Google

World Wide Web anti-scam


Seitenindex umschalten Seiten: 1 Thema versenden
Normales Thema John Burgman <j.burgman@hotmail.co.uk> (Gelesen: 415 mal)
 
Bountyhunter
Themenstarter Themenstarter
General Counsel
***
Offline


Scambaiting macht Fun

Beiträge: 3792
Standort: Coober Pedy South Australia
Mitglied seit: 31. Dezember 2013
Geschlecht: männlich
John Burgman <j.burgman@hotmail.co.uk>
26. Mai 2015 um 02:33
 
Ich kenne diesen Knilch gar nicht was will der eigentlich von mir? Schockiert/Erstaunt

Dear Email Client,

You have exhausted the 5GB Bandwidth of your email account and for this reason some of your incoming mails with files and documents above 50KB have been filtered and placed pending using Google Drive Secured Doc App. 



Incoming Mail & Attachment from: j.burgman@hotmail.co.uk


 
Your  e-mail account's  Bandwidth has been upgraded to 10GB to enable us serve you better. Kindly Click on the below link to complete the upgrade on your account in order to receive your pending mails and view your Attachment for download on the mail and enjoy better quality and efficient service delivery.

Follow this link to complete the process: CLICK HERE
  


Once the information provided matches the records on our database, your account will function normal again.

 

Sincerely,

 

Mail Service Team.

********** ******************************************************* **********************************  
Disclaimer: 

The information contained in this e-mail message and/or attachments to it may contain confidential or privileged information.If you are not the intended recipient of this message any dissemination, use, review, distribution, printing or copying of the information contained in this e-mail message and/or attachments to it are strictly prohibited and your are requested to notify the sender & delete this message from your system. Any unauthorized use or dissemination of this message in whole or 
in part is strictly forbidden.

Spoiler:
gzvYXdEGSKGVJKWyWZXFJHU2S9bkBLVY3KvLdcqV93nl57b2Nm3fSoazKP3n+Ibyq6t3UFvM=
Authentication-Results: hotmail.com; spf=pass (sender IP is 212.227.17.12) smtp.mailfrom=xxx; dkim=none header.d=hotmail.co.uk; x-hmca=none header.id=j.burgman@hotmail.co.uk
X-SID-PRA: j.burgman@hotmail.co.uk
X-AUTH-Result: NONE
X-SID-Result: NONE
X-Message-Status: n:n
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0xO0Q9MTtHRD0xO1NDTD0w
X-Message-Info: mMX9hrmlwseCMrtifNplRLzWXcQKQ0WtZZCtuL2eU98P+DusuTNEYWL4/DFdu/mPDcMWkakpER8=
Received: from mout.web.de ([212.227.17.12]) by SNT004-MC2F25.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.23008);
      Mon, 25 May 2015 17:16:22 -0700
Received: from [212.227.17.8] ([212.227.17.8]) by mx-ha.web.de (mxweb102) with
ESMTPS (Nemesis) id 0M9rT2-1YqOiL0z0q-00B2xI for
<xxx>; Tue, 26 May 2015 02:16:21 +0200
Received: from rogue.websitewelcome.com ([192.185.12.176]) by mx-ha.web.de
(mxweb102) with ESMTPS (Nemesis) id 0LnQTC-1ZdE790yuU-00hc66 for
<xxx>; Tue, 26 May 2015 02:16:21 +0200
Received: from serbless by rogue.websitewelcome.com with local (Exim 4.82)
     (envelope-from <serbless@rogue.websitewelcome.com>)
     id 1Yx2Xb-0008PV-Ha
     for xxx; Mon, 25 May 2015 19:16:19 -0500
Date: Mon, 25 May 2015 19:16:19 -0500
To: xxx
From: =?UTF-8?Q?John_Burgman?= <j.burgman@hotmail.co.uk>
Subject: =?UTF-8?Q?Re=3aAdobe_Secured_Doc_App=21_Email_Alert_Notification=21?=
Message-ID: <bd7a6cf5c4fe67a2a476849721363ade@www.serbless.com>;
X-Priority: 3
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - rogue.websitewelcome.com
X-AntiAbuse: Original Domain - web.de
X-AntiAbuse: Originator/Caller UID/GID - [5361 32003] / [47 12]
X-AntiAbuse: Sender Address Domain - rogue.websitewelcome.com
X-BWhitelist: no
X-Source-IP: 
X-Exim-ID: 1Yx2Xb-0008PV-Ha
X-Source: /opt/php54/bin/php-cgi
X-Source-Args: /opt/php54/bin/php-cgi /home/serbless/public_html/.css/wp-send.php 
X-Source-Dir: serbless.com:/public_html/.css
X-Source-Sender: 
X-Source-Auth: serbless
X-Email-Count: 497
X-Source-Cap: c2VyYmxlc3M7aTUzbmQxbjtyb2d1ZS53ZWJzaXRld2VsY29tZS5jb20=
X-UI-Out-Filterresults: notjunk:1;
Return-Path: xxx
X-OriginalArrivalTime: 26 May 2015 00:16:23.0182 (UTC) FILETIME=[32A4EAE0:01D09749]
« Zuletzt geändert: 18. Juni 2015 um 18:46 von Stiray »  
Zum Seitenanfang
 
IP gespeichert
 
Indikation
x5dr
Forum Administrator
*****
Offline


Die spinnen, die Scammer!

Beiträge: 4918
Standort: Oberweis
Mitglied seit: 05. Februar 2012
Geschlecht: männlich
Re: John Burgman <j.burgman@hotmail.co.uk>
Antwort #1 - 27. Mai 2015 um 19:46
 
Mail über USA!

Code
Alles auswählen
IP:	192.185.12.176
Decimal:	3233352880
Hostname:	rogue.websitewelcome.com
ISP:	Websitewelcome.com
Organization:	CyrusOne LLC
Services:	None detected
Type:	Corporate
Assignment:	Static IP
Country:	United States
State/Region:	Texas
City:	Houston 



Zitat:
Date: Mon, 25 May 2015 19:16:19 -0500


Sieht nach Pishing aus! Gleicher Text hier: https://itsc.ust.hk/services/it-security/phishing/phishing-samples/

@ Bountyhunter

Deine Mailaddy steht noch im Header.

Änderung:
Demnächst eine PN an mich, sonst kümmert sich keiner.
« Zuletzt geändert: 18. Juni 2015 um 18:47 von Stiray »  
Zum Seitenanfang
 
IP gespeichert
 
Seitenindex umschalten Seiten: 1
Thema versenden
Link zu diesem Thema