Fake banks, couriers, law firms, escrow and other fake sites used in scams.
by Terminator5 Tue Sep 24, 2013 12:35 pm
Phishing Site .


[email protected]

Begin Scam Email:

Dear Sir/Madam,

We have interest in purchasing your products and we sincerely hope to

establish a long-term business relation with your esteemed company.

Please send us your proforma invoice for the following this is a very large

and urgent request. Login your valid email address and password to view the

items in our website below.

http://ningboengg.yolasite.com/contact-us.php

Alternatively, copy and paste the hyperlink into your web browser.

Your early reply is highly appreciated. Thank You!

Best Regards,
*************************************************
Sincerely yours
Rachel Qiu / Weina Jin(EM)
Ningbo ENGG Auto Parts Co.,Ltd
Add: 6th Flr,Bldg A, Huizhan Road#181,Ningbo(Zip315000),China
Tel: +86 574 87623176 / 87579696

Daniel 8 :25
Advertisement

by Terminator5 Wed Nov 20, 2013 3:37 pm
The source IP address is 41.71.208.2


Geo-Location Information

Country Nigeria
State/Region 05
City Lagos


Tel: +8657487623176


Begin Scam Email


Dear Sir/Madam,

We have interest in purchasing your products and we sincerely hope to

establish a long-term business relation with your esteemed company.

Please send us your proforma invoice for the following this is a very large

and urgent request. Login your valid email address and password to view the

items in our website below.

http://ningboengg.yolasite.com/contact-us.php

Alternatively, copy and paste the hyperlink into your web browser.

Your early reply is highly appreciated. Thank You!

Best Regards,
*************************************************
Sincerely yours
Rachel Qiu / Weina Jin(EM)
Ningbo ENGG Auto Parts Co.,Ltd
Add: 6th Flr,Bldg A, Huizhan Road#181,Ningbo(Zip315000),China
Tel: +86 574 87623176 / 87579696

End Scam Email


Header Details:

Delivered-To: xxxxxx
Received: by 10.60.124.131 with SMTP id mi3csp26107oeb;
Wed, 20 Nov 2013 08:15:07 -0800 (PST)
X-Received: by 10.68.209.232 with SMTP id mp8mr1431810pbc.129.1384964107488;
Wed, 20 Nov 2013 08:15:07 -0800 (PST)
Return-Path: <[email protected]>
Received: from kydb.kuaiyou.com ([220.194.56.110])
by mx.google.com with ESMTPS id hi3si14562201pbb.303.2013.11.20.08.15.01
for <multiple recipients>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Wed, 20 Nov 2013 08:15:07 -0800 (PST)
Received-SPF: fail (google.com: domain of [email protected] does not designate 220.194.56.110 as permitted sender) client-ip=220.194.56.110;
Authentication-Results: mx.google.com;
spf=hardfail (google.com: domain of [email protected] does not designate 220.194.56.110 as permitted sender) [email protected]
Received: from User ([41.71.208.2])
(authenticated bits=0)
by kydb.kuaiyou.com (8.13.8/8.13.8) with ESMTP id rAKGAbjh000642;
Thu, 21 Nov 2013 00:10:41 +0800
Message-Id: <[email protected]>
Reply-To: <[email protected]>
From: "Abudu Lrauf"<[email protected]>
Subject: Re:New Order
Date: Wed, 20 Nov 2013 17:11:53 +0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 131119-0, 11/19/2013), Outbound message
X-Antivirus-Status: Clean

Daniel 8 :25
by Terminator5 Wed Dec 11, 2013 11:22 am
The source IP address is 41.71.217.204

Geo-Location Information

Country Nigeria
State/Region 05
City Lagos


Begin Scam Email:


Dear Sir,

Attached,Please find herewith our NEW ORDER for
your kind consideration.

Thanks & regards

abdulrauf

Bothra group of company
332-A, Shopping Centre
Kota (Rajasthan)
Ph: +917442363681
Cell:+918875000492


End Scam Email


Attachment to Scam Email . Deposits.htm 50KB


Header Details:

Delivered-To: xxxxxx
Received: by 10.60.21.226 with SMTP id y2csp236427oee;
Wed, 11 Dec 2013 01:37:24 -0800 (PST)
X-Received: by 10.224.22.200 with SMTP id o8mr766812qab.100.1386754644533;
Wed, 11 Dec 2013 01:37:24 -0800 (PST)
Return-Path: <[email protected]>
Received: from vps.dcsinfoway.com (vps.dcsinfoway.com. [72.29.93.200])
by mx.google.com with ESMTPS id e16si14933086qej.129.2013.12.11.01.37.23
for <multiple recipients>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Wed, 11 Dec 2013 01:37:24 -0800 (PST)
Received-SPF: neutral (google.com: 72.29.93.200 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=72.29.93.200;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 72.29.93.200 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Message-Id: <52a83254.3023310a.55e3.ffffe325SMTPIN_ADDED_MISSING@mx.google.com>
Received: from [41.71.217.204] (port=52802 helo=User)
by vps.dcsinfoway.com with esmtpa (Exim 4.80.1)
(envelope-from <[email protected]>)
id 1VqgE3-0008U0-Pe; Wed, 11 Dec 2013 01:37:08 -0800
Reply-To: <[email protected]>
From: "Abudu Lrauf"<[email protected]>
Subject: Re: Swift Payment Copy
Date: Wed, 11 Dec 2013 10:36:59 +0100
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0061_01C2A9A6.3F7F7460"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 131210-1, 12/10/2013), Outbound message
X-Antivirus-Status: Clean
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - vps.dcsinfoway.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - pradvi.com
X-Get-Message-Sender-Via: vps.dcsinfoway.com: authenticated_id: pradvi/from_h
X-Source:
X-Source-Args:
X-Source-Dir:

Daniel 8 :25

Who is online

Users browsing this forum: Bing [Bot], ClaudeBot and 4 guests