Finance and Credit Fraud
Report
Active
Domain
Don't Bear Internet Fraud
Home
Bobbear Icon

Finance and Credit screenshot

Finance and Credit is a new twist to the genre for me. At present the URL they are using for their website, (
http://elsardon.balder.prohosting.com), indicates that they are using a sub-domain of prohosting.com, or to be more accurate they are apparently abusing the free.prohosting.com service.

There are bound to be many legitimate companies with the same or a similar name to these criminals. The fraud site is as portrayed by the screenshot above and should not be confused with any legitimate company of the same name.

Evidence of Criminal Fraud:

i) The 'Job' (from the website):

The above screenshot speaks for itself - it's an obvious money mule 'job'

ii) The Spam (received in a dedicated spamtrap address)
:

Hi there.

We're looking for representatives in the US. Average compensation is $70.000/yr.
No fees, nothing, only your strong desire to work and make money.

Please visit our site to sign up for this program, for free.

http://elsardon.balder.prohosting.com

Thank you for your attention.

Short and sweet - just directs you to the fraud website

iii) The Spam Headers

Return-Path: <stacy@pbxsoftware.com>
Received: from mwinf3419.me.freeserve.com (mwinf3419.me.freeserve.com)
    by mwinb3a06 (SMTP Server) with LMTP; Wed, 13 Feb 2008 06:07:45 +0100
X-Sieve: Server Sieve 2.2
Envelope-to: xxxxxxxxx
Received: from me-wanadoo.net (localhost [127.0.0.1])
    by mwinf3419.me.freeserve.com (SMTP Server) with ESMTP id D1FDE1C0008F
    for <xxxxxxxxx>; Wed, 13 Feb 2008 06:07:45 +0100 (CET)
Received: from 80.85.149.205 (unknown [80.85.149.205])
    by mwinf3419.me.freeserve.com (SMTP Server) with ESMTP id 83EDB1C000EE
    for <xxxxxxxxx>; Wed, 13 Feb 2008 06:07:45 +0100 (CET)
X-ME-UUID: 20080213050745540.xxxxxxx@xxxxxxxxx
Message-ID: <xxxxxxxxxx>
From: "broderick moshe" <stacy@pbxsoftware.com>
To: <xxxxxxxxxx>
Subject: *** SPAM *** work at home
Date: Wed, 13 Feb 2008 03:20:28 +0000
MIME-Version: 1.0
Content-Type: text/plain;
    charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
X-me-spamlevel: med
X-me-spamrating: 95.420921

It's from a Russian IP (80.85.149.205) with no RDNS so it's probably not a zombie.

iv)
 No legitimate company would use private individuals to transfer money in this way using private bank accounts. To do so is illegal and defines the company as both bogus and criminal.

v) Usual mis-spelling and grammatical mangling common to these Russian scams.

vi) No contact information such as address or telephone number on the website - no genuine company would operate with the only contact being via a one-way webform.


Webpage created 13-February 2008

Later - Fraud website removed from free.prohosting.com domain for violating their Acceptable Use Policy.