Nigerian Phish from Google Gmail
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 13 Feb 2024 06:53:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from)
id 1rZtCe-000000002Jy-3aqb
for dave@doctor.nl2k.ab.ca;
Tue, 13 Feb 2024 06:52:04 -0700
Resent-From: The Doctor
Resent-Date: Tue, 13 Feb 2024 06:52:04 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-yw1-f171.google.com ([209.85.128.171]:45461)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.97.1 (FreeBSD))
(envelope-from)
id 1rZoCu-00000000KTA-3zvA
for games@nl2k.ab.ca;
Tue, 13 Feb 2024 01:32:03 -0700
Received: by mail-yw1-f171.google.com with SMTP id 00721157ae682-6077d2b3bb1so5689257b3.3
for; Tue, 13 Feb 2024 00:30:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1707812998; x=1708417798; darn=nl2k.ab.ca;
h=to:subject:message-id:date:from:reply-to:mime-version:from:to:cc
:subject:date:message-id:reply-to;
bh=Ud7W4pwthtRSnjlwyfwOHXWb8gFJciIeFECbMRgV79A=;
b=k+SyuY8sadVVjQOtgm5kACzeDotT5l6PrHannP9U9li9RoxbS1W+1HrDi/amsbslr+
GKgDDwVgn4MNQelXYlIhnKbQYHM0XAu3QCTUI+qujZy5tsMlIVrGRDWRBjKGyf6AdZB8
EgCWMYPdlXk2Ntf1BBrwoVB8yZ2EMdohp4MLvaEi464gCrrZuMt3CtstL5TAD1KHwyPO
b/DdarwFC200RpNQSqYe++jVRQ0chwFwKuTxtZdt1L0qrEjtkPkFY6TAiKsximXsZTeP
unFwcTDBCvE4mi4F0jqKQ0l3+dbG8ZiGtH+mTP9EAB8UCwvEs3QO039Y6d3Y562XilJP
WzYw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1707812998; x=1708417798;
h=to:subject:message-id:date:from:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=Ud7W4pwthtRSnjlwyfwOHXWb8gFJciIeFECbMRgV79A=;
b=hUs5IjmUdINr2xIYO1JxSyudMs3vKuniJBZDPcUd50ew2Bhr0U9MAySeM/urCnsqK7
7j5uCrRjj7u2/FMsKptSI0rnQx4pddE8GM4pIL+3y2uP98LEfQQl1S29nmZ0xWQcz4W0
SicWbuuFmCEb393PhfL4SOA2+0jF4CsIL6xjgtuNqdeyv5a2jLnxeWSTblt3mw4fRMYK
wXPhU9kIwHlEF1leurwA+I12lB9bTXCz3uAJH86/zRR+2yV2/kpanS/PWQEKqvUxdn3R
LcOBHhSABQtWPJIiGkSGpUrPhCcND2MXyhnHzqJi6cv41+FDNgEjvkYVJwPBF8DkfKaM
mohA==
X-Gm-Message-State: AOJu0YzMNceazR9eT7mhvo0GErpAfDguZVrrUXDgbA46PTvvCgdqB/Ch
LWBz4IbYdOy+319VXRlxVxy7hss2gsy3kPGg4K2OsHfwtcAvC/x5V7KDd/qwc3WPaPMXkAtkMfh
dJXjcxUpdtajCv5bvW3J7J1/Bfxk=
X-Google-Smtp-Source: AGHT+IGFnCtvmbZt0TGTvc+eCgq3CRvaYyTTgmT4+v6uI8Q366iiJX8FLgf0k8HmxuqhDIYWwPP+PlwJgB9AEzI1/4Y=
X-Received: by 2002:a0d:ccce:0:b0:607:7c24:fc7b with SMTP id
o197-20020a0dccce000000b006077c24fc7bmr2311693ywd.32.1707812996760; Tue, 13
Feb 2024 00:29:56 -0800 (PST)
MIME-Version: 1.0
Received: by 2002:a05:7000:da0f:b0:556:5b0:887f with HTTP; Tue, 13 Feb 2024
00:29:54 -0800 (PST)
Reply-To: dongood910@gmail.com
From: Jerome Powell
Date: Tue, 13 Feb 2024 00:29:54 -0800
Message-ID:
Subject: Central Bank of USA
To: undisclosed-recipients:;
Content-Type: text/plain; charset="UTF-8"
Bcc: games@nl2k.ab.ca
X-Spam_score: 16.4
X-Spam_score_int: 164
X-Spam_bar: ++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: -- I am now in charge of your fund payment in my department
here in Central Bank of USA (CBN) and like i stated in my mail that your
name appear in our Central Computer here as a beneficiary who have not [...]
Content analysis details: (16.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.128.171 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.128.171 listed in wl.mailspike.net]
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit
[homelandsamuel48(at)gmail.com]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[homelandsamuel48(at)gmail.com]
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[dongood910(at)gmail.com]
0.0 LOTS_OF_MONEY Huge... sums of money
-0.0 T_SCC_BODY_TEXT_LINE No description available.
2.5 MONEY_NOHTML Lots of money in plain text
1.9 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?
1.5 MONEY_ATM_CARD Lots of money on an ATM card
2.7 UNDISC_FREEM Undisclosed recipients + freemail reply-to
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
3.0 UNDISC_MONEY Undisclosed recipients + money/fraud signs
3.7 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Subject: {SPAM?} Central Bank of USA
--
I am now in charge of your fund payment in my department here in
Central Bank of USA (CBN) and like i stated in my mail that your
name appear in our Central Computer here as a beneficiary who have not
receive his contract payment for long, Be informed that your fund
of USD $5000,Million Dollars has been approved by the (IMF) and the federal
government for payment and we have decided to convert your fund into
an (ATM CARD) which we will send to you in your country for the
withdrawal of your fund in any ATM machine in your country.
To make it easy for your payment in order to avoid many expenses in
receiving your funds, we have made every arrangement regarding your
payment through (ATM CARD) since last week Due to the instruction
given to us for your immediate payment.
I have to inform you again, That we are not playing over this, I know
my reason for the continuous sending of this notification to you, The
fact is that you can't seem to trust any one again over this payment
for what you have been in cantered in many Year/months ago, But i want
you to trust me, I cannot scam you for $50 It is for bank processing
of your ATM CARD, The fees of $50 is clearly written to you before, I
did not invent the bill to defraud you of $50 It is an official bank
ATM CARD processing fee, And the good part of this, Is that you will
never, Ever be disturbed again over any kind of payment, This is
final, And the forms from there becomes effective once we submit your
ATM CARD application processing fee and pay the form fee of $50 don't
want you to loose this ATM CARD this time,
Thank you and God bless you.
Name/ Jerome Powell
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 13 Feb 2024 06:53:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rZtCe-000000002Jy-3aqb
for dave@doctor.nl2k.ab.ca;
Tue, 13 Feb 2024 06:52:04 -0700
Resent-From: The Doctor
Resent-Date: Tue, 13 Feb 2024 06:52:04 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-yw1-f171.google.com ([209.85.128.171]:45461)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.97.1 (FreeBSD))
(envelope-from
id 1rZoCu-00000000KTA-3zvA
for games@nl2k.ab.ca;
Tue, 13 Feb 2024 01:32:03 -0700
Received: by mail-yw1-f171.google.com with SMTP id 00721157ae682-6077d2b3bb1so5689257b3.3
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1707812998; x=1708417798; darn=nl2k.ab.ca;
h=to:subject:message-id:date:from:reply-to:mime-version:from:to:cc
:subject:date:message-id:reply-to;
bh=Ud7W4pwthtRSnjlwyfwOHXWb8gFJciIeFECbMRgV79A=;
b=k+SyuY8sadVVjQOtgm5kACzeDotT5l6PrHannP9U9li9RoxbS1W+1HrDi/amsbslr+
GKgDDwVgn4MNQelXYlIhnKbQYHM0XAu3QCTUI+qujZy5tsMlIVrGRDWRBjKGyf6AdZB8
EgCWMYPdlXk2Ntf1BBrwoVB8yZ2EMdohp4MLvaEi464gCrrZuMt3CtstL5TAD1KHwyPO
b/DdarwFC200RpNQSqYe++jVRQ0chwFwKuTxtZdt1L0qrEjtkPkFY6TAiKsximXsZTeP
unFwcTDBCvE4mi4F0jqKQ0l3+dbG8ZiGtH+mTP9EAB8UCwvEs3QO039Y6d3Y562XilJP
WzYw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1707812998; x=1708417798;
h=to:subject:message-id:date:from:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=Ud7W4pwthtRSnjlwyfwOHXWb8gFJciIeFECbMRgV79A=;
b=hUs5IjmUdINr2xIYO1JxSyudMs3vKuniJBZDPcUd50ew2Bhr0U9MAySeM/urCnsqK7
7j5uCrRjj7u2/FMsKptSI0rnQx4pddE8GM4pIL+3y2uP98LEfQQl1S29nmZ0xWQcz4W0
SicWbuuFmCEb393PhfL4SOA2+0jF4CsIL6xjgtuNqdeyv5a2jLnxeWSTblt3mw4fRMYK
wXPhU9kIwHlEF1leurwA+I12lB9bTXCz3uAJH86/zRR+2yV2/kpanS/PWQEKqvUxdn3R
LcOBHhSABQtWPJIiGkSGpUrPhCcND2MXyhnHzqJi6cv41+FDNgEjvkYVJwPBF8DkfKaM
mohA==
X-Gm-Message-State: AOJu0YzMNceazR9eT7mhvo0GErpAfDguZVrrUXDgbA46PTvvCgdqB/Ch
LWBz4IbYdOy+319VXRlxVxy7hss2gsy3kPGg4K2OsHfwtcAvC/x5V7KDd/qwc3WPaPMXkAtkMfh
dJXjcxUpdtajCv5bvW3J7J1/Bfxk=
X-Google-Smtp-Source: AGHT+IGFnCtvmbZt0TGTvc+eCgq3CRvaYyTTgmT4+v6uI8Q366iiJX8FLgf0k8HmxuqhDIYWwPP+PlwJgB9AEzI1/4Y=
X-Received: by 2002:a0d:ccce:0:b0:607:7c24:fc7b with SMTP id
o197-20020a0dccce000000b006077c24fc7bmr2311693ywd.32.1707812996760; Tue, 13
Feb 2024 00:29:56 -0800 (PST)
MIME-Version: 1.0
Received: by 2002:a05:7000:da0f:b0:556:5b0:887f with HTTP; Tue, 13 Feb 2024
00:29:54 -0800 (PST)
Reply-To: dongood910@gmail.com
From: Jerome Powell
Date: Tue, 13 Feb 2024 00:29:54 -0800
Message-ID:
Subject: Central Bank of USA
To: undisclosed-recipients:;
Content-Type: text/plain; charset="UTF-8"
Bcc: games@nl2k.ab.ca
X-Spam_score: 16.4
X-Spam_score_int: 164
X-Spam_bar: ++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: -- I am now in charge of your fund payment in my department
here in Central Bank of USA (CBN) and like i stated in my mail that your
name appear in our Central Computer here as a beneficiary who have not [...]
Content analysis details: (16.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.128.171 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.128.171 listed in wl.mailspike.net]
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit
[homelandsamuel48(at)gmail.com]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[homelandsamuel48(at)gmail.com]
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[dongood910(at)gmail.com]
0.0 LOTS_OF_MONEY Huge... sums of money
-0.0 T_SCC_BODY_TEXT_LINE No description available.
2.5 MONEY_NOHTML Lots of money in plain text
1.9 MONEY_FREEMAIL_REPTO Lots of money from someone using free email?
1.5 MONEY_ATM_CARD Lots of money on an ATM card
2.7 UNDISC_FREEM Undisclosed recipients + freemail reply-to
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
3.0 UNDISC_MONEY Undisclosed recipients + money/fraud signs
3.7 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Subject: {SPAM?} Central Bank of USA
--
I am now in charge of your fund payment in my department here in
Central Bank of USA (CBN) and like i stated in my mail that your
name appear in our Central Computer here as a beneficiary who have not
receive his contract payment for long, Be informed that your fund
of USD $5000,Million Dollars has been approved by the (IMF) and the federal
government for payment and we have decided to convert your fund into
an (ATM CARD) which we will send to you in your country for the
withdrawal of your fund in any ATM machine in your country.
To make it easy for your payment in order to avoid many expenses in
receiving your funds, we have made every arrangement regarding your
payment through (ATM CARD) since last week Due to the instruction
given to us for your immediate payment.
I have to inform you again, That we are not playing over this, I know
my reason for the continuous sending of this notification to you, The
fact is that you can't seem to trust any one again over this payment
for what you have been in cantered in many Year/months ago, But i want
you to trust me, I cannot scam you for $50 It is for bank processing
of your ATM CARD, The fees of $50 is clearly written to you before, I
did not invent the bill to defraud you of $50 It is an official bank
ATM CARD processing fee, And the good part of this, Is that you will
never, Ever be disturbed again over any kind of payment, This is
final, And the forms from there becomes effective once we submit your
ATM CARD application processing fee and pay the form fee of $50 don't
want you to loose this ATM CARD this time,
Thank you and God bless you.
Name/ Jerome Powell
Trackbacks
Trackback specific URI for this entryThis link is not meant to be clicked. It contains the trackback URI for this entry. You can use this URI to send ping- & trackbacks from your own blog to this entry. To copy the link, right click and select "Copy Shortcut" in Internet Explorer or "Copy Link Location" in Mozilla.
No Trackbacks
Comments
Display comments as Linear | ThreadedNo comments