Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#182806 by Faizan Docherty Sun Dec 01, 2013 12:27 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 64.12.254.133<br>Originating ISP: America Online<br> City: n/a<br>Country of Origin: United States<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.177.2 with SMTP id bg2csp12987vcb;
Sat, 30 Nov 2013 12:13:42 -0800 (PST)
X-Received: by 10.224.75.9 with SMTP id w9mr34483134qaj.68.1385842422032;
Sat, 30 Nov 2013 12:13:42 -0800 (PST)
Return-Path: <[email protected]>
Received: from omr-d06.mx.aol.com (omr-d06.mx.aol.com. [205.188.109.203])
by mx.google.com with ESMTPS id p10si39494qce.69.2013.11.30.12.13.41
for <snipped>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Sat, 30 Nov 2013 12:13:42 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 205.188.109.203 as permitted sender) client-ip=205.188.109.203;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 205.188.109.203 as permitted sender) [email protected];
dkim=pass [email protected]
Received: from mtaomg-ma05.r1000.mx.aol.com (mtaomg-ma05.r1000.mx.aol.com [172.29.41.12])
by omr-d06.mx.aol.com (Outbound Mail Relay) with ESMTP id B48D4700000A0;
Sat, 30 Nov 2013 15:13:41 -0500 (EST)
Received: from core-dnb002a.r1000.mail.aol.com (core-dnb002.r1000.mail.aol.com [172.29.214.5])
by mtaomg-ma05.r1000.mx.aol.com (OMAG/Core Interface) with ESMTP id 607B9E000081;
Sat, 30 Nov 2013 15:13:41 -0500 (EST)
X-MB-Message-Source: WebUI
Subject: Re:INVESTMENT/PARTNERSHIP
X-MB-Message-Type: User
MIME-Version: 1.0
From: Yuen Hang <[email protected]>
Content-Type: multipart/alternative;
boundary="--------MB_8D0BC1FCC1E00C4_16F0_1F1D95_webmail-vm039.sysops.aol.com"
X-Mailer: AOL Webmail 38203-STANDARD
Received: from 41.45.163.102 by webmail-vm039.sysops.aol.com (64.12.254.133) with HTTP (WebMailUI); Sat, 30 Nov 2013 15:13:41 -0500
Message-Id: <[email protected]>
X-Originating-IP: [41.45.163.102]
Date: Sat, 30 Nov 2013 15:13:41 -0500 (EST)
x-aol-global-disposition: G
DKIM-Signature: <snipped>
x-aol-sid: 3039ac1d290c529a46f5709e

This is a multi-part message in MIME format.
----------MB_8D0BC1FCC1E00C4_16F0_1F1D95_webmail-vm039.sysops.aol.com
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="us-ascii"


First, I must insist on your confidence in this transaction. I am making this contact with you based on reliable information available to me courtesy of Internet business index and confirmed by our local chambers of commerce and industry concerning your reputation. Thus I am convinced you would be capable to provide me with a solution.

Please contact me immediately you receive this message in my private email thus signifying your capability and willingness to enable me give you additional details on our proposed course of action for getting these funds to you 100% risk free.

Hope to hear from you soon
Thanks,

Yuen Hang
[email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

#184764 by Faizan Docherty Thu Dec 19, 2013 2:47 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.130.134.59<br>Originating ISP: Link Egypt<br> City: Cairo<br>Country of Origin: Egypt<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.221.13 with SMTP id ia13csp158123vcb;
Wed, 18 Dec 2013 21:16:17 -0800 (PST)
X-Received: by 10.68.134.229 with SMTP id pn5mr39068967pbb.9.1387430176267;
Wed, 18 Dec 2013 21:16:16 -0800 (PST)
Return-Path: <[email protected]>
Received: from p3plwbeout14-04.prod.phx3.secureserver.net (p3plsmtp14-04-2.prod.phx3.secureserver.net. [173.201.192.188])
by mx.google.com with ESMTP id vv1si1661590pbb.209.2013.12.18.21.16.15
for <snipped>;
Wed, 18 Dec 2013 21:16:16 -0800 (PST)
Received-SPF: neutral (google.com: 173.201.192.188 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=173.201.192.188;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 173.201.192.188 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Received: from localhost ([173.201.192.243])
by p3plwbeout14-04.prod.phx3.secureserver.net with bizsmtp
id 3HGF1n0075FYrgV01HGFr3; Wed, 18 Dec 2013 22:16:15 -0700
X-SID: 3HGF1n0075FYrgV01
Received: (qmail 19568 invoked by uid 99); 19 Dec 2013 05:16:15 -0000
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="utf-8"
X-Originating-IP: 41.130.134.59
User-Agent: Workspace Webmail 5.6.45
Message-Id: <20131218221613.76f363be44a1c1a0a22388352065d0c5.9b243e61f4.wbe@email14.secureserver.net>
From: "Yuen" <[email protected]>
X-Sender: [email protected]
Reply-To: "Yuen" <[email protected]>
To:
Subject: Fwd: Investment!
Date: Wed, 18 Dec 2013 22:16:13 -0700
Mime-Version: 1.0


I am making this contact with you based on reliable information available to me courtesy of Internet business index and confirmed by our local chambers concerning your reputation. Thus I am convinced you would be capable to provide me with a solution to this transaction. I must first of all insist this is not an internet transaction at some point you will be required to be physically present to sign the release documents for the said funds.

Let me know if you will be able to commit yourself to such level of responsibilities as soon as you convince me of your readiness and seriousness more information's will be given to you.



Yuen
[email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#185102 by Faizan Docherty Mon Dec 23, 2013 10:36 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.130.126.78<br>Originating ISP: Link Egypt<br> City: Cairo<br>Country of Origin: Egypt<br>* For a complete report on this email header goto ipTRACKERonline


From Yuen Sun Dec 22 18:48:15 2013
X-Apparently-To: <snipped> via 72.30.239.32; Sun, 22 Dec 2013 18:48:16 -0800
Return-Path: <[email protected]>
X-YahooFilteredBulk: 97.74.135.182
Received-SPF: none (domain of mjsoftware.com does not designate permitted sender hosts)
X-YMailISG: <snipped>
X-Originating-IP: [97.74.135.182]
Authentication-Results: mta1385.mail.bf1.yahoo.com from=account.com; domainkeys=neutral (no sig); from=account.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO p3plwbeout10-01.prod.phx3.secureserver.net) (97.74.135.182)
by mta1385.mail.bf1.yahoo.com with SMTP; Sun, 22 Dec 2013 18:48:16 -0800
Received: from localhost ([97.74.135.244])
by p3plwbeout10-01.prod.phx3.secureserver.net with bizsmtp
id 4qoG1n00C5GZ5JR01qoGHm; Sun, 22 Dec 2013 19:48:16 -0700
X-SID: 4qoG1n00C5GZ5JR01
Received: (qmail 2309 invoked by uid 99); 23 Dec 2013 02:48:16 -0000
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="utf-8"
X-Originating-IP: 41.130.126.78
User-Agent: Workspace Webmail 5.6.45
Message-Id: <20131222194815.3b5f95f8f921bdbb2fd7c2f118bf80d4.e1a65563e3.wbe@email10.secureserver.net>
From: "Yuen" <[email protected]>
X-Sender: [email protected]
Reply-To: "Yuen" <[email protected]>
To:
Subject: Industry Investment!
Date: Sun, 22 Dec 2013 19:48:15 -0700
Mime-Version: 1.0
Content-Length: 871


I am making this contact with you based on reliable information available to me and confirmed by our local chambers concerning your reputation. Thus I am convinced you would be capable to provide me with a solution.

Yuen
[email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.

Who is online

Users browsing this forum: Bing [Bot], Majestic-12 [Bot] and 85 guests