Monday, March 21, 2016

Request.

I am Ms.Golan I am getting in touch with you regarding an extremely important and urgent matter.If you would oblige me the opportunity, shall provide you with details upon your response.

Faithfully,
Ms. Golan

Email analysis :

NOTE : rte2378@outlook.com
NOTE : meraso@idsn.gov.co
NOTE : X-Originating-Ip : [45.58.37.104]


NOTE : Received : from mail.idsn.gov.co (mail.idsn.gov.co [190.66.23.131])


NOTE : X-Mailer : Zimbra 8.0.4_GA_5737 (zclient/8.0.4_GA_5737)
NOTE : Thread-Topic : Request.

Notes from scam.cz :

- Instituto Departamental de Salud de Nariño was used to relay this scam.
- Account was "meraso"

Hello My love

Hello My love

My name is lina williams I am a single girl, never no married. i will like to be your good friend and i am interested in knowing you, Write back to me in my E-mail I D at (lina48williams@gmail.com )so that i will give you full explanation of myself. and my picture, also ihave something to tell you about me

.Am Waiting for your quick reply

Thanks from me,l
lina williams

Email analysis :

NOTE : lina48williams@gmail.com
NOTE : lina12williams@outlook.com
NOTE : client-ip=65.55.34.15;

Angelina Belinda Beverly

It is well real that I do not know you but I ask God is to fit your saint heart to help me in my projects of donation with me. Then for more of details, so please contact me for more information on the donation project and myself. If his might that be you my vision and that you be in good faith please you want to contact me by mail private: beverly.angelinabel@gmail.com

May the peace and mercy of God be with you.

Ms. ANGLINA BELINDA BEVERLY

Pleased to read,

Email analysis :

NOTE : beverly.angelinabel@gmail.com
NOTE : User-Agent : izi webmail
NOTE : phil.autarddebragard@izi.re
NOTE : Mime-Version : 1.0
NOTE : amavisd-new at mail1.mobius.fr
NOTE : 80.69.208.48 as permitted sender


NOTE : smtp.mailfrom=phil.autarddebragard@izi.re
NOTE : X-Sender : phil.autarddebragard@izi.re
NOTE : Received : from smtp.izi.re ([127.0.0.1])
NOTE : Received : from iziport4 (pub13-134.mobius.fr [80.69.213.134])


NOTE : by smtp.izi.re
NOTE : HELLO

FUNDS DONATION

I Mr.Neil Trotter is the current winner of ?108 million Pounds on the 2014 concluded Euromillion JackpotDraw, See link for proof:http://www.bbc.com/news/uk-england-london-26627075, I donated One MillionPounds{?1000,000.00} to you as a gift,respond for more information.;this my email contact moreinformation, Contact: ntrotterdonation@gmail.com

Email analysis :

NOTE : ntrotterdonation@gmail.com
NOTE : bobby@ustc.edu
NOTE : FUNDS DONATION
NOTE : Return-Path : < bobby@ustc.edu >
NOTE : X-Originating-Ip : [41.216.50.160]


NOTE : Mime-Version : 1.0
NOTE : Content-Type : text/plain; charset=GBK
NOTE : Received : from unknown (HELO ustc.edu) (218.22.21.7)


NOTE : Received : from 41.216.50.160 ( 41.216.50.160 [41.216.50.160] )


NOTE : by ajax-webmail-mail.ustc.edu (Coremail) ;
NOTE : Sat, 19 Mar 2016 07:58:04 +0800 (CST)

Notes from Scam.cz :


- USTC.EDU servers were used to relay this scam.
- USTC is the University Of Science and Technology of China
- Account used during this scam was "bobby"

Rép : YOUR COMPENSATION PAYMENT

Dear friend,

I'm sorry but happy to inform you about my success in getting those funds transferred under the cooperation of my new partner from Sweden who financed it to a logical conclusion. though I tried my best to involve you in the business but God decided the whole situation. Presently I am in Sweden for investment projects with my own share of the total sum. Meanwhile, I didn't forget your past efforts and attempts to assist me in transferring those funds despite that it failed us somehow. Due to your effort, sincerity, courage and trustworthiness you showed during the course of the transaction I want to compensate you and show my gratitude to you. My dear friend I will like you to contact Dr Lucas Baldwin, i have authorized him to release your compensation payment which i kept for your compensation for all the past efforts and attempts to assist me in this matter. I appreciated your efforts at that time very much. Please I will like you to accept this little token and get in touch with Dr Lucas Baldwin so he can release your compensation fund to you without delay.

NAME: Dr Lucas Baldwin
EMAIL: drlucasbaldwin@gmail.com

Please do let me know immediately you receive it so that we can share the joy after all the sufferings at that time. In the moment, I am very busy here because of the investment projects which I and my new partner are having at hand, i may not reply to any email for some time.

Best Regards

Ken C. Walker

Email analysis :

NOTE : chris.chudi@virgin.net
NOTE : X-Originating-Ip : 64.184.2.5
NOTE : X-Mailer : Open-Xchange Mailer v7.6.2-Rev46
NOTE : client-ip=212.54.57.96;
NOTE : Received : from oxbe19.tb.ukmail.iss.as9143.net ([172.25.160.150])

Sunday, March 20, 2016

Sehr geehrter Kunde, (Zürcher Kantonalbank Phishing)

Sehr geehrter Kunde,

kürzlich zeigten unsere Aufzeichnungen, dass Ihr Zürcher Kantonalbank -Konto durch einen Dritten unbefugten Zutritt hatte. Die Sicherheit Ihres Kontos ist unser wichtigstes Anliegen. Deshalb haben wir beschlossen, den Zugang zu Ihrem Konto vorübergehend zu begrenzen. Für den vollen Zugang zu Ihrem Konto, müssen Ihre Daten wiederhergestellt werden, daher bestätigen Sie Ihr Konto über diesen Link: http://apartment808.com.au/g/public_html/index.html

Sobald Ihre Angaben überprüft und bestätigt ist, erhalten Sie eine Anruf aus von uns. Und somit wird auf Ihr Konto wieder komplettes Zugreifen wiederhergestellt. Wir danken Ihnen für Ihre Kooperation.

Mit freundlichen Grüßen,
Zürcher Kantonalbank AG
Bahnhofstrasse 45 8001 Zurich

Zürcher Kantonalbank CH-8098 Zurich
SWIFT (BIC): ZKBWCHZH
BIC: UBSWCHZH80A

Phishing analysis :

CLICK : http://apartment808.com.au/g/public_html/index.html
NOTE : The page was inaccessible

Email analysis :

NOTE : info@admin.com
NOTE : Mime-Version : 1.0
NOTE : Content-Disposition : inline
NOTE : Content-Transfer-Encoding : quoted-printable
NOTE : sf.bg.ac.rs
NOTE : Received : from sf.sf.bg.ac.rs (sf.bg.ac.rs. [147.91.232.1])


NOTE : Received : from 105.112.10.229 ([105.112.10.229]) by webmail.sf.bg.ac.rs (Horde Framework)


NOTE : client-ip=147.91.232.1;
NOTE : User-Agent : Horde Application Framework 5
NOTE : Sehr geehrter Kunde,

Notes from Scam.cz

- Phishing was against Zürcher Kantonalbank users. (https://www.zkb.ch/)


- University of Belgrade was used to relay this phishing. (http://www.bg.ac.rs/)
- Work in progress for (http://apartment808.com.au/g/public_html/index.html)