The full headers of the scam mail below was received with no message included and only an in-line graphic jpg containing a message stating "...you have won 1 million dollars in the Coca Cola Rewards Sweepstake Program..."
The scammer is using two fraudulent domains within the full headers of the email below. The 2 domains are http://www.cocacolarewards.win and http://www.cocacolaworld.win. Received: by 2002:a17:90a:170b:0:0:0:0 with SMTP id z11-v6csp542831pjd;
Wed, 1 Aug 2018 01:59:30 -0700 (PDT)
X-Google-Smtp-Source: AAOMgpee8FCOlXRQJpkmDKNVN3zS2m9SYTVLngp07GzK6bXILLAyvdqvqrXxWpsEbbzU3htogzC1
X-Received: by 2002:a63:844:: with SMTP id 65-v6mr24325504pgi.406.1533113970276;
Wed, 01 Aug 2018 01:59:30 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1533113970; cv=none;
d=google.com; s=arc-20160816;
b=XheM4v+L1zUP40cebjBpTshoe66sYx4OcU0BK+Red81nOAR8aV/qdNU3W79lsQnpg/
9nzpcRG5LJV04eGwdDxE7R2x4HCZevaX8foobJObuNb9mgeIDZ0AWHvFrTKCJuV15qU+
E8VoRUgn4pIYCjOvs9KzZfAagNhCNLOzWxLtjwdJm0Y0BrDwhV9AQSJbD2bCvlSwYZOX
kN/FA0N7a+CkBpeTpz0YWpjdOw/sT1QYfMA9eLpMzYXLOutqen5a3wJZb5TXrh6yF9jI
G7rSOFEu7Gua3MrPhJQ1P6jipAmimywjqzZwPTZKEDx5/y4azei2SM0HyegTi60lohFY
gFqQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
h=user-agent:message-id:mail-reply-to:reply-to:subject:to:from:date
:mime-version:dkim-signature:arc-authentication-results;
bh=Y1czXGREpbeFiez0IH6QK93viyuIbKTKyYmIy//eipU=;
b=Z8nvymjCQxw98kIcVrrjxF+YJLK6gxG/853wGJM/IXeeheAzDdy+MPaIrEFoWdvhNc
1g9TXKQawocV6+sqqkBlvFuI7sOJqeu925BZK3ILodZ4wVQGwfhBIhGjARK6bt8atUYT
jbEwq7blV3ccX5vPqxn+hPJxkwr+ngH+qjkB1dDAT4N185PfWtbKHI5sWbhJNurF89Vf
OlfkC5r6bg5OmxPgsqIr8OOZnLNAbkMACtriscUnPegVNtCnFj8I5SBzrSwpFlqs3jHr
S+8ha4RL3VrhU+mOJ4dTPOeucSVGBcbApG8NPYT+sr0ld+fyzUnMDj+uMbckI+D+52Tn
SuGw==
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass
[email protected] header.s=default header.b="IouL/jzW";
spf=neutral (google.com: 198.54.115.167 is neither permitted nor denied by best guess record for domain of
[email protected])
[email protected]Return-Path: <
[email protected]>
Received: from business33-3.web-hosting.com (business33-3.web-hosting.com. [198.54.115.167])
by mx.google.com with ESMTPS id q13-v6si16095652pgc.670.2018.08.01.01.59.28
(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Wed, 01 Aug 2018 01:59:30 -0700 (PDT)
Received-SPF: neutral (google.com: 198.54.115.167 is neither permitted nor denied by best guess record for domain of
[email protected]) client-ip=198.54.115.167;
Authentication-Results: mx.google.com;
dkim=pass
[email protected] header.s=default header.b="IouL/jzW";
spf=neutral (google.com: 198.54.115.167 is neither permitted nor denied by best guess record for domain of
[email protected])
[email protected]DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=cocacolaworld.win; s=default; h=Message-ID:Reply-To:Subject:To:From:Date: Content-Type:MIME-Version:Sender:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Y1czXGREpbeFiez0IH6QK93viyuIbKTKyYmIy//eipU=; b=IouL/jzW37a21IHMJCt3jDkp61 2JrSUsdz8hjUEi+PpK3Tz2MxxxhlR19sdj2E6Cz4ybKb4Oyrdi0NaG6Nr+jWmxL+duXUnmGlWTKdW cDN3u92X+8EIyFHmOnJorQZFLbrxgZfqTv3L7KhCu4GXt+XJMKtq+hI9dYWldmPyCDNaYkHMULtnD mGF/FAiMPp+HflA6c8vfC8az9hVcEfPkmpq09iyS+wuLAGftmJkC55uysH/c7354WqJbrKC9Z7NTD iTbXLgZFejCWZFzM1T6VbxVR3qY0EJd8lFq+rRKyhkmIFvgCJGH4c/jCEEeEDNJ5e4X60Em4/uLWw jr22TamA==;
Received: from [::1] (port=58878 helo=business33.web-hosting.com) by business33.web-hosting.com with esmtpa (Exim 4.91) (envelope-from <
[email protected]>) id 1fkmyc-001crl-3J; Wed, 01 Aug 2018 04:59:27 -0400
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="=_495cf3a774f3ff4f19795f6306683d5d"
Date: Wed, 01 Aug 2018 04:59:25 -0400
From:
[email protected]To: undisclosed-recipients:;
Subject: Congratulations
Reply-To:
[email protected]Mail-Reply-To:
[email protected]Message-ID: <
[email protected]>
X-Sender:
[email protected]User-Agent: Roundcube Webmail/1.3.3
X-OutGoing-Spam-Status: No, score=0.9
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - business33.web-hosting.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - cocacolaworld.win
X-Get-Message-Sender-Via: business33.web-hosting.com: authenticated_id:
[email protected]X-Authenticated-Sender: business33.web-hosting.com:
[email protected]X-Source:
X-Source-Args:
X-Source-Dir:
X-From-Rewrite: unmodified, already matched
--=_495cf3a774f3ff4f19795f6306683d5d
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset=US-ASCII
--
--=_495cf3a774f3ff4f19795f6306683d5d
Content-Type: multipart/related; boundary="=_74f9b1a7d56f2e9efcd13991123925bb"
--=_74f9b1a7d56f2e9efcd13991123925bb
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset=UTF-8
<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
=3DUTF-8" /></head><body style=3D'font-size: 10pt; font-family: Verdana,Gen=
eva,sans-serif'>
<p><br /></p>
<div>-- <br />
<p><img src=3D"cid:
[email protected]" widt=
h=3D"807" height=3D"208" /></p>
</div>
</body></html>
--=_74f9b1a7d56f2e9efcd13991123925bb
Content-Transfer-Encoding: base64
Content-ID: <
[email protected]>
Content-Type: image/jpeg; name=5ef824d9.jpeg
Content-Disposition: inline; filename=5ef824d9.jpeg; size=64348
--=_74f9b1a7d56f2e9efcd13991123925bb--
--=_495cf3a774f3ff4f19795f6306683d5d--