Information on romance scams and scammers.
#255088 by buried under 419s Mon Jun 08, 2015 4:39 am
Return-path: <>
Envelope-to:
Delivery-date: Sun, 07 Jun 2015 23:11:00 -0700
Received: from 181-163-70-238.baf.movistar.cl ([181.163.70.238]:55774)
by with esmtp (Exim 4.80)
(envelope-from <>)
id 1Z1qGt-0000CK-4v
for ; Sun, 07 Jun 2015 23:11:00 -0700
From: "Valerie" <>
To:
Date: Mon, 08 Jun 2015 02:16:57 -0300
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="MIMEBoundarye99abcc5b1a9daed1003f645f3f8519b"
List-Unsubscribe: <mailto:[email protected]>
Reply-To:
Message-ID: <0280A-63893109-42256108-2015.06.08-02.16.57-@181-163-70-238.baf.movistar.cl>
X-Spam-Status: Yes, score=15.9
X-Spam-Score: 159
X-Spam-Bar: +++++++++++++++
X-Spam-Report: Spam detection software, running on the system "", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.

Content preview: Greetings from the wonderland! How are you doing? IÂ’m Valerie,
and IÂ’m dying to meet you! May I ask your name? I saw you on this website
the other day, and I really wanted to talk to you butI was late – you had
already gone offline. Could we chat tomorrow? IÂ’m sureitÂ’ll be fun. Write
me some time. My email [email protected] mailto:[email protected]
[...]

Content analysis details: (15.9 points, 7.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.5 CK_HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname
(Split IP)
0.0 TVD_RCVD_IP Message was received from an IP address
0.4 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[181.163.70.238 listed in zen.spamhaus.org]
3.3 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?181.163.70.238>]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[181.163.70.238 listed in bl.score.senderscore.com]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.7 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5371]
1.0 RDNS_DYNAMIC Delivered to internal network by host with
dynamic-looking rDNS
2.0 HTML_TITLE_SUBJ_DIFF HTML_TITLE_SUBJ_DIFF
3.6 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr
2)
X-Spam-Flag: YES
Subject: ***SPAM*** hi

This is a multi-part message in MIME format.

--MIMEBoundarye99abcc5b1a9daed1003f645f3f8519b
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Greetings from the wonderland!

How are you doing? I’m Valerie, and I’m dying to meet you! May I ask your name?
I saw you on this website the other day, and I really wanted to talk to you butI was late – you had already gone offline.
Could we chat tomorrow? I’m sureit’ll be fun. Write me some time.
My email [email protected]

Have a great day,
Valeriya

Questions about scams? fraudatiocruor @ gmail.com to contact remove spaces
Advertisement

Who is online

Users browsing this forum: Google [Bot] and 246 guests