An
Email with the Subject "Fwd: Alert" was
received in one of Scamdex's honeypot email accounts on 06 Jul 2020 04:21:56 -0000
and has been classified as a Generic Scam Email.
The sender shows as Tanya Davis <tana970@msn.com>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[delivered-to:] => Array
(
[0] => unknown
[1] => scamdex@gmail.com
)
[received:] => Array
(
[0] => from imap.gmail.com (74.125.195.108:993) by mail.scamalot.com with IMAP4-SSL; 06 Jul 2020 04:21:56 -0000
[1] => by 2002:a02:2424:0:0:0:0:0 with SMTP id f36csp1498434jaa; Thu, 25 Jun 2020 05:50:30 -0700 (PDT)
[2] => from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id s17sor19485656qkg.182.2020.06.25.05.50.29 for (Google Transport Security); Thu, 25 Jun 2020 05:50:29 -0700 (PDT)
[3] => from NAM12-DM6-obe.outbound.protection.outlook.com (mail-dm6nam12olkn2059.outbound.protection.outlook.com. [40.92.22.59]) by gmr-mx.google.com with ESMTPS id z7si1225892qta.2.2020.06.25.05.50.29 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 25 Jun 2020 05:50:29 -0700 (PDT)
[4] => from MW2NAM12FT061.eop-nam12.prod.protection.outlook.com (2a01:111:e400:fc65::49) by MW2NAM12HT208.eop-nam12.prod.protection.outlook.com (2a01:111:e400:fc65::372) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3131.13; Thu, 25 Jun 2020 12:50:28 +0000
[5] => from BN8PR07MB6898.namprd07.prod.outlook.com (2a01:111:e400:fc65::45) by MW2NAM12FT061.mail.protection.outlook.com (2a01:111:e400:fc65::509) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3131.13 via Frontend Transport; Thu, 25 Jun 2020 12:50:28 +0000
[6] => from BN8PR07MB6898.namprd07.prod.outlook.com ([fe80::5041:4488:863e:4d8e]) by BN8PR07MB6898.namprd07.prod.outlook.com ([fe80::5041:4488:863e:4d8e%8]) with mapi id 15.20.3131.020; Thu, 25 Jun 2020 12:50:28 +0000
)
[x-received:] => Array
(
[0] => by 2002:aed:3e2e:: with SMTP id l43mr19005773qtf.287.1593089429873; Thu, 25 Jun 2020 05:50:29 -0700 (PDT)
[1] => by 2002:a37:a20d:: with SMTP id l13mr28425695qke.296.1593089429682; Thu, 25 Jun 2020 05:50:29 -0700 (PDT)
)
[arc-seal:] => Array
(
[0] => i=3; a=rsa-sha256; t=1593089429; cv=pass; d=google.com; s=arc-20160816; b=K8A4K2//aSJqIh1WDHDV8FoNqLpNUcQt0PXaAp/5ek9nn3t3tXsVenQ17r57wtysmS UXWR31i9NsWfljmXcppa0OhCWouIDde1TNxQg2l3IOT/oHqwmssGY0wCn/ca2aREHTLy 1f7ooPFV7iZuEwNwXgxz6mfU2raMSSRyBoLx5Mv+afmry1c4b/Zgu00FbN5iPOLn9kzs m+jqa0WIXxg2ibgjV8dbgGEZgZteLKHSQwqbBF9ZDq6VVScxQYeEYkBCIVsXZSyAs3bD O7ya8rCV2r6SbvW3Z5bGfWc5Y05C7qyDc59HTbx27zHnhTsUIoyNDo2NXpT1zsNr8ulC TUAg==
[1] => i=2; a=rsa-sha256; t=1593089429; cv=pass; d=google.com; s=arc-20160816; b=D7fW0HIWm27Ujmzqs917p488dSh6BdqBNLqHf7kFWvLt4RomL4CHhyowD2hAmlY00p SbKLDpOfQHuAzFRVkREoY70sG+M2KJMcekjtCsWVlpYneVlVYkbWTvIX8OkgBj6Ml7u2 ZEKaDQ4/TsnTNY5vKbPST2SQ1m1J+ZAUuRY6cDbc66lxKPYk1vp/Gdre+dvssdgHEdSb VOQZMQtgCf+4Tdf9LBpURnhbRYHPRYLqCZtpH/0SxGnGENU5PZC0y4EOiZyadMiEJqtT Rj3Q83R/ZDRsW2vV0QNzf14171FMI84EIgDPwdgcGlJeuOsrxSlK7RqD4S3K3n+7n9ga jjIQ==
[2] => i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=iGSkr1GT+70LRbV/owMmU30OF3q9h/Xc5lF/WfGy1m63Q9EEVVsS9DIGwqx6xDOnQRQHLuaLFps2usy4jb16Ab0oeM92pRijNVXZYplgW3Jg/xAfbRw1SlQGHpZY0w7GsbpTMGzkUGrcPPHrh0EoGuMqCb2mdiQ/22NkUhrLopAu8hfprqyk/jmJa9XMh2miv5ncBWJsg5J2L32JjRlrB3tupNXCzku68f4VAdf9KerMrz4jh/MpHzDwhPFbdchuqUPuAcn4uDAyMj/eTZ55xMuFtBr4qPVe/edosceyjlg0skdHjDASnKreBTSxJlAIYI/6fg2X9RWakeRb5UiT6A==
)
[arc-message-signature:] => Array
(
[0] => i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=mime-version:content-language:accept-language:in-reply-to :references:message-id:date:thread-index:thread-topic:subject:to :from:dkim-signature; bh=+7hC1yLv/d47Fm1f/crmWbnmNjpz9dGkU3VT6y9MZ9E=; b=ZADfwPM/1an9o7jliFOnh2RfRuV0mh8pm/EI5OPIt2SmTLMmfdj0HjNFecsFFyby1C xx3NPT22WhOqLgUT7nDKFPtuKXQqdHd1KGPk2pGEWsPqQcXTebOSX6Na0xNJaAaqBhxI HrRv2VBMBW+MVA7MyWG5xkwO6aVvyO/+K+6x2uPVyJYLXPVt0tcPcfVkWTo9iCmbStnw wP5cgosfNomR20D5sj9u/P2CdobOvy2N5gxsGtt99/pM9uaiZb3at3S8XMJxSyN9SMuq 2/Qwe3wj7BqpmrIpvzOjEQUxGNpiIHXxCZ9EUeDQcGhVXyHbTGpYR6IT8/Uxyw7uPjhC /+xg==
[1] => i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=mime-version:content-language:accept-language:in-reply-to :references:message-id:date:thread-index:thread-topic:subject:to :from:dkim-signature; bh=+7hC1yLv/d47Fm1f/crmWbnmNjpz9dGkU3VT6y9MZ9E=; b=RM9WSlDd/XzVffERP29X5U8QJAaTsXOfW5Hji35420qI9JQilsMT1zmKTbQav8CfyD yJhpy6fEZBcIgZgiezJpQSKJqKeKg5XRW2Hlspnsah1UZ3adXCM3XAZN9TdFcuiUKrOU x6B0dXpAPvaMSPHOgfUpqiKmjTV4PbCevo2BKyXnewr/Nnn5FqIzdQfDCVRotYK+rkfB 5FwGOhZXCMPC+bGUpQ5m/GcrCm6MktyK7C+FaehAGeap12WS4ccVihUvwPh0JTgW/kdo MiHMH+AtxQwMWiPQCZnK9Uwe1HlKnxVdu4/w1Fb9lxfC8+8XOL3/Thw0Xmos5vstQmy6 K5Yg==
[2] => i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+7hC1yLv/d47Fm1f/crmWbnmNjpz9dGkU3VT6y9MZ9E=; b=BPhnvPsY7igxSNxS7HTWr/dlxYUyZ+OM2l4X9ICJ0fDE+Akj3tBYTRa3hMwI7FH144+IHnu98bMOkq/vFqRf3ccsZL/0t4s+eofKbKw492x59IeFvflkeau1+MNJIVVJOiOAmpYvzN+x+ndyfHBl77b3DLHsbVpBXDY9sbAM5KyAGahILM8lTRfPQ6tS+Y49kjQob3AOheP78C1DdLQdr6H90UdPZDza5jXwJWtEh3aoR8sWhb9TTweaEXOH/PCnxrVQroayNs5A6cHugXoX0iphcTkR6WNvCqDJdt7hLxxb53Xxrrz0oi5DlwX3FURR9mkp+mQbcTQ6XE4s2lXjQw==
)
[arc-authentication-results:] => Array
(
[0] => i=3; mx.google.com; dkim=pass header.i=@msn.com header.s=selector1 header.b=NZT8AF5G; arc=pass (i=2 spf=pass spfdomain=msn.com dkim=pass dkdomain=msn.com dmarc=pass fromdomain=msn.com); spf=softfail (google.com: domain of transitioning tana970@msn.com does not designate 209.85.220.41 as permitted sender) smtp.mailfrom=tana970@msn.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=msn.com
[1] => i=2; gmr-mx.google.com; dkim=pass header.i=@msn.com header.s=selector1 header.b=NZT8AF5G; arc=pass (i=1); spf=pass (google.com: domain of tana970@msn.com designates 40.92.22.59 as permitted sender) smtp.mailfrom=tana970@msn.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=msn.com
[2] => i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
)
[received-spf:] => Array
(
[0] => softfail (google.com: domain of transitioning tana970@msn.com does not designate 209.85.220.41 as permitted sender) client-ip=209.85.220.41;
[1] => pass (google.com: domain of tana970@msn.com designates 40.92.22.59 as permitted sender) client-ip=40.92.22.59;
)
[authentication-results:] => mx.google.com; dkim=pass header.i=@msn.com header.s=selector1 header.b=NZT8AF5G; arc=pass (i=2 spf=pass spfdomain=msn.com dkim=pass dkdomain=msn.com dmarc=pass fromdomain=msn.com); spf=softfail (google.com: domain of transitioning tana970@msn.com does not designate 209.85.220.41 as permitted sender) smtp.mailfrom=tana970@msn.com; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=msn.com
[x-google-dkim-signature:] => v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:dkim-signature:from:to:subject:thread-topic :thread-index:date:message-id:references:in-reply-to:accept-language :content-language:mime-version; bh=+7hC1yLv/d47Fm1f/crmWbnmNjpz9dGkU3VT6y9MZ9E=; b=aEuDauF0Wsgkm4t1xSgrVxASwYVlddxxaDGUs5VkjcetAtXkiNl1xkX3oofkZX80a6 KPaUcRKGHPPHIIAeDfFHK/7jaSz0UVfUWrsPCSAiYvEjCq6Zq7BOUudX2a+fcsqvbC0Y 8X2SYC88HTgXcam8H46hbiBwZLraKZxUUy0pb5zOUW2v6jlAbSMzDyv/byfvRhF1F+jD YAPrxQxYDRy12LKVSgWIacCyUfCzNiaK+Bx+vIdjOO34N5Htp3Z1/f4EBM+aRWw+kV5U 15bP4pGMjjqRWprDKtexrB+cfgn65P4EZHAqcZOM1FKDCgIeDfPYmf+KK2DH4X4gpOkt P4ZQ==
[x-gm-message-state:] => AOAM532OnNLanibADLYUF4EoHs1HO9Gn77Ya/AGZfdAtrfTQVgwEhL3C IqkIf2BVyuwD+8WLinEt52oO87hsXFOqWqXBrw==
[x-google-smtp-source:] => ABdhPJw9iope30SZc0J+fYRLzszdKj9yaGNIm3ih4Adm5k3Z19j2dD7lz102HT1EKzMPSpTNasiErNBKgUWEseX/6FYFuyV4OKg=
[dkim-signature:] => v=1; a=rsa-sha256; c=relaxed/relaxed; d=msn.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+7hC1yLv/d47Fm1f/crmWbnmNjpz9dGkU3VT6y9MZ9E=; b=NZT8AF5GtbNOZisehFAVDsgwVALVBqsx0i2lmPlwsACNPE2iZ7skp9ac2FuT5lJLZujQB1Pl1bq42CPyltKYzgNXpyFn/qI/C4l8ydG4j4YZ/BWhNJxLBfbNlpeCL3HWL+EBesDWu2dXihnvRD5zwd8VZS28Muia9PC40f6YqEt00fLy9cZ9N1e4H+UofyoAlqwt+DOM6+lGLmlRO2b6B5xfSV7Dpj/E7wG0t0mUIHowWzxcJTFuzphYuR9XlegCWT4NErNcarhsTuK4n1OeFfqa55rnK91sth2Oi6a3Oareib4RhygVSN3Lx5hXCcowqZZBOxT9zqg1fg1izbLC7A==
[from:] => Tanya Davis
[to:] => "Scams@scamdex.com"
[subject:] => Fwd: Alert
[thread-topic:] => Alert
[thread-index:] => AQHWSZEK5WtKI00whUCWKulvez9X6ajpS0UP
[date:] => Thu, 25 Jun 2020 12:50:28 +0000
[message-id:] =>
[references:] => <08ca7c2f240f252ce0e553ff14604a5f5b3601@xka.be.lss.toppsfootball.co.uk>
[in-reply-to:] => <08ca7c2f240f252ce0e553ff14604a5f5b3601@xka.be.lss.toppsfootball.co.uk>
[accept-language:] => en-US
[content-language:] => en-US
[x-ms-has-attach:] =>
[x-ms-tnef-correlator:] =>
[x-incomingtopheadermarker:] => OriginalChecksum:C9A642925ED1C40C7E2320F84E6ABA0A5D5E5D87C69DFF24ACA9B1E198A0F897;UpperCasedChecksum:0B3CE251FA0C45D8A6235705EE9D44751DC2AC52FE776440DB3F7359D83F043C;SizeAsReceived:6748;Count:44
[x-ms-exchange-messagesentrepresentingtype:] => 1
[x-tmn:] => [NGQeURebDhY24lVjzVhkbBWOt/OzQeik]
[x-ms-publictraffictype:] => Email
[x-incomingheadercount:] => 44
[x-eopattributedmessage:] => 0
[x-ms-office365-filtering-correlation-id:] => 2b2c3bac-a3e1-4191-aec0-08d819065685
[x-ms-traffictypediagnostic:] => MW2NAM12HT208:
[x-microsoft-antispam:] => BCL:0;
[x-microsoft-antispam-message-info:] => 8EuihRmL9AlxsaT2kKHA7V1rlwuJkzhSwBtEsnek0QulhucROrnavjZRk/KNRX3YtVmVlONA5V8BUxq0dQm9JbUF8njRLK1HkyTeTRUFRn0sA1RhkW4itf/Grpw4irz0vXCLXRn0G4NwrOuGmc8Iyk9UwbLKZe5IY+8gRqEejDTAnovEziXp15T/ScfuWWw5/yshoVtL17AkadfduXc9zw==
[x-forefront-antispam-report:] => CIP:255.255.255.255;CTRY:;LANG:en;SCL:0;SRV:;IPV:NLI;SFV:NSPM;H:BN8PR07MB6898.namprd07.prod.outlook.com;PTR:;CAT:NONE;SFTY:;SFS:;DIR:OUT;SFP:1901;
[x-ms-exchange-antispam-messagedata:] => A3wyHTAt/1vLTNzaGipwYFNsxQ1gqDHKrNfUjcSKktvrV46S+csJ06RoQkvZhOG/y8TKlMSxujw7LgJKUNyGZiiRIyQ99NPKB56ENdyNX5iOUXmORVThPPs64p7+SHmyZhAqVvTMlDrXxFFD0tHKwA==
[x-ms-exchange-transport-forked:] => True
[content-type:] => multipart/alternative; boundary="_000_BN8PR07MB6898A790C4BA508B2FBBA70CE1920BN8PR07MB6898namp_"
[mime-version:] => 1.0
[x-originatororg:] => outlook.com
[x-ms-exchange-crosstenant-authas:] => Anonymous
[x-ms-exchange-crosstenant-authsource:] => MW2NAM12FT061.eop-nam12.prod.protection.outlook.com
[x-ms-exchange-crosstenant-rms-persistedconsumerorg:] => Array
(
[0] => 00000000-0000-0000-0000-000000000000
[1] => 00000000-0000-0000-0000-000000000000
)
[x-ms-exchange-crosstenant-network-message-id:] => 2b2c3bac-a3e1-4191-aec0-08d819065685
[x-ms-exchange-crosstenant-originalarrivaltime:] => 25 Jun 2020 12:50:28.4556 (UTC)
[x-ms-exchange-crosstenant-fromentityheader:] => Internet
[x-ms-exchange-crosstenant-id:] => 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
[x-ms-exchange-transport-crosstenantheadersstamped:] => MW2NAM12HT208
[x-getmail-retrieved-from-mailbox:] => =?utf-8?q?=5BGmail=5D/Important?=
[x-gmail-labels:] => =?utf-8?b?IlxcSW5ib3gi?=
[x-gmail-thrid:] => =?utf-8?q?1670475341789779934?=
[x-gmail-msgid:] => =?utf-8?q?1670475341789779934?=
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
-------- Original Message -------- Subject: Alert From: You've been HACKED <lc.usl.ar@xka.be.lss.toppsfootball.co.uk> Sent: Tuesday, June 23, 2020, 3:03 PM To: CC:
Be sure to read this message ! Your personal data is threatened. Exposure - 355 !
-------- Original Message --------
Subject: Alert
From: You've been HACKED <lc.usl.ar@xka.be.lss.toppsfootball.co.uk>
Sent: Tuesday, June 23, 2020, 3:03 PM
To:
CC:
Be sure to read this message ! Your personal data is threatened. Exposure - 355 !
3Hello!7
9I2am3a6hacker2who1has1access5to4your7operating7system.3
3I1also2have9full2access1to4your9account.9
4I4made4a4video7showing3how2you4satisfy4yourself6in4the6left7half7of3the8screen,9
8and1in9the6right4half2you9see3the9video2that9you9watched.3
5With6one8click8of2the5mouse,7I9can6send8this4video2to2
9all9your8emails1and5contacts5on3social5networks.8
1If7you4want6to2prevent6this,3transfer8the2amount7of9$7001to4my9BTC8address.1
6
6You9do7not8know7how7to4buy?5Search2to5Google1:4Buy1BTC8
9My9BTC8address3(BTC5Wallet)5is:4
1Mhbnf6W3DEfeSzNmnFKxZmPbWKNjXjkdA
3After6receiving7the7payment,6I1will6delete5the3video3and5you6will7never3
7hear8me2again.8
3I8give9you5505hours8(more1than623days)4to4pay.
3I2have4a3notice9reading6this4letter,3and7the7timer3will8work6when
2you6see6this4letter.1
7Filing7a2complaint5somewhere2does3not1make1sense7because5this5email1
2cannot6be7tracked6like4my6BTC1address.9
2I8do6not9make6any9mistakes.7
3Bye7!7
1