Logo



If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/peyJjIjogOTUxOSwgImYiOiAwLCAibSI6IDg2MTksICJsIjogMzAsICJzIjogMSwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 8.0) pts rule name description ---- ---------------------- -------------------------------------------------- 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 1.3 GAPPY_SUBJECT Subject: contains G.a.p.p.y-T.e.x.t 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129492 - Sent on June 15, 2015, 12:54 pm by Toco.Warranty@isonlineorwhat.com
Greetings! You have a Bank Draft of $125.000.00 United States Dollars, but I have not heard from you.Then I went to deposited the Draft with FedEx Delivery,united kingdom,I traveled out of the country for a 3 Months Course and I will not come back till end of July .what you have to do now is to contact the FedEx Delivery as soon as possible to know when they will deliver your package to you,because of the expiring date. Contact Person: Mr.Daniel Cole Email Address: courierdefedexdelivery@hotmail.com Yours Faithfully, Mr Wellington. SpamAssassin Report (spam score: 1.2) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_PASS SPF: sender matches SPF record 1.2 MISSING_HEADERS Missing To: header 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 0.0 LOTS_OF_MONEY Huge... sums of money
Click to view scam #129488 - Sent on June 15, 2015, 12:45 pm by dkurten@williamson.edu
 Greetings My Dear,From feddag?s wife With your permission I want you to present my sincere initiatives and proposals. In the spirit offaith, solidarity, humanity and common sense appeal to your wisdom and kindness as a human of this planet with the requestfriendship sustains me if you consider setting up a foundation for humanitarian work with 7.5 million American United States dollarsinherited from my late husband who was an industrialist.I decided to donate these funds because I have no child and my daysare numbered according to my physician who always examines my health because I was diagnosed by cancer. I want you to use these fundsnationally and internationally to people without hope, against which we must not be careless. My name is Madam Safia feddag Aged 50, andchildless, always cheerful with a desire to do good and give those who need help. The principles which Irely in life are faith, humanity, solidarity, respect and trust.Please always put me in your daily prayers so that God will grant more days to my leaving and confirm these funds into your hand. Hoping to hearing from you soonest with your information that I will submit to the bank for the transfer of this money to youraccount and your delays in replying to this message will create an avenue of searching for another person that willunderstand the nature of  my situation in other handlethis donation funds gloriously to the Kingdom of God. Pleasereply urgently.Send your name, your picture, your telephoneand your occupation.Remainblessed with your family.Madam Safia feddag SpamAssassin Report (spam score: 5.8) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.54 listed in list.dnswl.org] 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (safiafedda[at]hotmail.fr) -0.0 SPF_PASS SPF: sender matches SPF record 0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit (safia feddag ) 1.2 MISSING_HEADERS Missing To: header 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 1.9 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129489 - Sent on June 15, 2015, 12:37 pm by safiafedda@hotmail.fr
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/ueyJjIjogOTUxOCwgImYiOiAwLCAibSI6IDg2MTgsICJsIjogMzAsICJzIjogMSwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129487 - Sent on June 15, 2015, 12:20 pm by Pharmacy@isonlineorwhat.com
Good Day. I am delighted to inform you that the Guarantee Trust Bank Plc (GTB) Management through the office of Mr. President have decided to call back all approved fund payment through offshore payment center following directives from UNITED NATIONS & WORLD BANK and have concluded arrangements to pay your beneficiary/contractual fund by cash through Diplomatic Agent.The Agent will be delivering the cash in a Machine sealed consignment to your door step as my bank have temporarily stopped further payment via wire transfer this quarter. Diplomatic. In this regard, we are going to send your inheritance/contractual part-payment of 10.5Million usd only to you via our accredited Diplomatic Agent shipping company and we have secured every needed document to cover the delivery of the money.Note:The money is synthetic nylon seal and padded with machine. The boxes are coming with a Diplomatic agent who will accompany the boxes to your house address. All you need to do is to send to me the below information's. 1) Full Name 2) Full house address 3) Your mobile phone 4) Any form of identification.The Diplomat attached will travel with it. He will call you immediately he arrives your country's airport. 5)Age and Occupation. Note:The diplomat does not know the original contents of the boxes. What l declared to them as the contents is Sensitive Photographic Film Materials for security reasons. I did not declare money to them please. If they call you and ask you the contents please tell them the same thing Ok. You will secure the Diplomatic immunity clearance certificate, which will make it pass every custom check point all over the world without hitch. Confirm the receipt of this message and re-send the requirements to me immediately you receive this message. Please I need your urgent reply because the boxes are scheduled to live as soon as we hear from you. I will call you as soon as l get your contact info and you can also call and make sure that you must reply me on the email bellow and my Direct telephone number you can call me for more directives (+234-7068161405) Thank's Dr Ahmed Bello SpamAssassin Report (spam score: 9.6) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.220.182 listed in list.dnswl.org] 0.7 MILLION_USD BODY: Talks about millions of dollars 0.9 URG_BIZ BODY: Contains urgent matter 2.8 HK_SCAM_N3 BODY: HK_SCAM_N3 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (markmaxwell909[at]gmail.com) 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 T_HK_NAME_FM_DR T_HK_NAME_FM_DR 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 3.6 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Click to view scam #129484 - Sent on June 15, 2015, 12:19 pm by markmaxwell909@gmail.com
Good Day. I am delighted to inform you that the Guarantee Trust Bank Plc (GTB) Management through the office of Mr. President have decided to call back all approved fund payment through offshore payment center following directives from UNITED NATIONS & WORLD BANK and have concluded arrangements to pay your beneficiary/contractual fund by cash through Diplomatic Agent.The Agent will be delivering the cash in a Machine sealed consignment to your door step as my bank have temporarily stopped further payment via wire transfer this quarter. Diplomatic. In this regard, we are going to send your inheritance/contractual part-payment of 10.5Million usd only to you via our accredited Diplomatic Agent shipping company and we have secured every needed document to cover the delivery of the money.Note:The money is synthetic nylon seal and padded with machine. The boxes are coming with a Diplomatic agent who will accompany the boxes to your house address. All you need to do is to send to me the below information's. 1) Full Name 2) Full house address 3) Your mobile phone 4) Any form of identification.The Diplomat attached will travel with it. He will call you immediately he arrives your country's airport. 5)Age and Occupation. Note:The diplomat does not know the original contents of the boxes. What l declared to them as the contents is Sensitive Photographic Film Materials for security reasons. I did not declare money to them please. If they call you and ask you the contents please tell them the same thing Ok. You will secure the Diplomatic immunity clearance certificate, which will make it pass every custom check point all over the world without hitch. Confirm the receipt of this message and re-send the requirements to me immediately you receive this message. Please I need your urgent reply because the boxes are scheduled to live as soon as we hear from you. I will call you as soon as l get your contact info and you can also call and make sure that you must reply me on the email bellow and my Direct telephone number you can call me for more directives (+234-7068161405) Thank's Dr Ahmed Bello SpamAssassin Report (spam score: 9.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.7 MILLION_USD BODY: Talks about millions of dollars 0.9 URG_BIZ BODY: Contains urgent matter 2.8 HK_SCAM_N3 BODY: HK_SCAM_N3 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (markmaxwell753[at]gmail.com) -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.216.174 listed in list.dnswl.org] 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 T_HK_NAME_FM_DR T_HK_NAME_FM_DR 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 3.6 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Click to view scam #129485 - Sent on June 15, 2015, 12:16 pm by markmaxwell753@gmail.com
             My names are Mr Bright Prince Kofi,  I hail from the Federal Republic of Ghana,I am 49 years old, I am married with three children. I am the Operation Director of Global Pay way Security Limited Ghana. I got the information concerning you from the foreign department of our chamber of commerce and after due consideration, I decided to contact you believing that by the Grace of God, that you will not disappoint me over this deal. I have been working with this company for over fifteen years. Within this period, I have watched with meticulous precision how African Heads of State and Government functionaries have been using Global Pay way Security Ltd to move sums of money USD, Pounds Sterling, French Francs (cash) to their foreign partners. They bring in these consignments of cash and secretly declare the contents as jewelries, gold, diamonds, precious stones, family treasures, and documents etc. Mobutu Sese Seko of Zaire (dead), Gen.Sanni Abacha of Nigeria (dead), Fode Sankoy of Sierra Leone, Babangida of Nigeria, Felix Houphet Boigny of Cote d"Ivoire (dead), Kanan Bedie of Cote d"Ivoire (Abidjan) etc. All these people have many consignments deposited with my office. Their foreign partners, friends and relatives are claiming most of these consignments. A lot of them are lying here unclaimed for as much as eight years. Nobody will ever come for them because in most cases, the Certificate of Deposit are never available to anybody except the depositors or company since most of them are dead.I have through the instrumentality of Global Pay way Security re-deposited all these unclaimed and overstayed consignment into the Vault Facility of a reputable Security Company in GHANA. Since the inception of the year 2009, our company's management has changed the procedure of claims of consignment, as soon as you are able to produce the secret information as contained in the secret file of any consignment,it will be released to you upon demand. I have finalized every arrangement for you to claim consignment No. 2521, 1422 containing $8 Million each. I will supply you with all the information and documents that will facilitate your easy claim of the consignment.Upon your positive reply of this letter, This business is risk free as I have taken necessary preventive measures.The mode of sharing will be (50-50), you can reach me by email  and I will direct you on what to do.Upon your positive consideration and reply of this letter. Expedite action. Yours faithfully, Bright Prince Kofi SpamAssassin Report (spam score: 3.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (brightprince01[at]gmail.com) -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.50 listed in list.dnswl.org] 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129483 - Sent on June 15, 2015, 12:16 pm by brightprince01@gmail.com
15-06-2015 Compliment of the season.. I am Mr. Ronald Ellman; the Personal Financial Consultant to Mr.Saif Al-Islam Gaddafi, son of Late Libyan leader Muammar Gaddafi. With due respect, I have decided to contact you on a business proposal that will be very beneficial to you and my Client (Mr.Saif Al-Islam Gaddafi) at the end of the transaction. Due to current developments in Libya and incarceration of my client, he requires a partnership of a reliable and trustworthy person to help in the RE-PROFILING of a total of $65 Million dollars deposited with a defunct Finance House in the United States. Upon your positive response to this proposal, I will furnish you with more details. I will not fail to inform you that you stand benefit 40% of the fund as gratification for your role in this transaction. Please I wait for your response. Regards and respect, Mr. Ronald Ellman. SpamAssassin Report (spam score: 6.8) pts rule name description ---- ---------------------- -------------------------------------------------- 2.7 HK_SCAM_N1 BODY: HK_SCAM_N1 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.46 listed in list.dnswl.org] 1.6 SUBJ_ALL_CAPS Subject is all capitals -0.0 SPF_PASS SPF: sender matches SPF record 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 T_MONEY_PERCENT X% of a lot of money for you 0.0 MONEY_FRAUD_5 Lots of money and many fraud phrases 3.2 ADVANCE_FEE_3_NEW_MONEY Advance Fee fraud and lots of money
Click to view scam #129479 - Sent on June 15, 2015, 12:06 pm by test@euro-gas.com
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/meyJjIjogOTUxNywgImYiOiAwLCAibSI6IDg2MTcsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129478 - Sent on June 15, 2015, 11:56 am by Peak.Life@isonlineorwhat.com
Start Your Day With Unlimited Fresh Tools Only @ Www. smtpmercantile .in SpamAssassin Report (spam score: 1.8) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.42 listed in list.dnswl.org] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.8 DKIM_ADSP_NXDOMAIN No valid author signature and domain not in DNS -0.0 SPF_PASS SPF: sender matches SPF record 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
Click to view scam #129477 - Sent on June 15, 2015, 11:44 am by seller@smtpsell.com
If you cannot click the link above, Copy & Paste this link: http://doyoulikeeeme.com/zeyJjIjogOTQ4OCwgImYiOiAwLCAibSI6IDg1OTEsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: doyoulikeeeme.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: doyoulikeeeme.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: doyoulikeeeme.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129476 - Sent on June 15, 2015, 11:39 am by From.Kroger@doyoulikeeeme.com
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/xeyJjIjogOTUxNiwgImYiOiAwLCAibSI6IDg2MTYsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: ) pts rule name undefined
Click to view scam #129471 - Sent on June 15, 2015, 11:35 am by Bank.Account@isonlineorwhat.com
Date: Mon, 15 Jun 2015 03:30:53 -0700From: demainklose@yahoo.comSubject: Contact UPS ( ups-speedydispatch@outlook.com )After much attempts to reach you on phone, I deemed it necessary and urgent to contact you via your e-mail address and to notify you finally about your outstanding compensation payment.After the last annual calculation of your Banking/Financial activities, you are qualified and eligible to receive a compensation check payment of $475,950.00 USD from the 2015 United Nations Compensation Commission Payment Reconciliation program.Your Cashier?s Check ($475,950.00) has been forwarded to the United Parcel Service for shipment to you. Send your Name, Resident Address, Country and Telephone number to the United Parcel Service (UPS) in order to receive your compensation check payment.United Parcel Service (UPS)Contact Name: Ahmad MooreContact E-mail: ups-speedydispatch@outlook.comPlease take note that you will pay a shipping/handling fee of $87 USD to receive your cashier check payment from the United Parcel Service (UPS).Demain Klose.Information Officer,United Nations Human Settlements Program.
Click to view scam #129473 - Sent on June 15, 2015, 11:35 am by demainklose@yahoo.com
Begin forwarded message:From: Alveiro De Jesús Monsalve Zapata <ALVEIRO.MONSALVE@javeriana.edu.co>Date: 15 June 2015 11:05:09 BSTTo: "info@mail.com" <info@mail.com>Subject: Loan We offer Private,commercial and any type of loans with very minimal annual Interest Rate of 3% contact us via E-mail :norton_finance_loan_services@hotmail.com
Click to view scam #129469 - Sent on June 15, 2015, 11:14 am by ALVEIRO.MONSALVE@javeriana.edu.co
 Assaalamu Alaikkum my dear friend, I am Mr Afzzal Ahmed, the chief operating officer with my bank and I want to inform you that an amount of US$31.6 million will be moved on your name as the Foreign Business Partner to our late deceased customer Mr Waleed Hazaa Salim, I need your help to receive this money as we shall share the money in the ratio of 60:40%. You will receive this amount through a bank wire transfer. Please send your full names, direct telephone numbers, and home address, more details of how to claim the form will be given upon your reply. Your quick response will be highly appreciated. Yours sincerely, Mr. Afzzal Ahmed.SpamAssassin Report (spam score: 9.1) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (afzzalahmed[at]voila.fr) -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no trust [106.10.148.106 listed in list.dnswl.org] 0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in digit (edetvictor95[at]yahoo.in) 1.2 MISSING_HEADERS Missing To: header 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 1.9 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 0.0 TVD_SPACE_RATIO TVD_SPACE_RATIO 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 2.0 MIME_NO_TEXT No (properly identified) text body parts 0.6 BODY_URI_ONLY Message body is only a URI in one line of text or for an image 2.0 SPOOFED_FREEM_REPTO Forged freemail sender with freemail reply-to
Click to view scam #129474 - Sent on June 15, 2015, 11:12 am by afzzalahmed@voila.fr
Government pays you to go solar SpamAssassin Report (spam score: 3.8) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: rangeboer.com] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 0.1 MISSING_MID Missing Message-Id: header 0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily 0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable
Click to view scam #129468 - Sent on June 15, 2015, 11:09 am by @
Date: Mon, 15 Jun 2015 18:55:00 +0900From: officefle138@gmail.comSubject: CONTACT AGENT MR KENNETH RICE WITH ALL YOUR DETAILS.To: Attention:We have finally succeeded in getting your package worthy of $12.5Million out of delivery your  consignment with the help of Dr David Don Attorney General of Federal High Court of Justice Benin which act as your foreign Attorney representative here in Benin.So every necessary arrangement has been made successfully with the Agent Mr Kenneth Rice of your package and every Documents guiding your delivery is well updated so you are advice to re-confirm your full delivery information to the Agent right now as he is currently at Los Angeles International Airport in USA with your consignment box, As he called me this morning to inform me that he misplaced your delivery address which he has.So you are advice to reconfirm your full delivery information to the diplomat and call him with this  Number 805 203-6461 so as to have easy conversation with him and to enable you give him full direction to get your package delivered to you and hand you over your package safe and sound, Furthermore you are advice to be very fast as the Agent Mr Kenneth Rice has no time to waste due to his flight ticket, So the Information you are Required to Reconfirm to the Agent is as Follow.(1)Your Full Name(2)Mobile Phone Number(3)Current Home Address(4)Fax Number(5)Country(6)City(7)Nearest AirportAs he is at Los Angeles International Airport in USA right now because of the Searching and Scanning of the consignment box which made him to misplace your address (8) A Copy of Your I D For attached Identification. So contact him to deliver your package first thing tomorrow morning possibly today, So get back to us immediately you contact the Agent to make sure that your fund has getting to you without any hitch,Please try to make sure that you contact him with this EmailName- Agent... Mr Kenneth RiceCall or Email :....805 203-6461So contact him to deliver your Consignment box first thing tomorrow morning possibly today, So get back to us immediately you contact the Agent to make sure that your fund has getting to you without any hitch, Furthermore remember the Agent delivering the Consignment Box does not know the content of that consignment box is money, Because the Attorney which represented you registered it as a family value to avoid hitch during the delivery so unknown circumstances should you let him know the content of that consignment box is to avoid lost of your fund as your Consignment was Sign and Stamp by Federal Ministry of Justice to make sure that it is protected until it gets to you..RegardsRev. Jerry MarkMobile: (+229)  98582119
Click to view scam #129465 - Sent on June 15, 2015, 11:09 am by officefle138@gmail.com
Zero Down Auto Loans - All Credit Approved!. SpamAssassin Report (spam score: 3.8) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: importge.com] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 0.1 MISSING_MID Missing Message-Id: header 0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily 0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable
Click to view scam #129467 - Sent on June 15, 2015, 11:09 am by @
Advert
Date: Mon, 15 Jun 2015 02:55:40 -0300Subject: Unusual sign-in activity Microsoft account teamFrom: outlook@email.microsoft.comMicrosoft accountThanks for verifying your Microsoft accountSign-in to upgrade your Microsoft account. To keep your email account safe, You require an extra security challenge.Continue with Upgrade To opt out or change where you receive security notifications, click here.Thanks,The Microsoft account team.
Click to view scam #129460 - Sent on June 15, 2015, 10:31 am by outlook@email.microsoft.com
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/meyJjIjogOTUxNSwgImYiOiAwLCAibSI6IDg2MTUsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129459 - Sent on June 15, 2015, 10:17 am by Attorney.Help@isonlineorwhat.com
  Beloved, My sincere greetings to you, Please permit me to introduce myself, My name is Vivian Justin Yak, 24years old female (single) originated from Sudan. I appeal to you to exercise a little patience and read through my letter although, we have neither met in person but I decided to contact you personally for a long term business Relationship and investment assistance in your country. My father Dr. Justin Yak Arop was the former Minister for SPLA Affairs and Special Adviser to President Salva Kiir of South Sudan for Decentralization. My father Dr. Justin Yak and my mother including other top Military officers and top government officials had been on board when the plane crashed on Friday May 02, 2008. My late Father Dr. Justin Yak was an investor, he invested his fund to stock exchange market, Gold storing investment, he was a preference shareholder in Shell Petroleum Company and deals in Real Estate building investment. I have chosen to contact you after my prayers and I believe that you will not betray my trust. But rather take me as your own sister. Though you may wonder why I am so soon revealing myself to you without knowing you, well, I will say that my mind convinced me that you are the true person to help me. I want you to stand as my trustee and clear my inheritance fund to your Bank account for investment purpose while I will spend the rest of my life with you after the transfer. More so, I will like to disclose much to you if you can help me to relocate to your country because my uncle has threatened to assassinate me. The amount is $12.8 Million and I have confirmed from the bank. You will also help me to place the money in a more profitable business venture in your Country. However, you will help by recommending a nice University in your country so that I can complete my studies. It is my intention to compensate you with 25% of the total money for your services while 5% will be for any expense that may occur during the process and the balance shall be my capital in your establishment. I have no knowledge of international transaction of this nature but it occurred to me that transfer of this type must involve expenditure. As soon as I receive your interest in helping me, I will put things into action immediately. In the light of the above, I shall appreciate an urgent message indicating your ability and willingness to handle this transaction sincerely by replying to me, Please do keep this only to your self, I beg you not to disclose it till i come over because I am afraid of my wicked uncle who has threatened to kill me. Sincerely yours, Vivian Justin Yak. SpamAssassin Report (spam score: 6.9) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.214.177 listed in list.dnswl.org] 2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL [212.52.159.74 listed in zen.spamhaus.org] 0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server [212.52.159.74 listed in dnsbl.sorbs.net] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (vivianyak827[at]gmail.com) 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 1.2 MISSING_HEADERS Missing To: header 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129458 - Sent on June 15, 2015, 9:58 am by vivianyak827@gmail.com
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/ueyJjIjogOTUxNCwgImYiOiAwLCAibSI6IDg2MTQsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: ) pts rule name undefined
SpamAssassin Report (spam score: 5.7) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (webkjdh209[at]outlook.com) -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.41 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit ( ) 1.2 MISSING_HEADERS Missing To: header 1.9 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129455 - Sent on June 15, 2015, 9:44 am by webkjdh209@outlook.com
Attention: Beneficiary,   This is to officially inform you that we have verified your inheritance file and found out that why you have not received your payment is because you have not fulfilled the obligations given to you in respect of your inheritance payment.   Secondly we have been informed that you are still dealing with none officials in the bank and all your attempt to secure the release of the fund to you has been abortive. We wish to advise you that such an illegal act like this have to stop if you wish to receive your payment since we have decided to bring a solution to your problem. Right now we have arranged your payment through our swift ATM card payment center that is the latest instruction from Mr. President, General Mohammadu Buhari  (gcfr) president federal republic of Nigeria and federal ministry of finance.   This card center will send you an atm card which you will use to withdraw your money in any atm machine in any part of the world, but the maximum is three thousand dollars per day, so if you wish to receive your fund this way please let us know by contacting the card payment center and also send the following information to enable him proceed immediately:   First name :. Last Name :. Age: ... Gender: .. Your address: .. E-mail address: Phone: .. Mobile phone. Fax :. Occupation:. Country:   However, kindly find below the contact person: Mr.Godwin Emefiele Governor Central Bank of Nigeria Tel: +234-802-212-6910 Email: centbank2015@gmail.com   The ATM card payment center has been mandated to issue out $10,000,000.00 as part payment for this fiscal year 2015. Also for your information, you have to stop any further communication with any other person(s) or office(s) to avoid any hitches in receiving your ATM payment.     Note that because of impostors, we hereby issue you our code of conduct, which is (atm-222) so you have to indicate this code when contacting the card center by using it as your subject.     Best regards, Honourable Minister of Foreign Affairs. H.E Chief Ojo Maduekwe, CFR Address: No. 3 Maputo Street, Wuse Zone 3,Abuja SpamAssassin Report (spam score: 23.2) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.214.177 listed in list.dnswl.org] 3.3 DEAR_BENEFICIARY BODY: Dear Beneficiary: 0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 NSL_RCVD_FROM_USER Received from User 0.0 TVD_RCVD_IP Message was received from an IP address 1.6 SUBJ_ALL_CAPS Subject is all capitals -0.0 SPF_PASS SPF: sender matches SPF record 0.0 T_US_DOLLARS_3 BODY: Mentions millions of $ ($NN,NNN,NNN.NN) 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 FROM_MISSP_XPRIO Misspaced FROM + X-Priority 2.0 YOU_INHERIT Discussing your inheritance 0.0 FROM_MISSP_MSFT From misspaced + supposed Microsoft tool 2.0 FSL_NEW_HELO_USER Spam's using Helo and User 0.0 AXB_XMAILER_MIMEOLE_OL_024C2 Yet another X header trait 3.4 MSOE_MID_WRONG_CASE MSOE_MID_WRONG_CASE 0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only 0.0 FROM_MISSP_TO_UNDISC From misspaced, To undisclosed 0.0 FROM_MISSP_USER From misspaced, from "User" 0.0 MONEY_FROM_MISSP Lots of money and misspaced From 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 0.0 FROM_MISSPACED From: missing whitespace 0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable 0.5 MONEY_ATM_CARD Lots of money on an ATM card 2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook 0.0 FILL_THIS_FORM Fill in a form with personal information 2.2 FILL_THIS_FORM_LOAN Answer loan question(s) 0.0 FROM_MISSP_FREEMAIL From misspaced + freemail provider 0.0 MONEY_FORM Lots of money if you fill out a form 2.3 MONEY_FRAUD_8 Lots of money and very many fraud phrases 1.6 ADVANCE_FEE_5_NEW_FRM_MNY Advance Fee fraud form and lots of money
Click to view scam #129451 - Sent on June 15, 2015, 9:38 am by admin1@idola.net.id
Attention: Beneficiary The United Nations has deposited your Over-due payment of $950,000.00, United States Dollars with this bank (Lloyds.TSB Bank London), This is regarding the draws the Secretary General Ban Ki-Moon organized on his visit to some countries around the world last Month to help individuals/Scam victims and charity organizations. Your name & email was listed among those who are to benefit from these compensation exercise. The Lloyds.TSB Bank of London United Kingdom will be waiting to hear from you. Please note that this payment of $950,000.00, United States Dollars has also been programmed into an MASTER ATM CARD signed and approved in your Name with Registration Reference No:FDXB/xxx/100. Kindly get back to this office with your details as listed below. (+).Residential Address:- (+).Full Names:- (+).Phone Number:- (+).A scanned copy of your ID or passport:- MRS. MARGARET BROWN. DIRECTOR INVESTIGATION/OPERATIONS UNIT Lloyds.TSB BANK. TEL: (+44)7011149196 FAX: (+44)7089149196 London, United Kingdom. SpamAssassin Report (spam score: ) pts rule name undefined
Click to view scam #129453 - Sent on June 15, 2015, 9:30 am by gundam_vince@yahoo.com.sg
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/reyJjIjogOTUxMywgImYiOiAwLCAibSI6IDg2MTMsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 8.3) pts rule name description ---- ---------------------- -------------------------------------------------- 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 1.7 BAD_CREDIT BODY: Eliminate Bad Credit 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 T_DKIM_INVALID
Click to view scam #129447 - Sent on June 15, 2015, 9:28 am by VivaLoan@isonlineorwhat.com
.ielka {font-family: Arial, Helvetica, sans-serif} .s {font-family: Arial, Helvetica, sans-serif; color: rgb(51, 51, 51); } ??? ?? ?????? ???? ?????, ??? ?????? ?????? ??????????? last minute ???????? ????? -80% Jhiva -50% Lee, Vans, Pepe Jeans -50% Calvin Klein -70% ????? ?? ?? ????????? ???? ?????????? ?????????, ????????? ?? ????????? ????????? ? ?????????? ??????????? ?????? ????????? ????????? ????, ??? ???????? ? ????? ?? ??????????: ????? 1000, ?????? ??????????, ????? ????????, ???. ???? ???????????? ? 10, ??. 3, ? ??? 202706277, ?????? ??? ??????????? ?????????? ? ??? ?????? ?????? ??????? ?? ???????? ?? ?????, ??? ????? ??? ??????? ?? ? ??????? ?? ?? ???????????? ??? ????? goldensales.bg ?????? ?????? contact@goldensales.bg ? ????????? ?? ?????, ?? ?? ????????? ?????? ?????? ?? ?????? ???????????. ?? ????? ?? ????????? ???? ???????? ????? ?? ?? ???????. ??? SpamAssassin Report (spam score: 5.9) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.220.178 listed in list.dnswl.org] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_PASS SPF: sender matches SPF record 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: goldensales.bg] 2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level above 50% [cf: 100] 0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50% [cf: 100] 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129450 - Sent on June 15, 2015, 9:24 am by contact@nm.goldensales.bg
FROM THE DESK OF Mr Khan Omar Ali SaeedAUDITS & ACCOUNTS DEPTAFRICAN DEVELOPMENT BANKOuagadougou Burkina Faso Private Phone Number +22676519849                 Attention: Please  I am Mr Khan Omar Ali Saeed the manager Audit & Accounts dept. in the African Development Bank(ADB). I am writing to request your assistance to transfer the sum of $15, 000.000.00 [Fifteen million, United States dollars) into your accounts.  The above sum belongs to our deceased customer late Mr. John korovo who died along with his entire family in the Benin plane crash 2004 and since then the fund has been in a suspense account. After my further investigation, I discovered that Mr. John korovo died with his next of kin and according to the laws and constitution guiding this banking institution, it states that after the expiration of (7) seven years, if no body or person comes for the claim as the next of kin, the fund will be transferred to national treasury as unclaimed fund. Because of the static of this transaction I want you to stand as the next of kin so that our bank will accord you the recognition and have the fund transferred to your account.  The total sum will be shared as follows: 60% for me, 40% for you and all incidental expenses that may occur during the transfer process will be incurred by both of us. The transfer is risk free on both sides hence you will follow my instructions till the fund get to your account.  More detailed informations with the official application form will be Forwarded to you to explain more comprehensively what is required of you. You are free to call me through my private telephone number. Your Full Name.......................... ...Your Sex........................... ........Your Age........................... ........Your Country....................... ........Your Occupation.................... ......Your Personal Mobile Number...................... Thanks   Mr Khan Omar Ali Saeed  +22676519849   SpamAssassin Report (spam score: 21.9) pts rule name description ---- ---------------------- -------------------------------------------------- 0.9 URG_BIZ BODY: Contains urgent matter 0.7 MILLION_USD BODY: Talks about millions of dollars 2.5 HK_SCAM_N2 BODY: HK_SCAM_N2 2.7 UNCLAIMED_MONEY BODY: People just leave money laying around 0.4 INVALID_DATE Invalid Date: header (not RFC 2822) 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (mr.salif_kavara5[at]terra.com.pe) -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no trust [208.84.243.123 listed in list.dnswl.org] 1.6 SUBJ_ALL_CAPS Subject is all capitals -0.0 SPF_PASS SPF: sender matches SPF record 0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in digit (mr.salif_kavara5[at]terra.com.pe) 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 LOTS_OF_MONEY Huge... sums of money 1.9 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC 1.8 MISSING_MIMEOLE Message has X-MSMail-Priority, but no X-MimeOLE 0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily 1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different freemails 0.0 T_MONEY_PERCENT X% of a lot of money for you 0.0 FILL_THIS_FORM Fill in a form with personal information 0.0 T_FILL_THIS_FORM_LONG Fill in a form with personal information 2.2 FILL_THIS_FORM_LOAN Answer loan question(s) 0.0 MONEY_FORM Lots of money if you fill out a form 2.3 MONEY_FRAUD_8 Lots of money and very many fraud phrases 1.6 ADVANCE_FEE_5_NEW_FRM_MNY Advance Fee fraud form and lots of money
Click to view scam #129446 - Sent on June 15, 2015, 9:17 am by mr.salif_kavara5@terra.com.pe
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/weyJjIjogOTUxMiwgImYiOiAwLCAibSI6IDg2MTIsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Sent from my iPhoneBegin forwarded message:From: Minnie Lucas <administrador@ludonatura.com>Date: 15 June 2015 00:09:26 BSTSubject: 1 New SnapHookupMsgReply-To: Minnie Lucas <administrador@ludonatura.com> want to have some fun? I'm 28/f with a double D chest... want to have some fun?. My username is SxyQueen19 check out my profile here CHAT SOON
Click to view scam #129440 - Sent on June 15, 2015, 9:05 am by administrador@ludonatura.com
Begin forwarded message:From: "Amazon UK" <service@rakuten.co.uk>Date: 15 June 2015 07:53:53 BSTTo: inbox <service@rakuten.co.uk>Subject: Important security message Dear Member, Due to the on-going security upgrade at Amazon, all customers are required to update their information to the new security system to enable a faster, easier and more secure online Shopping experience. Sign In Here to proceed PLEASE NOTE: This is a compulsory measure. Failure to update your information will lead to service suspension. Amazon Online Shopping
Click to view scam #129437 - Sent on June 15, 2015, 9:03 am by service@rakuten.co.uk
body {height: 100%; color:#000000; font-size:12pt; font-family:arial,helvetica,sans-serif;}Vá?ený zákazníkD?a 15.06.2015 na?e bezpe?nostné internetové zabezpe?ení zjistil pokus o prihlásenie do vá?ho ú?tu, ktorý mát? vedený v na?ej Tatrabanke a to z nám neznámej IP. adresy v Ruskej federácii.Prosím pre potvrdenie va?ej informácie kliknete tu.bud?te neodkladn? kontaktovaný na?ím bezpe?nostným pracovníkom, ktorý s vami provede n?zbyzné kroky k vylep?ení zabezpe?ení Vá?ho ú?tu. Zárove? vás chceme ubezpe?it, ?e na?e bezpe?nostné odd?lení detekovalo hrozbu v?as, a preto sa nemusít? obáva? straty ?i zneu?ití va?ich finan?ných prostriedkov.?akujeme za pochopenie a t??íme sa na va?u buduc? spolupráciu. Michal LidayVa?a Tatrabanka SpamAssassin Report (spam score: 2.5) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.43 listed in list.dnswl.org] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_PASS SPF: sender matches SPF record 1.2 MISSING_HEADERS Missing To: header 2.0 MIME_NO_TEXT No (properly identified) text body parts
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/ueyJjIjogOTUxMSwgImYiOiAwLCAibSI6IDg2MTEsICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
-----Original Message----- From: MR. BILL GATES <BILLG4316@GB.COM> Sent: Sun, Jun 14, 2015 11:19 pm Subject: $5 MILLION USD DONATION FROM MR BILL GATES Greetings to You You have been gifted $5 MILLION USD From Mr Bill Gates. Contact me at this email for your claim: donations2015@qq.com I hope this information meet you well as I know you will be curious to know why/how I selected you to receive a sum of $5,000,000,00 USD, our information below is 100% legitimate, please see the link below: http://www.cnet.com/news/bill-and-melinda-gates-top-forbes-list-as-most-philanthropic-americans/ I BILL GATES and my wife decided to donate the sum of $5,000,000,00 USD to you as part of our charity project to improve the 10 lucky individuals all over the world from our $65 Billion Usd I and My Wife Mapped out to help people. We prayed and searched over the internet for assistance and i saw your profile on Microsoft email owners list and picked you. Melinda my wife and i have decided to make sure this is put on the internet for the world to see. as you could see from the webpage above,am not getting any younger and you can imagine having no much time to live. although am a Billionaire investor and we have helped some charity organizations from our Fund. You see after taken care of the needs of our immediate family members, Before we die we decided to donate the remaining of our Billions to other individuals around the world in need, the local fire department, the red cross, Haiti, hospitals in truro where Melinda underwent her cancer treatment, and some other organizations in Asia and Europe that fight cancer, alzheimer's and diabetes and the bulk of the funds deposited with our payout bank of this charity donation. we have kept just 30% of the entire sum to our self for the remaining days because i am no longer strong am sick and am writing you from hospital computer.and me and my wife will be traveling to Germany for Treatment. To facilitate the payment process of the funds ($5,000,000.00 USD) which have been donated solely to you, you are to send us your full names................. your contact address................ your personal telephone number............... so that i can forward your payment information to you immediately. I am hoping that you will be able to use the money wisely and judiciously over there in your City. please you have to do your part to also alleviate the level of poverty in your region, help as many you can help once you have this money in your personal account because that is the only objective of donating this money to you in the first place. Thank you for accepting our offer, we are indeed grateful You Can Google my name for more information: Mr Bill Gates or Bill & Melinda Gates Foundation REMAIN BLESSED Regards Mr Bill Gates
Click to view scam #129429 - Sent on June 15, 2015, 8:35 am by BILLG4316@GB.COM
Assalam-o-Alaikum (Dear Friend) I am Mrs. Aisha Gaddafi, 38years old and a widow with three children, i am the only biological daughter of late Libyan President by birth and my Father(Muammar Gaddafi) was killed on 20 October 2011 and three of my Brother were also killed during the war, including the former National Security Adviser Mutassim Gaddafi, who died at the hands of the rebels on the same day. I was granted refuge in Algeria with my mother and brother and Three days after my arrival i gave birth to my baby girl called Safiya. For more knowledge, kindly read the below news: http://www.bbc.com/news/world-africa-19966059 After some time, the Algerian government accused me of setting fires on the house and burning the Algerian President's picture. However, that was how I was booted out of Algeria. I left Algeria to Burkina Faso where i am presently seeking a confidential asylum. You can read the news for more information: http://www.theguardian.com/world/shortcuts/2013/apr/03/muammar-gaddafi-daughter-out-algeria I inherited Nine Million Five Hundred Thousand United State Dollar ($9.500.000.00) from my late Father (late Gen. Muammar Gaddafi) and i need an investment Partner, however, I am curious in you for an investment project assistance in your country, may be from there, we can build a business relationship in the near future. Please write me for possible business and investment co-operation in your country. More so, i am ready to facilitate any business that is capable of generating a good income on investment. Iam willing to offer you 30% of $9.500.000.00 as a compensation for your unconditional support and the balance shall be my investment capital under your control. Can i trust you?, Can you handle this project?, As you indicate your willing interest, i shall provide you more information about me to enable you know whom you are dealing with. I shall appreciate an urgent RESPONSE indicating your willingness to handle the transaction and the investment project with good mind. You can reach me by email: [ aishaalqadafi@gmail.com ] Your Urgent Reply Will Be Appreciated Mrs Aisha Gaddafi SpamAssassin Report (spam score: 20.9) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: theguardian.com] 0.7 MILLION_USD BODY: Talks about millions of dollars 2.7 HK_SCAM_N1 BODY: HK_SCAM_N1 0.9 URG_BIZ BODY: Contains urgent matter 0.0 FSL_CTYPE_WIN1251 Content-Type only seen in 419 spam 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 NSL_RCVD_FROM_USER Received from User 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.214.171 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 1.2 MISSING_HEADERS Missing To: header 0.0 T_US_DOLLARS_3 BODY: Mentions millions of $ ($NN,NNN,NNN.NN) 0.0 LOTS_OF_MONEY Huge... sums of money 0.0 FROM_MISSP_XPRIO Misspaced FROM + X-Priority 1.9 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC 0.0 FROM_MISSP_MSFT From misspaced + supposed Microsoft tool 2.0 FSL_NEW_HELO_USER Spam's using Helo and User 0.0 AXB_XMAILER_MIMEOLE_OL_024C2 Yet another X header trait 3.4 MSOE_MID_WRONG_CASE MSOE_MID_WRONG_CASE 0.0 FROM_MISSP_USER From misspaced, from "User" 0.0 MONEY_FROM_MISSP Lots of money and misspaced From 0.0 TO_NO_BRKTS_FROM_MSSP Multiple formatting errors 0.0 FROM_MISSPACED From: missing whitespace 0.0 T_FROM_MISSP_DKIM From misspaced, DKIM dependable 0.0 T_MONEY_PERCENT X% of a lot of money for you 2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook 2.3 MONEY_FRAUD_8 Lots of money and very many fraud phrases 3.6 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Click to view scam #129434 - Sent on June 15, 2015, 8:32 am by scc@chu.edu.tw
Advert
Dear Buyer,ENCEINTE FRANÇAISNous envoyons liste Stock Cars à vous, Vous pouvez trouver la voiture de moins de1.000 US $ et moins de 2.000 US $ avecd'autres des prix plus élevés ,TELECHARGER votre attachement et de visualiser les photos avec les prix indiqués , AUSSI CAR SELECT que vous souhaitez acheter , afin que nous puissions donner les renseignements coût total pour la livrons dans votre pays PORT DE MER,Please utilisé Google Translator pour traduire de l'anglais au français,Si vous ne parlez pas anglais,ENGLISH SPEAKER:You can find the CarUnder US$ 1,000 and Under US$ 2,000with other higher prices,We can rapidly supply any kind of used cars and Spare Parts to the world., We can find out your requested cars / tires / parts Within our huge network,You can find good Condition Cheap Car,Wagon,SUV,Hatch back, Sedan,Van/Truck Crane Left and Right Hand Cars, Some are not posted here, Request your Choice soWe can make it available to you,We have USA, Germany,South Korea, Japan,India and UK Cars,We ship used Cars globally to Africa, Asia, Middle East, Caribbean region, Oceania, South America, and Europe with offices in 15 countries.Decent and energetic staffs are always ready for 24 hours Customer attendance,Reliability is always there and we have built up excellence in used car industry for 20 years, and have put the finest focus on reliability,DOWNLOAD YOUR ATTACHMENT AND VIEW THE PHOTOS WITH LISTED PRICE*****************************************************************************************Send us vehicle you want to purchase from the attachment if your ready to purchase the cars also sendyour Mobile number,your name andyour Country Seaport Name for calculation of total Shipment cost (CIF) from our Seaport to your Country Seaport,Thank you!Best RegardsDr. Kazuya TANAKA(Representative Director)
Click to view scam #129433 - Sent on June 15, 2015, 8:21 am by jumvea_jpnusedcars@live.com
Free business cards. .rjbvydymikej{color:#6c0b89;} SpamAssassin Report (spam score: 6.3) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.192.46 listed in list.dnswl.org] 0.8 DKIM_ADSP_NXDOMAIN No valid author signature and domain not in DNS -0.0 SPF_PASS SPF: sender matches SPF record 1.2 MISSING_HEADERS Missing To: header 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: aristoshaigiadd.com] 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: aristoshaigiadd.com] 0.7 HTML_IMAGE_ONLY_28 BODY: HTML: images with 2400-2800 bytes of words 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.6 URIBL_SBL Contains an URL's NS IP listed in the SBL blocklist [URIs: aristoshaigiadd.com]
Dear Sir/Madam, We are interested in purchasing your products and we sincerely hope toestablish a long-term business relation with your esteemed company. Pleasekindly send me your latest catalog. Also, inform me about the Minimum OrderQuantity, Delivery time or FOB, and payment terms warranty. Your earlyreply is highly appreciated.Thank You!Best Regards,Mr.Venkat ratnamApex Global LTD.Malaysia Sdn Bhd operates restaurants, kiosks, and cafes. The company is based in Kuala Lumpur, Malaysia Sdn Bhd is a subsidiary of ApexPal International LtdTel:+6085431122 SpamAssassin Report (spam score: 5.4) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (mrvenkat258[at]gmail.com) -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.220.172 listed in list.dnswl.org] 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 0.0 TVD_SPACE_RATIO TVD_SPACE_RATIO 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 2.0 MIME_NO_TEXT No (properly identified) text body parts 2.7 TVD_SPACE_RATIO_MINFP TVD_SPACE_RATIO_MINFP
Click to view scam #129430 - Sent on June 15, 2015, 8:05 am by mrvenkat258@gmail.com
Dear Sirs, I'm Amelia from Shanghai Mikun Industrial Co.,Ltd. We mainly supply chemical materials used for polyurethane foam, silicone molds production.Product catalogue:1). Polyether Polyol, MDI,TDI 80/202). Polyetheramine(D-230,D-400,D-2000)3). Liquid Silicone Rubber, DETDA/E100 We are also a agent of other chemical materials.Any requirements, please feel free email us, thanks. Ameliaamelia@shmikun.com www.shmikun.com
Click to view scam #129419 - Sent on June 15, 2015, 8:04 am by amelia@shmikun.com
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/oeyJjIjogOTUxMCwgImYiOiAwLCAibSI6IDg2MTAsICJsIjogMzAsICJzIjogMSwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
If you cannot click the link above, Copy & Paste this link: http://isonlineorwhat.com/peyJjIjogOTUwOSwgImYiOiAwLCAibSI6IDg2MDksICJsIjogMzAsICJzIjogMCwgInUiOiAxOTM0MTIxMTAsICJ0IjogMSwgInNkIjogMH0= SpamAssassin Report (spam score: 6.6) pts rule name description ---- ---------------------- -------------------------------------------------- 2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist [URIs: isonlineorwhat.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record 0.3 URIBL_RHS_DOB Contains an URI of a new domain (Day Old Bread) [URIs: isonlineorwhat.com] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: isonlineorwhat.com] 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Click to view scam #129416 - Sent on June 15, 2015, 7:45 am by AT&T@isonlineorwhat.com
      view the attach copy and get back to us. SpamAssassin Report (spam score: 4.4) pts rule name description ---- ---------------------- -------------------------------------------------- -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.214.179 listed in list.dnswl.org] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL [200.11.173.10 listed in zen.spamhaus.org] -0.0 SPF_PASS SPF: sender matches SPF record 2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Click to view scam #129424 - Sent on June 15, 2015, 7:15 am by mrjohn2345@cantv.net
Responsive Email .portrait{ display:none; font-size:0; max-height:0; line-height:0; padding:0; mso-hide:all; overflow:hidden; } @media (min-width: 481px){ .mobile-hide{ display:block !important; overflow:visible !important; width:auto !important; max-height:inherit !important; height:auto !important; } } @media (min-width: 481px){ .portrait{ display:none; font-size:0; line-height:0; height:0; overflow:hidden; } } @media (min-width: 1px) and (max-width: 480px){ body{ background-color:#FFFFFF !important; } } @media (min-width: 1px) and (max-width: 480px){ .mobile-hide{ display:none; font-size:0; line-height:0; height:0; } } @media (min-width: 1px) and (max-width: 480px){ .portrait{ display:block !important; overflow:visible !important; width:auto !important; max-height:none !important; height:auto !important; } } @media (min-width: 481px){ .mobile-hide{ display:block !important; overflow:visible !important; width:auto !important; max-height:inherit !important; height:auto !important; } } @media (min-width: 481px){ .portrait{ display:none; font-size:0; line-height:0; height:0; overflow:hidden; } } Call (855) 325-7769 To Verify Your Eligibility For The Student Loan Forgiveness Program* If you are experiencing difficulty viewing this important message, visit here. 2967 Michelson Dr., #G404, Irvine, CA 92612 This message was delivered to you because you have subscribed at one of our choice affiliate sites. If you received this in error and/or want to stop future mailings from this affiliate, you may do so here. Please allow 2-5 days for this to take effect. You can also send correspondence to: Customer Support, 925 B Peachtree St NE Suite 620 Atlanta, Georgia 30309 SpamAssassin Report (spam score: 3.8) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: cbssportsinteractive.com] 0.0 FORGED_RELAY_MUA_TO_MX FORGED_RELAY_MUA_TO_MX 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.0 SPF_PASS SPF: sender matches SPF record 0.8 HTML_IMAGE_RATIO_02 BODY: HTML has a low ratio of text to image area 0.0 HTML_MESSAGE BODY: HTML included in message 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
FYI
Sorry for the delay in making the payment, please see attachment for proof of payment, follow link; http://bit.ly/1JFvkwE and sign-in to view secured document. Kindly confirm payment. Thanks, Cassandra Webber. SpamAssassin Report (spam score: 4.7) pts rule name description ---- ---------------------- -------------------------------------------------- 2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL [196.46.245.149 listed in zen.spamhaus.org] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: bit.ly] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.220.173 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit (graves231[at]outlook.com ) 0.0 URIBL_DBL_ABUSE_REDIR Contains an abused redirector URL listed in the DBL blocklist [URIs: bit.ly] 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 0.0 MSGID_FROM_MTA_HEADER Message-Id was added by a relay 2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Click to view scam #129420 - Sent on June 15, 2015, 7:06 am by ashraf.aly@almashfa.com
Attn: Our Esteem Customer, We have deposited the check of your fund ($80000000USD) through Western Union department after our final meeting regarding your fund, All you will do is to contact Western Union director Dr. Nicholas Aguagu via E-mail(westerunionofficetg@gmail.com). He will give you direction on how you will be receiving the funds daily.Remember to send him your Full information to avoid wrong transfer such as, Receiver's Name_______________ Address: ________________ Country: ____________ Phone Number: _____________ Though, Mrs.Agnes Aguagu has sent $5000 in your name today Senders so contact Dr. Nicholas Aguagu or you call him +228-99226853 as soon as you can receive this email and tell him to give you the MTCN, sender name and question/answer to pick the $5000 Please let us know as soon as you received all your fund, Best Regards Thanks, Dr. Joseph Tony  -''''SpamAssassin Report (spam score: 4.0) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.220.171 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 TVD_SPACE_RATIO TVD_SPACE_RATIO 2.0 MIME_NO_TEXT No (properly identified) text body parts 2.7 TVD_SPACE_RATIO_MINFP TVD_SPACE_RATIO_MINFP
Click to view scam #129411 - Sent on June 15, 2015, 6:55 am by zumahamson12@one.lt
Dear Sir/ Madam, Please kindly see attachment and view original bill of Landing/proforma Invoice confirmation attached below. This was made for your company through one of your last order. Please confirm to us before shipment. Regards, Monica. Maersk Shipping Line 17/F, Tower B, Landgent Center, No. 24 Middle - East Third Ring Road, Chao Yang District Customer service and booking: +86 532 80951000Call: +86 532 80951000 Sales service and inquiries: +86 10 65692188Call: +86 10 65692188 Export Trades Customer Service: +86 532 83104622Call: +86 532 83104622 Import Customer Service: +86 532 83104611Call: +86 532 83104611 Sales service and inquiries: +86 10 65692199 65692199 SpamAssassin Report (spam score: 9.8) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.192.54 listed in list.dnswl.org] 2.6 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL [197.242.112.21 listed in zen.spamhaus.org] 1.6 SUBJ_ALL_CAPS Subject is all capitals -0.0 SPF_PASS SPF: sender matches SPF record 1.5 NAME_EMAIL_DIFF Sender NAME is an unrelated email address 0.0 TVD_SPACE_RATIO TVD_SPACE_RATIO 2.0 MIME_NO_TEXT No (properly identified) text body parts 2.7 TVD_SPACE_RATIO_MINFP TVD_SPACE_RATIO_MINFP
Click to view scam #129414 - Sent on June 15, 2015, 6:52 am by SALESSERVICE@INFO.COM
Locostia a img{ border : none; } img { display : block;}Si vous ne parvenez pas à lire cet e-mail, visualisez la version en ligne Vous recevez ce mail car vous vous êtes abonné(e) à la base de Woocom . Cet email vous est envoyé par woocom 16 rue du capitaine Ferber 75 020 PARIS -. Pour vous désabonner de notre newsletter : Rendez-vous sur cette page SpamAssassin Report (spam score: 7.9) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: woocom-2.com] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.218.45 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist [URIs: woocom-2.com] 2.4 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level above 50% [cf: 100] 0.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50% [cf: 100] 1.7 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 2.0 MIME_NO_TEXT No (properly identified) text body parts
Click to view scam #129408 - Sent on June 15, 2015, 6:52 am by news@contact.woocom-2.com
I am William Leung, I have a business proposal worth 24.5 million US Dollars for you. Kindly reply back via < williamleung864@gmail.com> for More details if interested. No Scam Please !!! --- This email has been checked for viruses by Avast antivirus software. https://www.avast.com/antivirus SpamAssassin Report (spam score: 2.6) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: avast.com] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.192.42 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars 0.0 LOTS_OF_MONEY Huge... sums of money 1.3 MONEY_FROM_41 Lots of money from Africa 2.0 ADVANCE_FEE_2_NEW_MONEY Advance Fee fraud and lots of money
Click to view scam #129407 - Sent on June 15, 2015, 6:23 am by info@mail.com
???????????????????????????????????????????????????????????????????????????????????????????????????????? ??Windows 8 x86+x64 6?1+5???????+62? ???????? ?????????? ????????ie???: http://83?to SpamAssassin Report (spam score: 10.6) pts rule name description ---- ---------------------- -------------------------------------------------- 1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see ] -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low trust [209.85.214.177 listed in list.dnswl.org] 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (hildan70wmi7[at]yahoo.co.jp) 0.0 DKIM_ADSP_CUSTOM_MED No valid author signature, adsp_override is CUSTOM_MED -0.0 SPF_PASS SPF: sender matches SPF record 3.9 MSGID_OUTLOOK_INVALID Message-Id is fake (in Outlook Express format) 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid 0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily 1.2 NML_ADSP_CUSTOM_MED ADSP custom_med hit, and not from a mailing list 2.0 MIME_NO_TEXT No (properly identified) text body parts 2.7 TVD_SPACE_RATIO_MINFP TVD_SPACE_RATIO_MINFP
Click to view scam #129406 - Sent on June 15, 2015, 6:04 am by hildan70wmi7@yahoo.co.jp
From: pamela.hurley.poitras@umoncton.caTo: pamela.hurley.poitras@umoncton.caSubject: RE : $2million to youDate: Mon, 15 Jun 2015 01:54:02 +0000.ExternalClass P {MARGIN-BOTTOM:0px;MARGIN-TOP:0px;}.ExternalClass P {MARGIN-BOTTOM:0px;MARGIN-TOP:0px;} De : Pamela Hurley PoitrasEnvoyé : 14 juin 2015 22:13À : Pamela Hurley PoitrasObjet : $2million to youJim McCullar has decided to donate funds to you contact him { jim_mccullar125@outlook.com } for more info.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 **************************L'information contenue dans ce courriel et dans n'importe quelle annexe est confidentielle et vise uniquement la personne à qui s'adresse ce message. Toute autre distribution, copie ou divulgation est strictement interdite. Si nous vous avons transmis ce message par erreur, veuillez nous en aviser immédiatement par retour de courriel et détruire l'original ainsi que les annexes sans en faire de copie.     Université de Moncton, campus d?Edmundston     165, boulevard Hébert, Edmundston (N.-B.) E3V 2S8     http://www.umoncton.ca/umce************************** **************************L'information contenue dans ce courriel et dans n'importe quelle annexe est confidentielle et vise uniquement la personne à qui s'adresse ce message. Toute autre distribution, copie ou divulgation est strictement interdite. Si nous vous avons transmis ce message par erreur, veuillez nous en aviser immédiatement par retour de courriel et détruire l'original ainsi que les annexes sans en faire de copie.     Université de Moncton, campus d?Edmundston     165, boulevard Hébert, Edmundston (N.-B.) E3V 2S8     http://www.umoncton.ca/umce**************************