Fake banks, couriers, law firms, escrow and other fake sites used in scams.
by flickflame Sun Jul 07, 2013 6:06 pm
I thought the first email could be legitimate but I was suspicious because the address was for a primary school that could not be viewed on Google street view.

They completely ignored the questions in my reply email and tried to get me to follow a link to a phising website, according to my antivirus.

I haven't found this email/scam anywhere on the internet so I have added the complete emails below, so if anyone Google's it they can see my experience.

The reasons I know its a scam are as follows.
  • The address is for a British Primary School
  • C&B Group Limited, if it were real, does not exist anywhere near the address.
  • They completely ignore the questions in my reply email and provide a weird one size fits all response with weird grammar "good start of a wonderful and more future business transaction with us and your company"
  • They try to get me to follow a link to a website blocked by my anti-virus stating it is a reported "phising" website.
The first email from the scammer is as follows:
-----Original Message-----
From: Mrs Linda Coal [mailto: [email protected] ]
Sent: Friday, 5 July 2013 1:47 AM
To: my business email
Subject: Order

Dear Sir/Madam,

I write to inform you that we are interested in your products.

And we would like to inquire about the following:

*Minimum Order Quantity

*Your delivery time

*Payment terms But My payment term is T/T or Letter of Credit.

Best Regards,

C&B Group Limited

Head Office:
Unit 65 Bridgewater Business Park
West Bridgewater Street Leigh
Greater Manchester
WN7 4HB




My reply:

On Thu, Jul 4, 2013 at 9:40 PM

Dear Linda,

We are interested in providing you with our products.

Are you an importer/distributor or an importer wholesaler?

Which products and their sizes and quantities were you after?

............ etc.


Their reply: [email protected]

From: MISS LINDA COAL [mailto: [email protected] ]
Sent: Friday, 5 July 2013 7:18 PM
To: Russell
Subject: Re: Order

Good-day!

Thank you for your kind reply, sorry for my late reply, we hope this will be a good start of a wonderful and more future business transaction with us and your company, The order volume is very large and will span the next 3 years which was why we demanded to know your maximum production output.

Due to project size, volume and variety of products required and the need to keep a secure lasting business relationship/correspondence with you, our technical team has arrange the buyer protection Purchase Order list which includes, specifications and quantity in our secure business file below:

http://www. %20%20oer.%20ro /wp-%20content%20/%20uploads /viewtradeorder%20.%20htmLink Disabled (BW)

To access and view the order list, you should login using your valid email address (the same you use in communicating with me) & password and get back to me asap with your best quote and and delivery time with any further question.

Note that if your quotation is favorable, PO for 1st batch of order and 3 years contract agreement will be drafted and sent to you via email as well as fax within the next 1 week. Also, our technical team will be visiting your production line for inspection as soon as agreement is entered.

Waiting for your urgent reply.


Best Regards,

C&B Group Limited
Last edited by Bryon Williams on Sun Jul 07, 2013 6:28 pm, edited 2 times in total. Reason: Added quotations and disabled link.
Advertisement

by Bryon Williams Sun Jul 07, 2013 6:33 pm
Welcome to Scamwarners flickflame,

What you have posted shows 100% of a scam attempt. Please post the email header of the email address that included the link. Our members who look into fake sites may need this information. You can find information in my signature on how to find headers.

Please contacta moferatorstor if you have a question or information about this post.



Please do not tell the scammer he is posted here.


Please remember the fallen. https://www.odmp.org/
by flickflame Sun Jul 07, 2013 6:46 pm
Bryon Williams wrote:Welcome to Scamwarners flickflame,

What you have posted shows 100% of a scam attempt. Please post the email header of the email address that included the link. Our members who look into fake sites may need this information. You can find information in my signature on how to find headers.


Return-Path: <(I removed my email)>
Received: from dovecot-shared-1.private.netregistry.net ([192.168.100.95])
by dovecot-shared-3.private.netregistry.net (Dovecot) with LMTP id j63eAS7D1lF8QQAA4+JkjA
; Fri, 05 Jul 2013 23:00:44 +1000
Received: from smtp-mx-server-8.servers.netregistry.net ([192.168.101.71])
by dovecot-shared-1.private.netregistry.net (Dovecot) with LMTP id C0EqNOi81lHpbAAAPTHShg
; Fri, 05 Jul 2013 23:00:44 +1000
Received: from spamexpert-2.servers.netregistry.net ([202.124.241.73])
by smtp-mx-server-8.servers.netregistry.net protocol: esmtp (Exim 4.72 #1 (Debian))
id 1Uv5cy-0003gv-43; Fri, 05 Jul 2013 23:00:44 +1000
Received: from smtp.netregistry.net ([202.124.241.204] helo=smtp-1.servers.netregistry.net)
by spamexpert-2.servers.netregistry.net with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.80.1)
(envelope-from <(I removed my email)>)
id 1Uv5d2-00050o-8V; Fri, 05 Jul 2013 23:00:49 +1000
Received: from [203.45.207.31] (helo=BrettPC)
by smtp-1.servers.netregistry.net protocol: esmtpa (Exim 4.69 #1 (Debian))
id 1Uv5cv-0008Qx-7d; Fri, 05 Jul 2013 23:00:42 +1000
From: "Information" <(I removed my email)>
To: (I removed my email)
Subject: FW: Receipt of APPROVED purchase/payment @ eWAY
Date: Fri, 5 Jul 2013 23:01:18 +1000
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook 12.0
Thread-Index: Ac55fLPQtLV7spYcTjKAP5YeknX/lQAAwlDQ
Content-Language: en-au
X-Authenticated-User: (I removed my email)
X-Filter-ID: XtLePq6GTMn8G68F0EmQvWjstC9Z6A0GOmS7qZi+81KOOCWlz7RPRJw8iTXeF6VEERWeKKG4PAQY
Nyavp7c49BVFx2BQ1njkDGBloPee6unjaHW585raPfAGTKVim8qnI9aBMJAbuKyjMzN7T0C/dNm2
v4H6kc3Ey+LTCHE9heA+Bm/VeLMH5AdOTtVPr9AiPed1zCRxgIxDS97X29+lpXQucG0bx5smAHWh
QOOCbV/QhyNlfJfKA7IXnsSTeVi831/E3ahF5MMcDI7KdpjQKTmlZYxkTphOEMLhQy1tN6hdlv7C
evYdRKZjAM/9Mb+bOJrpgSTpo6K+w49swuDFtiICVcHySUdbxcaTJaJFtiwGoYP8nwMgQ8ZY/Tv0
G8FlA9Sghw9DgFOLOdQghfXuYoPAgTtUp75uqlx0KezvZHUtfyvm70V1sOOo6v47oSaUHVdPcwR3
FaywXFCJSpESIrzPi2vFsO2jRoDHYXn3eld1jOSCMeTKi2Zz43AyrShuiyP9sb3FxtgXtKOdGztm
gZJGVhk6to711JZVV9DoQyPmCyewTcRhBy/EMCSw4dF2JlFYhq+da/vBdbyiSxhHh5C+jxxOLslg
nWOOgqpt8yuc2LUXzChJJUwGglzcYWuNTujWIEItf3ms7NwlhXyUVsI5qEAS+tfJfpsslZ3AMJaS
vhqsaMpxqbEjd0A1hN7p
X-CloudWebTools-Class: unsure
X-CloudWebTools-Evidence: Combined (0.50)
X-Recommended-Action: accept
by Bryon Williams Sun Jul 07, 2013 6:51 pm
^^^Thank you.

ETA: The link is dangerous with phishing and possible malware/virus.

Please contacta moferatorstor if you have a question or information about this post.



Please do not tell the scammer he is posted here.


Please remember the fallen. https://www.odmp.org/

Who is online

Users browsing this forum: ClaudeBot and 12 guests