Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#261686 by DennisHondema Mon Jul 27, 2015 5:58 pm
Hello Scamwarners,

I found this site because of some emails send to me from Syria. A person named Speckmann Almas Duha wich contacted me first on facebook sends me the mail i have pasted here below. At first it seemed legit untill the Red Cross Diplomatic Jet came into play. The emails send to me are from [email protected] and she should be surviving in a refugee camp in Syria. I got quite far into this scam at the point that there is a box with 1.3 million american dollars is waiting for me to pick up in London. The Diplomat is called Dr. Michael Anthony and he is mailing from [email protected]. in this mails he like to stress out that he is Dr. and has a PHD which has nothing to do with work as diplomat. Also a bit strange that as a diplomat for the Red Cross, he is not mailing me from an official ICRC mail account.

''Hello dear, thank you so much for getting back to me trying to know more, firstly, I will like to tell you that there is no business without trust. My major interest this time is to leave my troubled country to your country, I lost my husband on the line of duty and i cannot risk training my child in this war country.

Let me clear your mind more further, among all the persons i saw, your personality got my attention and my heart really accepted you, luckily that I found someone like you, I have a great believe and trust that you can help me out in this because I have no other better option and it took me by the grace of God to locate you.

For the money, i made my money legally and i will take all necessary measures to make sure the parcel gets to you. I would have considered transferring the money into someones bank account but our banks are not functional since the war started, i have also thought about coming to your country with the money but you know since the war started, travelers are always searched thoroughly at the Airport, I will loose all my life savings if they get to find out the box am carrying contains that kind of money. That is the major reason I have decided to send this money through the Red Cross Shipping Service which has immunity that prevents parcels from being searched or opened at any checkpoint. I would have sent this box straight to your home, but as you may know, they Red Cross route only stop at London.
So, when the box gets to London, I will plead with the Red Cross agent to establish communication between you and the Diplomat who will receive the box in London and you will communicate with him for a pick up.

I know you might be confused, please do not be, my coming to your country will be when you have received the box, confirm the box in your possession, you will let me know immediately so that I will quickly meet with the Syrian Red Cross here to sign the final documents, after meeting with the Red Cross agents for the final signatory, indicating that my box got to you, after that, I will be issued a written note from them that my parcel arrived your country safely, this letter, when I present it at the embassy, it will enable me get a Visa immediately to your country, then I will start coming to meet you with my lovely daughter.

I needed a man who has a cool heart, and i believe you do, I saw you, your gentle looks got my attention, i decided to approach you, I know it is not the best way but as it stands now, i got no choice now than to leave my troubled country to yours. For the 30% that I have promised to give you when the whole thing is materialized, I know you might not be interested about it but I am using this to encourage you so that you see reasons to help me, and I know also that your struggles toward helping me leave my war country will not be in vain at last. Please, I need you to understand me because I am deeply in a hurry to leave here, we are not safe anymore.

The best way I can send this box to you is through the Red Cross Agent which has a Courier service immunity. Their work in Syria is for carrying of Huge funds, Hard Documents etc, bear in mind that i will not tell anybody that the box contains anything like money other than your personal belonging at the point of registration because that might be the end of my money. I am doing this in order to save my future, life and that of my lovely daughter.

If you are interested to execute this and i can trust you on this, all i need you to do for me now is to allow me register the box properly in your name by given me your particulars like:
1 Full name
2 Full address
3 Direct phone number
4 Occupation
5 Scanned copy of your ID or passport.
I pray you understand me this time. The crisis is too much, please help''.

Yours, Almas.

Now the mail from the RC Diplomat..

From: Diplomat Michael Anthony
Address: London -United Kingdom

To: Mr. Dennis
Address: Netherlands

Your consignment was sent to me through the Red Cross Agent by one Mrs Almas from Syria, I was asked to receive the box on your behalf until you contact me for collection.

If you are, please reply this message as soon as possible.


Yours Sincerely,
(Diplomat) Michael Anthony (Ph.D)
Last edited by DennisHondema on Mon Jul 27, 2015 6:43 pm, edited 1 time in total.
Advertisement

#261687 by DennisHondema Mon Jul 27, 2015 6:16 pm
Received: by 10.25.26.194 with SMTP id a185csp519465lfa;
Sat, 25 Jul 2015 09:08:08 -0700 (PDT)
X-Received: by 10.52.110.135 with SMTP id ia7mr23878545vdb.69.1437840487926;
Sat, 25 Jul 2015 09:08:07 -0700 (PDT)

Can this info help in identifying the person behind the scam?
#261688 by DennisHondema Mon Jul 27, 2015 6:20 pm
Received-SPF: pass (google.com: domain of [email protected] designates 2607:f8b0:400c:c0f::231 as permitted sender) client-ip=2607:f8b0:400c:c0f::231;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 2607:f8b0:400c:c0f::231 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
Received: by mail-vn0-x231.google.com with SMTP id a140so18201722vna.2
#261858 by AlanJones Wed Jul 29, 2015 12:35 am
The only valid IP address in the bits of header that you have posted is 2607:f8b0:400c:c0f::231 and that is a Google IP.

As the scammer is using Gmail's web interface, you will not get an accurate originating IP as Gmail strips them out.

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#261886 by DennisHondema Wed Jul 29, 2015 6:55 am
Delivered-To: <Snipped>
Received: by 10.25.26.194 with SMTP id a185csp519465lfa;
Sat, 25 Jul 2015 09:08:08 -0700 (PDT)
X-Received: by 10.52.110.135 with SMTP id ia7mr23878545vdb.69.1437840487926;
Sat, 25 Jul 2015 09:08:07 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail-vn0-x231.google.com (mail-vn0-x231.google.com. [2607:f8b0:400c:c0f::231])
by mx.google.com with ESMTPS id fi8si5299671vdb.71.2015.07.25.09.08.07
for <Snipped>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Sat, 25 Jul 2015 09:08:07 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 2607:f8b0:400c:c0f::231 as permitted sender) client-ip=2607:f8b0:400c:c0f::231;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 2607:f8b0:400c:c0f::231 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
Received: by mail-vn0-x231.google.com with SMTP id a140so18201722vna.2
for <Snipped>; Sat, 25 Jul 2015 09:08:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20120113;
h=mime-version:in-reply-to:references:date:message-id:subject:from:to
:content-type;
bh=uN8ZEEp94N3ESxUaEkyeI1AUmXgarLwcbuY1+plIKHE=;
b=T5chuiEo8Ezo1AMgafvuTxf7BhJMaEG48Gq5wGfLlG9f54EmD2eBgGlgUl9+/oXP1F
/Rer4zopzfrjLW2K8PJyeOw0vp0mS/td1rQ922F+IaV19y1l90NzyktYYn8xVuw1WEmB
BGpsLKVQF8GlIsEbNlexo1b9P1XOFKFtXLa2AamHn5qJQwGB2eAh8qb4n3HdC2LNg8+p
HSTYuFO5sQ4KXHdJx8a0sAtHoSegc81e9Mbae+HV5lLOn+0l+ZPOi7LfjfiTMkDarnPm
l/PHE7/+LB1uPXe4nlR03gilZGVVIoAkBuVdbWNJQ5znQNeZbRUvSSnoScqd3MQs3Rk/
WJbw==
MIME-Version: 1.0
X-Received: by 10.52.32.34 with SMTP id f2mr23817406vdi.11.1437840487094; Sat,
25 Jul 2015 09:08:07 -0700 (PDT)
Received: by 10.31.152.197 with HTTP; Sat, 25 Jul 2015 09:08:07 -0700 (PDT)
In-Reply-To: <CAGkCBkbnof544KXS7scUocEy7P4n+zTZmV7ZRp=6kGA0wBGyWQ@mail.gmail.com>
References: <CAGkCBkbnof544KXS7scUocEy7P4n+zTZmV7ZRp=6kGA0wBGyWQ@mail.gmail.com>
Date: Sat, 25 Jul 2015 17:08:07 +0100
Message-ID: <CAGGNwgfeKp0T=gOAsfhyqpd_LmoUnzK3hcfUuOPhMzYdEQyBzw@mail.gmail.com>
Subject: Re: My Gmail account
From: Speckmann Almas Duha <[email protected]>
To: <snipped>
Content-Type: multipart/alternative; boundary=bcaec51d2b807a1dd7051bb55306

--bcaec51d2b807a1dd7051bb55306
Content-Type: text/plain; charset=UTF-8
#261899 by AlanJones Wed Jul 29, 2015 8:06 am
I still can't see any valid IP addresses in there, other than the Google IPv6 one that I quoted earlier.

Which IP address is it that you see that belongs to "Timeless Holidays" in Durban?

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#261919 by AlanJones Wed Jul 29, 2015 11:20 am
That is not a valid IP address. It is used within private networks to identify individual machines. In this case, probably different servers on Google's internal networks.

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.

Who is online

Users browsing this forum: Bing [Bot], Majestic-12 [Bot] and 202 guests