Wednesday, August 23, 2017

Antonin (Military Scam)

I am Sgt Antonin Andel, i have a project for you.

Email analysis :

NOTE : antonin.andel@outlook.fr
NOTE : postmaster@spamwall.quilmes.gov.ar
NOTE : designates 190.120.191.6 as permitted sender)
NOTE : client-ip=190.120.191.6;


NOTE : Received : from [192.168.0.100] (unknown [43.240.7.127])

Bonjour (Arnaque financement)

Bonjour,

Par respect, êtes-vous en besoin de financement ? Si oui, je vous expliquerai plus en détails dans mon prochain mail.

A vous lire,

Linette TROST

Email analysis :

NOTE : sperandeosnc@tin.it
NOTE : linette.trost@gmail.com
NOTE : X-Originating-Ip : 41.138.89.213:49283


NOTE : sperandeosnc@tin.it designates 212.216.176.195
NOTE : as permitted sender) client-ip=212.216.176.195;

Your response is highly appreciated!!

Hello ,

I am specifically contacting you in respect of a business proposal that I have for you as you appear very relevant in the proposal.

Please kindly reply back to me for further details.

Waiting to hear from you.

Regards,

Mr.Adams Salem

Email analysis :

NOTE : mradamssalem@mail.ru
NOTE : do.tapia@centrosur.gob.ec
NOTE : Received : from DESKTOP-THKGO5T.localdomain
NOTE : (unknown [169.159.126.174])


NOTE : by mail.iniciativa.cat (Postfix)

PRIVATE....

I am seeking your assistance in helping me receive a large amount of money and in giving a clear research and feasibility study on areas I could invest on. If you are interested then kindly send your feedback to this mailbox: mrmichealwuu14@yahoo.com.hk

Regards,
Micheal Wu

Email analysis :

NOTE : mrmichealwuu14@yahoo.com.hk
NOTE : drmartens.trinoma@cln.com.ph
NOTE : Received : from [74.208.131.168]
NOTE : (unknown [74.208.131.168])


NOTE : by mail.cln.com.ph (Postfix)

how are you doing my dear,

i have a personal reason of writing you now.write to me ok

Email analysis :

NOTE : davidmiller5113@gmail.com
NOTE : michael.un@yahoo.com
NOTE : Content-Type : text/plain; charset="UTF-8"
NOTE : 209.85.220.65 as permitted sender

Tuesday, August 22, 2017

This page was sent to you by Mr Jason Drew from CAHHALL MORTGAGE (Email Leak)

Mr Jason Drew from CAHHALL MORTGAGE I WANT YOU TO KNOW THAT WE ARE CURRENTLY GIVING OUT LOANS AT 3 INTEREST RATEAPPL NOW AND BE FINANCIALLY STABLED EMAIL CASHHALLORGGMAILCOM would like to let you know about his interesting page. Please click on the following link to view the page:

http://www.jnj.ch/en/careers/candidate-info-center.html

Johnson & Johnson AG

--------------------------

Johnson & Johnson AG
Rotzenbühlstrasse 55
CH – 8957 Spreitenbach

Tel. +41 56 417 33 33
Fax +41 56 417 35 00

Email analysis :

NOTE : CASHHALL.ORG@GMAIL.COM
NOTE : X-Php-Originating-Script : 1001:SimpleMailInvoker.php
NOTE : 148.251.83.5 (bplusd01.bplusd-interactive.de)


NOTE : Received : from cilag by jnj33.bplusd-interactive.de with local (Exim 4.82)

Email leak (504 emails) :

juve-ad@hotmail.com, cmbusi_sas@hotmail.com, mastermindbp@yahoo.com, dcarsurfgurl72@yahoo.com, kevinmj4@gmail.com, c3craske@hotmail.co.uk, jlluent@gmail.com, jerryl5511@aol.com, jjoseclararivera@gmail.com, ps3@live.com, mariza1987@gmail.com, yaonalejandro@yahoo.com, amotemarco@hotmail.com, jtennyson9@aol.com, dalmar_1995@hotmail.com, parthsoni_786@yahoo.com, chabelita85_1@yahoo.com, ferrary1970@hotmail.com, garcia.lais@gmail.com, britneybrit@msn.com, zacatac26@yahoo.com, gricelia_05@hotmail.com, imister2@hotmail.com, flor.i.94@hotmail.com, eriniboyd@gmail.com, legocow123@gmail.com, rosemarypena45@gmail.com, fakhir02@hotmail.com, rcrogers61@hotmail.com, jessicaryanwalker@gmail.com, hoangthangknh08@gmail.com, budhachic@hotmail.com, pelusina_73@hotmail.com, krystacoggin@hotmail.com, kenmasse@hotmail.com, herewearenow@hotmail.com, tylerlamlam@gmail.com, vananh_666@yahoo.com, pcermak@gmail.com, md1925@gmail.com, dennyp4work@gmail.com, pareja953@gmail.com, peggypotvin27@hotmail.com, st ring_4all@hotmail.com, weider.mcf@hotmail.com, nia_sya07@yahoo.com, orelie_meffe@hotmail.com, rohit_karanth@yahoo.com, umair.ikhlaq@yahoo.com, jordanstreeter9@gmail.com, mano_barbiedoll@hotmail.com, enos_enoc@yahoo.com, scottslaten@hotmail.com, aod2545@hotmail.com, n-hamdan2008@hotmail.com, adobe.yumos@hotmail.com, nicolo.defelice99@yahoo.com, agsfly1@gmail.com, unikcontent@gmail.com, acisternas50@hotmail.com, anairda_iaras@hotmail.com, lisiming714@gmail.com, terrencenurse@gmail.com, linam_amaya@hotmail.com, pedrito_96_07@hotmail.com, thisandthat100@gmail.com, lhighshaw@gmail.com, lakers_49ers@hotmail.com, slim-chic@live.com, miguel.852456@hotmail.com, alondriz_24@hotmail.com, hsfolck@hotmail.com, sol_veras_03@hotmail.com, thirumalaivkp@gmail.com, poloo_714@hotmail.com, mrcrusher236@gmail.com, chavanketki@yahoo.com, critii.mca@hotmail.com, marsjoan@msn.com, andresleoflorez@gmail.com, sierra.sonier@yahoo.com, nelsonmyc@hotmail.com, twochixlogistics@yahoo.com, sis_k0403@yahoo.com, edn a14426@hotmail.com, kybosports@gmail.com, cahmilla_rsfr@hotmail.com, kimberlybolden2011@gmail.com, zachthomas1207@gmail.com, kpxaznjung86@hotmail.com, smiku294@gmail.com, om3r4nn@hotmail.com, loveaddict_vs@hotmail.com, minaei.1981@gmail.com, shijukakkara@gmail.com, bigbrotheril@hotmail.com, rakesh.flair@gmail.com, n-eil_17@hotmail.com, margaretwhiting@hotmail.com, charudatta09@gmail.com, rahimbo@hotmail.com, rocio.munoz1996@gmail.com, nplessjensen2@googlemail.com, louisdung9x@gmail.com, zorachan99@gmail.com, princess_hermioninne@hotmail.com, sarahireland97@hotmail.com, gian_al_92@hotmail.com, beavolin1048@hotmail.co.uk, qyeb_boy@yahoo.com, smihtuncay06@hotmail.com, luciana_mp@hotmail.com, sundarbiswas@yahoo.co.in, jd_2274@yahoo.com, tom.shockman@gmail.com, marciobezerramarketeiro@hotmail.com, fabian260398@hotmail.com, mexicali_rap@hotmail.com, upsman132@yahoo.com, pao.r.r@hotmail.com, blankpeter58@yahoo.com, sucrylhas@hotmail.com, adri00@hotmail.com, workmncomp@aol.com, roland.mijar es@yahoo.com, guilhermegrandchase@hotmail.com, patel.vatsal16@yahoo.com, ebeville63@yahoo.com, baagiicccp@yahoo.com, huangzemin96@gmail.com, el_poeta_isaac@hotmail.com, johan-082010@hotmail.com, faikar.azim@yahoo.com, antopom@hotmail.com, emanbutt92@yahoo.com, aimstr8@gmail.com, ege_35-2@hotmail.com, andi.jagsch@gmail.com, amymear@gmail.com, mm66282@gmail.com, esirtgen@gmail.com, pysycutzapysy19@yahoo.com, fx_ym@yahoo.com, aryanblitar@yahoo.com, therciopbtjg@hotmail.com, ashleycat83@yahoo.com, calatayudweb1@gmail.com, thexikito-grone@hotmail.com, gideon.iii@gmail.com, loka-ariele@hotmail.com, danielle.gilopes@hotmail.com, disahign.estudio@gmail.com, craftdinner007@hotmail.com, bamf5285@gmail.com, demente.angl@hotmail.com, gaikwad71suraj@gmail.com, fifthmouse@gmail.com, gente.educada@gmail.com, angelicajoycortez@gmail.com, anhviet1505@gmail.com, danielhglendinning@gmail.com, choll.pu@gmail.com, timber_rat@yahoo.com, up2you26@live.com, abdulbasit.khidir@gmail.com, adamfarago@hotmail.c om, polciar@gmail.com, le.thanhhuyen1987@gmail.com, chrstphrwrght3@gmail.com, mlevex@gmail.com, dipti.gorecha@gmail.com, erictaro8@hotmail.com, kinder_teo@yahoo.com, ng1390@gmail.com, roman9686@gmail.com, thescotts108@gmail.com, muki_k1@hotmail.com, l.natasha.hay@gmail.com, arreokim@yahoo.com, sense_lu@hotmail.com, sweety.bangera@gmail.com, yulicarbb@hotmail.com, gildanasengoku@hotmail.com, mikafalck@yahoo.com, mennaabouzeid@gmail.com, ash3229@hotmail.com, revoloutionzz@gmail.com, cantrelljohn32@yahoo.com, kaylyn_armybrat@yahoo.com, amorimpt@gmail.com, cr7327@hotmail.com, tai_suke@hotmail.com, theguv86@gmail.com, peace_luvzed08@yahoo.com, ostpizzan@gmail.com, heeradevishairulla@gmail.com, tominespatrick@yahoo.com, mateen_sher@hotmail.com, tavo-3111@hotmail.com, deboradesigns@hotmail.com, guilherme609@yahoo.com, heathhgrayson@gmail.com, oshiris727@hotmail.com, gcpaprion@hotmail.com, egedirenc@gmail.com, francisco_valdi_718@hotmail.com, cara.sings@hotmail.com, freemugs@gmail.com, brad y_lyman77@hotmail.com, alys_start_6@hotmail.com, connor_sutherland@hotmail.com, lisa_orsini@hotmail.com, ole1047@msn.com, sailingsylke@hotmail.com, anthony_c_hill@hotmail.com, akrossen@msn.com, lyncht118@gmail.com, adellisarazu@yahoo.com, sqc1834@hotmail.com, akabueze99@yahoo.com, danydvc_231189@hotmail.com, smarte56@hotmail.com, pequetello@hotmail.com, emir_han1235@hotmail.com, llddrr@hotmail.co.uk, norkow@gmail.com, imperial_majesty2002@yahoo.com, ashley.j.keen@gmail.com, fhdesign@mindspring.com, thomas.trucks@us.army.mil, pgmhs@optonline.net, admin@globalinternetcorp.com, tejana@email.com, keith@newformula.org, andreas@freq.com, paris75@prisedevue.com, sam.gallina@ngc.com, vlad@e2creativegroup.com, howard.womboldt@pega.com, gpike@houston.rr.com, tlinn@npark.com, johngrantham@sbcglobal.net, stanfl@earthlink.net, akira@vcube.com, saudjawed@yhaoo.co.in, jdrouin@telus.net, davidwigington@sbcglobal.net, theberge.francis@uqam.ca, juan@calvillophoto.com, harold.lloyd@lloydcontrols.com, emil@beumers.org, colins@symmen.com.au, bigfella@dsl.pipex.com, info@digipictools.com, ruault@csnsm.in2p3.fr, jari.hannukainen@elisa.net, tgarrita@iupui.edu, sdfalk@telus.net, kp4bjd@direcway.com, sancho_panza@acampos.net, macromedia@squarewithin.com, nanou1@neuf.fr, info@bjbox.com, pb9000@comcast.net, billsmith@mmcd.biz, michael@strickslpgas.com, prairiefire@earthlink.net, ewestjohn@aug.edu, nicole@kierainedesign.com, bredvig@email.dk, dnadvornick@cox.net, johnmo@austin.utexas.edu, tony@imaker.ca, aaron.packard@usd.edu, rob@wehmeierphoto.com, diane@eoir.com, rpearsal@paulbunyan.net, nullmail@ooda.airpost.net, curry17@comcast.net, pubnb@videotron.ca, mikerodriguez@comcast.net, rogerwilson74@btopenworld.com, zibbi@zibbi.com, hvejle@post.tele.dk, utbeliever@soon.com, algane@algane.fr, jevanr@rediffmail.com, tim@swellpictures.com, john.warner@rrd.com, mindstream@btinternet.com, lgcmjw@ameritech.net, charleymeyer@earthlink.net, karolina.julia@poczta.onet.pl, john@seoft.com, syed@yorkc.c om, nokoston@nokoston.com, alexva@telusplanet.net, stills@matlock.com, rysiek@um.bielsko.pl, mail@rickrussie.com, cjones@chrisjonesstudios.com, babrams@v-tek.com, naf6@ix.netcom.com, deepforest@mindspring.com, occe3@spray.se, adobe@yorn.niroj.com, domifer@optonline.net, dicktracy@gmx.li, osalord@club-internet.fr, joeoutlaw@outlawproductions.com, speckschwarte@operamail.com, pcox@mlgw.org, tim.richard@crawfordmh.org, maronoff@littlepeople.net, lefeuvrest@wanadoo.fr, keving@dockwalker.com, bci2oo5@mailinator.com, tomekrossa@cox.net, adobe@versionke.com, danmc@jps.net, maria@frozenreflections.com, junk@de-online.co.uk, kronholm@mail.dk, fotografie@wilfriedoverwater.nl, johanna.markkanen@vti.fi, look@tyleryoungcreated.com, frenchspud@earthlink.net, hally166@mail.com, napoleon.1er@laposte.net, emig@infograu.com, arthur@costerus.eu, dannyf@summer.com, spieler@matrixstructural.com, mark.whitwham@btopenworld.com, macromedia@hpgx.net, mgravel@cox.net, carole.galassi@ucop.edu, scott@smith-nel son.com, schrody@fastmail.fm, wemarsh@comcast.net, jbrown@laphamsquarterly.org, rv.giovanelli@wanadoo.fr, r.houtum@home.nl, john@liz.lu, arjgolf@mindspring.com, tgarbutt@xplornet.com, roland.hoskins@virgin.net, kevin@kevinwickphotography.com, adam@adamangel.com, bbeazely@comcast.net, jean-louis.salvignol@wanadoo.fr, clifford.johansen@telia.com, gareth@woolridge.org.uk, mfgordon4@comcast.net, emusic@pobox.com, charcot@comcast.net, msaylor@adiginfo.com, sabloom@ufl.edu, rtweten@twetensphotography.com, lowell@sbcc.edu, glen@glenalmond.us, guru@mail.maclaunch.com, mail@andybarton.com, macromedia@lostinfo.com, admin@moissat.net, jhjunk@earthlink.net, adobe@vejce.com, don1@by-print.com, ray@fajita.net, whalli1@comcast.net, info@tonymayimages.com, folbert.boersma@12move.nl, wpaley@ix.netcom.com, bob@pixel-gym.com, shawnlierow@davidbowie.com, nhelm@nmu.edu, ncavalli@ryerson.ca, hurtig@vardgarden.se, david.sharp@autoexoposure.co.uk, adobe@nplawes.com, jaime@studiomio.com, diane.trentini@opti mation.us, younisse@greatbooks.org, daho@socal.rr.com, klicrobert@insightbb.com, bour.cy@caramail.fr, catephoto@cox.net, duane@aspenpress.com, nicke.jonsson@home.se, sgorham@hccfl.edu, benj@jabbawok.net, magohe18@ono.com, niels.christophersen@get2net.dk, rampel@bezeqint.net, justinp@thefamilychurch.net, usmetz@optonline.net, terje.storksen@h-avis.no, biosim@netbox.com, blivsupport@macktez.com, conrad@planept.com, xx_baybee_ash_xx@rangers.co.uk, david@davidgunter.com, eeeeeee@eeee.com, jojo_wong8738@yahoo.com.hk, 3424@hotmail.se, reguieg.fouad@caramail.com, info@phpbackend.com, naren320271@rediffmail.com, macromedia.com@freexxx.dyndns.org, 033255235@yahoo.com.tw, dcooper288@comcast.net, matthackney@kewsoft.com, gary-yamaha@hotmaill.co.uk, adobe@web.knobby.ws, efbertram@mail.com, janssens.vranckx@telenet.be, david.laborde@adidasus.com, oskar.lindell@home.se, jackshit@rogers.com, photo@lacerdas.com, dmalatesta@praxisoft.com, sky33940@skynet.be, amenblue@earthlink.net, ionut.vlad@rdslin k.ro, ervf@sbcglobal.net, mail@graphicsarena.com, josh.willis@hp.com, fnpjf@uaf.edu, mario@mariotoscani.com, boochon@skynet.be, colek@seznam.cz, wayratze@optonline.net, vipinvenu@poornam.com, cgood34@sbcglobal.net, tdhoss@yaoo.com, david@schooleyweb.com, me53@privacy.net, tomquinlan@charter.net, markgqs@erols.com, info@ceatrus.nl, efischer@phillyburbs.com, pete@endoran.com, darkpath@optonline.net, opr@opr1700.com, chris@primesolid.com, arush@bryant.edu, kaminski.172@osu.edu, bernards@tnt21.com, krismoore@comcast.net, muncher@eatbeef.com, ray_hewitt@btinternet.com, ljhpain1@tiscali.co.uk, alepacheco@itelcel.com, simon.kavanagh@btinternet.com, bloostater@comcast.net, woutyo@quicknet.nl, silvanal@optusnet.com.au, chris@portjeff.net, ews@evanwinslowsmith.com, dbtale@netscape.net, josuealcantara@prodigy.net.mx, post@thoirs.com, clee@ibahn.com, jtwms@triad.rr.com, stephen.green@computerland.co.nz, jason@bluemtnphoto.com, slehmann@sldnet.com, fmorales@htexas.com, sime n@fangel.no, wenk@stillsman.com, wally55@j-wave.net, ebelenski@optonline.net, wouter@d-block.nl, peterleyenaar@netscape.ca, info@upaphoto.com, hackie@prohost.org, bh@epilog.com, jonathan@kerstingarchitecture.com, pascal@fuelindustries.com, didier.eyer@wanadoo.fr, jdyrek@desertlightmedia.com, ehbds@gd.nl, benb@abcwarehouse.com, audiovideo.antibes@neuf.fr, ryan.s.russell@comcast.net, florent.parent@beon.ca, spencer@shepler.org, ville.salmi@helsinkilainen.com, fssfs@fdsf.sfds, j_azaceta@telefonica.net, jamthorpe@bellsouth.net, gryff2@wanadoo.fr, toto@zeriotzeri.com, iamb@razzolink.com, juitwijk@tiscali.nl, chagen@thepolicygroup.com, management@itonet-world.nl, pmanuel@bordernet.com.au, jo.pauwels@pandora.be

Saturday, August 19, 2017

BARCLAY,S BANK PLC,UK ( Scam )

KJHGFDDFGHJKLKJHGF
BARCLAY,S BANK PLC,UK
1 Churchill Place,
London, E14 5HP
Tel: (352) 437-8240
From The Desk Of:
Mr. Jimmy Johnson
Email(justiciaclient@gmail.com)

Attention,

I am Mr. Jimmy Johnson from Barclays Bank PLC,UK. we had just formed a new forum which is the newly inaugurated World Debt Recovery committee (WDRC). My committee has a mandate to recover unpaid debts associated with NNPC contracts, Lottery fund, inheritance fund, loans and grants etc ranging from $1M-$95.5M owed to various beneficiaries and companies across the globe (Asia, Europe, USA, Africa, and Australia) and submit the list of the unpaid beneficiaries/companies to the 2 appointed official paying Banks for immediate payment of the fund. In the course of our investigation, your email address/particulars were shortlisted among the first fifteen individuals yet to be paid hence this email. However, we received a petition today from one Mrs. Christina Morgan that you are dead. According to her, you died in a plane crash as such your fund should be paid to her as the apparent heir. She has also submitted her Bank account with Bank of America for the transfer of the fund to her. To avoid undue delay or paying the fund to wrong individual/beneficiary, we have decided to contact you for confirmation. If we fail to hear from you after 72 hours, it will be assumed that the petition of Mrs. Morgan is true and the fund will be paid to her without further delay. Therefore, We would like you to choose below your choice of fund transfer:

(A) Bank Transfer/Online Banking
(B) Certified Bank Draft/Cheque
(C) ATM Card
(D) Consignment

Your full personal information is also required as below which will be needed for the transfer of your fund.

(A) Full name and residential address
(B) Next of kin
(C) Occupation
(D) Nationality
(E) Bank Account Information
(F) Telephone numbers
(G) Scan the first page of your international passport or drivers license, recent passport photograph, send all via email attachment.

Email(justiciaclient@gmail.com)

Your urgent response is always required because you have a limited time to execute this fund. be free to call us any time for more information.

Sincerely Yours
Mr. Jimmy Johnson

Email analysis :

NOTE : client-ip=92.61.41.40;


NOTE : X-Originator-Ip : 41.86.234.171


NOTE : justiciaclient@gmail.com
NOTE : User-Agent : Roundcube Webmail/0.4.2
NOTE : Return-Path : < shadowmagic222@one.lt >
NOTE : Organization : Mr. Jimmy Johnson
NOTE : Mime-Version : 1.0
NOTE : X-Php-Originating-Script : 502:func.inc
NOTE : BARCLAY,S BANK PLC,UK

Your fund has been discovered (Scam from a zombie server)

Hello,
My name is Frank. I am a top-exec in a global bank here in Asia. I have an offer for you that will greatly benefit us both if we work together. Please, do get in touch with me so I can explain more about the deal.
Cordially,
Frank

Email analysis :

NOTE : p.pproject@outlook.com
NOTE : test@rachatcredits.ovh
NOTE : X-Ovh-Remote : 213.186.33.59 (b9.ovh.net)
NOTE : Mime-Version : 1.0
NOTE : Content-Description : Mail message body
NOTE : client-ip=91.121.204.118;


NOTE : helo=ns336204.ip-91-121-204.eu;
NOTE : Received : from [51.254.235.99] (ip99.ip-51-254-235.eu [51.254.235.99])


NOTE : by ns336204.ip-91-121-204.eu (Postfix)
NOTE : Rép :
NOTE : Scam from a zombie server hosted on OVH.

Votre demande d'ahésion ! (Phishing Société Générale)


vos information
SG

Email analysis :

NOTE : Mime-Version : 1.0
NOTE : Content-Type : text/html; charset=iso-8859-1
NOTE : Return-Path : < noreply@tix.fr >
NOTE : X-Sender-Info : < 349043243@infong732.kundenserver.de >
NOTE : Received : from mout.kundenserver.de ([212.227.126.133])
NOTE : Received : from infong732.kundenserver.de (infong732.kundenserver.de [212.227.29.55])
NOTE : by mrelayeu.kundenserver.de (node=mreue007) with ESMTP (Nemesis)
NOTE : Received : from 62.210.15.181 (IP may be forged by CGI script)
NOTE : by infong732.kundenserver.de
NOTE : Votre demande d'ahésion !

Phishing analysis :

CLICK : SG
OPEN : x-webdoc://***
OPEN : SOURCE CODE
EXTRACTED : http://apalomino.com/calson/ - http://peinturesdusud-avignon.com/sec
EXTRACTED : cyberzoide@multimanoi.com_body
OPEN : http://apalomino.com/calson/
REDIRECT : http://cubiertasbarcelona.es/eteg/nera/
SCREENSHOT :


Impacted services :

Relay : kundenserver.de
Open Redirect : apalomino.com
Phishing hosted on : cubiertasbarcelona.es
Victim : Société Générale

Tuesday, August 15, 2017

Is it a scam ? ( Vol 1 )


I received numerous questions on scam.cz. The most interesting is : "Is it a scam ?"

The answer is always the same.

Muqthar Ahmed


Subject : my number 9866900701 has been se;ected for 3.35crore BMW PROMO
Message : SIR WHAT SHOULD I DO TO CLAIM THIS OPPRUTNITY IF THIS IS NOT FAKE
Answer from Scam.cz : This is a fake.

Robert Siemen


Subject : uba atm center 4
Message : There is a Mark Gray who is working on setting up a atm card for me and wants my account numbers here so he can send my my atm card and join it with mine sounds not right so I am checking on this Please get back to me on this matter.THANK YOU Robert SIEMEN
Answer from Scam.cz : This is a scam.

Katja Aaltonen


Subject : got this kind of e-mail today. It was from "Mrs.......
Message : I got this kind of e-mail today. It was from "Mrs. Mary Bustamante". She asked to contact Barrister George Patropoulus (Esq), whose e-mail address is barristergeorgepetropoulos@gmail.com. This message came to me from e-mail address "www."@cube.ocn.ne.jp
Answer from Scam.cz : This is a scam.

Carol Domingos


Subject : WHEN CAN I GET THIS DELIVERED
Message : I WILL SEND THE MONEY. PLEASE CONTACT ME AT 2148087453
Answer from Scam.cz : This is a scam.

Muhamamd Irsyadi


Subject : i have fun in uba bank usd $8,500,000.00 it,s true?
Message : give me information asap.
Answer from Scam.cz : This is a scam.

Rita D Crumpton

Subject : do i rita crumpton have a cleared imf certificate signed by Christine Lagarde and being held for customs taxes?
Message : total tax is 95,000 and I owe 60000.I have paid 3000 for certificate clearance.Am I dealing with the cia?
Answer from Scam.cz : This is a scam.

FWD:TR:RE (Phishing attempt Société Générale)

SOCIETE GENERALE

Cher client,

Le département technique de Société Générale procède à une mise à jour de logiciel programmée de façon à améliorer la qualité des services bancaires.

Nous vous demandons avec bienveillance de cliquer sur le lien ci-dessous et de confirmer vos détails bancaires.

https://www.societegenerale.fr/customercare/banque/confprocedure.asp

Nous nous excusons pour tout désagrément et vous remercions pour votre coopération.

© Société Générale 2017

Phishing screenshot :


Email analysis :

NOTE : natalia1@telus.net
NOTE : Natalia Toroshenko
NOTE : X-Mailer : Zimbra 8.6.0_GA_1211 (zclient/8.6.0_GA_1211)
NOTE : X-Originating-Ip : [160.163.161.144]


Phishing analysis :

CLICK : https://www.societegenerale.fr/customercare/banque/confprocedure.asp
OPEN : http://www.cfa-sport.fr/wp-includes/Text/theme/
REDIRECT : http://www.anti-laser.at/wp-includes/css/theme/
NOTE : Not Found 404 / You are connected from a remote location.
RESULT : Phishing attempt.

Wednesday, August 9, 2017

RE: REPLY. Thoreen (US ARMY)

I seek your assistance to safe keep two military trunk boxes of values
that is of great benefit to we both. Do not panic as i do not pose any
threat to you neither do i mean harm on you whatsoever. Be patient to
hear details as soon as i see your reply to this my direct Email: caseythoreen2017@yandex.com

Email analysis :

NOTE : Thoreen (US ARMY)
NOTE : casey@fancy.ocn.ne.jp
NOTE : ME@mf-smf-ucb010.ocn.ad.jp
NOTE : casey2017thoreen@yandex.com
NOTE : Received : from User (p4220005-ipngn24501marunouchi.tokyo.ocn.ne.jp [118.8.137.5])


NOTE : by vcfancy.ocn.ne.jp (Postfix)

Tuesday, August 8, 2017

Rép : (BSN Solution Scam)

Hello,

On behalf of BSN Solution we want to take this opportunity to advertise our loan offer to those who need urgent financial assistance. I am a loan adviser for BSN Solution; and we seek for beneficial projects for the organizations; seeking means of expanding and relocating our business interest abroad in the following sectors: textile/garment manufacturing, oil/gas, banking, real estate, stock speculation and mining, transportation, health sector and tobacco, communication services, agriculture forestry & fishing; thus any sector. We are ready to fund projects in and out of the country in the form of 'Soft Loan'. We grant loan to both corporate and private entities at a very low interest rate of 3.00% ROI per annum. The terms are very flexible and interesting. If you are interested in our offer, please contact us for details.

Sincerely,
Management.

Email analysis :

NOTE : bsn-solution-ltd@rogers.com
NOTE : lyrivera@justicia.pr.gov
NOTE : Received : from owa.justicia.pr.gov (doj-exch1.justicia.pr.gov. [66.129.175.188])

FWD:RE (Phishing Société Générale)

Decouvrez Le Pass Securite

Afin de prevenir l'utilisation frauduleuse des cartes bancaire sur Internet, Societe Generale est dotee d'un dispositif de controle des paiements. Ce service est entierement gratuit

Notre systeme a detecte que vous n'avez pas active Pass securite

Cliquez ici Pour activez ce service

NOUVEAU: Votre identifiant evolue
NOTE : Ne pas repondre a ce courrier electronique car il est emis
automatiquement depuis une adresse technique

Cordialement
Alexandre krivine
Directeur de la relation clients

Merci pour choisire SOCIETE GENERALE!

Copyright ©2017 Societe Generale. Tous droits réservés.
Numéro d'immatriculation FSASociete Generale: 226056.

Apply Now >

Facebook
Twitter
Instagram
RSS
Appstore
Android

This message was sent to ilyass-maradona@live.fr
If you would like to update your email address, please click here.

To unsubscribe from emails, please log in to your Mint account
where you can manage your email and mobile alerts setting.

©2007—2017 Mint Software, Inc. | All Rights Reserved.
Mint.com 2632 Marine Way, Mountain View, CA 94043
Privacy Policy | Terms and Conditions

Phishing screenshot :


Email analysis :

NOTE : ing22@telus.net
NOTE : ilyass-maradona@live.fr
NOTE : Received : from cmta16.telus.net ([209.171.16.89])
NOTE : Received : from mtlp000023.email.telus.net ([172.20.100.250])
NOTE : by cmsmtp with SMTP
NOTE : X-Originating-Ip : [105.149.30.122]


Phishing anaylsis :

CLICK : Cliquez ici Pour activez ce service
OPEN : http://www.goingesten.se/wp-snapshots/tmp/
REDIRECT : http://se.nickelmountain.se/wp-includes/theme/9f24e/Action.php?*
SCREENSHOT :


CLICK : VALIDATE WRONG CODE
REDIRECT : http://se.nickelmountain.se/wp-includes/theme/9f24e/dcr-web/
SCREENSHOT :


VALIDATE : FORM
REDIRECT : http://se.nickelmountain.se/wp-includes/theme/9f24e/dcr-web/deconnecter.php?date=0000000000&crd=0000&date-ex=00&year-ex=0000&cv=000&numo=0000000000&zob1=00000000&zob2=000000
REDIRECT : http://societegenerale.fr/

Monday, August 7, 2017

Payment Notification, (Western Union Scam)

Dear Western Union Customer,

You have been awarded with the sum of $360,000.00 USD. in the western
union money transfer program s one of our customers who use Western
Union in their daily business transaction,Please provide Mr.Dennis Woods
with the following details below so that your fund will be remitted to
you through Western Union Transfer.

(1)Names:
(2)Address:
(3)Phone Number:
(4)Sex:
(5)Age:
(6)Country:
(7)Occupation:

Mr.Dennis Woods
(Western Union Online coordinator)
E-mail: wu.moneytransfer_online1117@live.com
(Help Line: +254-7801-02173)

As soon as these details are received and verified, your
fund will be transferred to you. Thank you, for using
western union.

Email analysis :

NOTE : ECOLE MATERNELLE PUBLIQUE ROBERT DEBRE - SAINT-LOUIS
NOTE : ce.9740750X@ac-reunion.fr
NOTE : wu.moneytransfer_online11@msn.com
NOTE : Received : from [172.31.186.125] (Forwarded-For: 154.123.121.136)


NOTE : by store1.in.ac-reunion.fr (mshttpd);
NOTE : Received : from ac-reunion.fr (store1.ac-reunion.fr [172.31.186.61])


NOTE : by smtpout2.ac-reunion.fr (Postfix)
NOTE : client-ip=195.98.231.113;
NOTE : @educationfrance : Western Union Scam relayed from ce.9740750X / ac-reunion

Monday, July 31, 2017

FWD:RE (Phishing Société Générale)

En ce qui concerne les informations relatives à votre compte bancaire:
Cher client:

Notre systeme a detecte que vous n'avez pas active Pass securite (Societe Generale):

Decouvrez Le Pass Securite

Afin de prevenir l'utilisation frauduleuse des cartes bancaire sur Internet, Societe Generale est dotee d'un dispositif de controle des paiements. Ce service est entierement gratuit.

Cliquez ici Pour activez ce service

Merci pour choisire SOCIETE GENERALE!

Copyright ©2017 Societe Generale. Tous droits réservés.
Numéro d'immatriculation FSASociete Generale: 226056.

Mon compte
Téléphone
Facebook
Instagram
Twitter
Pinterest
Youtube
Magazine

MENTIONS LÉGALES
PROTECTION DES DONNÉES
CGV

SE DÉSINSCRIRE DE LA NEWSLETTER

Phishing screenshot :


Email analysis :

NOTE : kaizenqm@telus.net
NOTE : Cmm-Sender-Ip : 209.171.16.90


NOTE : X-Mailer : Zimbra 8.6.0_GA_1211 (zclient/8.6.0_GA_1211)
NOTE : Received : from mtlp000003.email.telus.net ([172.20.100.250])

Phishing analysis :

CLICK : Cliquez ici Pour activez ce service
OPEN : http://kombiringen.se/wp-content/theme/
REDIRECT : http://www.goingesten.se/wp-content/theme/
REDIRECT : http://www.goingesten.se/wp-content/theme/*/service.php?*


RESULT : Phishing Société Générale

Votre-Paiement-En ligne (Phishing attempt)

Bonjour,

Afin de prévenir l'utilisation frauduleuse des cartes bancaires Internet,

Votre Service Générale, est dotée d'un dispositif de controle des paiements.

Ce service est entierement gratuit Notre Systeme a detecte que vous n'avez pas active -Pass-Service-sécurite

Service sécurite

Banque-Générale

Nous vous remercions de votre Confiance.

Cordielement

Email analysis :

NOTE : INFO@news.promovacances.com
NOTE : Received : by footcenter.fr (Postfix, from userid 33)
NOTE : Received : from footcenter.fr ([165.227.79.193])
NOTE : X-Php-Originating-Script : 0:nel.php
NOTE : Message-Id : < *.*@footcenter.fr >
NOTE : Votre-Paiement-En ligne

Phishing screenshot :


Phishing analysis :

CLICK : Service sécurite
OPEN : http://sirlwad.gear.host/s52.html
SCREENSHOT :


RESULT : Phishing attempt.

Information about this phishing

SCRIPT : nel.php
HACKED RELAY : footcenter.fr
OPEN REDIRECT : sirlwad.gear.host
SPOOFED EMAIL : INFO@news.promovacances.com
PHISHING : Société Générale

Camelot

You have Won $680,000

Email analysis :

NOTE : camelot.group@gmx.co.uk
NOTE : Received : from [192.168.0.100] (unknown [43.240.7.1])


NOTE : by spamwall.quilmes.gov.ar (Postfix)
NOTE : Received : from spamwall.quilmes.gov.ar
NOTE : (spamwall.quilmes.gov.ar. [190.120.191.6])


NOTE : The quilmes.gov.ar server was hacked to relay this scam.
NOTE : @QuilmesMuni was contacted

Thursday, July 27, 2017

Urgent sunTrust Confirmation

We have updated your contact information

For details about what changed, sign on to Messages and Alerts. To view the updates, or make additional updates, sign on to update your contact information.

1. If you did not make this request online, by phone, or at a Suntrust store, please sign on immediately . We are available 24 hours a day, 7 days a week.

Please update and verify your information by clicking the link below:

To view the updates

If your account information is not updated within 72 hours then your ability to access your account will become restricted.

Fraud Prevention Unit
Legal Advisor
Suntrust Bank

Email analysis :

NOTE : spam@petofisopron.hu
NOTE : Received : from [205.209.150.138] (205.209.150.138)


NOTE : by psrv01.petofisopron.hu (192.168.0.3)

Phishing analysis :

CLICK : To view the updates
OPEN : http://deliaujica.com/css/images/sunTrust/sun/validation/
RESULT : Phishing was removed.

Wednesday, July 26, 2017

Agence ClientèIe SBE : RappeI (Phishing Bred)

Cher(e) Client(e),

Votre conseiller vous informe que vousiavezireçuiunimessageoimportant

conçernantivotreiE-Code.

tVotre accès en ligne

Cordialement
Votre Banque

ic

Email analysis :NOTE :

NOTE : laempresadelexito.com@emails.afm-telethon.fr
NOTE : laempresadelexito.com
NOTE : X-Php-Originating-Script : 0:tmsir.php
NOTE : Received : by emails.afm-telethon.fr (Postfix, from userid 33)
NOTE : Received : from emails.afm-telethon.fr ([165.227.14.87])
NOTE : emails.afm-telethon.fr@emails.afm-telethon.fr

Phishing screenshot :


Phishing analysis :

CLICK : tVotre accès en ligne
OPEN : http://laempresadelexito.com/BredEcode
REDIRECT : http://www.metaltripshop.com/metaltripshop/app/code/community/Mage/Sales/Model/Convert/Model/brlogin/brlogin/*/
SCREENSHOT :


VALIDATE : FORM
REDIRECT : http://www.metaltripshop.com/metaltripshop/app/code/community/Mage/Sales/Model/Convert/Model/brlogin/brlogin/*/phone.php?tok=*
VALIDATE : FORM
REDIRECT : http://www.metaltripshop.com/metaltripshop/app/code/community/Mage/Sales/Model/Convert/Model/brlogin/brlogin/*/sms.php?tok=*
VALIDATE : FORM
REDIRECT : http://www.metaltripshop.com/metaltripshop/app/code/community/Mage/Sales/Model/Convert/Model/brlogin/brlogin/*/done.php?tok=*
REDIRECT : https://www.bred.fr/index.html

Conclusion :

Victim : BRED
Spoofed service : emails.afm-telethon.fr
Location of the Open redirect : laempresadelexito.com
Location of the Phishing : metaltripshop.com

Cancelled: Hello Dear (Email leak)

This event invitation was sent from Yahoo Calendar

Email leak :

jo.robinson@vbase.co.nz hayley.mckay@vbase.co.nz janelle.frost@vbase.co.nz valerie.sisson@vbase.co.nz daniel.chee@vbase.co.nz jane.crampton@vbase.co.nz peter.maddock@vbase.co.nz caroline.whittaker@vbase.co.nz laurie.frankcom@vbase.co.nz mark.meyer@vbase.co.nz christian.barbier@vbase.co.nz christian.barbier@nccnz.co.nz amanda.fairbairn@nccnz.co.nz williambabcock@bnj.com cameron@glengarry.net campbellh@sensato.com glengarry@scot89.freeserve.co.uk loglinecontest@gmail.com howardbusservice@ripnet.com jnlarocque@hmnet.net jim.devlin@coachcanada.com claude@sleep.winthrop.org owner-bcr-l@bcr.org lucy-fryish@hotmail.com jillaroo@hotmail.co.yk gemmelldr@btinternet.com acw26@st-andrews.ac.uk cjw11@st-andrews.ac.uk gracemcbride@virgin.net bruce.macnab1@btinternet.com lynnkidd@glenaray.f2s.com derry.barton@blueyonder.co.uk ajohnston@shinty.com allanmacleod@shinty.com s0347230@sms.ed.ac.uk ti66c@p6isti6a.dyo sales@glengarry.co.nz celticpublicity@gmail.com 4zeke@wrteme.com ryan@eroi.com macsnest@mnsi.net simonwillans@hotmail.com pegstew@ibm.com mirandamulholland@gmail.com info@nviro.com rjf@radiks.net fbjjnunn@netscape.net christinametrose@yahoo.com asawyer@cwfcof.org mumford@cadvision.com gca1@cornell.edu thebigape2000@hotmail.com kee_empire@hotmail.com election@electionprediction.org selwynmac@telus.net ken.steffenson@telus.net shannajones@charter.net linguaphile@wordsmith.org drumfest06@masamba.com andy@andyfilius.com information@tartangift.co.uk kdkopple@bellatlantic.net potters54@comcast.net vmconnell@vonrollwti.com heaven@funcow.com hw15@juno.com comcat@woosh.co.nz sales@nzcleanskinwines.co.nz martinc@planetwine.co.nz wineonjervois@xtra.co.nz info@roadworks.co.nz bpedaci@tickets.com aalbers1@sbcglobal.net ggarim@yahoo.com bronwyn.dodson@tianz.org.nz nicki.vanasch@tianz.org.nz fiona.morris@tianz.org.nz angela.h@peek.co.nz info@tianz.org.nz soonerfann@cox.net ohiostate521979@yahoo.com info@australindtravel.com greenleaves@bigpond.com sales@jetset-belmont.co bredmond@gmail.com margaret.harvey@btinternet.com jessmcleod@nzhouseofwine.com contact@vinsdumonde.com theglengarrybhoys@yahoogroups.com reservations@bwglengarry.com shop@sandygroup.com torino@nt.net susie_thomson@prinz.org.nz fluidfx@wi.rr.com webmaster@brigadeaustralia.org peter.wiseman@intecbilling.com carsonchisholm@hotmail.com under@2world.com info@aussiemoot.com rrc.regactivities@sydneynorthscouts.com rovers@sydneynorthscouts.com imacmill@interlog.com ncimino@hotmail.com info@edfilmfest.org.uk contact@kosb-berwick-branch.co.uk contact@kosb-edinburgh-branch.co.uk kathleenweetman@hotmail.co.uk shuggie1999@hotmail.com jmichaelhamilton@hotmail.com bjls@heaneyb.fsnet.co.uk crap@sydneynorthscouts.com pearcey_sico@msn.com blokes@razorbackrovers.com apriledwards39@hotmail.com boagies@branchball.nswrovers.com info@streamwave.com wgustafson@adwilliams.com ralston@macdonnellgroup.com ejmartin@mgcl.net lutkevich@pbworld.com p.burden@stonyplain.com orite@bobcat.ent.ohiou.edu stayabji@ctlgroup.com simeonsamba@gmail.com 0535583@student.ul.ie katharine.hoskyn@xxx.xx.xx diannashipman@xxxxxxxx.xxx.xxx sales@henhousedesigns.com glengarry@glengarrybooks.co.nz oqp-subscribe@yahoogroups.com tim@timdawsn.demon.co.uk enquiries@obersvatorypitlochry.com sales@guideposthotel.net sales@dubrovnik.co.uk info@midland-hotel-bradford.com enquiries@parkgrovehotel.co.uk newbeehiveinn@talk21.com raymogood@yahoo.co.uk info@thewhitcliffehotel.co.uk enquiries@glengarryhouse.com admin@umiversal-arts.com admin@universal-arts.com cmhanat@interlog.com cmhasim@bconnex.net dmeurkes@cmhakent.com cmhaelgn@elgin.net cmha@jam21.net cmhagb@bmts.com cmha@kwic.com cmhahalton@interhop.net cmha@cyg.net cmhstaff@adan.kingston.net general@cmha.sarnia.net londoncmha@golden.net cmhanip@onlink.net cmhaottawa@globalserve.net cmhaoxf@execulink.com cmhanpar@interlog.com cmha@accel.net cmhsdgpr@cnwl.igs.net mqcmha@cyberbeach.net cmhatb@norlink.net cmhatmsk@nt.net cmhavcb@nexicom.net megan_willmann@wayne.edu hiltonps@world.net qtrmileprincess@yahoo.com starry1ca@hotmail.com greenbrier@thegreyhavens.zzn.com tripleplay204@hotmail.com

NOTE : toshibazenmate6789@yahoo.com
NOTE : Received : from [127.0.0.1] by ec05.unp.bf1.yahoo.com

RE: ATM

You can hack and break into any bank's security ATM Machine without carrying guns or any weapon. How is this possible? First of all we have to learn about the manual hacking of ATM MACHINES and BANKING ACCOUNTS HOW THE ATM MACHINE WORKS. If you have been to the bank you find out that the money in the ATM MACHINE is being filled right inside the house where the machine is built with enough security. To hack this machine, We have develop the special blank ATM Card which you can use in any ATM Machine around the world. this card is been programmed and can withdraw 8,000 within 24 hours in any currency your country make use of there is no ATM MACHINES this BLANK ATM CARD CANNOT penetrate into it because it have been programmed with various tools and software before it will be send to you. The card will make the security camera malfunction at that particular time until you are done with the transaction you can never be trace. it also has a technique that makes it impossible for the CCTVs to detect you, there are so many other hacker out there whom claim to be real you have to be very careful they can never create this card all they want is your money. no ATM card can be able to withdraw 50,000USD each day that is impossible, getting the card you will forward the company your address details so we can proceed to send the card to you once you agree to the terms and conditions. you can contact us on email now at: ATM.smartcardcenter2017@hotmail.com

--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.

Email analysis :

NOTE : ATM.smartcardcenter2017@hotmail.com
NOTE : 049unaj@tjpa.jus.br
NOTE : Unaj da Comarca de Santa Izabel
NOTE : X-Originating-Ip : [177.125.100.114]

Finance loan 3%.

Attn:

We offer variety of finance including: Personal loan, Home loan, Debt Consolidation loans, Car loans, agricultural loan, business loans and company loans at 3.00% interest rate per annual and it is fixed. Please contact us via email: cfunding988@gmail.com for more info

(1)Full Names:
(2)Country:
(3)Loan Amount):
(4)Loan duration:
(5)Phone number:
Sign
Management.

Email analysis :

NOTE : cfunding988@gmail.com
NOTE : 57019800@mylife.unisa.ac.za
NOTE : X-Originating-Ip : [41.247.195.72]

Sunday, July 23, 2017

TREAT AS UTMOST IMPORTANCE.

From the office of the Branch manager
Hawaii National Bank
Main branch
45 north king street Honolulu, HI 96817
United States of America.
Email: hnbnk.mb@gmail.com
Monday -Thursday 8am-4pm
Friday 8am-5pm

We received instruction from ECOWAS financial authorities in charge of debt reconciliation/compensation to remit the sum of $1.9m to you. Kindly confirm your photo ID and reconfirm your personal details as stated below to enable us start the processing immediately.

1 Your full name:
2 Your present contact address:
3 Your telephone & Fax numbers:
4 Your Occupations/age/sex:
5 Your Private/alternative Email Address:

Your prompt response will enable us effect a quick release .

CONGRATULATIONS.

Joe Yit
Branch Manager
Hawaii National Bank

Email analysis :

NOTE : hnbnk.mb@gmail.com
NOTE : Received : from [127.0.0.1]
NOTE : (helo=User) by ct.stormnet.co.za with smtp (Exim 4.76)
NOTE : client-ip=209.203.29.154;

Tuesday, July 18, 2017

Personal loan (Email leak)

Hello ,

Do you need a personal loan or a business loan to start up a business of your own? We offer loans to all in need at very low interest rate 5% we would be able to give you any amount you want, contact us now for more information (financial1group@gmail.com )

http://www.amcp.org/AboutUs.aspx?id=8821

Screenshot of the scam :


Email leak (391 emails) :

Cia_takim@gmx.de, Ciaranc666@Gmail.Com, Cijayhd@gmail.com, Cimmern@hotmail.com, Cinderellasoulmates@gmail.com, Clarencewistock@yahoo.com, Clashnlash@gmail.com, Clivecornwall83@gmail.com, ClockFaceContact@gmail.com, CoRvali_2024@guildzmail.com, Code.Monkey78@gmail.com, Codenlilly@hotmail.co.uk, Cody@techcodesupport.com, Coka.In@gmx.net, Coline0404@icloud.com, Colviniphone@gmail.com, Communitywebtech@gmail.com, Conformityntomorte@gmail.com, Connie.Lane489@yahoo.com, Connor.henderson@gmail.com, Consigliereco@gmail.com, Contact@WEBSITEHOSTINGOVERVIEW.COM, Cool.smiley@me.com, Cooldline@gmx.de, Corazan00@hotmail.com, Coreyjreed@msn.com, Cornelius.Munson@gmail.com, CorneliusHarder@gmail.com, Cory0401@stcloudstate.edu, CouldBeJesus@yahoo.com, Courtneyalexanderdds@yahoo.com, CptDylanHuntSystemsCommonwealth@yahoo.com, Craig.Jones2006@blueyonder.co.uk, CraigFWhite@armyspy.com, Cramzta@hotmail.com, Crashppm@gmail.com, CrazyMenConnected@gmail.com, Crazyman323@hotmail.com, Crazyyahoohead@gmail.com, CreationLeader@yahoo.co.uk, Creed_Bratton@email.com, CronoOB@gmail.com, Cuervo2998@gmail.com, Cujo20001us@yahoo.com, Cukr01@gmail.com, Cullen.1996@mail.ru, Curchofblessedtrinity@gmail.com, Curphpistachio@yahoo.com, Cwilson16856@gmail.com, CypherBotX@yahoo.com, Cypherhawk@live.com, Cyril.rosewood@gmail.com, D.BarnesMordant@googlemail.com, D.DuJaque@gmail.com, D.sumadija@gmail.com, D3xterity@live.nl, D6D6D5@gmail.com, DARKTITANK@YAHOO.COM, DBaggs@bagnoli.co.uk, DDY9121@YAHOO.COM, DGQuattro@gmail.com, DGTalSoul@gmail.com, DILLON.CAMPBELL25@GMAIL.COM, DILPAK11@AYHOO.COM, DIRECTR@GMAIL.COM, DJ.BUTLER@xtra.co.nz, DJJOSH@HOTMAIL.ES, DJT@Trumporg.com, DJonesLamont45@gmail.com, DOBRACHI@OUTLOOK.COM, DONIAALI85@YAHOO.COM, DONNAKEYBONKER@GMAIL.COM, DORINU76@LIVE.COM, DRSTEVEPD@GMAIL.COM, DTechtnzl@gmail.com, DTvampire@live.com, DUpedAL@hotmail.com, DWHampshire@gmail.com, DaHunter@sogetthis.com, DaNyiTaLiAnU@gmail.com, Daan5481@hotmail.com, Dagamand@gmail.com, Dagoldman123@gmail.com, Dahg.Hieyyt@gmail.com, Daian_Style@web.de, Daily0023@gmail.com, Dalepatrick1@outlook.com, Dallas.DeMarr.310@gmail.com, Dallowlucran@gmail.com, Dalton_Michaels@hotmail.com, Damian07PT@gmail.com, Dammiga_tofflan@hotmail.com, Damnjoshawadamn@aim.com, Damon@open.by, Dan.Sk3lton@googlemail.com, Dan.the.smelly.man@gmail.com, Dan_McEntaffer@yahoo.com, Daniel.Fox73@hotmail.com, DanielNicklasson@hotmail.com, DanielTYoung62@gmail.com, Danielsdavid028@gmail.com, Danieltubb@live.co.uk, Danls92_iPTF@yahoo.com, Danny_Lee2000@yahoo.com, Dannyvaeskalkman@gmail.com, Dano_the_boy@yahoo.com, Danso11.ed@gmail.com, Daria919@mail.ru, DariusLGrant@protonmail.com, DarkAlchemist@hushmail.me, DarkMaster.ScL@gmail.com, DarkRyder3018@gmail.com, Dark_knigth20009@hotmail.com, Darkmaus20032003@gmail.com, DarknessX@windowslive.com, Darksyder1@gmail.com, Darrensateen@gmail.con, Darrensateen@hotmail.com, DarrinJMoret@mail.com, Darrinm@aol.com, Daryan.snake@hotmail.com, Dasitya@hotmail.com, Datch@tempmail.it, Datcubanboiberto@aol.com, Dav49@live.com, DaveMcDave@spidey.me.uk, Davetaylor696969@gmail.com, David-beer@hotmail.com, David.robs@icloud.com, David.sentelle@icloud.com, David89@126.com, DavidAJones1983@gmail.com, DavidIWeisberg@gmail.com, DavidSoares223@hotmail.com, David_E_Long@shaw.ca, Davidagib@yahoo.com, Davidandrews4676@gmail.com, Davidmealson@yahoo.com, Davidparker1952@yahoo.com, Daviem531@gmail.com, Ddrosemont@gmail.com, Dduuggiiee@gmail.com, Deadlymice@hotmail.com, Dean.laidlaw@pertemps.co.uk, Deano200780@googlemail.com, Deathruler@abv.bg, Dedraelos@yahoo.com, DeejayCrazzy@gmail.com, Deepelmdesciple@gmail.com, Deltavox@gmail.com, DemisePower@gmail.com, DemonicApes@google.com, Demonx6@webmerch.zzn.com, DemsOFF2@gmail.com, DeniCevap@gmail.com, Denis.Pisczor@web.de, Dennis.o.wolf@gmail.com, DerrickHanchob@gmail.com, DevChatts@gmail.com, Devidkin@pacific-ocean.com, Dextros121@googlemail.com, Dfreeman12344@gmail.com, Dharmkey@gmail.com, Diabolo.demonttn@gmail.com, DiannMcSwain10101@innocent.com, DickHardy42@gmail.com, Digitalhdelectronic@gmail.com, Dillanmortemerpublications@mail.com, Dimasa87@gmail.com, DinaRosenmauer@gmail.com, Dingo@younoob.net, Dirkgently351@gmail.com, Divine.Hate88@Gmail.com, Divinewind169@gmail.com, Dj.fantaa@gmail.com, Djthunder1@msn.com, Dlh2409@gmail.com, Dmac91@Gmail.com, Dmitrysilvers@gmail.com, Dnegel22@hotmail.com, Dnte1020@gmail.com, DoGapes1102@hotmail.com, Dobby2007@live.co.uk, Doc_cheeks@outlook.com, Doctorrodneysoul@gmail.com, Dodytorrent@yahoo.com, Dominic.morgan22@mail.com, Don.a@farmside.co.nz, Donald.rictus@outlook.com, DonaldTheGiver@hotmail.com, Dorothybeatriceyaeger@gmail.com, DoubleAAMods@gmail.com, DougLerner@hotmail.com, Doverb83@gmail.com, Dr.Richard.Poke@gmail.com, Dr.Ugubu@gmail.com, Dr.ivorbigone@yahoo.co.uk, Dr.midick@gmail.com, DrB_Whitmore@outlook.com, DrBillStroker@gmail.com, DrJasonZimmerman@gmail.com, DrShrooms2k10@gmail.com, DrTim@TexasPediatricDentistry.com, DrVinnieBoomBotzMD@gmail.com, DraGon_K1nG@Hotmail.com, Draconic_Draconic@yahoo.com, Dragonsharkyt@gmail.com, Drakestein24@gmail.com, Drangiepd@gmail.com, Drcristophpanopolous@gmail.com, DreadyTony@gmail.com, Drewsmith542002@gmail.com, DrokcX@gmail.com, Duanebenzie60@gmail.com, Duckflappynorris@gmail.com, Ducky033@gmail.com, DumbDude@Gmail.Com, Durot.cindy1@gmail.com, Durvor@gmail.com, Dustin.Friederich@hotmail.com, Dustin_Holloway@hotmail.com, Dvdcarrot@gmail.com, Dvorova_marisha@mail.ru, Dwaynejohnson864@gmail.Com, Dwelsh1159@gmail.com, Dylan4anika@gmail.com, Dynomitedevo@aol.com, E.cocky22@gmail.com, E.cocky@gmail.com, EGutierrez91@gmail.com, EQUIPENEWSPACE@GMAIL.COM, EQforumadmin@gmail.com, EXcellence2@hotmail.com, EZ_HumanAbattoir@Hotmail.com, Easmar@sbcglobal.net, Easternklassiker@yahoo.de, EatMe@ModernWarfareGaming.com, Eddie.Hargreaves@mail.com, Eddy.orna@libero.it, Eddy777@zoznam.sk, EdgarInvestments@tormail.org, EdiBalagula@gmail.com, Edward@yourcarrierquote.com, Ekofrmjerzy@aol.com, El.cecaracho@gmail.com, EladBr@Gmail.com, ElectroZoom@hotmail.com, Elisebartonsmythe@hotmail.com, EliteNeel@yahoo.com, Ellie.bridgit@outlook.com, Elliotsullivan67@gmail.com, Elopez1989@aol.com, Elplatano37@hotmail.com, Elsie.smithers@gmail.com, Elvajordan@gmail.com, Elwinderbucher@gmx.com, ElyOfIce@zoho.com, Elysiumite@gmail.com, Elzakarypurcell@gmail.com, Emanuality@yahoo.com, Emil_165@hotmail.com, EmiliaSimons@zoho.eu, EmilyJohanson0605@gmail.com, Eminem.gng@gmail.com, Eng.mohamedelmorsy@hotmail.com, Enginesb5@gmail.com, EnglishCofA@gmail.com, Engravex-321@hotmail.com, Enquiries@amc.edu.my, Enterprize914@gmail.com, Eric.Donaldson.spam@gmail.com, Eric.Oblepias@gmail.com, Erichammeran@mail.com, Erichisburg@gmail.com, Erickbernal27@gmail.com, Ericsonlil@yahoo.com, Erwin.Noordam@yahoo.com, Erynn_191@hotmail.com, Essaygrace128@yahoo.com.cn, EuAxxel@gmail.com, Euclides@AustinCacophony.com, Evildenny123@gmail.com, Evilmask01@gmail.com, EwanJanoski@yahoo.com, ExplosiveBread2@gmail.com, Express4g@aol.com, Exterior.Husky@gmail.com, ExtremeUnicycle@gmail.com, F50_SAEED@HOTMAIL.COM, FBerisha@web.de, FCrasher@gmail.com, FELIX8221983@yahoo.com, FMachado84@yahoo.com, FREDYHAWK@AOL.COM, FRGHTRH@web.de, FTN@hotmail.com, FU4Life29@gmail.com, FWThompson@europe.com, FabioLorenzo357@gmail.com, Fakee25@gmail.com, FallenAngel20007@yahoo.com, Fallen_Angel_Of_Disgrace@hotmail.com, Falloutie@gmail.com, FamilyGuy977@rock.com, Fantasy2000@web.de, Fantasy_Hins@126.com, Farahrasshad@sharklasers.com, FarePak350z@googlemail.com, Fariousinc@gmail.com, FaronMorgan@Hotmail.co.uk, Father.Jed@gmail.com, Feenafer@gmail.com, Felix2131@aol.com, FenderTele@gmx.co.uk, Ferekikoo@yahoo.com, FerrariCentury01@gmail.com, Fgfortgshs@gmail.com, Fieldsjabbar@gmail.com, Fiestaaccount312@live.com, Fighter_S@bigmir.net, Finalgaming@yahoo.com, FinchJ1978@gmail.com, FinnKelley@Gmail.com, Finviter@gmail.com, Fionalews@mail.com, Firey.pancake@gmail.com, Fishingforsnorlax@gmail.com, FlossieBowers@gmail.com, Floyd.J.Owens@gmail.com, Fluxxen@hotmail.com, FlyAsTheSky00@yahoo.com, FlySwatterz@googlemail.com, Flying-Splargen@hotmail.com, FlyingLotus@aol.pl, Flyleaf82@gmail.com, Foonzy007@hotmail.com, Forten@email.com, Fortunataapple@gmail.com, Fost555@gmail.com, FouadSMF@hotmail.com, FoxieHouston@gmail.com, FoxysTijuana@gmail.com, Fr.Meemersmith@gmail.com, FrancineSparks@hotmail.com, Franco145@gmail.com, Francocartongesso@yahoo.com, Frang004@gmail.com, FrankEJam@gmail.com, Fred248@hushmail.com, FredARQ@gmail.com, FredFredburger@Europe.com, Freetoaster@hotmail.com, Frisk.alexander@gmail.com, Frithiof@live.com, Fro6612@gmail.com, Frozenfuryblade@gmail.com, Fuckyou@gotohell.com, Full.House@hotmail.com.tr, Fundamental.Jack@gmail.com, Funfriendsfast@mailinator.com, Funkmastachad1@gmail.com, Funkmastachad2@gmail.com, Fuzzywaters52@gmail.com, G.a.clooney@gmail.com, G.moore68@hotmail.com, G8page@gmail.com, GAZA1512@HOTMAIL.COM, GGkuaipao@gmail.com, GMP1@mail.com, GNR.clan@yahoo.in, GOOJZAR3000@GMAIL.COM, GOOJZAR333@GMAIL.COM, GOST.DOG987@GMAIL.COM, GP@HANNAPLUMBING.com, GQSoul@gmail.com, GR8SDS@gmail.com, GTDrift@hotmail.com, GT_RS4@yahoo.com, GZASloveless@yahoo.com, Gaara.DJalil@gmail.com, GamerZFX@gmail.com, Gaming.Only@hotmail.com, GandhiReborn@gmail.com, GangStar.cw@gmail.com, Garagebeatz@hotmail.co.uk, Garcia_13077@yahoo.com, Gardnera218@gmail.com, GarlicJohnson@gmail.com, GarryLee78@hotmail.com, Gatepc@gmail.com, Gauuute@gmail.com, Gavinscottrealilluminati@gmail.com, Geeneralknas@gmail.com, GeneDDS79@yahoo.com, Generalkawundeaa@gmail.com, Generodan@gmail.com, Genjiro@gmx.de, GeoffBridges1961@gmail.com, George15@yahoo.com

Email analysis :

NOTE : ellisonbill6@gmail.com
NOTE : Received : from AMCPWeb (unknown [208.75.222.100])


NOTE : by listserv.wsol.net

Saturday, July 15, 2017

Avis Important : Activation de votre PASS SECURITE

Bouygues Telecom
ACTIVATION DE VOTRE PASS SECURITE

Chère Cliente, Cher Client,
Nous vous présentons le nouveau : PASS SECURITE .Un service simple et rapide pour confirmer vos transactions en ligne. Intégré dans l’Appli(1) Smartphone Société Générale, ce nouveau service vous permet de confirmer rapidement et directement vos opérations réalisées en ligne. Une simple démarche vous permettra l'adhésion à ce service.

Nous vous prions de remplir le formulaire demandé en cliquant ici.

Veuillez saisir de votre identifiant et mot de passe banque en ligne en premier lieu.
Nous vous remercions de votre confiance ainsi que du temps accordé
À très bientôt.

Alain Angerame
Directeur de la Relation Clients
Pensez-y
Societe Generale, SA au capital de 2 492 770 306 euros - Siège social : 16, boulevard des Italiens - 75009 PARIS.
Immatriculée sous le n° 662

Merci de ne pas répondre à ce courrier électronique : il est émis depuis une adresse technique.
Facebook est une marque déposée de Facebook, Inc.

This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you are not the named addressee you should not disseminate, distribute, copy or take any action in reliance on the contents of this e-mail and these activities are strictly prohibited. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system.

Phishing screenshot :


Phishing analysis :

CLICK : en cliquant ici
OPEN : https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0ahUKEwjfmPKqlojVAhWHWRoKHT2lAuEQFggmMAA&url=http%3A%2F%2Fwww.losramonvanenmoto.com%2F%3Fp%3D398&usg=AFQjCNGf_uOWCXPgrOUk9HQftp6Bw-MSOQ
EXTRACT LINK : http://www.losramonvanenmoto.com/?p=398
REDIRECT : http://sh212342.website.pl/clientsg/


NOTE : As you can see inside this phishing, the fraud used a Google approach.

Email analysis :

NOTE : no.reply@clarabridge.com
NOTE : Cmm-Sender-Ip : 64.78.52.184
NOTE : Received : from vultrguest (185.92.222.28)
NOTE : by east.exch023.serverdata.net (10.240.8.31)

Tuesday, July 11, 2017

Directeur de l' agence : E-Code (Phishing Bred)

Cher(e) Client(e),

Votreiconseiller vous informe que vousiavezireçuiunimessageoimportant

conçernantivotreiE-Code.

iVotreiaccèsienilignei

Cordialement
Banque BRED

sd

Phishing screenshot :


Phishing analysis :

CLICK : iVotreiaccèsienilignei
OPEN : http://motivacionempresas.com/Bred/Ecode
REDIRECT : http://www.metaltripshop.com/fotos/demo/img/demo/0day/img/0day/login-03f844f750d92844533c7114b77b104/brlogin/brlogin/84e2dceb893464b1f65509eaad9f7bed/
SCREENSHOT :


NOTE : The phishing page requests for a mobile phone.
NOTE : The phishing page requests for a code related to the mobile phone.
SCREENSHOT :


REDIRECT : https://www.bred.fr/index.html

Email analysis :

NOTE : eventosinfantiles.es@stepstone.fr
NOTE : Received : from stepstone.fr (mx28-g26.priv.proxad.net [172.20.243.98])
NOTE : X-Php-Originating-Script : 0:manager.php