Friday, December 8, 2017

Agent

To whom it may concern:

We bring you genuine and certified credit offer. Contact us for more details if you are honestly interested please. You can send a whatsapp message for more info at +91-720-433-5745

Email analysis :

NOTE : maryjaynewise2342@gmail.com
NOTE : Received : from unknown (HELO acsgsemail1.acsgs.com)
NOTE : ([65.248.101.241])

Thursday, March 2, 2017

Congratulation !!!

Congratulation !!! You have just won 2,000,000 euro contact Fiduciary agent on this
Email now for more details. Email: guanchen14@gmail.com

Email analysis :

NOTE : guanchen14@gmail.com
NOTE : ing06@fbb.3a.net.tw
NOTE : X-Mailer : OpenWebMail 2.53
NOTE : client-ip=61.57.159.141;


NOTE : X-Originatingip : 78.135.24.25 (ing06)

Monday, December 7, 2015

Kevin Michael

Attention Dear,

We have deposited the check of your fund ($4.800`000`00USD) through Western Union department after our finally meeting regarding your fundS, All you will do is to contact Western Union director Mr.Anthony Kevin via E-mail( manager.westernuniontransfer@mail.ru ) He will give you direction on how you will be receiving the funds daily, remember to send him your Full information to avoid wrong transfer such as,

Receiver's Name_______________
Address: ________________
Country: _____________
Phone Number: _____________

Though, Mr.Anthony Kevin has sent $4500 in your name today so contact Mr.Kevin Michael or you call him +229-68709787 as soon as you receive this email and tell him to give you Western Union Ref. pin number, sender name to pick the $4500 only per day, and the only fee you are to send is $79 usd.

Best Regards.
Western Union Agent

Email analysis :

NOTE : good-news@cantv.net
NOTE : philtermeh@gmail.com
NOTE : manager.westernuniontransfer@mail.ru
NOTE : Received : from 41.222.194.237 ([41.222.194.237])
NOTE : by webmail-03.datacenter.cha.cantv.net (Cantv Webmail) with HTTP;

Wednesday, November 18, 2015

Attention,

You are to contact western union (UN) has taken over the Inheritance/Prize Winning payment issue which you currently or previously had with your transaction agents. based on the fact that you where subjected to too many processes that will make you spend more money before receiving your funds.

The Management of the Western Union Payment Center, Benin has designated that the amount be remitted to you via our Daily Limit Payment of $5000 USD. Please provide your Full Name, Address, Phone Numbers to Western Union Coordinating officer:

Mr. Simon Bontus
info-western-union@barid.com
+229-99610517

Email analysis :

NOTE : zzbhsbus@gmail.com
NOTE : mr.davidhassn24@cantv.net
NOTE : info-western-union@barid.com
NOTE : X-Matched-Lists : []
NOTE : X-Originating-Ip : [41.216.41.3]
NOTE : Mime-Version : 1.0
NOTE : Content-Transfer-Encoding : 7bit
NOTE : X-Mailer : Cantv Webmail
NOTE : Received : from 10ibl20ser04.datacenter.cha.cantv.net
NOTE : (10ibl20ser04.datacenter.cha.cantv.net. [200.11.173.11])
NOTE : Received : from webmail-05.datacenter.cha.cantv.net
NOTE : (webmail-05.datacenter.cha.cantv.net [200.11.153.88]) (authenticated bits=0)
NOTE : by 10ibl20ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0)
NOTE : Received : from 41.216.41.3 ([41.216.41.3])
NOTE : by webmail-05.datacenter.cha.cantv.net (Cantv Webmail)
NOTE : Attention,

Monday, August 31, 2015

Notice to Appear

Notice to Appear,

This is to inform you to appear in the Court on the September 02 for your case hearing. You are kindly asked to prepare and bring the documents relating to the case to Court on the specified date.

Note: The case may be heard by the judge in your absence if you do not come.

The copy of Court Notice is attached to this email.

Regards,
Gary Noble,
Court Secretary.

000475484.zip

File analysis :

OPEN : 000475484.zip
RESULT : File is a virus.

Virus analysis :

SHA256 : 0c8d2b8cba6611097793124c3dac9e9313207ba8857b41330ca021c89f52c82f
ALYac : JS:Trojan.JS.Downloader.AN
AVG : JS/Downloader.Agent
AVware : Malware.JS.Generic (JS)
Ad-Aware : JS:Trojan.JS.Downloader.AN
Arcabit : JS:Trojan.JS.Downloader.AN
Avast : JS:Agent-DOB [Trj]
BitDefender : JS:Trojan.JS.Downloader.AN
CAT-QuickHeal : JS.Downloader.Z
Comodo : Heur.Dual.Extensions
DrWeb : SCRIPT.Virus
ESET-NOD32 : JS/TrojanDownloader.Nemucod.AV
Emsisoft : JS:Trojan.JS.Downloader.AN (B)
F-Secure : JS:Trojan.JS.Downloader.AN
Fortinet : JS/Agent.CPL!tr
GData : JS:Trojan.JS.Downloader.AN
Kaspersky : Trojan-Downloader.JS.Agent.hhe
McAfee : JS/Nemucod.c
McAfee-GW-Edition : JS/Nemucod.c
Microsoft : TrojanDownloader:JS/Nemucod.P
NANO-Antivirus : Trojan.Script.Agent.dtchtk
Rising : NORMAL:Trojan.DL.Script.JS.Nemucod.b!1616509[F1]
Sophos : JS/DwnLdr-MON
VIPRE : Malware.JS.Generic (JS)
nProtect : JS:Trojan.JS.Downloader.AN

Email analysis :

NOTE : Notice to Appear
NOTE : gary.noble@wayneshostingworld.co.uk
NOTE : Received : from doggroom by server.wayneshostingworld.co.uk with local (Exim 4.85)
NOTE : Received : from server.wayneshostingworld.co.uk (wayneshostingworld.co.uk. [78.129.234.106])
NOTE : X-Php-Script : doggroomingparlour.co.uk/post.php for 77.111.207.70

Thursday, August 27, 2015

Indebtedness for driving on toll road #000948265 (Virus)

Notice to Appear,

You have not paid for driving on a toll road.
You are kindly asked to pay your debt as soon as possible.

The copy of the invoice is attached to this email.

Sincerely,
Thomas Gorman,
E-ZPass Agent.

E-ZPass_Invoice_000948265.zip

File analysis :

OPEN FILE : E-ZPass_Invoice_000948265.zip
RESULT : FILE IS A VIRUS

Virus analysis :

SHA256 : 5ec5b13bbf1d2a2179168acfaec53da59afa6b8ca480930e1b56d996b51dd140
ALYac : JS:Trojan.JS.Downloader.AN
AVG : JS/Downloader.Agent
AVware : Malware.JS.Generic (JS)
Ad-Aware : JS:Trojan.JS.Downloader.AN
Arcabit : JS:Trojan.JS.Downloader.AN
Avast : JS:Agent-DOB [Trj]
BitDefender : JS:Trojan.JS.Downloader.AN
CAT-QuickHeal : JS.Downloader.Z
Comodo : Heur.Dual.Extensions
DrWeb : SCRIPT.Virus
ESET-NOD32 : JS/TrojanDownloader.Nemucod.AS
Emsisoft : JS:Trojan.JS.Downloader.AN (B)
F-Secure : JS:Trojan.JS.Downloader.AN
Fortinet : JS/Agent.CPL!tr
GData : JS:Trojan.JS.Downloader.AN
Kaspersky : Trojan.JS.Agent.cpl
McAfee : JS/Nemucod.c
McAfee-GW-Edition : JS/Nemucod.c
MicroWorld-eScan : JS:Trojan.JS.Downloader.AN
Microsoft : TrojanDownloader:JS/Nemucod.P
NANO-Antivirus : Trojan.Script.Agent.dtchtk
Rising : NORMAL:Trojan.DL.Script.JS.Nemucod.b!1616509[F1]
Sophos : JS/DwnLdr-MON
VIPRE : Malware.JS.Generic (JS)
nProtect : JS:Trojan.JS.Downloader.AN

Email analysis :

NOTE : thomas.gorman@jerusalem.hostyou.com.br
NOTE : client-ip=104.238.195.142;
NOTE : Sender Address Domain - jerusalem.hostyou.com.br
NOTE : X-Source-Args : /usr/bin/php /home/centova/public_html/coisaseria.com.br/post.php
NOTE : < centova@jerusalem.hostyou.com.br >
NOTE : Mime-Version : 1.0
NOTE : X-Source-Dir : centova.com:/public_html/coisaseria.com.br
NOTE : X-Priority : 3
NOTE : X-Get-Message-Sender-Via : jerusalem.hostyou.com.br:
NOTE : authenticated_id: centova/primary_hostname/system user
NOTE : X-Source : /usr/bin/php
NOTE : Received : by 10.202.17.82 with SMTP
NOTE : Received : from centova by jerusalem.hostyou.com.br
NOTE : Indebtedness for driving on toll road #000948265

Monday, January 19, 2015

RE: %^01!?#15 ..Work as our receiver agent

Comfort International Co. Ltd.
Ningbo, 315100, China

Hello!

We introduce our company to you: Comfort International Co. Ltd. A company based in Asia which deals in Leather fabrics production, marketing, supplies and consultancy services world wide.

We need a reliable agent to act on our behalf. As an individual, would you be interested in acting as our independent receiver agent in your country on a part-time basis. As an individual all you have to do is receive funds on our behalf. The mode of payment from our clients, customers, business entities or individuals will usually be in the form of direct deposits. For rendering this valuable service you get to earn a flat 7.5% - 10% commission on whatever amount you receive per transaction and remit the rest to us according to our payment instructions. You can earn commission on deposits from $2,000 upto $50,000 and maybe higher under certain terms. Please Note: you are NOT paying for anything. I hope that is very clear. No academic or work experience of any sort is required to assist our interest. We only require your cooperation, honesty and reliability. This is a part-time thing. Very simple and straight forward.

However, for us to accept you;

You must adhere to our policies and be willing to assist our interests to the best of your ability. This is a great way for you to earn some money as an addition considering the tough economic climate globally. If you are interested in our offer then send us your response, include your full names and contact cell phone number and we will get back to you.

Thank you for your time.

Regards,
Ms. Jiao Hung

noreply@f088.deltashore.net