<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Crescent City Networking &#187; Phishing</title>
	<atom:link href="http://ccnetworking.com/wordpress/archives/tag/phishing/feed" rel="self" type="application/rss+xml" />
	<link>http://ccnetworking.com/wordpress</link>
	<description></description>
	<lastBuildDate>Wed, 28 Jul 2010 16:31:39 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Koobface</title>
		<link>http://ccnetworking.com/wordpress/archives/187</link>
		<comments>http://ccnetworking.com/wordpress/archives/187#comments</comments>
		<pubDate>Wed, 13 May 2009 01:43:51 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Phising]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ccnetworking.com/wordpress/?p=187</guid>
		<description><![CDATA[Koobface, a worm which steals Facebook or MySpace credentials and spams their credentials, is certainly alive and kicking.
Here&#8217;s a run occurring right now. You get a message from a friend:
 


Which leads to a Facebook page:

Which, when clicked, pushes a fake video codec that downloads Koobface:

And yes, my wife just got one from a friend. He [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.networkworld.com/news/2009/030309-koobface-worm-to-users-be.html"><span style="color: #336699;">Koobface</span></a>, a worm which steals Facebook or MySpace credentials and spams their credentials, is certainly alive and kicking.</p>
<p>Here&#8217;s a run occurring right now. You get a message from a friend:</p>
<p> <br />
<a href="http://1.bp.blogspot.com/_Ro7Ss7XtakY/SfZ3GecDG3I/AAAAAAAABPg/MzTLCqevEYM/s1600-h/facbook234882348288.png"><img id="BLOGGER_PHOTO_ID_5329578162173188978" style="width: 302px; height: 320px; cursor: hand;" src="http://1.bp.blogspot.com/_Ro7Ss7XtakY/SfZ3GecDG3I/AAAAAAAABPg/MzTLCqevEYM/s320/facbook234882348288.png" border="0" alt="" /></a></p>
<p><a href="http://1.bp.blogspot.com/_Ro7Ss7XtakY/SfZ2xu76sYI/AAAAAAAABPY/yuzZYIEAsyA/s1600-h/facbook234882348288.png"></a></p>
<p>Which leads to a Facebook page:</p>
<p><a href="http://4.bp.blogspot.com/_Ro7Ss7XtakY/SfZ0tQyig_I/AAAAAAAABPI/WZqI_2LR470/s1600-h/facebook234892348.png"><img id="BLOGGER_PHOTO_ID_5329575529989440498" style="width: 320px; height: 270px; cursor: hand;" src="http://4.bp.blogspot.com/_Ro7Ss7XtakY/SfZ0tQyig_I/AAAAAAAABPI/WZqI_2LR470/s320/facebook234892348.png" border="0" alt="" /></a></p>
<p>Which, when clicked, pushes a fake video codec that downloads Koobface:</p>
<p><a href="http://3.bp.blogspot.com/_Ro7Ss7XtakY/SfZ08oZwqEI/AAAAAAAABPQ/zuymSqbhzs4/s1600-h/facebook234892348a.png"><img id="BLOGGER_PHOTO_ID_5329575794025998402" style="width: 320px; height: 270px; cursor: hand;" src="http://3.bp.blogspot.com/_Ro7Ss7XtakY/SfZ08oZwqEI/AAAAAAAABPQ/zuymSqbhzs4/s320/facebook234892348a.png" border="0" alt="" /></a></p>
<p>And yes, my wife just got one from a friend. He was rather surprised when I called him&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://ccnetworking.com/wordpress/archives/187/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Swine flu search poisoning</title>
		<link>http://ccnetworking.com/wordpress/archives/181</link>
		<comments>http://ccnetworking.com/wordpress/archives/181#comments</comments>
		<pubDate>Wed, 13 May 2009 01:18:25 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
				<category><![CDATA[Phising]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ccnetworking.com/wordpress/?p=181</guid>
		<description><![CDATA[Not the most surpising news, but there’s SEO search poisoning going on using swine flue keywords.
Using the search term “Swine flu protection”, 8th result:

 
 
 
Using “swine flu statistics”, 2nd result:
 

 
 
 
Clicking on the link leads to a fake malware scan page (currently dead). 
 

 

 

 

 
 As posted on Sunbelt Blog
]]></description>
			<content:encoded><![CDATA[<p>Not the most surpising news, but there’s SEO search poisoning going on using swine flue keywords.</p>
<p>Using the search term “Swine flu protection”, 8<sup>th</sup> result:</p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swineflu213488234888p.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swineflu213488234888p_thumb.jpg" border="0" alt="Swineflu213488234888p" /></a></p>
<p> </p>
<p> </p>
<p> </p>
<p>Using “swine flu statistics”, 2<sup>nd</sup> result:</p>
<p> </p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swineflu213488234888q.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swineflu213488234888q_thumb.jpg" border="0" alt="Swineflu213488234888q" /></a></p>
<p> </p>
<p> </p>
<p> </p>
<p>Clicking on the link leads to a fake malware scan page <em>(currently dead). </em></p>
<p> </p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swine_pop.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swine_pop_thumb.jpg" border="0" alt="Swine_pop" /></a></p>
<p> </p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swine_scan.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swine_scan_thumb.jpg" border="0" alt="Swine_scan" /></a></p>
<p> </p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swine_scan2.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swine_scan2_thumb.jpg" border="0" alt="Swine_scan2" /></a></p>
<p> </p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/swine_scan3.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/swine_scan3_thumb.jpg" border="0" alt="Swine_scan3" /></a></p>
<p> </p>
<p> As posted on <a href="http://sunbeltblog.blogspot.com/2009/05/swine-flu-search-poisoning.html">Sunbelt Blog</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ccnetworking.com/wordpress/archives/181/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bizarre 419 scam letter</title>
		<link>http://ccnetworking.com/wordpress/archives/155</link>
		<comments>http://ccnetworking.com/wordpress/archives/155#comments</comments>
		<pubDate>Sat, 11 Apr 2009 15:24:41 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
				<category><![CDATA[Phising]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ccnetworking.com/wordpress/?p=155</guid>
		<description><![CDATA[I think this one takes the cake.
From: FEDERAL BUREAU OF INVESTIGATION [mailto:fbisecuritydeptoffice@org]
Sent: Tuesday, April 07, 2009 9:40 AM
Subject: FEDERAL BUREAU OF INVESTIGATION HELP STOP SCAMS ON INTERNET
Federal Bureau of Investigation
J. Edgar Hoover Building
935 Pennsylvania Avenue, NW Washington, D.C. 20535-0001, USA
FEDERAL BUREAU OF INVESTIGATION SEEKING TO WIRETAP THE INTERNET
The Federal Bureau of Investigation (F.B.I) write to [...]]]></description>
			<content:encoded><![CDATA[<p>I think this one takes the cake.</p>
<blockquote><p>From: FEDERAL BUREAU OF INVESTIGATION [mailto:fbisecuritydeptoffice@org]<br />
Sent: Tuesday, April 07, 2009 9:40 AM<br />
Subject: FEDERAL BUREAU OF INVESTIGATION HELP STOP SCAMS ON INTERNET</p>
<p>Federal Bureau of Investigation<br />
J. Edgar Hoover Building<br />
935 Pennsylvania Avenue, NW Washington, D.C. 20535-0001, USA</p>
<p>FEDERAL BUREAU OF INVESTIGATION SEEKING TO WIRETAP THE INTERNET</p>
<p>The Federal Bureau of Investigation (F.B.I) write to you in correspondence to the meeting we recently had with the Federal Republic of Nigeria Government on the ERADICATION of SCAMS on the internet, Federal Bureau of Investigation<br />
(FBI) Washington, DC in conjunction with some other relevant Investigation Agencies like Internal Revenue Service here in the United states of America have recently been informed through our Global intelligence monitoring network that you presently have a transaction with the Central Bank of Nigeria (CBN) as regards to your over-due contract payment which was fully endorsed in your favor accordingly.</p>
<p>After the meeting held on Monday 31st March 2009 at the Bank Auditorium Center , the whole conflict of SCAMS was revealed to us by the Board of Truste of Federal Republic of Nigeria mostly by the three arms of Government.</p>
<p>(The Judiciary, the Legislature and the Executive).</p>
<p>These three arms of Government has made us realize that the rampad of SCAMS over floating around the United State of America and some other part of the world was been set up by the root of some CBN Ex-Workers that have been suspended for sometimes due to their dubious characters of initiating people to impersonate the Government Workers to receive peoples hard earn money from them, mostly with the Executive Governor identity.</p>
<p>For these reasons, the Central Bank Executive Governor was invited to this office to defend the allegation against Him while he made complain that his office was not in charge of foreign transfer of funds, that the accredited office was Federal Ministry of Finance Department (FEDMINAP) in person of (Rev.Paul Badmus) as the Accountant General in charge of all foreign transfer payment files.</p>
<p>They also told us that the only problem they are facing right now is that some unscrupulous element are using this project as an avenue to scam innocent people off their hard earned money by impersonating the Executive Governor that is why the Federal Government has appoint Rev. Paul Badmus as the Payment Director of the Central Bank office.</p>
<p>The Federal government of Nigeria has approved that all overdue outstanding payments must be Paid on OR before 25th, April 2009, for the preparation of their next category to be paid which might leads to recalling of funds back to the Bank Treasury.</p>
<p>Meanwhile, we are also informed that a Man with an America passport number<br />
(3028882234) came to the Central Bank affiliated bank office in U.K few days ago with a letter, claiming to be your true representative.</p>
<p>Here are the man informations bellow:</p>
<p>Name: Denis Marion<br />
Bank Name: City Bank<br />
Bank Address: Arizona, USA<br />
Account Number: 6503809008.</p>
<p>INSTRUCTION/WARNING FROM ROBERT S. MUELLER III.</p>
<p>NB: You are urgently advised to please reconfirm the following to the Office of the Accountant General, as a matter of urgency if this Man is from you so that this office will not issue your fund and be held responsible, If this man isn&#8217;t of your true representative, you are requested to contact for your inheritance claim valued of US$12,500,000.00M (Twelve Million, Five hundred thousand United States Dollars)only will be remitted into your nominated bank account.</p>
<p>1) Your full name.<br />
2) Phone, fax and mobile #.<br />
3) Residential address.<br />
4) Company name, Office position and Company address.<br />
5) Profession, Age and marital status.<br />
6) Working I&#8217;d / Int&#8217;l passport.</p>
<p>And should incase you are already dealing with anybody or office claiming to be from the Central Bank of Nigeria, you are further advised to STOP further contact with in person from africa in your best interest and then contact immediately the real office of the Central Bank of Nigeria (CBN) only with the below information&#8217;s accordingly:</p>
<p>NAME: REV. PAUL BADMUS<br />
OFFICE ADDRESS: Central Bank of Nigeria,<br />
Central Business District,<br />
Cadastral Zone,<br />
Abuja, Federal Capital Territory,<br />
Nigeria.</p>
<p>TEL: 001234-01-4328033<br />
0012347032032230<br />
Email: <a href="mailto:paulbadmus_desk@live.com">paulbadmus_desk@live.com</a><br />
IMPORTANT NOTICE.</p>
<p>Note: we are on investigation and security watch over any message with Central Bank, to benefit the satisfaction of all the United States Citizen by seeking to wiretap scams on the internet with the help of Nigeria Government and also with the assistance of all United states Citizen, by listening to the instructions we give out to avoid falling for SCAMS on INTERNET.</p>
<p>All modalities has already been worked out even before you were contacted and note that we will be monitoring all your dealings with them as you proceed so you don&#8217;t have anything to worry about, All we require from you henceforth is an update so as to enable us be on track with you and the Central Bank of Nigeria, without wasting much time, will want you to contact them immediately with the above email address so as to enable them attend to your case accordingly without any further delay as time is already running out.</p>
<p>Should in case you need any more information&#8217;s in regards to this notification, be free to get back to us so that we can brief you more as we are here to guide you during and after this project has been completely perfected and you have received your contract fund as stated.</p>
<p>Thank you very much for your co-operation in advance as we earnestly await your urgent response to this matter.<br />
Best Regards,<br />
Robert S. Mueller III<br />
Federal Bureau of Investigation<br />
J. Edgar Hoover Building<br />
935 Pennsylvania Avenue, NW Washington, D.C. 20535-0001, USA <a href="mailto:internet.securitys_federalbureauofinvestigation@live.com">internet.securitys_federalbureauofinvestigation@live.com</a></p></blockquote>
<p>(Thanks to Jeff)</p>
]]></content:encoded>
			<wfw:commentRss>http://ccnetworking.com/wordpress/archives/155/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing targets military personnel</title>
		<link>http://ccnetworking.com/wordpress/archives/93</link>
		<comments>http://ccnetworking.com/wordpress/archives/93#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:44:47 +0000</pubDate>
		<dc:creator>Ken</dc:creator>
				<category><![CDATA[Phising]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://ccnetworking.com/wordpress/?p=93</guid>
		<description><![CDATA[They have no shame


Phishing military personnel…


Alex Eckelberry

POSTED BY SUNBELT SOFTWARE BLOG




]]></description>
			<content:encoded><![CDATA[<h3 class="post-title">They have no shame</h3>
<div class="post-body">
<div>
<p>Phishing military personnel…</p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/noshame1283812388pa.png"></a></p>
<p><a href="http://www.sunbeltsoftware.com/alex/gblog/noshame1283812388pa.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/noshame1283812388pa_thumb1.jpg" border="0" alt="Noshame1283812388pa" /></a><a href="http://www.sunbeltsoftware.com/alex/gblog/noshame1283812388p.png"><img src="http://www.sunbeltsoftware.com/alex/gblog/noshame1283812388p_thumb.jpg" border="0" alt="Noshame1283812388p" /></a><br />
Alex Eckelberry</div>
</div>
<p class="post-footer"><em>POSTED BY SUNBELT SOFTWARE BLOG</em></p>
<p class="post-footer">
<p class="post-footer">
<p class="post-footer"><em><br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://ccnetworking.com/wordpress/archives/93/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
