The “new shopping new life” spam

For about a year I have been receiving spam emails like this one below. They all look like they’ve been sent by private individuals somewhere in the world (usually from Yahoo or Hotmail accounts) but advertise companies in China:

hi:
New shopping new life!
How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
Look forward to your early reply!
The Web address: www.vanigo.com
E-mail: vanigo@188.com
MSN : vanigo@msn.cn

——————————————————————————–

Få en billig laptop. Se Kelkoos gode tilbud her!

Looking at the mail headers, it had come from the mail account of a Danish Yahoo user, but originated from an IP address in China (details edited to protect the privacy of the account owner):

Received: from [124.118.179.157] by web26101.mail.ukl.yahoo.com
via HTTP; Wed, 11 Feb 2009 19:54:29 GMT
X-Mailer: YahooMailWebService/0.7.260.1
Date: Wed, 11 Feb 2009 19:54:29 +0000 (GMT)
From: uffe #####sen <uf###2@yahoo.dk>
Reply-To: uf###2@yahoo.dk
Subject: hi:
To: undisclosed recipients: ;

IP address 124.118.179.157 belongs to China Telecom:

inetnum: 124.118.0.0 – 124.119.255.255
netname: CHINANET-XJ
descr: CHINANET Xinjiang province network
descr: China Telecom
descr: No1,jin-rong Street
descr: Beijing 100032
country: CN

What appears to have happened is that spammers know the passwords to these mail accounts and are using them to send that spam to everyone in the mail account’s address book.

This is a very effective way to get through spam filters, as many recipients are likely to also have the sender in their address book and address book entries are automatically whitelisted by many spamfilters.

If you receive an email like that, alert the “sender” that their account has been compromised. They need to immediately change their email password to something more secure.

This abuse of stolen passwords illustrates the potential of password harvesting scams such as this one I documented in August 2008, which is still going on.

Here are some Google searches related to the hacked webmail spam:

Here is a (probably incomplete) list of websites advertised this way:

  • gvccn.com
  • ibvcn.com
  • jvccn.com
  • tvtcn.com
  • szfac.com
  • cxkeg.com
  • yaier.com
  • mmhdf.com
  • ixicb.com
  • vanigo.com
  • wabada.com
  • bj-trade.com
  • store-168.com
  • ele-motors.com
  • electronics-brand.com
  • exciting-zone.com

Common subject lines:

  • New shopping new life
  • Good shopping good mood!
  • Good web site
  • Have a great shopping!
  • good website!
  • Hi,Thank you!
  • Hi,
  • Dear friend

Good passwords and bad passwords

A strong password should be the first line of defense against such criminals, but what makes a password good? It should contain a mixture of all of the following:

  • lower case letters
  • upper case letters
  • digits
  • at least one non-alphanumeric character

This makes it hard to break the password through brute force or through dictionary attacks.

Also the password should not be too short (8 characters or more) and should be reasonably easy to memorize, so you don’t have much need to write it down. Some examples:

  • 45Knife%Cabbage
  • 4F5g6H&j
  • J0hn1945-07-31

Bad choices are passwords that consist of any word found in a dictionary, proper names, digits-only dates, adjacent keys on the keyboard or repeated characters. Never use anything like these:

  • secret
  • qwerty
  • xxxx
  • john45

It is very important not to use the exact same password for different purposes.

If spammers manage to trick you into revealing your password for one site (e.g. by getting you to create a new account at a site they control or by breaking into the database of another site where you’re a customer) then you’ve effectively handed them the key to the candy store. They can get access to your email account, in which they may find login information, password reminders, etc. of many other sites you’ve signed up for. At the very least they can harvest all your email contacts.

Beyond using different passwords for every site and service, it’s also a good idea to use a different password schema for “core” sites that you trust and depend upon (such as your email provider and webhost) and another for sites to which you sign up more casually (such as various forums, online shopping, etc.). Thus if one of the latter is compromised, it does not give criminals any clues what your more critical passwords may look like.

Who is behind this spam?

The sites advertised from the hacked email accounts constantly vary. They usually have been created only a few weeks or months earlier. For example, the domain in the above example was created two months ago:

Domain name: vanigo.com

Registrant Contact:
wuxianj
xiaos wu zhongfm@it5.cn
0592-5861837 fax: 0592-5861834
beijin
beijin beijin 100000
cn

Administrative Contact:
xiaos wu zhongfm@it5.cn
0592-5861837 fax: 0592-5861834
beijin
beijin beijin 100000
cn

Technical Contact:
xiaos wu zhongfm@it5.cn
0592-5861837 fax: 0592-5861834
beijin
beijin beijin 100000
cn

Billing Contact:
xiaos wu zhongfm@it5.cn
0592-5861837 fax: 0592-5861834
beijin
beijin beijin 100000
cn

DNS:
ns1.4everdns.com
ns2.4everdns.com

Created: 2008-12-08
Expires: 2009-12-08

Considering the highly illegal way the companies advertised, what are the chances that any order you make at those sites would ever get shipped to you? For sure, they will gladly take your cash by (untraceable, unsafe) Western Union or take your credit card number, expiration date and security code. Never use Western Union to send money to people you don’t know from real life in person. Never enter your credit card on a site that doesn’t have SSL access (indicated by a URL starting with https:// and a padlock icon in the browser status bar) with a proper certificate.

Even more basic: Never do business with spammers. By sending you spam, they have already proven to you that they lack any morals. You have no reason to trust them and every reason to be alert!

If you have received similar spams, feel free to post them below.

93 thoughts on “The “new shopping new life” spam

  1. Here is a spam example from October 2008, originating from IP address 123.12.234.76 in China:

    ====
    Dear friend,
    i would like to introduce a good company who trades mainly in electornic products.
    Now the company is under sales promotion,all the products are sold nearly at its cost.
    They provide the best service to customers,they provide you with original products of
    good quality,and what is more,the price is a surprising happiness to you!
    It is realy a good chance for shopping.just grasp the opportunity,Now or never!
    The web address: www.ixicb.com

    ————————————————————-
    Get the latest buzz on outsourcing. Up to date information on mergers, acquisitions and deals on BPO Watch. Try it now!
    ====

    The spam was sent by a compromised Hotmail account:

    ====
    Received: from blu0-omc4-s1.blu0.hotmail.com (blu0-omc4-s1.blu0.hotmail.com
    [65.55.111.140]) by cobalt.pobox.com (Postfix) with ESMTP id 89701400172;
    Fri, 3 Oct 2008 16:55:50 -0400 (EDT)
    Received: from BLU146-W19 ([65.55.111.137]) by blu0-omc4-s1.blu0.hotmail.com
    with Microsoft SMTPSVC(6.0.3790.3959); Fri, 3 Oct 2008 13:54:50 -0700
    Message-ID: <BLU146-W193BAD638B139C28B815B0933C0@phx.gbl>
    Content-Type: multipart/alternative; boundary=”_52839366-ef2a-4abd-916b-9b1a26a6de54_”
    X-Originating-IP: [123.12.234.76]
    From: #### S.M <advocate_####@hotmail.com>
    To: a long list of recipients
    Subject: good website!
    Date: Fri, 3 Oct 2008 20:54:50 +0000
    ====

  2. Sent in September via a cracked Hotmail account from IP 221.11.93.140 in China:

    ====
    From: “John ####” <john.#####@hotmail.co.uk>
    To: a long list of recipients
    Sent: Monday, September 29, 2008 17:57
    Subject: Dear friend

    Home | Products | Payment | Shipping | Contact us | News | Feedback | Register | Currency Converter

    Dear friend:
    We are an electronic products wholesale .Our products are of high quality and low price. If you want to do business , we can offer you the most reasonable discount to make you get more profits. We are expecting for your business.
    Please visit our website: http://www.Store-168.com

    Email :yousupplier@yahoo.com

    Looking forward to your contact and long cooperation with us!

    Our mainly products such the phones, PSP, display TV, notebook, video, computers, Mp4, GPS, xbox 360, digital cameras and so on.

    Welcome to visit our website!

    ——————————————————————————–
    Try Facebook in Windows Live Messenger! Try it Now!
    ====

  3. From IP address 121.34.172.144 in China via a cracked Yahoo account in August (personal details obscured for protection of the account onwer):

    ====
    Received: from [121.34.172.144] by web94401.mail.in2.yahoo.com via HTTP; Sat, 02 Aug 2008 21:20:25 IST
    X-Mailer: YahooMailRC/1042.48 YahooMailWebService/0.7.218
    Date: Sat, 2 Aug 2008 21:20:25 +0530 (IST)
    From: mani ####### <armani######@yahoo.com>
    Subject: Hi,Thank you!
    To: recipient removed

    Dear friend,
    We are an electronic products wholesaler located in Shenzhen China .Our products are of high quality and competitive price. If you want to find the best supplier , we can offer you the most reasonable discount to leave you more profits.
    Sincerely looking forward to your cooperation..

    Please visit our website: http://www.wabada.com

    E-mail : exwabada@yahoo.com

    MSN: exwabada@hotmail.com

    Our mainly products: such as Mobile Phone (Apple iphone , Nokia N95, Nokia N96, Nokia N76, Nokia N93i , Nokia 8800, Nokia 6500), Ipod Mp3 Mp4 Player, Ipod, Name Card Mp3, SONY PSP, GPS navigation, Memory Card , Bluetooth Headset etc.

    Welcome to visit our website! http://www.wabada.com
    ====

  4. Sent in November via a cracked Hotmail account from IP 123.6.239.123 in China:

    ====
    X-Originating-IP: [123.6.239.123]
    From: estrella ##### <#######@hotmail.com>
    Subject: Daily Trade Notifications
    Date: Sat, 22 Nov 2008 13:49:16 +0100

    Dear friend ,

    We are the store of electrical products,including phones ,laptops ,ps3 ,psp ,tv and dvd players www.exciting-zone.com.
    All of them have excited prices.Because we order them from the manufactery directly .We can take advantage of the best price.
    More important is that they are all original and brand new. You can buy them without any worry .They come with original
    warranty card and you can get free repairment in your local brand shop when it have any problems. We will chose more convinent and fast method to send your items so that it can get your door accurately in time.
    With the Christmas Day coming ,we will have many promotional activities. You will get free gift as long as you buy from us .The great gifts are waitting for you ( Games ,Ipod ,PS3, Robet dog and so on ). Sincerely hope you can enjoy shopping here www.exciting-zone.com and contact our customer service workers when you have any questions .
    Looking forward to visiting our website

    Nokia N95 8GB 248 EUR
    Sony PlayStation 80 GB 260 EUR
    Lenovo ThinkPad X300 Notebook 64771ZU 695 EUR
    Apple iPod touch 32GB w/Sofware Upgrade 198 EUR
    Apple MacBook Pro MB133LL/A 15.4″ Laptop 600 EUR
    NEW BLACK APPLE IPHONE 3G GPS 8GB 285 EUR
    Samsung i900 Omnia 16GB – Maps on 8GB Card 298 EUR
    Sony Bravia XBR KDL-52XBR4 52″ LCD HDTV 960 EUR
    Xbox 360 Premium System Fully Loaded with Peter 178 EUR

    ——————————————————————————–
    ¡Pasa del Pendrive! Skydrive almacena hasta 5 GB online gratis
    ====

  5. Same thing with this adress. Sent from a cracked hotmail acount.

    Createt 2008-11-24 an says on the webside that it was created 2002

    http://www.mmhdf.com/index.asp

    Hello!
    i would like to introduce a good company who trades mainly in electornic products.
    Now the company is under sales promotion,all the products are sold nearly at its cost.
    They provide the best service to customers,they provide you with original products of
    good quality,and what is more,the price is a surprising happiness to you!
    It is realy a good chance for shopping.just grasp the opportunity,Now or never!
    The web address http://www.mmhdf.com

    Domain name: mmhdf.com

    Registrant Contact:
    du hai
    hai du
    +86.1067486541 fax: +86.1067486541
    beijing chaoyang xidawanglu137hao
    beijing Beijing 100021
    cn

    Administrative Contact:
    hai du
    +86.1067486541 fax: +86.1067486541
    beijing chaoyang xidawanglu137hao
    beijing Beijing 100021
    cn

    Technical Contact:
    hai du
    +86.1067486541 fax: +86.1067486541
    beijing chaoyang xidawanglu137hao
    beijing Beijing 100021
    cn

    Billing Contact:
    du hai
    +86.1067486541 fax: +86.1067486541
    beijing chaoyang xidawanglu137hao
    beijing Beijing 100021
    cn

    DNS:
    ns1.4everdns.com
    ns2.4everdns.com

    Created: 2008-11-24

  6. Sent today from a hacked Hotmail account from IP address 124.118.168.210:

    ====
    RE:hi
    Heya,how are you doing recently? I would like to introduce you a very good company which i knew. Their website is www.xmas-buy.com. They can offer you all kinds of electronical products which you need like laptops,gps,TV LCD,cell phones,ps3,MP3/4, etc……..Please take some time to have a check ,there must be somethings you’d like to purchase.
    THeir contact email: xmas_buy@vip.188.com MSN: xmas-buy@hotmail.com
    Hope you have a good mood in shopping from their company !
    Regards

    ——————————————————————————–
    Agrupa tus contactos de Messenger y realiza conversaciones grupales.
    ====

  7. Hi, I lost nearly 1 thousand € because I acted in a very stupid way trusting this kind of websites. I have lost all hopes on trying to get any money back or find the people behind all this. But if you know anything about more people who had been through the same as me, I’d like to have a chat with them. Thanks, from South America Argentina.

  8. hi there i was reading about VANIGO.COM
    thank you so much for the info cause i was ready to order something from them but before i did i check their site and confirmed it is a scam. Also i should let you know that i came across another one like vanigo from a e-mail i received the site is the same thing different name, globseason.com they also sell electronics and if you notice there contact info it looks like they are in the same building.
    thank for your time please post this

    Franco

  9. So glad i read this webpage!!!! was about to pick up the phone and order something from mmhdf.com but now my suspisions have been realised. if it seems too good to be true it usually is! thank you!

  10. Received from a hacked Hotmail account:

    ====
    Subject:
    Date: Thu, 5 Mar 2009 16:44:25 +0000

    Hey friend,
    How are you doing recently? I’d like to introduce you a very good foreign trading online company and the website is www.shuenwoyi.com
    It can offer you so many kinds of electronic products which you may be in need,such as laptops, gps, TV, cell phones, ps, MP3/4, motorcycles even several kinds of musical instruments and etc..
    You can take some time to have a check ,there must be something you are interested in and you ‘d like to purchase .
    The contacts:
    Mail : shuenwoyi@188.com
    MSN : shuenwoyi@hotmail.com
    Hoping you can enjoy your shopping from that company !
    Regards
    ====

  11. I have found the website of Chinese Comp
    in Beiing – w address¨: http://www.mmhdf.com
    they have also online chatwindow, so you can put a question a you / even on Sunday/ can communicate with somebody from this company. Who has got some experience, good or bad with this company
    let me know…Mila from Prague Czech

  12. míla,

    mmhdf.com is a scam, like all the other companies listed in this thread. They will take your money and not send you anything you ordered.

    This company also sends spam and hacks email accounts, which is openly criminal, but even with Chinese companies that are not obviously criminal one has to be careful and know exactly what one is doing in order to not get cheated, because the courts and the police in China will not be of much help to a foreigner who lost money in a scam.

  13. New shopping new life!
    How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
    Look forward to your early reply!
    The Web address: http://www.globseason.com
    E-mail: globseason@188.com
    MSN : globseason@live.cn

    ——————————————————————————–
    Planning the weekend ? Here’s what is happening in your town. as well as from down South.

  14. I got the following message today. It deleted all my contact entries and changed my vacation setting to ON. I have been placing fake orders on their website and pasting their message (below) in the Order Remarks section about 100 times with each order. The idea is to flood their ordering system with data intensive spam orders. If everyone who is a victim sends them such orders, they will think twice about doing this again to other unsuspecting users.

    New shopping new life!
    How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
    Look forward to your early reply!
    The Web address: http://www.globseason.com
    E-mail: globseason@188.com
    MSN : globseason@live.cn

  15. i was stupid enough to order and paid using western union; they sent me another e-mail asking for more money for the custom duty . when asked to cancel the order they stop replying to my mail , its a scam PLEASE BE CAREFUL NEVER ORDER ANYTHING FROM GLOBSEASON.COM, ITS A COMPANY BASED IN CHINA AND NEVER PAY TO ANY COMPANY USING WESTERN UNION ITS NOT TRACEABLE AND YOU WILL LOSE YOUR MONEY.

  16. The guys at Globseason have created another website: http://www.FDtrade.com. It has the same look and feel,and it evens says Globseason at the top. I think the scam is simple: Create a website that looks legitimate with lot of items to sell, etc. They probably are running this from some apartment in China and don’t have anything that is advertised on the website. If they can get at least 200-300 people around the world to order from them and send them money, they can easily make $50,000 to $100,000. They can then shut this website down and open another one. They probably know that the Chinese Govt will do nothing to them. Or, maybe they are even giving a share of the profits to some Government official.

  17. Also I have receive mail as following:(Fri, 13 Mar 2009 23:52:44 -0700 mail reach time: 2009-03-14 14:52:46)
    New shopping new life!
    ?How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
    Look forward to your early reply!
    The Web address:?www.globseason.com
    E-mail: globseason@188.com牋?
    MSN : globseason@live.cn

  18. Hello Eugene Richardson,

    “fdtrade.com” is hosted on the same IP as “mntrd.com”, another scam site. I added both the spam list.

    The following sample was sent from IP 70.87.152.171, which is probably a proxy site:

    ====
    Nice shopping for you!
    i would like to introduce a good company who trades mainly in electornic products.
    Now the company is under sales promotion,all the products are sold nearly at its cost.
    They provide the best service to customers,they provide you with original products of
    good quality,and what is more,the price is a surprising happiness to you!
    It is realy a good chance for shopping.just grasp the opportunity,Now or never!
    The web address: http://www.mntrd.com
    ====

    You are probably right about the Chinese government not taking action, but it’s not just the Chinese. Fake electronics stores claiming to be based in the UK, in Spain and many other countries also defraud numerous victims.

    Unfortunately international fraud using the Internet is usually not investigated and prosecuted, unless someone has lost hundreds of thousands of dollars.

    There are just so many people who do not understand that they can not do business internationally as they would in the same city or state, because once jurisdiction issues come into it (i.e. your police can’t directly arrest the bad guys) you’re usually on your own, unless the damage is HUGE.

  19. A few pieces of advice to readers of this thread:

    1) If electronics sellers want to be paid by Western Union or MoneyGram, assume it to be a scam.

    2) If they sells popular electronics items more than 10% cheaper (or even 5%) than you can find anywhere else, it’s a scam. Margins are razor thin in this market. The only way someone can undercut other suppliers by 30% is by never shipping anything.

    3) An electronics website in China or the UK that prices its goods in euro is a scam. An electronics website in the euro zone that prices its goods in dollar is a scam.

    4) Any electronics exporter based in Nigeria is a scam. There are only importers there. Don’t buy from anyone in Nigeria unless you yourself live there.

  20. Here are the details of the globseason domain. Note that the domain was created just recently – Jan 19, 2009. Apparently, this person, bingbing, owns at least 12 other domains:

    Domain name: globseason.com

    Registrant Contact:
    bingbing
    bing bing bingbing010@sina.com
    010-5874874 fax: 010-2587458
    beijin
    beijin biejin 100000
    cn

    Administrative Contact:
    bing bing bingbing010@sina.com
    010-5874874 fax: 010-2587458
    beijin
    beijin biejin 100000
    cn

    Technical Contact:
    bing bing bingbing010@sina.com
    010-5874874 fax: 010-2587458
    beijin
    beijin biejin 100000
    cn

    Billing Contact:
    bing bing bingbing010@sina.com
    010-5874874 fax: 010-2587458
    beijin
    beijin biejin 100000
    cn

    DNS:
    ns1.4everdns.com
    ns2.4everdns.com

    Created: 2009-01-19
    Expires: 2010-01-19

  21. Here is another one, made to look like an eBay message but actually sent through a hacked Hotmail account and originating from IP 115.59.73.5 in China:

    ====
    [eBay logo] eBay sent this message to Jen lyon (E-founders).
    Your registered name is included to show this message originated from eBay. Learn more.

    This member has a question for you.

    Dear friend:
    Please forgive us to disturb your precious time.This is an agent of online trade, accept paypal payment.
    There are famous brand of Shoes, clothing wear, Bag, Watch, other accessory of electron.
    I’m sure you would have great interesting.
    I’m sure that all the merchandise are updated,fascinating and of good quality as well as SURPRISE low price .
    If you have time, please visit our website: http://www.E-founders.com

    MSN/E-mail: E-founders@hotmail.com
    website: www[b][/b].E-founders.com

    Answer the question

    Item and user details
    Item Title: IBM ThinkPad T60p 233GHz T7600 2GB 100GB 7200 15….
    Item Number: 12642
    Item URL: http://www[b][/b%5D.e-founders.com/productinfo.asp?id=3460
    End Date: Feb-03-08 18:11:03 PST
    From User: E-founders( 9821)

    100.0% Positive Feedback
    Member since Aug-10-05 in United States
    Location : KY, United States
    Activity with billy5547 (last 90 days):billy5547 has bid on 0 of my items

    ——————————————————————————–
    Conheça já o Windows Live Spaces, o site de relacionamentos do Messenger! Crie já o seu!
    ====

  22. Your blog is very helpful. I got the “Re:hi” message recently in my cracked hotmail accounta bout the www .globseason.com company. You’ve already mentioned that company. Just like Eugene’s response, it deleted all my hotmail contacts and set my vacation setting to on. Pretty frustrating. I’ve since changed the password to a stronger one.

  23. Sent from IP 222.88.240.8 in China via a hacked MSN account:

    ====
    Subject: RE:
    Date: Wed, 8 Apr 2009 04:10:45 -0600

    Dear,
    I found a nice site recently.I am sure you will like it,it is really wonderful.It sells electronic products.
    I have bought some products from this company.The price was very cheap,and the products have very good quality.
    Please do have a look at this web page : www .djqoop.com
    I am sure you will save lots of money.
    Best regards,

    ——————————————————————————–
    Tell the whole story with photos, right from your Messenger window. Learn how!
    ====

  24. Received via a hacked Gmail account, sender IP unknown:

    ====
    Sent: Sunday, April 12, 2009 04:52
    Subject: Dear Friend,

    Dear Friend,

    New shopping new life!

    How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.

    Look forward to your early reply!

    The Web address: www. easylifeing.com

    ====

  25. Sent from a hacked Hotmail account from IP 121.23.123.186 in China:

    ====
    Sent: Sunday, April 05, 2009 08:06
    Subject: helloT

    Welcome to our company site:www .ele-warehouse.com
    We are a large electronics product ssale company that locates in China. Our vision is to grow and expand the market to share with our customers.We treasure a long term business partnership. Quality and prestige are the most important for us.We mainly sell our products to those countries: USA,UK,Germany,Italy,Sweden,France,Canada,Australia,South American, etc.
    Products the best selling:

    About us Payment Shipping Contact us
    E-mail: worldtradingsky@188.com
    MSN: ele-warehouse@hotmail.com
    Address: www .ele-warehouse.com
    postcode:100086 Copyright2009, All Rights Reserved
    ====

  26. Had this one sent from my Hotmail account yesterday, Hotmail support are useless.

    Nice shopping for you!
    i would like to introduce a good company who trades mainly in electornic products.
    Now the company is under sales promotion,all the products are sold nearly at its cost.
    They provide the best service to customers,they provide you with original products of
    good quality,and what is more,the price is a surprising happiness to you!
    It is realy a good chance for shopping.just grasp the opportunity,Now or never!
    The web address: http://www.cdert.com

  27. I received the very same e-mail today from a yahoo account:

    New shopping new life!
    What are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer realy competitive and reasonable price and high quality goods for our clients,so i think you make a big profit if do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
    Look forward to your early reply!
    The Web address: www(dot)easylifeing(dot)com
    Elizabeth!

    The sad thing is it came from a friend I met at acting school last year. I knew she didn’t have bad grammar like this! Thank you so much for posting this blog! It saved me trouble!

  28. Hello,

    I just received an email from a friend. Basically the same type of BS. I checked it out because the friend is a good friend of mine. The prices were too good to be true prompting me to buy. The website was http://globseason.com….
    I checked the site through the whois.net database and found the site only opened in january. 4 months ago. I then started researching the site online and found a few discussions about this site and how they will steal your money. I will notify my friend to change her password and I also say thank you for having this blog up.

  29. Good on you Joe….here is another dodgy site nshopcn.com , came from a hotmail account in the UK. I nearly bought some stuff from them….how gullible can you get? Sure enough Western Union is one of the preffered methods of payment….or straight into their bank account!
    Keep up the good work.
    Phil

  30. Thanks for providing such great info. Here’s one my friends received from me! They also wiped out my entire contact list. Luckily I have the important ones backed up:

    Hello!How are you recently?
    I would like to introduce a good company who trades mainly in electornic products.Now the company is under sales promotion,all the products are sold nearly at its cost.They provide the best service to customers,they provide you with original products of good quality,and what is more,the price is a surprising happiness to you!It is realy a good chance for shopping.just grasp the opportunity,Now or never!The web address: http://www.nshopcn.com

  31. From IP 125.44.158.151 in China in “German” via a hacked Hotmail account:
    ====
    Is everything going on well?

    Ich m?chte eine gute Web-Shop, wo vertreibt alle Arten von Elektronik: Handys, Laptops, Fernseher, Kamera und so weiter.

    Ich kaufte mir ein Motorrad gibt. Es ist sehr sch?n und mit niedrigeren Preis. Ich glaube, es ist zuverl?ssig und wettbewerbsf?hig mit so guter Qualit?t und günstigen Preis. Sie k?nnen ja mal versuchen. Die

    Website: http://www.sjwffd.com

    Die Kontakt-E-Mail: sjwffd@188.com MSN: sjwffd@hotmail.com

    Hoffe, Sie genie?en k?nnen Sie in Shopping aus, dass die Firma!

    Grü?e

  32. This seems to be getting more and more common – I’ve had several friends with Hotmail accounts who I’ve had to advise to change to a stronger password. It’s not a keylogger, and I don’t think it’s phishing – otherwise I think we’d see other email providers targeted more.
    The following page features a response from Windows Live: https://windowslivehelp.com/community/t/39018.aspx implying phishing rather than a brute force attack.

    Previous examples used to include all the recipients from the address book in the To line – now I think it’s more often BCCed.

    Here’s one from today, again from a China IP:

    X-Originating-IP: [218.26.8.207]
    Subject: Hello!How are you recently?
    To: undisclosed-recipients:;

    Same text as Spaceman Spiff, different domain:

    Hello!How are you recently?
    I would like to introduce a good company who trades mainly in electornic products.Now the company is under sales promotion,all the products are sold nearly at its cost.They provide the best service to customers,they provide you with original products of good quality,and what is more,the price is a surprising happiness to you!It is realy a good chance for shopping.just grasp the opportunity,Now or never!
    The web address: (www.spamsomunged.elecshopcn.com)

    I’ve inserted that subdomain, as I’m worried we might accidentally get the spammer’s sites listed higher on a search engine by posting URLs here.

    (I note that it is sent in the same quoted-printable format, escaping commas, that Hotmail always uses. All this makes it quite hard to block as spam, except using a RHSBL/SURBL like Joe’s. There’s been a lot of webmail phishing, but that mostly seems to be centred in Nigeria.)

  33. Here’s another:

    X-Originating-IP: [115.61.200.170]
    From: Munged munged
    To:
    Subject: re
    Date: Sat, 16 May 2009 11:11:22 +0000

    Dear friends:

    – Do you need famous brand of electronic products with original quality and international warranty?
    – Here is a very good shoppingsite: http://spamsomunged.ohereonline.com
    – It involves the world of popular electronic products,agents of the brands have DELL | SONY | HP | IBM | APPLE | PANASONIC | LG | SAMSUNG | CANON | NOKIA | MOTOROLA. There is much profit for you if you are our stable customer or agent.

    – WEB: http://spamsomunged.ohereonline.com

    – Kind regards !

    Don’t want to receive this email? Unsubscribe from this email.

    ———
    The unsubscribe link is to my.ebay.ca, unrelated of course.

  34. Finally, one in French and English asking for direct email/IM contact rather than via the store:

    X-Originating-IP: [60.10.213.207]
    From: munged@hotmail.com
    To: sorted email addresses beginning with h…
    Subject: RE:

    Chers amis:
    Nous sommes un grand grossiste qui vendent principalement des produits électriques tels que les ordinateurs portables, TV, appareil photo numérique, mobile, vidéo numérique, MP4, GPS, et ainsi de suite. Et notre web officiel est fcxqrz.com Nous vous offrons les produits de la meilleure qualité et de prix. Tous les articles sur notre site Web sont tout nouveau usine scellées en boite et de garantie offert par le produit original.
    E-Mail: fcxqrz01@188.com
    MSN: fcxqrz@hotmail.com

    Dear Friends:

    We are a large wholesaler who mainly sell electrical products such as laptop,TV,digital camera, mobile, Digital Video, Mp4, GPS, and so on. And our official web is fcxqrz.com We offer you the products with the best quality and price .All the items on our website are brand new in sealed factory box and offered warranty by the original manufactures .

    Email: fcxqrz01@188.com

    MSN : fcxqrz@hotmail.com

  35. Hi Cedders, I have a sample from the same scammers from last October from a Danish Hotmail account, Chinese IP 61.51.169.207:

    ====
    Dear Friends:
    We are a large wholesaler who mainly sell electrical products such as digital camera, mobile, TV, Laptop, Digital Video, Mp4, GPS, and so on. And our official web is www.fcxqrz.com We can offer you both high quality products and good price .All items we list on this website are brand new and original with sealed box. and come with official warranty .
    MSN : fcxqrz@hotmail.com
    Email: fcxqrz01@yahoo.com.cn

    Thank you and best regards.

  36. Another one, this time from an IP address in the US (208.184.6.17, 208.184.6.17.available.above.net). The IP has been linked to spamming activity by Project Honeypot.
    ====
    Hi friend:
    we are the International Electronics Import and Export Corporation.(BIEIEC)
    Such as: Digital Cameras, PSP,LCD TV, Laptops Notebook, Digital Video,Mp4,GPS,
    and so on.
    We will offer you best goods and service.
    If you are interested in any product, or have any questions,please contact us.
    I guarantee you that all our goods with lowest price and best quality.
    We will offer you excellent after-sale service.
    We do hope we can have a happy and long term partnership in the near future.
    E-mail: service@goldensaler.com
    support@goldensaler.com
    MSN: goldensaler@live.cn
    web site: www.goldensaler.com

    ——————————————————————————–
    What can you do with the new Windows Live? Find out

  37. Sent from IP address 60.10.210.24 in China via a hacked Hotmail account:
    ====
    Sir/Madam
    Please forgive us to disturb your precious time !
    Welcome to visit our supply site:offersell.net
    brand shoes,bags and clothes.more autumn clothes waiting for you.
    ◆The best service ◆Quick delivery
    ◆Competitive price ◆A large selection of merchandise
    More information,please visit my online shipping store.
    Any question please *M-S-N*:lianghong2010@hotmail.com
    Best wishes! 🙂

    ——————————————————————————–
    Gana premios actualizando tu Perfil de Windows Live

  38. THIS IS AN EMAIL THAT I RESEIVED FROM A FRIEND :It is a large wholesaler who trade mainly in all kinds of electronical products for promotion. To my surprise, their products are very low price and high quality.

    I bought an iphone from this website last month, and the iphone works very well! I think it is a shopping paradise which can bring you much benefit, so i want to share it with you! It is really worthy to have a try.

    Best Regards!

    AND THIS IS WHAT HAPPENED : I SHOWED THIS TO MY HUSBAND AND HE DESIDE TO CHECK IT OUT , BECAUSE WE KNOW THE FRIEND SO WE DIDN’T DOUBT , MY HUSBAND LIKED ONE NIKIA PHONE AND HE WANTED TO BUY IT , BUT THE ONLINE SUPPORT TOLD HIT THAT HE HAS TO BUY 3 ON THAT LOW PRISE , AND HE ASKED THEM IF THE PRODUCTS R REAL AND WHY SO CHEAP, THEY EXPLAIN THAT THE GET THEM FROM FINLAND AND THAY R A WHOLE SALERS THATS WHY THEY SALE THEM FOR LESS . HOWEVER MY HUSBAND DESIDED TO BUY THEM , SO HE SENT MONEY THROUGH WESTERN UNION , 3 DAYS LATER THEY CONTACT HIM THROUGH EMAIL SAYING THAT THE BORDER OF CHINA WANTS TO CHARGE THE PAKAGE 259 EURO DUTY ,OR IF HE WANTS HE CAN ORDER SOMETHING ELSE AND IF THE TOTAL IS 8OO EURO THEY WILL COVER THE DUTY. NOW ITS BEEN A WEEK AND WE WERE SUPPOSE TO RESEIVED THEM BY THURSDAY THE -PAST WEEK, NO MORE ONLINE SUPPORT NOTHING , TODAY MY HUSBAND START LOOKING FOR FEEDBACK BUT OFCOURSE IT IS NOT OPEN FOR PUBLIC SO WE FOUND YOUR WEB SIDE . IF U HAVE ANY SUGGESTION HOW WE CAN WANR EVERYBODY SO NOBODY GET SCAM LIKE US TELL US , WE LOST HOPPEFULLY NOBODY ELSE THANK U FOR TAKING TIME READING IT

  39. Hello Stoianaka,

    unfortunately once you’ve sent money via Western Union or MoneyGram and it has been picked up, there is nothing you can do to get the money back or to trace the criminals. You have no protection against fraud whatsoever, but many people are not aware of that. That is precisely why criminals like to use it.

    Almost all Nigerian scams involve Western Union or MoneyGram and so do many scams involving scammers from China, Indonesia, Romania, Russia and Ukraine.

    WU and MG should *never* be used to send money to anyone you don’t know personally from real life. Never use it for online business. In fact, my advice would be to break off any business where these modes of payment are even just mentioned.

    This is what Western Union says for itself on its website on the subject of fraud involving their service:

    ====
    Protect Yourself from Fraud

    The Western Union Money Transfer® service is a great way to send money to people you know and trust. If you need to send money to someone you don’t know well, you may be putting yourself at risk for fraud.

    Because we care about consumers, Western Union urges you to protect yourself from fraud by considering the following:

    * Never send money to a stranger using a money transfer service.
    * Beware of deals or opportunities that seem too good to be true.
    * Don’t use money transfer services to pay for things like online auction purchases.
    * Never send money to pay for taxes or fees on foreign lottery winnings.
    * Never send a money transfer, in the name of a friend or relative, with the intention of changing the name to someone you have not met personally.
    * Never send a money transfer, in the name of a friend or relative, in order to delay payment of the transaction to someone you have not met personally.

    If you think you’ve been a victim of fraud, contact us at 1-800-448-1492.
    ====

  40. I have been looking at this site for some time now only because it deals with paypal so although it is listed as one of your spammer a/cs how can paypal allow this to go on?

    Concerned caribbean

  41. Hello Sean,

    online scammers that claim to accept Paypal often say so only to gain the confidence of people, to make themselves look legitimate. When you then place an order they will tell you that they recently stopped taking PayPal because there’s been too much fraud (what irony!) and suggest you send them money by WU if you want quick delivery.

    Another, less common scam is that they give you a PayPal address of someone they have recruited to forward PayPal payments to them. That person will withdraw the payments and wire them to the scammers by WU. When you then report the scam to PayPal and the payment gets canceled, that forwarder will end up owing money to PayPal and will have his/her account locked, while the scammers already have cash. Either way, someone always ends up out of pocket and it’s not the scammers.

    Using credit cards is not much safer either, because some bogus sellers only provide the option to pay by credit card in order to harvest credit card details (card number, expiration date, security code, billing address), to then sell that data on the black market to other fraudsters, or to charge purchases to your card. Did you ever wonder how these guys pay for all the website registrations without getting traced?

  42. I receive spam E-mails about this company in chaina call’s FUDA TRADE (fdtrade.com)
    ofering me “amazing” deals in electronics,
    I catch the sacam because I was looking for aa Sony Bravia XBR6 lcd tv and they offerme this tv , but the picture was a Samsung tv with a technical description of a Sony Bravia XBR6 lcd tv, this way I know some thing is wrong, I ask and they reply…and insit that they picture on his website belongs to a sony tv, which was obiusly WRONG, this website desapire now, they are probabli with another name.

  43. Apart from changing your hotmail password what else can we do to stop this? I changed my password last night (GMT) and I had another email go out from my account at 0100. Any ideas this is driving me mad!!

  44. Stef, if they can gain access to your account even after you change password, that’s scary.

    From what I gathered so far, the main way they get in is weak passwords, not something more devious such as key logging (recording all keystrokes and sending them to the criminal).

    They also can set up auto-responders or signatures to send or add their ad to your personal contacts. Could this have been the case for the most recent email?

    Check all your Hotmail settings for anything you don’t recognize. The safest of course would be to start a new mail account and ask for the old one to be closed. Personally I would not recommend Hotmail.

  45. Sent from IP address 116.22.17.2 in China via a hacked Hotmail account:
    ====
    Dear Sir/Madam:

    – Welcome to:<http:tusrust.net>

    – We are a wholesale company of shoes, bags, shirts, sunglasses, watches, belts of Gucci, Prada, Nike, LV.Puma.Chanel and so on.

    – Here we can supply you a best price. we are looking for business partner now.hope we can cooperate.looking forward to you.our company accept the payment via paypal.

    – Via MSN/Email:happyclick123@hotmail.com
    – PayPal.The Safer,Easier way to pay and get paid onliine……

    – Kind Regards 🙂
    ====

  46. During the last few months I don’t stop getting these “Dear friend” and similar messages.
    I have tried SpamFighter blocking and Hotmail message rules blocking without any success.
    Obviously I have no intention to contact or place an order. It is very annoying but I can’t find a good solution. Closing my present email account and start a new one is not practical.
    A reasonable reaction could be punishing these sites by overflooding them with fake messages. All one needs is an auto message generator to be activated against these spam sites. I wonder if this can be considered an illegal reaction.

  47. hi there,

    finally I was hacked by this spam. They copy their spam message and activate your automatic absence answer.

    To stop it, I found only one way. Remove your absence automatic answer and change your password.

    Hoping it can help

  48. To: skyhigh2008@live.com
    Date: Wed, 23 Sep 2009 22:07:17 -0700
    From: jaja496@hotmail.com
    Subject: Vacation reply

    Heya,how are you doing recently ? I would like to introduce you a very good company which i knew.Their website is http://www.buangels.com .They can offer you all kinds of electronical products which you need like laptops ,gps ,TV LCD,cell phones,ps3,MP3/4,motorcycles etc……..Please take some time to have a check ,there must be somethings you ‘d like to purchase .
    Their contact email: buangels@188.com . MSN: buangels@hotmail.com
    Hope you have a good mood in shopping from their company !
    Regards

Leave a Reply

Your email address will not be published. Required fields are marked *