|
419 Scam – Harry Potter Audition Scam
The Harry Potter Audition Scam offers a chance to audition for a Harry Potter movie casting, but other than that works the same way as a job agency scam, of which it is a variant. In such scams a fake job agency offers a job at excellent conditions only to defraud the victim who is made to send cash for travel costs, visas and other incidental expenses. The promised job doesn't exist. We received the samples of the fraud emails since November 2005, from an IP addresses (1, 2) that have been the sources of numerous other advance fee fraud emails (classic Nigerian scams, fake lotteries, company representative scams).
Example email (November 2005): This spam was not sent from the UK but from an IP address of a satellite broadband provider in Israel that hooks up many Internet cafes in Nigeria and elsewhere in West Africa:
WARNERBROS ACTING STUDIOS Message headers: Received: from webmail.minx.net.uk ([212.85.248.15] helo=localhost.localdomain) by emailhost with esmtp (Exim 4.54) id 1EcNkI-0004Da-P2 for emailaddress; Wed, 16 Nov 2005 14:54:42 +0100 Received: (from apache@localhost) by localhost.localdomain (8.11.6/8.11.6) id jAGDrY420249; Wed, 16 Nov 2005 13:53:34 GMT X-Authentication-Warning: localhost.localdomain: apache set sender to cast@cymreig.co.uk using -f Received: from 80.179.244.99.satcom-systems.net (80.179.244.99.satcom-systems.net [80.179.244.99]) by webmail.minx.net.uk (IMP) with HTTP for <TWISP530932@mail.minx.net.uk>; Wed, 16 Nov 2005 13:53:32 +0000 Message-ID: <1132149212.437b39dc32cad@webmail.minx.net.uk> Date: Wed, 16 Nov 2005 13:53:32 +0000 From: cast@cymreig.co.uk Subject: WARNERBROS CASTSEARCH MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit User-Agent: Internet Messaging Program (IMP) 3.2.2 X-Originating-IP: 80.179.244.99 Scam email December 2005:
From: <cast@cymreig.co.uk> Message headers: Received: from 80.179.244.99.satcom-systems.net (80.179.244.99.satcom-systems.net [80.179.244.99]) by webmail.minx.net.uk (IMP) with HTTP for <TWISP530932@mail.minx.net.uk>; Fri, 16 Dec 2005 16:49:01 +0000 Message-ID: <1134751741.43a2effd97c9a@webmail.minx.net.uk> Date: Fri, 16 Dec 2005 16:49:01 +0000 From: cast@cymreig.co.uk Subject: WARNERBROS CASTSEARCH
WHOIS details for sending network (IP 80.179.244.99): % This is the RIPE Whois query server #2. % The objects are in RPSL format. % % Note: the default output of the RIPE Whois server % is changed. Your tools may need to be adjusted. See % http://www.ripe.net/db/news/abuse-proposal-20050331.html % for more details. % % Rights restricted by copyright. % See http://www.ripe.net/db/copyright.html % Note: This output has been filtered. % To receive output for a database update, use the "-B" flag % Information related to '80.178.0.0 - 80.179.255.255' inetnum: 80.178.0.0 - 80.179.255.255 org: ORG-GLIC1-RIPE netname: IL-GOLDENLINES-20020705 descr: Provider Local Registry descr: Golden Lines International Communication Services Ltd. country: IL admin-c: DR5299-RIPE tech-c: DR5299-RIPE status: ALLOCATED PA mnt-by: RIPE-NCC-HM-MNT mnt-lower: AS9116-MNT mnt-routes: AS9116-MNT source: RIPE # Filtered organisation: ORG-GLIC1-RIPE org-name: Golden Lines International Communication Services Ltd. org-type: LIR address: 25 Hasivim St. K. Matalon address: 41970 address: Petach Tikva address: Israel phone: +97239291122 fax-no: +97239274608 admin-c: DR5299-RIPE admin-c: AG914-RIPE admin-c: GE2074-RIPE admin-c: MH21010-RIPE admin-c: IB737-RIPE admin-c: KI373-RIPE mnt-ref: AS9116-MNT mnt-ref: RIPE-NCC-HM-MNT mnt-by: RIPE-NCC-HM-MNT source: RIPE # Filtered role: DNS REG address: 25 Hsivim st. Petach-Tiikva, Israel remarks: trouble: abuse@012.net.il admin-c: GE2074-RIPE tech-c: IB737-RIPE tech-c: AG914-RIPE nic-hdl: DR5299-RIPE mnt-by: AS9116-MNT source: RIPE # Filtered abuse-mailbox: abuse@012.net.il % Information related to '80.179.244.0/24AS9116' route: 80.179.244.0/24 descr: Golden Lines origin: AS9116 mnt-by: AS9116-MNT source: RIPE # Filtered
Scam email in December 2005: From: "John Micheal" <johnmicheals@suuperstores.net> Message headers: Received: from delos.hu-delos.com (hu-delos.com [67.15.182.13]) by mx.gmail.com with ESMTP id 8si695754wrl.2005.12.14.06.12.13; Wed, 14 Dec 2005 06:12:18 -0800 (PST) Received-SPF: neutral (gmail.com: 67.15.182.13 is neither permitted nor denied by best guess record for domain of johnmicheals@suuperstores.net) Received: from stores14 by delos.hu-delos.com with local (Exim 4.52) id 1EmXIl-00012x-V2; Wed, 14 Dec 2005 14:08:16 +0000 From: "John Micheal" <johnmicheals@suuperstores.net> To: Reply-To: johnmicheals@z6.com Subject: Harry Potter Audition X-Mailer: NeoMail 1.27 X-IPAddress: 212.199.108.236
WHOIS details for sending network (IP 212.199.108.236): % This is the RIPE Whois query server #2. % The objects are in RPSL format. % % Note: the default output of the RIPE Whois server % is changed. Your tools may need to be adjusted. See % http://www.ripe.net/db/news/abuse-proposal-20050331.html % for more details. % % Rights restricted by copyright. % See http://www.ripe.net/db/copyright.html % Note: This output has been filtered. % To receive output for a database update, use the "-B" flag % Information related to '212.199.108.128 - 212.199.108.255' inetnum: 212.199.108.128 - 212.199.108.255 netname: Gilat-ISP-Benin1 descr: Please Send Abuse/SPAM complaints to Abuse-gilat@012.net.il country: GB admin-c: DR5299-RIPE tech-c: DR5299-RIPE status: ASSIGNED PA mnt-by: AS9116-MNT mnt-lower: AS9116-MNT source: RIPE # Filtered role: DNS REG address: 25 Hsivim st. Petach-Tiikva, Israel remarks: trouble: abuse@012.net.il admin-c: GE2074-RIPE tech-c: IB737-RIPE tech-c: AG914-RIPE nic-hdl: DR5299-RIPE mnt-by: AS9116-MNT source: RIPE # Filtered abuse-mailbox: abuse@012.net.il % Information related to '212.199.108.0/24AS9116' route: 212.199.108.0/24 descr: Golden Lines origin: AS9116 mnt-by: AS9116-MNT source: RIPE # Filtered
|