Paul@usa-googleapps.com

The Purpose of this post is to ALERT you that the job you are about to apply for orscamalert may have applied FOR or is CONSIDERING APPLYING FOR is FRAUDULENT. The identities of an individual or a business entity have been stolen along with fund from their bank accounts.

These job postings are an attempt to lure you into accepting and cashing counterfeit checks into your bank accounts. You are being recruited to wire transfer these funds via WESTERN UNION or MONEYGRAM from your bank into a DOMESTIC BANK  or OFFSHORE BANK ACCOUNT.

 Essentially You Become A Money or Repackage Mule

  1. Money Mule Explained 
  2. Understanding The Cyber Theft Ring
  3. Protecting Yourself Against Money Mule
  4. KrebsOnSecurity – Cyberheist
  5. Washingtonpost.com by Brian Krebs
  6. Interview With A Money Mule
  7. Bobbear.co.UK ~ Historical Money Mule Sites

____________________

Email header analysis report
All valid IP Addresses found in the header.
Ip Address 3rd Party Info Provider City Flag Country
* 177.47.45.166 Check 177.47.45.166 at Senderbase.org Check 177.47.45.166 at Reputationauthority.org Tvn São Luís Brazil
98.138.213.185 Check 98.138.213.185 at Senderbase.org Check 98.138.213.185 at Reputationauthority.org Yahoo Sunnyvale United States

*Probable originating IP address

 

From  Wed Nov 27 12:12:45 2013
X-Apparently-To: scamFRAUDalert via 98.138.213.185; Wed, 27 Nov 2013 12:12:46 -0800
Return-Path: <backpacked2@google.com>
X-YahooFilteredBulk: 177.47.45.166
Received-SPF: softfail (transitioning domain of google.com does not designate 177.47.45.166 as permitted sender)
X-YMailISG: A3SB6NkWLDsIH1Tf77MZW17qBypNUMKSSocQ6ghGtyt84Qsn
CiCW6U2clMYZrbcxjLK7ZV1DJaK4ovZMu_z4.WtE12vMlarfjFPYht7.VEd4
AETx02GWk1W9teANHSLggqg460sTTAkk1I4ZUvaSz2LAmswVIrOBNTCZsPVd
UyFyY2lk8VmZUm7rTdcYBCnXFb7MSZ7oyva6attLT3Zm11FW2XfbnH8DJheI
iPf958m3Yk7uPjTkabbMkDNtu7RsLcRe4EUtX6CVh8jXUpFFccCIAg0mSAkY
.78Nfu4WTN.cBG1udx1RbWUuWRp6ml_AjL_i3Tpz3n.0Mh9_S6qcTDXFXqID
Ohfe4.Cy_dmVvna5Aa1QcgGHykm2GlGT3G9eW3bshC3jbUEZgT98VAf3mMFG
1IbI4Wak6SSxaFcqoE2HkHIdTIhwM.edSh3y9Md9fq2O3F2E815aPkfwe2ZJ
ZGC93dOABQ6xNC0YiYbn74yCcYLA300rBPiaMXh_v1VHd8GKm.Idcnwtv_.w
vVxmAfe.dkUMBPhE.5u1AlrvYbV5enGs8M8JWbQF40wxEsr4IQrbciAY1B8a
_UzSx668CHylXoSz8yl1_OVMOp6bMM5jRhdTiboXLqcalAxo429BPIJqrWQa
ow7AiB_uii_nFachQ3Fmv0fSuuCa67_kdn_12vC08dBlZkouXm0DlpUwQi1s
YcC9s56K46XemkbHPW8jXDhAQoHsCApDA4HkV.vhdi.LVJkeajTwU0UelupM
4P3NBCUeLVTzujQr4muQwdq0.B7hLb049toK6C1oIcPdBhBQ7hcu9lbU1FNd
vb_NcAI29iiLbNvlxh09TkqXI6Sl.tYDkh8UkPHfliGDRARh8o1Jta8xdXSm
Rr8Ph_F25zdlGU97Rc377gqWa8GedJYwAjdwBRb2SO6g_o0LeTBBW1_ryqrc
2yhhEIQpZMUrWbmkufcntlQC.QQA7fVDSPw9AOHMZ3ZHg3GO.29.8ML.Di_T
Ptno6tEKpP3NAsSpDWq2RBePnlDKiGOcnebsqyEEBaxQjvc20cLEhSCjElaE
dr1zgL3.WVVgxaTDDHXqr5xh3tBvR6Rf8eH7uKJUsQnSovyanWRmFafx3oix
jqv86zdEsDSc0Q5aBQm1.0cKu4zK5.ZLQdHcbuSO6j8nfkSgLvps7Bx1LCVf
2MQw66EjKHlLqb4gR.fOx056YyHk4BpRyP6DSdL9oO4csi274XG3UeClFd_l
0pOtXAQHHNv.AKKXjQ–
X-Originating-IP: [177.47.45.166]
Authentication-Results: mta1217.sbc.mail.gq1.yahoo.com  from=sbcglobal.net; domainkeys=neutral (no sig);  from=sbcglobal.net; dkim=neutral (no sig)
Received: from 127.0.0.1  (EHLO PcPam.connectify) (177.47.45.166)
by mta1217.sbc.mail.gq1.yahoo.com with SMTP; Wed, 27 Nov 2013 12:12:46 -0800
Received: from apache by pchiphpjhjbif.wonderware.com with local (Exim 4.67)
(envelope-from <<scamFRAUDalert)
id H7A7JA-5L1M29-5S
for scamFRAUDalert Wed, 27 Nov 2013 17:12:45 -0300
To:
Subject: Re: CV 37
X-PHP-Script: pchiphpjhjbif.biolconseils.ch/sendmail.php for 177.47.45.166
From: scamFRAUDalert
X-Sender: scamFRAUDalert
X-Mailer: PHP
X-Priority: 1
Content-Type: text/plain; charset=”Windows-1252″
Message-Id: <AC3C9G-F6N12A-AA@pchiphpjhjbif.barronheating.com>
Date: Wed, 27 Nov 2013 17:12:45 -0300
Content-Length: 1511

We are offering a shipping manager assistant position.
We are offering a distant job.

The job routine will take 2-3 hours per day and requires absolutely no investment.
You will work with big shops, suppliers, factories all around the States.
The communication line will flow between you and your personal manager, you will receive orders via email and phone,
and our trained manager will be with you while every step to help you to work out first orders and answer any questions which may appear.
The starting salary is about ~2800 USD per month + bonuses.

You will receive first salary in 30 days after you will successfully complete your first task.
When the first working month will be over you will have a right to receive salary every 2 weeks.
The bonuses are calculated on the very last working day of each month,
and paying out during a first week of the next month.

We will accept applications this week only!
To proceed to the next step we should register you in HR system so we will need a small piece of your personal information.

Please fill in the fields:
Full name:
Your Contact phone number:
Your email address :
City of residence :
We need your personal information to create HR file only,
it will stay secure on the separate server till the moment it will be deleted (which take place every 2 days),
and only HR people will have access to it.

Please send your answer to my secured email Paul@usa-googleapps.com
I will reply you personally as soon as possible.

Sincerely,
Paul Chavez

WhoIs rssing.com aka archive.is

archive2_IS

rssing

http://scamfraudalert67.rssing.com/chan-15224466/all_p3.html

http://fraudulent107.rssing.com/browser.php?indx=15224477&item=42

http://scamfraudalert.org/category/employment-alert/fake-job-offers/feed

Channel Title: scamFRAUDalert Report » fraudulent job offer

rssing2

Address lookup
canonical name rssing.com

aliases
addresses 216.155.149.122
Domain Whois record

Queried whois.internic.net with “dom rssing.com”…

Domain Name: RSSING.COM
Registrar: KEY-SYSTEMS GMBH
Whois Server: whois.rrpproxy.net
Referral URL: http://www.key-systems.net
Name Server: NS1.DOMAINDISCOUNT24.NET
Name Server: NS2.DOMAINDISCOUNT24.NET
Name Server: NS3.DOMAINDISCOUNT24.NET
Status: clientTransferProhibited
Updated Date: 29-may-2013
Creation Date: 10-jun-2010
Expiration Date: 10-jun-2014

>>> Last update of whois database: Wed, 27 Nov 2013 13:39:19 UTC <<<

Queried whois.rrpproxy.net with “rssing.com”…

Domain: rssing.com
Registry Domain ID: 1601455616_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.rrpproxy.net
Registrar URL: register your domain with http://www.d

Network Whois record

Queried whois.arin.net with “n ! NET-216-155-149-120-1″…

NetRange: 216.155.149.120 – 216.155.149.127
CIDR: 216.155.149.120/29
OriginAS:
NetName: NET-216-155-149-120-29
NetHandle: NET-216-155-149-120-1
Parent: NET-216-155-128-0-1
NetType: Reassigned
RegDate: 2013-08-16
Updated: 2013-08-16
Ref: http://whois.arin.net/rest/net/NET-216-155-149-120-1

OrgName: ReliableSite.Net LLC
OrgId: RL-102
Address: P.O. Box 110
City: Greenwich
StateProv: CT
PostalCode: 06836
Country: US
RegDate: 2012-11-27
Updated: 2012-11-27
Ref: http://whois.arin.net/rest/org/RL-102

OrgAbuseHandle: ABUSE3593-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-866-932-0001
OrgAbuseEmail: abuse@reliablesite.net
OrgAbuseRef: http://whois.arin.net/rest/poc/ABUSE3593-ARIN

OrgTechHandle: SUPPO1295-ARIN
OrgTechName: Support Department
OrgTechPhone: +1-866-932-0001
OrgTechEmail: support@reliablesite.net
OrgTechRef: http://whois.arin.net/rest/poc/SUPPO1295-ARIN

OrgNOCHandle: SUPPO1295-ARIN
OrgNOCName: Support Department
OrgNOCPhone: +1-866-932-0001
OrgNOCEmail: support@reliablesite.net
OrgNOCRef: http://whois.arin.net/rest/poc/SUPPO1295-ARIN

DNS records
name class type data time to live
rssing.com IN NS ns2.domaindiscount24.net 28800s (08:00:00)
rssing.com IN SOA
server: ns1.domaindiscount24.net
email: tech@key-systems.net
serial: 2013100609
refresh: 10800
retry: 3600
expire: 604800
minimum ttl: 180
28800s (08:00:00)
rssing.com IN NS ns1.domaindiscount24.net 28800s (08:00:00)
rssing.com IN NS ns3.domaindiscount24.net 28800s (08:00:00)
rssing.com IN A 216.155.149.122 28800s (08:00:00)
122.149.155.216.in-addr.arpa IN PTR hosted-by.reliablesite.net 3600s (01:00:00)
122.149.155.216.in-addr.arpa IN NS ns1.reliablesite.net 14400s (04:00:00)
122.149.155.216.in-addr.arpa IN NS ns2.reliablesite.net 14400s (04:00:00)

— end —

 

Related Article:

http://archive.is/5wc6R