Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#249856 by Tim Atem Thu May 07, 2015 3:02 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.203.79.249
Originating ISP: Glomobile Benin Republic
City: n/a
Country of Origin: Benin
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.112.143.231 with SMTP id sh7csp3557099lbb;
Thu, 7 May 2015 08:48:58 -0700 (PDT)
X-Received: by 10.170.166.3 with SMTP id i3mr3939749ykd.104.1431013737841;
Thu, 07 May 2015 08:48:57 -0700 (PDT)
Return-Path: <[email protected]>
Received: from 10ibl21ser04.datacenter.cha.cantv.net (10ibl21ser04.datacenter.cha.cantv.net. [200.11.173.10])
by mx.google.com with ESMTPS id r67si1219715yhp.118.2015.05.07.08.48.52
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Thu, 07 May 2015 08:48:57 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) client-ip=200.11.173.10;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) [email protected]
X-Virus-Scanned: amavisd-new at cantv.net
Received: from webmail-05.datacenter.cha.cantv.net (webmail-05.datacenter.cha.cantv.net [200.11.153.88])
(authenticated bits=0)
by 10ibl21ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with ESMTP id t47Fmpxn020838;
Thu, 7 May 2015 11:18:51 -0430
X-Matched-Lists: []
Received: from 41.203.79.249 ([41.203.79.249]) by webmail-05.datacenter.cha.cantv.net (Cantv Webmail) with HTTP; Thu, 7 May 2015 11:18:49 -0430 (VET)
Date: Thu, 7 May 2015 11:18:49 -0430 (VET)
From: deopie <[email protected]>
Reply-To: [email protected]
To: <snipped>
Message-ID: <1865671880.3954671.1431013731284.JavaMail.gess@webmail-05.datacenter.cha.cantv.net>
Subject: I'm diplomat Jerry Mark
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Mailer: Cantv Webmail
X-Originating-IP: [41.203.79.249]



I'm diplomat Jerry Mark, I have just arrived at the airport with your valued consignment box 30 mins ago, please reconfirm your home address/ direct phone number/ nearest airport /a copy of your picture to me so that I can proceed to your home right away. you can call on
tel: +229-68193843

email : [email protected]

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5
Advertisement

#259050 by Tim Atem Sat Jul 04, 2015 10:57 am
Using the same email address [email protected]

The link in the email has already been reported for fraud and phishing.

from: diplomatic egent <[email protected]>
subject: We have finally finalized the transfer of your total fund of $4.5 million usd

Delivered-To: <snipped>
Received: by 10.112.26.75 with SMTP id j11csp140673lbg;
Fri, 3 Jul 2015 10:23:20 -0700 (PDT)
X-Received: by 10.112.138.199 with SMTP id qs7mr26665574lbb.21.1435944200498;
Fri, 03 Jul 2015 10:23:20 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail-la0-x241.google.com (mail-la0-x241.google.com. [2a00:1450:4010:c03::241])
by mx.google.com with ESMTPS id dp7si7673859lbc.155.2015.07.03.10.23.20
for <<snipped>>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Fri, 03 Jul 2015 10:23:20 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 2a00:1450:4010:c03::241 as permitted sender) client-ip=2a00:1450:4010:c03::241;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 2a00:1450:4010:c03::241 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
Received: by mail-la0-x241.google.com with SMTP id r2so3255113lae.2
for <<snipped>>; Fri, 03 Jul 2015 10:23:20 -0700 (PDT)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.112.72.164 with SMTP id e4mr36648950lbv.113.1435944200421;
Fri, 03 Jul 2015 10:23:20 -0700 (PDT)
Received: by 10.112.149.33 with HTTP; Fri, 3 Jul 2015 10:23:20 -0700 (PDT)
Date: Fri, 3 Jul 2015 18:23:20 +0100
Message-ID: <CAKHCUYZxBYyDbDG3q=LsBhkzOMrDN-gVZUkGhLsG2=Epwoj+9A@mail.gmail.com>
Subject: We have finally finalized the transfer of your total fund of $4.5
million usd
From: diplomatic egent <[email protected]>
To: <snipped>


This is from Internal Revenue Service (IRS) We have finally finalized
the transfer of your total fund of $4.5 million usd and it will be
immediately forwarded to you without any upfront fee because every
needed fee have being deducted on the total fund therefore click the
above online transfer link here, and feel out your banking details for
immediate transfer of your
total fund http://www.id-prom.fr/espace-pro/photos/file/file.html then
lo-gin your current email address and password then there is know need
of any payment because it have been deducted so the only thing you
have to do now is to vew your money online to make sure that is true
and then long your email to see it
click login now to claim your fund without anymore delay.Make sure you
click this http://www.id-prom.fr/espace-pro/photos/file/file.html

Thank you

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5
#259241 by Tim Atem Mon Jul 06, 2015 12:36 pm
And another:


Delivered-To: <snipped>
Received: by 10.112.26.75 with SMTP id j11csp1588113lbg;
Mon, 6 Jul 2015 05:12:24 -0700 (PDT)
X-Received: by 10.112.78.105 with SMTP id a9mr48754354lbx.70.1436184744921;
Mon, 06 Jul 2015 05:12:24 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail-la0-f53.google.com (mail-la0-f53.google.com. [209.85.215.53])
by mx.google.com with ESMTPS id du6si14643908lbc.41.2015.07.06.05.12.24
for <<snipped>>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Mon, 06 Jul 2015 05:12:24 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 209.85.215.53 as permitted sender) client-ip=209.85.215.53;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 209.85.215.53 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
Received: by mail-la0-f53.google.com with SMTP id t12so272laz.2
for <<snipped>>; Mon, 06 Jul 2015 05:12:24 -0700 (PDT)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.112.55.207 with SMTP id u15mr48687014lbp.88.1436184744455;
Mon, 06 Jul 2015 05:12:24 -0700 (PDT)
Received: by 10.112.140.65 with HTTP; Mon, 6 Jul 2015 05:12:24 -0700 (PDT)
Date: Mon, 6 Jul 2015 13:12:24 +0100
Message-ID: <CAKHCUYbRV=yxvAwSsse6hDZzD55HvE0DHDEdUUX6YGgRpHcUxg@mail.gmail.com>
Subject: Dear Sir/Madam,
From: diplomatic egent <[email protected]>
To: <snipped>
Content-Type: text/plain; charset=UTF-8


Dear Sir/Madam,

Thanks for the response to our message,you can view your payment
online by clicking the link below and Login your email account.
Link removed (BW)
Just click on the above link Blue Color and Login accurately to view
your payment online.click here
Link removed (BW)

Thanks
Ms.Lisa Cheng.

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5

Who is online

Users browsing this forum: Google Adsense [Bot], Majestic-12 [Bot] and 194 guests