Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#261246 by Tim Atem Thu Jul 23, 2015 10:26 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.138.172.61
Originating ISP: Visafone Communications Limited
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.112.26.75 with SMTP id j11csp225012lbg;
Wed, 22 Jul 2015 16:28:51 -0700 (PDT)
X-Received: by 10.170.225.213 with SMTP id r204mr2527919ykf.24.1437607731364;
Wed, 22 Jul 2015 16:28:51 -0700 (PDT)
Return-Path: <[email protected]>
Received: from dispartes.com (mail.dispartes.com. [181.48.157.70])
by mx.google.com with ESMTP id n66si2116308ywf.154.2015.07.22.16.28.50
for <<snipped>>;
Wed, 22 Jul 2015 16:28:51 -0700 (PDT)
Received-SPF: neutral (google.com: 181.48.157.70 is neither permitted nor denied by domain of [email protected]) client-ip=181.48.157.70;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 181.48.157.70 is neither permitted nor denied by domain of [email protected]) [email protected]
Received: from localhost (localhost.localdomain [127.0.0.1])
by dispartes.com (Postfix) with ESMTP id 260E01ECD86
for <<snipped>>; Wed, 22 Jul 2015 18:28:49 -0500 (COT)
X-Virus-Scanned: amavisd-new at dispartes.com
Received: from dispartes.com ([127.0.0.1])
by localhost (dispartes.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id kexMv12NEJFg for <<snipped>>;
Wed, 22 Jul 2015 18:28:49 -0500 (COT)
Received: from User (unknown [41.138.172.61])
by dispartes.com (Postfix) with ESMTPA id C78751ECDB8
for <<snipped>>; Wed, 22 Jul 2015 18:28:45 -0500 (COT)
From: "Roy BREALEY" <[email protected]>
Subject: Distribution notice
To: <snipped>
Content-Type: multipart/alternative; boundary="PWOLRWqMwJjMxdYSeGlxMezywcM=_bRmlR0"
MIME-Version: 1.0
Reply-To: [email protected]
Date: Wed, 22 Jul 2015 23:28:41 +0000
Message-Id: <[email protected]>


Greetings, As a dedicated Christian and philanthropist, I am emailing you because I wish to donate towards charitable programs; such that care for the Poor, Victims, Sick and Disabled. I plan to donate US$3.5 Million for this purpose if only you can distribute it appropriately. I sincerely would appreciate a response at your convenience and bear in mind that 15% of the total amount is for your services.

Regards,
Dr. Roy Brealey
Retired Medical Doctor
Aberdeen, Scotland |
[email protected]
[email protected]

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5
Advertisement

#265364 by Tim Atem Thu Aug 27, 2015 1:39 pm
Using the same reply-to email address [email protected]

ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.138.190.252
Originating ISP: Visafone
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.112.170.227 with SMTP id ap3csp4435836lbc;
Thu, 27 Aug 2015 09:48:30 -0700 (PDT)
X-Received: by 10.68.57.203 with SMTP id k11mr8562125pbq.8.1440694109671;
Thu, 27 Aug 2015 09:48:29 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail.121arabia.com ([66.226.76.42])
by mx.google.com with ESMTPS id hq10si4641615pac.214.2015.08.27.09.48.27
for <<snipped>>
(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
Thu, 27 Aug 2015 09:48:29 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 66.226.76.42 as permitted sender) client-ip=66.226.76.42;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 66.226.76.42 as permitted sender) [email protected]
Return-Path: <[email protected]>
Received: from ([41.138.190.252])
by mail.121arabia.com (mail.121arabia.com) with ASMTP id 201508272048342520
for <<snipped>>; Thu, 27 Aug 2015 20:48:34 +0400
From: "Otary Express Courier" <[email protected]>
Subject: HIGHLY CONFIDENTIAL
To: <snipped>
Content-Type: multipart/alternative; boundary="OUIj9SVMqlfYDUetBtGPZOuOPGS=_DUnhZ0"
MIME-Version: 1.0
Reply-To: [email protected]
Date: Thu, 27 Aug 2015 16:48:16 +0000
Message-ID: <[email protected]>
X-Antivirus: avast! (VPS 150827-0, 08/27/2015), Outbound message
X-Antivirus-Status: Clean


Greetings, As the vault manager of Otary Express Courier, there are many unclaimed boxes belonging to deceased depositor's which is difficult to locate their next of kin. Your confidential assistance is highly needed to dispatch the box containing two million euros, which i cannot handle alone considering the high number of security watch in this vault, i await your reply only at my private email for more briefing.

Mr. MARUTYAN ARMEN
GYULIQEKHVYAN STR., APT. 7, 0076 YEREVAN, ARMENIA
Phone number: +374 55 171 474
Private email: [email protected]

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5

Who is online

Users browsing this forum: No registered users and 247 guests