Scams operating under the guise of a charity.
#174166 by Faizan Docherty Thu Aug 15, 2013 12:14 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 13.8.14.181<br>Originating ISP: Xerox Corporation<br> City: Norwalk<br>Country of Origin: United States<br>* For a complete report on this email header goto ipTRACKERonline


X-Apparently-To: <snipped> via 188.125.85.150; Wed, 14 Aug 2013 21:40:15 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 192.114.66.138
Received-SPF: softfail (transitioning domain of outlook.com does not designate 192.114.66.138 as permitted sender)
X-YMailISG: <snipped>
X-Originating-IP: [192.114.66.138]
Authentication-Results: mta1392.mail.ne1.yahoo.com from=outlook.com; domainkeys=neutral (no sig); from=outlook.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO fss.bezeqint.net) (192.114.66.138)
by mta1392.mail.ne1.yahoo.com with SMTP; Wed, 14 Aug 2013 21:40:13 +0000
Received: from 116.203.127.221 (EHLO User) ([116.203.127.221])
by fss4.bezeqint.net (MOS 4.3.6-GA FastPath queued)
with ESMTP id AQR88399 (AUTH eli100476);
Thu, 15 Aug 2013 00:40:00 +0300 (IDT)
Reply-To: <[email protected]>
From: "Adrian Gillian Bayford"<[email protected]>
Subject: Great Donation Of ?1,500,000.00 GBP
Date: Thu, 15 Aug 2013 03:09:44 +0530
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 130814-1, 14-08-2013), Outbound message
X-Antivirus-Status: Clean
Message-Id: <[email protected]>
X-Mirapoint-IP-Reputation: reputation=Neutral-1,
source=Queried,
refid=tid=0001.0A0C0301.520BF914.006F,
actions=TAG
X-Junkmail-Premium-Raw: score=29/50,
refid=2.7.2:2013.8.14.181825:17:29.943,
ip=116.203.127.221,
rules=__RECEIVED_FROM_USER2,
__HAS_REPLYTO,
__FRAUD_WEBMAIL_REPLYTO,
__HAS_FROM,
__SUBJ_HIGHBIT,
__SUBJ_ALPHA_END,
__MIME_VERSION,
__CT,
__CHARSET_IS_CP1251,
__CT_TEXT_PLAIN,
__CTE,
__HAS_X_PRIORITY,
__HAS_MSMAIL_PRI,
__HAS_X_MAILER,
USER_AGENT_OE,
__OUTLOOK_MUA_1,
__USER_AGENT_MS_GENERIC,
__HAS_MSGID,
__SANE_MSGID,
MISSING_HEADERS,
__FRAUD_MONEY_VALUE,
__FRAUD_CONTACT_NUM,
__FRAUD_CONTACT_SEX,
__FRAUD_CONTACT_AGE,
__FRAUD_CONTACT_JOB,
__SUBJ_ALPHA_END2,
BODY_SIZE_100_199,
BODYTEXTP_SIZE_3000_LESS,
__MIME_TEXT_ONLY,
RDNS_NXDOMAIN,
HTML_00_01,
HTML_00_10,
FRAUD_CONTACT_X4,
__FRAUD_MONEY,
__LOCALE_CYRILLIC_CP1251,
LOCALE_CYRILLIC,
BODY_SIZE_5000_LESS,
RDNS_SUSP_GENERIC,
WEBMAIL_REPLYTO_NOT_FROM,
__OUTLOOK_MUA,
__PHISH_SPEAR_STRUCTURE_1,
BODY_SIZE_1000_LESS,
RDNS_SUSP,
BODY_SIZE_2000_LESS,
SMALL_BODY,
__PHISH_SPEAR_STRUCTURE_2,
__FRAUD_WEBMAIL,
FORGED_MUA_OUTLOOK,
REPLYTO_FRO
X-Junkmail-Status: score=29/50, host=fss4.bezeqint.net
X-Junkmail-Signature-Raw: score=bulk(0),
refid=str=0001.0A0C0203.520B59F2.005F,ss=3,sh,re=9.591,recu=0.000,reip=0.000,cl=3,cld=1,fgs=0,
ip=116.203.127.221,
so=2012-12-31 14:30:00,
dmn=2013-04-19 10:07:54,
mode=multiengine
X-Junkmail-IWF: false
X-Mirapoint-Virus-RAPID-Raw: score=unknown(0),
refid=str=0001.0A0C0203.520B59F2.005F,ss=3,sh,re=9.591,recu=0.000,reip=0.000,cl=3,cld=1,fgs=0,
ip=116.203.127.221,
so=2012-12-31 14:30:00,
dmn=2013-04-19 10:07:54
X-Mirapoint-Loop-Id: 11e3460dd321be752ed72b567447ee33
Content-Length: 116


We are donating 1.5million pounds to you, Send Name, Country, Mobile Number, Sex, Age, Occupation for more details.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: No registered users and 4 guests