Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#220212 by Faizan Docherty Wed Sep 24, 2014 5:52 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.55.34.209
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.125.234 with SMTP id mt10csp33807pdb;
Sat, 20 Sep 2014 06:33:25 -0700 (PDT)
X-Received: by 10.70.43.100 with SMTP id v4mr8992583pdl.108.1411220005391;
Sat, 20 Sep 2014 06:33:25 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (si-002-i86.relay.mailchannels.net. [173.236.122.36])
by mx.google.com with ESMTP id c8si7620226pat.25.2014.09.20.06.33.24
for <snipped>;
Sat, 20 Sep 2014 06:33:25 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 173.236.122.36 as permitted sender) client-ip=173.236.122.36;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 173.236.122.36 as permitted sender) [email protected]
X-Sender-Id: _forwarded-from|65.55.34.199
Received: from r8-chicago.webserversystems.com (ip-10-213-14-133.us-west-2.compute.internal [10.213.14.133])
by relay.mailchannels.net (Postfix) with ESMTPA id 7ED62100472
for <snipped>; Sat, 20 Sep 2014 13:33:21 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.55.34.199
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.220.170.51])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.13);
Sat, 20 Sep 2014 13:33:23 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.55.34.199
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1411220003054:952868043
X-MC-Ingress-Time: 1411220003054
Received: from col004-omc4s7.hotmail.com ([65.55.34.209]:63833)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XVKmu-000EW1-2J
for <snipped>; Sat, 20 Sep 2014 08:33:20 -0500
Received: from COL131-W45 ([65.55.34.199]) by COL004-OMC4S7.hotmail.com with Microsoft SMTPSVC(7.5.7601.22724);
Sat, 20 Sep 2014 06:33:19 -0700
X-TMN: [YmJpyZVTISmnxf5SV3jb4euRMAYIRuBd]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_296c8ca6-c29f-456d-8afc-1d5077504bb4_"
From: sully atkins <[email protected]>
Date: Sat, 20 Sep 2014 14:33:19 +0100
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 20 Sep 2014 13:33:19.0425 (UTC) FILETIME=[70E69310:01CFD4D7]
X-Spam-Status: Yes, score=8.6
X-Spam-Score: 86
X-Spam-Bar: ++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: I hope that this email finds you well. I sent you an email
a few days ago and am unsure that its arrival at your end destination. However,
I would like to bring you awareness of my urgent situation. Let me take a
moment to write again to let you know the reason why i contacted you before.
I am a single mother of 13 years old boy. am 59 year old from Palestinian
but grown up in Isreal. I am looking for investment opportunities for my
only son from develop countries specifically to secure his financial future
due to the crisis. I have a bachelor's degree in petroleum chemical in past
years I worked at Zion Petroleum Company in Caesarea Isreal. A company whose
focus is on the upstream Oil & Gas. I retired from the company after I was
diagnosed with a medical condition, apancreatic cancer and cannot handle
the stress and pressure of the job which provoked a flare-up within my late
husband family members since I have few months to live. Due to my situation,
I need your assistance to secure a profitable business worth $1,950,000 (ONE
MILLION NINE HUNDRED AND FIFTY THOUSAND DOLLARS) for my son in future because
now he his too small If you are sure you can help me handle any investment
in your country on behalf of my son, then do not hesitate to contact me i
will transfer the fund. Looking forward to reading from you soon. Thank you
and Warm Regard, Mrs Sully atkins [...]

Content analysis details: (8.6 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.55.34.209 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(sullyatkins01[at]hotmail.com)
-0.0 SPF_PASS SPF: sender matches SPF record
-0.7 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (sullyatkins01[at]hotmail.com)
1.0 MISSING_HEADERS Missing To: header
1.8 US_DOLLARS_3 BODY: Mentions millions of $ ($NN,NNN,NNN.NN)
0.0 HTML_MESSAGE BODY: HTML included in message
1.4 MALFORMED_FREEMAIL Bad headers on message from free email service
0.0 LOTS_OF_MONEY Huge... sums of money
2.2 ADVANCE_FEE_4_NEW Appears to be advance fee fraud (Nigerian 419)
0.0 ADVANCE_FEE_5_NEW Appears to be advance fee fraud (Nigerian 419)
2.6 ADVANCE_FEE_3_NEW Appears to be advance fee fraud (Nigerian 419)
0.0 ADVANCE_FEE_4_NEW_MONEY Advance Fee fraud and lots of money
0.0 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
0.0 ADVANCE_FEE_3_NEW_MONEY Advance Fee fraud and lots of money
X-Spam-Flag: YES
Subject: ***SPAM*** Looking forward to reading from you soon. Thank you and Warm
Regard,

X-MC-Forward: <snipped>
X-AuthUser:


I hope that this email finds you well.

I sent you an email a few days ago and am unsure that its arrival at your end destination. However, I would like to bring you awareness of my urgent situation. Let me take a moment to write again to let you know the reason why i contacted you before.

I am a single mother of 13 years old boy. am 59 year old from Palestinian but grown up in Isreal. I am looking for investment opportunities for my only son from develop countries specifically to secure his financial future due to the crisis.

I have a bachelor's degree in petroleum chemical in past years I worked at Zion Petroleum Company in Caesarea Isreal. A company whose focus is on the upstream Oil & Gas. I retired from the company after I was diagnosed with a medical condition, apancreatic cancer and cannot handle the stress and pressure of the job which provoked a flare-up within my late husband family members since I have few months to live.

Due to my situation, I need your assistance to secure a profitable business worth $1,950,000 (ONE MILLION NINE HUNDRED AND FIFTY THOUSAND DOLLARS) for my son in future because now he his too small

If you are sure you can help me handle any investment in your country on behalf of my son, then do not hesitate to contact me i will transfer the fund.

Looking forward to reading from you soon.

Thank you and Warm Regard,

Mrs Sully atkins

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: No registered users and 107 guests