Site logo

     


Advert.
Switch to full style
DO NOT click on any links in these emails.
Post a reply

FedEx elharris@amega.com

Sat Feb 20, 2016 9:34 pm

Email:

FedEx


We have sent you a message with the required information.
Click here to open this email in your browser.


Thanks for choosing FedEx®.

More details
This message was sent to xxx@gmail.com. Please click unsubscribe if you don't want to receive these messages from FedEx in the future.

©2016 FedEx. The content of this message is protected by copyright and trademark laws under U.S. and international law.
Review our privacy policy . All rights reserved.


Phishing link hidden in the content of the message: http:/ /www. bayshorebeachclub. com/wp-content/plugins/ruffle.php

Header:

Return-Path: <elharris@amega.com>
Received: from srv29.bitloft.de (srv29.bitloft.de. [134.119.11.16])
Subject: FedEx #67576
Castigate-Carcinogen-Uprightness: 4
Hedgehogs-Surpasses: honer
Content-Transfer-Encoding: 7bit
From: FedEx <elharris@amega.com>
To:
Content-Type: text/html; charset=UTF-8
Oppressing-Shutters-Pornographic: cathedrals
Message-ID: <d73fe9d.48498.d6f11@srv29.bitloft.de>
MIME-Version: 1.0
Metropolitan-Typewriter: 32abbe9ca62311b

Originating IP: 134.119.11.16
Originating ISP: Domainfactory Gmbh
Country of Origin: Germany

<Fedex@fedex.tracking.com>

Fri Mar 18, 2016 12:09 am

* 195.238.75.22 Serverius Holding B.v. n/a Netherlands

Return-Path: <mln00321@vps3.twsf.eu>
Received: from vps3.twsf.eu ([195.238.75.22])
by mx.google.com with ESMTPS id e18si12688624wjx.104.2016.03.17.15.27.41
for <xxx>
(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Thu, 17 Mar 2016 15:27:41 -0700 (PDT)
Received-SPF: neutral (google.com: 195.238.75.22 is neither permitted nor
denied by best guess record for domain of mln00321@vps3.twsf.eu)
client-ip=195.238.75.22;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 195.238.75.22 is neither permitted nor denied by
best guess record for domain of mln00321@vps3.twsf.eu)
smtp.mailfrom=mln00321@vps3.twsf.eu
Received: from mln00321 by vps3.twsf.eu with local (Exim 4.86_1)
(envelope-from <mln00321@vps3.twsf.eu>)
id 1aggOL-0002sA-AN
for xxx Thu, 17 Mar 2016 23:27:41 +0100
Date: Fri, 18 Mar 2016 00:27:41 +0200
To: xxxx
From: FEDEX <Fedex@fedex.tracking.com>
Subject: Fedex Shipping Notification
Message-ID: <d29ca9b54f1c4fe0779f6afd82a3ccd0@www.von-der-oelmuhle-irishwolfhounds.de>
X-Priority: 3
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="us-ascii"
X-AntiAbuse: This header was added to track abuse, please include it with any
abuse report
X-AntiAbuse: Primary Hostname - vps3.twsf.eu
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [526 32007] / [47 12]
X-AntiAbuse: Sender Address Domain - vps3.twsf.eu
X-Get-Message-Sender-Via: vps3.twsf.eu: authenticated_id: mln00321/only user
confirmed/virtual account not confirmed
X-Authenticated-Sender: vps3.twsf.eu: mln00321
X-Source: /usr/bin/php
X-Source-Args: /usr/bin/php /home/mln00321/public_html/media/contacts/ugopro.php
X-Source-Dir: von-der-oelmuhle-irishwolfhounds.de:/public_html/media/contacts




Hi xxx

March 17, 2016

We are having delivery Problems.

We have tried to deliver a parcel to you multiple times and we found out your delivery address is wrong

You will need to take a survey below and give us your correct delivery address.



login
"http:/ /www.ulusalgonullulukkomitesi.org/fedex/?email=xxx



@FedEx 1995-2016 | Global Home | Terms of Use | Security and Privacy

Phishers impersonating FedEx

Fri Mar 18, 2016 9:01 pm

FedEx guisado@abbottlaw.com

Email:

FedEx:Not possible to make delivery

FedEx

Delivery problems notification.


Our companys courier couldnt make the delivery.

Tracking Updates


© FedEx 1995-2016 | Global Home | Terms of Use | Security and Privacy


Phishing link: http: / / dxmfc.org / backscattering.php

Return-Path: <guisado@abbottlaw.com>
Received: from s17629681.onlinehome-server.info (s17629681.onlinehome-server.info. [212.227.91.45])
Subject: FedEx:Not possible to make delivery
From: Paige <guisado@abbottlaw.com>


Originating IP: 212.227.91.45
Originating ISP: 1&1 Internet Ag
Country of Origin: Germany

<me@ns1.service.sg> Fedex@fedex.tracking.com

Wed Apr 06, 2016 12:21 am

* 124.6.63.102 Apc Hosting Pte Singapore Singapore

Return-Path: <me@ns1.service.sg>
Received: from ns1.service.sg (mail.service.sg. [124.6.63.102])
by mx.google.com with ESMTP id ur11si180108igb.94.2016.04.04.11.11.19
for xxx
Mon, 04 Apr 2016 11:11:19 -0700 (PDT)
Received-SPF: pass (google.com: best guess record for domain of me@ns1.service.sg
designates 124.6.63.102 as permitted sender) client-ip=124.6.63.102;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of me@ns1.service.sg
designates 124.6.63.102 as permitted sender) smtp.mailfrom=me@ns1.service.sg
Received: by ns1.service.sg (Postfix, from userid 790)
id D2414165C5B; Tue, 5 Apr 2016 02:10:23 +0800 (SGT)
To: xxx
Subject: TRACKING NOTIFICATION
From: FEDEX DELIVERY SERVICE <Fedex@fedex.tracking.com>
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <20160404181023.D2414165C5B@ns1.service.sg>
Date: Tue, 5 Apr 2016 02:10:23 +0800 (SGT)



Hi xxxx

March 31, 2016

We are having delivery Problems.

We have tried to deliver a parcel to you multiple times and we found out your delivery address is wrong

You will need to take a survey below and give us your correct delivery address.



login
"http:/ /musiq143.com/fed/?



@FedEx 1995-2016 | Global Home | Terms of Use | Security and Privacy

dgweil@amega.com

Sat Jun 11, 2016 4:14 am

Email:

FedEx


Delivery problems notification.


An package containing confidential personal information was sent to you.

Tracking Updates - phishing link: http: / / botducthinh.com/perish.php


© FedEx 1995-2013 | Global Home | Terms of Use | Security and Privacy


Return-Path: <dgweil@amega.com>
Received: from 134.vps.ho.ua (134.vps.ho.ua. [91.228.147.134])

Originating IP: 91.228.147.134
Originating ISP: Web Hosting, Datacenter And Domain Names Registrat
Country of Origin: Ukraine

Impersonating FedEx - ee44dbc9@cc.net

Sun Aug 07, 2016 7:32 pm

Email:

FedEx No.9228

We've got a new message for you.

We have sent you a message with the required information.

Have trouble reading this email?
Click here to open this email in your browser.
View messages
Please click unsubscribe if you don't want to receive these messages from FedEx in the future.



Return-Path: <ee44dbc9@cc.net>
X-Originating-IP: [203.191.147.47]
From: Catriona (FedEx) <ee44dbc9@cc.net>
Subject: xxx Notice #9228
Date: Fri, 5 Aug 2016

Originating IP: 203.191.147.47
Originating ISP: China Telecom
Country of Origin: China

Re: Phishers impersonating FedEx

Wed Aug 24, 2016 5:55 pm

Email:

FedEx No.65833

We have sent you a message.

We have sent you a message with the required information.

Have trouble reading this email?
Click here to open this email in your browser.
View messages
Please click unsubscribe if you don't want to receive these messages from FedEx International in the future.


Phishing link - http: / /illinois-litigation.com/prosodic.php

Return-Path: <et6mpon@amega.com>
Received: from 127.0.0.1 (HELO 25hr.ru) (188.226.255.139)
; Wed, 24 Aug 2016
From: Ailsa (FedEx International) <et6mpon@amega.com>

Originating IP: 188.226.255.139
Originating ISP: Digital Ocean
City: Amsterdam
Country of Origin: Netherlands

FedEx - fuentes@canega.com

Sun Sep 25, 2016 4:13 pm

Email - from FedEx <fuentes@canega.com> :

FedEx #4791

We've got a new message for you.

We have sent you a message with the required information.

Have trouble reading this email?
Click here to open this email in your browser. - link
View messages
Please click unsubscribe if you don't want to receive these messages from FedEx in the future.


Phishing link: http:/ / ochomeschool.com/cenozoic.php

Return-Path: <fuentes@canega.com>
Received: from 127.0.0.1 (HELO black-ld-079.loomes.net) (217.119.54.130)

Originating IP: 217.119.54.130
Originating ISP: Plusserver-as
City: Höst
Country of Origin: Germany
From: FedEx <fuentes@canega.com>

Kerry (FedEx International) - enriquez@ksaeng.com

Sun Feb 11, 2018 10:19 pm

Email:

FedEx No.9616

We've got a new message for you.

We have sent you a message with the required information.

Have trouble reading this email?
Click here to open this email in your browser.
View messages
Please click unsubscribe if you don't want to receive these messages from FedEx International in the future.


Return-Path: <enriquez@ksaeng.com>
X-Originating-IP: [176.9.8.205]
Received: from 127.0.0.1 (EHLO star.maralhost.com) (176.9.8.205)
Briggs-Explore: 53fe1a3e78996c
Date: Thu, 8 Feb 2018 11:01:41 +0000
Message-ID: <923b4.e5a3f47.46a8f@ksaeng.com>
From: Kerry (FedEx International) <enriquez@ksaeng.com>
Content-Type: text/html; charset=UTF-8
Subject: xxx Ticket #9616

Originating IP: 176.9.8.205
Originating ISP: Hetzner Online Gmbh
Country of Origin: Germany

Hidden link in the body of the message: http: / / ALEKSEYBROVKIN.RU/circumspectly.php

FedEx International <ggmancjancompetition@4clubbers.net>

Sat Mar 03, 2018 12:52 am

Email:

FedEx International


We have sent you a message with the required information.
Click here to open this email in your browser.


Thanks for choosing FedEx®.

More details
This message was sent to xxx. Please click unsubscribe if you don't want to receive these messages from FedEx International in the future.

©2018 FedEx. The content of this message is protected by copyright and trademark laws under U.S. and international law.
Review our privacy policy. All rights reserved.


Header:

Return-Path: <ggmancjancompetition@4clubbers.net>
Received: from isp.hwsservice.it (isp.hwsservice.it. [46.21.178.142])
Message-ID: <d2b553-a76e-b6c42@4clubbers.net>
From: FedEx International <ggmancjancompetition@4clubbers.net>
Subject: FedEx International #7194
Date: Thu, 1 Mar 2018 07:45:49

Originating IP: 46.21.178.142
Originating ISP: Planetel Srl
City: Milan
Country of Origin: Italy

Hidden link in the body of the message: http: / / reactivalaboratorio.com/curingm.php. The link analyze shows malware.
Post a reply