Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Phishing email saying they are Western Union:
- (Uploaded image copy of the phishing email)
- http://i.imgur.com/t1NcN.jpg
- Phishing email below with headers:
- _________________________________________________________________
- Delivered-To: **omitted email address**
- Received: by 10.50.22.68 with SMTP id b4csp342208igf;
- Tue, 24 Jul 2012 07:50:32 -0700 (PDT)
- Received: by 10.236.77.163 with SMTP id d23mr19036762yhe.75.1343141431872;
- Tue, 24 Jul 2012 07:50:31 -0700 (PDT)
- Return-Path: <cus069@peoplepc.com>
- Received: from elasmtp-junco.atl.sa.earthlink.net (elasmtp-junco.atl.sa.earthlink.net. [209.86.89.63])
- by mx.google.com with ESMTP id i49si15008048yhn.102.2012.07.24.07.50.30;
- Tue, 24 Jul 2012 07:50:31 -0700 (PDT)
- Received-SPF: neutral (google.com: 209.86.89.63 is neither permitted nor denied by best guess record for domain of cus069@peoplepc.com) client-ip=209.86.89.63;
- Authentication-Results: mx.google.com; spf=neutral (google.com: 209.86.89.63 is neither permitted nor denied by best guess record for domain of cus069@peoplepc.com) smtp.mail=cus069@peoplepc.com
- DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
- s=dk20050327; d=peoplepc.com;
- b=ji++DKTjRXbgqov6ZA4tAR/i0HLlMhp+QfZYb5JoEOlPgplUPJFFropOjQPVWbWF;
- h=Message-ID:Date:From:Reply-To:Subject:Mime-Version:Content-Transfer-Encoding:X-Mailer:Content-Type:X-ELNK-Trace:X-Originating-IP;
- Received: from [209.86.224.34] (helo=elwamui-hound.atl.sa.earthlink.net)
- by elasmtp-junco.atl.sa.earthlink.net with esmtpa (Exim 4.67)
- (envelope-from <cus069@peoplepc.com>)
- id 1StgOs-0007PV-NQ; Tue, 24 Jul 2012 10:47:50 -0400
- Received: from 41.74.0.193 by webmail.peoplepc.com with HTTP; Tue, 24 Jul 2012 10:47:50 -0400
- Message-ID: <16120981.1343141270420.JavaMail.root@elwamui-hound.atl.sa.earthlink.net>
- Date: Tue, 24 Jul 2012 07:47:50 -0700 (GMT-07:00)
- From: =?UTF-8?B?V2VzdGVybiBVbmlvbsKuIA==?= <cus069@peoplepc.com>
- Reply-To: =?UTF-8?B?V2VzdGVybiBVbmlvbsKuIA==?= <transfer014@blumail.org>
- Subject: You have a pending transfer with us.
- Mime-Version: 1.0
- Content-Transfer-Encoding: quoted-printable
- X-Mailer: EarthLink Zoo Mail 1.0
- Content-Type: text/html; charset=UTF-8
- X-ELNK-Trace: a4bf18a3c9ac5926e9c7218ab0f5e41dca1e3986070cb94714610d398cc62187d08b99f0f178fd94350badd9bab72f9c350badd9bab72f9c350badd9bab72f9c
- X-Originating-IP: 209.86.224.34
- <head><style>body{font-size:10pt;font-family:arial,sans-serif;background-co=
- lor:#ffffff;color:black;}p{margin:0px;}</style></head><body><div align=3D"c=
- enter" style=3D"font-family: Tahoma; "><div align=3D"center"><font face=3D"=
- Tahoma" style=3D"text-indent: 0in !important; "><div style=3D"text-indent: =
- 0in !important; line-height: 1.22em; text-align: left; padding: 0px; "><str=
- ong><a title=3D"http://www.google.com/imgres?imgurl=3Dhttp://www.festivalse=
- gou.org/logo%20western%20union.jpg&imgrefurl=3Dhttp://www.festivalsegou=
- .org/Festival,%20textpartners.htm&h=3D37&w=3D146&sz=3D21&tb=
- nid=3DkzwP-QhFmZ0J:&tbnh=3D37&tbnw=3D146&prev=3D/images?q=3Dwes=
- tern+union+logo&sa=3DX&oi=3Dimage_result&resnum=3D1&ct=3Dim=
- age&cd=3D1" href=3D"http://www.google.com/imgres?imgurl=3Dhttp://www.fe=
- stivalsegou.org/logo%2520western%2520union.jpg&imgrefurl=3Dhttp://www.f=
- estivalsegou.org/Festival%2c%2520textpartners.htm&h=3D37&w=3D146&am=
- p;sz=3D21&tbnid=3DkzwP-QhFmZ0J:&tbnh=3D37&tbnw=3D146&prev=
- =3D/images?q%3Dwestern%2Bunion%2Blogo&sa=3DX&oi=3Dimage_result&=
- resnum=3D1&ct=3Dimage&cd=3D1" target=3D"_blank" rel=3D"nofollow"><b=
- r class=3D"Apple-interchange-newline"><img title=3D"http://www.google.com/i=
- mgres?imgurl=3Dhttp://www.festivalsegou.org/logo%20western%20union.jpg&=
- imgrefurl=3Dhttp://www.festivalsegou.org/Festival,%20textpartners.htm&h=
- =3D37&w=3D146&sz=3D21&tbnid=3DkzwP-QhFmZ0J:&tbnh=3D37&t=
- bnw=3D146&prev=3D/images?q=3Dwestern+union+logo&sa=3DX&oi=3Dima=
- ge_result&resnum=3D1&ct=3Dimage&cd=3D1" height=3D"37" alt=3D"ht=
- tp://www.google.com/imgres?imgurl=3Dhttp://www.festivalsegou.org/logo%20wes=
- tern%20union.jpg&imgrefurl=3Dhttp://www.festivalsegou.org/Festival,%20t=
- extpartners.htm&h=3D37&w=3D146&sz=3D21&tbnid=3DkzwP-QhFmZ0J=
- :&tbnh=3D37&tbnw=3D146&prev=3D/images?q=3Dwestern+union+logo&am=
- p;sa=3DX&oi=3Dimage_result&resnum=3D1&ct=3Dimage&cd=3D1" sr=
- c=3D"http://www.google.com/images?q=3Dtbn:kzwP-QhFmZ0J:www.festivalsegou.or=
- g/logo%252520western%252520union.jpg" width=3D"146" align=3D"middle" vspace=
- =3D"4" border=3D"1" style=3D"width: 310px; height: 86px; "></a></strong></d=
- iv><div style=3D"text-indent: 0in !important; line-height: 1.22em; text-ali=
- gn: left; padding: 0px; "><br></div><div style=3D"text-indent: 0in !importa=
- nt; line-height: 1.22em; text-align: left; padding: 0px; ">Dear Customer,</=
- div><div style=3D"text-indent: 0in !important; line-height: 1.22em; text-al=
- ign: left; padding: 0px; "><br></div><div style=3D"text-indent: 0in !import=
- ant; text-align: left; padding: 0px; "><span style=3D"line-height: 16px; ">=
- There is an issue with the WESTERN UNION MONEY TRANSFER in the amount of $1=
- ,500,000.00 USD directed in cash credited to file WUMT/90231108/12, at the =
- owner of this email address. The International Monetary Fund contacted us f=
- or your compensation a couple of hours ago due to your allocated security c=
- ode.</span></div><div style=3D"text-indent: 0in !important; text-align: lef=
- t; padding: 0px; "><span style=3D"line-height: 16px; "><br></span></div><di=
- v style=3D"text-indent: 0in !important; text-align: left; padding: 0px; "><=
- span style=3D"line-height: 16px; ">They said that they choose to send it to=
- an email address instead of a name. We are unable to complete a transfer d=
- irected at an email address, so we require some more information in order t=
- o complete this transfer.</span></div><div style=3D"text-indent: 0in !impor=
- tant; text-align: left; padding: 0px; "><span style=3D"line-height: 16px; "=
- ><br></span></div><div style=3D"text-indent: 0in !important; text-align: le=
- ft; padding: 0px; "><span style=3D"line-height: 16px; ">FULL NAME: &=
- nbsp; <=
- /span></div><div style=3D"text-indent: 0in !important; text-align: left; pa=
- dding: 0px; "><span style=3D"line-height: 16px; ">FULL CONTACT ADDRESS: &nb=
- sp; </span></div><div style=3D"text-indent: 0in !importa=
- nt; text-align: left; padding: 0px; "><span style=3D"line-height: 16px; ">M=
- OBILE PHONE NUMBER: </span></div><div styl=
- e=3D"text-indent: 0in !important; text-align: left; padding: 0px; "><span s=
- tyle=3D"line-height: 16px; ">OCCUPATION: =
- </span></div=
- ><div style=3D"text-indent: 0in !important; text-align: left; padding: 0px;=
- "><span style=3D"line-height: 16px; ">MARITAL STATUS AND AGE:  =
- ; </span></div><div style=3D"text-indent: 0in !important; text-align:=
- left; padding: 0px; "><span style=3D"line-height: 16px; "><br></span></div=
- ><div style=3D"text-indent: 0in !important; text-align: left; padding: 0px;=
- "><span style=3D"line-height: 16px; ">In order to resolve this problem, pl=
- ease email via Western Union Solicitors Fund Verification Department: (&nbs=
- p;<font color=3D"#1f497d"><b>transfer014@blumail.org</b></font> ). As =
- soon as this information is received, and you complied with the requirement=
- s of payment of the western union charges, payment will be made to your nom=
- inated bank account or at the counter directly from the Western Union trans=
- ferring Bank. When emailing, please use reference number 450-247 for our mu=
- tual convenience.</span></div><div style=3D"text-indent: 0in !important; te=
- xt-align: left; padding: 0px; "><span style=3D"line-height: 16px; "><br></s=
- pan></div><div style=3D"text-indent: 0in !important; text-align: left; padd=
- ing: 0px; "><span style=3D"line-height: 16px; ">THE MANAGEMENT OF WESTERN U=
- NION MONEY TRANSFER, OFFICE BENIN BRANCH.</span></div><div style=3D"text-in=
- dent: 0in !important; text-align: left; padding: 0px; "><span style=3D"line=
- -height: 16px; "><br></span></div><div style=3D"text-indent: 0in !important=
- ; text-align: left; padding: 0px; "><span style=3D"text-indent: 0in; line-h=
- eight: 16px; ">Sincerely,</span></div></font></div></div><div style=3D"text=
- -indent: 0in !important; font-family: Tahoma; padding: 0px; line-height: 1.=
- 22em; "><font face=3D"Tahoma" size=3D"2" style=3D"text-indent: 0in !importa=
- nt; line-height: 1.22em; "><div style=3D"text-align: left; "><span style=3D=
- "text-indent: 0in; line-height: 1.22em; "> </span></div></font></div><=
- div style=3D"text-indent: 0in !important; font-family: Tahoma; padding: 0px=
- ; "><span style=3D"text-indent: 0in !important; line-height: 1.22em; "><fon=
- t face=3D"Tahoma" size=3D"2" style=3D"text-indent: 0in !important; font-siz=
- e: 10pt; line-height: 1.22em; "></font></span><div align=3D"center"><font s=
- tyle=3D"text-indent: 0in !important; "><div style=3D"text-indent: 0in !impo=
- rtant; font-size: 10pt; line-height: 1.22em; text-align: left; padding: 0px=
- ; "><font face=3D"Tahoma" size=3D"2" style=3D"text-indent: 0in !important; =
- line-height: 1.22em; ">Rev. Lee Benson</font></div><div style=3D"text-inden=
- t: 0in !important; text-align: left; padding: 0px; "><font size=3D"2" style=
- =3D"text-indent: 0in !important; font-size: 10pt; line-height: 1.22em; "><f=
- ont face=3D"Tahoma" style=3D"text-indent: 0in !important; line-height: 1.22=
- em; ">E-Mail: (</font></font><font style=3D"text-indent: 0in !important; ">=
- <font color=3D"#0000ee" face=3D"Arial"><span style=3D"line-height: 16px; ">=
- <u>transfer014@blumail.org</u></span></font><font size=3D"2"><span style=3D=
- "line-height: 1.22em; ">)</span></font></font></div></font><font face=3D"Ta=
- homa" size=3D"2" style=3D"text-indent: 0in !important; line-height: 1.22em;=
- font-size: 10pt; "><div style=3D"text-indent: 0in !important; text-align: =
- left; padding: 0px; line-height: 1.22em; "><font face=3D"Tahoma" size=3D"2"=
- style=3D"text-indent: 0in !important; line-height: 1.22em; ">Phone:+229 97=
- 626788</font></div></font></div></div><div align=3D"center" style=3D"font-f=
- amily: Tahoma; "></div><font face=3D"Tahoma" style=3D"text-indent: 0in !imp=
- ortant; font-family: Tahoma; "><div style=3D"text-align: center; "><br></di=
- v><span style=3D"text-indent: 0in !important; "><font face=3D"Arial" size=
- =3D"2" style=3D"text-indent: 0in !important; "></font></span></font><div al=
- ign=3D"center" style=3D"font-family: Tahoma; "></div><div align=3D"center" =
- style=3D"font-family: Tahoma; text-align: left; "><font face=3D"Tahoma" siz=
- e=3D"2" style=3D"text-indent: 0in !important; font-size: 10pt; line-height:=
- 1.22em; "><img height=3D"224" src=3D"http://www.lifeonourown.com/wp-conten=
- t/uploads/2009/04/mellow-yellow-monday-western-union-money-transfer-office-=
- dsc_9892.jpg" width=3D"500" style=3D"text-indent: 0in !important; border-wi=
- dth: 0px; width: 242px; line-height: 1.22em; height: 117px; "></font></div>=
- </body><pre>
- ________________________________________
- PeoplePC Online
- A better way to Internet
- http://www.peoplepc.com</pre>
- _________________________________________________________________
- Images used in the phishing email:
- http://www.festivalsegou.org/logo%20western%20union.jpg
- http://www.lifeonourown.com/wp-content/uploads/2009/04/mellow-yellow-monday-western-union-money-transfer-office-dsc _9892.jpg
- First image link was actually:
- http://www.google.com/i=
- mgres?imgurl=3Dhttp://www.festivalsegou.org/logo%20western%20union.jpg&=
- imgrefurl=3Dhttp://www.festivalsegou.org/Festival,%20textpartners.htm&h=
- =3D37&w=3D146&sz=3D21&tbnid=3DkzwP-QhFmZ0J:&tbnh=3D37&t=
- bnw=3D146&prev=3D/images?q=3Dwestern+union+logo&sa=3DX&oi=3Dima=
- ge_result&resnum=3D1&ct=3Dimage&cd=3D1" height=3D"37" alt=3D"ht=
- tp://www.google.com/imgres?imgurl=3Dhttp://www.festivalsegou.org/logo%20wes=
- tern%20union.jpg&imgrefurl=3Dhttp://www.festivalsegou.org/Festival,%20t=
- extpartners.htm&h=3D37&w=3D146&sz=3D21&tbnid=3DkzwP-QhFmZ0J=
- :&tbnh=3D37&tbnw=3D146&prev=3D/images?q=3Dwestern+union+logo&am=
- p;sa=3DX&oi=3Dimage_result&resnum=3D1&ct=3Dimage&cd=3D1" sr=
- c=3D"http://www.google.com/images?q=3Dtbn:kzwP-QhFmZ0J:www.festivalsegou.or=
- g/logo%252520western%252520union.jpg
- Relevant information in email as way for recipient to contact the scammer:
- transfer014@blumail.org
- Phone:+229 97626788
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement