Tuesday, June 28, 2016

vous avez un nouveau ✉ (Phishing CIC)

CI C

Cher(e) Client(e),

Lors de votre dérnier achat, vous avez été averti par un message vous informant de l'obligation d'adhérer à la nouvelle réglementation concernant la fiabilité pour les achats par C.B sur internet et de la mis en place d'un arrét pour vos futurs achats

Or, nous n'avons pas, ce jour , d'adhésion de votr part et nous sommes ou regret de vous informer que vous pouvez plus utiliser votr cart sur internet

Adhésion : cIiquant ici

Merci de la confiance que vous nous témoignez

Cordialement

Conseil d'administration

Email screenshot :


Email analysis :

NOTE : mdl@geosoc.fr
NOTE : Content-Type : text/html; charset=iso-8859-1
NOTE : Return-Path : < www-data@geosoc.fr >
NOTE : Received : from geosoc.fr ([84.39.46.170])
NOTE : Received : by geosoc.fr (Postfix, from userid 33)
NOTE : X-Php-Originating-Script : 0:lkhourza.php
NOTE : Message-Id : < 20160628050458.0648121078@geosoc.fr >
NOTE : vous avez un nouveau ✉

Phishing analysis :

CLICK : Adhésion : cIiquant ici
OPEN : http://royalapparels.com/cgi/
REDIRECT : http://marcellocampos.com.br/loja/magmi/state/-/mpl/lpf/zero/normal42/accorde/*
REDIRECT : http://marcellocampos.com.br/loja/magmi/state/-/mpl/lpf/zero/normal42/accorde/*/lb.php?id=*&default=*
SCREENSHOT :


CLICK : OK
SCREENSHOT :


NOTE : ANALYSIS WITH NO REDIRECT IF THE PASSWORD IS WRONG

Domain analysis : marcellocampos.com.br

domain: marcellocampos.com.br
owner: Marcelo Campos
responsible: Turbo Web Internet
country: BR
owner-c: MAACA45
admin-c: ZAB
tech-c: WAA218
billing-c: MAACA45
nserver: nsbra16.hostgator.com.br
nsstat: 20160627 AA
nslastaa: 20160627
nserver: nsbra17.hostgator.com.br
nsstat: 20160627 AA
nslastaa: 20160627
created: 20070704 #3724896
expires: 20220704
changed: 20150719
status: published
nic-hdl-br: MAACA45
person: Marcelo Andr? de Campos
created: 20070109
changed: 20160126
nic-hdl-br: WAA218
person: Willianson de Almeida Araujo
created: 20050409
changed: 20130401
nic-hdl-br: ZAB
person: Zilda Aparecida Bagattini
created: 19971223
changed: 20151230

Monday, June 27, 2016

Dr. David Patrick

Read carefully ,

This is to inform you that International Monetary Fund IMF is compensating all the scam victims $2.700,000.00USD each, and your email address was found in the scam victim's list. This Western Union head office has been mandated by the IMF Director to transfer your compensation fund to you via Western Union Transfer Daily. We the western union office here stated that you will be receiving your fund $2.700.000.00 at the maximum of $5,000.00 daily until the whole money is completely transfer to you. We have sent out your first payment $5,000 but it placed on hold because your payment is not yet activated. BELOW IS YOUR FIRST PAYMENT $5,OOO.OOUSD but still on hold

MTCN#________________________ 8860-3341-09#
Sender’s First Name:------- David
Sender’s Last Name:------Patrick
Sender’s Location:------- Seattle,Benin Republic
Amount sent:------- $5000

Remember we need your full information as where we will be sending the funds, such as to avoid wrong transfer,

Receiver name:-________
Address:-__________
Country:-____________
Phone number:-_____________

Note that you are not expected to pay for transfer charges all the fee has been paid by International Monetary Fund the depositor. The only fee you will you send before you will start picking up your daily payment $5,000.00 as it was sign is only $105.00 for the activation of your western union payment transfer files. Note that your payment files will be returned to the IMF within 72 hours if we did not hear from you, this was the instruction given to us by the IMF.

Contact us Below:westernunionm4@gmail.com
Call me now +229-98151176

Thanks,
Dr.David Patrick
The Western Union Director Benin Republic
Call me now +229-98151176

Email analysis :

NOTE : westernunionm4@gmail.com
NOTE : massage.@ocn.ne.jp
NOTE : X-Originating-Ip : [104.167.217.234]

Steiner, D Ms : Dir NEPAD, Africa Multilateral, DIRCO

Hello, can i share with you a business? kindly reply!! (sergio_bed111@163.com)

Disclaimer: This email and files transmitted with it contain confidential and privileged information and are intended solely for the use of the individual or entity to which they are addressed. If you have received this email in error please -

- do not read, disseminate, distribute, copy or take action in reliance on this email and
- delete it immediately and arrange for the deletion thereof on your server, and
- notify the administrator of the Department of International Relations and Cooperation at postmaster@dirco.gov.za immediately.

Any unauthorised, use duplication or interception of this e-mail or any files transmitted with it is expressly and strictly prohibited. No representation, guarantee or undertaking (expressed or implied) is made or given

- As to the confidentiality or security of the e-mail system' Or
- As to the accuracy of the information in this email and any files transmitted with it is virus-free.

No responsibility or liability is accepted for:

- the proper, complete transmission of the information contained in this email or any files transmitted with it or any delay in its receipt; or rising from or as a result of the use of or reliance on the content of this email or any files transmitted with it. Any views expressed in this email or any files transmitted with it are not necessarily the views of the Department of International Relations and Cooperation. Queries regarding this emails or any files transmitted with it, should be directed to postmaster@dirco.gov.za.

This disclaimer forms part of the content of this e-mail for purposes of section 11 of the Electronic Communications and Transactions Act, 2002 (Act No. 25 of 2002)

Email analysis :

NOTE : SteinerD@dirco.gov.za
NOTE : Content-Language : en-ZA
NOTE : Mime-Version : 1.0
NOTE : client-ip=196.14.41.164;

FW: Your Shipping Documents (DHL Phishing)

Shipping Documents Receiver's eMail: ***@***.com

Greetings,

As instructed by your shipper, we have attached below the secured PDF copies of your shipping documents and your shipment tracking details from our international logistic partner, DHL Epress.

Click Here To View Your Documents And Shipment Tracking Details : www.dhl.com/documents/0094325.pdf

At Co-Logistics we offer best Service Delivery Commitment with shipper & client.

*´¨)
¸.• ´¸.•*´¨) ¸.•*¨)
(¸.•´ (¸.•'* Best Regards
(¸.•'* .•*´¨)
Smith Wan *
(¸.•'*
Sales Excutive

Cooperate Logistics Co.,Ltd
************************

Head Office
Rm 2401-2502,Guidu Bld, Chungfeng Rd,
Luohu, Shenzhen, China
Phone: (86) 755 88863799
Email: info@co-logistics.com
URL: www.co-logistics.com
Image result for Carrier: DHL FedEx UPS TNT

Phishing analysis :

CLICK : www.dhl.com/documents/0094325.pdf
REDIRECT : http://namaren.com/jyg/DHL/tracking.php?userid=***@***.com

Email analysis :

NOTE : jbarba@morsco.com
NOTE : Mime-Version : 1.0
NOTE : X-Originating-Ip : [14.139.59.197]


NOTE : client-ip=157.56.111.70;

Phyllis  Riccia

Greetings, We've obtained your details from career builder Inc, Database, and considered you as an ideal representative for the HOME-BASED job position detailed below. I am Mr Phyllis  Riccia, Chief Executive Officer of Equator Oil and Gas Ltd. We are an OPEC member that deals on crude oil, raw materials and export to Canada, United Kingdom, America,Europe and Asia.We are searching for receiving/payment officer who can help us establish a medium of getting to our customers as well as making payments through you to us. Also as part of our vision to help in eradicating JOBLESSNESS in the global world. We are now seeking qualified personnel to be our company offshore REPRESENTATIVE. We would like to use this medium to inform you that a vacant position exists for you in our CREDIT and PAYMENT COLLECTION DEPARTMENT. Export Company. Fill the details below FULL NAME................. FULL HOME ADDRESS.......... CITY....... STATE..... ZIP CODE.... AGE... PHONE/FAX NUMBERS............ OCCUPATION................. Mr Barriter Christian Paul Chief Executive Officer Equator Oil and Gas Ltd. N:B:  All we need is your Trust, Honesty & Communication.    Mr, Phyllis  Riccia.

Email analysis :

NOTE : phriccia@yahoo.com
NOTE : ricciap@yahoo.com
NOTE : X-Yahoo-Newman-Property : ymail-3
NOTE : Mime-Version : 1.0
NOTE : 98.138.91.114

Private Discussion

Hello,
I am looking for a joint business partner to invest $ 26 million value.

Find my private e-mail: jo853268074_3442145@yahoo.com , to reply if you are interested.

Dr. Jorasse

Email analysis :

NOTE : emp.tihc@yahoo.ca
NOTE : info@expo-viagens.pt
NOTE : client-ip=213.13.175.87;


NOTE : Received : from [192.168.8.100]
NOTE : (unknown [41.85.189.163])