LinkedIn.com Job Scams

Scammers Promise Easy Money in Trolling for LinkedIn Users

By Antone Gonsalves, CSO
November 25, 2013 09:51 AM ET

Antone Gonsalves of NETWORKWORLD.COM and other IT Security experts are LinkedIn4reporting on a growing problem with job posted on LinkedIn.com.

Accordingly, scammers have moved operation onto LinkedIn.com platform big time. Below is an excerpt which suggest that these scams are increasing at an accelerating rate.

CSO – Scammers exploiting the weak job market are looking for hapless victims on LinkedIn, which has become a major meeting site for job seekers and recruiters.

[Security experts warn against using LinkedIn Intro app for Apple iPhone]

Over the last year, swindlers promising employment have been spreading from Facebook and Twitter to LinkedIn, where their fake profiles have been popping up as fast as the site is able to take them down, Bianca Stanescu, security specialist for anti-virus vendor Bitdfender, said Friday.

While job scams are regularly found on Facebook, LinkedIn was considered less susceptible because of its professional clientele, Stanescu said. However, it seems that a LinkedIn profile with a picture of a pretty woman posing as a job recruiter and promising easy money is too hard for people, particularly men, to resist.

“It’s especially enticing for men to click on these ads to work with such beautiful human resource managers likes Christina and Annabelle,” Stanescu said. “We also found someone named Jessica.”

In a recent scam reported by Bitdefender, “Annabelle Erica,” a good-looking blonde, promised to put job applicants in touch with hundreds of companies looking for English translators.

Fake profiles that gather personal details and lead users to dangerous websites are spreading at a faster pace on LinkedIn. Amid research into the growing scams on the professional social network, antivirus software provider Bitdefender has detected a new virulent campaign that lures victims with exciting job offers from an attractive female recruiter.

Read More…..

LinkedIn

scamFRAUDalert see it appropriate to issue this PUBLIC ALERT regarding LinkedIn.com. This is to warn indLinkedIn4ividuals that it is un-advisable to post PROFESSIONAL, PERSONAL or DETAIL information on PUBLIC FORUMS and to exercise case and caution.

________________________________

Email Header Analysis

IP Address:  202.158.39.250 (ftp.petromindo.com)
IP Address Country:  Indonesia
IP Continent:  Asia
IP Address City Location:  Jakarta
IP Address Region:  Jakarta Raya
IP Address Latitude:  -6.1744,
IP Address Longtitude:  106.8294
Organization:  PT. Cyberindo Aditama

__________________

LinkedIn

REMINDERS

Invitation reminders:

From Lesley Douglas  (LinkedIn Member)

PENDING MESSAGES

There are a total of 3 messages awaiting your response. Go to InBox now.

This message was sent to scamFRAUDALERT  Don’t want to receive email notifications? Login to your LinkedIn account to Unsubscribe. LinkedIn values your privacy. At no time has LinkedIn made your email address available to any other LinkedIn user without your permission. © 2013, LinkedIn Corporation.

___________________________

LinkedIn2-spapm

From Lesley Douglas Tue Apr 9 04:09:34 2013
X-Apparently-To: scamFRAUDALERT via 98.138.213.179; Mon, 08 Apr 2013 15:40:08 -0700
Return-Path: <hede13q@ftp.petromindo.com>
X-YahooFilteredBulk: 202.158.39.250
Received-SPF: none (domain of ftp.petromindo.com does not designate permitted sender hosts)
X-YMailISG: NXWw5.QWLDunKiBqzZm_PVvJfMgp231pSvEuW4AqOiq0IjZ8
XmZoYGx1wytETnlUdAUawIEI.rd8_6NfO.F3HsENAInT6ZCUv30WFYXbiqVn
cyo3_BcEMDDbdpeYQz0yVfob2TuKMaDHEL0Z87c82HwWWL13vFqjH.5o8w7x
_eBZ7T69PIe9CbkIiFdYI4PcW6qI3gBKqxp8FvvNqmVfr.jyrEIQ09q8Ji5N
pEsZwuHJhEk.g4nnE4bLZ45FkSg7GJ0dTU438eXLYYSGG1OMH0Te3sqKtI9Y
iTB.8AK3C0IzK_ufoMtAqQ4Y1rPizf4svfSAe6h32NGFQqIyDCWTcUnmN3tn
rx5LIFcSTiymFEafsACFHp6XfpzBQEfVi_7tp.XmT2zEkg.4dLxoN9_4XjXE
y4oo8EE7Dhq4y_DRgrtdKtQBTTtjetz88Uske4IW1NAl4HlUZ64Y3grKxqvf
OxyuboGjruTVGeLG5LPhx09NwK97Fd1L8MqKV6b1EnJWBeNBt3MwBRRynShO
k5IHZ72M3Yunkg2Ot0SqZ9aoZKp1F_9mx72nPlmjHhMHwftIeytt8bTSi12S
Na.gOfoWV0JOPYQbRSkkT8o89cDOH4Tg7lgUDVZMphw6IIXV0hR_MxNtl7z2
9TopUJhN_1HCTA3axOuIxM80DHS7OSkNByyfzhWcWAcVvlWNbgdKfXkQ1tAK
HjmWk1wBVVYpqbbmmp5.ri7Pit5xeFR_1wj27xKXJNyuvzTNZMkHR96cqreS
6ssvFrxwovNkVh9_vmXaJL6AyISSo7BVSSTPYmq_C1lAF23N1lQ861bH4MbP
SDSsp_t.V83ZwY9TpFYKPyCLDJNAZZZnQxLIvSe1WdmSMeFqI_hbtq6hVBlV
ysfQGoS5OkvvyfwpK.mnCbv2lam7XVowpJBBDyUzhS6Grptfy.xkN0crIpAI
.dffxeF_.F0JHg.MDSvrH7G6sbScz2VCI9DUQWfRyc2_ij4PLSfU_654jYL_
ypf7ryd1RLWUIiUewekxiplO9MfY_XLjHZFGgCFpcLmVAYaaZ6brchTyuY4N
SMDoDn2NafskJso4XW1iBQbF26BKBymp3_uHzei73A16ptrmyA_dhqGpmtz9
Vb3f4sKy14otsuF8PwSnEeAouTKklDLzfDOCXAgrMoW9GwrzcnyNoXWVRDVM
ZUOGe1FhPwo4gpa.DUAiHvg2q0DlKZeu.yq6rMiGCNuUnfF4zQUKN87pGwtf
X5Gl5U7WCgegT_FXpw0zSgjchhpv6.z8OPS_7FqCWa6umVp0e4h1XstLlDTM
OsgUX3s-
X-Originating-IP: [202.158.39.250]
Authentication-Results: mta1289.sbc.mail.gq1.yahoo.com from=ftp.petromindo.com; domainkeys=neutral (no sig); from=ftp.petromindo.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO ftp.petromindo.com) (202.158.39.250)
by mta1289.sbc.mail.gq1.yahoo.com with SMTP; Mon, 08 Apr 2013 15:40:08 -0700
Date: Tue, 9 Apr 2013 06:09:34 -0500
From: Lesley Douglas <hede13q@ftp.petromindo.com>
To: scamFRAUDalert
Message-ID: <432d62-5edb77-b9613a@ftp.petromindo.com>
Subject: Reminder: You have notifications pending
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
Content-Length: 2025

LinkedIn – Brendan Richardson just sent you a direct message

scamFRAUDalert see it appropriate to issue this ALERT regarding LinkedIn.com. This is to warn indLinkedIn4ividuals that it is un-advisable to post PROFESSIONAL, PERSONAL or DETAIL information on PUBLIC FORUMS and to exercise case and caution.

________________________________

Email Header Analysis

IP Address:  178.63.185.165 (static.165.185.63.178.clients.your-server.de)
IP Address Country:  Germany
IP Continent:  Europe
IP Address City Location:
IP Address Region:
IP Address Latitude:  51,
IP Address Longtitude:  9
Organization:  Joao Filipe Santos Rebordao Neves

__________________________________

Email header by email header analysis (show/hide)
X-Apparently-To: scamFRAUDalert via 98.138.213.211; Thu, 04 Apr 2013 06:33:23 -0700
Return-Path: <forbes3@static.165.185.63.178.clients.your-server.de>Image representing LinkedIn as depicted in Cru...
X-Yahoofilteredbulk: 178.63.185.165
Received-Spf: none (domain of static.165.185.63.178.clients.your-server.de does not designate permitted sender hosts)X-Ymailisg: 9evfIUgWLDu9Vw4mCDDFBeF5f4z6VlLFz9qxJMtdrD.x5CkvDIGZKUmz8YEYB8XzYvp
T4Vl499HRBhItJJ0KeFvapZz2WrZhevvzvKrh8aeznjm4n6BOlMtdnVZRpoI
8Vkfle6RKGMOzput5nEgrXftmsYwxWM_c9Fyw_E5 i8I6SZ6DNdU7k6aOCw7.Wu7UOujJaXjJ_MEUoAZnH_AD5IpHAmqPvf3Foso. TR95G5OQiSxDbX4F1Qktx4LbY2x55u6qH86lB4zsFjWozrtaj63rtxikADI9 xCesANm5I5adOP4CGW3pAtPHo6hBgPkMNOA3GKXtx5ZbkUQ40buvhKu5RqSQ tC7zTuHNtqKtX3piUpZpYlajGye.8y9b0bJlQF7Y6tESOXxlgR0xZdno.9.r T5FG2iVocPbndRGpYOoy.SFCE8cr9yqIGlDOFbSc2EOuwAkzRZ3fQiGpTK88 kJL_cHTt2h5qaHG3n_h5vWaBm9PuE5ey6m_HPvuyBj6pL29igwQ7MuQTJPcs o1PtyEcxftwswGWll18bxP7U9YaYbnuJhPBShXm8zxXcgIIawbzQViiElaR9 RzUxymhLVWgdXL16G61t8X8dBV.ygjEDoGuaLOmNO2d4qPT2aVCxp0OM.R3h Ox2oL5WGcZdkzFJ0l3pAfsBrM3T9A2iQAi5nuFOPXHnppGgQRl87hb_s2n9k BbX3WbSgYnlRLTZr1hIFtTMixK0LwctOsRm2tL9.Rz1IAvt5tTEnkNDsQ_eA Zo0ilgWTetJcYV8AdiC4f.S5THF2SuW7eXHt7S61m8hVUjE7.bcHWTuYBfaC g8INjCWW5vYodnpUZtrgXkoGWVi3zw3wRMFmW0YNzLVwPM.2GjcLBMYgsNQZ 72p4LF7bNz5CwbBnRni0nvNEpHrN16QZG3E0O0QC2DNOslhXmcgylwH9Hd9y 3fw7D3aZmiSWhXllbSPTaV9VNgWLC.uRamvkP52_niixzLQmt0btiHZvjK10 scmQ17y6JPa7jV6.vTpQWJhUXsOHptwqbCL94nIYhy9VlilrnLsQ8p4B9eL2 dLoQa9cluKNrvVkojMQi8fkfUANLb0WSxNS7xhJAjVLA0qh4otky7WF8983j Hl3q0GUz4wT0Tg410VZNbNwoDeUgOcgf7DArErw3_P3smbCBqE5xUbFQ8Nht o1q5jScX.Z492pMR0uklmZekBxsmz8cpJtljJ_X3nm28
X-Originating-Ip: [178.63.185.165]
Authentication-Results: mta1221.sbc.mail.gq1.yahoo.com from=static.165.185.63.178.clients.your-server.de; domainkeys=neutral (no sig); from=static.165.185.63.178.clients.your-server.de; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO static.165.185.63.178.clients.your-server.de) (178.63.185.165) by mta1221.sbc.mail.gq1.yahoo.com with SMTP; Thu, 04 Apr 2013 06:33:22 -0700
Date: Thu, 4 Apr 2013 15:33:22 -0600
From: “Brendan Richardson via LinkedIn” <forbes3@static.165.185.63.178.clients.your-server.de>
To: “scamFRAUDalert
Message-Id: <cd28b1_faa87e95.47d473@static.165.185.63.178.clients.your-server.de>
Subject: Brendan Richardson just sent you a direct message
Mime-Version: 1.0
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
Content-Length: 1153

LinkedIn-spapm