NIGERIAN SCAMMER – ADVANCE FEE FRAUD
My spam-box gets overwhelmed with scam mail that sometimes its hard to keep up so I’ve decided to post the older emails in lists of five in each post. I know scammers tend to change their names/email-addresses to avoid detection so I want to post these emails before its to late. By ”old” I mean the emails that are several weeks old.
1.) SCAM RECEIVED 11/03/12 – Lottery Scam – FRAUD – Fake Cashier Check ( Microsoft and Shell Petrolum
Lottery )
FROM: United Nations Organisation unitednationprogram101@gmail.com RETURN-ADDRESS: unitednations77@yahoo.cn
EMAIL: United Nations Assisted Program
Directorate of International Payment
United Nations Liaison Office – Africa
Attention Beneficiary,
This email is to notify you about the release of your outstanding payment
which is truly $2.500,000.00 Million Dollars The Federal Government
scheduled a time frame to settle all foreign debts which includes
Contract/Inheritance/Lottery (Sponsored by Microsoft and Shell Petrolum
Lottery) and other international loans. News had it that over the
past,numerous individual(s) who happen to be impostors (claiming to be
individuals, banks and organizations) are claiming to release numerous sums
of fund via numerous ways.
You have two options to receive your payment which is either a Pin Based
ATM card or Certified Cashier s Check. You are advised to select one out of
the two options on how you wish to receive your $2.500, 000.00 Million
Dollars through ATM card or Check which will be shipped via Apex Express
Shipping Courier Company and would get to you within 2 to 3 working days at
most.
DO NOT SEND MONEY TO ANYONE UNTIL YOU READ THIS MASSAGE:
The actual fees for shipping your ATM Card/ Check is $125.99 Dollars but
because Apex Express Shipping Courier have temporarily discontinued the
C.O.D which gives you the chance to pay when package is delivered for
international shipping as stated on their We had to sign a contract with
them for bulk shipping which makes the fees reduce from the actual $125.99
Dollars to $98.99 Dollars nothing more and no hidden fees of any sort! You
are advised to contact the disparch officer responsible for the shipping
of your Check or ATM Card with the following information for shipping of your
payment through Check or ATM Card.
Contact: Mathew Benson
United Nation Dispatching Officer
E-Mail: ( apex.expressbj@hotmail.fr )
Tel No: +229-98660756
Make Sure you provide him with the following information:
1,Your full Name.
2,Your Address where your payment will be dispatch to you:.
3,Home/Cell Phone:.
4,Preferred Payment Method (Check or ATM):
5,Passport ID
The dispatching officer will provide you with instructions on how you are
to make the payment of $98.99 Dollars only for the shipping of your ATM
Card or Cashier s Check. Remember that you are not paying any fees extra
no matter what. Once again note that the actual Apex Express Shipping
Courier Retail Price is: $125.99 Dollars Your Price (Because of our contract
signed): $98.99 Dollars ($27.00 Dollars Savings!)
Respectfully,
Mrs Gee Pascal
UN Envoy (African Region)
HEADER:
Return-Path: | <unitednationprogram101@gmail.com> | |
X-YahooFilteredBulk: | 85.95.227.44 | |
Received-SPF: | neutral (85.95.227.44 is neither permitted nor denied by domain of gmail.com) | |
X-YMailISG: | sWdekBcWLDssnWv.BveVT_YbxrQD86AacHKbtR.12ZPBbfNx Ad.oBkT29R.LE0V5esaZbUkZRPHzAXD4D3fb7SthrhRR2oATGJ7ViO7nHj2Y Cun9AJTMU4BFInv4aeS5y4rBjxuo2pkRTMz1S_0nfDcT5AbBXaZsRu6L89zG y3whvwnLq4Pp6MsyiPqFR5WK8aEFcQ03OOeqOngTDeS7V9F4ow9VsVCbNnbo lR3lm0aSaMAoPcxWyoinnaopAfehC7DFfaoY0oMbqyKBYYMGSpkUHPjLujET lmNlr3O5e4qRk5GLncnodLvFpBNx3XArv7DRBOkkQhn0klpH7HNyJJ9xCDCh 6xXHuhr1Q9V2sKXZtOYXDlsBQUA9Xo1Wol7Ox8C.QZfnRXuU_9t0_._4huXf 8FKaQCFKCyqe86URPLmoDdx13MYrx2oc5Y0I_MYn7ohLYWxMgSlCkg06AuB. 7oyuoSZckSK5H0hp3Cx9ENM1skq.Tn0IdUTrDdQpkpHoAFX3FUEZmQjAun3n Qe1KKYYNydzQxkNb884IW8VXiBI9q9AZBI0tVL_i318hZbRZhXO6h6fAS1IJ ERs_6RQdMJw3O6ln2F7n06pFsLzOexX9gsXC9E03ZvoyxdDEeKmvmD1nXX9v vNgAOIiLbZd93ny6s1elUXO0rVbbavH5mcTQGlDOMXiHtjSOK53pSXQgGAK. kgimeAYBwfHx.gNKDfMfP.Vbka5RzIqgCGFBRBqsNX1JlUXEdvlJN.zcFQPd lvZ2WqLAcPK7KEt1lUDdwxhvH47wVYgoVBF8CclOV_H9rYjaVjxke4BOyXSA fJZcfIl4EaPHyLZM3UpMEL74zbGUlKLLR7LUdEODVdZWggQlk_nhWG.pE2zv xzwN8qBGokKGE1ipznT6xMZmMweUJu7o.UWIksfxBJAB_22u1V6SaIRTuh6C SXGKMN5qsHdwzxrcARyNsKtpGJyMlZVN7xr5buXiuxRQjAVZMzeeeuYPk7HV mNAlMkV765ZEudSNEW0S_cxXnxvm_mczrNYAVF975dNasK0z92G5da4I.Bvw bLJj3AiOjRoyyc7CsdRhXjecey8VQcIQj9XbnPp.U1pSQdKt6n9vge39xXWA DqjLhWyNtir4CVLR_zP7b3lOTbY0x3UVoEV0YcXLukaTYgEFlcLJ.9HObQTp GsQV4o9cd9bjtz3HLkjY1JdStOhEFj03HPEX_kC7wbIo6Ry74yDtuFVkMJ2u _cd98GcrBXgFba2ogZ73DP5nZ4k0PEe5cS7oIZv1vKSfEQA23J__yYScRw5u BYoEYZnnmg77EY13hdzG7B5OenBv1D4qOevACZ20JQy37kkv7ne9mj.f0E9I OEbg2sn7Jo5MIBI1Cqu27ZkFn29i3Sjig8MCJWiR.s_S.yc2AQs58bzlC0tV lSrX_JsCA272B7d4DCHQzfbXdJ2LDIgJ7dxszuVho7yYzfPOU3o.DrsUgAg- | |
X-Originating-IP: | [85.95.227.44] | |
Authentication-Results: | mta1385.mail.bf1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=neutral (no sig) | |
Received: | from 127.0.0.1 (EHLO ip227.240.onofis.com) (85.95.227.44) by mta1385.mail.bf1.yahoo.com with SMTP; Sat, 03 Nov 2012 12:00:16 -0700 | |
Received: | from ip227.240.onofis.com (unknown [127.0.0.1]) by ip227.240.onofis.com (Postfix) with ESMTP id 5A31859C10CD; Sat, 3 Nov 2012 16:51:29 +0000 (UTC) | |
Received: | from User (unknown [41.79.217.115]) by ip227.240.onofis.com (Postfix) with ESMTP; Sat, 3 Nov 2012 16:51:27 +0000 (UTC) | |
Reply-To: | <unitednations77@yahoo.cn> | |
From: |
“United Nations Organisation”<unitednationprogram101@gmail.com>
|
|
Subject: | Contact Apex Express Courier Immediately For Your $2,500,000,00 | |
Date: | Sat, 3 Nov 2012 17:52:09 +0100 | |
MIME-Version: | 1.0 | |
Content-Type: | text/plain; charset=”Windows-1251″ | |
Content-Transfer-Encoding: | 7bit | |
X-Priority: | 3 | |
X-MSMail-Priority: | Normal | |
X-Mailer: | Microsoft Outlook Express 6.00.2800.1081 | |
X-MimeOLE: | Produced By Microsoft MimeOLE V6.00.2800.1081 | |
X-Antivirus: | avast! (VPS 121103-0, 11/03/2012), Outbound message | |
X-Antivirus-Status: | Clean | |
Message-Id: | <20121103165129.5A31859C10CD@ip227.240.onofis.com> | |
To: | undisclosed-recipients:; | |
Content-Length: | 2523 |
2.) SCAM SENT 11/02/12 – NIGERIAN 419 SCAM – MONEY TRANSACTION – FRAUD
FROM: Derick Ahmed raymond@tjzhjc.com RETURN-ADDRESS: dmk150dmk@yahoo.co.jp
EMAIL: Greetings Sir,
Our company (VETCO) requires urgently a dietary chemical material which are produced and sold in your country. This Material is used in the production of dietary supplement, vaccines and injections for sub Saharan Horses and pets. My director will be sending our procurement officer to Your country to purchase the chemical material and am requesting you to stand as a supplier so that i can give you the contact of the local Vendor for you to procure the material from him and sell to my CEO at a very lucrative price. It will interest you to know that our director does not have the direct contact of the local producer due to some managerial changes in our company. l was opportune to discover this contact from the last airway bill used by our last procurement officer who just died. Previously our deceased officer has been inflating the supply to the tune of $27,000.
But i discovered from the receipt that the local dealer is selling the material for $11,750 per 5 liter gallon and you will supply to my CEO at $23,500 per gallon , that is the more reason our Director will like to buy from you and my company will require more than 100 gallons.My CEO will advance you payment as soon as he can confirm the availability of the Material.
l will give you more details when i hear from you confirming your interest.
Pls reply here: dmk150dmk@yahoo.co.jp with your details as:
1. Full name/address
2. Your occupation/ position
3. Your cell/mobile phone number
4. Your marital.
5. Age.
With best wishes,
Derick Ahmed
HEADER:
Return-Path: | <raymond@tjzhjc.com> | |
X-YahooFilteredBulk: | 60.29.49.154 | |
Received-SPF: | temperror (encountered temporary error during SPF processing of domain of tjzhjc.com) | |
X-YMailISG: | EpdmWYgWLDvPLauZcS0wRXH_51JSUq9S5ZtFTcdmkowJeHd5 L.DVIcQV_CHHdlh4vTRZVnZQuLlCI8lzW2u_XiDSI7iv0vRZgStykfxABzi0 4.bBzTITCulzG8IqSr6B.nNYMXQGrI79irWOtTtd.Gvyrr8UkK47xg4hEsl5 kUtyXVEdppZbEO0joJTaycE2H5st2i8O2m9BaKVfeBJZAXLsJuiIc48rayXt LfcaSojRGR77MutLiGyX3h25yfDPBGzvdUYv7BoIRYbfpCNSaDCAtWKVgjPB 4TVPYe36yjDsz.snUDTbFouqUWpF5.OXQ.uHYmKJtLpgyMjffIs9dtsW_OQc .REHFzmbizv3aervzy.nnC5YjxGVbkIQlA6.yvR2yk0tGoL1bujXVCXEiXqQ aB8hyZw1PxMu6NhtQ0JDdzLjng6FkMVi3b8DESm7We8VfZ3GpTRv_BFZPZEc bvSvo6v8Umsj1D8kWvP4xGZyob3mgsu.DvqIDU3T7rI_sX7rSlZrRbgSl94k ZgD5xajvpHbZul.wGHip6CX6C9AyETsU2GJgNd8J7iMmabEnJo3neKfVDJ7B 7Jfps_Vhfb6Lslmo1B5sAtTE6MbEyNRuXcX9ZKQBuJlkmirPnDXFNARg.qiA UoUY31PPAC.ig5eT2oR8eyA.dP2SUV.lnGgG5lxCvUkAM1BpqKvHrzp.QYjV rzUU5keDRx7A01sImXoM7WZY77WNsiadM.7qIEsFZBk4sD.YQJZ0lc_tcTX_ yTOQNBtCiJElgLhFNykIKpLt8PhGQuVWTImzrNxLfzYKgA88wiuP4Ds.LjMm xhl1iXjs9JAT7fhKdmolgm_W5xJ2Wf6Bo7hpUb.GJLKgNFoWZ6HEV6lSRoAv ySff.yxW_FtOfSHsmmrARo0f2HmGJ1sjKFXfpRBE45YUmZ4Uyc06nyTswKUB kJp8G5U0xAwHyGQqjFcr9ag1jL_Yd.CQf3qgRkeU4Q7vPaJhoaIqiBZ4IX0S avrePSGg80Y5LK_aP_LWXyWo7g9XewYK0aau9Gxqhzcuvnz1p9nRDIZO.otN qBYU9v5Jiq8RNGfHPDgB0dKQJ14TNmg4TVdobRdWOUSqFZoC_YP.B4GLRwAq FDR8J22fh10GPud7e_orzxBDVwq0O2To4PQdHR5vRhVdSocAAwdKRVGBz9Is e2kTAL14SZH1hFEfv_fMELeklNKFdisWhUlzfToNqEyboYKUSkvZiJFQo1XX B001QVFObIC_5UKHDNA3Zh3fseiUdw.GAaLvPxs8Wc58iNODCBTHYcfg_Pfz h5REynzlAZpnRKUTOpMNiIYMQjhrWWziBwghx56W0wcdBwD2duoa2oxMxtay ex18oWxBp_o- | |
X-Originating-IP: | [60.29.49.154] | |
Authentication-Results: | mta1234.mail.ac4.yahoo.com from=tjzhjc.com; domainkeys=neutral (no sig); from=tjzhjc.com; dkim=neutral (no sig) | |
Received: | from 127.0.0.1 (EHLO mail.tjzhjc.com) (60.29.49.154) by mta1234.mail.ac4.yahoo.com with SMTP; Fri, 02 Nov 2012 12:47:27 -0700 | |
Authenticated-By: | raymond | |
X-SpamFilter-By: | BOX Solutions SpamTrap 5.21 with qID qA28Fir9010416, This message is released by code: ctauth0007 | |
Received: | from User (64-120-173-240.static.hostnoc.net[64.120.173.240](maybeforged)) (authenticated bits=0) by mail.tjzhjc.com (8.14.5/2.23/5.36) with ESMTP id qA28Fir9010416; Fri, 2 Nov 2012 16:15:50 +0800 | |
Message-Id: | <201211020815.qA28Fir9010416@mail.tjzhjc.com> | |
X-Authentication-Warning: | mail.tjzhjc.com: Host 64-120-173-240.static.hostnoc.net [64.120.173.240] (may be forged) claimed to be User | |
Reply-To: | <dmk150dmk@yahoo.co.jp> | |
From: |
“Derick Ahmed” <raymond@tjzhjc.com>
|
|
To: | you@yourdomain.co | |
Subject: | Can you supply for us? | |
Date: | Fri, 2 Nov 2012 04:16:03 -0400 | |
MIME-Version: | 1.0 | |
Content-Type: | text/plain; charset=”Windows-1251″ | |
Content-Transfer-Encoding: | 7bit | |
X-Priority: | 3 | |
X-MSMail-Priority: | Normal | |
X-Mailer: | Microsoft Outlook Express 6.00.2800.1081 | |
X-MimeOLE: | Produced By Microsoft MimeOLE V6.00.2800.1081 | |
Content-Length: | 1546 |
3.) RECEIVED ON 10/23/12 – EMPLOYMENT (PERSONAL ASSISTANT) SCAM
FROM: Jeffer Brett jeffery_brett@hotmail.com – RETURN-ADDRESS: jefferjeffery_brett@hotmail.com
EMAIL: Hello,
My Name is Jeffery Brett am glad to offer you this part time job offer.I am looking for someone who can handle my personal and business errands at his/her spare time. Someone who can offer me these services:Mail services: Receive my mails and drop them off at FedEx,Dhl,Ups(nothing illegal).Shop for Gifts,Sit for delivery( at your home) or pick items up at nearby post office at your convenience.I would love to meet up with you to talk about this job if you will like to work full time.But i am currently away to see my family.
I will prepay you in advance to do my shopping. I will also have my mails and packages forwarded to your address. If you will be unable to stay at your
house to get my mails, I can have it shipped to a post office near you and then you can pick it up at your convenience. When you get my mails/packages; you are required to mail them to where I want them mailed to. You don’t have to put money out of your pocket, all you have to do is have packages shipped to your house and do my shopping. You are allowed to open the packages to reveal its content.The content of the packages are computer and electronics, clothings business and personal letters. All expenses and taxes will be covered by me.. You will work between 15 to 20hrs a month. How much will you charge per month? I will pay $350. That is not a bad offer, is it?I need your service because I am constantly out of town. I work in real estate and I own an Art Gallery,Clothing and Electronics Store in Australia. I will return to US on 3OTH of this month the state.
I will email you the list and pictures of what to shop for when I am ready. No heavy packages is involved! You can do the shopping at Sears, Walmart, Bestbuy, Circuicity, Oldnavy and other stores. You will be shopping for Electronics and clothings.I will provide you my UPS, DHL, FEDEX account number for Shipping. All you have to do is provide my account number to UPS, DHL, FED EX and shipping charges will be applied into the account. I will provide clear set of instructions for each task I need done as well the funds to cover them. If i were to mail you money order to do my shopping plus upfront payment for your service, where would you want it mailed to? How should your name appear on the money order?..I will need the information below,
Application Form
First Name:
Last Name:
Address:
City:
State:
Zip code:
Cell Phone:
Age:
Gender:
Salary History:
Current Employer:
Possible Working Hours:
Please get back to me as soon as possible so that i can mail the payment out to you..NB: THE PAYMENT WILL COME INFORM OF MONEY ORDER CHECK or CERTIFIED
CHECK. Get back to me as soon as possible.
Jeffery Brett
HEADER:
Return-Path: | <jeffery_brett@hotmail.com> | |
X-YahooFilteredBulk: | 68.15.100.135 | |
Received-SPF: | softfail (transitioning domain of hotmail.com does not designate 68.15.100.135 as permitted sender) | |
X-YMailISG: | CxPfQjUWLDteUrYNT8VR_hAg_F53QzjzOq3KLmRmemHnWvXG Oa3I1uLQzEadGvMrIdzLT9ueVjEZ1lUmhkZz.jXYXG1RWllkx9gajD4X6XHQ onKcXjMDfVuwvkh80LIF1BSo.j0XyGOC9PGqiReoMApNqUhBKGrkwvm1ICzw c2qsq3P_Cl4hMdyBoKAa10eEw.aM_660Pe3vgGDOWF2lPEJlLQAfLLWmZ0xI yzwB7n7HMQqVaGx6BysFd8mnHmWfAl7wqW_W1JTzIh4xaPBL1Caxjrmx9B9n 24ewY4fXnv3P17.n5oXxBh98ObHY8VCVc10kzt1CCHzxr_C06LY.Kt_E4JmM q_DyEWIBvyiuFlfO4ml9zxO54_T6TZtdq3dB76o8oz.FY3.ph_WrmloQQcG6 bN6twEo75pe0tNFBjkb7p5sqG_Krw7qj2f.GfaL6MSzjZSQXWDI1bP1G67Ch PExP2V.1kqUY4Ksr5_uX5rbayNvO7lSieo5WIGOoTD5TFveRwPK1DMbXnpZ3 LkPvhmDztxj43I21WlPHkTCSb5AJrqA9QsRP.qGS_UTKZ9diFTeP4JD.ku2X Ei.Q5Id7HxmDBnWANjySdxUN6Gj_BrgczmqHYOMykebQxfIAwgdHXWMQKZdE OfpNgcwN24dvpgTH43rzGVJ5_I6LzZawI9adqilBkzO1C8Dxr9IkMOI.5hEC GKe3h10l4D30Ehqijcva.XF_ExUNb6g8dY5Mgg1ZEFWUk9WECBTsKY7M_Kqf rYsFZ8Nw8s1KbZLq_U3sxH.2X4uD_wYwwfkqtnPv3FsjwLoRnnhz9UOgnKRa wgFydy7UyhKJFnCYOhJ901464OaNGZf7f.cMkZHzZhIS189fq0XqDfbRLYnW i.JHZ469g33S5YJnM0mDR1_hUg5_xzmelxJhf6nAPSCOb_bNQadUZSVVhYyo FEKzrZrN.ED0NlA7J1fjPfxqPKFoInl4nyM7Tt_aqJ_aOTQyGZUVSecAIYRO LmbKAt9wDSIJNqI2NTPPP2MhDl8O8LbKsTZw.n8T2KFdl9SyiSvJ4UX9AxsR NocpUaqNzkcVCCZhW0c6hzvRL8oGaHCc4VV0aRzW7UNC7jxJnt2qP7W2ghas Lprd4n9eCFm5DuxvR059USoAUumwzCN9x_ArqfYkwK2J0nkOIlQuu.cDGkrH vRwgLwGLRFQrZiPKx1.ObOSVm.kYEQU8rvF7Sqakid15UbWl48xe1_Vk5Hpv 7QgnwfmVZul4bYanHTu_To7E2pV5zRzll.KFS6DpvOx5vdepYaPUA0vcYsbG 2ynGoUl1QMLCXcOx1SvTXK85SX5Zm8eHRNzXGNkIclXGgRsEUboDqQgPfdrB keuIuMs9Z0TLqqSJcoT3con91nNNJUBX3mihnWCIeLZVDXmSPs2ytuxgTV7m cgVvBPDZG6ntbZvrHzDXcbTwP1OThPCNMN9rHwYu7tOG2xN9csJHwhX4WPVn 4tQuM6cQ1g7HNyEH1cRpjg6h4EnPPcRdqtQ21CAyrSrUugE1pQzKtEGKMazW LE2Zh34Ea0sb8TREbjt0LoKUQg– | |
X-Originating-IP: | [68.15.100.135] | |
Authentication-Results: | mta1194.mail.mud.yahoo.com from=hotmail.com; domainkeys=neutral (no sig); from=hotmail.com; dkim=neutral (no sig) | |
Received: | from 127.0.0.1 (EHLO webmail.avl1.com) (68.15.100.135) by mta1194.mail.mud.yahoo.com with SMTP; Mon, 22 Oct 2012 19:37:36 -0700 | |
Received: | from User ([71.186.195.12] RDNS failed) by webmail.avl1.com with Microsoft SMTPSVC(6.0.3790.4675); Mon, 22 Oct 2012 17:05:15 -0500 | |
Reply-To: | <jefferjeffery_brett@hotmail.com> | |
From: |
“Jeffer Brett”<jeffery_brett@hotmail.com>
|
|
Subject: | ****PERSONAL ASSISTANT IS NEEDED**** | |
Date: | Mon, 22 Oct 2012 18:01:04 -0400 | |
MIME-Version: | 1.0 | |
Content-Type: | text/plain; charset=”Windows-1251″ | |
Content-Transfer-Encoding: | 7bit | |
X-Priority: | 3 | |
X-MSMail-Priority: | Normal | |
X-Mailer: | Microsoft Outlook Express 6.00.2600.0000 | |
X-MimeOLE: | Produced By Microsoft MimeOLE V6.00.2600.0000 | |
Bcc: | ||
Return-Path: | jeffery_brett@hotmail.com | |
Message-ID: | <AVL-S02E4D3MBhe3WYI0000012f@webmail.avl1.com> | |
X-OriginalArrivalTime: | 22 Oct 2012 22:05:15.0128 (UTC) FILETIME=[508D6780:01CDB0A1] | |
X-TM-AS-Product-Ver: | SMEX-8.6.0.1168-7.000.1014-19294.004 | |
X-TM-AS-Result: | No-2.712100-4.000000-31 | |
X-TM-AS-User-Approved-Sender: | No | |
X-TM-AS-User-Blocked-Sender: | No | |
Content-Length: | 2706 |
4.) RECEIVED ON: 10/22/12 – JOB (BABYSITTER NEEDED) SCAM –
How convient — I emailed Anthony Webb almost two months after he spammed my spam box and he is still ”looking for a sitter” — Yes his information is a little different now. Scammers like switching up info to avoid detection. I asked what area he is moving too (because he doesn’t no my exact location lol) and he put:
We are not sure of the area we would be visiting since we don’t have a nanny to take good care of her. Which part do you live (City & State)? Your decision will determine where we would be staying in your location, let us know if you can take care of her in your home.
Give me a BREAK! Anyways… He emailed me with new email addresses. Anthonywebb01@yahoo.com – IP 98.136.218.175
FROM: Anthony Webb paredese@comcast.net RETURN-ADDRESS: fredsam002@yahoo.com
EMAIL: Hello There,
Return-Path: | <paredese@comcast.net> | |
X-YahooFilteredBulk: | 76.96.30.16 | |
Received-SPF: | pass (domain of comcast.net designates 76.96.30.16 as permitted sender) | |
X-YMailISG: | w9HZbUMWLDugWjkkZVsrVFrnt7mKBiRe4Vhr7H2aTzOySAlE H.NzpX2wkMNQ8Xj0s4FKAxYIFHimUsvSofe8irt5SpLJ7kCl0.iPHB0hpVZQ IPbeCPGYVzBAoc.PP9Fa2oHu_OYnHo_mhgu3KaQX_T0_CawHUL68HxmmP.d_ iTGWv_HV8S6J6JbdhfT_IqYhegGBmGOOuOH9o5GRfktQkyKSWNRK7epWy3_T G5WFKshB16gNrwazp.rNmP5L5o0pdbGmReIwiO3VYkX7he1wY01ro8Rc9Cvb 62tUpBl_lz3XSkaJi4wugG8alvxGEqbNNIQPPtUGZ.Cj5ioe7TJHRwTdnhyk hC6p8ufx0zp2o.qNFGLvq98AEzhPrbAzP_1KHg_tcENK2C_fqoBovlX_ax49 u.hRrKNSHOZ8NVxcK4NJVcte1h5VmanH__Gw0HytHBATFWW6NBbSu3xo6nGb 3g6uev2THTULgp1qqRVNxDoku3cT_zFKRm5QpeKHDeGgVFg4tgPWOCV9zfxU AuItab8xCDC79PoEEVSYkQ37RRUiKmTJmBRjmN12yuaLaiXrowCeeNsUeims CsNvZu1ABwxNqEk45o2G2uBaQWXFSlEpziSd_1bN.s1JbyhYrgbJR9kOmrip rWOuLabniTTX8zvT2ZK.TNmeMrwGGzftEWGXSkAFGK1_HSSg9CDnHQ2SDQAd Vbl9zDkYxj_e0ujvB9d4IggGS41FJM_OZunV3xMWqd8LOJjnHYrsq3Nod.1_ RvGRf0FpugGJLA1hUByUD8iJMjaeogGZ.eRhwCU.6R8vtuzepaCXAkOSrWcK 75BXu80hjtCgz.Oh84A9yDZ_W7LFDbjzCuWb7zDUozaM5fe_klf2yvwjSpcS gpzH5AROIOBEQNRKhPAF.i5zIGfooLzo5xbcZ0vOQ1u0xAWZLt_erCUj2OPQ pRSvpdDh0FHvEf9FjBQyxePbToRxBktm0Ypx7BrPzJ0hVWFCiGqK01DclztT oeihGZaNU5CcPx0SjaCR7k6WlIEUmq7THpO8d4I_3UxoWrISske9RpParcah _pHDuPE.1iqvtVROeq22QKRgyhEQ_dc_9yC_dqiJ89DFfBhBpE37zltXxBj0 vh_qdKRop5SgL043x03wwUNmp3g.sM3sgatKFZxgBHvfB3uap6Whl3XgkbLY VN4- | |
X-Originating-IP: | [76.96.30.16] | |
Authentication-Results: | mta1284.mail.sk1.yahoo.com from=comcast.net; domainkeys=neutral (no sig); from=comcast.net; dkim=neutral (no sig) | |
Received: | from 127.0.0.1 (EHLO qmta01.emeryville.ca.mail.comcast.net) (76.96.30.16) by mta1284.mail.sk1.yahoo.com with SMTP; Mon, 22 Oct 2012 05:10:11 -0700 | |
Received: | from omta15.emeryville.ca.mail.comcast.net ([76.96.30.71]) by qmta01.emeryville.ca.mail.comcast.net with comcast id EBuy1k0051Y3wxoA1CAAvE; Mon, 22 Oct 2012 12:10:10 +0000 | |
Received: | from sz0115.ev.mail.comcast.net ([76.96.40.137]) by omta15.emeryville.ca.mail.comcast.net with comcast id ECAA1k0012xZMJ48bCAA20; Mon, 22 Oct 2012 12:10:10 +0000 | |
Date: | Mon, 22 Oct 2012 12:10:09 +0000 (UTC) | |
From: |
Anthony Webb <paredese@comcast.net>
|
|
To: | fredsam002@yahoo.com | |
Message-ID: | <1476744060.725012.1350907809979.JavaMail.root@sz0115a.emeryville.ca.mail.comcast.net> | |
Subject: | Babysitter/Nanny needed ASAP!!! | |
MIME-Version: | 1.0 | |
Content-Type: | multipart/alternative; boundary=”—-=_Part_725011_1665355573.1350907809978″ | |
X-Originating-IP: | [::ffff:197.177.153.97] | |
X-Mailer: | Zimbra 6.0.13_GA_2944 (ZimbraWebClient – SAF3 (Win)/6.0.13_GA_2944) | |
Content-Length: | 4584 |
197.177.153.97 – This IP address is considered 85% BAD on Reputation Authority and has been blacklisted and reported by other sites/internet-users. This isn’t the scammers actual IP location because scammers are little rats, they hide behind proxy servers, names, etc.
5.) RECEIVED ON: 10/17/12 – PHISHING ATTACK (HACKER) – SUNTRUST BANK SECURITY NOTIFICATION –
FROM: Suntrust Online onlinealerts7590@suntrustonline.com RETURN-ADDRESS: onlinealerts7590@suntrustonline.com
EMAIL: Dear Customer,
Suntrust is serving you better and has upgraded its Platform, Your Online account has been upgraded to Evl ssl 4 platform.
You are required to update your account online to enjoy this platform,
Some Slight Restrictions has been placed on your account due to old Platform
Please Upgrade your account information by
Downloading the attachment in this email to verify and gain immediate access to your account .
Regards Suntrust Bank
EMAIL CAME WITH AN ATTACHED FILE. I DID NOT POST IT HERE NOR DID I EVEN CLICK ON IT.
HEADER:
Return-Path: | <onlinealerts7590@suntrustonline.com> | |
X-YahooFilteredBulk: | 174.36.249.42 | |
Received-SPF: | fail (domain of suntrustonline.com does not designate 174.36.249.42 as permitted sender) | |
X-YMailISG: | g90TuMQWLDuGmnhuraNEC5oY0fuz8eBUD_paKMANXDzMZ8Y0 afBnB0VgKExPjsWYDgxoDWRBUNPL8lPmtrTJR4mcYPlc7HoDjdPMRxPM8F_c dYfPhO6ULuwR5qvbr.BZIzb1YWe2lyrJLhWSgGPRkmCbshEbI6yL0_3u3k8E VlSqP8rJQMO_XiV8BmUAYb5c0zQnEujmmKCd_l4vR5zB22mH0krLRxt7K5bd OLErS1J6kXCYgFSLlIYuGK5O5vZW5EZ_bZeNP9GPRXE3BXwND.KWagct7PY3 nYVh_VrdXEi5IcX9OX2h0VTe8ZxCtiLYvncC_GLKYQ_YmQ1JZNWtShkVEv8p PH68ASP6pSMm8pAZ9MDdtadL22P3abkPspAjW9B.BoI0sYBCt1lSD2DRtsgz LGSUL3etOocZLGMSUQUXkcaDa30HTfnONWDNwBx0pGGG_5rsxbjlSK2e8nRq VvKWOx0ucUhGG4J0_TspwnmVfCsWWoXmmNfg_b7hPBSF1.5PBIEVS.0ToQvY vcIK83GeixRfMv8N_8amLl3qB1cPsbcWpLnhB8TOE5WLGWuk6SuKsD6duam5 XnlHf6u_.Mh7thsKDUsBaAnBH2tPFbU82JWGhHc3AiTJ7Oq4v4F44qV5_CR1 EBw0mqqv_f2P4VphB0mNq8XhqSHyVdjzbCUdPqtnJ0jhYJ0O48m2dD_loJAt frEz4FvYWALMywnv4P.MB52tQaZlLAUhgbUlGoxoDZe90.ubGwrS.BgpiehP LNN3gBJlnN7ZwDuKnDgRA81BQ4gjoeXRe9T_qdE9ZiH79vepcwF93QsAmQe2 Zz7XaNc9d0zA56TE5Jx2TrpLuLCgF951U1egzsW9duTHYZpsTfdyO6Jg5wpO E3v8gnjRD1x008Q6HWNmEGqFmqgrSSd8087Iy8ILkytGWDLeIsHmOaEnsqvZ A.OB6EFfDuI5EAqchtaVfDYF5Cu_b1DIBowF7p9rcxRKlEuQ5I_0WVOPeAN7 F5_gFhV3H1ZvUdRbnrqOkD6GPQHatz0P124juy2ZoI3moOnDcw6GafeznyiK HdX8GVJcdGrq.eayZFyg9ki8mQn23hHW2aMqsWcDWVAb962QuSyhArVwkEY6 1eAzN23Sa1MlS8aYvQHE46dcdHiYDAbAg.9wBpaYRHxUEfoQD19P0wzAkGA1 _UPhoaEsHRct._CINkv2hmLC7uODbFUBeE98H.ZBaOFb4lMD4z4boRBTXCwQ 8Q8YaHSQ4Wg80ryDtMSAXX5DjzEDy1je3MFVcLoju9xGpfi_wavbm6Q.J3V0 3GffSNxftFiy_fQAczaHdJLS.VAmWo70GkKwSq4mu6mMS673i3EeA0RurXGW HKxaitRipHsQeJFj6QKx0bxa7WOqHmZtDOiXF4j_5eVVqGdx.PN4Nvrbj8RL baPCmOKymGrY8TSdTUf5FdnI69kbsrOginNsrzQso9I2trlQBwvazuGtG54H Em.NVw– | |
X-Originating-IP: | [174.36.249.42] | |
Authentication-Results: | mta1373.mail.gq1.yahoo.com from=suntrustonline.com; domainkeys=neutral (no sig); from=suntrustonline.com; dkim=neutral (no sig) | |
Received: | from 127.0.0.1 (EHLO server.idealpropertiesgroup.com) (174.36.249.42) by mta1373.mail.gq1.yahoo.com with SMTP; Fri, 19 Oct 2012 05:03:00 -0700 | |
Received: | from 66-168-52-170.static.mdsn.wi.charter.com ([66.168.52.170]:32903 helo=User) by server.idealpropertiesgroup.com with esmtpa (Exim 4.80) (envelope-from <onlinealerts7590@suntrustonline.com>) id 1TOVOh-0006p5-It; Wed, 17 Oct 2012 11:19:06 -0400 | |
From: |
“Suntrust Online”<onlinealerts7590@suntrustonline.com>
|
|
Subject: | Security Notification From Suntrust Bank | |
Date: | Wed, 17 Oct 2012 10:08:37 -0400 | |
MIME-Version: | 1.0 | |
Content-Type: | multipart/mixed; boundary=”—-=_NextPart_000_0068_01C2AA85.67F4DB90″ | |
X-Priority: | 3 | |
X-MSMail-Priority: | Normal | |
X-Mailer: | Microsoft Outlook Express 6.00.2800.1081 | |
X-MimeOLE: | Produced By Microsoft MimeOLE V6.00.2800.1081 | |
X-AntiAbuse: | This header was added to track abuse, please include it with any abuse report | |
X-AntiAbuse: | Primary Hostname – server.idealpropertiesgroup.com | |
X-AntiAbuse: | Original Domain – yahoo.com | |
X-AntiAbuse: | Originator/Caller UID/GID – [47 12] / [47 12] | |
X-AntiAbuse: | Sender Address Domain – suntrustonline.com | |
Content-Length: | 51721 |
174.36.249.42 – REVERSE DNS – hosting2.idealpropertiesgroup.com
Suntrust scammer received IP – 66.168.52.170 – is blacklisted and alerted on many websites including Project Honey Potwhere it is listed as a MAIL SERVER and DICTIONARY ATTACKER, below is a list of other phishing scams sent out by scammers using the same IP address
Messages Sent From 66.168.52.170 |
From: “NaturalViagra Provider” <cefudotei6175@charter.co Subject: Hi jdtamburrino, win a 80% discount. or |
From: “NaturalViagra Provider” <kiivavax9297@charter.com Subject: Hi highoctaneheskett, win a 80% discount. was trad |
From: “NaturalViagra Provider” <befudehal9500@charter.co Subject: Hi margrettyeamans, win a 80% discount. a Alves |
From: “NaturalViagra Provider” <hehucyuz2724@charter.com Subject: Hi margrettjrumburd, win a 80% discount. Public Br |
From: “NaturalViagra Provider” <omiuwym7179@charter.com> Subject: Hi wallace_z_vollenweider, win a 80% discount. Mad |
From: “NaturalViagra Provider” <pexoiv2035@charter.com> Subject: Hi constituency3953, win a 80% discount. This all |
From: “NaturalViagra Provider” <tumof1883@charter.com> Subject: Hi omega.a.suchan, win a 80% discount. Kg user of |
From: “SuperViagra Provider” <atevaa2678@charter.com> Subject: Hi isadora.tandy, we offer -70%. his only |
From: “SuperViagra Provider” <bewuv7282@charter.com> Subject: Hi marquitagerdsen, we offer -70%. aircraft Bangko |
From: “SuperViagra Provider” <uxutuka9392@charter.com> Subject: Hi charity_lantis, we offer -70%. It In |
From: “SuperViagra Provider” <ylukyukeg2821@charter.com> Subject: Hi brynn.roehrich, we offer -70%. Joseon In Astero |
From: “SuperViagra Provider” <bumenyxy6643@charter.com> Subject: Hi nunsnaval1969, we offer -70%. Empirical small o |
From: “TrustableViagra reseller” <ojyyyz8323@charter.com Subject: Hi ceciltraver, hits are chaper today. of |
From: “TrustableViagra reseller” <ywimafepo8592@charter. Subject: Hi illustriousburwinkel, hits are chaper today. ne |
From: “TrustableViagra reseller” <guyni2542@charter.com> Subject: Hi fkdecourley8, hits are chaper today. growing |
From: “TrustableViagra reseller” <yqesab1206@charter.com Subject: Hi erna_h_gochenour, hits are chaper today. once T |
From: “TrustableViagra reseller” <pahoza8298@charter.com Subject: Hi marilynn_k_tolosky, hits are chaper today. The |
From: “TrustableViagra reseller” <uqywece8818@charter.co Subject: Hi antionetteloots, hits are chaper today. Gold |
From: “TrustableViagra reseller” <ivixuxi9983@charter.co Subject: Hi clemmens4268, hits are chaper today. fraternity |
From: “TrustableViagra reseller” <iwywexibiy4689@charter Subject: Hi carolbalfour, hits are chaper today. immigratio |
From: “Cheap GenuineViagra” <ayxeekaxe4131@charter.com> Subject: Hi billi_hritz, get super prices. players Dino |
From: “Cheap GenuineViagra” <zugeealuo1504@charter.com> Subject: Hi billi_kuenzi, get super prices. The academies r |
From: Cheap GenuineViagra ysisigezul4424@charter.com Subject: Hi splatzer02, get super prices. end by |
From: Cheap GenuineViagra oxamyfo8640@charter.com Subject: Hi margart.blumenkrantz, get super prices. six far |
From: Cheap GenuineViagra uzaan3193@charter.com Subject: Hi marry.sgroi, get super prices. took many the wi |