Advert.

Do NOT tell your scammer he is posted here, or report their accounts as it puts others at risk!

business@magentamail.site

DO NOT click on any links in these emails.

business@magentamail.site

Unread postby Wayne » Mon Mar 30, 2020 5:25 pm

Sent to my site email, so thank you Mr. spammer for that :D

Robert Espinal <business@magentamail.site>
***SPAM*** Successful Payment


Great Clothes
1929 Elsie Drive
Baltimore, 21229

2020-01-11 Transaction Id: 405SH6
$997.95




Item 1

Quantity: 1 Price: $997.95


Download receipt
Links to https:// gpreceipt .xyz/ index.php?q=f55d21685c5c27e519aaef27367b08b4


SubTotal
Total $997.95
$997.95





Return-Path: <business@magentamail.site>
Delivered-To: wayne@scamsurvivors.com
Received: from server1.scamsurvivors.com
by server1.scamsurvivors.com with LMTP
id zmiaKqocgl58bQAAcPn/pw
(envelope-from <business@magentamail.site>)
for <wayne@scamsurvivors.com>; Mon, 30 Mar 2020 17:22:02 +0100
Return-path: <business@magentamail.site>
Envelope-to: wayne@scamsurvivors.com
Delivery-date: Mon, 30 Mar 2020 17:22:02 +0100
Received: from [195.123.224.13] (port=50742 helo=magentamail.site)
by server1.scamsurvivors.com with esmtp (Exim 4.93)
(envelope-from <business@magentamail.site>)
id 1jIxAm-0007FB-NA
for wayne@scamsurvivors.com; Mon, 30 Mar 2020 17:22:02 +0100
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=key1; d=magentamail.site;
h=Message-ID:Reply-To:From:To:Subject:Date:MIME-Version:Content-Type; i=business@magentamail.site;
bh=P73VCTHlwfgry+8Csl4odQ8F/z4=;
b=UFYe5FZbHQqLUNuex31nSaBHh9uicGOOy9u+EqqpETdORN5H3QM015gFlCD8/C5cNgzG8ObxUDpI
jWIJ5UH+mOLWYHXW3q6PDCXFRvUiNEZ/HwE23ZuCOyM/4ffO5KHUAFx/aOTzSqdrOt/T/glm6Fbr
Z+PsOlQE8F0JnHyB4cs=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=key1; d=magentamail.site;
b=TuyXWkih+JEiqm7Wv7CxnzgBQxPPRsbDs+d6NYXxT8mN+sLULTHOa9UgUnmf+cXSLGgZ+RQyo44m
dWDfcFrZ/ibCiTzZ0/4gfKjjFyXjexOxw1YSExBqnseXTHREAHAuEQzIt8iv5QQ/HM80GxnLKm59
c+sdZKmycIFtmk/nLa8=;
Message-ID: <a879309d02133933efea5cf017e3c9ccf0920e@magentamail.site>
Reply-To: "Robert Espinal" <maillist@mailserver.com>
From: "Robert Espinal" <business@magentamail.site>
To: wayne@scamsurvivors.com
Date: Mon, 30 Mar 2020 09:18:50 -0700
Organization: LLC
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="2889c06df2e3c9c31f1aac00e713393c08f25d"
X-Spam-Status: Yes, score=27.1
X-Spam-Score: 271
X-Spam-Bar: +++++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server1.scamsurvivors.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Great Clothes 1929 Elsie Drive Baltimore, 21229 2020-01-11
Transaction Id:  405SH6 $997.95
Content analysis details: (27.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
4.5 URIBL_DBL_SPAM Contains a spam URL listed in the Spamhaus DBL
blocklist
[URIs: magentamail.site]
1.2 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL
blocklist
[URIs: gpreceipt.xyz]
3.3 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[195.123.224.13 listed in zen.spamhaus.org]
0.1 URIBL_CSS_A Contains URL's A record listed in the Spamhaus CSS
blocklist
[URIs: magentamail.site]
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5000]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
1.4 PDS_OTHER_BAD_TLD Untrustworthy TLDs
[URI: gpreceipt.xyz (xyz)]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 HTML_MESSAGE BODY: HTML included in message
5.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: gpreceipt.xyz]
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
0.9 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
1.9 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
0.5 FROM_SUSPICIOUS_NTLD From abused NTLD
0.7 FROM_SUSPICIOUS_NTLD_FP From abused NTLD
5.0 KAM_VERY_BLACK_DBL Email that hits both URIBL Black and Spamhaus
DBL
0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
X-Spam-Flag: YES
Subject: ***SPAM*** Successful Payment
X-Antivirus: Avast (VPS 200329-0, 29/03/2020), Inbound message
X-Antivirus-Status: Clean
Click HERE for webcam blackmail/sextortion help.
Do NOT email me for sextortion help. Use the link above. If you ignore this, your message WILL be deleted.
Image
User avatar
Wayne
Site owner/"cruel and sarcastic" admin.
 
Posts: 48111
Joined: Mon Apr 16, 2012 5:13 pm

Return to No clicky clicky. Sites that try to install a virus on your PC.

Who is online

Users browsing this forum: No registered users and 3 guests