SCAMS | EMAIL | PHONE | MAP | TAGS | EMAIL ANALYSIS | IP LOCATOR
Click to go to Scammed.by homepage
Forward scams to - remove your name and email address first! TO CONTACT US CLICK HERE INSTEAD


Scam email #250420 - Your user is part of the hitwheeste spoof design to spoof and sent us spam: Kopie von: Vafamosy Vafamosy

Email info

The email was sent on 2018-05-16 10:49:16 and appeared to be from info@gobi.com.sg but this address could have been spoofed.
If you replied to this email, your reply would have been sent to info@gobi.com.sg which was the scammer's actual email address.
It was probably sent from in Unknown, United Kingdom

Email header

Explains what each bit of the header means, and shows the journey the email took. Click here to show or hide it

Your content is below the advert

The scam

Your email is part of the hitwheese spoof attack.
Until your email, we have never heard of your site before.
Gobi.com.sg was hit with hitwheeste ddos attack meant to overwhelm our email server which is a repository for our cake orders and gmail correspondences.
For more on what we have found out on the attack http://zifsoft.com/2018/04/28/hitwheeste-ddos/
We would appreciate if you could help us look into this. Your email was triggered by a fake registration. Please check your forms.
Hitwheeste ddos attack starts with unsecured forms (ours was ninja forms) and unchallenged comments. you should take steps to secure them
-----------------------------------------------------------
---original email header---
Return-Path:
X-Original-To: info@gobi.com.sg
Delivered-To: x14518238@homiemail-mx25.g.dreamhost.com
Received: from mout.kundenserver.de (mout.kundenserver.de [212.227.126.187])
(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
(No client certificate requested)
by homiemail-mx25.g.dreamhost.com (Postfix) with ESMTPS id 9FAB82004BF50
for ; Tue, 15 May 2018 23:23:22 -0700 (PDT)
Received: from infong1379.kundenserver.de ([217.72.198.201]) by
mrelayeu.kundenserver.de (mreue007 [172.19.35.7]) with ESMTPA (Nemesis) id
0LdyNE-1eVEwu0ejs-00pxEV for ; Wed, 16 May 2018 08:23:20
+0200
Received: from 218.94.86.18 (IP may be forged by CGI script)
by infong1379.kundenserver.de with HTTP
id 1Jpham-1eP4Wr2kfq-00tmXi; Wed, 16 May 2018 08:23:19 +0200
X-Sender-Info: <501140061@infong1379.kundenserver.de>
Precedence: bulk
To: info@gobi.com.sg
Subject: Kopie von: Vafamosy Vafamosy
Date: Wed, 16 May 2018 08:23:19 +0200
From: "Petra D. Ernst"
Reply-To: Jerela
Message-ID:
X-Priority: 3
X-Mailer: PHPMailer 5.2.1 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="utf-8"
X-Provags-ID: V03:K1:cC4CpgoBLxHoBwYvU9jvNlS0TTvHaeBqidIcUbQ7mRkSbWaCpSA
8l8ya3beP1m6C36e4Y7uMUxw7cRTIrJvhkwHyaLjjxK5fNlHyQuxTiskY9LbB0uXWzNseTK
5LFYHhtjszJwJiDJOFpn2En2CWA2vy8nOJHwgwkUaQ6sObKPKjixnTY8td/Qq7ICjOgaFay
IGyYON+8Hoe/k91SexSnLqaWhY2ImLrxGDsC9cBk00=
X-UI-Out-Filterresults: notjunk:1;V01:K0:YmItrmOs/Sk=:H0T7iUjI0VJbzJ+W9ZzOQs
YZ1BPNeyLb0hcplhkh4YbLZtMfJh+Spdxa/qN/dw8ZlHUWsG7wSGIptKTR2sXWMNAYo5Epw07
DKfSwLx1ouSUbNI5D/bFpd1bLixe7y5d01P1CZXN/squ47Xt16s2CX3rCfHCNZSgrCJKxXhPL
Hpj+ZImqGU4+2svmLxvWHexnrKgY6Uc6GKcksYKnFE1ED0dY8o/ht0qkNwzOPtQcg9V4D97TK
aJKlQJi+7B6tll8qTt0FYuqk9LIZdEi5yoPschf/PQjm9m2XKkstA1VVqzjU3H8AIUlRP6Ky1
ojeIWBSop6FGvcPrJ7U8LKbrpr4338m3Uo/oipA46asMtkK3OGMXfmpr40buqi5QqeHZgjzll
vQ7foe4x27vjLJMALicV8EdfkBr5uxBOF1M/vdMx0Me0ySZamc8l4G/e+KggOx5D/BoNbRqlt
82p2X8sBamIm3RIjwvvCZp1gK2fPzsfZh0n11ZPhzWDdpCSIEdHYMwYnoow2ObTqO4KwrF5mQ
0NxCEKrP3pZzLZUHzOB3po5CRP1N+e18l36HTJiYExawXW9El90O6bzDht6Hqa7NwwgvM38+l
V6f05EmqYQtUgM9hGD85qPffE4rHxVhrl13RMIvkX0WAwMPAtjWaUf1WrC7yNUkj4qAyAfT2O
6sO02EY74bfiePapk0/r7avoRuIdZlmzYo9Se+/bQ2nYVumwD8KrnmjjzZz7y+TO3ZVC04joi
lCbekJsW74tU71H9

-----------------------------------------------------------
Dieses ist eine Kopie der folgenden Nachricht, die an Petra D. Ernst via Petra D. Ernst gesendet wurde:

Dies ist eine Mailanfrage via http://www.pde-schmuck.de/ von:
Jerela

But... our wallets. Our keys!
buy cake online Twenty minutes before lunch Mrs. Kind helped Fystie set up his portable CD player; Mr. Brawn cleared the largest room; Miss Glee supervised footwear and excess clothing removal, and Mrs. Dominint told them Mort was going to lead them in a jazzercise class just like the ones his stepfather took in the town gymnasium where Miss Glee went. The atmosphere became tense with excitement.

SpamAssassin Report (spam score: 8)


 pts rule                   description                                       
---- ---------------------- --------------------------------------------------
 1.0 MISSING_HEADERS        Missing To: header                                
-0.0 NO_RELAYS              Informational: message was not relayed via SMTP   
 0.5 MISSING_MID            Missing Message-Id: header                        
 1.4 MISSING_DATE           Missing Date: header                              
 1.0 MISSING_FROM           Missing From: header                              
 2.3 EMPTY_MESSAGE          Message appears to have no textual parts and no   
                            Subject: text                                     
 1.8 MISSING_SUBJECT        Missing Subject: header                           
-0.0 NO_RECEIVED            Informational: message has no Received headers    
 0.0 NO_HEADERS_MESSAGE     Message appears to be missing most RFC-822 headers



Please be careful with the links in the above email - Scammed.by strongly suggests that you do not click on any links in the above message
The email above is most likely a scam but every now and then legitimate emails do come through, as do spam emails which are not attempting to defraud, so please use your judgement
You can contact ScamSearch at help at scammed.by for any information, help, or if you have spotted a legitimate email. Please link to the email you think is legitimate.
ScamSearch does not accept any responsibility for visitors enduring any issues as a result of following links in the above email and/or contacting the sender
Please do not contact the sender unless you know what you are doing (i.e. experienced scambaiters)

Comments

Where the scam probably came from



theScamBaiter freight bait archive, theFailure Cole baits   theFAILURE freight bait from theScamBaiter - Cole v2.0   theFAILURE freight bait from theScamBaiter - Rebait at Cole's   theFAILURE freight bait from theScamBaiter - the Martins Cole saga   theFAILURE Butch Driveshaft telemarketer phone baiting   theFAILURE freight bait from theScamBaiter - Anus Laptops commercial made by scammer   theFAILURE freight bait from theScamBaiter - script of Anus Laptops commercial made by scammer