{"id":3159,"date":"2019-10-24T13:52:15","date_gmt":"2019-10-24T04:52:15","guid":{"rendered":"https:\/\/joewein.net\/blog\/?p=3159"},"modified":"2019-10-24T13:56:17","modified_gmt":"2019-10-24T04:56:17","slug":"loan-application-spam","status":"publish","type":"post","link":"https:\/\/joewein.net\/blog\/2019\/10\/24\/loan-application-spam\/","title":{"rendered":"Loan Application Spam"},"content":{"rendered":"<p>Usually Gmail does a great job at keeping spam out of my Gmail inbox, but this morning I found an unsolicited email that looked like perhaps it was meant for someone else, supposedly for a loan application I had made:<\/p>\n<blockquote><p>Hi,<\/p>\n<p>Welcome to Statforge Finance!!<\/p>\n<p>Thank you for applying loan with Statforge Finance.<\/p>\n<p>As per the telephonic conversation, please find attached the company brochure and list of required documents.<\/p>\n<p>Please find below the list of documents which you need to submit as a primary and secondary identification proof.<\/p>\n<p>1. Primary Identification Proof (Driver\u2019s License or Copy of the passport)<br \/>\n2. Address proof (Any utility bill under your name. Most recent is preferred)<br \/>\n3. Income Proof (Recent 3 Months of bank statement\/Pay stubs\/Tax Documents)<\/p>\n<p>In case of any further clarification please revert on this email or feel free to reach us back on our Toll Free number 1-855-892-0516.<\/p>\n<p>Please submit all the required documents on our email or fax us on 1-810-222-7376 in order to proceed further.<\/p>\n<p>We are happy to help you.<\/p>\n<p>Thanks &amp; Regards,<br \/>\nCommunication Department,<br \/>\nStatforge Finance US LLC<br \/>\nContact No: 1-855-892-0516<br \/>\nFax No: 1-810-222-7376<br \/>\nEmail: info@statforgefinance.com<br \/>\nWebsite: https:\/\/www.statforgefinance.com\/<\/p><\/blockquote>\n<p>I had never heard of this company, let alone contacted them for a loan (I don&#8217;t live in the US).<\/p>\n<p>Sometimes I receive mail meant for people with a similar address, so I wanted to check out if this was perhaps legitimate, but the more I looked the more I found that was odd about it.<\/p>\n<p>To start with, the email wasn&#8217;t addressed to anyone by name, nor was it signed by anyone by name. &#8220;Thank you for applying loan&#8221; is broken English. This matched up with a line in the email header that mentioned an IP address in India:<\/p>\n<blockquote><p>x-originating-ip: [175.111.128.90]<\/p><\/blockquote>\n<p>I had a look at the website listed in the mail footer. The &#8220;About Us&#8221; page stated:<\/p>\n<blockquote><p>Statforge Finance loans are best-received and utilized by our customers when they are able to easily understand the loan terms and determine whether the product is the correct fit for their needs.<\/p><\/blockquote>\n<p>Searching Google for that line, without the company name, also found the same wording on a couple of other websites, e.g.<\/p>\n<blockquote><p>Ventura Financials loans are best-received and utilized by our customers when they are able to easily understand the loan terms and determine whether the product is the correct fit for their needs.<\/p><\/blockquote>\n<p>and<\/p>\n<blockquote><p>LOANRAFT finance loans are best-received and utilized by our customers when they are able to easily understand the loan terms and determine whether the product is the correct fit for their needs.<\/p><\/blockquote>\n<p>Web contents ripped-off from other websites is never a good sign, but sometimes it&#8217;s not straightforward to tell whether a site is a legitimate original or a dodgy clone. So I looked at all three sites (there may be more).<\/p>\n<p>These were the contact details for &#8220;LOANRAFT&#8221;:<\/p>\n<blockquote><p>Give us a call<br \/>\n855 955 9655<br \/>\nMail us<br \/>\ninfo@loanraftfinance.com<br \/>\nFAX<br \/>\n3023518834<\/p>\n<p>855 955 9655<br \/>\nAddress: Delaware Avenue , Wilmington, DE 19801<br \/>\nEmail: info@loanraftfinance.com<\/p><\/blockquote>\n<p>Notice the absence of a number on the street address. Like the other two companies it uses an 855 free dial phone number with a physical area code for the fax number. The domain is registered through GoDaddy, with the registrant hidden:<\/p>\n<blockquote><p><code>Domain Name: loanraftfinance.com<br \/>\nRegistry Domain ID: 2283058202_DOMAIN_COM-VRSN<br \/>\nRegistrar WHOIS Server: whois.godaddy.com<br \/>\nRegistrar URL: http:\/\/www.godaddy.com<br \/>\nUpdated Date: 2019-07-09T16:51:23Z<br \/>\nCreation Date: 2018-07-06T22:55:47Z<br \/>\nRegistrar Registration Expiration Date: 2020-07-06T22:55:47Z<br \/>\nRegistrar: GoDaddy.com, LLC<br \/>\nRegistrar IANA ID: 146<br \/>\nRegistrar Abuse Contact Email: abuse@godaddy.com<br \/>\nRegistrar Abuse Contact Phone: +1.4806242505<br \/>\nDomain Status: clientTransferProhibited http:\/\/www.icann.org\/epp#clientTransferProhibited<br \/>\nDomain Status: clientUpdateProhibited http:\/\/www.icann.org\/epp#clientUpdateProhibited<br \/>\nDomain Status: clientRenewProhibited http:\/\/www.icann.org\/epp#clientRenewProhibited<br \/>\nDomain Status: clientDeleteProhibited http:\/\/www.icann.org\/epp#clientDeleteProhibited<br \/>\nRegistry Registrant ID: Not Available From Registry<br \/>\nRegistrant Name: Registration Private<br \/>\nRegistrant Organization: Domains By Proxy, LLC<br \/>\nRegistrant Street: DomainsByProxy.com<\/code><\/p><\/blockquote>\n<p>Contact details for Statforge Finance:<\/p>\n<blockquote><p>info@statforgefinance.com<br \/>\nGreenfield Rd, Oak Park, MI 48237<br \/>\nStatforge Finance US LLC<br \/>\nContact No: 1-855-892-0516<br \/>\nFax No: 1-810-222-7376<\/p><\/blockquote>\n<p>Again no number on the street address, 855 free dial and a physical area code for the fax. However, the 810 area code does not include Oak Park, MI which instead uses 248 and 947.<\/p>\n<p>The domain is also registered via GoDaddy, only two months earlier and the registrant is also cloaked:<\/p>\n<blockquote><p><code>Domain Name: statforgefinance.com<br \/>\nRegistry Domain ID: 2259908468_DOMAIN_COM-VRSN<br \/>\nRegistrar WHOIS Server: whois.godaddy.com<br \/>\nRegistrar URL: http:\/\/www.godaddy.com<br \/>\nUpdated Date: 2019-05-13T20:06:35Z<br \/>\nCreation Date: 2018-05-04T17:19:55Z<br \/>\nRegistrar Registration Expiration Date: 2020-05-04T17:19:55Z<br \/>\nRegistrar: GoDaddy.com, LLC<br \/>\nRegistrar IANA ID: 146<br \/>\nRegistrar Abuse Contact Email: abuse@godaddy.com<br \/>\nRegistrar Abuse Contact Phone: +1.4806242505<br \/>\nDomain Status: clientTransferProhibited http:\/\/www.icann.org\/epp#clientTransferProhibited<br \/>\nDomain Status: clientUpdateProhibited http:\/\/www.icann.org\/epp#clientUpdateProhibited<br \/>\nDomain Status: clientRenewProhibited http:\/\/www.icann.org\/epp#clientRenewProhibited<br \/>\nDomain Status: clientDeleteProhibited http:\/\/www.icann.org\/epp#clientDeleteProhibited<br \/>\nRegistry Registrant ID: Not Available From Registry<br \/>\nRegistrant Name: Registration Private<br \/>\nRegistrant Organization: Domains By Proxy, LLC<\/code><\/p><\/blockquote>\n<p>And this is the third one in the set:<\/p>\n<blockquote><p>Green Valley Parkway,<br \/>\nHenderson, NV 89074<br \/>\n+1 (855) 850 7390<br \/>\ninfo@venturafinancials.com<br \/>\nFax: 13033747343<\/p><\/blockquote>\n<p>No number on the street address, 855 free dial plus physical area code for the fax.<\/p>\n<p>It is also registered via GoDaddy, in the same month as loanraftfinance.com:<\/p>\n<blockquote><p><code>Domain Name: venturafinancials.com<br \/>\nRegistry Domain ID: 2416866824_DOMAIN_COM-VRSN<br \/>\nRegistrar WHOIS Server: whois.godaddy.com<br \/>\nRegistrar URL: http:\/\/www.godaddy.com<br \/>\nUpdated Date: 2019-07-25T21:31:33Z<br \/>\nCreation Date: 2019-07-25T21:31:32Z<br \/>\nRegistrar Registration Expiration Date: 2020-07-25T21:31:32Z<br \/>\nRegistrar: GoDaddy.com, LLC<br \/>\nRegistrar IANA ID: 146<br \/>\nRegistrar Abuse Contact Email: abuse@godaddy.com<br \/>\nRegistrar Abuse Contact Phone: +1.4806242505<br \/>\nDomain Status: clientTransferProhibited http:\/\/www.icann.org\/epp#clientTransferProhibited<br \/>\nDomain Status: clientUpdateProhibited http:\/\/www.icann.org\/epp#clientUpdateProhibited<br \/>\nDomain Status: clientRenewProhibited http:\/\/www.icann.org\/epp#clientRenewProhibited<br \/>\nDomain Status: clientDeleteProhibited http:\/\/www.icann.org\/epp#clientDeleteProhibited<br \/>\nRegistry Registrant ID: Not Available From Registry<br \/>\nRegistrant Name: Registration Private<br \/>\nRegistrant Organization: Domains By Proxy, LLC<\/code><\/p><\/blockquote>\n<p>Looking at who hosts email for the three different domains:<\/p>\n<blockquote><p>loanraftfinance.com.    3600    IN      MX      0 loanraftfinance-com.mail.protection.outlook.com.<br \/>\nventurafinancials.com.  3600    IN      MX      0 venturafinancials-com.mail.protection.outlook.com.<br \/>\nstatforgefinance.com.   2858    IN      MX      0 statforgefinance-com.mail.protection.outlook.com.<\/p><\/blockquote>\n<p>They are all using Microsoft&#8217;s Outlook mail infrastructure. This is also where my initial sample email was sent from.<\/p>\n<p>While I don&#8217;t know yet what exactly these people are up to, I would advise anyone who received a loan offer via spam to steer well clear of such offers.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Usually Gmail does a great job at keeping spam out of my Gmail inbox, but this morning I found an unsolicited email that looked like perhaps it was meant for someone else, supposedly for a loan application I had made: &hellip; <a href=\"https:\/\/joewein.net\/blog\/2019\/10\/24\/loan-application-spam\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-3159","post","type-post","status-publish","format-standard","hentry","category-spam"],"_links":{"self":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/3159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/comments?post=3159"}],"version-history":[{"count":2,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/3159\/revisions"}],"predecessor-version":[{"id":3161,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/posts\/3159\/revisions\/3161"}],"wp:attachment":[{"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/media?parent=3159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/categories?post=3159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joewein.net\/blog\/wp-json\/wp\/v2\/tags?post=3159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}