Blog for hpHosts, and whatever else I feel like writing about ....

Monday 6 February 2012

ALERT: Liberty Reserve 419'er

Ever get the feeling they're not really trying any more? This one came into my inbox today, and it's a standard 419'er along the lines of "give us money and we'll give you double for doing absolutely nothing" - hint: You'll lose your money!!

============================================
Please note that in all e-mails from Liberty Reserve we will:
Always address you by your first name.
Never send you any links or attached files.
Never ask you to send us your password and/or login PIN.
============================================

Dear Members,

Liberty Reserve has made considerable progress and improvement, it has become the leading e-currency and its services are being improved continuously.

Recently we have estabilished a very important relation with leading Forex traders from Costa Rica and we decided to give a special offer to you:

GET 200% LR MONEY RETURN IN 5 DAYS !!!!

Example:

You deposit $100 we return $200

You deposit $1000 we return $2000

You deposit $5000 we return $10000

This opportunity will not last long, so you must react quickly.

Deposits are accepted until February 15.2012 00:00 (GMT).

One unit in this special program is worth 100 US dollars. The minimal deposit is 1 unit ($100), while the maximum deposit is 1000 units ($100000) per member.

You need to make a spend to: Liberty Reserve account U1209005 -https://sci.libertyreserve.com/?lr_acc=U1209005

The 200% payout will be made back to your LR account in 5 days.

The payout is AUTOMATICAL, GUARANTEED and there is NO RISK from losing your funds.

This is a TIME LIMITED ONE-TIME OFFER and you must ACT NOW!

Please DO NOT reply to this e mail.

For information and support please use our contact form in the help section of our web site.

Thank you.

2002 - 2011 Liberty Reserve S.A. All rights reserved.


Another hint if you've not worked it out - this has NOT come from Liberty Reserve. As much as I despise them (and Western Union), not even they are daft enough to engage in phishing scams such as this.

It actually originated from Iran;

Return-Path: <no_reply@libertyreserve.com>
Delivered-To: ceo@it-mate.co.uk
X-Spam-Flag: YES
X-Spam-Score: 9.71
X-Spam-Level: *********
X-Spam-Status: Yes, score=9.71 tagged_above=-9999 required=1.3
tests=[ACT_NOW_CAPS=2.211, BAYES_00=-1.9, FH_FROMEML_NOTLD=1.082,
FS_LARGE_PERCENT2=1.96, HTML_MESSAGE=0.001,
HTML_MIME_NO_HTML_TAG=0.377, MIME_HTML_ONLY=0.723,
MIME_HTML_ONLY_MULTI=0.001, MIME_QP_LONG_LINE=0.001,
MPART_ALT_DIFF=0.79, ONE_TIME=0.714, RCVD_IN_BRBL_LASTEXT=1.449,
RDNS_NONE=0.793, RISK_FREE=0.001, SPF_FAIL=0.001,
SPF_HELO_PASS=-0.001, SUBJ_ALL_CAPS=1.506, TO_NO_BRKTS_PCNT=0.001]
autolearn=no
Received: from server144.dnslake.com (unknown [62.193.15.160])
by mail4.emailconfig.com (Postfix) with ESMTP id 1711739814F
for <ceo@it-mate.co.uk>; Mon, 6 Feb 2012 22:52:19 +0000 (GMT)
Received: (qmail 32531 invoked from network); 7 Feb 2012 02:20:43 +0330
Content-Type: multipart/alternative;
boundary="===============4901855315610602507=="
MIME-Version: 1.0
Subject: [SPAM] =?iso-8859-1?q?GUARANTEED_200=25_MONEY_IN_5_DAYS_!!!?=
From: =?iso-8859-1?q?no=5Freply=40libertyreserve=2Ecom?=
Message-Id: <20120206225221.1711739814F@mail4.emailconfig.com>
Date: Mon, 6 Feb 2012 22:52:19 +0000 (GMT)
To: undisclosed-recipients:;


There's over 150 sites on the IP it originated from. Whether or not they're involved (i.e. directly or because they've been compromised), is something I'll be investigating.

In the meantime, if you receive this, or anything resembling it - delete it!

No comments: