Tuesday, April 27, 2010

5th Spam Mail [Subject : P ay Pal Security Notification - Please Read [ref id: XRHEE]]


This is quiet a different email, the Mailer wants me to think like the email is sent from PayPal Security. The mail is actually from different domain "@security-mail.com". Probably if anyone doesn't notice this domain on the sender, Will surely accept this as PayPal Security email, though the mailer did not include any authorized image of PayPal. Let me describe this email. The mail is sent from a website hosted to a French based Hosting site. There were two IP addresses in the email.
                                                                                                                                                                                                                                                                Delivered-To: ***********7@gmail.com Received: by 10.216.185.3 with SMTP id t3cs40544wem;         Mon, 26 Apr 2010 11:51:57 -0700 (PDT) Received: from mr.google.com ([10.143.87.5])         by 10.143.87.5 with SMTP id ************************ (num_hops = 1);         Mon, 26 Apr 2010 11:51:56 -0700 (PDT) Received: by 10.143.87.5 with SMTP id ***************************;         Mon, 26 Apr 2010 11:51:56 -0700 (PDT) X-Forwarded-To: *************@gmail.com X-Forwarded-For: ++++++@gmail.com *************@gmail.com Delivered-To: +++++++gmail.com Received: by 10.142.233.8 with SMTP id f8cs81499wfh;         Mon, 26 Apr 2010 11:51:55 -0700 (PDT) Received: by 10.216.162.149 with SMTP id y21mr2132891wek.196.1272307914507;         Mon, 26 Apr 2010 11:51:54 -0700 (PDT) Return-Path:  Received: from smtp2a.orange.fr (smtp2a.orange.fr [80.12.242.138])         by mx.google.com with ESMTP id p18si5557448wbc.13.2010.04.26.11.51.50;         Mon, 26 Apr 2010 11:51:54 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning gzyqif@security-mail.com does not designate 80.12.242.138 as permitted sender) client-ip=80.12.242.138; Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning gzyqif@security-mail.com does not designate 80.12.242.138 as permitted sender) smtp.mail=gzyqif@security-mail.com Received: from me-wanadoo.net (localhost [127.0.0.1])  by mwinf2a02.orange.fr (SMTP Server) with ESMTP id 95E9480002E9;  Mon, 26 Apr 2010 20:51:50 +0200 (CEST) Received: from me-wanadoo.net (localhost [127.0.0.1])  by mwinf2a02.orange.fr (SMTP Server) with ESMTP id 880B880002E8;  Mon, 26 Apr 2010 20:51:50 +0200 (CEST) Received: from wanadoo.fr (APuteaux-155-1-94-215.w90-35.abo.wanadoo.fr [90.35.77.215])  by mwinf2a02.orange.fr (SMTP Server) with SMTP id 2662880002FC;  Mon, 26 Apr 2010 20:51:48 +0200 (CEST) X-ME-UUID: 20100426185148157.2662880002FC@mwinf2a02.orange.fr Reply-To: gzyqif@security-mail.com From: Support To: ebleich@gmail.com,ebm62980@gmail.com,ebogame@gmail.com,eboku01@gmail.com,ebolax@gmail.com,ebonds22@gmail.com,ebonyblake@gmail.com,ebonyseraphim@gmail.com,ebooks505@gmail.com,eboresow@gmail.com,eborge@gmail.com,ebossche7767@gmail.com,eboucher@gmail.com,eboxgj@gmail.com Subject: P ay Pal Security Notification - Please Read [ref id: XRHEE] Date: Mon, 26 Apr 2010 20:55:22 +0200 MIME-Version: 1.0 Content-Type: multipart/alternative;  boundary="----=_NextPart_000_00C9_01C2A75B.1697F626" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4522.1200 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200 Message-Id: <20100426185148.2662880002fc@mwinf2a02.orange.fr>  This is a multi-part message in MIME format.  ------=_NextPart_000_00C9_01C2A75B.1697F626 Content-Type: text/plain;  charset="Windows-1251" Content-Transfer-Encoding: 7bit  

Dear P ayP al member,

You have a new message concerning your online security.
In order to read it, please login to your account by clicking the link below:

http://www.paypalusa.com.cmd.irolessmass.eu.com/us/webscr/?id=XRHEE

Thank you for your co-operation. ------=_NextPart_000_00C9_01C2A75B.1697F626 Content-Type: text/html; charset="Windows-1251" Content-Transfer-Encoding: 7bit

Dear P ayP al member,

You have a new message concerning your online security.
In order to read it, please login to your account by clicking the link below:

http://www.paypalusa.com.cmd.irolessmass.eu.com/us/webscr/?id=XRHEE

Thank you for your co-operation. ------=_NextPart_000_00C9_01C2A75B.1697F626--
####################################################################################