Sunday, April 6, 2014

2014-04-07 Email Scam of the Day #2

This one came with a Word attachment titled "WESTERN_UNION_WINNING_IDENTIFICATION_LETTER.doc" with a file size of 977kb.  Notice the different email addresses in the return-path/from and reply-to header fields.


==== Begin Scam Email =====

 

Open Your Attachment For More Details


===== Begin Scam Email Header Info =====

Return-path: <unionlo65@gmail.com>
Received: from omp1012.access.mail.bf1.yahoo.com ([unknown] [66.196.81.136])
 by vms172089.mailsrvcs.net
 (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009))
 with ESMTP id <
0N3M00J52615R720@vms172089.mailsrvcs.net> for
 <recipient_address_omitted>; Sun, 06 Apr 2014 09:39:07 -0500 (CDT)
Received: (qmail 43263 invoked by uid 1000); Sun, 06 Apr 2014 14:39:05 +0000
Received: (qmail 52426 invoked by uid 60001); Sun, 06 Apr 2014 14:39:03 +0000
Received: from [41.150.143.170] by web5706.biz.mail.ne1.yahoo.com via HTTP;
 Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024;
 t=1396795143; bh=kpQrbCrXyq3FnLKr2y0DrW4WT4zHjn7VpJR6u1tztSA=;
 h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-RocketYMMF:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type;
 b=nNJWG3H72vLHM+zZgl/an2Md+Zi7d9WatwQP9KWGF+xjCkufm/K/5uq6/QdBneWBWaFVhfU1sBGHHFDUtNFhN+rmEEa48Nv9Et9h6tLJ4hws0VB2DQQI6oQX4FERHPCYID++DuxzOOdN9c77VioFmfYtXOiuoNKgCAXADSKBAXk=
Date: Sun, 06 Apr 2014 07:39:03 -0700 (PDT)
From: Western Union Lottery <
unionlo65@gmail.com>
Subject: Congratulations! You have won
In-reply-to: <
1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
X-Originating-IP: [66.196.81.136]
To: undisclosed recipients: ;
Reply-to: Western Union Lottery <
mrfredrichard2013@yahoo.co.za>
Message-id: <
1396795143.8634.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
MIME-version: 1.0
X-Mailer: YahooMailWebService/0.8.182.648
Content-type: multipart/mixed; boundary="Boundary_(ID_qVeOTNi3bBw9jDX9SE/nyA)"
X-YMail-OSG: L6fAxeoVM1kMOjyFKDaNiG0ac_GNCoSe69lZI162yylvSxT
 dRnWJlb0QWbbuKHywtYD6RIR_Qv1PDqddiazG1P0UVuX3FFsXUD8.j8KMstz
 O_DetDO2aXCB98UsCwRFpe66Qq1qGkp4gZBn2wwpneP2UMTkkdz3jd_NU0At
 hQAn42sCJmpDSngBubsjV_czPqoKTvAEqCoOfoWAugaikH5B.i7DqKGkm2U4
 BvQmGrbgKe_svsW25fAhszc0p1_LcR9vMoUXIRuG0f9fW3Yp6pjHvsBHtHKT
 uOFY5UkWxSRZVVmOQw0OVg.Z2AHejFkLU8Trf6V7oX9PeMXES3AFb.yjn2Yc
 GWwLpju8yy1pyRhBGRsct9iXY9D1x_NMvw0_WspZvC2hdoclFJrKjZmKpWKH
 5rDq.pfR5eS8rE2qNBzJAn7kATuGC8GIpgU4ND8fILGDXjEPEP24T4ibBfzm
 55TJsbtODCMmNka5RipTfpYsLHgUqcPkSDJn5bweyii1dM79loMMYJWnmE7q
 KJcef77JGkswfyu8utbjuPXm9Ed9pDg8wVij6sqqkSQQHDZj3A0PgX.El
X-Rocket-MIMEInfo:
 002.001,CgpPcGVuIFlvdXIgQXR0YWNobWVudCBGb3IgTW9yZSBEZXRhaWxzIAEwAQEBAQ--
X-RocketYMMF: webzol
References: <
1396791310.83680.YahooMailNeo@web5706.biz.mail.ne1.yahoo.com>
 <
1396791418.12776.YahooMailNeo@web5703.biz.mail.ne1.yahoo.com>
 <
1396791543.64860.YahooMailNeo@web5704.biz.mail.ne1.yahoo.com>
Original-recipient: rfc822;<recipient_address_omitted>

No comments:

Post a Comment