#232415 by Jack Fendly Mon Dec 29, 2014 12:28 pm
X-Apparently-To:
Return-Path: <[email protected]>
X-YahooFilteredBulk: 209.85.160.170
Received-SPF: softfail (transitioning domain of fucsalud.edu.co does not designate 209.85.160.170 as permitted sender)
X-YMailISG:
X-Originating-IP: [209.85.160.170]
Authentication-Results: mta1342.mail.bf1.yahoo.com from=fucsalud.edu.co; domainkeys=neutral (no sig); from=fucsalud.edu.co; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO mail-yk0-f170.google.com) (209.85.160.170) by mta1342.mail.bf1.yahoo.com with SMTPS; Mon, 29 Dec 2014 05:49:08 +0000
Received:
X-Google-DKIM-Signature:
X-Gm-Message-State:
MIME-Version: 1.0
X-Received: by 10.170.147.130 with SMTP id o124mr31051088ykc.101.1419832147809; Sun, 28 Dec 2014 21:49:07 -0800 (PST)
Received: by 10.170.44.19 with HTTP; Sun, 28 Dec 2014 21:49:07 -0800 (PST)
Reply-To: [email protected]
Date: Mon, 29 Dec 2014 12:49:07 +0700
Message-ID: <CAGaBb60kHGFg-5VZX41KcjoE4kee8Gcyesze_iUaYxVu=MVE+g@mail.gmail.com>
Subject: Inquiry on Your Products
From: THAI NURSERY AND SCAPE CO LTD <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=001a1139239acfba87050b546e9a
Bcc:
Content-Length: 2825


Good day,

We are interested in your Goods displayed on the Trade site and we want to purchase some of the products on trade site for our ref. Do send us more information about your company and your best price. Kindly send to our company purchase email address: [email protected]

Best Regards
M/s denov
Purchase Manager.

THAI NURSERY AND SCAPE CO LTD
179/48-49, soi 15 NawongPrachattana, Sigan
Donmuang, Bkk -Thailand
Phone +66-7031979246
Email: [email protected]

You cannot win a lottery you haven't entered

Please DO NOT tell a scammer you found their details posted here
Advertisement

#232981 by Faizan Docherty Sun Jan 04, 2015 11:18 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 190.38.217.119
Originating ISP: Cantv Servicios, Venezuela
City: Barcelona
Country of Origin: Venezuela
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.25.211.135 with SMTP id k129csp3350762lfg;
Sun, 4 Jan 2015 01:03:18 -0800 (PST)
X-Received: by 10.170.173.78 with SMTP id p75mr61862780ykd.66.1420362197597;
Sun, 04 Jan 2015 01:03:17 -0800 (PST)
Return-Path: <[email protected]>
Received: from 10ibl21ser04.datacenter.cha.cantv.net (10ibl21ser04.datacenter.cha.cantv.net. [200.11.173.10])
by mx.google.com with ESMTPS id c185si19581145yka.176.2015.01.04.01.03.14
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Sun, 04 Jan 2015 01:03:17 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) client-ip=200.11.173.10;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) [email protected]
X-Virus-Scanned: amavisd-new at cantv.net
Received: from srvtmg1602.cobeca.com.ve (dbe26d977.dslam-172-17-96-245-383-0433-anz-04.dsl.cantv.net [190.38.217.119] (may be forged))
(authenticated bits=0)
by 10ibl21ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with ESMTP id t0492ZhJ022093;
Sun, 4 Jan 2015 04:33:04 -0430
Message-Id: <201501040903.t0492ZhJ022093@10ibl21ser04.datacenter.cha.cantv.net>
X-Matched-Lists: []
Content-Type: multipart/alternative; boundary="===============1378370138=="
MIME-Version: 1.0
Subject: Export Business.
To: Recipients <[email protected]>
From: Anukur Peter <[email protected]>
Date: Sun, 04 Jan 2015 04:33:02 -0530
Reply-To: [email protected]


Dear Sir/Ma I represent the interest of government officials from South Sudan. We are in need of a foreign associate with capability to supply large number of agricultural machines (tractors, etc.) of durable quality. Please, contact me for details if you are able to handle such export business. Anukur Peter.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#233016 by Faizan Docherty Sun Jan 04, 2015 8:57 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.58.212.214
Originating ISP: Swiftng
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


From sanjai san Sun Jan 4 22:38:37 2015
X-Apparently-To: <snipped>; Sun, 04 Jan 2015 22:39:48 +0000
Return-Path: <[email protected]>
Received-SPF: pass (domain of gmail.com designates 74.125.82.67 as permitted sender)
<snipped>
X-YMailISG: <snipped>
X-Originating-IP: [74.125.82.67]
Authentication-Results: mta1671.mail.gq1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO mail-wg0-f67.google.com) (74.125.82.67)
by mta1671.mail.gq1.yahoo.com with SMTPS; Sun, 04 Jan 2015 22:39:41 +0000
Received: by mail-wg0-f67.google.com with SMTP id k14so3243987wgh.2;
Sun, 04 Jan 2015 14:39:38 -0800 (PST)
DKIM-Signature: <snipped>
X-Received: by 10.194.201.137 with SMTP id ka9mr177070278wjc.66.1420411178882;
Sun, 04 Jan 2015 14:39:38 -0800 (PST)
Return-Path: <[email protected]>
Received: from DSCENTCUZ-PC.www.huaweimobilewifi.com ([41.58.212.214])
by mx.google.com with ESMTPSA id n8sm73158877wjx.0.2015.01.04.14.38.42
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Sun, 04 Jan 2015 14:39:36 -0800 (PST)
Message-ID: <[email protected]>
Content-Type: multipart/mixed; boundary="===============0428777487=="
MIME-Version: 1.0
Subject: NEW ORDER
To: Recipients <[email protected]>
From: sanjai sani<[email protected]>
Date: Sun, 04 Jan 2015 23:38:37 +0100
Content-Length: 259685


Good day,

I would like to place our new order # HZD-18, as follows:

7018 Flux : 10 metric tons

Kindly send us PI asap so we can T/T partial payment to you.

Thank you.

Best regards,
procurement manager
Director, Doha trading Centre.
P.O.BOX:19683,
Doha, Qatar.
Mob:+974:55548151
Fax: 456738423

Sent from my iPhone

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#233264 by Faizan Docherty Tue Jan 06, 2015 6:55 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.82.141.237
Originating ISP: Clients-adsl
City: Dakar
Country of Origin: Senegal
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.25.211.135 with SMTP id k129csp3994148lfg;
Tue, 6 Jan 2015 12:48:19 -0800 (PST)
X-Received: by 10.194.184.171 with SMTP id ev11mr191771998wjc.119.1420577299281;
Tue, 06 Jan 2015 12:48:19 -0800 (PST)
Return-Path: <Zhejiang>
Received: from qubeemail.com.bd (mail.qubeemail.com.bd. [180.234.0.202])
by mx.google.com with ESMTP id e9si26861540wiv.77.2015.01.06.12.48.17
for <snipped>;
Tue, 06 Jan 2015 12:48:19 -0800 (PST)
Received-SPF: temperror (google.com: error in processing during lookup of Zhejiang: DNS timeout) client-ip=180.234.0.202;
Authentication-Results: mx.google.com;
spf=temperror (google.com: error in processing during lookup of Zhejiang: DNS timeout) smtp.mail=Zhejiang
Message-Id: <54ac4a13.a948b40a.7cd4.ffff95b0SMTPIN_ADDED_MISSING@mx.google.com>
Received: (qmail 20080 invoked by uid 89); 7 Jan 2015 00:51:24 +0600
Received: by simscan 1.4.0 ppid: 18723, pid: 20064, t: 0.4514s
scanners: attach: 1.4.0 clamav: 0.97.2/m:53/d:13356
Received: from unknown (HELO ?192.168.1.36?) ([email protected]@41.82.141.237)
by qubeemail.com.bd with ESMTPA; 7 Jan 2015 00:51:24 +0600
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Subject: INQUIRY
To: Recipients <Zhejiang>
From: Zhejiang Trade & Industry Co, Ltd
Date: Tue, 06 Jan 2015 18:36:29 +0000
Reply-To: [email protected]


Dear Sir/Madam,

This is Mrs Jacqueline Augustin, from Zhejiang Trade & Industry Co, Ltd, one of our costumers refer us to your product, we have seen your product sample and we have concluded to place a large order on your product.We require that you please send us quotations, pricing and also you company certificate for final approval.

Please kindly send me your latest catalog. Also, inform me about the Minimum Order Quantity, Delivery time or FOB, and payment terms warranty.Please contact us .via: [email protected].

Looking forward to you early reply
Best Regards
Mrs Jacqueline Augustin
Executive Manager
Zhejiang Trade & Industry Co, Ltd
1098 Harrison Street San Francisco, CA, 94103 USA
Tel: +1 (240) 621-0239 Fax:+ 1- (206)-203-054.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#237830 by Faizan Docherty Sat Feb 14, 2015 11:17 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 141.105.71.151
Originating ISP: Mir Telematiki Ltd
City: n/a
Country of Origin: Russian Federation
* For a complete report on this email header goto ipTRACKERonline


From "Mirghani Isam" Fri Feb 13 18:30:38 2015
X-Apparently-To: <snipped>; Fri, 13 Feb 2015 18:30:50 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 222.177.15.13
Received-SPF: none (domain of cq.stats.cn does not designate permitted sender hosts)
X-YMailISG: <snipped>
X-Originating-IP: [222.177.15.13]
Authentication-Results: mta1532.mail.bf1.yahoo.com from=cq.stats.cn; domainkeys=neutral (no sig); from=cq.stats.cn; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO CQ-EXEDGE-01.cq.stats.cn) (222.177.15.13)
by mta1532.mail.bf1.yahoo.com with SMTPS; Fri, 13 Feb 2015 18:30:47 +0000
Received: from CQ-EXHC-01.cq.stats.cn (10.50.99.53) by
CQ-EXEDGE-01.cq.stats.cn (10.50.98.30) with Microsoft SMTP Server (TLS) id
8.1.375.2; Sat, 14 Feb 2015 02:27:20 +0800
Received: from User (141.105.71.151) by CQ-EXHC-01.cq.stats.cn (10.50.99.53)
with Microsoft SMTP Server id 8.1.375.2; Sat, 14 Feb 2015 02:30:19 +0800
Reply-To: <[email protected]>
From: "Mirghani Isam" <[email protected]>
Subject: SEEKING FOR YOUR PRODUCTS!!
Date: Fri, 13 Feb 2015 22:30:38 +0400
MIME-Version: 1.0
Content-Type: text/html; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-ID: <[email protected]>
To: Undisclosed recipients:;
Return-Path: [email protected]
Content-Length: 5004


Dear Sir,

I am pleased to receive your email address & company details through my search of direct and reliable Manufacturers/ Distributors Agents.

However, my name is Mirghani Abdelrahim Isameldin,im a citizen of Republic of Sudan, a medical practitioner working with United Nations, I am stationed in Republic of Benin and Rep. Togo, covering the two countries at the moment. My primary aim of communicating with you has two objectives, firstly, I need your PRODUCTS, Im newly appointed for a contract worth of Millions of Dollars, I will not mention the amount here for security reasons. This contract was awarded by UN to Supply foods products like, Rice, Sugar, Canned Sardine/Beef, Frozen Chicken/Fish, Milk powder, Veg Oil,Soap,Detergent, Pharmaceutical Products and material products, like Cloth both new and secondhand, Etc; to Refugee Camps in nine countries in West African Region for 3 & half years.

I need a genuine established reputable Company that I can engage into constant and steady purchase of those products listed above in a very large quantity.

Terms and conditions of payment: We agree to release 70% upfront after signing of the purchase contract agreement. Supplier Must Be At Present In The Credit General Office In Lome Togo West Africa To Sign The Purchase Contract Agreement For Three And Half Years Constant Shipment. After signing agreement, Credit General Officials we take both of us to bank for the transferring of 70% to your nominated bank account. After that you will return back to your country to start the shipment. Partial shipment is allowed.

Right now I would like to know the type of products you have in stock. Mention the products names, quantity you can supply monthly, gives us price quotations in C&F Cotonou Sea port, Port of Kpeme Lome and Port of Sudan Green Harbour.

Be informed that face to face meeting for signing of the contract in Credit General Office in Lome Togo is inevitable/ unavoidable to avoid Fraud and the transfer of 70% will be done via T/T Wire Transfer in your present immediately we conclude the contract agreement endorsement.
CONDITIONAL OPTION
In case you were not able to fly down due to maybe your condition of health or business engagement tied up, we can consider signing the contract with you but in one condition of payment. You will receive 70%TT upon Scan copy of Bill of Lading, and balance 30% after we received original BL in Credit General.

Contact me with your full name, Company name, address, direct Telephone number and Mobile if you can handle the contract.

Waiting for your urgent communication.
Best regards
Dr. Mirghani Abdelrahim Isameldin
Email: [email protected]
Direct Tel. where i can be reached any moment
00229 67252137
Add my skype for us to have a video conversation
Skype ID: mirghani.isameldin

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#238292 by Faizan Docherty Wed Feb 18, 2015 5:32 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 209.85.217.195
Originating ISP: Google
City: Mountain View
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


From SRI SRITHA Wed Feb 18 14:29:49 2015
X-Apparently-To: <snipped>; Wed, 18 Feb 2015 14:29:52 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 209.85.217.195
Received-SPF: pass (domain of gmail.com designates 209.85.217.195 as permitted sender)
X-YMailISG: <snipped>
X-Originating-IP: [209.85.217.195]
Authentication-Results: mta1648.mail.gq1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO mail-lb0-f195.google.com) (209.85.217.195)
by mta1648.mail.gq1.yahoo.com with SMTPS; Wed, 18 Feb 2015 14:29:52 +0000
Received: by lbdu10 with SMTP id u10so303464lbd.2
for <snipped>; Wed, 18 Feb 2015 06:29:50 -0800 (PST)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.152.29.66 with SMTP id i2mr34261593lah.64.1424269790133;
Wed, 18 Feb 2015 06:29:50 -0800 (PST)
Sender: [email protected]
Received: by 10.112.32.69 with HTTP; Wed, 18 Feb 2015 06:29:49 -0800 (PST)
Date: Wed, 18 Feb 2015 15:29:49 +0100
X-Google-Sender-Auth: b_BaTENHgA-fmrR030hkXazeToo
Message-ID: <CAPA1w4viOB0gRsnTPWXjJpKWLwM4fMMKywO9M=+X1BufUosRcg@mail.gmail.com>
Subject: INQUIRY FOR PRICE QUOTATION.
From: SRI SRITHA <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=089e0160bac0e7d5f4050f5da6e6
Bcc: <snipped>
Content-Length: 4310


Dear Sir,

Greetings!

This is Hakan Bahceci from Hakan Agro DMCC, Dubai, UAE. I got your contact through online. We are based in the United Arab Emirates. Our main office and warehouses are based here in Dubai, U A E.

We are looking forward to buy some products from your company.


Please quote your best CIF Price – Dubai, UAE with the following…
· Data Specification.
· Trade terms: CIF - DUBAI.
· Packing details
· Payment terms.
· Delivery period.
· Need samples

We look forward to your most favorable and immediate reply.



Best Regards,
Mr. Hakan Bahceci
CEO



Head Office:
Hakan Agro DMCC
34th Floor, Mazaya Business Avenue, BB2 Tower
Jumeirah Lakes Towers,
Sheikh Zayed Road, P.O. Box 31489
Dubai, United Arab Emirates

Email: [email protected]

Website; http://www.hakanfoods.com

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#238321 by Faizan Docherty Wed Feb 18, 2015 8:34 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.60
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


From Binish Naz Thu Feb 19 00:25:56 2015
X-Apparently-To: <snipped>; Thu, 19 Feb 2015 00:26:05 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 65.54.190.12
Received-SPF: pass (domain of outlook.com designates 65.54.190.12 as permitted sender)
X-YMailISG: <snipped>
X-Originating-IP: [65.54.190.12]
Authentication-Results: mta1246.mail.bf1.yahoo.com from=outlook.com; domainkeys=neutral (no sig); from=outlook.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO BAY004-OMC1S1.hotmail.com) (65.54.190.12)
by mta1246.mail.bf1.yahoo.com with SMTPS; Thu, 19 Feb 2015 00:26:03 +0000
Received: from BAY181-W38 ([65.54.190.60]) by BAY004-OMC1S1.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Wed, 18 Feb 2015 16:25:56 -0800
X-TMN: [zhx6DfloKV/5jpJnYdB8BOD/BVRdtg+L]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
Content-Type: multipart/alternative;
boundary="_69ac8140-ca55-407d-90a8-0f0ba6978adf_"
From: Binish Naz <[email protected]>
To: Binish Naz <[email protected]>
Subject: About your product
Date: Thu, 19 Feb 2015 00:25:56 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 19 Feb 2015 00:25:56.0986 (UTC) FILETIME=[A10075A0:01D04BDA]
Content-Length: 1200


Dear Sir

We will like to buy your products. do you ship to Poland?
Upon your response we will provide you our order along with our company details.

Binish Naz
CEO
Alta Poland

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#239995 by Jack Fendly Tue Mar 03, 2015 4:19 pm
From Scott & Sons SHOP LTD Tue Mar 3 13:29:38 2015
X-Apparently-To:
Return-Path: <[email protected]>
X-YahooFilteredBulk: 54.251.43.231
Received-SPF: none (domain of ip-10-138-14-104.ap-southeast-1.compute.internal does not designate permitted sender hosts)
X-YMailISG:
X-Originating-IP: [54.251.43.231]
Authentication-Results: mta1598.mail.gq1.yahoo.com from=gmail.com; domainkeys=neutral (no sig); from=gmail.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO ip-10-138-14-104.ap-southeast-1.compute.internal) (54.251.43.231)
by mta1598.mail.gq1.yahoo.com with SMTP; Tue, 03 Mar 2015 14:31:02 +0000
Received: by ip-10-138-14-104.ap-southeast-1.compute.internal (Postfix, from userid 33)
id 3292B117D07; Tue, 3 Mar 2015 13:29:38 +0000 (UTC)
To:
Subject: QUOTATION
X-PHP-Originating-Script: 33:mail.php
From: Scott & Sons SHOP LTD <[email protected]>
Reply-To: [email protected]
Message-Id: <[email protected]>
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Date: Tue, 3 Mar 2015 13:29:38 +0000 (UTC)
Content-Length: 760


Hello My name is SCOTT. I'm the General Manager of S & B SHOP LTD. We are certainly willing to make some purchase of some items in your company or store but before we proceed answer the question below. 1. Do you have POS machine to charge credit card? 2.Do you accept master and visa credit card payment? 3. Do you accept private pick up by our forwarder? 4. Can you send me your website to view your products? 5. Can you send me your wholesale price sheet if possible? Kindly email me if this is possible to ship to us without any problem. I will await your reply Asap Thank you SCOTT ORLOVSKY Scott & Sons SHOP LTD 113 Edison Plaza Avenida Ricardo J. Alfaro Apartado 0815-01119 Zona 4 Panama Tel::(925) 310 5613 Fax::(925) 234 5030

You cannot win a lottery you haven't entered

Please DO NOT tell a scammer you found their details posted here
#240105 by AlanJones Wed Mar 04, 2015 7:26 am
From: Clara Liem - [email protected]

Greetings,

I have visited your website and i'm interested in buying XXX. Before i proceed, i would like to know if you could provide me that item and do you accept international customers and able to ship overseas ? It would be shipped to my billing address. Is it possible for me to place order by email ?

Also, i would like to know if i can use my credit card as payment. Do you have a card machine to entry my credit card manually or Mail Order Phone Order merchant that has entry method manually for an offline charge and without my presence?

Please add my email in your address book to avoid my email goes to your spam or bulk folder.

Thank you and look forward to receive your prompt reply.

Sincerely,
Clara Liem


Hello,

Thanks for your info. Here is my order :

XXX

Total incuding FedEx Int Priority : XXX

Here is my credit card details :

- Type of credit card : MasterCard
- Credit card number : XXX
- Cardholder’s name : CLARA LIEM
- Expiration date : XXX
- CVV : XXX

ADDRESS (Shipping and Billing):
Name : Clara Liem
Company : CV.CLM WAE
Address : MAC-CRG(PITU8), 115 Airport CRG Road #02-30
CRG Agent, Building C
Singapore 819466

Please charge my card above and let me know if you have successfully charged it
and keep inform me regarding my order progress.
We should be grateful for your prompt delivery as the goods urgently needed.
Thanks for your time and waiting for your next information.

Sincerely,
Clara Liem

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#240514 by Faizan Docherty Sat Mar 07, 2015 11:14 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.102
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.23.65 with SMTP id k1csp1134362pdf;
Thu, 5 Mar 2015 23:50:00 -0800 (PST)
X-Received: by 10.68.102.194 with SMTP id fq2mr22578581pbb.99.1425628200165;
Thu, 05 Mar 2015 23:50:00 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (si-002-i152.relay.mailchannels.net. [108.178.49.164])
by mx.google.com with ESMTP id e12si13182024pat.195.2015.03.05.23.49.58
for <snipped>;
Thu, 05 Mar 2015 23:50:00 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 108.178.49.164 as permitted sender) client-ip=108.178.49.164;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 108.178.49.164 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=outlook.com
X-Sender-Id: _forwarded-from|65.54.190.125
Received: from r8-chicago.webserversystems.com (ip-10-220-9-73.us-west-2.compute.internal [10.220.9.73])
by relay.mailchannels.net (Postfix) with ESMTPA id 4729D42E1
for <snipped>; Fri, 6 Mar 2015 07:49:58 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.54.190.125
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.224.7.213])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.8 );
Fri, 06 Mar 2015 07:49:58 +0000
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.54.190.125
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1425628198454:2394177611
X-MC-Ingress-Time: 1425628198454
Received: from bay004-omc2s27.hotmail.com ([65.54.190.102]:58951)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YTn1A-000E9r-Oh
for <snipped>; Fri, 06 Mar 2015 01:49:57 -0600
Received: from BAY169-W84 ([65.54.190.125]) by BAY004-OMC2S27.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Thu, 5 Mar 2015 23:49:56 -0800
X-TMN: [UPsuBTTovLLCkH83c2HJEJoa1cE0wq1D]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_fd8cef26-6ac3-4bf8-806d-48e99d2840b3_"
From: owusu james <[email protected]>
Date: Fri, 6 Mar 2015 07:49:55 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 06 Mar 2015 07:49:56.0081 (UTC) FILETIME=[23560610:01D057E2]
X-Spam-Status: Yes, score=9.3
X-Spam-Score: 93
X-Spam-Bar: +++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Dear Sir/Madam, An open Tender for the supply of your products
to the Government of Ghana.Urgently furnish us in full details about the
standard of your product for the ongoing rehabilitation project.We will appreciate
it more if you can give us with detail specification/price lists to avoid
making a wrong choice of product. [...]

Content analysis details: (9.3 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(owusuj500[at]outlook.com)
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.54.190.102 listed in list.dnswl.org]
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (owusuj500[at]outlook.com)
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
1.6 MALFORMED_FREEMAIL Bad headers on message from free email service
1.0 FREEMAIL_REPLY From and body contain different freemails
X-Spam-Flag: YES
Subject: ***SPAM*** INQUIRY FOR SUPPLY
X-AuthUser:


Dear Sir/Madam,

An open Tender for the supply of your products to the Government of
Ghana.Urgently furnish us in full details about the standard of your
product for the ongoing rehabilitation project.We will appreciate it more
if you can give us with detail specification/price lists to avoid making a
wrong choice of product.

Terms of Payment: An upfront payment of 70% (T/T) will be made to your
account for production, while 30% will be paid before shipment.

Regards,
Mr.Mark Alfred
E-mail: to our office [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#241514 by AlanJones Sat Mar 14, 2015 4:30 am
From: Mr. Karim Abdul - [email protected]
Tel. No.: +60102149434

Dear Manufacturer
I will like to place an urgent order in your company, on behalf of my
company if I am contacting the right source, please get back to me so we
can talk on our exact need.

Mr. Karim Abdul

Purchase Manager
Agro Mega Co. Ltd.
Tel: +60102149434
[email protected]

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#241721 by Faizan Docherty Sun Mar 15, 2015 7:49 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.15
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.23.65 with SMTP id k1csp1140752pdf;
Fri, 13 Mar 2015 14:18:25 -0700 (PDT)
X-Received: by 10.66.141.231 with SMTP id rr7mr102551104pab.72.1426281505009;
Fri, 13 Mar 2015 14:18:25 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (ftx-008-i895.relay.mailchannels.net. [50.61.143.195])
by mx.google.com with ESMTP id j5si6188945pde.17.2015.03.13.14.18.23
for <snipped>;
Fri, 13 Mar 2015 14:18:24 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 50.61.143.195 as permitted sender) client-ip=50.61.143.195;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 50.61.143.195 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=outlook.com
X-Sender-Id: _forwarded-from|65.54.190.60
Received: from r8-chicago.webserversystems.com (ip-10-33-12-218.us-west-2.compute.internal [10.33.12.218])
by relay.mailchannels.net (Postfix) with ESMTPA id 8E79EA0622
for <snipped>; Fri, 13 Mar 2015 21:18:21 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.54.190.60
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.83.15.107])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.8 );
Fri, 13 Mar 2015 21:18:21 +0000
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.54.190.60
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1426281501742:2501597480
X-MC-Ingress-Time: 1426281501741
Received: from bay004-omc1s4.hotmail.com ([65.54.190.15]:52576)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YWWyK-000174-3I
for <snipped>; Fri, 13 Mar 2015 16:18:20 -0500
Received: from BAY182-W77 ([65.54.190.60]) by BAY004-OMC1S4.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Fri, 13 Mar 2015 14:18:19 -0700
X-TMN: [2iuLc1GCTZQBbLrLCVC8lzZmcTYduh46]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_66f0eceb-ad99-42e5-87f3-98ba31ca70ad_"
From: "Rev. Henry Okoroafor" <[email protected]>
Date: Fri, 13 Mar 2015 21:18:19 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 13 Mar 2015 21:18:19.0490 (UTC) FILETIME=[3A832420:01D05DD3]
X-Spam-Status: Yes, score=5.7
X-Spam-Score: 57
X-Spam-Bar: +++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Attention Sir/Madam I got your company information through
a search in the internet. I am an authorized agent registered with the ECOWAS
contract and procurement board of Nigeria, as a sourcing agent for sundry
products. I search for companies to bid for supply contracts on commission
basis. [...]

Content analysis details: (5.7 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.54.190.15 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(agency-gh77[at]outlook.com)
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (agency-gh77[at]outlook.com)
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
2.4 MALFORMED_FREEMAIL Bad headers on message from free email service
X-Spam-Flag: YES
Subject: ***SPAM*** SUPPLY
X-AuthUser:


Attention Sir/Madam

I got your company information through a search in the internet. I am an authorized agent registered with the ECOWAS contract and procurement board of Nigeria, as a sourcing agent for sundry products. I search for companies to bid for supply contracts on commission basis.

Could you please be kind enough to furnish me with the following information to enable me present/introduce your highly esteemed company to the Tender committee for approval.

1) Your price list in CIF
2) The Technical details of your products
3) Your company profile

Please reply to my proposal and we shall deploy all resources in our
disposal to ensure a successful bidding for your company We are looking
forward to working with you.


Best regards,
Re.Henry Okoroafor
CEO A. I. Karim BizConsult Ltd
No. 174 Alhaji Abubakar Mamoud Way
P.O. Box 1015,Aba-Nigeria

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#241941 by AlanJones Tue Mar 17, 2015 1:02 am
From: American International Group, Inc. - [email protected]
Reply-to: [email protected]
Tel. No.: +6569087700

Dear friend,

We are interested in purchasing your product,
Kindly reply us with your company business terms and conditions so that we can place a trial order ASAP

Waiting for your timely reply
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
Best Regards

Mr Mike Snow
Purchasing Manager
American International Group, Inc.
11 North Buona Vista Drive,
Unit #08-09
Singapore 138589
T +65 6908 7700

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#242154 by Faizan Docherty Wed Mar 18, 2015 10:14 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.220.69.192
Originating ISP: Mtn Nigeria Communication Limited
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


X-Apparently-To: <snipped>; Wed, 18 Mar 2015 11:46:14 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 119.235.30.131
Received-SPF: pass (domain of tirtamahakam.com designates 119.235.30.131 as permitted sender)
X-YMailISG: <snipped>
X-Originating-IP: [119.235.30.131]
Authentication-Results: mta1474.mail.bf1.yahoo.com from=; domainkeys=neutral (no sig); from=tirtamahakam.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO server1.tirtamahakam.com) (119.235.30.131)
by mta1474.mail.bf1.yahoo.com with SMTP; Wed, 18 Mar 2015 11:46:13 +0000
Received: (qmail 7411 invoked by uid 34887); 18 Mar 2015 12:46:01 +0700
Cc: <snipped>
Received: from t87596 by server1.tirtamahakam.com with local (spanel-sendmail 1.3 16.009)
id 69215c2138a2dcc592562cdec3c67042;
18 Mar 2015 12:46:01 +0700
Received: from ([41.220.69.192])
(SquirrelMail authenticated user [email protected])
by tirtamahakam.com with HTTP;
Wed, 18 Mar 2015 12:46:00 +0700
Message-ID: <[email protected]>
Date: Wed, 18 Mar 2015 12:46:00 +0700
Subject: GOOD DAY
Reply-To: [email protected]
User-Agent: SquirrelMail/1.4.21
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-1
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
X-Spanel-Sendmail-Original-From: [email protected]
From: [email protected]
Content-Length: 454


Dear Manager,

We want to make a large purchase from your company. We would be delighted to
enter into business cooperation with you.

if you can produce and supply us good quality products in large quantity.
Please advise your terms.

contact Email: [email protected]

Expecting to hear from you.

Best regards,

Kierownik David
Grupa Topex Sp. z o.o. Sp.k.,
Street: ul. Pograniczna 2/4,
ZIP: 02-285
CITY: Warszawa
POLAND
T +48 22 57 32 310

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#242751 by Faizan Docherty Sun Mar 22, 2015 8:10 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 5.65.61.205
Originating ISP: Sky Broadband
City: Ilford
Country of Origin: United Kingdom
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.25.32.4 with SMTP id g4csp415864lfg;
Sat, 21 Mar 2015 00:03:21 -0700 (PDT)
X-Received: by 10.70.45.227 with SMTP id q3mr130151656pdm.22.1426921400391;
Sat, 21 Mar 2015 00:03:20 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail.nrcs.org (mail.nrcs.org. [203.78.167.102])
by mx.google.com with ESMTP id xs1si1433646pbb.21.2015.03.21.00.03.19
for <snipped>;
Sat, 21 Mar 2015 00:03:20 -0700 (PDT)
Received-SPF: none (google.com: [email protected] does not designate permitted sender hosts) client-ip=203.78.167.102;
Authentication-Results: mx.google.com;
spf=none (google.com: [email protected] does not designate permitted sender hosts) [email protected]
Received: from localhost (mail [127.0.0.1])
by mail.nrcs.org (Postfix) with ESMTP id 29D561768CCE
for <snipped>; Sat, 21 Mar 2015 05:22:42 +0545 (NPT)
X-Virus-Scanned: amavisd-new at nrcs.org
Received: from mail.nrcs.org ([127.0.0.1])
by localhost (mail.nrcs.org [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 7SxYJMmU49VD for <snipped>;
Sat, 21 Mar 2015 05:22:42 +0545 (NPT)
Received: from User (unknown [5.65.61.205])
by mail.nrcs.org (Postfix) with ESMTPA id 5A96B1764A29;
Sat, 21 Mar 2015 02:00:19 +0545 (NPT)
Reply-To: <[email protected]>
From: "Brittany Enterprises LTD"< [email protected]>
Subject: ORDER
Date: Fri, 20 Mar 2015 20:19:00 -0000
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 150320-0, 20/03/2015), Outbound message
X-Antivirus-Status: Clean
Message-Id: <[email protected]>


Hello,

Warm Greetings from Brittany Enterprises LTD, We are UK base company we supply various product to our customers requirement. am writing in respect of our interests in purchasing some goods from your company. Before we proceed further I would like to know if your products are authorized to be shipped to these locations Malta, Mauritius, Indonesia, and Philippines. If its okay for your products to be shipped to these locations. I will be pleased if you can get back to me with picture samples and price list of each product to enable me get back to you with the quantity of goods we are going to order from you.
Quickly reply to purchasing manager Mrs Maria Dawn direct :Email: [email protected]
Direct tel:+447448844878
I await the requested information so I can proceed with the ordering.

Regards,
Mrs Maria Dawn
Purchasing Manager


---

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.

Who is online

Users browsing this forum: No registered users and 12 guests