by Terminator5
Mon Nov 07, 2011 2:38 pm
Scam Coca Cola Lottery with website and 3 email attachments .
The source host name is "132.115.in-addr.arpa" and the source IP address is 115.132.112.16
Geo-Location Information
Country Malaysia
City Petaling Jaya
Begin Scam Email:
Opportunity to be a millionair on coca-cola x mass promotion!
We select one of our visitors from an email raffle . You could be a potential winner!
COCA COLA®CORPORATION
Act fast! Otherwise, we'll give your spot to another eligible visitor!
How to register and claim your prize in only 7 simple steps:
Step 1:
Click here to register on our Coca-Cola site.
Step 2:
Step4
Step 5:
Step 6
Step 7
Your Email verification code
Use your email and your prefer password to login into your profile page.
Click on (Click Here to make a winning Registration)
on your profile page to play.
Don't forget to enter a valid mobile phone number and your Email verification Code that came with this email
Don't forget to keep your registration details safely and provide a LUCKY PROMO NO for your raffle.
Logging into your profile every 24hrs to view who is the lucky winner.
0134746407
Good luck!
Click here to register to make a profile page on our Coca Cola website
Click here to register instantly & claim your opportunity!
Copyright © 2011 ?Social Rewards ? All rights reserved.
End Scam Email
3 attachments to scam email : noname 111K, noname 9K, noname 7K
The scam email contains the following links , which lead you to a website that is not functioning properly .
http://www.cocacolaxmasspromo.imf-world ... r-form.php
http://www.cocacolaxmasspromo.imf-world ... rofile.php
Header Details:
Delivered-To: xxxxxx
Received: by 10.180.84.8 with SMTP id u8cs68985wiy;
Mon, 7 Nov 2011 10:19:00 -0800 (PST)
Received: by 10.68.35.105 with SMTP id g9mr1006820pbj.40.1320689935608;
Mon, 07 Nov 2011 10:18:55 -0800 (PST)
Return-Path: <[email protected]>
Received: from server1.3ticksserver.net ([66.85.167.186])
by mx.google.com with ESMTPS id d4si16135573pbq.233.2011.11.07.10.18.51
(version=TLSv1/SSLv3 cipher=OTHER);
Mon, 07 Nov 2011 10:18:55 -0800 (PST)
Received-SPF: neutral (google.com: 66.85.167.186 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=66.85.167.186;
Authentication-Results: mx.google.com; spf=neutral (google.com: 66.85.167.186 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Received: from localhost.localdomain ([127.0.0.1] helo=localhost)
by server1.3ticksserver.net with esmtpa (Exim 4.69)
(envelope-from <[email protected]>)
id 1RNTlh-0006Ya-Gz; Mon, 07 Nov 2011 11:18:01 -0700
Received: from 115.132.112.16 ([115.132.112.16]) by 2hsbcc.org (Horde
Framework) with HTTP; Mon, 07 Nov 2011 11:18:00 -0700
Message-ID: <[email protected]>
Date: Mon, 07 Nov 2011 11:18:00 -0700
From: [email protected]
To: [email protected]
Subject: COCA COLA XMAS BONANZA 2011
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_4iy3bamtsjuos"
Content-Transfer-Encoding: 7bit
User-Agent: Internet Messaging Program (IMP) H3 (4.3.9)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server1.3ticksserver.net
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - 2hsbcc.org
This message is in MIME format.
--=_4iy3bamtsjuos
Content-Type: text/plain;
charset=ISO-8859-1
Content-Description: Plaintext Version of Message
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
The source host name is "132.115.in-addr.arpa" and the source IP address is 115.132.112.16
Geo-Location Information
Country Malaysia
City Petaling Jaya
Begin Scam Email:
Opportunity to be a millionair on coca-cola x mass promotion!
We select one of our visitors from an email raffle . You could be a potential winner!
COCA COLA®CORPORATION
Act fast! Otherwise, we'll give your spot to another eligible visitor!
How to register and claim your prize in only 7 simple steps:
Step 1:
Click here to register on our Coca-Cola site.
Step 2:
Step4
Step 5:
Step 6
Step 7
Your Email verification code
Use your email and your prefer password to login into your profile page.
Click on (Click Here to make a winning Registration)
on your profile page to play.
Don't forget to enter a valid mobile phone number and your Email verification Code that came with this email
Don't forget to keep your registration details safely and provide a LUCKY PROMO NO for your raffle.
Logging into your profile every 24hrs to view who is the lucky winner.
0134746407
Good luck!
Click here to register to make a profile page on our Coca Cola website
Click here to register instantly & claim your opportunity!
Copyright © 2011 ?Social Rewards ? All rights reserved.
End Scam Email
3 attachments to scam email : noname 111K, noname 9K, noname 7K
The scam email contains the following links , which lead you to a website that is not functioning properly .
http://www.cocacolaxmasspromo.imf-world ... r-form.php
http://www.cocacolaxmasspromo.imf-world ... rofile.php
Header Details:
Delivered-To: xxxxxx
Received: by 10.180.84.8 with SMTP id u8cs68985wiy;
Mon, 7 Nov 2011 10:19:00 -0800 (PST)
Received: by 10.68.35.105 with SMTP id g9mr1006820pbj.40.1320689935608;
Mon, 07 Nov 2011 10:18:55 -0800 (PST)
Return-Path: <[email protected]>
Received: from server1.3ticksserver.net ([66.85.167.186])
by mx.google.com with ESMTPS id d4si16135573pbq.233.2011.11.07.10.18.51
(version=TLSv1/SSLv3 cipher=OTHER);
Mon, 07 Nov 2011 10:18:55 -0800 (PST)
Received-SPF: neutral (google.com: 66.85.167.186 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=66.85.167.186;
Authentication-Results: mx.google.com; spf=neutral (google.com: 66.85.167.186 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Received: from localhost.localdomain ([127.0.0.1] helo=localhost)
by server1.3ticksserver.net with esmtpa (Exim 4.69)
(envelope-from <[email protected]>)
id 1RNTlh-0006Ya-Gz; Mon, 07 Nov 2011 11:18:01 -0700
Received: from 115.132.112.16 ([115.132.112.16]) by 2hsbcc.org (Horde
Framework) with HTTP; Mon, 07 Nov 2011 11:18:00 -0700
Message-ID: <[email protected]>
Date: Mon, 07 Nov 2011 11:18:00 -0700
From: [email protected]
To: [email protected]
Subject: COCA COLA XMAS BONANZA 2011
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_4iy3bamtsjuos"
Content-Transfer-Encoding: 7bit
User-Agent: Internet Messaging Program (IMP) H3 (4.3.9)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server1.3ticksserver.net
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - 2hsbcc.org
This message is in MIME format.
--=_4iy3bamtsjuos
Content-Type: text/plain;
charset=ISO-8859-1
Content-Description: Plaintext Version of Message
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Daniel 8 :25