Amazon

Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Friday, 16 January 2015

UK Fuels E-bill invoices@ebillinvoice.com document malware

UK Fuels E-bill  invoices@ebillinvoice.com  are being spammed out.
The Word document has a random attachment, however these emails aren't from UK Fuels Ltd at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
 Date: Fri, 16 Jan 2015 10:08:44 +0300
From: invoices@ebillinvoice.com
Subject: UK Fuels E-bill

Message Body (Note:  the amount, company person and name are random)
Dear Customer

Please find attached your invoice for Week 02 2015.

In order to open the attached DOC file you will need
the software Microsoft Word.

If you have any queries regarding your e-bill you can contact us at invoices@ebillinvoice.com. Alternatively you can log on to your account at www.velocitycardmanagement.com to review your transactions and manage your account online.

Yours sincerely

Customer Services
UK Fuels Ltd

======================================================
This email, its content and any files transmitted with
it are confidential and intended solely for the use of
the individual(s) to whom it is addressed.
If you are not the intended recipient, be advised that
you have received this email in error and that any use,
dissemination, forwarding, printing or copying of
this email is strictly prohibited.
======================================================
Attachment: (Note: the filename is random)
35056_02_2015.DOC

Md5 Hashes:
f26cb0d400e1f842605077de2c231726 [1]
fea2f5617fdf6f672ee117574734f859 [2]
436cffad2557fd4c083414a71527b73e [3]

Malware Macro document information:

VirusTotal Report [1] (hits 0/57 Virus Scanners)

VirusTotal Report [2] (hits 0/57 Virus Scanners)

VirusTotal Report [3] (hits 0/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as:

Sanesecurity.Malware.24676.DocHeur
Sanesecurity.Malware.24682.OffHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Thursday, 15 January 2015

netcarrer.com job scam

netcarrer.com - another "money making" scam.... from the same people that brought you this one

Various Message Headers:
Subject: Best job (according to Google Analytics).
Subject: Mail delivery failed: returning message to sender
Subject: Make money more often!
Subject: Undelivered Mail Returned to Sender
Subject: Want to make money fast?
Subject: You can STILL make money fast and easy.
Subject: You can use it to make cash anytime you need it.

Message Body:
You can be earning commissions like that by the end of today with this:

>>Follow instructions on next page: www.netcarrer.com
Whois information for the domain:
Domain Name: NETCARRER.COM
Registrar: BIZCN.COM, INC.
Sponsoring Registrar IANA ID: 471
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.AFRAID.ORG
Name Server: NS2.AFRAID.ORG
Name Server: NS3.AFRAID.ORG
Name Server: NS4.AFRAID.ORG
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 13-jan-2015
Creation Date: 13-jan-2015
Expiration Date: 13-jan-2016
Domain name: netcarrer.com
Registry Domain ID: 1895612653_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.bizcn.com
Registrar URL: http://www.bizcn.com
Updated Date: 2015-01-13T12:21:07Z
Creation Date: 2015-01-13T12:21:07Z
Registrar Registration Expiration Date: 2016-01-13T12:21:07Z
Registrar: Bizcn.com,Inc.
Registrar IANA ID: 471
Registrar Abuse Contact Email: abuse@bizcn.com
Registrar Abuse Contact Phone: +86.5922577888
Reseller: Cnobin Technology HK Limited
Registry Registrant ID: 
Registrant Name: Marc Jacobs
Registrant Organization: Marc S. Jacobs
Registrant Street: 630 Simpson Street
Registrant City: Fairview (Fulton)
Registrant State/Province: IL
Registrant Postal Code: 61432
Registrant Country: us
Registrant Phone: +1.3097785683
Registrant Phone Ext: 
Registrant Fax: +1.3097785683
Registrant Fax Ext: 
Registrant Email: info@netcarrer.com
Here's the website you get, trying to "help" you with a "$500 a day" incentive !

Cheers,

Steve
Sanesecurity.com

Payment request of invoice document malware

Payment request of invoice from random emails and companies are being spammed out.
The Word document has a random attachment, however these emails aren't from these companies  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header: (Note: the email address and amount are random)
Subject: Payment request of 3682.49 (14 JAN 2015)
From: Lucinda Zamora {Mabel.ca9@mitchhughes.net}

Message Body (Note:  the amount, company person and name are random)
Dear Sirs,
Sub: Remitance of GBP 3682.49
This is with reference to the above, we request you to kindly remit GBP 3682.49 in favor of our bank account.
For more information on our bank details please refer to the attached document.
Thanking you,
Lucinda Zamora
Accounting Team
Attachment: (Note: the filename is random)
ADV9814QV.doc

Md5 Hashes:
44d5e293fc3e4a68aca41b5651f5b897 [1]
7f3c2b0c5abe311f4e40b2a938a8ed75 [2]
38665c6364dd127b4b8bf98e033c4ec7 [3]
984597f7d4e83599baac04c7708394b2 [4]

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 3/57 Virus Scanners)

VirusTotal Report [3]
(hits 3/57 Virus Scanners)

VirusTotal Report [4]
(hits 3/57 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Invoice from Hexis {Invoice@hexis.co.uk} document malware

Invoice from Hexis {Invoice@hexis.co.uk} S-INV-CREATIFX document malware is being spammed out.
The Word document has a random attachment, however these emails aren't from HEXIS (UK) LIMITED  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.

Update: Direct from Hexis themselves...  note, although they say they've been "hacked" they haven't been, it's just being faked:

Dear Customer,

Hexis UK Ltd has had their E-mail account hacked early this morning the hacker is sending emails that look like they are coming from Hexis with the following email address (invoice@hexis.co.uk).

If you receive an email from Hexis and are not expecting it then please DO NOT OPEN the email & simply delete it.

Please note that due to huge amount of emails that have been sent, we are receiving a very very high telephone demand from thousands of people.

Should you wish to place an order with Hexis then please bare with us or email us at sales@hexis.co.uk


We thank you for your understanding.

Message Header:
From: Invoice from Hexis {Invoice@hexis.co.uk}
Subject: Invoice

Message Body:
Sent 15 JAN 15 08:30

HEXIS (UK) LIMITED
7 Europa Way
Britannia Park
Lichfield
Staffordshire
WS14 9TZ

Telephone 01543 411221
Fax 01543 411246
Attachment:
S-INV-CREATIFX-465219.doc

Md5 Hashes:
7071702019e845579cefd35724d87944
b2356ce5a8f311df482d5b2a92e567ff

Malware Macro document information:

VirusTotal Report [1]
(hits 3/57 Virus Scanners)

VirusTotal Report [2]
(hits 0/21 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Wednesday, 14 January 2015

SEPA REMITTANCE ADVICE malware

SEPA REMITTANCE ADVICE macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from the company they appear to be from at all, they just being used to make the email look more genuine:
It's also worth remembering that the company itself  may not have any knowledge of this email and it's link(s) or attachment as it won't have come from their servers and IT systems but from an external bot net.

It's not advised to ring them as there won't really be anything they can do to help you.
Message Header (Note: Random from address)
From: Nichole England {Jared.4bbd@ono.com}
Subject: SEPA REMITTANCE ADVICE 6513.56 EUR 12 JAN 2014

Message Body: (Note: Name and amount is random)
Good Afternoon
Please see attached a copy of remittance advice for SEPA payment of 6513.56  EUR made on 12/01/2015
Regards,
Nichole England
Senior Accounts Payable
Attachment (Note: Random document name)
E538XH.doc

Md5 Hashes:
57dbc8da6e0ae797d5f0c7e22722cf37
9875233ba6f2c6d10fbf3c91f0b46a96

Malware Macro document information:

VirusTotal Report [1]  (hits 0/57 Virus Scanners)

VirusTotal Report [2]  (hits 0/57 Virus Scanners)


Malwr Report [1]

Malwr Report [2]


Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Tuesday, 13 January 2015

Card Receipt AquAid Tracey Smith tracey.smith@aquaid.co.uk receipt of payment document malware

Card Receipt 01.12.2015 AquAid Tracey Smith tracey.smith@aquaid.co.uk receipt of payment emails are back once again and trying to trick you into opening a word document, containing a malicious macro.

AquAid malware run of a macro infected "Card Receipt" word document has a random attachment,
however these emails aren't from AquAid at all, they just being used to make the email look more
genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.

Message Headers (Note that the email address is random):
From: "Tracey Smith" {tracey.smith@aquaid.co.uk}
Subject: Card Receipt 01.12.2015
Date: Tue, 13 Jan 2015 08:49:46 +0200

Message Body:

 Hi

Please find attached receipt of payment made to us today

Regards

Tracey
Tracey Smith| Branch Administrator
AquAid | Birmingham & Midlands Central
Unit 35 Kelvin Way Trading Estate | West Bromwich | B70 7TP
Telephone:        0121 525 4533
Fax:                  0121 525 3502
Mobile:              07795328895
Email:               tracey.smith@aquaid.co.uk

AquAid really is the only drinks supplier you will ever need with our huge product range. With products ranging from bottled and mains fed coolers ranging up to coffee machines and bespoke individual one off units we truly have the right solution for all environments. We offer a refreshing ethical approach to drinks supply in that we support both Christian Aid and Pump Aid with a donation from all sales.  All this is done while still offering a highly focused local service and competitive pricing. A personalised sponsorship certificate is available for all clients showing how you are helping and we offer £25 for any referral that leads to business.

*********************************************************************
AquAid Franchising Ltd is a company registered in England and Wales with registered number 3505477 and registered office at 51 Newnham Road, Cambridge, CB3 9EY, UK. This message is intended only for use by the named addressee and may contain privileged and/or confidential information. If you are not the named addressee you should not disseminate, copy or take any action in reliance on it. If you have received this message in error please notify the sender and delete the message and any attachments accompanying it immediately. Neither AquAid nor any of its Affiliates accepts liability for any corruption, interception, amendment, tampering or viruses occurring to this message in transit or for any message sent by its employees which is not in compliance with AquAid corporate policy.
One example of the random attachment file name:
CARD015 151239.doc

Md5 Hashes:
0bc08e20e1e7b850b04616a85f572296
eb0209febd5951a28e6680b56c75d740

Macro document information:

VirusTotal Report [1]
(hits 1/56 Virus Scanners)

VirusTotal Report [2]
(hits 1/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24646.DocHeur

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Monday, 12 January 2015

Jason Bracegirdle JPS Projects Ltd - Summary Paid Against - {jason.bracegirdle@jpsprojectsltd.co.uk}

Summary Paid Against - Jason Bracegirdle JPS Projects Ltd - Copy of Weekly Summary {jason.bracegirdle@jpsprojectsltd.co.uk} macro based malware being spammed out.

The Word document has a random attachment, however these emails aren't from JPS Projects Ltd  at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Message Header:
From: "Jason Bracegirdle JPS Projects Ltd" {jason.bracegirdle@jpsprojectsltd.co.uk}
Subject: Summary Paid Against
Date: Mon, 12 Jan 2015 20:47:34 +0900

Message Body:
Please find attached summary which was paid against

Jas

Jason Bracegirdle  Managing Director

M: 07912 883455
O: 02031 741416
F: 02030 700632
E: 
jason.bracegirdle@jpsprojectsltd.co.uk
W:  www.jpsprojectsltd.co.uk

Manchester
402 Chaddck Lane
Astley
Manchester
M29 7JS
London

Unit 9,
Bunns Lane Works,
Bunns Lane,
Mill Hill,
London
NW7 2AJ

This e-mail is confidential and is intended solely for the use of the
individual or entity to whom it is addressed. If you are not the intended
recipient and you have received this e-mail in error then any use,
dissemination, forwarding, printing or copying of this e-mail is strictly
prohibited. You should contact the sender by return e-mail and delete and
destroy all the information from your system. Any views or opinions
presented are solely those of the author and do not necessarily represent
those of JPS. This email does not form part of a legally binding agreement.
We have taken precautions to minimise the risk of transmitting software
viruses or trojans, but we advise that you carry out your own virus checks
on any attachments to this message. We cannot accept liability for any loss
or damage caused to your software, hardware or system.

More information about JPS can be found at our website at:
http://www.jpsprojectsl
Attachment:
Copy of Weekly Summary 28 12 2014 w.e 28.12.14.doc

Md5 Hashes:
030bbc1dc435a612d4ed7a049470ddb5
4cbc955ea75fa3edff0f73c2ca859119

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.

NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

webscareer.com job money making scam

webscareer.com - another "money making" scam.... from the same people that brought you this one

Various Message Headers:
Subject: Hello!
Subject: Hi!
Subject: It's a very good thing
Subject: it's fantastic
Subject: Please look it
Subject: Special for you

Message Body:
Hi,

I guarantee that you will never ever look for other money making methods
after you watch this presentation!

Exceed your wildest financial goals NOW:

=> www.webscareer.com

Regards
Whois information for the domain:
   Domain Name: WEBSCAREER.COM
   Registrar: BIZCN.COM, INC.
   Sponsoring Registrar IANA ID: 471
   Whois Server: whois.bizcn.com
   Referral URL: http://www.bizcn.com
   Name Server: NS1.AGERMAINVA.NET
   Name Server: NS2.AGERMAINVA.NET
   Status: clientDeleteProhibited
   Status: clientTransferProhibited
   Updated Date: 11-jan-2015
   Creation Date: 11-jan-2015
   Expiration Date: 11-jan-2016

Domain name: webscareer.com
Registry Domain ID: 1895239097_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.bizcn.com
Registrar URL: http://www.bizcn.com
Updated Date: 2015-01-11T17:45:36Z
Creation Date: 2015-01-11T17:45:35Z
Registrar Registration Expiration Date: 2016-01-11T17:45:35Z
Registrar: Bizcn.com,Inc.
Registrar IANA ID: 471
Registrar Abuse Contact Email: abuse@bizcn.com
Registrar Abuse Contact Phone: +86.5922577888
Reseller: Cnobin Technology HK Limited
Registrant Name: Josefina Ferris
Registrant Organization: Josefina D. Ferris
Registrant Street: 3642 Woodstock Drive
Registrant City: Pasadena
Registrant State/Province: CA
Registrant Postal Code: 91101
Registrant Country: us
Registrant Phone: +1.6265350013
Registrant Phone Ext: 
Registrant Fax: +1.6265350013
Registrant Fax Ext: 
Registrant Email: info@webscareer.com
Here's the website you get, trying to "help" you with a "$500 a day" incentive !

Cheers,

Steve
Sanesecurity.com

Invoice from simply carpets of Keynsham Ltd document malware

Invoice from simply carpets of Keynsham Ltd - sales@simplycarpets.co.uk emails with an attached document, is being spammed out.  The document contains a macro.

The Word document has a random attachment, however these emails aren't from Keynsham Ltd
at all, they just being used to make the email look more genuine, ie. from a real company.

It's also worth remembering that the company itself  may not have any knowledge of this attachment as it won't have come from their servers and IT systems.

They may not be able to tell you if it's malware or even help clean up your system.
Message Header:
From: "Simply carpets " {sales@simplycarpets.co.uk}
To: hilaryr@newburydata.co.uk
Subject: Invoice from simply carpets of Keynsham Ltd
Date: Mon, 12 Jan 2015 09:40:29 +0200

Message Body:
Your invoice is attached.  Please remit payment at your earliest
convenience.

Thank you for your business - we appreciate it very much.

Sincerely,

simply carpets of Keynsham Ltd

Inv_12983_from_simply_carpets_of_keynsham_ltd_3464.doc

Md5 Hashes:
030bbc1dc435a612d4ed7a049470ddb5
4cbc955ea75fa3edff0f73c2ca859119

Malware Macro document information:

VirusTotal Report [1]
(hits 0/56 Virus Scanners)

VirusTotal Report [2]
(hits 0/56 Virus Scanners)

Malwr Report [1]

Decoded Macro [1]
Sanesecurity signatures are blocking this as: Sanesecurity.Malware.24679.DocHeur.


NOTE

The current round of Word and Excel attachments are targeted at Windows users.

Apple and Android software can open these attachments and may even manage to run the macro embedded inside the attachment.

The auto-download file is normally a windows executable and so will not currently run on  any operating system, apart from Windows.

However, if you are an Apple/Android user and forward the message to a Windows user, you will them put them at risk of opening the attachment and auto-downloading the malware.

Currently these attachments try to auto-download Dridex, which is designed to steal login information regarding your bank accounts (either by key logging, taking auto-screens hots or copying information from your clipboard (copy/paste))
Cheers,

Steve

Thursday, 8 January 2015

binaryworking.com scam

binaryworking.com - another "money making" scam.... from the same people that brought you this one

Various Message Headers:
Subject: 100% FREE
Subject: Best job (according to Google Analytics).
Subject: Best job for You
Subject: Copy + Paste = $13,000 a month
Subject: Have you seen this yet?
Subject: Make money more often!
Subject: Want to make money fast?
Subject: You can STILL make money fast and easy.
Subject: You can use it to make cash anytime you need it.

Message Body:
You can be earning commissions like that by the end of today with this:

>>Follow instructions on next page: www.binaryworking.com
Whois information for the domain:
   Domain Name: BINARYWORKING.COM
   Registrar: BIZCN.COM, INC.
   Whois Server: whois.bizcn.com
   Referral URL: http://www.bizcn.com
   Name Server: NS1.AGERMAINVA.NET
   Name Server: NS2.AGERMAINVA.NET
   Status: clientDeleteProhibited
   Status: clientTransferProhibited
   Updated Date: 07-jan-2015
   Creation Date: 07-jan-2015
   Expiration Date: 07-jan-2016

Registrar: Bizcn.com,Inc.
Registrar IANA ID: 471
Registrar Abuse Contact Email: abuse@bizcn.com
Registrar Abuse Contact Phone: +86.5922577888
Reseller: Cnobin Technology HK Limited
Domain Status: clientDeleteProhibited
Domain Status: clientTransferProhibited
Registry Registrant ID: 
Registrant Name: Heather Vitela
Registrant Organization: Heather A. Vitela
Registrant Street: 4967 Tator Patch Road
Registrant City: Chicago
Registrant State/Province: IL
Registrant Postal Code: 60607
Registrant Country: us
Registrant Phone: +1.3128298860
Registrant Phone Ext: 
Registrant Fax: +1.3128298860
Registrant Fax Ext: 
Registrant Email: info@binaryworking.com
Here's the website you get... lovely...

Think I'll stay away from this one as well.

Cheers,

Steve
Sanesecurity.com

Tuesday, 6 January 2015

See my photo collection Perhaps you want to see my camshots dating scam

See my photo collection -  the dating spams go on and on and on.. pretty much the same forum types links as reported on the blog earlier.

Message Headers:
From: "Wilda" {Karcher1961kq@fibertel.com.ar}
Subject: See my photo collection
Date: Tue, 06 Jan 2015 11:56:16 -0300
Example Message Body, with slight variations on the Name...
Hi,
Perhaps you want to see my camshots? Do you like Russian girls?

I am the one who wants to find male friends abroad.
See my photo collection

Hope we will talk soon.
The above message links to various websites that run a forum... and point to a direct post:
prozacville.com/mc/viewtopic.php?f=3&t=1573&p=3013#p3013

An example forum post:

Dreaming to fall in love with a foreign man

by Elenaservt » Sun Jan 04, 2015 2:46 pm
Hi everyone!
My name is Elena,
I live in Moscow (Russia) and have a dream like many other girls – I want to find my love and live a wonderful life together!
This is not the only my interest, but for now it has become a priority.

Cheers,

Steve
Sanesecurity.com