RSS

Tag Archives: Free Promotion

“Microsoft Corporation”

WARNING – EMAIL SCAM / ADVANCE FEE FRAUD

scam-trap

Subject: You’ve Won!!!
From: “Microsoft Corporation” <bobfrench@cagroup.net>

Reference Number: YM35447XN/2013
Winning Number: YM02788ZM/2013

We are pleased to announce you as one of the five lucky winners in the 3rd-category of the Yahoo/Microsoft Windows & Windows Live Free-Award draw held on 11th of May 2013,in United Kingdom. All Five winning email addresses were selected through Computer ballot system without the winner applying or purchasing a Lottery Ticket, this is fully based on an electronic selection from over 50,000 companies and 2,000,000 individual email addresses of all the Yahoo/Microsoft Windows & Windows Live Subscribers from all over the world which consequently won you the huge sum of £3,000,000.00 GBP (Three Million Great British Pound) only.

Kindly contact the “Claims Manager” through email below with your Winning Number: YM02788ZM/2013, for verification and processing of your winning Cheque of (£3,000,000.00 GBP). We congratulate you for being one of the people selected.

(Details of the Claims Manager)
Claims Manager: Dr. Charles Morgan
Reply To: emailaward1381@yahoo.com.hk
Contact Telephone: +448-7123-40962
Thank you and accept my hearty congratulations once again!

Best Regards,
Microsoft Corporation.

Return-Path: <bobfrench@cagroup.net>
Received-SPF: none (domain of cagroup.net does not designate permitted sender hosts)
X-Originating-IP: [173.201.193.182]
Authentication-Results: mta1335.mail.bf1.yahoo.com from=cagroup.net; domainkeys=neutral (no sig); from=cagroup.net; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO p3plwbeout18-01.prod.phx3.secureserver.net) (173.201.193.182) by mta1335.mail.bf1.yahoo.com with SMTP; Sun, 12 May 2013 13:59:42 -0700
Received: from localhost ([173.201.193.245]) by p3plwbeout18-01.prod.phx3.secureserver.net with bizsmtp id b8zi1l00G5J8WZH018zit5; Sun, 12 May 2013 13:59:42 -0700
X-SID: b8zi1l00G5J8WZH01
Received: (qmail 16940 invoked by uid 99); 12 May 2013 20:59:42 -0000
X-Originating-IP: 173.255.139.12
User-Agent: Workspace Webmail 5.6.38
Message-Id: <20130512135939.04da1c3b48121d4af2a511fb1b29fce4.49320978e4.wbe@email18.secureserver.net>
From: “Microsoft Corporation” <bobfrench@cagroup.net>
Reply-To: “Microsoft Corporation” <emailaward1381@yahoo.com.hk>
Subject: You’ve Won!!!

Microsoft Corporation bobfrench@cagroup.net
emailaward1381@yahoo.com.hk
+44-8712340962

Advertisements
 
Leave a comment

Posted by on 05/12/2013 in Lottery Scam

 

Tags: , , , , , , , , , , , ,

“yahoo Inc”

WARNING: YAHOO LOTTERY SCAM – ADVANCE FEE FRAUD

UPDATE: Digging up information on this header and posting it in the search engine, for some reason, always brings me to another scammer I posted up weeks ago. ” Juliana Roman Medina ” with the email addresses julianar@pijaos.udea.edu.co <> fedexdeliverydesk@yahoo.cn IP’s used: 200.24.31.84 <> 41.138.172.174 (location Nigeria) — For more information on this scammer, who also sent a lottery scam and is believed to be the same scammer(s) as this post – Click here

NAME/EMAIL-ADDRESS:  Yahoo Inc <> ruthy_financial@yahoo.co.uk <> marystokesuk@gmail.com <>
EMAIL:
WINNING ALERT!!!
Yahoo  Awards Center
124 Stock port Road, Long sight,
Manchester M60 2DB – United Kingdom.
THIS IS FOR YOU!!!
This is to inform you that your email identity has emerged as one of the lucky winner of YAHOO ONLINE free promotion  of  GBP150,000.00  (ONE HUNDRED AND FIFTY THOUSAND GREAT BRITISH POUNDS STERLING ONLY ) for the just concluded online sweepstakes drawn in London recently.
In appreciation to yahoo,hotmail and gmail users! we gathered all the e-mail addresses of the people that are active online during during the draw and among the millions that subscribed to different email addresses and others through Electronic Balloting System (E.B.S) without the candidates applying for it .
PAYMENT OF PRIZE AND CLAIM
You are required to contact our Legal attorney in United Kingdom for representative.Barr Mrs. Mary Stokes
E-MAIL: marystokesuk@gmail.com
TEL: +447024038948
Your winners numbersYAH NO: 498876
DRAW TCK NO: 11098322
E-MAIL POSS: 234876
CATEGORY B: INDEX
SECRET WIN CODE: B32000Congratulations once again.

No virus found in this incoming message.
Checked by AVG – www.avg.com
HEADER: 
Return-Path: <ruthy_financial@yahoo.co.uk>
X-YahooFilteredBulk: 77.238.189.58
Received-SPF: none (domain of yahoo.co.uk does not designate permitted sender hosts)
X-YMailISG: NdS_pu4WLDsNaT3akZ7yPUDozjg1SwutxbxaG4luget.NmUV JAxEPSkjTsUOKhJCaMal.mbjPfmNWLyFXD7.TLbs2YZ5eIyLo.zeprF0yFcG x5vMaZZn05FfxxSba.amT2oGeuZ8SJbWx__ctHkvFOXJKz1fYjsW5RLt0XPH mkvc84ERic.I.V7q8sjMcRkk5BTrt_HFJTngvD0Jz78LiGAKqQU.CwHFLjF_ fCmmO5h.1LLfd.yDlMExYPz6GkeoiqTvJWvvP.SBgDUAm6PfjZak4gnQVUCf sLYWZf0tExv3bp42VphqsqjxZoAEmW4V0fhMYlHEYAJYjPyI3PWjGAbGkSVO vuRTxYFc3.NdAg1DdwtUzh0.xtA64dMzkn_1AfRWNsVECC1Hj4zX3lX8mpq1 aeltHMn5kL3ltEf66.pPp2fs0dyBpVZPzXaWSWH9LxX5JjiH3kS0nN6i2IS0 JTHXmRKtxkXpr8svfJpXQJLB.Fw1l1WYg8MR0y16187p3RSxcR8g.8iPjITg DqO9cm542tUZqnB8eselzVISzwJ7NQKHHpZ1ofSgowc8tehzjb8JszLH2QpE YidhUsXq_JS3lcH0r5X0dx52yLsUv0_Fjy7XvoSXtkv7phso2SOgHwV00iBq qKdi1Vj6OJQdnyUZyAmw.OPqB5poJp_s9p1TQm5tJuRCRksZW2QplD9O35bJ cb6QVwPsKnpTW59y.Y8pi8l2Y5Kw2UWCniZSb1I.Qom7dhoPZ4j_igAAUdIS R_j4.cDW.AR6upgTImY8zaWXAHXhPQZ2AR1ySBg9ha5WZIn6MnmDULjwndxt m0_oFyouUpz5tB4gFXNdp6p8sERAFKMXUfTW72M4oFXAqvWLnbb_S4td2jFq IHAHiGLurlu8OKNG3cddt4A6DBKOrvQZD3lRsXBSftJ8Qw0UNCYmHucneREn WDLmW3vthoLoes7_1LesMlHF2tBw6Vn7Bp7DXl1iiUBbs_kia5EugPumZ6pH rslpq7qR2LfYUoy2BHr7giAFXBoOgzhIJtDJ.Z.rClmM0jMahpESa.FpKzWx yA3tdHNkmVkxBAv6sSjEwAI26Lin92B8IrF2FJoIYAdsGdOz5yiO7yt03sqg ULk57hm94aSyYxqXrOQRsTp2meZgCDOyXI8WCnkdjz2pgdC9Et5M0TObolE7 KW8KmgGNz3oOpwkWbhwekiTRDeNrl4q9BDsnE0nUMcStPwTbb3khwcPlXHIM OTFXwn1ri0HpplotgDk6Ikkf_7PFRSmYzbtGIbp9RtXKaKnloZbI0mEXaYu6 v_5kwAdsNizWUoKrjkUWzGU7DJABRHjpN5UdrXfD3AKS00aoYFBi23Qh3LtP 9eoYgSWyi0.ALKIlExRcq76mMqA-
X-Originating-IP: [77.238.189.58]
Authentication-Results: mta1076.mail.gq1.yahoo.com from=yahoo.co.uk; domainkeys=pass (ok); from=yahoo.co.uk; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO nm1.bullet.mail.ird.yahoo.com) (77.238.189.58) by mta1076.mail.gq1.yahoo.com with SMTP; Mon, 19 Nov 2012 04:13:05 -0800
Received: from [212.82.105.244] by nm1.bullet.mail.ird.yahoo.com with NNFMP; 19 Nov 2012 12:13:02 -0000
Received: from [212.82.108.123] by tm16.bullet.mail.ird.yahoo.com with NNFMP; 19 Nov 2012 12:13:01 -0000
Received: from [127.0.0.1] by omp1032.mail.ird.yahoo.com with NNFMP; 19 Nov 2012 12:13:01 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 927814.13983.bm@omp1032.mail.ird.yahoo.com
Received: (qmail 51996 invoked by uid 60001); 19 Nov 2012 12:13:01 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.co.uk; s=s1024; t=1353327181; bh=iA41e3cptztcs4OfqEqg3P1UU05elM2wHBJidEewk4I=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Content-Type; b=BA0V/lvNb3g8ICmqCmJPbBUDMASq3g7dO9gYsGBxwvNiQfiJmdMmYdtfretP62Y3YdscvpQaL39vLARuPlXvN99RIZLN0s0gVefV8goLjAhV7ELbNIaUrPuAjvE4BvIbcgvuf9zMo1LnYv95FX9O5zgHofwxOTYtFOfiVy5uCaw=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.co.uk; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Content-Type; b=epvk28xWMC/n2L61OGw1a7wjmcirfFCQnXq9wxXrH+mT3HsPQ5dT6BjQdZywvoxVeHdU6StErnnbkFa5TuOf6e0WM+03jfkrprNKUIu3S3UIzeHVWQWWpt2GVyqgGtLdOVSdOpIeVPvXhmwpZMw+17LzolAjKfNQhLjniuulqbc=;
X-YMail-OSG: 6ok6V18VM1miJbWwZPtPmm8sgOI_RgxNr1NGtFmHZw90Mvv 6D7Q-
Received: from [193.164.133.72] by web29802.mail.ird.yahoo.com via HTTP; Mon, 19 Nov 2012 12:13:00 GMT
X-Mailer: YahooMailClassic/15.0.8 YahooMailWebService/0.8.123.460
Message-ID: <1353327180.51095.YahooMailClassic@web29802.mail.ird.yahoo.com>
Date: Mon, 19 Nov 2012 12:13:00 +0000 (GMT)
From: yahoo Inc <ruthy_financial@yahoo.co.uk>
Subject: “”””” Winning Alert ,from Yahoo Inc! ( Check your mail you have a massage)”””””””””””
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=”478945831-1873120208-1353327180=:51095″
Content-Length: 23720

UPDATE: My email server detected viruses from this incoming email received from ‘ Mary Stokes ‘ .. A link was also detected (us.i1(dot)yimg(dot)com/us/yimg(slash)com/i/us/nt/ma/ma-mail-cl_1(dot)g=)

______________________________

The below header is also Mary Stokes scammer pretending to be FBI office in an inheritance scam. Email addresses used: barristernecter@yahoo.fr – REPLY-TO-ADDRESS: offilcefile1905@superposta.com – – – This Nigerian scammer is blacklisted on multiple websites and has been reported under multiple fake addresses.  Click here for more information on this inheritance scam

X-Originating-IP: [203.188.201.151]
Authentication-Results: mta1091.mail.ac4.yahoo.com from=superposta.com; domainkeys=neutral (no sig); from=yahoo.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO nm13-vm5.bullet.mail.tp2.yahoo.com) (203.188.201.151) by mta1091.mail.ac4.yahoo.com with SMTP; Sat, 17 Nov 2012 02:43:59 -0800
Received: from [203.188.200.142] by nm13.bullet.mail.tp2.yahoo.com with NNFMP; 17 Nov 2012 10:43:55 -0000
Received: from [202.165.102.48] by tm4.bullet.mail.tp2.yahoo.com with NNFMP; 17 Nov 2012 10:43:55 -0000
Received: from [127.0.0.1] by omp102.mail.cnb.yahoo.com with NNFMP; 17 Nov 2012 10:43:54 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 977911.45325.bm@omp102.mail.cnb.yahoo.com
Received: (qmail 39060 invoked by uid 60001); 17 Nov 2012 10:43:54 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1353149034; bh=4NHRjGox1llxlGTpuwwzaXz2wAEyMSFQlVe/RepWfVQ=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-RocketYMMF:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=P0DhZFg9Mjj05/vqaDc0igv+GPAlNxBBckhxEzU4PJ/OEqkdNXv8cHYOGIrX06GRSxiYBDEXksxF+7O6itMLQryiu63e3X/TBdnGMXPpsJmwW89Nu0b5IpbVDCyBNfuzLVNzU62iHNFjxppWoL8m/2ohhLEweTQDE86CwjMFUjc=
X-YMail-OSG: UNddAlUVM1kvGGStE1FY34uiMeKn2clDYRgV8R.tDHiC3Gd LJa0arT0C
Received: from [41.223.248.96] by web92408.mail.cnh.yahoo.com via HTTP; Sat, 17 Nov 2012 18:43:53 CST
X-Mailer: YahooMailClassic/15.0.8 YahooMailWebService/0.8.123.460
Message-ID: <1353149033.34956.YahooMailClassic@web92408.mail.cnh.yahoo.com>
Date: Sat, 17 Nov 2012 18:43:53 +0800 (CST)
From:
FBI OFFICE <offilcefile1905@superposta.com>
Reply-To: barristernecter@yahoo.fr
Subject: YOUR ATM MASTER CARD OF 1.5MILLION

The names, email addresses, IPs/host names below are sent out by Nigerian scammers using the same host/DNS/ETC as ‘ Mary Stokes ‘ pretending to be the Yahoo inc lottery personal above. If you’ve googled any of the information you see here, it’s a SCAM!

Received: from nm19-vm0.bullet.mail.ird.yahoo.com ([77.238.189.92])
  Tue, 18 Sep 2012 15:25:17 -0700
Received: from [212.82.105.245] by nm19.bullet.mail.ird.yahoo.com with NNFMP;
farid_abdul01
41.203.225.136 by web29802.mail.ird.yahoo.com
82.10.220.112 by web29802.mail.ird.yahoo.com
41.138.109.92 (same host as the ones above.)
82.227.153.207 by web29802.mail.ird.yahoo.com
80.87.92.58 by web29802.mail.ird.yahoo.com
laura_deng@yahoo.com
184.171.165.50 by web29803.mail.ird.yahoo.com
d.kabori@live.fr
Dericah Riceh  dericah_rice5@yahoo.fr
jose_riceh@hotmail.com 
41.138.89.38 by web29802.mail.ird.yahoo.com
41.190.88.206 by web29802.mail.ird.yahoo.com

 18 Sep 2012 22:25:16 -0000
Received: from [212.82.108.252] by tm17.bullet.mail.ird.yahoo.com with NNFMP;

847439.61289.bm@omp1017.mail.ird.yahoo.com
 

Tags: , , , , , , , , , , , , , , , , , , , , , , , , , ,

 
%d bloggers like this: