Monday, November 18, 2019

Good day,

NOTE: Yet another bulk spammer hiding behind a free email address so you won't really know who they are. Too ashamed to show, but hey, here's an offer of millions from a stranger on the internet who is afraid to tell the truth and show who they really are. Why would a criminal give up their identity willingly?  They won't. This one will lie to you right until the very end. The very end should be you deleting this and not exerting any energy to responding to such preposterous claims. In case one anonymous free email wasn't enough it gets sent from one and you are asked to respond to an entirely different one.  If you don't think this entire thing is suspicious, play into this thief, you'll learn. The hard way, but you will learn and wish it was a lesson you never even explored.


From: "Mr. RICHARD STEVE" <renittwerfff111@gmail.com> To: undisclosed-recipients:;04:18:16 CST, Monday 18 November 2019
Attachments: None
Message ID: <CAHeBqBDejhMrFouYPhPovYD3SOZeCi-eaiYsswBexzHdY28EhA@mail.gmail.com>
Return Path: <renittwerfff111@gmail.com>
Reply To: steverichard802@yahoo.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="000000000000fcc69705979c4340"
Attachments:
None
Received:
from mx1-us4.ppe-hosted.com (unknown [10.7.66.39]) by pure.maildistiller.com with ESMTPS id 2DDFA1A004D for <>; Mon, 18 Nov 2019 10:18:16 +0000 (UTC)

from mail-vk1-f196.google.com (mail-vk1-f196.google.com [209.85.221.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 072058005E for <>; Mon, 18 Nov 2019 10:18:16 +0000 (UTC)

by mail-vk1-f196.google.com with SMTP id p78so2785334vkp.8 for <>; Mon, 18 Nov 2019 02:18:15 -0800 (PST)


Good day,
I am Mr. RICHARD STEVE, the Director Bills & Exchange. I personally discovered a dormant account with a total sum of $39,000,000.00 (THIRTY-NINE MILLION

UNITED STATE DOLLARS) during our Bank's Annual Year Account Auditing.

The owner of this dormant account died on 8th December 2009. Since the death of the deceased, nobody has operated in this account till date. Moreover,

this account has NO BENEFICIARY attached to it. Definitely, this fund will be confiscated by our BANKING CODE OF ETHICS if it remains dormant for a period of

(10) years without any claims. In this regard, I earnestly need your full cooperation in transferring this dormant fund out of our bank to avoid confiscating

this fund. I will split the transfer into two 2 stages for easy and smooth transfer.

First, I will transfer $9,000,000.00 to any valid foreign account you will nominate, upon a successful transfer without any disappointment from your side, I

will then fly to meet you in your home destination for sharing, and thereafter we jointly transfer the remaining balance of $30,000,000.00 for the magnitude

investments.

Note that you are required to furnish me with the requested information's bellow immediately;

(1)Full names.
(2)Contact address.
(3)Telephone and fax numbers.
(4)Location.

Please note that you are required to keep this transaction very confidential. also you have the same last name with

my late client which will enable us move

this funds without much protocol or suspect from the bank.
Yours truly,

 Mr. RICHARD STEVE

contact me at email  steverichard802@yahoo.com



Envelope Sender: <renittwerfff111@gmail.com>
'From' Header: "Mr. RICHARD STEVE" <renittwerfff111@gmail.com>
Subject: Good day,
Timestamp: 04:18:16 CST, Monday 18 November 2019
Message-ID: <CAHeBqBDejhMrFouYPhPovYD3SOZeCi-eaiYsswBexzHdY28EhA@mail.gmail.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 209.85.221.196
Client GeoIP Lookup: United States
Email Size: 6.5 kB
Encrypted? No

Contact the Courier.

NOTE: Not one to give up, our new frenemny "Agent Frederick Janssen", within 3 days, went from China to Indonesia and must have run out of VPN steam since with this missive, he/she/it is still in Indonesia, sending the same worn out copy/paste email scam with just a different subject. This criminal is persistent, but still reusing a worn out, tired, raggedy, lying scam email. This email and its sender is phishing for idiots. Be smart and delete these thieving morons.  Don't be played for a fool, don't lose your identity and money over this, just trash these.


From: "Agent Frederick Janssen" <janssenf339@gmail.com> To: 02:32:58 CST, Monday 18 November 2019
Attachments: None
Message ID:
Return Path: <janssenf339@gmail.com>
Reply To: topchrono@citromail.hu
MIME Version: 1.0
Content Type: text/plain; charset="iso-8859-1"
Attachments:
None
Received:
from mx1-us4.ppe-hosted.com (unknown [10.7.66.41]) by pure.maildistiller.com with ESMTPS id 5BC4C1A0051 for <>; Mon, 18 Nov 2019 08:32:58 +0000 (UTC)

from mailborder-in.ptp.co.id (unknown [103.244.245.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 1F03C4C0059 for <>; Mon, 18 Nov 2019 08:32:58 +0000 (UTC)

from [185.162.235.209] (unknown [10.202.253.215]) by mailborder-in.ptp.co.id (Postfix) with ESMTP id EACB313063E for <>; Sun, 17 Nov 2019 09:10:11 +0700 (WIB)


IMMEDIATE RELEASE OF YOUR TOTAL FUND OF $7.5 MILLION US DOLLARS I am Agent Frederick Janssen,an INTERPOL Special Agent and this is to inform you that I was sent down to Benin Republic to secure the release of your fund which has now been credited into an ATM Card by the issuing bank. This decision was taken to assist you secure your fund safely and prevent you from dealing with internet scammers who may claim to be in possesion of your money. The bank has now handed over your package to Topchrono Courier and you have to send them details now for the delivery; Your Full names................... Address........................... Telephone number.................. Contact email; topchrono@citromail.hu I will be waiting for your prompt feedback because I have few days more to stay here before going back to United States Agent Frederick Janssen INTERPOL SPECIAL AGENT


Envelope Sender: <janssenf339@gmail.com>
'From' Header: "Agent Frederick Janssen" <janssenf339@gmail.com>
Subject: Contact the Courier.
Timestamp: 02:32:58 CST, Monday 18 November 2019
Message-ID:
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
SPF (SoftFail) Medium

Client IP Address: 103.244.245.21
Client GeoIP Lookup: Indonesia
Email Size: 2.8 kB
Encrypted? No

your atm card is with the courier..

NOTE: First this one sends an email with the subject all in caps: "URGENT". To days later the same "Agent Frederick Janssen" has gone from China all the way to Indonesia to inform the reader, falsely, that there's some magic atm card ready for them. This criminal is still hiding behind anonymous email addresses that don't cost a thing. Wait, this one sent another one yet from the same email address a day after this one came in. The only differences between these emails are the VPN location and the subject line. Yep, this one is playing his/her/its recipients as complete idiots.


From: "Agent Frederick Janssen" <janssenf339@gmail.com> To: 13:56:46 CST, Sunday 17 November 2019
Attachments: None
Message ID:
Return Path: <janssenf339@gmail.com>
Reply To: topchrono@citromail.hu
MIME Version: 1.0
Content Type: text/plain; charset="iso-8859-1"
Attachments:
None
Received:
from mx1-us1.ppe-hosted.com (unknown [10.110.49.30]) by pure.maildistiller.com with ESMTPS id DCBA440052 for <>; Sun, 17 Nov 2019 19:56:45 +0000 (UTC)

from mailborder-in.ptp.co.id (unknown [103.244.245.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us1.ppe-hosted.com with ESMTPS id 9750A140061 for <>; Sun, 17 Nov 2019 19:56:45 +0000 (UTC)

from [185.162.235.209] (unknown [10.202.253.215]) by mailborder-in.ptp.co.id (Postfix) with ESMTP id 0D43F12C3F1 for <>; Sun, 17 Nov 2019 07:39:32 +0700 (WIB)


IMMEDIATE RELEASE OF YOUR TOTAL FUND OF $7.5 MILLION US DOLLARS I am Agent Frederick Janssen,an INTERPOL Special Agent and this is to inform you that I was sent down to Benin Republic to secure the release of your fund which has now been credited into an ATM Card by the issuing bank. This decision was taken to assist you secure your fund safely and prevent you from dealing with internet scammers who may claim to be in possesion of your money. The bank has now handed over your package to Topchrono Courier and you have to send them details now for the delivery; Your Full names................... Address........................... Telephone number.................. Contact email; topchrono@citromail.hu I will be waiting for your prompt feedback because I have few days more to stay here before going back to United States Agent Frederick Janssen INTERPOL SPECIAL AGENT


Envelope Sender: <janssenf339@gmail.com>
'From' Header: "Agent Frederick Janssen" <janssenf339@gmail.com>
Subject: your atm card is with the courier..
Timestamp: 13:56:46 CST, Sunday 17 November 2019
Message-ID:
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
SPF (SoftFail) Medium

Client IP Address: 103.244.245.21
Client GeoIP Lookup: Indonesia
Email Size: 2.8 kB
Encrypted? No

Proposal

NOTE: This funny one is using a Chinese name, a South African VPN and telling you they're from Japan. What a geographic trip this is without even leaving your home/office. First free email this criminal hides behind is based out of New York (Squarespace), then there's the free email address from Russia (yandex.com). These crooks hide like this because they know they don't have millions to give random strangers on the internet. They just hope your naive and gullible enough to give them your information, while you think you're going to get rich for nothing (don't be greedy), meanwhile you'll be stolen from in ways that will hurt you can't even imagine. Delete these financial criminals. Only lying thieves promise such outrageousness.


From: "Kim Sue-Kim" <rentia@gns.co.za> To: 20:06:53 CST, Saturday 16 November 2019
Attachments: None
Message ID:
Return Path: <rentia@gns.co.za>
Reply To: kimsuekim@yandex.com
MIME Version: 1.0
Content Type: text/plain; charset="iso-8859-1"
Attachments:
None
Received:
from mx1-us1.ppe-hosted.com (unknown [10.7.66.30]) by pure.maildistiller.com with ESMTPS id 7A98C14004D for <>; Sun, 17 Nov 2019 02:06:52 +0000 (UTC)

from mdaemon.gns.co.za (mdaemon1.gns.co.za [196.15.170.158]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us1.ppe-hosted.com with ESMTPS id D006E100077 for <>; Sun, 17 Nov 2019 02:06:49 +0000 (UTC)

from user-PC.wifi [(41.113.26.187)] by mdaemon.gns.co.za (196.15.170.158) (MDaemon PRO / Cloud v18.0.2) with ESMTP id md50029458425.msg; Sun, 17 Nov 2019 04:04:19 +0200


For your attention My Name is Kim Sue-Kim from Japan .I have your contact information through international public records while searching for reliable and trustworthy person for an urgent proposal worth $2.5 Million for your own consideration. Please kindly let me know via kimsuekim@yandex.com. Best regards, Mr. Kim Sue-Kim


Envelope Sender: <rentia@gns.co.za>
'From' Header: "Kim Sue-Kim" <rentia@gns.co.za>
Subject: Proposal
Timestamp: 20:06:53 CST, Saturday 16 November 2019
Message-ID:
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Low

Client IP Address: 196.15.170.158
Client GeoIP Lookup: South Africa
Email Size: 1.7 kB
Encrypted? No

URGENT.

NOTE: Someone from China, providing a very fake, very American name to a very scammy email from a free, anonymous email address. This crook is promising thousands of internet strangers millions of dollars.  How outrageous can this get before they finally stop treating their public like complete idiots? It will stop when people receiving these stop acting like idiots and giving them the information they ask for!!!  No one is ever going todrop millions in your lap, much less a stranger with no accountability emailing from an internet cafe or mom's basement/garage. This criminal thinks they're in a get rich quick scheme, get rich by ripping off innocent people. Delete these crooks, don't be part of this crime.


From: "Agent Frederick Janssen"<janssenf339@gmail.com> To:19:14:12 CST, Friday 15 November 2019
Attachments: None
Message ID:
Return Path: <janssenf339@gmail.com>
Reply To: <topchrono@citromail.hu>
MIME Version: 1.0
Content Type: text/plain; charset="Windows-1251"
Attachments:
None
Received:
from mx1-us1.ppe-hosted.com (unknown [10.7.66.33]) by pure.maildistiller.com with ESMTPS id 33B7F1A0055 for <>; Sat, 16 Nov 2019 01:14:12 +0000 (UTC)

from mail.kaisenbaoxian.com (unknown [123.139.57.206]) by mx1-us1.ppe-hosted.com with ESMTP id EC6CEA8006D for <>; Sat, 16 Nov 2019 01:14:11 +0000 (UTC)

from User (unknown [185.162.235.209]) by mail.kaisenbaoxian.com (Postfix) with SMTP id 163AA423DC; Fri, 15 Nov 2019 18:34:58 -0500 (EST)


IMMEDIATE RELEASE OF YOUR TOTAL FUND OF $7.5 MILLION US DOLLARS I am Agent Scott Simpson,an INTERPOL Special Agent and this is to inform you that I was sent down to Benin Republic to secure the release of your fund which has now been credited into an ATM Card by the issuing bank. This decision was taken to assist you secure your fund safely and prevent you from dealing with internet scammers who may claim to be in possesion of your money. The bank has now handed over your package to Topchrono Courier and you have to send them details now for the delivery; Your Full names................... Address........................... Telephone number.................. Contact email; topchrono@citromail.hu I will be waiting for your prompt feedback because I have few days more to stay here before going back to United States Agent Frederick Janssen INTERPOL SPECIAL AGENT


Envelope Sender: <janssenf339@gmail.com>
'From' Header: "Agent Frederick Janssen"<janssenf339@gmail.com>
Subject: URGENT.
Timestamp: 19:14:12 CST, Friday 15 November 2019
Message-ID:
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 123.139.57.206
Client GeoIP Lookup: China
Email Size: 1.9 kB
Encrypted? No

Friday, November 15, 2019

CONFIRM THIS PLEASE

NOTE: Because being demanding and pushy in the subject line must be yielding positive results? Or is this criminal just as desperate as he/she/it sounds? Most likely desperate to gain maximum return for minimal work: stealing from others. This is a phishing email sent by a criminal. Don't fall for it, rather delete and ban these thieves and cowards.


From: Mark Williams <rita.okoro@yahoo.fr> To:08:45:56 CST, Friday 15 November 2019
Attachments: None
Message ID: <423782302.1366664.1573829145723@mail.yahoo.com>
Return Path: <rita.okoro@yahoo.fr>
Reply To: mark679williams@gmail.com
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Attachments:
None
Received:
from mx1-us5.ppe-hosted.com (unknown [10.110.50.12]) by pure.maildistiller.com with ESMTPS id 2EE684006B for <>; Fri, 15 Nov 2019 14:45:56 +0000 (UTC)

from sonic304-22.consmr.mail.ir2.yahoo.com (sonic304-22.consmr.mail.ir2.yahoo.com [77.238.179.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us5.ppe-hosted.com with ESMTPS id DFBAB4005C for <>; Fri, 15 Nov 2019 14:45:55 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic304.consmr.mail.ir2.yahoo.com with HTTP; Fri, 15 Nov 2019 14:45:49 +0000


Attention Beneficiary, Did you authorize Maria Davis to claim your $10.5m? Yours faithfully, Mr. Mark Williams


Envelope Sender: <rita.okoro@yahoo.fr>
'From' Header: Mark Williams <rita.okoro@yahoo.fr>
Subject: CONFIRM THIS PLEASE
Timestamp: 08:45:56 CST, Friday 15 November 2019
Message-ID: <423782302.1366664.1573829145723@mail.yahoo.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High

Client IP Address: 77.238.179.147
Client GeoIP Lookup: United Kingdom
Email Size: 3.1 kB
Encrypted? No

Fedex Authorized Ship Center Los Angeles, CA, United States

NOTE: Another genius who tries cramming the body of the email into the subject. Someone must have missed the criminal class on constructing their thieving scam emails.  FedEx never uses gmail accounts to send information, they also aren't all text. Nor would FedEx ask you for personal private information via an unsecured email promising funds that don't really exist. Nope, this is a criminal phishing venture. Another point: Fedex won't call you dear, won't use bad English and misuse capitalization. Right from the get go this email is a scam, just a criminal trying to make to a buck from nothing.


From: MRS HENDERSON ELIZABETH <mrjohnpaul343@gmail.com> To: "ELIZABETH@yahoo.com" <ELIZABETH@yahoo.com>05:59:26 CST, Friday 15 November 2019
Attachments: None
Message ID: <54058.1880.qm@web101912.mail.ssk.yahoo.co.jp>
Return Path: <mrjohnpaul343@gmail.com>
Reply To: MRS HENDERSON ELIZABETH <mrshendersonelizabeth040@gmail.com>
MIME Version: 1.0
Content Type: multipart/alternative; boundary="100747863-1622476865-1573819156=:1880"
Attachments:
None
Received:
from mx1-us5.ppe-hosted.com (unknown [10.7.65.197]) by pure.maildistiller.com with ESMTPS id 4D2C62C0052 for <>; Fri, 15 Nov 2019 11:59:26 +0000 (UTC)

from ns505-vm8.bullet.mail.kks.yahoo.co.jp (ns505-vm8.bullet.mail.kks.yahoo.co.jp [183.79.57.142]) by mx1-us5.ppe-hosted.com with SMTP id D2126A40060 for <>; Fri, 15 Nov 2019 11:59:25 +0000 (UTC)

from [183.79.100.138] by ns505.bullet.mail.kks.yahoo.co.jp with NNFMP; 15 Nov 2019 11:59:18 -0000

from [183.79.100.136] by t501.bullet.mail.kks.yahoo.co.jp with NNFMP; 15 Nov 2019 11:59:18 -0000

from [127.0.0.1] by omp505.mail.kks.yahoo.co.jp with NNFMP; 15 Nov 2019 11:59:18 -0000

(qmail 43673 invoked by uid 60001); 15 Nov 2019 11:59:18 -0000

from [105.112.105.137] by web101912.mail.ssk.yahoo.co.jp via HTTP; Fri, 15 Nov 2019 20:59:16 JST


Fedex Authorized Ship Center Los Angeles, CA, United States ,Closed Opens 9AM Attention, my dear i am your Diplomatic Agent from FEDEX AUTHORIZED SHIP CENTRE. i am contacting you here regarding your fund worth 6.8 million USD only okay, so all i want you to do now is just get back to me with your full information where i can deliver your fund, Here is the information: Your name Your home address your number Your occupation Your age/sex Your country Your ID card Your Email Thanks MRS HENDERSON ELIZABETH


Envelope Sender: <mrjohnpaul343@gmail.com>
'From' Header: MRS HENDERSON ELIZABETH <mrjohnpaul343@gmail.com>
Subject: Fedex Authorized Ship Center Los Angeles, CA, United States ,Closed Opens 9AM Attention, my dear i am your Diplomatic Agent from FEDEX AUTHORIZED SHIP CENTRE. i am contacting you here regarding your fund worth 6.8 million USD only okay, so all i want you
Timestamp: 05:59:26 CST, Friday 15 November 2019
Message-ID: <54058.1880.qm@web101912.mail.ssk.yahoo.co.jp>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 183.79.57.142
Client GeoIP Lookup: Japan
Email Size: 6.5 kB
Encrypted? No

Please Read Carefully NG

NOTE: India, free and anonymous email sender and a demand right in the subject line. These are glaring red flags that this bulk spam email is nothing but garbage. Your best option is to steer clear of these criminals offering millions to some stranger. How unrealistic can you get? Common sense should have you deleting, blocking and banning these emails. They come from criminals who want all of your something for doing nothing but manipulating sensitive and private information from you and your own gullibility. Don't be gullible, don't be stupid like the sender. Delete these, save your finances and save your identity because that's what will be stolen if you give this crook your info. These are BAD NEWS.


From: "Mrs.S.M"<message@insightbb.com> To:01:12:33 CST, Friday 15 November 2019
Attachments: None
Message ID:
Return Path: <message@insightbb.com>
Reply To: <mrs.mh7177@gmail.com>
MIME Version: 1.0
Content Type: text/html; charset="Windows-1251"
Attachments:
None
Received:
from mx1-us5.ppe-hosted.com (unknown [10.7.65.198]) by pure.maildistiller.com with ESMTPS id 04CAC4005A for <>; Fri, 15 Nov 2019 07:12:33 +0000 (UTC)

from server.technoindiauniversity.ac.in (server.technoindiauniversity.ac.in [182.18.161.146]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1-us5.ppe-hosted.com with ESMTPS id A5BD380050 for <>; Fri, 15 Nov 2019 07:12:32 +0000 (UTC)

from [95.174.65.231] (port=53637 helo=User) by server.technoindiauniversity.ac.in with esmtpa (Exim 4.92) (envelope-from <message@insightbb.com>) id 1iUrwU-0007r4-Kh; Wed, 13 Nov 2019 18:10:14 +0530


Hello Friend,

It is after a careful and comprehensive study and analysis of your countrys development and the present investors coming into the country I have decided to invest in your country,thus the reason for this communication. Without wasting much of your time,My names are Mrs.Sarahmina Mohammed married to late Col. Al-Kamal Hamza Mohammed a Libyan who was shot dead during the civil war in Libya.

My late Husband was loyal companion and a business representative to the late President Muammar Muhammad Abu Minyar Al-Gaddafi the former late president of Libya who at one point had a net worth estimated at $200 billion Dollars. Muammar Gaddafi was the longest serving ruler of Libya since the Ottoman Empire, and the longest non-royal ruler still living at the time of his death.

I have Twenty  Million dollars moved from Libya to a financial house in a particular country that i will detail you soon.The funds need an urgent stabilization on the aspect of configuration of the Original owner`s data`s into the Bank system database.I am the only one in direct communication with the financial house and the funds cannot be placed under my name for some good reasons which I will explain in details should  you decide to work with me. The financial house has called on my urgent attention to provide the details of the original owner to enable them create an account and place the funds correctly for possible transfers. Therefore I am sincerely seeking your assistance on this matter to work with me in honesty for the funds to be placed under your name thereafter be transferred to any bank account of your choice in your country.

I need you to work with me because I intend living and investing in your country for good reasons I contacted you in as much as we don`t know each other in person.

I am ready to offer you 20% of the Twenty Million dollars for your humble assistance on the successful conclusion of this transaction. Now the question is can I rely on you to work with me in strict confidentiality?  If your answer is YES, Kindly get back to me for further details but if your answer is NO, please delete this message from your e-mailbox and forget I ever contacted you.

Yours Sincerely
Mrs.Sarahmina Mohammed


Envelope Sender: <message@insightbb.com>
'From' Header: "Mrs.S.M"<message@insightbb.com>
Subject: Please Read Carefully NG
Timestamp: 01:12:33 CST, Friday 15 November 2019
Message-ID:
Attachments: None

Classification: Malicious
Threat Level: High
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Phishing Very High
Spam Very High
Bulk Very High

Client IP Address: 182.18.161.146
Client GeoIP Lookup: India
Email Size: 4.5 kB
Encrypted? No

Reagieren Sie dringend!

NOTE: This crook is completely tone deaf.  Sending a foreign written spam email to an English speaking audience. This is as funny as women getting emails to buy Viagra and men getting emails to make their boobs bigger. Facebook does not send emails like this, nor do they use a free anonymous gmail account to do so. Facebook also doesn't have a lottery or offer millions to hundreds at a time by sending spam like this. This spam has rotted, it's moldy, it needs to be tossed in the garbage and banned. Otherwise this criminal will be happy to plunder your identity and finances for a mere copy/paste/send scam. Don't pay these criminals, get rid of them. P.S. The person this was sent to doesn't and never has had a facebook account, further adding to it's untrustworthiness.


From: cef21_sanjorge <cef21_sanjorge@santafe.edu.ar> To:20:13:45 CST, Thursday 14 November 2019
Attachments: None
Message ID: <1040142673.225537.1573775950866.JavaMail.zimbra@santafe.edu.ar>
Return Path: <cef21_sanjorge@santafe.edu.ar>
Reply To: facebookinc231@gmail.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="----=_Part_225536_1841273249.1573775950864"
Attachments:
None
Received:
from mx1-us1.ppe-hosted.com (unknown [10.7.66.31]) by pure.maildistiller.com with ESMTPS id 722574004D for <>; Fri, 15 Nov 2019 02:13:45 +0000 (UTC)

from correo.santafe.edu.ar (correo.santafe.edu.ar [200.12.192.40]) by mx1-us1.ppe-hosted.com with ESMTP id F3218940064 for <>; Fri, 15 Nov 2019 02:13:44 +0000 (UTC)

from localhost (localhost [127.0.0.1]) by correo.santafe.edu.ar (Postfix) with ESMTP id 2F2EE4E79AC6; Thu, 14 Nov 2019 20:59:14 -0300 (GMT+3)

from correo.santafe.edu.ar ([127.0.0.1]) by localhost (correo.santafe.edu.ar [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id S4ApGN91-Pwy; Thu, 14 Nov 2019 20:59:12 -0300 (GMT+3)

from localhost (localhost [127.0.0.1]) by correo.santafe.edu.ar (Postfix) with ESMTP id 9A22D4E79ABF; Thu, 14 Nov 2019 20:59:12 -0300 (GMT+3)

from correo.santafe.edu.ar ([127.0.0.1]) by localhost (correo.santafe.edu.ar [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 6otE8DRuSncC; Thu, 14 Nov 2019 20:59:11 -0300 (GMT+3)

from correo.santafe.edu.ar (correo.santafe.edu.ar [10.30.1.40]) by correo.santafe.edu.ar (Postfix) with ESMTP id E4DA84E78E8B; Thu, 14 Nov 2019 20:59:10 -0300 (GMT+3)


FACEBOOK INC
1601 WILLOW ROAD MENLO PARK, CA 94025
www.facebook.com
facebookinc231@gmail.com
Sehr geehrter Facebook-Nutzer:

Hiermit möchten wir Sie darüber informieren, dass Ihr Facebook-Konto ein Preisgeld von 1.000.000,00 USD (eine Million US-Dollar) für die Facebook-Aktion „Edition 2019“ gewonnen hat.

Wir gratulieren Ihnen, dass Sie zu den ausgewählten Personen gehören.

Es wird daher empfohlen, die folgenden Informationen an das Management von FACEBOOK INC zu senden, um Ihren Anspruch zu bearbeiten [facebookinc231@gmail.com]

[TRANSLATED] We're writing to let you know that your Facebook account has won $ 1,000,000.00 ($ 1 million) in Facebook's "Edition 2019" campaign. We congratulate you on being one of the selected individuals. It is therefore recommended to send the following information to the FACEBOOK INC management to process your claim [facebookinc231@gmail.com]

 1. Vollständiger Name .............
 2. Land ..............
 3. Kontaktadresse ........
 4. Telefonnummer .....
 5. Familienstand ........
 6. Beruf .............
 7. Firma ...............
 8. Alter .....................

 Herzliche Glückwünsche!! Noch einmal.

 [TRANSLATED] 1. Full name ............. 2. Country .............. 3. Contact address ........ 4. Telephone number .. ... 5. Marital Status ........ 6. Profession ............. 7. Company ............... 8. Age ..................... Congratulations !! Once again.


Aus Sicherheitsgründen empfehlen wir allen Gewinnern, diese Informationen der Öffentlichkeit gegenüber vertraulich zu behandeln, bis Ihr Antrag bearbeitet und Ihr Gewinn an Sie freigegeben wurde. Dies ist Teil unseres Sicherheitsprotokolls, um zu vermeiden, dass nicht teilnehmendes oder inoffizielles Personal doppelte Ansprüche erhebt und ungerechtfertigt von diesem Programm Gebrauch macht.

Senden Sie Informationen an die offizielle Adresse für Bearbeitungsansprüche {facebookinc231@gmail.com].


Büro des Präsidenten
CEO von Facebook
Herr Mark Zuckerberg
facebookinc231@gmail.com

[TRANSLATED] For security reasons, we recommend that all winners keep this information confidential with the public until your application has been processed and your winnings have been released to you. This is part of our security protocol to prevent non-participating or unofficial personnel from making duplicate claims and unjustifiably using this program.

Send information to the official address for processing claims {facebookinc231@gmail.com].

Office of the President CEO of Facebook
Mr. Mark Zuckerberg facebookinc231@gmail.com


Envelope Sender: <cef21_sanjorge@santafe.edu.ar>
'From' Header: cef21_sanjorge <cef21_sanjorge@santafe.edu.ar>
Subject: Reagieren Sie dringend!
Timestamp: 20:13:45 CST, Thursday 14 November 2019
Message-ID: <1040142673.225537.1573775950866.JavaMail.zimbra@santafe.edu.ar>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High

Client IP Address: 200.12.192.40
Client GeoIP Lookup: Argentina
Email Size: 6.4 kB
Encrypted? No

CIMB BANK MALAYSIA BERHAD (127776-V) HEAD OFFICE

NOTE: If the gmail address this was sent to isn't a red flag, then "CIMB BANK MALAYSIA" should be glaring and staring you down! Then there's the bulk email factor. We have a sea of red flags starting here. This criminal is promising strangers on the internet riches by submitting their personal information (another HUGE red flag) so your identity and finances can be plundered. For what? A lazy crook who did nothing more than copy/paste/send a scam email. Be smart, know red flags for what they are, delete and ban these crooks, save yourself.


From: Ching Yew Chye <infodavid819@gmail.com> To: undisclosed-recipients:;11:14:43 CST, Thursday 14 November 2019
Attachments: None
Message ID: <CA+8FgwzNHMB=cnHS5tADGBae41SwWJ+vbpM46KU0keBvc17i4g@mail.gmail.com>
Return Path: <infodavid819@gmail.com>
Reply To: chingyewchye00@gmail.com
MIME Version: 1.0
Content Type: text/plain; charset="UTF-8"
Attachments:
None
Received:
from mx1-us4.ppe-hosted.com (unknown [10.110.49.109]) by pure.maildistiller.com with ESMTPS id 5227A40074 for <>; Thu, 14 Nov 2019 17:14:43 +0000 (UTC)

from mail-oi1-f196.google.com (mail-oi1-f196.google.com [209.85.167.196]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 4055FB40081 for <>; Thu, 14 Nov 2019 17:14:43 +0000 (UTC)

by mail-oi1-f196.google.com with SMTP id i185so5949561oif.9 for <>; Thu, 14 Nov 2019 09:14:43 -0800 (PST)

by 2002:ac9:5ccb:0:0:0:0:0 with HTTP; Thu, 14 Nov 2019 09:14:42 -0800 (PST)


CIMB Bank Malaysia Berhad (127776-V) Head Office 338, Jalan Raja Laut Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia IMBURSEMENT FUND (US$18,500,000.00). We are hereby officially notify you concerning your fund telegraphic Transfer through our CIMB Bank Malaysia Berhad, to your bank account,which has been officially approved by the management of World Bank Swiss (WBS) to credit the sum of US$18.5 Million into your bank account. Note that I have started processing your payment and everything concerning the immediate remittance of your funds will be carried out within the shortest possible time from the time we received your below needed information. Also be informed that the Governor of Bank in London (BL) will sign on your payment advice and a copy of the advice will be sent to the World Bank in Swiss for some record purposes. Meanwhile your information and your full contact details were received from our research manager,Barr. Paul Peterson on your behalf to FRB for immediate release of your fund This fund was part of the lodged Late President Saddam Hussein of Iraq discovery fund with World Bank of Switzerland, which the Swiss Bank has decided to distribute it generously to help few lucky individuals and the American Government is in agreement with the Swiss Bank to distribute the fund to 700 hundred thousand people in America, Europe & Asia in other to help improve their businesses. Therefore, reconfirm the aforesaid information accurately, because this office cannot afford to be held liable for any wrong transfer of funds or liable of any fund credited into an unknown account. These are the information we needed to be reconfirmed by you. 1. Your Full Bank Account Details 2. Your Direct Cell or office phone to reach you 3. Your address of locations 4. Your full name Finally, you are required to reconfirm directly to me the above information to enable me use it to process your bill of payment. Your quick response shall be mostly appreciated; all your response should be directed through our alternative email address for the immediate attention of the credit control department.Email us here(chingyewchye00@gmail.com). Yours in Service, Ching Yew Chye Director, Credit / Telex Dept.CIMB Bank Malaysia Berhad


Envelope Sender: <infodavid819@gmail.com>
'From' Header: Ching Yew Chye <infodavid819@gmail.com>
Subject: CIMB BANK MALAYSIA BERHAD (127776-V) HEAD OFFICE
Timestamp: 11:14:43 CST, Thursday 14 November 2019
Message-ID: <CA+8FgwzNHMB=cnHS5tADGBae41SwWJ+vbpM46KU0keBvc17i4g@mail.gmail.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 209.85.167.196
Client GeoIP Lookup: United States
Email Size: 5.1 kB
Encrypted? No

PLEASE REVERT BACK TO ME ASAP,

NOTE: This Class A moronic criminal sent this email twice, in a row, in less than a minute apart. "PLEASE REVERT BACK TO ME ASAP," is not only bad English but a demand and from several free email anonymous addresses also!!!!  How bold of a financial criminal, but not shocking. In reality there is no millions for any of the hundreds of people who received this same email. There is, however, a future that holds someone stealing your identity and finances for nothing more than a copy/paste/send scam. Keep your identity, keep your finances, delete these a**wipes from your inbox and ban them.


From: Omar Mohamed <evg.emobm@aol.com> To:02:38:51 CST, Thursday 14 November 2019
Attachments: None
Message ID: <1630954922.227961.1573720724562@mail.yahoo.com>
Return Path: <evg.emobm@aol.com>
Reply To: om8978349@gmail.com
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Attachments:
None
Received:
from mx1-us2.ppe-hosted.com (unknown [10.7.65.175]) by pure.maildistiller.com with ESMTPS id DF8414004D for <>; Thu, 14 Nov 2019 08:38:50 +0000 (UTC)

from sonic306-19.consmr.mail.sg3.yahoo.com (sonic306-19.consmr.mail.sg3.yahoo.com [106.10.241.139]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us2.ppe-hosted.com with ESMTPS id 6EE8470006C for <>; Thu, 14 Nov 2019 08:38:50 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic306.consmr.mail.sg3.yahoo.com with HTTP; Thu, 14 Nov 2019 08:38:47 +0000


Dear friend I am contacting you on a business deal of $17.5 Million US Dollars, ready for transfer into your account if we make this claim, we will share it 60%/40%. 100% risk free and it will be legally backed up with government approved If you are interested reply for more details. Best regards, Omar Mohamed +226 68874958


Envelope Sender: <evg.emobm@aol.com>
'From' Header: Omar Mohamed <evg.emobm@aol.com>
Subject: PLEASE REVERT BACK TO ME ASAP,
Timestamp: 02:38:51 CST, Thursday 14 November 2019
Message-ID: <1630954922.227961.1573720724562@mail.yahoo.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 106.10.241.139
Client GeoIP Lookup: Singapore
Email Size: 3.3 kB
Encrypted? No

Thursday, November 14, 2019

From Mrs Rita Williams

NOTE: Ah yes, bad English, using religion to tug the heart strings. Nothing bu a criminal manipulating you out of information they can use to steal from you. A lazy low life criminal wrote this.


From: Rita Williams <wir4478@gmail.com> To:09:10:28 CST, Wednesday 13 November 2019
Attachments: None
Message ID: <1970859003.255328.1573657822516@mail.yahoo.com>
Return Path: <wir4478@gmail.com>
Reply To: ritawi668@yahoo.co.jp
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Attachments:
None
Received:
from mx1-us4.ppe-hosted.com (unknown [10.7.66.40]) by pure.maildistiller.com with ESMTPS id 2B6892C004D for <>; Wed, 13 Nov 2019 15:10:28 +0000 (UTC)

from sonic304-24.consmr.mail.gq1.yahoo.com (sonic304-24.consmr.mail.gq1.yahoo.com [98.137.68.205]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us4.ppe-hosted.com with ESMTPS id 083EEBC0087 for <>; Wed, 13 Nov 2019 15:10:27 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic304.consmr.mail.gq1.yahoo.com with HTTP; Wed, 13 Nov 2019 15:10:27 +0000


Dearest one in Christ, I am Mrs Rita Williams, I married Mr.David williams, for 19 years without a child and my husband died in 2007. I'm contacting you so that you will know my desire to donate the sum of ( 6,500,000 Dollars ) ( Six million five hundred thousand Dollars that I inherited from my late husband to charity, currently the fund is still in the bank. Recently, my doctor told me that I have serious sickness which is cancer problem and I will not last for the next 2 months. I want a person that will use this fund for orphanages, schools, churches, widows, propagating the word of God in his country. Reply me for more information's, and also Send me the following information, as per below. Your full name .......... Address ........... Photo ............... Remain blessed Your sister in christ Mrs Rita Williams


Envelope Sender: <wir4478@gmail.com>
'From' Header: Rita Williams <wir4478@gmail.com>
Subject: From Mrs Rita Williams
Timestamp: 09:10:28 CST, Wednesday 13 November 2019
Message-ID: <1970859003.255328.1573657822516@mail.yahoo.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
SPF (SoftFail) Medium
Bulk Low

Client IP Address: 98.137.68.205
Client GeoIP Lookup: United States
Email Size: 3.9 kB
Encrypted? No

Dearest Beloved

NOTE: This one has a crude grasp on using a VPN. Still a criminal trying to manipulate others out of their money in the guise of illness. A manipulative ploy you'd be best not to respond to and realize this is nothing but a criminal looking to gain, financially, from your good nature. Make no mistake they are playing the reader for being a complete fool, idiot and mentally challenged.


From: "Mrs Brenda Mayette Cowart," <brendamayettecowart@gmail.com> To: undisclosed-recipients:;08:28:22 CST, Wednesday 13 November 2019
Attachments: None
Message ID: <CAGta3wQ5hny2YtO3fh_r5-JEJShKtsVmLShrB8GheG3dgEpxig@mail.gmail.com>
Return Path: <vyrostkovaanastasiia10@gmail.com>
Reply To: brendamayettecowart@gmail.com
MIME Version: 1.0
Content Type: multipart/alternative; boundary="000000000000ac25ae05973b2c3c"
Attachments:
None
Received:
from mx1-us3.ppe-hosted.com (unknown [10.7.66.37]) by pure.maildistiller.com with ESMTPS id 4C2211A0051 for <>; Wed, 13 Nov 2019 14:28:22 +0000 (UTC)

from mail-ed1-f66.google.com (mail-ed1-f66.google.com [209.85.208.66]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us3.ppe-hosted.com with ESMTPS id 0031BB4007C for <>; Wed, 13 Nov 2019 14:28:21 +0000 (UTC)

by mail-ed1-f66.google.com with SMTP id s10so1972056edi.5 for <>; Wed, 13 Nov 2019 06:28:21 -0800 (PST)



Dear Friend:
may the peace of God be upon you, I am Mrs Brenda Mayette Cowart, from the United Kingdom.However I know this message may come to you as a surprise, please consider this with all seriousness I solicited your assistance in  the most polite language.I went through your profile on Google and counted you worthy for this transaction.
I am a dying woman who had decided to donate what I have to Charities I am 69 years old by age, and was diagnosed for cancer about two years ago immediately after the death of my husband, Life for me in this world is not that important since we are passing our life in this world so we can have a place in Heaven, I have been touched by God to donate from what I have inherited from my late husband for the good work of God, rather than allow his relatives to use my husband's hard earned funds ungodly, As I lay on my sick bed,I want you to help me in carrying out my last wish on earth which will be very profitable to you.
i want to WILL a total sum of{$6,000,000, Six million,U.S dollars} to you which I want you to distribute part of it to any charity home,  for your kindness,on this work you are to carry out I am offering you 40% while 60% of the Fund will go to any Charity organizations of your choice for me, please I am looking forward to hearing from you soon.

Regards,
Mrs Brenda Mayette Cowart,


Envelope Sender: <vyrostkovaanastasiia10@gmail.com>
'From' Header: "Mrs Brenda Mayette Cowart," <brendamayettecowart@gmail.com>
Subject: Dearest Beloved
Timestamp: 08:28:22 CST, Wednesday 13 November 2019
Message-ID: <CAGta3wQ5hny2YtO3fh_r5-JEJShKtsVmLShrB8GheG3dgEpxig@mail.gmail.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
Bulk Very High

Client IP Address: 209.85.208.66
Client GeoIP Lookup: United States
Email Size: 5.9 kB
Encrypted? No

Dear Beneficiary, I’ve recently become aware

NOTE: ROFLMAO the "U.S Department of Homeland Security" does not use gmail or yahoo. Nor are they so stupid and inept that they attempt to cram the body of an email all in the subject line. OMG this is a joke, it has to be. This email takes a special kind of stupid to have mass emailed it to thousands all over the world. Still a lazy no good criminal all the same.  Stupid, inept, clueless, but still a thief.


From: "U.S Department of Homeland Security" <dhskmc091@gmail.com> To: "usdhs@usa.com" <usdhs@usa.com>08:11:10 CST, Wednesday 13 November 2019
Attachments: None
Message ID: <66843.98486.qm@web102119.mail.ssk.yahoo.co.jp>
Return Path: <dhskmc091@gmail.com>
Reply To: "U.S Department of Homeland Security" <kevinmcaleenan77@gmail.com>
MIME Version: 1.0
Content Type: multipart/alternative; boundary="966491297-850742971-1573654262=:98486"
Attachments:
None
Received:
from mx1-us3.ppe-hosted.com (unknown [10.110.49.105]) by pure.maildistiller.com with ESMTPS id 128F380080 for <>; Wed, 13 Nov 2019 14:11:10 +0000 (UTC)

from ns603-vm9.bullet.mail.ssk.yahoo.co.jp (ns603-vm9.bullet.mail.ssk.yahoo.co.jp [182.22.91.90]) by mx1-us3.ppe-hosted.com with SMTP id 84CE29C00AF for <>; Wed, 13 Nov 2019 14:11:09 +0000 (UTC)

from [182.22.66.105] by ns603.bullet.mail.ssk.yahoo.co.jp with NNFMP; 13 Nov 2019 14:11:03 -0000

from [182.22.91.205] by t603.bullet.mail.ssk.yahoo.co.jp with NNFMP; 13 Nov 2019 14:11:03 -0000

from [127.0.0.1] by omp608.mail.ssk.yahoo.co.jp with NNFMP; 13 Nov 2019 14:11:03 -0000

(qmail 76023 invoked by uid 60001); 13 Nov 2019 14:11:03 -0000

from [197.234.221.99] by web102119.mail.ssk.yahoo.co.jp via HTTP; Wed, 13 Nov 2019 23:11:02 JST


Subject:
Dear Beneficiary, I $B!G (Bve recently become aware that your funds in the tune of US$7,500,000.00 (Seven Million, five hundred thousand United States Dollar) are still being held by the Benin authorities (West Africa). I have instructed ECOWAS and the concerned authorities to box the total amount and deliver it to the Department of Homeland Security Washington DC. The fund is going to arrive here today. In this case, your current home address and Direct Cell Phone number is essential to complete this delivery when your fund arrives. Please ensure that all details are correctly supplied to avoid wrong delivery. The Homeland Security takes very seriously its responsibility to protect your information and ensure your privacy is secured. We expect your urgent response to this email to enable us monitor this payment effectively. Yours sincerely Kevin McAleenan Secretary of the U.S Department of Homeland Security, Washington DC


Envelope Sender: <dhskmc091@gmail.com>
'From' Header: "U.S Department of Homeland Security" <dhskmc091@gmail.com>
Subject: Dear Beneficiary, I’ve recently become aware that your funds in the tune of US$7,500,000.00 (Seven Million, five hundred thousand United States Dollar) are still being held by the Benin authorities (West Africa). I have instructed ECOWAS and the concer
Timestamp: 08:11:10 CST, Wednesday 13 November 2019
Message-ID: <66843.98486.qm@web102119.mail.ssk.yahoo.co.jp>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
SPF (SoftFail) Medium

Client IP Address: 182.22.91.90
Client GeoIP Lookup: Japan
Email Size: 5.3 kB
Encrypted? No

ATTENTION BENEFICIARY

NOTE: There's that word again ... beneficiary. Are these lazy copy paste criminals trying to come off smart? Professional? They are neither. The only thing you should authorize is deleting this scam.


From: Maria Ben <mariaben787@yahoo.com> To:03:13:34 CST, Wednesday 13 November 2019
Attachments: None
Message ID: <1522066345.2343558.1573636410247@mail.yahoo.com>
Return Path: <mariaben787@yahoo.com>
Reply To: drjimmyharrson@hotmail.com
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Attachments:
None
Received:
from mx1-us5.ppe-hosted.com (unknown [10.110.50.9]) by pure.maildistiller.com with ESMTPS id 60AEA80060 for <>; Wed, 13 Nov 2019 09:13:34 +0000 (UTC)

from sonic306-1.consmr.mail.bf2.yahoo.com (sonic306-1.consmr.mail.bf2.yahoo.com [74.6.132.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us5.ppe-hosted.com with ESMTPS id 45A7E580055 for <>; Wed, 13 Nov 2019 09:13:34 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic306.consmr.mail.bf2.yahoo.com with HTTP; Wed, 13 Nov 2019 09:13:33 +0000


ATTENTION BENEFICIARY Be inform that We have been authorized by the United Nations Debt Reconciliation Unit,to release your approved compensation and Award of US$1,500,000.00.However, for security reasons, your compensation funds of $1.500,000.00 USD has been loaded in ATM VISA CARD and this will enable only you to have direct control over your funds. You are advice to contact our director of ATM CARD Payment Center Dr.Jimmy Harrison and request him to send your ATM CARD to you. Contact him through the below stated information and forward your personal details to him. Contact Person:Dr.Jimmy Harrison Phone Number: +299 90411776 Email address:drjimmyharrison@hotmail.com REMEMBER TO SEND HIM YOUR FULL INFORMATION AS REQUIRED BELOW TO AVOID WRONGFUL DELIVERY, 1. Your Full Name:____ 2. Address:____ 3. Telephone Numbers:____ 4. Country:____ NOTE: that the amount to be paid to you is ($1.5million USD) we expect your urgent response to this email to enable us monitor the payment effectively. Best Regards Maria Ben


Envelope Sender: <mariaben787@yahoo.com>
'From' Header: Maria Ben <mariaben787@yahoo.com>
Subject: ATTENTION BENEFICIARY
Timestamp: 03:13:34 CST, Wednesday 13 November 2019
Message-ID: <1522066345.2343558.1573636410247@mail.yahoo.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High

Client IP Address: 74.6.132.40
Client GeoIP Lookup: United States
Email Size: 4.1 kB
Encrypted? No

Urgent Information,

NOTE: The English is so bad I struggled to get past the first sentence. A stupid scammer in every sense. Delete these emails and save yourself the trouble of dealing with criminal ignorance. The only urgency this needs ... deletion.


From: "Amina J. Mohammed" <transferscredits@gmail.com> To:01:42:16 CST, Wednesday 13 November 2019
Attachments: None
Message ID: <863959960.2344819.1573630933787@mail.yahoo.com>
Return Path: <transferscredits@gmail.com>
Reply To: atminfo23@gmail.com
MIME Version: 1.0
Content Type: text/plain; charset=UTF-8
Attachments:
None
Received:
from mx1-us5.ppe-hosted.com (unknown [10.7.65.199]) by pure.maildistiller.com with ESMTPS id 1658840062 for <>; Wed, 13 Nov 2019 07:42:16 +0000 (UTC)

from sonic307-1.consmr.mail.bf2.yahoo.com (sonic307-1.consmr.mail.bf2.yahoo.com [74.6.134.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mx1-us5.ppe-hosted.com with ESMTPS id DC9DC180050 for <>; Wed, 13 Nov 2019 07:42:15 +0000 (UTC)

from sonic.gate.mail.ne1.yahoo.com by sonic307.consmr.mail.bf2.yahoo.com with HTTP; Wed, 13 Nov 2019 07:42:15 +0000


Urgent Information, This is to official inform you that United Nations Compensation Commission (UNCC) in conjunction with World Bank Authorities (WBA), has after investigation approved your ($12,500.000 United States Dollars) outstanding compensation merit reward which was undergoing the investigation law of claimant since 5 years now, which has today been released into ATM MasterCard in your name for your urgent/easier collection, since MasterCard is 100% active and legit alternatives claim permit worldwide, and also remain the safe and secure means for you to receive/collect this fund at no hitch. Therefore you're advice here to kindly contact the ATM Management office right away with your required details at bottom, which's for their recommendation before giving a more information of how you will get the MasterCard from them successful as agreed. 1. Full Name: ========== 2. Country: ============ 3. City:================ 4. Home/Office Add:====== 5. Phone:============== 6. Next of kin: ========== However note when contacting, then make sure you contact the ATM managing director: Mr. Paul C. Murphy only/direct on this email:( atminfo23@gmail.com ), so you must get his right direction at no mislead and be warn to read careful as well to avoid wrong contact which may lead you wrong which wasn't of the plan in this compensation. Thanks & stay bless. Mrs. Amina J. Mohammed UN Deputy Secretary-General


Envelope Sender: <transferscredits@gmail.com>
'From' Header: "Amina J. Mohammed" <transferscredits@gmail.com>
Subject: Urgent Information,
Timestamp: 01:42:16 CST, Wednesday 13 November 2019
Message-ID: <863959960.2344819.1573630933787@mail.yahoo.com>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High
SPF (SoftFail) Medium
Bulk Low

Client IP Address: 74.6.134.40
Client GeoIP Lookup: United States
Email Size: 4.5 kB
Encrypted? No

Your account was under attack! Change your access data!

NOTE: Some joker in Hong Kong thinks they are going to convince someone somewhere that they know what's going on with your email. The only attack on people's email are from idiot criminals like this one sending spam to thousands on an email list they got from someone else who likes scamming people.


From: <general@harbourtrade.com.hk> To: <>21:09:38 CST, Tuesday 12 November 2019
Attachments: None
Message ID: <870844B6-AAFB-54B3-7527-B51B6AC6C014@harbourtrade.com.hk>
Return Path: <general@harbourtrade.com.hk>
Reply To:
MIME Version: 1.0
Content Type: text/plain; charset="UTF-8"
Attachments:
None
Received:
from mx1-us2.ppe-hosted.com (unknown [10.7.65.176]) by pure.maildistiller.com with ESMTPS id EAE33140062 for <>; Wed, 13 Nov 2019 03:09:37 +0000 (UTC)

from mail.harbourtrade.com.hk (n11212070008.netvigator.com [112.120.70.8]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1-us2.ppe-hosted.com with ESMTPS id 7291368005C for <>; Wed, 13 Nov 2019 03:09:37 +0000 (UTC)

from [127.0.0.1] (212.113.234.151) by harbourtrade.com.hk (192.168.1.5) with Microsoft SMTP Server id 14.2.347.0; Wed, 13 Nov 2019 11:09:33 +0800


Hello! I am a hacker who has access to your operating system. I also have full access to your account. I've been watching you for a few months now. The fact is that you were infected with malware through an adult site that you visited. If you are not familiar with this, I will explain. Trojan Virus gives me full access and control over a computer or other device. This means that I can see everything on your screen, turn on the camera and microphone, but you do not know about it. I also have access to all your contacts and all your correspondence. Why your antivirus did not detect malware? Answer: My malware uses the driver, I update its signatures every 4 hours so that your antivirus is silent. I made a video showing how you satisfy yourself in the left half of the screen, and in the right half you see the video that you watched. With one click of the mouse, I can send this video to all your emails and contacts on social networks. I can also post access to all your e-mail correspondence and messengers that you use. If you want to prevent this, transfer the amount of $500 to my bitcoin address (if you do not know how to do this, write to Google: "Buy Bitcoin"). My bitcoin address (BTC Wallet) is: 36G8A3fXAz1FRdHLSYAdCSgw6x7bij7SWY After receiving the payment, I will delete the video and you will never hear me again. I give you 50 hours (more than 2 days) to pay. I have a notice reading this letter, and the timer will work when you see this letter. Filing a complaint somewhere does not make sense because this email cannot be tracked like my bitcoin address. I do not make any mistakes. If I find that you have shared this message with someone else, the video will be immediately distributed. Best regards!


Envelope Sender: <general@harbourtrade.com.hk>
'From' Header: <general@harbourtrade.com.hk>
Subject: Your account was under attack! Change your access data!
Timestamp: 21:09:38 CST, Tuesday 12 November 2019
Message-ID: <870844B6-AAFB-54B3-7527-B51B6AC6C014@harbourtrade.com.hk>
Attachments: None

Classification: Spam
Threat Level: Medium
Confidence: Very High
Classification Breakdown:
TAGS CONFIDENCE
Spam Very High

Client IP Address: 112.120.70.8
Client GeoIP Lookup: Hong Kong
Email Size: 3.1 kB
Encrypted? No