{"id":123,"date":"2005-10-13T01:03:03","date_gmt":"2005-10-13T00:03:03","guid":{"rendered":"http:\/\/www.craigmurphy.com\/blog\/?p=123"},"modified":"2008-10-27T00:37:15","modified_gmt":"2008-10-26T23:37:15","slug":"spam-recognition","status":"publish","type":"post","link":"http:\/\/www.craigmurphy.com\/blog\/?p=123","title":{"rendered":"Spam:  recognition"},"content":{"rendered":"<p>Two things:<\/p>\n<p>1. I know this is spam<br \/>\n2. I know the kind of folks who this is targeted at<\/p>\n<p>Anyway, a lot of folks have asked me &#8220;how do I know if something is dodgy?&#8221;  It can be a difficult question to answer as a lot of IT &#8220;things&#8221; are intuitive, it&#8217;s obvious.  But end users (friends too) don&#8217;t want to hear that, they want to know what they can look out for.  <\/p>\n<p>Sometimes it&#8217;s easy, sometimes end users (and friends) visit dodgy sites, downloading toolbars on they way.  Here&#8217;s a tip, if a web-site opens a pop-up window and offers you a great new search toolbar, ignore it, click on the red close icon in the top left of the pop-up (or, better still, shut the machine down).  The same goes for anything that offers to rid your machine of adware, spyware or other such nasties: it&#8217;s very likely that your machine was relatively free from such things&#8230;until you click &#8220;yes, please scan my computer for adware, etc.&#8221;<\/p>\n<p>I&#8217;m working on a rather lengthy article\/blog posting that covers my suggested security tips, but to keep my writer&#8217;s block from setting it, I thought I&#8217;d push this out now. <\/p>\n<p>Here&#8217;s a typical example of a dodgy e-mail&#8230;my comments are in <em><strong>bold italic<\/strong><\/em>&#8230;they should be enough to get you started.<\/p>\n<blockquote><p>\nReturn-path: < <code><strong>rmoore @lotto.nl<\/strong>>     <strong><em>there&#8217;s a space after the &#8216;moore&#8217; and before the &#8216;r&#8217;<\/em><\/strong><br \/>\nReceived: from punt-3.mail.demon.net by mailstore<br \/>\n        for <strong><my e-mail address removed><\/my><\/strong>  id 1E7Big-0000Uk-Lm;<br \/>\n        Mon, 22 Aug 2005 12:48:06 +0000<br \/>\nReceived: from [194.217.242.77] (helo=anchor-hub.mail.demon.net)<br \/>\n        by punt-3.mail.demon.net with esmtp id 1E7Big-0000Uk-Lm<br \/>\n        for <strong><my e-mail address removed><\/my><\/strong>; Mon, 22 Aug 2005 12:48:06 +0000<br \/>\nReceived: from [217.158.187.220] (helo=drake.uknoc.co.uk)<br \/>\n        by anchor-hub.mail.demon.net with esmtp id 1E7Big-0002rC-Ik<br \/>\n        for <strong><my e-mail address removed><\/my><\/strong>; Mon, 22 Aug 2005 12:48:06 +0000<br \/>\nReceived: from [84.246.8.20] (helo=<strong>rmoore@lotto.nl<\/strong>)   <strong><em>no space<\/em><\/strong><br \/>\n        by drake.uknoc.co.uk with smtp (Exim 4.52)<br \/>\n        id 1E7Big-00087e-RE<br \/>\n        for <strong><my e-mail address removed><\/my><\/strong>; Mon, 22 Aug 2005 13:48:07 +0100<br \/>\nFrom: &#8220;Director Moore&#8221; <rmoore @lotto.nl><br \/>\nTo: <strong><my e-mail address removed><\/my><\/strong><br \/>\nSubject: Congratulations: <strong>Vernus <\/strong>Millionaire Lotto winner !!!     <strong><em>Sounds like a famous name UK-based gambling group&#8230;<\/em><\/strong><br \/>\nMime-Version: 1.0<br \/>\nContent-Type: text\/plain; charset=&#8221;iso-8859-1&#8243;<br \/>\nDate: Mon, 22 Aug 2005 14:48:09<br \/>\nX-AntiAbuse: This header was added to track abuse, please include it with any abuse report<br \/>\nX-AntiAbuse: Primary Hostname &#8211; drake.uknoc.co.uk<br \/>\nX-AntiAbuse: Original Domain &#8211; scottishdevelopers.com<br \/>\nX-AntiAbuse: Originator\/Caller UID\/GID &#8211; [47 12] \/ [47 12]<br \/>\nX-AntiAbuse: Sender Address Domain &#8211; lotto.nl<br \/>\nX-Source:<br \/>\nX-Source-Args:<br \/>\nX-Source-Dir: <\/p>\n<p>VERNUS MILLIONAIRE LOTTO<br \/>\n23 RIJNWEGSTRAAT,<br \/>\nAMSTERDAM,NETHERLANDS <\/p>\n<p>                  TO WINNERS IN OUR <strong>PROGRAM<\/strong>           <strong><em>PROGRAM?  Surely PROGRAMME?<\/em><\/strong><\/p>\n<p>Good day, <\/p>\n<p>This is Mrs Rita Moore the Director of <strong>vernus <\/strong>Millionaire Lotto in <strong>the NETHERLANDS<\/strong>. Vernus Millionaire Lotto is an independent lotto<\/p>\n<p><strong><em>Suddenly, vernus is lower-case, previously it was sentence-case<\/em><\/strong><br \/>\n<strong><em>Surely The Netherlands?<\/em><\/strong><\/p>\n<p><strong>organization <\/strong>in the Netherlands that is conducting several online lotto programs on the internet. However,we wish to congratulate you<\/p>\n<p><strong><em>it&#8217;s organisation here in Europe, thank you<\/em><\/strong><\/p>\n<p>over your success in our computer balloting sweepstake held on 20th August,2005 in which your email address attached to ticket number<br \/>\nLNT456780909893 and drew the lucky numbers 4-10-12-55-25-87,batch number 4978\/NL and consequently won the lottery in the 1st category.<br \/>\nThis is a millennium scientific computer game in which email addresses were used and it is a promotional program aimed at encouraging<br \/>\ninternet users;so you do not need to buy a ticket to enter for our online lotto program. Note that this program was largely promoted<br \/>\nand sponsored by a group of philanthropist, industrialists from the internet ware industry and some other big multinational firms who<br \/>\nwish to be anonymous. <strong>Therefore,you<\/strong> have been approved for a lump sum amount of U.S <\/p>\n<p><strong>Throughout this e-mail, there is no space after each comma: there should be!  If this was legit, the use of language would be spot on.<\/strong><\/p>\n<p>$1million dollars credited as Bond into your security file LOTTERY REF NUMBER Amt\/nt\/423275\/01 with our security agent. This amount<br \/>\nis from the total prize money of $15,800,000 shared among the seventeen international winners in categories C with serial number:<br \/>\nIL\/PLW\/18-C0547671754.<br \/>\n<strong>This email is not one of those numerous lotto email scams you might have received in the past which always require you to sign out a<br \/>\nblank cheque or give out your bank information in order to perpetrate their illicit lotto scams. <\/strong><\/p>\n<p><strong><em>The give-away.   If you believe this, please cut up your credit cards now!<\/em><\/strong><\/p>\n<p>Please note that this winning is very<br \/>\nreal and legitimate and your exercising good faith in this our lottery program will enable us remit your winning funds to you in your<br \/>\npreferred mode of payment without any further delay. Therefore,to confirm the legitimacy of our lottery program, the <strong>below website <\/strong>is<\/p>\n<p><strong><em>The Dutch speak and write better English than some of us&#8230;<\/em><\/strong><\/p>\n<p>one of the websites we are running over the internet concerning our lottery programs in the Netherlands.<\/p>\n<p>http:\/\/www.lotto.nl\/lotto\/execute\/intro?node=lottointros&#038;default=lottorootnode&#038;ad=0<\/p>\n<p>However,to begin your claim,being non-netherlands resident or citizen,you are required <strong>within two days <\/strong>to officially notarize your<\/p>\n<p><strong><em>uh oh, you want me to go to The Netherlands in person?  Surely you&#8217;ll just bash me over the head with a baseball bat, take my passport, my Euros, my cards, etc. and leave me with nothing but a sore head?<\/em><\/strong><\/p>\n<p>winning claim at the Dutch Court of Justice in the Netherlands to sign the Release Order and the clearance papers that will enable the<br \/>\npaying Creft Consulting Agency release your winning funds to you. But in case you cannot come to the Netherlands within the stipulated<br \/>\ntwo days,do inform your claim officer to make proper arrangement regarding your claim notarization. Once your claim is fully notarized<br \/>\nand a copy of the Notary receipt from the court is forwarded to us,we will provide you with your Award winning Certificate. Please for<br \/>\nmore information concerning the claim of your winning funds,we advise you to forward a confirmation email to your claim officer at the<br \/>\npaying Creft Consulting Agency and as well follow their claim instructions. Below is the contact details of your claim officer:<\/p>\n<p>MR.CURTIS LUCAS<br \/>\n(PAYMENT DIRECTOR)<br \/>\n<strong>CREFT CONSULTING AGENCY<br \/>\nAMSTERDAM,NL<\/strong><\/p>\n<p><strong><em>Wot, no street name and postal district?<\/em><\/strong><\/p>\n<p>TELEPHONE: +31-622851045<br \/>\nEMAIL: <strong>snipped@fsmail.net <\/strong><\/p>\n<p><strong><em>fsmail.net &#8211; hang on, a consulting agency, I think not!<\/em><\/strong><\/p>\n<p><strong>Conclusively,vernus Millionaire Lotto is not a scam organization therefore this mail should not be treated as a scam scheme or be<br \/>\ntaken for granted,we are backed up by the appropriate lottery law in the Netherlands and only the successful winners in this our<br \/>\nonline lotto program receive this congratulation mail and because you won that is why this mail is being directed to you. <\/strong><\/p>\n<p><strong><em>That&#8217;ll be right.  Not a scam, not to be treated as a scam scheme&#8230;yeah yeah.  Pull the other one, it has got bells on.<\/em><\/strong><\/p>\n<p>Remember that all prize money must be claimed not later than 7 working days. After the last day, all funds will be returned as unclaimed.<br \/>\nCongratulations once again from our team of staff and thank you for being part of our promotional program.<\/p>\n<p>Sincerely,<br \/>\nDirector<br \/>\nRita Moore<br \/>\n(Lottery Coordinator)<\/p>\n<p> This mail was <strong>sended <\/strong>with <strong>unregistered <\/strong>version of Zmei Mail Sender.Visit http:\/\/www.zmei-soft.com for free download of Zmei Mail<\/p>\n<p><em><strong>&#8220;Sended&#8221; &#8211; wrong tense, another giveaway!<\/strong><\/em><\/p>\n<p><strong><em>Unregistered?  What?  A huge commercial lottery outfit like this?  Surely they would have their own domain and their own e-mail software.  More evidence.<\/em><\/strong><\/p>\n<p>Sender.<\/rmoore><\/p><\/blockquote>\n<p>If you receive an e-mail with any of these characteristics, I suggest you delete it without so much as a second glance (I take no responsibility if you delete a legit lottery winning notification!) <\/p>\n<p>Better still, I can recommend a program that can weed out such spam and prevent it from getting into your mailbox in the first place: check out <a href=\"http:\/\/fta.firetrust.com\/index.cgi?id=CAMURPHY&#038;page=1\">MailWasher Pro<\/a>.  It &#8220;sits ahead&#8221; of your e-mail client (application) and uses known databases of spam to intelligently mark incoming e-mail as either legit or possible spam: it&#8217;s a boon if you&#8217;re still on dial-up.<\/p>\n<p>Technorati Tags: <a href=\"http:\/\/technorati.com\/tag\/MailWasher\" rel=\"tag\">MailWasher<\/a>, <a href=\"http:\/\/technorati.com\/tag\/MailWasher+Pro\" rel=\"tag\">MailWasher Pro<\/a>, <a href=\"http:\/\/technorati.com\/tag\/spam\" rel=\"tag\">spam<\/a>, <a href=\"http:\/\/technorati.com\/tag\/recognising+spam\" rel=\"tag\">recognising spam<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It never ceases to amaze me what spammers think other folks will fall for&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[102,103,104],"class_list":["post-123","post","type-post","status-publish","format-standard","hentry","category-general","tag-mailwasher","tag-mailwasher-pro","tag-spam"],"_links":{"self":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=123"}],"version-history":[{"count":0,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/123\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=123"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.craigmurphy.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}