Amazon Scam – Scammers just do not try anymore!

Forumite Members General Topics Tech Security Talk Amazon Scam – Scammers just do not try anymore!

Viewing 5 posts - 1 through 5 (of 5 total)
  • Author
    Posts
  • #61519
    RSBRSB
    Keymaster
      @bdthree
      Forumite Points: 5,183

      Americans: Over Sexed, Over Payed and Over here, Wat Wat!

      #61523
      Ed PEd P
      Participant
        @edps
        Forumite Points: 39

        I think Amazon  UK may be interested in the existence of an Amaozonservices site. M$ used to have a lot of problems with similar looking sites and leant very heavily on Nominet etc. to take them down and delve down to the actual site owners.

        Of course that may be a totally fictitious name, you would need to look at the full header info to delve into it properly.

        #61525
        RSBRSB
        Keymaster
          @bdthree
          Forumite Points: 5,183

          Return-Path: <bounces+19510-8b11-admin=bdthree.co.uk@sendgrid.net>
          Delivered-To: admin@bdthree.co.uk
          Received: from bh-uk-3.webhostbox.net
          by bh-uk-3.webhostbox.net with LMTP
          id 6MnqEn6XP19i9woAU8+a6Q
          (envelope-from <bounces+19510-8b11-admin=bdthree.co.uk@sendgrid.net>)
          for <admin@bdthree.co.uk>; Fri, 21 Aug 2020 09:44:30 +0000
          Return-Path: <bounces+19510-8b11-admin=bdthree.co.uk@sendgrid.net>
          Envelope-To: admin@bdthree.co.uk
          Delivery-Date: Fri, 21 Aug 2020 09:44:30 +0000
          Received: from xtrwptpb.outbound-mail.sendgrid.net ([167.89.55.59]:7276)
          by bh-uk-3.webhostbox.net with esmtps  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
          (Exim 4.93)
          (envelope-from <bounces+19510-8b11-admin=bdthree.co.uk@sendgrid.net>)
          id 1k93b3-00319Z-PC
          for admin@bdthree.co.uk; Fri, 21 Aug 2020 09:44:30 +0000
          Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sendgrid.info; h=from:subject:mime-version:content-type:content-transfer-encoding:to; s=smtpapi; bh=E9CR+LF8O7safKQAN7MpolgxJFA0z/rEfcxUtqqlBuk=; b=gus/lL4MUlDp/Uo4uLziC7ZfyLdNx5Li/bAeyQDMU9bmWvPRecdNHk+VbBcgf9LKE0Go nW4XOZbei0IE+n1aKD3m5Sapv1IJ7QvGq05qyy/tEtbAZ066AemjoU2I4lRY351h3CHXOi J/Sl3T/HlBISt8PR48FCIHo6AoWqmqi2k=
          Received: by filterdrecv-p3iad2-86945d9569-74njm with SMTP id filterdrecv-p3iad2-86945d9569-74njm-18-5F3F9771-5C
          2020-08-21 09:44:17.997359341 +0000 UTC m=+56477.993667256
          Received: from WIN-MITUP6FMH0V (unknown)
          by ismtpd0101p1mdw1.sendgrid.net (SG) with ESMTP id PcT6egH9TeuDmSulKCH2Og
          for <admin@bdthree.co.uk>; Fri, 21 Aug 2020 09:44:17.895 +0000 (UTC)
          Message-Id: <045d60a7-44064-bb971140935764@win-mitup6fmh0v>
          From: Amaozn.co.uk <no-reply@amaoznservices.co.uk>
          Subject: Important message from Amazon.co.uk
          Date: Fri, 21 Aug 2020 09:44:18 +0000 (UTC) (21/08/20 10:44:18)
          Mime-Version: 1.0
          Content-Type: text/html; charset=us-ascii
          Content-Transfer-Encoding: 7bit
          X-Priority: 3
          X-Sg-Eid:
          nKtpiYG2f2vFLkEIwpHb/PxMUOLsLU8TpmXM7EWWyelvaC2F7Ka+AiCKs81ttxsMr3J27/Isz1Qi2awzXd82pdg+OZ6Q36x2UZOSlMEUkqDYwO35AxqVSQKtfdYj5xo+ObIj1DbQuG11FeKxg50ZAclcdz890SkUmzUYmESiTNa9IQTem6Rp06NgtGgSp2Y5cOQQnz1q7yH/JEJwTgER7paQrmlrKAxTKqB+tRz1R8xm7enno1kwrkBs5EVoHvjcIp6ssxX4QjpqtUx7NNcKZg==
          To: admin@bdthree.co.uk
          X-Spam-Status: No, score=0.4
          X-Spam-Score: 4
          X-Spam-Bar: /
          X-Spam-Flag: NO
          X-Evolution-Source: f973c7290d3e87ba38df5f56b5378652b457995e

          Americans: Over Sexed, Over Payed and Over here, Wat Wat!

          #61530
          JayCeeDeeJayCeeDee
          Participant
            @jayceedee
            Forumite Points: 230

            Info HERE for reporting suspicious emails, phishing attempts etc from a site purporting to be Amazon.

            Send the email to “stop-spoofing@amazon.com”.

            Well spotted!!

            #61535
            Ed PEd P
            Participant
              @edps
              Forumite Points: 39

              They need the mail header as part of the report.  Easiest way is normally to forward the email but make sure you are using a setting that allows the mail header to be seen otherwise it may get stripped. (view headers all in TBird)

            Viewing 5 posts - 1 through 5 (of 5 total)
            • You must be logged in to reply to this topic.