Extortion mail phishing scam requesting money refund for non-existant account.
PhishingEmail Spam
Anonymous
Received: from 10.197.36.76
by atlas304.free.mail.bf1.yahoo.com pod-id NONE with HTTPS; Thu, ... show moreReceived: from 10.197.36.76
by atlas304.free.mail.bf1.yahoo.com pod-id NONE with HTTPS; Thu, 12 Jan 2023 08:16:54 +0000
Return-Path: <[email protected]wn.eqlc.6wybr.autobiographicaldennison.com>
X-Originating-Ip: [198.20.170.14]
Received-SPF: fail (domain of wmlitsbka3eygj4fp0wn.eqlc.6wybr.autobiographicaldennison.com does not designate 198.20.170.14 as permitted sender)
Authentication-Results: atlas304.free.mail.bf1.yahoo.com;
dkim=unknown;
spf=fail smtp.mailfrom=wmlitsbka3eygj4fp0wn.eqlc.6wybr.autobiographicaldennison.com;
dmarc=unknown header.from=NYG0IPs.kl58nadjzfh9s40.autobiographicaldennison.com;
X-Apparently-To: [email protected]; Thu, 12 Jan 2023 08:16:55 +0000 show less
Received: from mout.perfora.net (mout.perfora.net [74.208.4.194])
KRIG - A strategy game <pro ... show moreReceived: from mout.perfora.net (mout.perfora.net [74.208.4.194])
KRIG - A strategy game <[email protected]> show less
Square phishing X-Originating-Ip: [74.208.4.194]
Received-SPF: none (domain of andrew-l-fawle ... show moreSquare phishing X-Originating-Ip: [74.208.4.194]
Received-SPF: none (domain of andrew-l-fawley.com does not designate permitted sender hosts) show less
Phishing scam
From: [email protected]
Sent on: Wednesday, September 21, 2022 9:4 ... show morePhishing scam
From: [email protected]
Sent on: Wednesday, September 21, 2022 9:44:35 AM
Subject: ACH COPY SENT September 21, 2022
Urgent: High
Attachments: <company name removed> ACH COPY.html (649 Bytes) show less
IT Services Companies M&A - 2022 Q3 Report - Federal Government Contracts Companies and other Compan ... show moreIT Services Companies M&A - 2022 Q3 Report - Federal Government Contracts Companies and other Company Acquired, Businesses Wanted and Available show less
PhishingWeb SpamEmail SpamSpoofing
Anonymous
%100 FINANCIALLY PHISHING !!!
Received: from 10.253.31.91
by atlas113.free.ma ... show more%100 FINANCIALLY PHISHING !!!
Received: from 10.253.31.91
by atlas113.free.mail.gq1.yahoo.com with HTTPS; Thu, 25 Aug 2022 10:01:34 +0000
Return-Path: <[email protected]>
X-Originating-Ip: [74.208.4.194]
Received-SPF: softfail (domain of transitioningtelus.net does not designate 74.208.4.194 as permitted sender)
Authentication-Results: atlas113.free.mail.gq1.yahoo.com;
dkim=unknown;
spf=softfail smtp.mailfrom=telus.net;
dmarc=fail(p=NONE) header.from=telus.net;
𝗖𝗵𝗮𝘀𝗲® Online: This is automatic message.Sent on: 10:01:32 AM Thursday, August 25, 2022
D323201BhfaaWe323201nUAXoamRhfr3232011uiOQZ CCll7C323201h80qkl323201sZEiJWIeg078yn323201ySo5tmtb6, show less
DNS CompromiseDNS PoisoningFraud OrdersDDoS AttackFTP Brute-ForcePing of DeathPhishingFraud VoIPOpen ProxyWeb SpamEmail SpamBlog SpamVPN IPPort ScanHackingSQL InjectionSpoofingBrute-ForceBad Web BotExploited HostWeb App AttackSSHIoT Targeted