An
Email with the Subject "Funding Offer" was
received in one of Scamdex's honeypot email accounts on Fri, 24 Apr 2015 01:35:24 -0700 (PDT)
and has been classified as a Generic Scam Email.
The sender shows as "dublimuk1@yahoo.co.uk" <dublimuk1@yahoo.co.uk>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[delivered-to:] => scamdex@gmail.com
[received:] => Array
(
[0] => by 10.96.216.195 with SMTP id os3csp1114672qdc; Fri, 24 Apr 2015 01:35:24 -0700 (PDT)
[1] => from nm21-vm3.bullet.mail.ne1.yahoo.com (nm21-vm3.bullet.mail.ne1.yahoo.com. [98.138.91.151]) by mx.google.com with ESMTPS id r41si8919999ioi.30.2015.04.24.01.35.23 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 24 Apr 2015 01:35:23 -0700 (PDT)
[2] => from [98.138.100.113] by nm21.bullet.mail.ne1.yahoo.com with NNFMP; 24 Apr 2015 08:35:20 -0000
[3] => from [98.138.88.233] by tm104.bullet.mail.ne1.yahoo.com with NNFMP; 24 Apr 2015 08:35:20 -0000
[4] => from [127.0.0.1] by omp1033.mail.ne1.yahoo.com with NNFMP; 24 Apr 2015 08:35:20 -0000
[5] => by 98.138.105.197; Fri, 24 Apr 2015 08:35:19 +0000
)
[x-received:] => by 10.50.61.130 with SMTP id p2mr1045639igr.9.1429864523863; Fri, 24 Apr 2015 01:35:23 -0700 (PDT)
[return-path:] =>
[received-spf:] => pass (google.com: domain of ericsunrise5@yahoo.com designates 98.138.91.151 as permitted sender) client-ip=98.138.91.151;
[authentication-results:] => mx.google.com; spf=pass (google.com: domain of ericsunrise5@yahoo.com designates 98.138.91.151 as permitted sender) smtp.mail=ericsunrise5@yahoo.com; dkim=pass header.i=@yahoo.co.uk; dmarc=pass (p=NONE dis=NONE) header.from=yahoo.co.uk
[dkim-signature:] => v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.co.uk; s=s2048; t=1429864520; bh=GGU6uvZtgoJoqB356WoLRrorIfvpRdDEf6Njn4bvWOY=; h=Date:From:Reply-To:To:Subject:From:Subject; b=A5L440OEQLoWj6b5rk91DxTKNyMeBD7e3ObVmq+9i2KMb1NCQTgvO8buv15Jr9sMl+xDEHJVNenM+yRWRS0v/sOEKmJopgaCUCvy5LrsR5GwlNUUBJIaQAFUiI2xrKYqeKgSKnLMCE3RDH0PUrYro0hrpCCsI41f2zxLcSM60ZDPCHeGxzVvS5oVKF5osqrrypu+F01RIAHoQiqDv769sMDCQJIi/FIwkfRRH7K76wy1V68Nog4NhPqYNFYHLhRoJuXniETy6krTviJPU2y+J1gC+EYa4jDNIMS1hGKsuR8rXFInZucbYTK7t4Y7JVljR/L/VhoDYFDmVHyRWAV5ng==
[x-yahoo-newman-property:] => ymail-3
[x-yahoo-newman-id:] => 542115.55908.bm@omp1033.mail.ne1.yahoo.com
[x-ymail-osg:] => 7IMhHOUVM1ln1KPlFBIgr4t4fI3RaWs8wRhhu1WzzlPQbf_M6m1B.BbRWVRYH.YbGOVR.r5aIPZt9vySG4QoPvRbvHIDtPcfiFLETG0GWuCBDmauXhPmcU8CTlGs_hhe0vRdtTvqgDnsAbKwH9wHSpsesszIF7_Ldg0SuWdx.BLQzWUocNj7tpc467dpw.SR6fruBSzZZ6hTawaexsVlrZ4f8DziJ1J_.JZU9lsG1Yg047DESNHMbesjXp_Gb9TnV90ueiDHwXVwgbZZCwctevKnyYHWoFCZ16Ied8Ztbpqdu705Ya2asPipqbn4Tt2rLqTBCdS5fywvIcBg1VYuyr9uELz4nNULarMtQ9ECdWqWx18MHrkpeC2FVTSKxmyjIrulFaPVOoHoBFbJEaM0tXuG2wrWbmtTDQhxyh8TrccBvRyxz6P3R_ZjKyl7UlJC9SrP3RIapTD785UQW7op9bwcNF.BjnkxioiQhLB60lWHFar8lOWvow--
[date:] => Fri, 24 Apr 2015 08:35:19 +0000 (UTC)
[from:] => "dublimuk1@yahoo.co.uk"
[reply-to:] => "dublimuk1@yahoo.co.uk"
[to:] => "dublimuk1@yahoo.co.uk"
[message-id:] => <387448513.3490265.1429864519477.JavaMail.yahoo@mail.yahoo.com>
[subject:] => Funding Offer
[mime-version:] => 1.0
[content-type:] => multipart/alternative; boundary="----=_Part_3490264_1247796694.1429864519474"
[content-length:] => 3086
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
We are financial consultants to a group of Arab investors whom we have their consent to manage their funds which is in our custody for cooperation in joint venture business investments. Our areas of interest include Property Development and real estate, Health Care,Education and training, Mining and exploration, Energy, oil and gas,Technology, Software development, Agriculture, Manufacturing,Finance Services and Leisure.
However, all viable proposals within reason will be considered. Funds shall be made available to you as a direct investment loan at 5% interest rate per annual for a period of 5 or 10 years depending on what you prefer. You may contact us if you have interesting investment proposal for possible business collaboration for our study.
We look forward to your reply to enable us provide you with details or you may visit our website
Kindly acknowledge receipt of email.
Yours Sincerely Mrs.M.Santos
Dear Sir,
We are financial consultants to a group of Arab investors whom we have their consent to manage their funds which is in our custody for cooperation in joint venture business investments. Our areas of interest include Property Development and real estate, Health Care,Education and training, Mining and exploration, Energy, oil and gas,Technology, Software development, Agriculture, Manufacturing,Finance Services and Leisure.
However, all viable proposals within reason will be considered. Funds shall be made available to you as a direct investment loan at 5% interest rate per annual for a period of 5 or 10 years depending on what you prefer. You may contact us if you have interesting investment proposal for possible business collaboration for our study.
We look forward to your reply to enable us provide you with details or you may visit our website