Advert.

Do NOT tell your scammer he is posted here, or report their accounts as it puts others at risk!

"Wells Fargo" <shovstad@purdue.edu>

DO NOT click on any links in these emails.

"Wells Fargo" <shovstad@purdue.edu>

Unread postby SlapHappy » Wed May 18, 2016 5:31 pm

41.246.124.143 Telkom Internet Johannesburg South Africa

Return-Path: <shovstad@purdue.edu>
Received: from mailhub247.itcs.purdue.edu (mailhub247.itcs.purdue.edu.
[128.210.5.247])
by mx.google.com with ESMTPS id r3si4969303itr.100.2016.05.17.14.13.21
for <xxx>
(version=TLS1 cipher=AES128-SHA bits=128/128);
Tue, 17 May 2016 14:13:21 -0700 (PDT)
Received-SPF: pass (google.com: best guess record for domain of
shovstad@purdue.edu designates 128.210.5.247 as permitted sender)
client-ip=128.210.5.247;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of
shovstad@purdue.edu designates 128.210.5.247 as permitted sender)
smtp.mailfrom=shovstad@purdue.edu
Received: from admin-PC.vpn.ucf.edu (dsl-246-124-143.telkomadsl.co.za
[41.246.124.143])
(authenticated bits=0)
by mailhub247.itcs.purdue.edu (8.14.4/8.14.4/mta-auth.smtp.purdue.edu)
with ESMTP id u4HL9noa022824
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT)
for <xxx>; Tue, 17 May 2016 17:13:20 -0400
Message-Id: <201605172113.u4HL9noa022824@mailhub247.itcs.purdue.edu>
Content-Type: multipart/alternative; boundary="===============1067697134=="
MIME-Version: 1.0
Subject: Please Upgrade Your Preference security Update
To: xxx
From: "Wells Fargo" <shovstad@purdue.edu>
Date: Tue, 17 May 2016 23:13:13 +0200
X-PMX-Version: 6.0.2.2308539
X-PerlMx-URL-Scanned: Yes
X-PerlMx-Virus-Scanned: Yes



Wells Fargo

Wells Fargo Customer Protection Center
We've detected something unusual about your Wells Fargo billing information.

To help keep you safe kindly click VERIFY ME NOW
"http:/ /largeprintlondon.co.uk/deltacleaning/wp-content/themes/twentythirteen/images/headers/red.php"

After you have successfully enter your billing account details, your billing information will be updated automatically.

Thank you for choosing Wells Fargo.
Regards,
Wells Fargo
If anyone asks you for money on the Internet they are always a scammer, 100% of the time.
Blackmail Scammed? Go here: https://www.scamsurvivors.com/blackmail/#/
FAQ viewtopic.php?f=3&t=19
Victim of a scam? Go here: https://scamsurvivors.com/forum/viewtop ... =3&t=26504
User avatar
SlapHappy
Retired admin/co creator
 
Posts: 44968
Joined: Tue Apr 17, 2012 5:18 am
Location: Just a face in a magazine, watching you post your scammer's details.

"Wells Fargo" <aclose@purdue.edu>

Unread postby SlapHappy » Thu May 19, 2016 7:58 pm

41.246.150.69 Telkom Internet Johannesburg South Africa

Return-Path: <aclose@purdue.edu>
Received: from mailhub248.itcs.purdue.edu (mailhub248.itcs.purdue.edu.
[128.210.5.248])
by mx.google.com with ESMTPS id l40si14829901iod.143.2016.05.19.11.48.06
for <xxx>
(version=TLS1 cipher=AES128-SHA bits=128/128);
Thu, 19 May 2016 11:48:06 -0700 (PDT)
Received-SPF: pass (google.com: best guess record for domain of
aclose@purdue.edu designates 128.210.5.248 as permitted sender)
client-ip=128.210.5.248;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of aclose@purdue.edu
designates 128.210.5.248 as permitted sender) smtp.mailfrom=aclose@purdue.edu
Received: from admin-PC.vpn.ucf.edu (8ta-246-150-69.telkomadsl.co.za [41.246.150.69])
(authenticated bits=0)
by mailhub248.itcs.purdue.edu (8.14.4/8.14.4/mta-auth.smtp.purdue.edu) with
ESMTP id u4JIj9gL004500
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT)
for <xxx>; Thu, 19 May 2016 14:48:04 -0400
Message-Id: <201605191848.u4JIj9gL004500@mailhub248.itcs.purdue.edu>
Content-Type: multipart/alternative; boundary="===============0604987935=="
MIME-Version: 1.0
Subject: Please Upgrade Your Preference security Update
To: xxx
From: "Wells Fargo" <aclose@purdue.edu>
Date: Thu, 19 May 2016 20:47:54 +0200
X-PMX-Version: 6.0.2.2308539
X-PerlMx-URL-Scanned: Yes
X-PerlMx-Virus-Scanned: Yes



Wells Fargo

Wells Fargo Customer Protection Center
We've detected something unusual about your Wells Fargo billing information.

To help keep you safe kindly click VERIFY ME NOW
"http:/ /largeprintlondon.co.uk/deltacleaning/wp-content/themes/twentythirteen/images/headers/red.php"


After you have successfully enter your billing account details, your billing information will be updated automatically.

Thank you for choosing Wells Fargo.
Regards,
Wells Fargo
If anyone asks you for money on the Internet they are always a scammer, 100% of the time.
Blackmail Scammed? Go here: https://www.scamsurvivors.com/blackmail/#/
FAQ viewtopic.php?f=3&t=19
Victim of a scam? Go here: https://scamsurvivors.com/forum/viewtop ... =3&t=26504
User avatar
SlapHappy
Retired admin/co creator
 
Posts: 44968
Joined: Tue Apr 17, 2012 5:18 am
Location: Just a face in a magazine, watching you post your scammer's details.


Return to No clicky clicky. Sites that try to install a virus on your PC.

Who is online

Users browsing this forum: No registered users and 16 guests

cron