Advertisement
wavellan

20230609_PHISHING_SCAM_1

Jun 9th, 2023
119
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.82 KB | None | 0 0
  1. Dear YOUR_NAME_HERE
  2.  
  3. My name is Sophie Robbins.
  4. We’ve got an open vacancy in the department and I am delighted to offer the position of Logistics Manager to you.
  5. In order to do this you will need to have laptop or personal computer with constant Internet access, desire to learn, and a USA citizenship.
  6.  
  7. Please reply to this letter if this sounds right for you and we will reach you to set the date for a telephone interview.
  8.  
  9.  
  10.  
  11. Best regards,
  12. Sophie Robbins
  13.  
  14.  
  15.  
  16.  
  17. Received: from SJ0PR05MB8632.namprd05.prod.outlook.com (2603:10b6:a03:394::12)
  18. by MWHPR0501MB3899.namprd05.prod.outlook.com with HTTPS; Fri, 9 Jun 2023
  19. 15:25:26 +0000
  20. Received: from SJ0PR13CA0118.namprd13.prod.outlook.com (2603:10b6:a03:2c5::33)
  21. by SJ0PR05MB8632.namprd05.prod.outlook.com (2603:10b6:a03:394::12) with
  22. Microsoft SMTP Server (version=TLS1_2,
  23. cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6455.33; Fri, 9 Jun
  24. 2023 15:25:22 +0000
  25. Received: from MW2NAM12FT087.eop-nam12.prod.protection.outlook.com
  26. (2603:10b6:a03:2c5:cafe::1e) by SJ0PR13CA0118.outlook.office365.com
  27. (2603:10b6:a03:2c5::33) with Microsoft SMTP Server (version=TLS1_2,
  28. cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6500.15 via Frontend
  29. Transport; Fri, 9 Jun 2023 15:25:23 +0000
  30. Authentication-Results: spf=pass (sender IP is 209.85.167.43)
  31. smtp.mailfrom=gmail.com; dkim=pass (signature was verified)
  32. header.d=gmail.com;dmarc=pass action=none header.from=gmail.com;compauth=pass
  33. reason=100
  34. Received-SPF: Pass (protection.outlook.com: domain of gmail.com designates
  35. 209.85.167.43 as permitted sender) receiver=protection.outlook.com;
  36. client-ip=209.85.167.43; helo=mail-lf1-f43.google.com; pr=C
  37. Received: from mail-lf1-f43.google.com (209.85.167.43) by
  38. MW2NAM12FT087.mail.protection.outlook.com (10.13.181.176) with Microsoft SMTP
  39. Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
  40. 15.20.6477.27 via Frontend Transport; Fri, 9 Jun 2023 15:25:23 +0000
  41. Received: by mail-lf1-f43.google.com with SMTP id 2adb3069b0e04-4f61735676fso2451269e87.2
  42. for <>; Fri, 09 Jun 2023 08:25:23 -0700 (PDT)
  43. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
  44. d=gmail.com; s=20221208; t=1686324321; x=1688916321;
  45. h=content-transfer-encoding:mime-version:message-id:subject:from:to
  46. :date:from:to:cc:subject:date:message-id:reply-to;
  47. bh=H+aCltHGHn/KUuEonLZhAaArSev+wmUraz+q6mG1bak=;
  48. b=ZRL2BCclg82s5S3E5ssdH+t/WRdB8AWqJC364YN0FZQNemFmx9DNJuJgGc7paLr8Jj
  49. /HYgiwJcvp9uMb8CpJ8fp9cq1nSAayLeU+cRW1+vMGTd7lwyoFluJi7n0geqTEBEraHH
  50. yfs9iP4PH4soMOqM3IqtW43I95CxIuz3Ao3TR7rHUv69bNSh1wh1jibr+QNffZZINSxA
  51. 7gYPBoY7yas/X99h8FVURy2Y5YHoJ1qYAJs2UnvACncIGdGMWewP6k8eU7cr1lfNxyaK
  52. KRmb4vYAzvmW6JNSedHUbG3AYL30UJ77L1mkfTnHJpDhtuZsWM92R+fmqFrMvJsUWOyR
  53. i5tA==
  54. X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
  55. d=1e100.net; s=20221208; t=1686324321; x=1688916321;
  56. h=content-transfer-encoding:mime-version:message-id:subject:from:to
  57. :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
  58. bh=H+aCltHGHn/KUuEonLZhAaArSev+wmUraz+q6mG1bak=;
  59. b=BC2Y3sz3Z3cByIiN2Nw0ALnQQUGjMycD8X9Lf9+vPG79AoeOgkVZyM9xLryF1U87Fh
  60. ukXzlhRZuViVCKJM1poq9wfp1fvS4urX+WLvV2oBBI9xCdE91LhG4QqV9EEbV8g/597C
  61. 1a6UCYoo4lu3nc1BRMOPLfO4MX6Hc332dQIsMgPrVjJuTHxmS+H/EItMT8NJOYcL6Dle
  62. 4M1f60B3diDjyIypB+Y6m/OOLUVMb/vZXFs/FfMVDmxsych5yES/KTEFmMNaD60bFw3D
  63. 0XnAdHnWLH8/2pTveViIXC3HHSk6SwBLTPrp7Mv+c/MWBCRR6O9BEUXKoQH963ERUDu7
  64. VeLw==
  65. X-Gm-Message-State: AC+VfDw3bxgO4eahYCV8t0IDzQanLtf4/ZBnTzHRK4AOfEMailTaMnba
  66. FZLu5yT9JQ2ZxvB+mpyMAU3I71yKxMA=
  67. X-Google-Smtp-Source: ACHHUZ7EOu3cUvJrG1wLzSn+jBhsaejHE5ljLD6BizdMekCRZGNSvX4morB3aWFHnGRs5HCAqPVpBw==
  68. X-Received: by 2002:a05:6512:52d:b0:4ec:8a12:9e70 with SMTP id o13-20020a056512052d00b004ec8a129e70mr1192953lfc.46.1686324321076;
  69. Fri, 09 Jun 2023 08:25:21 -0700 (PDT)
  70. Return-Path: [email protected]
  71. Received: from [127.0.0.1] ([91.194.3.60])
  72. by smtp.gmail.com with ESMTPSA id t3-20020ac24c03000000b004f3ba3b948dsm582003lfq.284.2023.06.09.08.25.20
  73. for <>
  74. (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
  75. Fri, 09 Jun 2023 08:25:20 -0700 (PDT)
  76. Date: Fri, 9 Jun 2023 10:25:20 +0000
  77. To:
  78. From: Sophie Robbins <[email protected]>
  79. Subject: Hello ... IDG11739
  80. Message-ID: <EDX2keEM5L3c07NSXF4HEzqfEkW5WCYqmlAMnf5GkQ@localhost>
  81. X-Priority: 3 (Normal)
  82. X-Mailer: WebService/1.1.16674 YMailNorrin Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36
  83. MIME-Version: 1.0
  84. X-MS-Exchange-Organization-ExpirationStartTime: 09 Jun 2023 15:25:23.4871
  85. (UTC)
  86. X-MS-Exchange-Organization-ExpirationStartTimeReason: OriginalSubmit
  87. X-MS-Exchange-Organization-ExpirationInterval: 1:00:00:00.0000000
  88. X-MS-Exchange-Organization-ExpirationIntervalReason: OriginalSubmit
  89. X-MS-Exchange-Organization-Network-Message-Id:
  90. 68e2547f-8008-4911-0772-08db68fdbe7c
  91. X-EOPAttributedMessage: 0
  92. X-EOPTenantAttributedMessage: 0d4bfd0a-5b8b-4c86-b245-3f11f8ea539a:0
  93. X-MS-Exchange-Organization-MessageDirectionality: Incoming
  94. X-MS-PublicTrafficType: Email
  95. X-MS-TrafficTypeDiagnostic:
  96. MW2NAM12FT087:EE_|SJ0PR05MB8632:EE_|MWHPR0501MB3899:EE_
  97. X-MS-Exchange-Organization-AuthSource:
  98. MW2NAM12FT087.eop-nam12.prod.protection.outlook.com
  99. X-MS-Exchange-Organization-AuthAs: Anonymous
  100. X-MS-Office365-Filtering-Correlation-Id: 68e2547f-8008-4911-0772-08db68fdbe7c
  101. X-MS-Exchange-Organization-SCL: 1
  102. X-Microsoft-Antispam: BCL:0;
  103. X-Forefront-Antispam-Report:
  104. CIP:209.85.167.43;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail-lf1-f43.google.com;PTR:mail-lf1-f43.google.com;CAT:NONE;SFS:(13230028)(7916004)(451199021)(73392003)(26005)(33716001)(9686003)(956004)(82202003)(66899021)(7126003)(426003)(336012)(83380400001)(66574015)(58800400005)(4744005)(1096003)(8676002)(76482006)(22186003)(6916009)(7246003)(5660300002)(86362001)(7636003)(356005)(7596003)(70300200001);DIR:INB;
  105. X-MS-Exchange-CrossTenant-OriginalArrivalTime: 09 Jun 2023 15:25:23.3465
  106. (UTC)
  107. X-MS-Exchange-CrossTenant-Network-Message-Id: 68e2547f-8008-4911-0772-08db68fdbe7c
  108. X-MS-Exchange-CrossTenant-Id: 0d4bfd0a-5b8b-4c86-b245-3f11f8ea539a
  109. X-MS-Exchange-CrossTenant-AuthSource:
  110. MW2NAM12FT087.eop-nam12.prod.protection.outlook.com
  111. X-MS-Exchange-CrossTenant-AuthAs: Anonymous
  112. X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
  113. X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR05MB8632
  114. X-MS-Exchange-Transport-EndToEndLatency: 00:00:03.0851959
  115. X-MS-Exchange-Processed-By-BccFoldering: 15.20.6455.026
  116. X-Microsoft-Antispam-Mailbox-Delivery:
  117. ucf:0;jmr:0;auth:0;dest:I;ENG:(910001)(944506478)(944626604)(920097)(930097);
  118. X-Microsoft-Antispam-Message-Info:
  119. Content-type: text/plain;
  120. charset="UTF-8"
  121. Content-transfer-encoding: quoted-printable
  122.  
  123.  
  124.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement