SPAM : Boulanger.com : Confirmation de votre commande

127 x served & 39 x viewed

Voici le message Brut:

Received: from a27-30.smtp-out.us-west-2.amazonses.com (a27-30.smtp-out.us-west-2.amazonses.com [54.240.27.30])
From: Boulanger.com <no-reply@boulanger-service-client.com>
Subject: Confirmation de votre commande

Tout est redirigé vers teinmsater.com ( Registrar URL: http://www.namecheap.com )

Merci amazon … Misère.

ARNAQUE : Confirmation de commande de la FNAC

129 x served & 31 x viewed

On recoit un email qui redirige sur https://www.fnac.com.annulation-lmd.com , le nom de domaine annulation-lmd.com est en Malaysie. ( Voir ici :http://www.whois-raynette.fr/whois/annulation-lmd.com )
Code source de l’email :

Return-Path: <0100017811151fec-dc1bbafd-b319-4052-bcb7-445671cafe74-000000@amazonses.com>
MIME-Version: 1.0
Subject: Confirmation de votre commande
From: "Fnac" <noreply@fnac-newsletter.com>
Date: Mon, 8 Mar 2021 09:05:00 +0000
Message-ID: <0100017811151fec-dc1bbafd-b319-4052-bcb7-445671cafe74-000000@email.amazonses.com>
X-SES-Outgoing: 2021.03.08-54.240.9.42
Feedback-ID: 1.us-east-1.p1NoGqjN4IXYsvq7gp6mllJ0kMt7wG3BOeOq8sI9/ls=:AmazonSES

Les autres liens visibles dans l’email :
– https://www.appondicide.com/new_fichiers/ (en Malaysie aussi : http://www.whois-raynette.fr/whois/appondicide.com )
– https://banners.wlservices.fr/jump-456

SPAM de nogueramonique.now147.site : mailamomo@gmail.com

En passant

193 x served & 26 x viewed

Source de l’email :

Return-Path: <bounces+15758027-5951-farias=cyber-neurones.org@em1869.nogueramonique.now147.site>
...
Received: from chfztvsd.outbound-mail.sendgrid.net (chfztvsd.outbound-mail.sendgrid.net [192.254.120.109])
...
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nogueramonique.now147.site;
...
Date: Thu, 06 Aug 2020 09:52:42 +0000 (UTC)
From: Noguera Monique <noguera-monique@nogueramonique.now147.site>
Mime-Version: 1.0
Message-ID: <qfAv4sHmQ1OvQLHZ-4ZRSQ@ismtpd0092p1mdw1.sendgrid.net>
Subject: Latest News from Noguera Monique
Reply-To: mailamomo@gmail.com
...

Fishing : Remboursement des impot.gouv.fr

208 x served & 99 x viewed

J’ai recu du fishing pour ce faire passer pour les impôts :

Return-Path: <info@forasmile.org>
Delivered-To: ....
Received: (qmail 96024 invoked by uid 65534); 18 Apr 2020 12:33:28 -0000
Received: from unknown (HELO mxin7.phpnet.org) (10.52.1.13)
  by mails18.phpnet.org with SMTP; 18 Apr 2020 12:33:28 -0000
Received: by mxin7.phpnet.org (Postfix, from userid 1001)
	id 494C6w44Hvz2xGc; Sat, 18 Apr 2020 14:33:28 +0200 (CEST)
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on spamd14.phpnet.org
X-Spam-Level: ***
X-Spam-Status: No, score=3.8 required=5.0 tests=BAYES_50,FROM_EXCESS_BASE64,
	HTML_MESSAGE,INVALID_DATE,MISSING_MIMEOLE,SPF_HELO_NONE,SPF_NONE,
	T_KAM_HTML_FONT_INVALID,URIBL_BLOCKED autolearn=no autolearn_force=no
	version=3.4.2
Received: from cus09-08.cs.nexin.it (cus09-08.cs.nexin.it [194.113.88.208])
	by mxin7.phpnet.org (Postfix) with ESMTPS id 494C6t6w55z2xFw
	for ....; Sat, 18 Apr 2020 14:33:26 +0200 (CEST)
Received: by cus09-08.cs.nexin.it (Postfix, from userid 5078)
	id A55D63C0D7; Sat, 18 Apr 2020 14:32:07 +0200 (CEST)
To: ....
Subject: =?UTF-8?B?W1Byw6lhdmlzXSAtIFJlbWJvdXJzZW1lbnQgTjAwNzg4Nzk1IDA0LzE4LzIwMjAgMDI6MzI6MDcgcG0u?=
X-PHP-Originating-Script: 5078:newsletter.php
Date: Sat, 18 Apr 2020 14:32:07 +0200
From: =?UTF-8?B?SW1wb3RzLmdvdXYuZnI=?= <info@forasmile.org>
Message-ID: <163e1bfa4bc5a6ef187307d3062ba8@www.forasmile.org>
X-Mailer: X-mailer: nlserver, Build 6.1.0.8192
List-Unsubscribe: <mailto:unsubscribe@www.forasmile.org?subject=/wf/unsubscribe*q*upn=ICUNALTOHVYZDRSEWKXPMBQJGF-27OJSNCA0BZPXGIE15LFHYDT34MQRU89V6WKDHCsvjNSlJrp3AVB7OqoFQf0E1YbhaxTtd2Xicn8GK94emyUgZIkMWuwPLRz65-3D>
X-MSMail-Priority: High
Importance: High
Organization: www.forasmile.org
X-mailer: nlserver, Build 6.1.0.8192
Date: 18/04/2020 02:32:07
X-AntiAbuse: This is a solicited email for - www.forasmile.org mailing list.
X-AntiAbuse: Servername - www.forasmile.org
X-OriginalArrivalTime: 16 Nov 2019 13:39:39.0481 (UTC) FILETIME=[7BF24490:01D0E3F2]
MIME-Version: 1.0
Content-Type: multipart/alternative;
	boundary="b1_21e63db75a4b0eae8ad576d4a763d98a"

This is a multi-part message in MIME format.

Le message est :

Notification d’impôts – Remboursement

Après les derniers calculs annuels de l’exercice de votre activité, nous avons déterminé que

vous êtes admissible à recevoir un remboursement d’impôt de 169,73€

Les noms de domaines :

  • cus09-08.cs.nexin.it ( Italie ) 
  • forasmile.org ( chez register.it : Italie ) 
  • L’Url du faux site : remboursement.impots.fr.zunket.com ( chez whoisguard.com : Panama )