hotel group&#8217;s online booking system and sold details of how to access it [...]]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:57:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/western hotel">western hotel</category>
      <category domain="http://securityratty.com/tag/unknown hacker">unknown hacker</category>
      <category domain="http://securityratty.com/tag/possibly indian">possibly indian</category>
      <category domain="http://securityratty.com/tag/thursday night">thursday night</category>
      <category domain="http://securityratty.com/tag/million people">million people</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/ultimately net">ultimately net</category>
      <category domain="http://securityratty.com/tag/criminal gang">criminal gang</category>
      <category domain="http://securityratty.com/tag/illegal funds">illegal funds</category>
      <source url="http://cyberinsecure.com/best-western-hotel-online-booking-breached-8-million-victims-in-personal-data-theft/">Best Western Hotel Online Booking Breached, 8 Million Victims In Personal Data Theft</source>
    </item>
    <item>
      <title><![CDATA[Corporate Identity Theft]]></title>
      <link>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</link>
      <guid>http://securityratty.com/article/57c21b4d57a8ae63a7ec8f43043877e8</guid>
      <description><![CDATA[I remember a talk by the value investor Mason Hawkins (Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at...]]></description>
      <content:encoded><![CDATA[<p>I remember a <a href="http://www.bengrahaminvesting.ca/Resources/videos.htm#hawkins">talk</a>&#160;by the value investor&#160;<a href="http://en.wikipedia.org/wiki/Mason_Hawkins">Mason Hawkins</a>&#160;(Longleaf Funds) where someone asked him about investing overseas. He answered that he does, but mainly in places where the British flag flew at some point, where there is a rule of law. Here is one example of what he is worried about and why investing in places where your assets have no legal protection does not give the investor a margin of safety.</p><div>Hermitage Fund was until recently the largest fund in Russia. From the Business Week story<a href="http://hermitagefund.com/index.pl/news/article.html?id=895"> &quot;Hijacking the Hermitage Fund&quot;</a></div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Corruption, intimidation, robbery, violent assault, forgery, large-scale fraud. No, not the subject of the latest John Grisham novel, but sensational allegations, made public Apr. 4 by Hermitage Capital Management -- until recently the largest foreign portfolio investor in Russia. In a detailed and damning report, titled Criminal Justice -- Russian-Style, Hermitage alleges the fund&#39;s Russian subsidiaries have fallen victim to an elaborate con designed to defraud the fund of hundreds of millions of dollars.&#160;<br />&#160;&#160;<br />The most sensational part of Hermitage&#39;s allegations is that the attempted larceny was carried out with the direct connivance of officials in the Russian police. Hermitage alleges the police seized documents and equipment that were instrumental to the attempted fraud, which involved bogus court cases based on forged documents, the aim of which was to sue Hermitage subsidiaries for hundreds of millions of dollars. &quot;The most shocking thing is not that there are corporate raiders in Russia who attempt to steal your shares,&quot; says Jamison Firestone, managing partner of Firestone Duncan, Hermitage&#39;s law firm. &quot;The shocking thing is that the police worked hand-in-hand with them, and actually performed the theft of the documents so that the corporate raiders could then do their work.&quot;</p></blockquote><div><br /><div>From the most recent Hermitage Fund letter, here is the current state:</div><br /><br /></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>So the two-pronged scam worked in one area and failed in another. The perpetrators weren’t able to steal the assets from us based on the fake court claims, but they were able to steal $230 million from the Russian government by filing amended tax returns on behalf of our stolen companies. What makes this story even more shocking is that we filed six 255-page criminal complaints with the Russian authorities in December last year, one month before the tax fraud took place, and they did nothing to stop it. Two complaints were sent to the Russian General Prosecutor, two to the Russian State Investigative Committee and two to the Internal Affairs Department of the Interior Ministry. There was enough information to prevent the fraud and indict a number of people behind it if the government had acted.&#160;</p><p>Instead of doing anything to save the Russian state from this highly sophisticated and organized looting, two of our complaints were thrown out immediately; two were returned to the same Interior Ministry official we were complaining about (essentially, he was being asked to “investigate himself”); and one was thrown out for “lack of any crime committed.” Only one complaint was taken seriously. It was taken up by the Russian State Investigative Committee in early February, but before it could get any traction, the case was lowered to the South region of the Moscow district of the State Investigative Committee (the lowest level of the Committee) and by June, another senior Interior Ministry official whom we had named in our complaint had joined the “investigation” team (again, to “investigate himself”). To this day there has been no serious response by the Russian authorities to this massive fraud against the Russian state.&#160;</p><p>As we described in our April letter, the problem of corporate “raiding” is now so endemic in Russia that President Medvedev speaks about it as one of the biggest problems faced by Russian businesses. In this case, raiders have taken this problem to a new and absurd extreme by “raiding” the Russian state itself and so far getting away with it. Together with HSBC, we will shortly be filing new criminal complaints with the Russian General Prosecutor and Russian State Investigative Committee as well as with many law enforcement authorities outside of Russia. It is hard to predict what will happen next in this unfolding and unbelievable saga, but as always we will keep you updated on any further developments as they arise.</p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><p>Of course we see individual identity theft on a regular basis (actually as Ross Anderson points out its not really identity theft but poor controls on the bank&#39;s parts using SSNs as secrets and so on), but you dont see a major corporation stolen every day.</p>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 05:58:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russian police">russian police</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian government">russian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/russian-style">russian-style</category>
      <category domain="http://securityratty.com/tag/hermitage">hermitage</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/corporate-identity-theft.html">Corporate Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[419 Mail Targets Musicians]]></title>
      <link>http://securityratty.com/article/78200fa3b050f8ec66cec2b25a18e6f9</link>
      <guid>http://securityratty.com/article/78200fa3b050f8ec66cec2b25a18e6f9</guid>
      <description><![CDATA[One of my musician colleagues received the following email

Original Message
From: smith douglas
Subject: lovely song
Sent: Aug 5, 2008 5:50 PM

Hello Lovely vocalist

I am Olatunji Hassan a music...]]></description>
      <content:encoded><![CDATA[
        One of my musician colleagues received the following email:<br /><br /><i>------Original Message------<br />From: smith douglas<br />Subject: lovely song<br />Sent: Aug 5, 2008 5:50 PM<br /><br />Hello Lovely vocalist <br />&nbsp; <br />I am Olatunji Hassan a music lover and I must say I listened to <br />your song via the internet and was moved.I lived in the United <br />States all my life and now I am back in my father land(AFRICA)<br />I must also lay my emphasis on the fact that I still travel to <br />&nbsp;us when the country is pretty hot. <br />I am the C.E.O of Douglas compensations<br />The compensation company is a company which has gotten the <br />approval of the Government to dispatch lost funds and recovered<br />theft funds to individuals who seems to need the funds. <br />I am using the power bestowed on me by my Government to approve <br />the sum of 100,000 United states Dollars for you. <br />your urgent reply is needed in regards to this development. <br />Olantunji Hassan.</i><br /><br />Of course, it's a scam. There are plenty of musicians promoting their music on their websites, blogs, fan sites and forums - which presents scammers with a huge selection of targets to choose from. Be on your guard...<br /><br /> 
        
    ]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 03:13:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/funds">funds</category>
      <category domain="http://securityratty.com/tag/dispatch lost funds">dispatch lost funds</category>
      <category domain="http://securityratty.com/tag/theft funds">theft funds</category>
      <category domain="http://securityratty.com/tag/music lover">music lover</category>
      <category domain="http://securityratty.com/tag/music">music</category>
      <category domain="http://securityratty.com/tag/lovely song">lovely song</category>
      <category domain="http://securityratty.com/tag/song">song</category>
      <category domain="http://securityratty.com/tag/compensation company">compensation company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://blog.spywareguide.com/2008/08/419-mail-targets-musicians.html">419 Mail Targets Musicians</source>
    </item>
    <item>
      <title><![CDATA[VCsChoosing How to Invest]]></title>
      <link>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</link>
      <guid>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</guid>
      <description><![CDATA[Don Dodge has a series going on about VCs and why startups fail, and he says VCs say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he compares...]]></description>
      <content:encoded><![CDATA[<p>Don Dodge has a series going on about VCs and why startups fail, and he says VC&#8217;s say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he <a rel="nofollow" target="_blank" href="http://dondodge.typepad.com/the_next_big_thing/2008/08/why-vcs-say-no-99-of-the-time.html">compares </a>the selection process to the way investors choose their stocks &#8211;</p>
<blockquote><p>I would guess that every one of you reading this blog have a stock portfolio with 5 to 10 individual stocks or mutual funds. There are more than 5,000 publicly listed companies to choose from, and another 5,000 mutual funds. But, out of 10,000 possible companies you chose 10 to invest in. Why? Why did you reject the other 9,990 companies? Obviously there are more than 10 good companies to invest in. Other investors chose to invest their money in the other 9,990 companies&#8230;why not you?</p></blockquote>
<p>I suppose the difference must be that many investors aren&#8217;t actively involved in their investments (maybe entrepreneurs are more so, since they have to know a certain investment space quite well)&#8230;</p>
<p>It sounds to me a lot like the editorial selection process for book manuscripts, articles, and so forth &#8212; editors receive a ton of submissions and they have to be choosy. Sometimes they don&#8217;t pick winners; sometimes they pick losers. More importantly, each has a personal style, opinions, preferences, and they are trying to appeal to a certain audience. It&#8217;s interesting to think that VCs are similar but makes sense&#8211;the end question of &#8220;What will be successful&#8221; really depends on the consumer base and industry, and VCs are just people who probably know and prefer to interact with a certain type of consumer base or audience.</p>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 06:23:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/investors chose">investors chose</category>
      <category domain="http://securityratty.com/tag/chose">chose</category>
      <category domain="http://securityratty.com/tag/investors">investors</category>
      <category domain="http://securityratty.com/tag/editorial selection process">editorial selection process</category>
      <category domain="http://securityratty.com/tag/investors choose">investors choose</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/selection process">selection process</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/mutual funds">mutual funds</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/355545351/">VCsChoosing How to Invest</source>
    </item>
    <item>
      <title><![CDATA[The Magical ATM Card and SMS Message in Thailand]]></title>
      <link>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</link>
      <guid>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</guid>
      <description><![CDATA[It was not too long ago that I penned Keyloggers: Why Banks Need Two-Factor Authentication . In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor...]]></description>
      <content:encoded><![CDATA[<p>It was not too long ago that I penned <a href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/">Keyloggers: Why Banks Need Two-Factor Authentication</a>. In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor authentication (2FA) with one-time password (OTP) to authenticate transactions.</p>
<p>One of my favorite banks in Thailand is <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">K-Bank</a>. With K-Bank I can simply walk up to an ATM machine and pay a mobile phone bill, purchase mutual funds, buy insurance, or transact an ever-growing list of services payable at the modern and sleek K-Bank ATM.</p>
<p>For example, tomorrow I fly to Chiang Mai in Northern Thailand and found K-Bank&#8217;s service amazingly better than in the US. For example, I booked my flight as usual (over the phone, but could have used the Internet) and told the reservation agent I was going to pay by ATM. He simply gave me a PayCode and told me I had three hours to go to the ATM and enter the PayCode to perfect my reservation.  I also got the PayCode via SMS.  This gave me the time I needed to make sure I had <a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/pictures/" target="_blank">booked the perfect boutique hotel</a> in Chiang Mai, the <strong><a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/review/" target="_blank">Fern Paradise</a>.</strong></p>
<p>Then, I went out into the beautiful Thai weather and completely my airplane reservation at the ATM machine; which also printed out a receipt with my flight details and reservation number.</p>
<p>It sometimes amazes me how much further advanced some services are in Thailand compared to the US. To me, it feels more secure not to use an on-line payment center or give out my credit card details over the phone. I can simply book a ticket, take a PayCode, and complete the transaction at a nice modern, shiny, K-Bank ATM machine.</p>
<p>Who knows, maybe soon I can select the perfect window seat at the ATM and the receipt will act as my boarding pass!</p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/atm">atm</category>
      <category domain="http://securityratty.com/tag/k-bank atm machine">k-bank atm machine</category>
      <category domain="http://securityratty.com/tag/sleek k-bank atm">sleek k-bank atm</category>
      <category domain="http://securityratty.com/tag/k-bank">k-bank</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/atm machine">atm machine</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/perfect window seat">perfect window seat</category>
      <category domain="http://securityratty.com/tag/perfect">perfect</category>
      <source url="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/">The Magical ATM Card and SMS Message in Thailand</source>
    </item>
    <item>
      <title><![CDATA[Smash and Grab]]></title>
      <link>http://securityratty.com/article/123ef88e4224522b141f1e24cbad6fa4</link>
      <guid>http://securityratty.com/article/123ef88e4224522b141f1e24cbad6fa4</guid>
      <description><![CDATA[Ever wondered how much damage can be caused with what is likely a few handily placed keyloggers and trojans

Well, this is probably a good (bad?) place to start

Also while that was happening the...]]></description>
      <content:encoded><![CDATA[
        Ever wondered how much damage can be caused with what is likely a few handily placed keyloggers and trojans?<br /><br />Well, <a href="http://www.shannonlilly.com/domains-taken-from-godaddy-account-whats-being-done-about-it/">this</a> is probably a good (bad?) place to start.<br /><br />"<i>Also while that was happening the person who stole my GoDaddy account
also stole our paypal accounts and charged several thousand dollars to
us. PayPal is working to get that money back, so far about 600.00
was&nbsp;retrieved but we are still waiting for news on the other funds.</i>"<br /><br />Ouch....<br /><br /><br /> 
        
    ]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 09:27:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/paypal">paypal</category>
      <category domain="http://securityratty.com/tag/paypal accounts">paypal accounts</category>
      <category domain="http://securityratty.com/tag/thousand dollars">thousand dollars</category>
      <category domain="http://securityratty.com/tag/godaddy account">godaddy account</category>
      <category domain="http://securityratty.com/tag/funds">funds</category>
      <category domain="http://securityratty.com/tag/damage">damage</category>
      <category domain="http://securityratty.com/tag/keyloggers">keyloggers</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/bad">bad</category>
      <source url="http://blog.spywareguide.com/2008/07/smash-and-grab.html">Smash and Grab</source>
    </item>
    <item>
      <title><![CDATA[Money Mule Recruiters use ASProx's Fast Fluxing Services]]></title>
      <link>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</link>
      <guid>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</guid>
      <description><![CDATA[Just consider this scheme for a second. A well known money mule recruitment site Cash Transfers is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/c7TMX064n4w/s1600-h/cash_transfers_money_mule_recruitment.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/CaeHtWn_06M/s200-R/cash_transfers_money_mule_recruitment.png" style="border: 0pt none ;" /></a>Just consider this scheme for a second. A well known <a href="http://www.docep.wa.gov.au/ConsumerProtection/scamnet/Scams/Cash-Transfers_Inc.html">money mule recruitment site Cash Transfers</a> is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting services for several hundred domains used on the last wave of SQL injection attacks. Ironically, <a href="http://www.banksafeonline.org.uk/moneymule_explained.html">the money mule recruitment site</a> is sharing IPs with many of them. Who are these money launderers (<b>cashtransfers.tk</b>; <b>cashtransfers.eu; type53.eu</b>; <b>sid57.tk</b>; <b>catdbw.mobi</b>; <b>cdrpoex.com </b>etc.&nbsp; ) anyway?<br />
<br />
<div style="text-align: left;">"<i>Cash-Transfers Inc. is an online-to-offline international money transfer service. We offer a secure, fast, and inexpensive means of sending money from the UK to offline recipients worldwide. Recipients do not require a bank account or Internet connection to receive funds. We have teamed with select local disbursement partners to provide a convenient, secure, and cost-effective means of sending money to family, friends and business partners abroad. The basic requirements to send money/transfer money are:</i></div><i><br />
1) Senders must have Internet access and a bank account or credit/debit card to transfer money. However, recipients do not require either a bank account or Internet connection.<br />
<br />
2) Money sent through Cash-Transfers Inc. is available for pick up at the distribution partner instantly, or, in most countries, money can be delivered to the recipient in a matter of hours.<br />
<br />
3) Our local agents will call your recipient (during local business hours) to provide additional details, including: forms of identification required, hours of operation, and other locations. The sender will also receive an email confirmation with transaction details and tracking information.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/qtHLcMs6sVs/s1600-h/cash_transfers_asprox_SQL_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/y-aSv2_Sztk/s200-R/cash_transfers_asprox_SQL_injection.JPG" style="border: 0pt none ;" /></a></div>The fast-flux infrastructure they're currently using is also providing services to domains that are currently used, or have been used in previous SQL injection attacks. Some info on the current DNS servers used in the fast-flux :<br />
<br />
<b>ns10.cashtransfers.tk<br />
ns11.cashtransfers.tk<br />
ns1.cashtransfers.tk<br />
ns12.cashtransfers.tk<br />
ns2.cashtransfers.tk<br />
ns13.cashtransfers.tk<br />
ns3.cashtransfers.tk<br />
ns14.cashtransfers.tk<br />
ns4.cashtransfers.tk<br />
ns15.cashtransfers.tk<br />
ns5.cashtransfers.tk<br />
ns16.cashtransfers.tk<br />
ns6.cashtransfers.tk<br />
ns17.cashtransfers.tk<br />
ns7.cashtransfers.tk<br />
ns8.cashtransfers.tk</b><br />
<br />
With the distributed and dynamic hosting infrastructure courtesy of the malware infected user, scammers, spammers, phishers and malware authors are only starting to experiment with the potential abuses of such an underground ecosystem build on the foundations of compromises hosts.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aMnYfJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aMnYfJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wo8AkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wo8AkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=22rmej"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=22rmej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ec2OKj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ec2OKj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LfbMJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LfbMJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LYf9J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LYf9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LO3zj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LO3zj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338919917" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 02:23:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/cashtransfers">cashtransfers</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <category domain="http://securityratty.com/tag/transfer money">transfer money</category>
      <category domain="http://securityratty.com/tag/fast-flux infrastructure">fast-flux infrastructure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338919917/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</source>
    </item>
    <item>
      <title><![CDATA[The most insecure banking/sales terminal]]></title>
      <link>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</link>
      <guid>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</guid>
      <description><![CDATA[Can you imagine an ATM running Windows XP Home Edition and being connected to the Internet or a Point of Sale terminal running Tetris ? Unlikely! Why then is allowing a customer to use any computer on...]]></description>
      <content:encoded><![CDATA[<p>Can you imagine an <a href="http://www.youtube.com/watch?v=FAnmuRHYamc">ATM running Windows</a> XP Home Edition and being connected to the Internet or a Point of Sale <a href="http://www.youtube.com/watch?v=wWTzkD9M0sU">terminal running Tetris</a>? &ndash; Unlikely! Why then is allowing a customer to use any computer on the Internet to connect to the banking system, and transfer much more money than you can take out of a cash machine, a good idea? Why did arguably the most conservative organisations in the world &ndash; the banks &ndash; agree to lower their defenses so low that they practically invited the criminals in?</p>

<p>The answer is simple &ndash; the same reasons why even risk-averse investors were chasing after every Internet company in the late 90s  &ndash; the attractiveness of the global scale and reduced costs of e-channels. </p>

<p>Over the years, payments and savings have always been a subject of the most advanced protection:</p>

<ul>
  <li>Banknotes have watermarks and other security features to resist counterfeiting</li>


  <li>Cheques require the account holder's signature</li>


  <li>ATMs require both your card and your PIN, run secure software, and are physically tamper-resistant</li>


  <li>Point of Sale terminals in your favourite supermarket are protected from tampering and use dedicated secure connections to the payment processing network</li>


</ul>


<p>These are all very sensible measures that work (to one degree or another) to protect customers' and banks' money.</p>

<p>Today, however, there is a huge imbalance between the value of electronically accessible funds and their security. This is being very effectively exploited by criminals and the banks are looking for a solution. Personal computers are not tamper proof sales terminals, therefore it is unfeasible to rely on the customer to keep them 100% secure. No one can take away online banking but banks can deploy new security measures, and  solving this problem requires a new innovative approach that can equally address security, ease of use, and cost.</p>

<p>At Cronto, we identified this imbalance years ago. We also correctly predicted that the only <a href="http://blog.cronto.com/index.php?title=transaction_verification_can_protect_aga">solution to address this problem is transaction authentication</a> (where the customer confirms each banking instruction). We then developed an innovative visual transaction signing solution. Based on our unique <a href="http://www.cronto.com/visual_cryptogram.htm">Visual Cryptogram</a>, the Cronto solution supports multiple end user options allowing the bank to choose what is right for their customers whilst maintaining consistency in their backend systems.</p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 09:27:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/address">address</category>
      <category domain="http://securityratty.com/tag/address security">address security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/security features">security features</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/banks agree">banks agree</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/internet company">internet company</category>
      <source url="http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1">The most insecure banking/sales terminal</source>
    </item>
    <item>
      <title><![CDATA[Malware and Office Documents Joining Forces]]></title>
      <link>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</link>
      <guid>http://securityratty.com/article/dee3d028ca8134c75e2aec7f397d1493</guid>
      <description><![CDATA[Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/X83g6Zkr9hg/s1600-h/screen1.jpg" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHtuv_mJSwI/AAAAAAAAB6M/b0YAu_NWEQk/s200-R/screen1.jpg" style="border: 0pt none ;" /></a>Common office files as documents, presentations, spreadsheets and PDF files, are the most widely abused ones in targeted attacks, which when backed up with enough personal information and take into consideration the time of their attack if the social engineering campaign is either going to be based on a current/upcoming event, or on an event anticipated due to information gathered through open source intelligence, often make it through common signature based scanning solutions.<br />
<br />
Despite the relatively easy to obtain, point'n'click <a href="http://www.f-secure.com/weblog/archives/00001450.html">DIY tools for backdooring common office files</a> are available for the script kiddies to take advantage of, some are <a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">naturally remaining proprietary tools</a>, making them harder to analyze unless a copy is obtained. Like this one, generating "undetected" by signatures based scanning, office documents and spreadsheets that would drop the actual malware on the PC.<br />
<br />
Automatic translation of its description and core features :<br />
<br />
<i>"The program represents a generator OfficeJoiner macros in the language Visual Basic for Application (VBA), for introduction in the document Microsoft Office Word / Microsoft Office Excel executable file (win32 exe), followed by fully automatic recovery and launch, without any&nbsp; additional action by the user. The only requirement that formed in such a way xls / doc files is to support&nbsp; VBA macros on the computer end-user formed file and permission to launch macros.</i><br />
<br />
<i>The program uses NOT a vulnerability (exploit) or macro-virus tools for the introduction, extraction or running embedded files. This means that it has generated macros compatible with ALL versions of Microsoft Office products starting with Microsoft Office 97 package, with any established "patches" and the service pack. Macros generated by this program not detected antivirus, for the simple reason that they are not viruses or macro viruses. The program uses only "established" means products built into Microsoft Excel VBA language to achieve their goals.</i><br />
<br />
<i>- Fully automatic generation of macro for the introduction of documents word / excel any given exe-file with his persistence in the body and subsequent documents automatic recovery and launch, when opening a document word / excel.&nbsp;</i><br />
<br />
<i>- Generated macros are compatible with all versions of ms word / excel since version 97,&nbsp; employments and regardless of the presence / absence of any patches / servicepacs.&nbsp;</i><br />
<br />
<i>- Generated macros are not macro-viruses, exploits do not use and do not contain any malicious code, so do not be detected by any antivirus tools as viruses.&nbsp;</i><br />
<br />
<i>- Conversion body ex-file macro happening in such a way that while in doc / xls file it not detected any antivirus, and can be freely sent by mail safely passed all checks, even if in itself contains viral code defined antivirus. <br />
&nbsp;</i><br />
<i>- Sgenerirovanny and attached to the body of the document macro can be protected with a password or signed certificate, using funds established Microsoft Office, which does not affect him productivity or efficiency (macro, in any case remain fully workable).&nbsp;</i><br />
<br />
<i>- Box macro can be made both in the new document, and in any document containing data and-or other macros. Generated program code is fully compatible with any other embedded in the document macros or entering data, and will not interfere with their work, as well as maintain its efficiency.</i><br />
<br />
<div dir="ltr" id="result_box"><i>- Added auto-finding ways to extract exe-file; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Added possibility of a macro arbitrary text in the body of the instrument; <br />
&nbsp;</i></div>
<div dir="ltr" id="result_box"><i>- Optimized algorithm macro-generation code; <br />
</i></div>
<div dir="ltr" id="result_box"><i>&nbsp;</i> </div>
<div dir="ltr" id="result_box"></div>
<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<div dir="ltr" id="result_box"><a href="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/BtNJaK_13LM/s1600-h/officedocs_malware_sample.PNG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp1.blogger.com/_wICHhTiQmrA/SHt7EgPiRwI/AAAAAAAAB6U/xhaiKacT-eM/s200-R/officedocs_malware_sample.PNG" style="border: 0pt none ;" /></a><i>Enabling this option will lead to the creation macro code, who himself will find a way to unpack and run embedded exe-file. Auto-search finds the current user folder and produces there extraction and launch embedded file. The peculiarity of this method is that this method will work on the computers of users with a limited account, because in its user folder in any case has the right to record / performance. Using this option is justified to improve the "punching" macro on computers with limited account or unknown file structure (let Windows installed on the disk is different from C). <br />
<br />
You can specify a name for final file independently, or leave blank, then the name will be generated automatically.</i> </div>
<div dir="ltr" id="result_box"><i><br />
</i></div>
<div dir="ltr" id="result_box"><i>On this possibility has asked for a user program, its essence is that after running a macro, retrieval and downloading exe-file the document with the introduction of exe-file will be withdrawn posed text. Perhaps in this way can improve the application of social engineering, designed to force the user to allow support for macros. For example, in the text of the document indicate: <br />
<br />
"This document contains hidden text (password, a system of calculation formulas, interactive components, etc.), Which can be viewed only after the inclusion of support macros. Please enable support for macros and re-opening this document ". <br />
<br />
After resolving support macros, and the implementation of embedded exe-file, the document will be withdrawn given a string containing probable "password" or any other textual information.</i>  " </div>
<br />
Despite that the tool is proprietary, the underground economy's leaks are largely driven by bargain hunters who would exchange proprietary tool, whose often biased exclusiveness may increase the profit margins, for a service or a good that may be worthless for them in general, but impossible to obtain and take advantage of in the present. It will not just leak in one way or another, someone will inevitably backdoor the backdooring tool and trick the novice bargain hunters into running it, by having both their host infected and money taken.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">The Underground Economy's Supply of Goods and Services</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/yet-another-diy-proprietary-malware.html">Yet Another DIY Proprietary Malware Builder</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit - Proprietary</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/diy-exploit-embedding-tool-proprietary.html">DIY Exploit Embedding Tool - A Proprietary Release</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype Spamming Tool in the Wild - Proprietary Release</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=mMDIJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=mMDIJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vtGZUJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vtGZUJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Voeqqj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Voeqqj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=QZJLHj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=QZJLHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=4VmcIJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=4VmcIJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rqLHKJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rqLHKJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LnaC8j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LnaC8j" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/335226251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 07:20:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/document">document</category>
      <category domain="http://securityratty.com/tag/document macros">document macros</category>
      <category domain="http://securityratty.com/tag/support">support</category>
      <category domain="http://securityratty.com/tag/enable support">enable support</category>
      <category domain="http://securityratty.com/tag/macro">macro</category>
      <category domain="http://securityratty.com/tag/macro viruses">macro viruses</category>
      <category domain="http://securityratty.com/tag/support vba macros">support vba macros</category>
      <category domain="http://securityratty.com/tag/exe-file">exe-file</category>
      <category domain="http://securityratty.com/tag/extract exe-file">extract exe-file</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/335226251/malware-and-office-documents-joining.html">Malware and Office Documents Joining Forces</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</link>
      <guid>http://securityratty.com/article/cac739eb23af3ee3d5ecd500b5815c6f</guid>
      <description><![CDATA[A handful of scam mails currently in circulation, including one mention of &quot;groundnut oil&quot; that seems so bizarre I had to highlight it in bold text. All this and more, after the jump
Subject
FROM THE...]]></description>
      <content:encoded><![CDATA[
        A handful of scam mails currently in circulation, including one mention of "groundnut oil" that seems so bizarre I had to highlight it in bold text. All this and more, after the jump...<br />  
        Subject:<br />FROM THE DESK OF MR. STEVEN JAMES<br />From:<br />"Steven James"&lt;steven@fristbnkngplc.net&gt;<br />Date:<br />Mon, 30 Jun 2008 19:17:03 +0100<br />BCC:<br /><br />FROM THE DESK OF MR. STEVEN JAMES<br />CHAIRMAN INTERNATIONAL RELATION<br />FIRST BANK OF NIGERIA PLC<br /># 1 BANK ROAD WUSE FCT <br />ABUJA-NIGERIA.<br />PHONE: +234-80-66520277<br />Email: stevenjames809@live.co.uk&nbsp; <br /><br /><br />Very Urgent Attention,<br /><br />Please permit me to introduce my humble self to you, my name is Mr. Steven James, I am the Manager of International Relation with First Bank of Nigeria Plc, I 'm 38yrs old, and I got your email address from a friend of mine, and my confidence reposed on you. I hope you read this message carefully and reply me immediately. Although we have not met before, but I suggest that this transaction will bring us together.<br /><br />My dear, we had a customer, a foreigner but base here in Nigeria, his Name was Mr. Hamilton Creek. He is from Atlanta Georgia United State of America, but based here with his wife and his two children, Mr. Hamilton has being banking with us for the past 4yrs and some time in August 2002, Mr. Hamilton was on his way to his house, and <b>unfortunately ran into a Trailer load of Groundnut Oil, and died&nbsp;&nbsp; immediately, Their car got burnt, no single soul was saved, Mr. Hamilton Creek and His entire family was confirmed dead.</b><br /><br />My Board of Directors and the Management of First Bank has mandated and instructed me to look for Mr. Hamilton Creek? Relation(s) and his Next of&nbsp; Kin to come and claim his fund, Since August 2003 till date, I have been looking for his relation's or his next of Kin to come and claim his fund which he Deposited with our bank, I have contacted his Embassy and after 3days, his Ambassador told me that Mr. Hamilton Creek has no relation and no next of Kin, their Ambassador told me that he used his first son as His next of kin, but it is quite unfortunate that Mr. Hamilton Creek Died with all his family members.<br /><br />The reason why I contacted you is thus, Mr. Hamilton is dead, and his only son who supposed to inherit his properties and money also died with him. As at this moment, nobody or person[s] is coming to&nbsp;&nbsp; claim this Money from our bank. The Board of Directors and management of our bank told me that if nobody or person[s] apply for the claim of Mr. Hamilton Fund, the bank will return the entire Fund into our Federal reserve. In the Light of the above, I want you to stand as the next of kin to Late Mr. Hamilton Creek; it might interest you to know that he had a Domiciliary Bank Account with our Bank and he has a total sum of US$9.2M Nine Million Two Hundred thousand Dollars, this is the exact amount which he had in his domiciliary account before the ugly incident occurred, and this money is still in his account as unclaimed money.<br /><br />This transaction is very easy and simple, and it is 100% risk free, I'm the Manager for International Relations with First Bank of Nigeria Plc, and the Management and Board of Directors of the Bank are waiting for me to provide to them the Relation or next of Kin to late Mr. Hamilton Creek, of which I told them that I am still searching the next of kin to the deceased. Finally, if you are interested with this transaction, I will front you to the bank as the only next of kin to late Mr. Hamilton Creek, and I will let the bank know that you are the only right person to inherit Late Mr. Hamilton Funds and properties. If you are interested, just email me or call me on my&nbsp;&nbsp; direct and private line#: +234-80-27536038 and late Mr. Hamilton's Funds will be credited into your account and all his Properties will be released to you either through Courier Services or the Bank will Cargo all his properties to you in any were you want it.<br /><br />So reply me immediately and feel free to ask any question with regards to this transaction. You will take 50% of the US$9.2M. Which is? US$4.600, 000.00 Four Million Six Hundred Thousand Dollars, while the Balance of the same amount will be mine.<br /><br />Your swift response will be highly appreciated.<br /><br />Thanks and have a nice day.<br /><br />Friendly Regards<br /><br />Mr. Steven James<br /><br />*******************************************************************************************<br /><br />Subject:<br />REPRESENTATIVE NEEDED<br />From:<br />DFS SALES LTD UK &lt;info@dfs.net&gt;<br />Date:<br />Tue, 01 Jul 2008 23:00:55 +0800<br />To:<br />undisclosed-recipients: ;<br /><br /><br />COMPLIMENT OF THE DAY TO YOU.<br /><br />I am PETER WOODS from DFS SALES LTD UK.(<br />Website: www.dfs-online.co.uk ) Visit our site<br /><br />We are into&nbsp; furnitures and we sell shares to people in<br />Canada,America, Australia and Europe.<br /><br />We are in need of a book keeper. someone who can represent our company<br />in his/her country.<br /><br />Our client in your location will contact you and make the company<br />payment to you.<br /><br />You will be entitle to 11% of every payment been made out to you.<br /><br />This is because most of our officer are from china and they do not<br /><br />understand english very well.its hard for them to contact our<br />customers.<br /><br />Our head office is located in CHINA. But we have a sub-office in the<br />uk.<br /><br />If you are interested, Kindly send the entries for more understanding.<br /><br />NAME IN FULL :.........<br />COMPANY NAME: .....<br />POSITION:......<br />FULL ADDRESS: .......<br />CITY/TOWN:........<br />STATE:............<br />ZIP CODE:........<br />COUNTRY:.......<br />MOBILE:.......<br />HOME TEL: .....<br />EMAIL ADDRESS: ........<br />OCCUPATION: ...........<br />BANK NAME :.......<br />AGE:............<br /><br />You are to send the above details to<br /><br />NAME : PETER WOODS.<br />EMAIL : dfs_woods@yahoo.co.uk<br />PHONE NUMBER : +44-704-575-0212<br /><br />HOPE TO HEAR FROM YOU<br /><br /><br />*****************************************************************************************<br /><br />To:<br />undisclosed-recipients:;<br /><br />Good day!!!<br /><br />&nbsp;We have been waiting for you since to contact me for your Confirmable Bank Draft of ?18 Million (Eighteen Million Pounds sterling) but we did not hear from you since for a couple of weeks now. Then we went to the bank to confirm if the draft that expired or getting near to expire and Metropolitan Police Uk told us that before the funds will get to your hand that it will expire.So I told him to cash the ?18 Million (Eighteen Million Pounds sterling) to cash payment to avoid losing this fund under expiration as I will be out of the country for a 6 Months Course.<br /><br />&nbsp;What you have to do now is to contact FED EX COURIER SERVICES as soon as possible to know when they will deliver of your funds to you because of the expiring date. For your information we have paid for the delivering Charge Insurance premium. The only money you will send to the FED EX COURIER SERVICES to deliver your cheque direct to your postal Address in your country is ?250.00 being Security Keeping Fee of the Courier Company so far. Again don't be deceived by anybody to pay any other money except ?250.00 for the Security Keeping Fee.We would have paid that but they said no because they don't know when you will contact them and in case of demurrage. You have to contact FED EX COURIER SERVICES now for the delivery of your Draft with this<br />information below:<br /><br />&nbsp;CONTROLLER: Mrs.Helen Williams<br />&nbsp;NAME: FED EX COURIER SERVICES<br />&nbsp;ADDRESS: fedexofficeuk@gmail.com<br />&nbsp;PHONE NUMBER: +447024080684<br /><br />&nbsp;IF YOU ARE THE OWENER OF THE FUNDS AND YOU WILL SEND YOUR INFORMATION TO US SO THAT WE CAN DELIVERY YOUR FUNDS TO YOU WITHIN THE NEXT 84HRS TIME.IF YOU DO NOT RECEIVED YOUR FUNDS WITHIN THE NEXT 72HRS TIME AND YOU REPORT US THE UK FBI AND THE METROPOLITAN POLICE (SCOTLAND YARD) or YOU CONTACT YOUR LAWYER TO TAKE UP PROCEDURES AGAINST US.<br /><br />&nbsp;Let me repeat again try to contact them as soon as you receive this mail to avoid any further delay and remember to pay them their Security keeping fee of ?250.00 for their immediate action. The FED EX COURIER SERVICES don't know the contents of the funds. This is to avoid them delaying with the funds.<br /><br />&nbsp;Thanks as you contact them today.<br /><br />&nbsp;Yours Faithfully<br /><br />&nbsp;Mrs Helen Williams.<br /><br /><b>(The above actually comes with a nifty graphic that they've thrown in, thinking it makes it all look more legitimate. It doesn't, but here it is anyway):</b><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fedx1.jpg" src="http://blog.spywareguide.com/images/fedx1.jpg" class="mt-image-none" style="" height="64" width="472" /></span>
<br /><br />....altogether now: oooooh. A slightly shorter 419 roundup than usual, but I'm sure I'll have piles of the things next week.<br /><br /><br /><div class="moz-text-plain" wrap="true" graphical-quote="true" style="font-family: -moz-fixed; font-size: 13px;" lang="x-cyrillic"><pre wrap=""><br /><br /><br /><br /><br /></pre></div><div><br /></div>
    ]]></content:encoded>
      <pubDate>Wed, 02 Jul 2008 13:11:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hamilton fund">hamilton fund</category>
      <category domain="http://securityratty.com/tag/hamilton">hamilton</category>
      <category domain="http://securityratty.com/tag/hamilton creek">hamilton creek</category>
      <category domain="http://securityratty.com/tag/draft">draft</category>
      <category domain="http://securityratty.com/tag/confirmable bank draft">confirmable bank draft</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/domiciliary bank account">domiciliary bank account</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/hamilton funds">hamilton funds</category>
      <source url="http://blog.spywareguide.com/2008/07/your-419-mail-roundup-1.html">Your 419 Mail Roundup</source>
    </item>
  </channel>
</rss>
