PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : [Betrug/Geldwäsche] Reply to your resume



Eniac
25.08.2005, 10:15
Leo mal wieder?

http://www.fastmoney-corp.net/images/pic_08.gif

-whois


-----------------------------------------------
Queried Domain Information as follows
-----------------------------------------------
Domain Name : fastmoney-corp.net
: :Registrant: :
Name : Foundation Men On Line
Email : poor [at] spamvictim.tld

Address : PO Box 76613 AMSTERDAM NH
Zipcode : 1070 HE
Nation : NL
Tel : 31206791556
Fax : 31206627572
: :Administrative Contact: :
Name : Foundation Men On Line
Email : poor [at] spamvictim.tld

Address : PO Box 76613 AMSTERDAM NH
Zipcode : 1070 HE
Nation : NL
Tel : 31206791556
Fax : 31206627572
...
: :Name Servers: :
ns1.fastmoney-corp.net
ns2.fastmoney-corp.net
ns3.fastmoney-corp.net
ns4.fastmoney-corp.net
ns5.fastmoney-corp.net
: : Dates & Status : :
Created Date 2005-08-18 16: 55: 54 EDT
Updated Date 2005-08-18 16: 55: 54 EDT
ValID: [ID filtered]
Status ACTIVE

Die beworbene Seite http://www.fastmoney-corp.net/ löst sich nach 84.29.56.54 (home.nl) oder 24.166.1.3 (rr.com) auf.


http://www.fastmoney-corp.net/images/photo03.jpg

Als Kontakt wird eine Adresse in Dortmund angegeben, die Telefonnummern lassen sich mit der Rückwärtssuche von http://www.dasoertliche.de/ nicht zuordnen.


If you any questions don't hesitate to contact us.
Our postal address:
FastMoney Corp.
Emil-Figge-Strasse 76 D-324
Dortmund
Germany

...


Customer service:
Tel.: 49-231-934-9003
Fax: 49-231-934-9003


http://www.fastmoney-corp.net/images/photo02.jpg



Re: www.fastmoney-corp.net [84.29.56.54] [24.166.1.3] (beworbene Seite)
To: poor [at] spamvictim.tld, poor [at] spamvictim.tld
CC: cp#interpol.int

===8<==============Original message text===============

From SRS0=dOy9=W3=fastmoney-corp.net=job [at] srs.kundenserver.de Wed Aug 24 xx:xx:xx 2005
Return-Path: <SRS0=dOy9=W3=fastmoney-corp.net=job [at] srs.kundenserver.de>
X-Flags: 1001
Received: (qmail invoked by alias); 24 Aug 2005 xx:xx:xx -0000
Received: from [221.208.3.134] (helo=-0.000000)
by mxeu0.kundenserver.de with ESMTP (Nemesis),
ID: [ID filtered]
Received: from fastmoney-corp.net (-1212457808 [-1212257832])
by artesmarciales.com (Qmailv1) with ESMTP ID: [ID filtered]
for <poor [at] spamvictim.tld>; Tue, 23 Aug 2005 xx:xx:xx -0500
Date: Tue, 23 Aug 2005 xx:xx:xx -0500
From: Job <job [at] fastmoney-corp.net>
X-Mailer: The Bat! (v2.00.9) Personal
X-Priority: 3
Message-ID: [ID filtered]
To: Info <poor [at] spamvictim.tld>
Subject: Reply to your resume
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----------8223846E7A770EA"


Reply to your resume

We have the vacancy in our company that is the job of the financial manager.
Our company is working in the field of international transport
At the present moment we have representatives in many countries: USA, UK, Spain, Germany, France and some others.
And now we have many orders; so, we need managers to process the orders.
You can perform the job from your place, it will take 2-3 hours a week, and the salary is about $400 a week.
Our web site is http://www.fastmoney-corp.net/jobs.htm

===8<===========End of original message text===========

Eniac

Goofy
25.08.2005, 16:02
Die Domain scheint DNS-timeout-Probleme zu haben.
Spamhaus findet nur für einen der Nameserver einen Record:

ns5.fastmoney-corp.net. [12.217.57.81]
->http://www.spamhaus.org/sbl/sbl.lasso?query=SBL30475

Einen konkreten Namen kann man dem noch nicht zuordnen.

Laut Spamhaus ein "Trojan-compromised" PC.
Das würde bedeuten, dass dort auf einer kompromittierten Kiste ein DNS-Server läuft...