Green Tree (Warehousing) Ltd Fraud

Report
Active
Domain
Don't Bear Internet Fraud
Home
Bobbear Icon

Green Tree (Warehousing) Ltd banner

Green Tree (Warehousing) Ltd scam is the latest fraud from the money laundering department of the well known 'rockphish' criminals. It is the replacement zombie botnet hosted fraud for the Newman, Esmond & Eisenberg criminal fraudster as clearly evidenced by the same nameservers and host IPs and uses a website stolen from the genuine company. If you are a registrar or a host who has received an abuse report concerning this criminal then please review the indisputable evidence below and take prompt and permanent action to shut this criminal down.

This stolen criminal fraud website should not be confused with the blameless legitimate UK company of the same name from which the criminals have stolen the above website content and who are as much a victim of this criminal as anyone else.

If you've either received an active website link in a spam, or know of an active domain and it is not listed in the domain tables below, then please let us know by reporting it using the 'Report Active Domain' option in the title bar above.

Current Zombie Botnet Controller Hosts

FortressITX/pwebtech.com - ns1.schemeetc.com [69.72.237.212] -
Notified 10-May-2008

  - ns1.mnink.com []


 - ns1.viemn.com [] - 



Miscellaneous Hosts

ENTEL CHILE S.A. - ns2.newmanesrb.net [200.72.139.67]

Netvigator (PCCW Ltd) - ns1.newmanesrb.net [219.76.235.93]

Open Data Network (JAPAN TELECOM CO.,LTD.) - 211.3.149.208

Orange Nederland Breedband B.V. - 85.150.209.34

Complex Telmatic Systems Siberia network - ns1.greentwo.net [81.16.131.40]

Sripatum University - ns2.greentwo.net [202.44.71.148]


The above table shows the current providers of
hosting services to the criminals and how long they have been providing them for. The decent ethical majority of service providers, (all credit to them - they are a pleasure to deal with), act within 1-24 hours of being informed of the criminal abuse of their system, (the best in less than 1 hour), but there are unfortunately some thatfor whatever reason, do not. Any hosting company that remains in the above list for more than 48 hours has not responded positively to abuse reports.

If you are an abuse team that has taken action, please let me know so that I can update the current status by removing the above record.

Green Tree (Warehousing) Ltd : Evidence of Site Theft and Criminal Fraud

i) The criminal fraudsters have stolen the website of the genuine Green Tree (Warehousing) Ltd as detailed above - this fraud is simply the latest in the series of frauds including Harvey InvestmentDraper InvestmentCronos Investment, Waller Truck Co.Newman, Esmond & Eisenberg frauds etc with an unfortunate new company as the victim. Examine the above screenshot of the stolen site and compare it to the genuine site. The evidence of site theft is indisputable. The criminals have simply changed the boxed location details, (but sloppily omitted to change the footer details), added a 'Vacancy' tab for their money laundering job and posted a fake Belgian telephone number. The genuine Green Tree website owners have posted the following warning of these criminals:
genuine green tree site

ii) The bogus websites are zombie botnet hosted as clearly demonstrated by the DNS data below. The initial nameservers, (ns1.uneedmc.com, ns1.book-xm.com and ns1.iwarzone.com), and initial host IP's are exactly the same as were used by the Newman, Esmond & Eisenberg criminal fraudsters which clearly demonstrate the fact that they are one and the same criminal organisation. In fact they are using one of the 'old' Newman, Esmond & Eisenberg domains (newmanesrb.net) for the Green Tree (Warehousing) Ltd fraud website. You don't get any better proof than that it's the same gang. No legitimate company would use a zombie botnet to host their websites.

iii) The criminal's spams, (example below), contain the illegal money mule function of accepting payments into a private bank account and transferring them back out to the criminals less 10% via Moneygram or Western Union - clear and irrefutable evidence of solicitation to commit money laundering fraud.

iv) The fake 
Green Tree (Warehousing) Ltd website contains the usual smokescreen of bogus jobs under the 'Vacancy' tab, but at the bottom is the following part-time, working from home, clear money mule function advertised as "Regional Financial Coordinator" which is the only post that is advertised in the criminal's spam, (sample below):

Regional Financial Coordinator

We are currently looking to recruit a Regional Financial Coordinator to manage payments from the customers based within the limits of his country. You will be our financial intermediary in your local area and will be responsible to remit customer payments for the ordered warehousing or shipping to facilitate and fasten payment receipt at the headquarters of the company. This is a brand new part-time position and has been created to improve supply chain performance for the company as we move into a period of substantial expansion where we will double our current turnover.

The role includes dealing with 2-3 customer payments a week; reviewing the balance of the bank account, where the payment is supposed to be debited to; ensuring precise settlements regarding each payment; transmitting the payments to the Headquarters and subsidiaries of the company by means of instant Western Union payment system and providing regular feedback and reports to the Headquaters OfficeManager and Supervisor.

Apply for this Position


Qualifications and training

It is essential that the candidate promotes positive/can do attitude and discharges his duties urgently, has literate communicational and PC-user skills to interact with other team members and make external contacts related to the job nature.

Successful applicants will need to have a bank account to be used for the customer payments to be debited to, be energetic, enthusiastic and naturally ambitious. This is very much seen as a career progression role that could lead to a management position, so if you are willing to work 1-2 hours a day and be paid on an interest basis ( net 10% out of each customer payment you have dealt with) you are welcome to apply now.

Apply for this Position
The above role is clearly the ILLEGAL role of a money laundering mule. Notice the illiterate trademark phrase  'fasten payment receipt' that these criminals always use.

v)
If you click on the 'Apply for this position' link, you will see the following first line:
Newman, Green Tree (Warehousing) Ltd, hereinafter referred to as “Company”, in the person of Mr Joachim Schroder, Chairman of board of the Directors, acting on the grounds of the bylaws of the Company, on one hand, and Applicant on the other hand, have concluded this agreement as follows:
Oops! - they've forgotten to delete the 'Newman' from their previous '
Newman, Esmond & Eisenberg' alias. No doubt if you look further you'll see more examples of this criminal's slip-ups....

vi) The criminal's numerous fraud domains, which are all used for the same fake website, are all registered with different fake whois details with various registrars in the last few days, but mainly now with Internet Invest Inc.(Imena.ua).

vii) The criminal's spam contains forged header information and the usual bayesian filter avoidance 'white text' code that irrefutably link it to the Cronos Investment, Draper Investment, Harvey Investment, Adamant Global, Sydney Car Centre, Waller Truck, Newman, Esmond and Eisenberg and all this criminal's many other aliases along with the 'rockphish' phishing criminals.

viii) Their spam is zombie botnet distributed as is easily demonstrated by the source IP RDNS data.

ix) As usual, the criminal's spams are all signed by different random names - they appear to have an infinite number of fake 'employees'.

x) A Google Earth check on the address (Antwerpen 2020) on the fake website shows no such installation as depicted. A check on the genuine address (DN7 6HD) clearly does show the genuine company's installation. Clear evidence that the Antwerp address is fake.

The above irrefutable evidence clearly demonstrates beyond any doubt that the stolen website has been set up by money laundering and phishing criminals purely for the purpose of spamvertising an illegal money laundering 'mule' job and is undoubtedly just a stolen copy of the genuine site and is directly related to Cronos Investment, Draper Investment, Harvey Investment, Adamant Global, Sydney Car Centre, Waller Truck, Newman, Esmond & Eisenberg and the rest of the money laundering/phishing criminal fraudsters' aliases documented here. If you are an abuse team that has received an abuse report regarding these fraudsters, please consider immediate termination of their services in view of the absolutely undeniable evidence of site theft, copyright offences, criminal money laundering activity and spamming - please don't delay - these criminals will not respond to any communication from you, (all their whois data is false), but will simply take advantage of any attempt at communication as a delaying tactic to allow them time to carry on their criminal activity and prepare their next network.

Do not be misled - these are professional criminals with a long history of fraud as detailed on the General Information page and are the same criminals as the 'rockphish' phishing fraudsters, so if a host or registrar shelters these crooks then they are also sheltering the 'rockphish' phishing fraudsters and aiding and abetting their criminal 'phishing' fraud activities.

Green Tree (Warehousing) Ltd Fraudsters - current hosting details.


Current Main Domains, Hosts and  Registrars
Domain


greentwo.net
greentwo.org
greentwo.biz
grntwo.com
grntwo.net
grtrw.org.uk
grtrw.me.uk
grtrw.co.uk
grntr.org.uk
grntr.me.uk
grntr.co.uk

Registrar


Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
Host IP Network /Botnet Nameserver Host


Orange Nederland Breedband B.V.
Orange Nederland Breedband B.V.
Orange Nederland Breedband B.V.
Orange Nederland Breedband B.V.
Orange Nederland Breedband B.V
FortressITX/pwebtech.com - ns1.schemeetc.com
FortressITX/pwebtech.com - ns1.schemeetc.com
FortressITX/pwebtech.com - ns1.schemeetc.com
FortressITX/pwebtech.com - ns1.schemeetc.com
FortressITX/pwebtech.com - ns1.schemeetc.com
FortressITX/pwebtech.com - ns1.schemeetc.com
Host IP/Botnet Nameserver IP

85.150.209.34
85.150.209.34
85.150.209.34
85.150.209.34
85.150.209.34
69.72.237.212
69.72.237.212
69.72.237.212
69.72.237.212
69.72.237.212
69.72.237.212

Current Zombie Botnet Nameserver Domains and Registrars

uneedmc.com - REGISTER.COM, INC. (03-Apr-2008)
book-xm.com - REGISTER.COM, INC. (07-Apr-2008)
netipm.com - KEY-SYSTEMS GMBH/Imena.ua (20-Mar-2008)
regnme.com - REGISTER.COM, INC. (29-Apr-2008)
mnink.com - Spiritdomains/IA Registry (30-Apr-2008)
viemn.com - Spiritdomains/IA Registry (30-Apr-2008)
schemeetc.com -
Spiritdomains/IA Registry (05-May-2008)

See table below for the full list of known active & suspended main domains used by this criminal.


List of all known domains used by the Green Tree (Warehousing) Ltd Fraudsters 

Domain

gretrw.com
greentwg.com
greentwg.net
greentwg.org
greentwu.com
greentwu.net
greentwu.org
greentwh.com
greentwh.net
greentwh.org
greentwi.com
greentwi.net
greentwi.org
greentwn.com
greentwn.net
greentwn.org
greentwd.com
greentwd.net
greentwd.org
greentwt.com
greentwt.net
greentwt.org
greentwl.com
greentwl.net
greentwl.org
greentwe.com
greentwe.net
greentwe.org
greentwo.net
greentwo.org
greentwo.biz
greentwr.com
greentwr.net
greentwr.org
greentwld.com
greentwld.net
greentwld.org
greentwlg.com
greentwlg.net
greentwlg.org
greentwlt.com
greentwlt.net
greentwlt.org
newmanesrb.net
grntwo.com
grntwo.net
grntwo.org
grntwh.com
grntwh.net
grntwh.org
grntwr.com
grntwr.net
grntwr.org
grtrw.org.uk
grtrw.me.uk
grtrw.co.uk
grntr.org.uk
grntr.me.uk
grntr.co.uk

Criminal Registered Nameserver Domains

uneedmc.com
iwarzone.com
book-xm.com
hyperzx.com
netipm.com
regnme.com
mnink.com
viemn.com
nx-web.com
schemeetc.com

Status

Active (Parked)
Suspended
(Parked)
Suspended
Suspended
DNS Looped
Suspended
Active (Parked)
Active (Parked
Active (Parked
Active (Parked
Active (Parked
Active (Parked
Active (Parked
Active (Parked
Active (Parked
Active (Parked)
Active (Parked)
Active (Parked)
Active (Parked)
Active (Parked)
Active (Parked)
Suspended
Suspended
DNS Looped
Active (Unhosted)
Active (Unhosted)
Active (Unhosted)
Active
Active
Active
Active (Unhosted)
Active (Unhosted)
Active (Unhosted)
Suspended
Suspended
Suspended
Suspended
Suspended
DNS Looped
Suspended
Suspended
Suspended
Suspended
Active
Active
Suspended
Suspended
Suspended
Active (DNS Error)
Suspended
Suspended
Suspended
Active
Active
Active
Active
Active
Active




Active (Parked)
Suspended
Active
Suspended
Active
Active
Active
Active
Active
Active
Registrar

M.G. INFOCOM PVT. LTD. DBA MINDGENIES (01-May-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (25-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (28-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (28-Apr-2008)
INTERNET INVEST, INC. DBA IMENA.UA (28-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (29-Mar-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
Spiritdomains/IARegistry (30-Apr-2008)
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk
GX Networks Ltd t/a 123-Reg.co.uk




REGISTER.COM, INC. (03-Apr-2008)
Spiritdomains/IA Registry (28-Mar-2008)
REGISTER.COM, INC. (07-Apr-2008)
Spiritdomains/IA Registry (30-Apr-2008)
KEY-SYSTEMS GMBH/Imena.ua (20-Mar-2008)
REGISTER.COM, INC. (29-Apr-2008)
Spiritdomains/IA Registry (30-Apr-2008)
Spiritdomains/IA Registry (30-Apr-2008)
REGISTER.COM, INC. (05-May-2008)
Spiritdomains/IA Registry (05-May-2008)

Please notify me of any errors or domains not listed here.

Notes for Registrars

i) The  Green Tree (Warehousing) Ltd criminal uses his own nameserver domains to control his zombie botnets or provide his DNS. By definition there can be no legitimate domains using his dedicated botnet nameservers & his conventional nameserver domains are always very recently registered. This provides an ideal database search option for you to identify and delete all of this criminal's fraud domains without any risk of hurting an innocent domain. All of the criminal's current botnet nameservers are - ns1.uneedmc.com, ns1.book-xm.com, ns1.netipm.com, ns1.regnme.com, ns1.mnink.com, ns1.viemn.com, ns1.nx-web.com, ns1.schemeetc.com

ii) The criminal's domains have different false whois registration data.

iii) The criminal will not respond to your challenge but will use the notice to prepare a new network - immediate suspension is requested, please.

The Spam Content

The
Green Tree (Warehousing) Ltd spam headers contain many different forged/bogus 'From' & 'Return Path' addresses & various forged 'Receive' lines. The subject lines vary & all indicate that there is a job opportunity to be had. There is - an illegal job as a money laundering 'mule' or transfer fraud victim, i.e. accepting stolen or counterfeit proceeds into your account and forwarding it on via Western Union or Moneygram for a percentage cut. Needless to say it is these mules that will probably feel the full weight of the law while the remote money launderers are safe. The bogus or stolen funds in the mules account may well also be recovered, leaving them with large losses.

This is the content of an actual Green Tree (Warehousing) Ltd scam spam received from a site contact:

Dear Sir/Madam,

Your resume has been furnished to our company by www.monst er.com web-site as one of the best-qualified job-seekers for a position offered.

Our company - Green Tree (Warehousing) Ltd., as a Third Party Logistics provider (3PL), works closely with major Blue Chip Companies & SME’s, providing mainstream warehousing and materials handling operations, innovative Supply Chain Solutions, Contract Packing and Distribution. We work closely with ou customers to deliver a flexible package that meets their requirements, and place emphasis on value-adding services of proven quality. Business expertise and a high level of diversity gained over 45 years combine to make "Green Tree" an attractive outsourced solution and versatile business partner.

We are currently looking to recruit a Regional Financial Coordinator to manage payments from the customers based within the limits of his country. You wi ll be our financial intermediary in your local area and will be responsible to remit customer payments for the ordered warehousing or shipping to facilitate and fasten payment receipt at the headquarters of the company. This is a brand new part-time position and has been created to improve supply chain performance for the company as we move into a period of substantial expansion where we will double our current turnover.

The role includes dealing with 2-3 customer payments a week; reviewing the balance of the bank account, where the payment is supposed to be debited to; ensuring precise settlements regarding each payment; transmitting the payments to the Headquarters and subsidiaries of the company by means of instant Western Union payment system and providing regular feedback and reports to the Headquarters Office Manager and Supervisor.

It is essential that the candidate promotes positive/can do attitude and discharges his duties urgently, has literate communicational and PC-user skills to interact with other team members and make external contacts related to the job nature.
Successful applicants will need to have a bank account to be used for the customer payments to be debited to, be energetic, enthusiastic and naturally ambitious. This is very much seen as a career progression role that could lead to a management position, so if you are willing to work 1-2 hours a day and be paid on an interest basis (net 10% out of each customer payment you have dealt with) you are welcome to apply now.
So if you are looking for a “career of your life” and would like to find out more about the job specification please visit our web-site at http://grntwr.com

Yours faithfully, Ricardo Barnett

0x0, 0x064, 0x6 HHAE, type, SZI, file, serv. 0x9072, 0x0353, 0x305, 0x5030, 0x6, 0x61586004, 0x423, 0x3, 0x7, 0x05, 0x21559254, 0x4, 0x90 CX0N: 0x61512327, 0x87, 0x94487070, 0x398, 0x3, 0x5, 0x90, 0x5, 0x848, 0x432, 0x543, 0x9, 0x927 0x94 rev: 0x4, 0x5139, 0x95356853, 0x667, 0x5, 0x29, 0x2821, 0x2638, 0x86771229, 0x028, 0x028, 0x643 0x4790, 0x8, 0x72906676, 0x1402, 0x25, 0x9027, 0x53558373, 0x90581881, 0x0, 0x55245205, 0x73622565, 0x5065, 0x6928 0x446, 0x022, 0x80503323, 0x4664, 0x1, 0x55179525, 0x99, 0x901, 0x95272721, 0x429 close: 0x904, 0x35, 0x01235165, 0x22, 0x5, 0x3, 0x1688, 0x283, 0x3, 0x333

0x9, 0x0, 0x822, 0x1618, 0x24, 0x45, 0x608, 0x6, 0x2, 0x24, 0x97 file: 0x41, 0x48865430, 0x40996320, 0x30988457, 0x149, 0x48464224, 0x93045952, 0x9030, 0x3, 0x63331922, 0x41, 0x36346476 R0RL: 0x04710091, 0x0936, 0x 6776, 0x188, 0x0 api, 59DO. 0x475, 0x88292188, 0x79, 0x45674182 0x6293, 0x195, 0x95, 0x559, 0x3, 0x46372613, 0x9, 0x17, 0x70, 0x1574, 0x3452, 0x3, 0x0, 0x48634299 define create GKWJ 449 I57 W999 revision. serv: 0x62772346, 0x9177, 0x68, 0x89, 0x326 0x80110401, 0x9104, 0x0218, 0x7415, 0x8681 0x24, 0x523, 0x1, 0x3945, 0x80, 0x84979753, 0x959, 0x148, 0x75, 0x940, 0x29182705, 0x89334086, 0x4240, 0x1518, 0x32

UR2: 0x1298, 0x60769556, 0x14977709, 0x99, 0x03180519, 0x318, 0x2, 0x499, 0x4, 0x65, 0x7, 0x0676, 0x591, 0x12137606, 0x07177336 0x260, 0x8, 0x88659828, 0x5341, 0x348 0x34474189, 0x0, 0x210, 0x5906, 0x8, 0x0, 0x25, 0x320, 0x02, 0x926 0x9, 0x124, 0x94 QM9, interface, MKDP, Q2Y, SVF, 6MT, OK5L. root: 0x006, 0x7 0x506, 0x81483632, 0x92, 0x65, 0x4, 0x5320, 0x436 KTMU: 0x85679595, 0x1287, 0x9727, 0x7938, 0x2137, 0x832, 0x137, 0x106, 0x1, 0x09, 0x95, 0x165 YLE rev XTVV hex rcs T3JQ MHD HADM: 0x43, 0x1 26, 0x72, 0x33076107, 0x265, 0x129, 0x08

Note the usual Bayesian filter avoidance 'code', commonly used by these criminals and the 'rockphish' scammers alike. It's normally in 'whitetext' so it's invisible, but here I've greyed it in.


The Zombie Botnet DNS Data (Valid for domains greentwu.com, greentwu.net and greentwu.org)

Looking up at the 2 greentwu.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.iwarzone.com [76.191.102.141]125.139.235.149 203.228.153.110 222.233.186.82 222.233.201.23 24.93.118.199 79.114.152.173 89.33.213.53
ns2.iwarzone.com [99.61.52.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.iwarzone.com hosted by PCCW Global/Spectrum Networks/Vanoppen.biz on IP 76.191.102.141 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). These are exactly the same botnet hosting details as were used for the Newman Esmond & Eisenberg fraud domains newnmm.com, newmmns.com and nwaesde.net.
These criminals are experienced liars, thieves and professional confidence tricksters. Do not be fooled - do not believe them. The evidence of criminal fraud is undeniable. I'd like to thank the many honest & ethical hosts who have disconnected these fraudsters within an hour of receiving an abuse report, (several in c. 20 minutes). However, the zombie botnet controlling nameservers seem to be occasionally hosted by Colocation/VPS service providers who do not respond to criminal fraud abuse reports. The honest & ethical SPs will respond with an immediate, (preferably not 24 hours or 48 hours & certainly not never...), disconnection on receipt of a criminal abuse report, having considered the evidence below & investigated, but more and more frequently service providers stall or simply ignore abuse reports. This latter minority of uncaring & unethical hosts are aiding and abetting criminal fraud and the victims suffer because of it.

Blocking The spam

I have had quite a few queries about how to block the criminal's spam in Outlook Express. Fortunately they are easily detected using the OE 'Mail Rules' (Tools - Message Rules - Mail).

Rules based on the From, To etc addresses will never work as the header data is all forged. The message body remains constant, however & that can be used to detect them.

Use the rule "Where the message body contains specific words" and use 
"Green Tree (Warehousing) Ltd" as the search item then choose 'delete' (or whatever action you prefer) as the action then that will definitely detect every single one of these spams.
If you find this site helpful then please feel free to link to it on your website by inserting the following HTML code, (opens site in new window):
<a href="http://www.bobbear.co.uk" target="_blank">Money Laundering Fraud Websites</a>
Fraud Blog Initial entry 26th. April 2008

***Latest News*** - 26th. April 2008

If you have any further information, including spam, active domains etc, please forward it to me via the home page 'Contact Us' form or via the 'Report Active Domain' form, thank you.

***Latest News*** - 28th. April 2008

Botnet DNS Data (Valid for domains greentwg.com, greentwg.net, greentwg.org, greentwn.com, greentwn.net, and greentwn.org)
Looking up at the 2 greentwg.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.uneedmc.com [71.6.211.122] 222.233.201.23 24.93.118.199 85.120.248.106 86.126.214.164 89.114.58.152 89.35.28.41 91.66.178.79
ns2.uneedmc.com [208.21.54.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.uneedmc.com hosted by Cari.net/Zanadoo Hosting on IP 71.6.211.122 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). This is exactly the same nameserver as was used for the Newman Esmond & Eisenberg fraud.

Later: The criminals Spectrum Networks/Vanoppen.biz botnet has been closed down and he is up on another network:
Botnet DNS Data (Valid for domains greentwl.com, greentwl.net, greentwu.com, greentwu.net and greentwu.org)
Looking up at the 2 greentwu.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.iwarzone.com [194.110.67.169] 24.93.118.199 79.116.4.156 79.117.63.109 85.217.201.213 89.32.130.125 89.35.28.41 89.41.8.243
ns2.iwarzone.com [99.61.52.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.iwarzone.com hosted by Netrouting Data Facilities/Grafix.nl on IP 194.110.67.169 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).

Botnet DNS Data (Valid for domains greentwh.com, greentwh.net, greentwh.org, greentwi.com, greentwi.net, greentwi.org)
Looking up at the 2 greentwh.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.book-xm.com [64.191.113.103] 78.97.15.238 79.115.12.6 79.116.4.156 85.120.248.106 85.217.201.213 86.120.95.11 89.32.130.125
ns2.book-xm.com [208.21.54.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.book-xm.com hosted by Network Operations Center Inc./Burst.net on IP 64.191.113.103 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).

***Latest News*** - 1st. May 2008
New botnet for domains greentwg.net, greentwg.org:

Botnet DNS Data (Valid for domains greentwg.net, greentwg.org)
Looking up at the 2 greentwg.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.hyperzx.com [71.6.211.122] 219.52.54.13 87.236.186.174 89.136.117.212 89.136.67.65 89.137.60.248 89.33.213.53 99.235.126.120
ns2.hyperzx.com [83.80.50.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.hyperzx.com hosted by Cari.net/Zanadoo Hosting on IP 71.6.211.122 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). This is exactly the same nameserver as was used for the Newman Esmond & Eisenberg fraud.

Twelve of the Imena.ua domains have been parked, but the criminal has registered replacement domains greentwl.com, greentwl.net and greentwl.org hosted on the above Netrouting Data Facilities/Grafix.nl zombie botnet. Two of the three hosts have failed to reply to abuse reports.
Later: New domains greentwe.com, greentwe.net, greentwe.org, greentwr.com, greentwr.net, greentwr.org found, all registered with Spiritdomains on 30-Apr-2008 and unhosted at present but showing 'A' records on the criminal's nameserver ns1.uneedmc.com
New domains greentwo.net, greentwo.org, greentwo.biz also found and also registered
with Spiritdomains on 30-Apr-2008 and all hosted on a new botnet hosted by ns1.book-xm.com:
Botnet DNS Data (Valid for domains greentwo.net, greentwo.org, greentwo.biz)
Looking up at the 2 greentwo.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.book-xm.com [67.207.75.11] 219.52.54.13 59.186.129.140 86.105.12.97 86.126.214.164 87.206.177.217 89.136.67.65 99.235.126.120
ns2.book-xm.com [208.21.54.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.book-xm.com hosted by Global Technology Solutions, Inc/KevWorks, LLC/ANS Communications on IP 67.207.75.11 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).

***Latest News*** - 2nd. May 2008

The above criminal fraudsters US hosts, namely Netrouting Data Facilities/Grafix.nl and Cari.net/Zanadoo Hosting have been informed of the illegal activities that they are aiding and abetting but appear to be happy to continue to do so. In addition Cox.net are uninterested that they are carrying the illegal traffic on behalf of their clients
Cari.net/Zanadoo Hosting. Looks like the criminals have currently got a secure set of accomplices in those companies. In addition there has been no response as yet from Global Technology Solutions Inc/KevWorks LLC/ANS Communications.
Later: Response received from
KevWorks LLC - the above criminal's botnet has been shut down. New botnet details:

Botnet DNS Data (Valid for domains greentwo.net, greentwo.org, greentwo.biz)
Looking up at the 2 greentwo.org. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.book-xm.com [78.110.164.36] 79.117.181.188 86.13.192.160 89.137.9.59 89.32.130.125 89.35.28.41 89.41.182.152 89.41.8.243
ns2.book-xm.com [208.21.54.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.book-xm.com hosted by VAServe LTD/UK Dedicated Servers Limited on IP 78.110.164.36 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).
Later: The botnet nameserver domains iwarzone.com and hyperzx.com have been suspended by Spiritdomains, (respect is due to them for their ethical stance - if only all registrars were as helpful), and have been replaced by netipm.com and regnme.com respectively - details in the table. New botnet details:

Botnet DNS Data (Valid for domains greentwl.net)
Looking up at the 2 greentwl.net parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.netipm.com [194.110.67.169] 77.127.204.199 79.112.28.155 79.112.57.16 79.113.68.83 84.58.108.32 85.64.54.195 86.125.70.98
ns2.netipm.com [83.80.50.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.netipm.com hosted by Netrouting Data Facilities/Grafix.nl on IP 194.110.67.169 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). Grafix.nl have not responded to abuse reports.

Botnet DNS Data (Valid for domains greentwg.net, greentwg.org, greentwld.com, greentwld.net, greentwld.org)
Looking up at the 2 greentwg.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.regnme.com [71.6.211.122] 77.127.204.199 79.112.57.16 79.113.68.83 82.24.119.110 84.58.108.32 85.64.54.195 89.110.58.31
ns2.regnme.com [203.95.52.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.regnme.com hosted by Cari.net/Zanadoo Hosting on IP 71.6.211.122 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). Cari.net/Zanadoo Hosting have not responded to abuse reports.

***Latest News*** - 4th. May 2008
The criminal's ns1.regnme.com controlled zombie botnet has been moved to a new host:
Botnet DNS Data (Valid for domains greentwg.net, greentwg.org, greentwld.com, greentwld.net)
Looking up at the 2 greentwld.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.regnme.com [85.197.99.29] 79.114.215.103 79.114.235.181 79.114.81.1 79.117.94.54 79.182.254.103 84.58.140.81 86.106.59.77
ns2.regnme.com [203.95.52.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.regnme.com hosted by Welcome 2 Inter.Net on IP 85.197.99.29 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT)
Later: An instant response from the superb ethical host Welcome 2 Inter.Net has resulted in the above botnet controller being shut down - many thanks. If only some other hosts were as intelligent and not so willing to shelter these criminals as some of them appear to be, e.g. grafix.nl in particular...
Later: If any more proof were needed that these Green Tree (Warehousing) Ltd criminals are the same gang as the Newman, Esmond & Eisenberg criminal fraudsters then they've kindly provided it by using the old NEE domain newmanesrb.net for the GTWL site.
DNS Data (Valid for domain newmanesrb.net)
Looking up at the 2 newmanesrb.net. parent servers:

ServerResponse
ns2.newmanesrb.net [200.72.139.67] 211.3.149.208
ns1.newmanesrb.net [219.76.235.93] 211.3.149.208

There we see the usual 'blackhat' nameserver host ENTEL CHILE S.A. (200.72.139.67) and the Netvigator (PCCW Ltd) IP
219.76.235.93 both of which were used for so long for the NEE fraud. The fraud website host IP (211.3.149.208) belongs to Open Data Network (JAPAN TELECOM CO.,LTD.) under the control of JPNIC. Once again the IP 211.3.149.208 has RDNS set up (OFSfb-12p2-208.ppp11.odn.ad.jp) so it is quite likely to be a solitary zombie or a criminal owned machine.

***Latest News*** - 5th. May 2008
The criminal has registered some new nameserver domains and set up some new botnets to replace ones disconnected by ethical hosts:
Botnet DNS Data (Valid for domains  greentwld.com, greentwld.net)
Looking up at the 2 greentwld.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.mnink.com [67.222.131.126] 77.127.96.54 79.113.69.156 79.113.74.213 80.193.151.186 84.58.175.128 85.64.54.195 85.66.209.81
ns2.mnink.com [195.81.52.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.mnink.com hosted by Tailor Made Servers/Amaresh Ray on IP 67.222.131.126 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT)

Botnet DNS Data (Valid for domains greentwo.net, greentwo.org, greentwo.biz, grntwo.com, grntwo.net)
Looking up at the 2 greentwo.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.viemn.com [78.110.164.36] 77.127.96.54 79.113.69.156 79.113.74.213 84.58.175.128 85.64.54.195 85.66.209.81 86.106.45.176
ns2.viemn.com [73.80.50.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.viemn.com hosted by VAServe LTD/UK Dedicated Servers Limited on IP 78.110.164.36 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).

Botnet DNS Data (Valid for domains grntwr.net, grntwr.com)
Looking up at the 2 grntwr.net. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.netipm.com [194.110.67.169] 77.127.96.54 79.113.69.156 79.113.74.213 79.117.166.43 84.58.175.128 85.64.54.195 85.66.209.81
ns2.netipm.com [83.80.50.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.netipm.com hosted by Netrouting Data Facilities/Grafix.nl on IP 194.110.67.169 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT). Grafix.nl have not responded to abuse reports to date.

***Latest News*** - 6th. May 2008
The VAServe LTD/UK Dedicated Servers Limited botnet on IP 78.110.164.36 has been shut down and is now back up on IP 65.75.189.85

Botnet DNS Data (Valid for domains greentwo.net, greentwo.org, greentwo.biz, grntwo.com, grntwo.net)
Looking up at the 2 grntwo.com. parent servers:

Zombie Botnet NameserverBotnet Nameserver 'A' Records (Zombie Site Host IPs)
ns1.viemn.com [65.75.189.85] 123.213.237.165 211.32.122.91 78.37.180.41 86.126.214.164 89.114.17.91 89.33.119.85 89.33.213.53
ns2.viemn.com [73.80.50.10]Timeout - Fake nameserver, (never resolves).

The data shows a standard 7-IP site hosting zombie botnet where the nameserver ns1.viemn.com hosted by SoftwareWorks Group, Inc./Carohosting.net on IP 65.75.189.85 is acting as a zombie botnet controller 'herding' the rotating zombies, (as determined by RDNS), in the 'A' records list which are hosting the fraud site (as determined by TRACERT).

**