Scams re-targeting those who have already been victimized
#216704 by Faizan Docherty Thu Aug 28, 2014 6:01 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 186.35.178.43
Originating ISP: Telmex Servicios Empresariales S.a.
City: Copiapo
Country of Origin: Chile
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.221.18.133 with SMTP id qg5csp252561vcb;
Wed, 27 Aug 2014 16:33:34 -0700 (PDT)
X-Received: by 10.66.141.77 with SMTP id rm13mr214679pab.91.1409182414154;
Wed, 27 Aug 2014 16:33:34 -0700 (PDT)
Return-Path: <[email protected]>
Received: from cebuanas.com (cebuanas.com. [216.240.146.57])
by mx.google.com with ESMTPS id mq9si3260154pdb.91.2014.08.27.16.33.33
for <snipped>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Wed, 27 Aug 2014 16:33:34 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 216.240.146.57 as permitted sender) client-ip=216.240.146.57;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 216.240.146.57 as permitted sender) [email protected];
dkim=neutral (no key for signature) [email protected]
Message-Id: <[email protected]>
DKIM-Signature: <snipped>;
Received: from [186.35.178.43] (port=1644 helo=User)
by cp.cebuanas.com with esmtpsa (TLSv1:AES256-SHA:256)
(Exim 4.77)
(envelope-from <[email protected]>)
id 1XMmib-0003Qc-LE; Wed, 27 Aug 2014 16:33:33 -0700
Reply-To: <[email protected]>
From: "Rickey Tarfa"<[email protected]>
Subject: Reply with phone Numbers for re-confirmation,final release of your funds.
Date: Wed, 27 Aug 2014 19:34:11 -0400
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 140827-0, 27/08/2014), Outbound message
X-Antivirus-Status: Clean
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - cp.cebuanas.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - cebuanas.com
X-Get-Message-Sender-Via: cp.cebuanas.com: authenticated_id: ritchel/only user confirmed/virtual account not confirmed
X-Source:
X-Source-Args:
X-Source-Dir:


Dear Beneficiary,


We at Rickey Tarfa & Associates have been duly consulted by the CBN Board of Trustees and have been fully informed about how the staff of the remitting bank have been taking advantage of you by telling you to pay unnecessarily exorbitant charges which will only make your fund payment a long drawn out process.

Due to this we have decided to step into the process of your fund transfer to enable your funds to be transferred within the soonest possible time you are to get back to us immediately without needing to pay all the huge sums of money that are being demanded from you by the remitting bank.

All process to have your funds paid to you immediately through the CBN's Liaison Remittance Office in New York have been initiated to cut out unnecessarily costs.

Furthermore, you are hereby advised to pay no further fees or charges to the Remitting Bank in Nigeria as they shall no longer be handling your payment process.

We shall await your immediate correspondence with your direct telephone numbers for re-confirmation so that we may conclude your payment immediately.



Yours Sincere
Rickey Tarfa

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: No registered users and 5 guests