Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#400067 by buried under 419s Mon Nov 11, 2019 9:29 pm
Return-path: <[email protected]>
Envelope-to:
Delivery-date: Mon, 11 Nov 2019 06:34:53 -0800
Received: from ns1.tinasnet.net.br ([177.125.124.40]:40469 helo=srv01.tinasnet.net.br)
by with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256)
(Exim 4.89)
(envelope-from <[email protected]>)
id 1iUAmG-0001Ei-QB
for ; Mon, 11 Nov 2019 06:34:53 -0800
Received: from [185.234.217.207]
by srv01.tinasnet.net.br with esmtpa (Exim 4.92.2)
(envelope-from <[email protected]>)
id 1iUAlW-0001Pe-SU; Mon, 11 Nov 2019 12:34:03 -0200
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
To: Recipients <[email protected]>
From: "Georgina Thompson" <[email protected]>
Date: Mon, 11 Nov 2019 06:33:52 -0800
Reply-To: [email protected]
Message-Id: <[email protected]>
X-Spam-Status: Yes, score=21.8
X-Spam-Score: 218
X-Spam-Bar: +++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Hi, I need your help to move some funds out of my location.
I will explain more when I read a positive response from you. Sincerely,
Georgina Thompson [...]

Content analysis details: (21.8 points, 7.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
0.1 RCVD_IN_SBL RBL: Received via a relay in Spamhaus SBL
[185.234.217.207 listed in zen.spamhaus.org]
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[177.125.124.40 listed in psbl.surriel.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[177.125.124.40 listed in bl.score.senderscore.com]
6.2 RCVD_IN_MSPIKE_L5 RBL: Very bad reputation (-5)
[177.125.124.40 listed in bl.mailspike.net]
1.8 PYZOR_CHECK Listed in Pyzor (https://pyzor.readthedocs.io/en/latest/)
0.0 RCVD_IN_MSPIKE_BL Mailspike blacklisted
1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
anti-forgery methods
0.1 FSL_BULK_SIG Bulk signature with no Unsubscribe
2.1 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
X-Spam-Flag: YES
Subject: ***SPAM*** URGENT


Hi, I need your help to move some funds out of my location. I will explain more when
I read a positive response from you.

Sincerely,
Georgina Thompson

Questions about scams? fraudatiocruor @ gmail.com to contact remove spaces
Advertisement

Who is online

Users browsing this forum: Bing [Bot] and 200 guests