| Scam Reporter | Scam Tips Received | |
|---|---|---|
![]() | No Name Cricklewood, Brent, United Kingdom 2012-10-20 11:16:01 Identity Theft | Scammer Information Attempted UPS scam alert!
Highly suspicious email from powweb@resge.com (id 1TPN8N-0000Wf-J3);supposed sender is providing-us@postal-ups.com
(NB: Delete email: do not open or click on any links)
possibly also includes Malware or Suspicious embedded script( suspected) in this UPS scam email
as subject text of email unconnected to Subject header.
Email Subject: UPS shipment status ID#3452
Received: from resge.com ([82.146.63.199]) by COL0-MC2-F13.Col0.hotmail.com with Micr… Read Full Report ⇒ |
![]() | Anonymous Santa Rosa, CA, United States 2012-10-16 16:48:09 Identity Theft Yahoo | Scammer Information This scam identfies themselves as a friend of mine in trouble in Spain and needs our help because they were mugged of all their money. They are asking for $1960.00 be wired to John McMahon, Comte d'Aiamans 14, Lloseta, Mallorca, Spain
I can forward emails to someone if I know who.
Thanks, Denise Hagy… Read Full Report ⇒ |
![]() | F Clark DuBois, PA, United States 2012-10-16 15:11:29 Identity Theft | Scammer Information Text recieved;
VOICE USAGE ALERT: your acct used abt 50% of Anytime Min for the bill ending on the 22nd. Monitor at vzw.com. As of 10/16 09:33 AM EDT. FREE MSG
Probably to entice reciever to reply to the 900 number.
Tried to report to 7726 but it refused to recognise the full 900 number.… Read Full Report ⇒ |
![]() | No Name Cricklewood, Brent, United Kingdom 2012-10-14 10:33:30 Identity Theft | Scammer Information Santander Identity Theft Scam from blacklisted IP located in Fareham, UK.
esc3@hermes.hood.edu , a HELO user of hermes.hood.edu sending phishing scam (with ESMTPA id 36711788) supposedly from securityalert@santander.co.uk with attached file link.
NB. DO NOT OPEN FILE ATACHMENT!
Originating IP: 88.212.147.234
ISP: Mailbox Networks
Host Name: 88-212-147-234.rdns.as8401.net
Organization: Mailbox Networks
Country: Fareham, Hampshire F2, United Kingdom.
Phish routed via IP 144… Read Full Report ⇒ |
![]() | Monika Pletschke Somewhere in South Africa 2012-10-12 14:03:17 Identity Theft | Scammer Information Raw message: Return-path:
Envelope-to: mcalitz@absamail.co.za
Delivery-date: Fri, 12 Oct 2012 14:53:16 +0200
Received: from mxl56v247.dotnetwork2.co.za ([41.77.56.247]:11179 helo=s11p02m011.dotnetwork2.co.za)
by aia-mx-vm-04 with esmtp (Exim 4.76 (FreeBSD))
(envelope-from )
id 1TMejr-000E87-62
for mcalitz@absamail.co.za; Fri, 12 Oct 2012 14:53:15 +0200
Authentication-Results: s11p02m011.dotnetwork2.co.za… Read Full Report ⇒ |
![]() | No Name Cricklewood, Brent, United Kingdom 2012-10-09 13:32:47 Identity Theft | Scammer Information Cyber fraudster (nobody@dabulyulinux.dabulyuhosting.com;
id 1TLXi0-000414-5o ) sending phishing email seemingly from customerservice@barclays.co.uk with redirect link to phishing Url at blacklisted site goldotclothing.com.
--------------------------------------
Email Details as follows:
IP: 46.105.237.0 (IP address belongs to a High Risk Hosting Provider ). (refer to abuseipdb.com/check/46.105.237.0)
ISP: Ovh Systems
Host Name: mail.dabulyuhosting.com
Organization: Ovh Sys… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-10-05 13:00:28 Identity Theft Paypal (paypal.com) | Scammer Information Paypal Scam email with verified phishing link to king-hiss.com ( refer http://www.phishtank.com/phish_detail.php?phish_id=1582085) sent by online@paypal.co.uk from IP 24.187.43.197 located in New Jersey, United States routed via SERVER.marcsolomon.local ([74.221.248.219]).
IP: 24.187.43.197
ISP: Optimum Online
Host Name: ool-18bb2bc5.dyn.optonline.net
Organization: Optimum Online
Location: Montauk, New York,NY11954, United States
Received: from SERVER.marcsolomon.local ([7… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-10-05 12:11:19 Identity Theft | Scammer Information User admin@ayyildizsesli.com sending fraudulent scam email supposedly from Halifax Bank Plc using originating source host ml82.128.1.68.multilinks.com in Nigeria.
Scam email has possibly malicious script as well as redirect link to phishing Url at www.bluesend.ir
email routed via server.uzmanpanel.com ([85.153.31.131])
Originating IP: 82.128.1.68
ISP: Multi-Links Telecommunications Limited
Host Name: ml82.128.1.68.multilinks.com
Organization: Mu… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-10-03 09:22:24 Identity Theft | Scammer Information SCAM: Authenticated User lesbrucepawsey@static-58-108-223-252.optusnet.com.au sending Yorkshire Building Society phish supposedly from online.account@yorkshire.co.uk , with fraudulent redirect link to phishing website sarperkara.com
Received: from mail34.syd.optusnet.com.au ([211.29.133.218]) by BAY0-MC4-F8.Bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Tue, 2 Oct 2012 11:40:33 -0700
Received: from User (static-58-108-223-252.optusnet.com.au [58.108.223.252] (may … Read Full Report ⇒ |
![]() | Anonymous Somewhere in United States 2012-09-25 13:00:30 Identity Theft | Scammer Information YOUR PACKAGE FUNDS $2.5M USD IN USA TODAY
We wish to inform you that the diplomatic agent conveying the consignment box
valued the sum of $2.5 Million United States Dollars misplaced your
address and
he is currently stranded at JFK AIRPORT NEW YORK USA now. We
required you
reconfirm the following information below so that he can deliver your
consignment box to you today Because his flight ticket is about to expire.
NAME: ========================= ============================… Read Full Report ⇒ |
![]() | Nolan Belk North Wilkesboro, NC, United States 2012-09-24 13:30:52 Identity Theft Craigslist (craiglist.com) | Scammer Information
Joseph William vvbnvfc@yahoo.com
Thanks for your quick response, i'm okay with the presentcondition
asstarted in the advert and the askingprice. i will not be able to
cometo look at it due to thelong distant and the easiest way for me
tomake thepayment is through a bank check, i'll wait until your
bankclears the check before we proceed with the pickup.I'llalso
takecare of the pickup and delivery when thecheck cleared, provide
meyour name, address, city,state, zip code for m… Read Full Report ⇒ |
![]() | RLD Mount Vernon, OH, United States 2012-09-20 15:40:57 Identity Theft | Scammer Information I do not know the details as I do not open obvious Spam, But the info after the @ is attachet is a legitimate Government site. However, it is not their email.… Read Full Report ⇒ |
![]() | Peacequester Myrtle Beach, SC, United States 2012-09-19 21:50:08 Identity Theft Yahoo | Scammer Information
Dear User,
Your E-mail account has exceeded its limit and needs to be verified, if not verified within 24 hours, we shall suspend your account. click here to verify your email account now
Thank you for being a loyal Yahoo! Mail user.
Regards,
Yahoo! Account Services
… Read Full Report ⇒ |
![]() | No Name New London, CT, United States 2012-09-19 02:53:37 Identity Theft Paypal (paypal.com) | Scammer Information Thank you for getting back to me.Can you assure me that it's in good state and i will not be disappointed with it.I'm ready to pay your asking price and to be honest, i wanted to buy this for my Son and i want it to be a surprise gift for him, but the issue is i am an oceanographer and i do have a contract to go for which starts tomorrow and am on my way right now.The contract is strictly no call due to the lack of reception on the sea area. But I'm able to access email anyti… Read Full Report ⇒ |
![]() | No Name Hastings, East Sussex, United Kingdom 2012-09-13 15:06:46 Identity Theft | Scammer Information Barclays Bank phish from allergy@d02-29-1-12.centos-server.net , id 1TC6J4-0007sk-0J (with fraudulent link that redirects to phishing Url at mapki.com (refer http://www.phishtank.com/phish_detail.php?phish_id=1561002)
IP: 68.171.215.27
ISP: Acenet
Host Name: empireallergy.com
Organization: Promitech-Technologies
Country: Dearborn, Michigan, MI 48124, United States.
… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-12 12:57:28 Identity Theft | Scammer Information Co-operative Co-operative Bank phishing seemingly sent by noreply@co-operative.co.uk, but actually sent by User (static-58-108-187-172.optusnet.com.au [58.108.187.172] (may be forged)) (authenticated sender happydayskindy)with ESMTP id q8C9Djpj032524
Blacklisted IP 58.108.187.172 is source of numerous phishing attempts involving various UK financial institutions.
IP: 58.108.187.172 (Blacklisted xbl.spamhaus.org, cbl.abuseat.org and bl.spamcop.net)
ISP: Optus
Host Name: sta… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-11 12:04:44 Identity Theft | Scammer Information Tax refund scam from blacklisted IP 58.108.187.172 (may be forged))-(authenticated sender happydayskindy)
Received: from mail01.syd.optusnet.com.au ([211.29.132.182]) by SNT0-MC4-F15.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Tue, 11 Sep 2012 03:58:54 -0700
Received: from User (static-58-108-187-172.optusnet.com.au [58.108.187.172] (may be forged))
(authenticated sender happydayskindy)
by mail01.syd.optusnet.com.au (8.13.1/8.13.1) with ESMTP id q8BAw59Q0217… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-11 10:29:45 Identity Theft | Scammer Information Barclays Bank phishing scam supposedly from customerservice@barclays.co.uk sent by nobody@insigaa4.miniserver.com id 1TB5g2-0006gH-NP with link to http://research.uleth.ca/mahavidya/site/index.htm
(DO NOT CLICK ON THIS LINK)
IP: 89.200.137.149
ISP: Memset Ltd
Host Name: insigaa4.miniserver.com
Organization: Memset Ltd
Country: London, City of London H9, United Kingdom (GB)
Received: from insigaa4.miniserver.com ([89.200.137.149]) by COL0-MC4-F29.Col0.hotmail.com with Micr… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-08 14:20:52 Identity Theft | Scammer Information Attempted scam sent by security@santander.co.uk with phishing link to http://217.219.20.51/Images/santander.htm
IP 82.77.37.9 (82.77.37.9.cablelink.rdsar.ro ; Organization: Romania Data Systems)in Arad, Romania is involved in constant fraudulent emails usually involving banking or financial institutions.
Link info:
site : 217.219.20.51
ISP: Information Technology Company (ITC)
Host Name: 217.219.20.51
Organization: Islamic AZAD Univeristy Yasooj
Location: Yasooj, 05 Kohkil… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-08 13:34:53 Identity Theft | Scammer Information Fraudulent email supposedly from Barclays with phishing link to url at lt2u.biz, a Malaysian site.
IP 200.185.51.84
ISP: TIVIT TECNOLOGIA DA INFORMACAO S.A.
Host Name: firenze.mundo.com.br
Organization: TIVIT TECNOLOGIA DA INFORMACAO S.A.
Country: Brazil
Received: from firenze.mundo.com.br ([200.185.51.84]) by COL0-MC2-F35.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Fri, 7 Sep 2012 16:51:52 -0700
Received: from firenze.mundo.com.br (localhost [127.0.0.1])
by fir… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-08 12:08:44 Identity Theft | Scammer Information IP 82.77.37.9 involved in constant phishing!!
ISP: Romania Data Systems
Host Name: 82.77.37.9.cablelink.rdsar.ro
Organization: Romania Data Systems
Located in Arad, 02 Arad,Romania
unsafe phishing link in email:http://217.219.20.51/Images/halifax.htm ( NB:DO NOT CLICK on link which is connected to the Islamic AZAD Univeristy Yasooj in Yasooj, 05 Kohkiluyeh va Buyer Ahmadi,Islamic Republic of Iran.
Received: from martel.biz ([89.174.1… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-06 12:26:45 Identity Theft | Scammer Information Phishing by mail2stduent@protocol.slc.co.uk with link to xerex.com.ar- a site that is blacklisted for malware and phishing- sent from blacklisted IP.
IP: 75.65.226.134
ISP: Comcast Cable
Source Host Name: c-75-65-226-134.hsd1.ms.comcast.net
Organization: Comcast Cable
Location:Clinton, Mississippi, MS 39056, United States
Received: from mail.tspspices.com ([76.12.10.210]) by COL0-MC4-F18.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Wed, 5 Sep 2012 10:18:13 -0700
… Read Full Report ⇒ |
![]() | No Name Gosport, Hampshire, United Kingdom 2012-09-04 13:22:22 Identity Theft | Scammer Information Attempted Nationwide phishing scam with link to phishing site www.ilam-telecom.ir/public/.
From: "Nationwide"; Subject: Unauthorized Access
Received: from golden-shuttle.be ([91.183.33.109]) by COL0-MC4-F8.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Mon, 3 Sep 2012 18:55:36 -0700
Received: from User ([82.77.37.9]) by golden-shuttle.be with Microsoft SMTPSVC(6.0.3790.4675); Sat, 25 Aug 2012 10:01:03 +0200
From: "Nationwid… Read Full Report ⇒ |
![]() | No Name Hythe, Kent, United Kingdom 2012-08-29 12:21:55 Identity Theft | Scammer Information 'Halifax Bank' phish with link to US site flagworldinc.com sent by onlineservice@halifax.co.uk (Return-Path: www-data@www.agriok.it )
NB: both agriok.it and flagworldinc.com found to have phishing url by Safeweb.Norton.com
IP: 62.149.210.190
ISP: Aruba S.p.A.
Source Host Name: host190-210-149-62.serverdedicati.aruba.it
Organization: Aruba S.p.A. - Housing and Colocation services.
Location: Teramo, Abruzzi 01, Italy
Received: from http://www.agriok.it([62.149.210.190])
… Read Full Report ⇒ |
![]() | Pierre Bacquet L'Aigle, Orne, France 2012-08-22 10:20:19 Identity Theft | Scammer Information Received the following email (as Bcc: since there isn't any To: or Cc: field)
--------------------
This is the Help desk Program that periodically checks the size of your e-mail space is sending you this information. The program runs to ensure your inbox does not grow too large, thus preventing you from receiving or sending new e-mail. As this message is being sent, you have 2.5 gigabytes (GB) or more stored in your inbox. We are currently upgrading our data base and e-mail … Read Full Report ⇒ |