Advert.

Do NOT tell your scammer he is posted here, or report their accounts as it puts others at risk!

"Match.com" <noreply@match.com>

DO NOT click on any links in these emails.

"Match.com" <noreply@match.com>

Unread postby SlapHappy » Sun Dec 18, 2016 11:54 pm

* 154.120.97.25 Lagos Nigeria

Return-Path: <noreply@match.com>
Received: from mx4.ust.hk (mx4.ust.hk. [143.89.12.154])
by mx.google.com with ESMTPS id w15si13862497pgh.58.2016.12.17.17.40.47
(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Sat, 17 Dec 2016 17:40:48 -0800 (PST)
Received-SPF: fail (google.com: domain of noreply@match.com does not designate
143.89.12.154 as permitted sender) client-ip=143.89.12.154;
Authentication-Results: mx.google.com;
spf=fail (google.com: domain of noreply@match.com does not designate
143.89.12.154 as permitted sender) smtp.mailfrom=noreply@match.com;
dmarc=fail (p=NONE dis=NONE) header.from=match.com
Received: from User ([154.120.97.25]) (authenticated bits=0) by mx4.ust.hk
(8.14.4/8.14.4) with ESMTP id uBI1c9qe020725; Sun, 18 Dec 2016 09:38:12 +0800
Message-Id: <201612180138.uBI1c9qe020725@mx4.ust.hk>
From: "Match.com" <noreply@match.com>
Subject: You have 1 new Security Message Alert
Date: Sun, 18 Dec 2016 02:38:50 +0100
MIME-Version: 1.0
Content-Type: text/html; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000


Dear Customer,

You have 1 new Security Message Alert.

Please Log In into your account by clicking verify your Match account details to secure your Match.
If you do not respond to this verification, it will be noted that you
support online fraudulent acts and you will have your Match account suspended.

verify
"http:/ /www.matchonline.myjino.ru/Match/Match/Match.htm"


Thank you

** Our Terms of Use Agreement was revised 10/7/2016.
? Copyright 2016 Match.com, L.L.C.

Page Rendered on: Fri Dec 16 2016 05:17:23 GMT+0100 (v2.6.3 #2d40790 h:da3-015 api:match)
If anyone asks you for money on the Internet they are always a scammer, 100% of the time.
Blackmail Scammed? Go here: https://www.scamsurvivors.com/blackmail/#/
FAQ viewtopic.php?f=3&t=19
Victim of a scam? Go here: https://scamsurvivors.com/forum/viewtop ... =3&t=26504
User avatar
SlapHappy
Retired admin/co creator
 
Posts: 44968
Joined: Tue Apr 17, 2012 5:18 am
Location: Just a face in a magazine, watching you post your scammer's details.

"Match.com" <email@emailserver.inc>

Unread postby SlapHappy » Mon Dec 19, 2016 1:56 pm

IP address [?]: 95.138.137.184
IP country code: GB
IP address country: ip address flag United Kingdom
ISP of this IP [?]: Rackspace Ltd.
Organization: Rackspace Ltd.
Host of this IP: [?]: ns1.strategy-plus.net

Return-Path: <apache@ns1.strategy-plus.net>
Received: from ns1.strategy-plus.net (ns1.strategy-plus.net. [95.138.137.184])
by mx.google.com with ESMTPS id cc1si17984075wjc.168.2016.12.19.02.44.36
for <xxx>
(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Mon, 19 Dec 2016 02:44:36 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of
apache@ns1.strategy-plus.net designates 95.138.137.184 as permitted sender)
client-ip=95.138.137.184;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of
apache@ns1.strategy-plus.net designates 95.138.137.184 as permitted sender)
smtp.mailfrom=apache@ns1.strategy-plus.net
Received: by ns1.strategy-plus.net (Postfix, from userid 48) id 757B1270EAF;
Mon, 19 Dec 2016 10:44:01 +0000 (GMT)
To: xxx
Subject: WARNING YOUR ACCOUNT WILL BE SHUTDOWN CANCEL DE-ACTIVATION
X-PHP-Originating-Script: 48:$ThanksToWater$.php
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: "Match.com" <email@emailserver.inc>
Reply-To: email@emailserver.inc
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: www.clarkabel.co.uk
Message-Id: <20161219104401.757B1270EAF@ns1.strategy-plus.net>
Date: Mon, 19 Dec 2016 10:44:01 +0000 (GMT)




Server Message


Dear [victim email address]
Our record indicates that you recently made a request to shutdown your email ([victim email address] ). And this request will be processed shortly.

If this request was made accidentally and you have no knowledge of it, you are advised to cancel the request now

Cancel De-activation
"http:/ /onlinematch.myjino.ru/Counter/Counter/index.php?email=victim email address"

However, if you do not cancel this request, the your account will be shutdown shortly
and all your email data will be lost permanently.
Regards.
Email Administrator

This message is auto-generated from E-mail security server, and replies sent to this email can not be delivered.
This email is meant for: [victim email address]
If anyone asks you for money on the Internet they are always a scammer, 100% of the time.
Blackmail Scammed? Go here: https://www.scamsurvivors.com/blackmail/#/
FAQ viewtopic.php?f=3&t=19
Victim of a scam? Go here: https://scamsurvivors.com/forum/viewtop ... =3&t=26504
User avatar
SlapHappy
Retired admin/co creator
 
Posts: 44968
Joined: Tue Apr 17, 2012 5:18 am
Location: Just a face in a magazine, watching you post your scammer's details.


Return to No clicky clicky. Sites that try to install a virus on your PC.

Who is online

Users browsing this forum: No registered users and 15 guests