#189194 by AlanJones Tue Jan 28, 2014 2:36 pm
From [email protected]

Delivered-To: XXX
Received: by 10.114.24.6 with SMTP id q6csp1298ldf;
Fri, 10 Jan 2014 21:44:50 -0800 (PST)
Return-Path: <[email protected]>
Received-SPF: pass (google.com: domain of [email protected] designates 10.224.60.69 as permitted sender) client-ip=10.224.60.69
Authentication-Results: mr.google.com;
spf=pass (google.com: domain of [email protected] designates 10.224.60.69 as permitted sender) [email protected];
dkim=pass [email protected]
X-Received: from mr.google.com ([10.224.60.69])
by 10.224.60.69 with SMTP id o5mr15008620qah.92.1389419089326 (num_hops = 1);
Fri, 10 Jan 2014 21:44:49 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20120113;
h=mime-version:date:message-id:subject:from:to:content-type;
bh=1kVNx0hD0KSBcPnfWVgkdrZNNDwWNocJ7KFxbKZNPXA=;
b=yZAJvoMX5NtkSM3qG1oydi7eOdEoYOhp/h8FMg0ckeELeYBu/J0niN7un+m22G91Q5
g5JbasHccjkJ6Lb/Sh4q+NyJXfLVmtLa5WNRgWiCDWXpaGHmRSsR35tzciqOkmvI2BKh
3OnnhgdUJqBNaxxehKaxASbvNREiCKXembZvGVgvnbWPjcxsxdl+eiAa+QMDY3BUyya6
vMTu0AbJgJfVUk1Ozf3ZkV2rCOyqWBaD72kdfuMUE7JHJMNorTWeACWPRb3gZSNMC717
0nWG6G9tnMT+LqkdRDyNT5955LYPXM/aE24JEmkC2i0jWvssNrQqevLlcM+RQ6Tp/BTj
NbiA==
MIME-Version: 1.0
X-Received: by 10.224.60.69 with SMTP id o5mr15008620qah.92.1389419089323;
Fri, 10 Jan 2014 21:44:49 -0800 (PST)
Received: by 10.96.149.39 with HTTP; Fri, 10 Jan 2014 21:44:49 -0800 (PST)
Date: Sat, 11 Jan 2014 07:44:49 +0200
Message-ID: <CAFL4oTV4zrRAOV41tQE1yD9Qs_Ju5ah9eaarU-=NZyiAeTs9xA@mail.gmail.com>
Subject: Purchase Inquiry
From: Daniel Tsoncheva <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=001a11c3e48843695e04efab576d
Bcc: XXXm


Hello,
I'm interested to make a purchase from your store, could you please send me your catalog please, so I can choose the one to buy and please include your discount prices for marge orders.
I await your utmost response soonest
Regards

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
Advertisement

#189266 by Faizan Docherty Wed Jan 29, 2014 9:39 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 74.238.241.169<br>Originating ISP: Bellsouth.net<br> City: Eunice<br>Country of Origin: United States<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp86274vcj;
Wed, 29 Jan 2014 04:34:12 -0800 (PST)
X-Received: by 10.43.52.65 with SMTP id vl1mr98272icb.86.1390998851228;
Wed, 29 Jan 2014 04:34:11 -0800 (PST)
Return-Path: <[email protected]>
Received: from smtp.mailhostbox.com (outbound-us3.mailhostbox.com. [70.87.28.152])
by mx.google.com with ESMTP id c18si29632402igr.22.2014.01.29.04.34.09
for <multiple recipients>;
Wed, 29 Jan 2014 04:34:11 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 70.87.28.152 as permitted sender) client-ip=70.87.28.152;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 70.87.28.152 as permitted sender) [email protected]
Message-Id: <52e8f543.f23b320a.710c.ffffeab7SMTPIN_ADDED_MISSING@mx.google.com>
Received: from User (adsl-074-238-241-169.sip.lft.bellsouth.net [74.238.241.169])
(Authenticated sender: [email protected])
by smtp.mailhostbox.com (Postfix) with ESMTPA id 0F46C1508025;
Wed, 29 Jan 2014 12:33:13 +0000 (GMT)
Reply-To: <[email protected]>
From: "abe shelton"<[email protected]>
Subject: New Order
Date: Wed, 29 Jan 2014 06:34:08 -0600
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-CTCH-RefID: str=0001.0A020201.52E8F540.0184,ss=1,re=4.793,recu=0.000,reip=0.000,cl=1,cld=1,fgs=0
X-CTCH-VOD: Unknown
X-CTCH-Spam: Unknown
X-CTCH-Score: 4.793
X-CTCH-Rules: FROM_MISSP_MSFT,FSL_CTYPE_WIN1251,
X-CTCH-Flags: 0
X-CTCH-ScoreCust: 0.000
X-CTCH-SenderID: [email protected]
X-CTCH-SenderID-TotalMessages: 16
X-CTCH-SenderID-TotalSpam: 0
X-CTCH-SenderID-TotalSuspected: 0
X-CTCH-SenderID-TotalBulk: 0
X-CTCH-SenderID-TotalConfirmed: 0
X-CTCH-SenderID-TotalRecipients: 0
X-CTCH-SenderID-TotalVirus: 0
X-CTCH-SenderID-BlueWhiteFlag: 0
X-Scanned-By: MIMEDefang 2.72 on 70.87.28.152


Good Day,



After viewing your advertised products I wish to introduce our company to

you as we would require to place an order with your establishment.



We are an independent buying house and we would

like to get a quotation on your products, we require your fairest prices

as we would be making huge/bulk purchases from time to time.



Awaiting your reply,



Sincerely,

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#189302 by Faizan Docherty Wed Jan 29, 2014 1:02 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.190.2.128<br>Originating ISP: Etisalat-ng<br> City: Lagos<br>Country of Origin: Nigeria<br>* For a complete report on this email header goto ipTRACKERonline


Val Donatus G. <[email protected]> 24 January 2014 12:11
Reply-To: [email protected]
To: <snipped>
Subject: Supply project



Attn: Sir/Madam,

An open Tender for the supply of your company products to the Economics
Community of West African States(ECOWAS). Urgently furnish us in full
details about the standard of your product. We will appreciate it more if
you give us with Details: Specification and Catalogs or Price list via
Email.To avoid making a wrong choice of products before placing an order
for it.

Terms of payment:An upfront payment of 80% (T/T) will be made to your
account for production,While 20% will be paid before shipment.
Thanks and Regards

Rev Val Donatus G

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#189494 by AlanJones Thu Jan 30, 2014 4:30 pm
From: Anthony Adams [email protected]

Hello, We extend our kind interest to make purchase on some items in your facility. Before we proceed kindly let us know the kinds of credit cards you accept and do you allow private pickup by freight forwarders ? Get back to me at : [email protected] Hope to read from you so soon. Anthony Adams

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#189660 by Faizan Docherty Sun Feb 02, 2014 1:51 am
Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp17831vcj;
Sat, 1 Feb 2014 05:02:26 -0800 (PST)
Return-Path: <[email protected]>
Received-SPF: pass (google.com: domain of [email protected] designates 10.236.222.231 as permitted sender) client-ip=10.236.222.231
Authentication-Results: mr.google.com;
spf=pass (google.com: domain of [email protected] designates 10.236.222.231 as permitted sender) [email protected];
dkim=pass [email protected]
X-Received: from mr.google.com ([10.236.222.231])
by 10.236.222.231 with SMTP id t97mr190309yhp.125.1391259746088 (num_hops = 1);
Sat, 01 Feb 2014 05:02:26 -0800 (PST)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.236.222.231 with SMTP id t97mr173410yhp.125.1391259745731;
Sat, 01 Feb 2014 05:02:25 -0800 (PST)
Received: by 10.170.137.86 with HTTP; Sat, 1 Feb 2014 05:02:25 -0800 (PST)
Date: Sat, 1 Feb 2014 13:02:25 +0000
Message-ID: <CAJAfUGgxHiTMTxHKXUFcYVCcY9hs4tVKc7d_KO=RhrHMCJ51gg@mail.gmail.com>
Subject: URGENT FOOD STUFF SUPPLY NEED FOR REFUGEES
From: securities badburkina <[email protected]>
To: [email protected]
Content-Type: text/plain; charset=ISO-8859-1
Bcc: <snipped>


Dear Sir:

My company has been mandated to look for a company capable of
supplying food stuffs product listed bellow by the AFRICAN HUMAN
RIGHT AND REFUGEES PROTECTION COUNCIL (AHRRPC) for assisting of the
refugee within the war affected countries IN middle east and Africa
like MALI,SYRIA, SOMALIA, CENTRAL AFRICA, and SOUTH SUDAN, which after
going through your company's profile, have decided to know if your
company is interested.

Below are the list of food Stuffs and the targeted value needed
by (AHRRPC)

1. Rice
2. Beans
3. Milk powder
4. Sugar
5. Vegetable Oil
6. Used Cloths
7. Wheat Flour
8. White corn meal
9. Corn Cooking oil
10. Cumin seed oil
11. Ground nut
12. Sage Oil
13. Soya bean oil
14. Palm oil
15. Fresh Vegetables
16. Fresh fruits
17. Cocoa powder.

We will be happy to work with you company only as representing agent
to secure an allocation for your company while in return your company
will give us comission as soon as your receive your contract value. We
will give you more details about the contract when we recieve your
reply.

Regards,

Mr Maiga Abubakar
AHRRPC AGENT
Website:www.ahrrpc.8k.com
Bamako-Mali in West Africa.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#189667 by Faizan Docherty Sun Feb 02, 2014 2:21 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.66.228.239<br>Originating ISP: Alcatel Project<br> City: Accra<br>Country of Origin: Ghana<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp9100vcj;
Thu, 30 Jan 2014 05:10:49 -0800 (PST)
X-Received: by 10.236.37.105 with SMTP id x69mr13135163yha.15.1391087449394;
Thu, 30 Jan 2014 05:10:49 -0800 (PST)
Return-Path: <[email protected]>
Received: from 10ibl21ser04.datacenter.cha.cantv.net (10ibl21ser04.datacenter.cha.cantv.net. [200.11.173.10])
by mx.google.com with ESMTPS id j24si5096351yhb.46.2014.01.30.05.06.04
for <multiple recipients>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Thu, 30 Jan 2014 05:10:49 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) client-ip=200.11.173.10;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) [email protected]
X-Virus-Scanned: amavisd-new at cantv.net
Received: from webmail-05.datacenter.cha.cantv.net (webmail-05.datacenter.cha.cantv.net [200.11.153.88])
(authenticated bits=0)
by 10ibl21ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with ESMTP id s0UD5UGZ003153;
Thu, 30 Jan 2014 08:35:31 -0430
X-Matched-Lists: []
Received: from 41.66.228.239 ([41.66.228.239]) by webmail-05.datacenter.cha.cantv.net (Cantv Webmail) with HTTP; Thu, 30 Jan 2014 08:35:30 -0430 (VET)
Date: Thu, 30 Jan 2014 08:35:30 -0430 (VET)
From: Andy Akim <[email protected]>
Reply-To: [email protected]
To: [email protected]
Message-ID: <2108257558.607206.1391087131050.JavaMail.gess@webmail-05.datacenter.cha.cantv.net>
Subject: CONTRACT SUPPLY
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
X-Mailer: Cantv Webmail
X-Originating-IP: [41.66.228.239]


Dear,

Can you supply any of these items listed below to Republic Of Ghana? Please get back to me for more details.

1. Promotional T-shirts.
2. Street Light.
3. Fertilizer.
4. Rice.
5. Mosquito net.
6. Hospital Bed.
7. Condoms.
8. Hospital Equipment.
9. Hospital bed sheets,Pillow cases.
10.Towels.
11.Knapsack sprayer.
12.Fire Fighting equipment.
13.Sanitary Wares
14.Energy Saving Bulbs.
15.Electrical Wires.
16.Standing Fan.
17.Ceiling Fan.
18.Wall Sockets.
19.Led Fluorescent.
20.A4- Paper
21.Sewing Machines.
22.Sports Equipment
23.Agricultural Products.
24.Agricultural Tools/Machines.
25.Erosion Control Equipment.
26.Industrial Wears.
27.Portland Cement.
28.Agricultural Equipment/Tractors.
30.Road construction Equipment.
31.Environmental Equipment
32.Poultry Equipment

I will be waiting for your urgent reply,I am a sourcing commission agent.

Regard`s



Andy Akim.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#189750 by Faizan Docherty Mon Feb 03, 2014 12:55 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 188.121.41.119<br>Originating ISP: Godaddy.com, Llc<br> City: n/a<br>Country of Origin: Netherlands<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp99532vcj;
Sun, 2 Feb 2014 19:07:19 -0800 (PST)
X-Received: by 10.180.87.9 with SMTP id t9mr6849218wiz.36.1391396838655;
Sun, 02 Feb 2014 19:07:18 -0800 (PST)
Return-Path: <[email protected]>
Received: from n1nlshrout01.shr.prod.ams1.secureserver.net (n1nlshrout01.shr.prod.ams1.secureserver.net. [188.121.43.193])
by mx.google.com with SMTP id ey18si3468336wid.19.2014.02.02.19.07.18
for <snipped>;
Sun, 02 Feb 2014 19:07:18 -0800 (PST)
Received-SPF: neutral (google.com: 188.121.43.193 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=188.121.43.193;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 188.121.43.193 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
Message-Id: <[email protected]>
Received: (qmail 31523 invoked from network); 3 Feb 2014 00:53:03 -0000
Received: from unknown (HELO N1NW8SHG119.ams1.gdhosting.gdg) ([188.121.41.119])
(envelope-sender <[email protected]>)
by n1nlshrout01.shr.prod.ams1.secureserver.net (qmail-ldap-1.03) with SMTP
for <snipped>; 3 Feb 2014 00:53:03 -0000
Date: Sun, 02 Feb 2014 17:53:03 -0700
Subject: NEW ORDER
To: <snipped>
X-PHP-Originating-Id: [8520701]
From: Mr Leo Price <[email protected]>
Reply-To: [email protected]
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit


Dear Exporter,

After viewing your advertised merchandise, we wish to introduce our company to you as we would require placing an order in your company.
We are an independent buying house based in UK and we would like to get a quotation on your products, we require your fairest prices as we would be making huge bulk purchases from time to time.

Please, remember to give us your mobile or contact numbers for easy communication.
Awaiting your soonest reply.

Mr Leo Price
Manager, Sales and Customer Relations,
Pingro Import & Export Ltd
Eastern Road, Farlington,
Portsmouth PO6 1UN,
United Kingdom
Email: [email protected]
Tel (+44) 7822171048
Fax (+44) 7822171148

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#190122 by Faizan Docherty Thu Feb 06, 2014 9:46 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.82.112.79<br>Originating ISP: Sonatel<br> City: Dakar<br>Country of Origin: Senegal<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp315493vcj;
Wed, 5 Feb 2014 16:42:36 -0800 (PST)
X-Received: by 10.15.10.73 with SMTP id f49mr1651788eet.2.1391647355431;
Wed, 05 Feb 2014 16:42:35 -0800 (PST)
Return-Path: <[email protected]>
Received: from outrelay01.libero.it (outrelay01.libero.it. [212.52.84.101])
by mx.google.com with ESMTP id x43si53015716eey.145.2014.02.05.16.42.19
for <multiple recipients>;
Wed, 05 Feb 2014 16:42:35 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 212.52.84.101 as permitted sender) client-ip=212.52.84.101;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 212.52.84.101 as permitted sender) [email protected]
X-CTCH-Spam: Unknown
X-CTCH-RefID: str=0001.0A0C0201.52F2DA6B.0007,ss=1,re=0.000,fgs=0
X-libjamoibt: 1587
Received: from wmail61 (172.31.0.58) by outrelay01.libero.it (8.5.140.03)
id 52EF758F007C14F9; Thu, 6 Feb 2014 01:42:18 +0100
Message-ID: <29082711.4853161391647338944.JavaMail.defaultUser@defaultHost>
Date: Thu, 6 Feb 2014 01:42:18 +0100 (CET)
From: "erico.laverdo21_2014" <[email protected]>
Reply-To: [email protected]
Subject: Hello
MIME-Version: 1.0
Content-Type: text/plain;charset="UTF-8"
Content-Transfer-Encoding: 7bit
X-SenderIP: 41.82.112.79
X-libjamv: azGJe09psBQ=
X-libjamsun: ZCs73FX7XtqkWno/B78Q3BXBxOq/pSK/P0el3vwq1bM=


Dear Sir/madam

We are International Trading Company, Ltd here in Italy ,We Imports &
Exports of all
kind of products and also we buy all kinds of product as well. We got your
contact email through a trade site,please if you are interested to do
business with our
company,please kindly reply as soon .

Best Regard.
Erico laverdo
EricoTrading Company Ltd

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#190205 by Faizan Docherty Fri Feb 07, 2014 2:03 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.190.3.8
Originating ISP: Etisalat-ng
City: n/a
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp387855vcj;
Thu, 6 Feb 2014 15:08:23 -0800 (PST)
X-Received: by 10.66.174.165 with SMTP id bt5mr3556332pac.151.1391728102480;
Thu, 06 Feb 2014 15:08:22 -0800 (PST)
Return-Path: <[email protected]>
Received: from metrokd.com (mail.metrokd.com. [182.160.126.66])
by mx.google.com with ESMTP id rx8si2653321pac.134.2014.02.06.15.08.20
for <snipped>;
Thu, 06 Feb 2014 15:08:22 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 182.160.126.66 as permitted sender) client-ip=182.160.126.66;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 182.160.126.66 as permitted sender) [email protected]
Received: (qmail 3377 invoked by uid 1008); 6 Feb 2014 23:09:34 -0000
Received: from unknown (HELO mail.metrokd.com) (127.0.0.1)
by metrokd.com with ESMTP; 6 Feb 2014 23:09:34 -0000
Received: from 41.190.3.8
(SquirrelMail authenticated user [email protected])
by mail.metrokd.com with HTTP;
Fri, 7 Feb 2014 05:09:34 +0600 (BDT)
Message-ID: <[email protected]>
Date: Fri, 7 Feb 2014 05:09:34 +0600 (BDT)
Subject: Quote Available Products And Prices
From: "Rachid Soraluk" <[email protected]>
Reply-To: [email protected]
User-Agent: SquirrelMail/1.4.8
MIME-Version: 1.0
Content-Type: text/plain;charset=iso-8859-1
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal


Dear Sir/Madam,

We have been directed to contact you for the purchase of your product,We
are interested in your products and are willing to discuss business with
your company.

kindly inform me about the available products,Minimum Order
Quantity,Delivery time or FOB, and payment terms warranty.

Regards

Mr Rachid soraluk
Director

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#190425 by AlanJones Sun Feb 09, 2014 6:18 am
Delivered-To: XXX
Received: by 10.194.125.176 with SMTP id mr16csp63758wjb;
Sat, 8 Feb 2014 19:28:06 -0800 (PST)
X-Received: by 10.14.87.129 with SMTP id y1mr2681712eee.38.1391916485984;
Sat, 08 Feb 2014 19:28:05 -0800 (PST)
Return-Path: <[email protected]>
Received: from cool.tjek.in (cool.tjek.in. [188.40.37.174])
by mx.google.com with ESMTPS id t5si17532084eeo.1.2014.02.08.19.28.05
for <XXX>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Sat, 08 Feb 2014 19:28:05 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of [email protected] designates 188.40.37.174 as permitted sender) client-ip=188.40.37.174;
Authentication-Results: mx.google.com;
spf=pass (google.com: best guess record for domain of [email protected] designates 188.40.37.174 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
Received: (qmail 9962 invoked by uid 1012); 8 Feb 2014 20:06:31 -0000
Date: 8 Feb 2014 20:06:31 -0000
Message-ID: <[email protected]>
To: XXX
Subject: Order Tetovo,Macedonia....
From: Victor Dritan <[email protected]>
Reply-To: [email protected]
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 8bit

Hi!

I would like to place an order on some of your products and if my personal freight company can ship directly to Tetovo,Macedonia.

1. Do you accept credit card Yes/No
2. What type of card do you accept Yes/No
3 Can you work hand in hand with my personal shipping agent ? and ship to me in Skopje Macedonia Yes/No

Thank you.


Victor Dritan

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#190623 by Faizan Docherty Tue Feb 11, 2014 1:08 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 209.85.128.193
Originating ISP: Google
City: Mountain View
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.126.40 with SMTP id mv8csp40960pdb;
Mon, 10 Feb 2014 03:58:14 -0800 (PST)
X-Received: by 10.42.61.4 with SMTP id s4mr728736ich.58.1392033494589;
Mon, 10 Feb 2014 03:58:14 -0800 (PST)
Return-Path: <[email protected]>
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com. [184.154.1.124])
by mx.google.com with ESMTPS id y7si13995288igl.56.2014.02.10.03.58.13
for <snipped>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Mon, 10 Feb 2014 03:58:14 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 184.154.1.124 as permitted sender) client-ip=184.154.1.124;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 184.154.1.124 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
Received: from mail-ve0-f193.google.com ([209.85.128.193]:58276)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1WCpV6-0007MX-PF
for <snipped>; Mon, 10 Feb 2014 05:58:13 -0600
Received: by mail-ve0-f193.google.com with SMTP id pa12so1254991veb.8
for <snipped>; Mon, 10 Feb 2014 03:58:12 -0800 (PST)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.52.188.41 with SMTP id fx9mr19534701vdc.19.1392031686258;
Mon, 10 Feb 2014 03:28:06 -0800 (PST)
Received: by 10.58.142.161 with HTTP; Mon, 10 Feb 2014 03:28:06 -0800 (PST)
Date: Mon, 10 Feb 2014 03:28:06 -0800
Message-ID: <CAG81Ag1ZjQux_rBmSaXXR_AKC3AZb+hJpaGJQdtRme9OGn=9uw@mail.gmail.com>
Subject: SUPPLY INVITATION OF YOUR PRODUCTS
From: JOHN OFORI <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=bcaec5485ca02cfb2904f20ba2a1
Bcc: <snipped>
X-Spam-Status: No, score=2.5
X-Spam-Score: 25
X-Spam-Bar: ++
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: DEAR SUPPLIERS, WE ARE AGENTS SOURCING FOR RELIABLE COMPANIES
THAT CAN SUPPLY TO OUR GOVERNMENT YOUR PRODUCT,ETC IN A LARGER QUANTITY FOR
ON GOING ECONOMIC COMMUNITY OF WEST AFRICAN STATE ( WEST AFRICA PROJECT GHANA)2014/2015
EXHIBITION CONTRACT SUPPLY HERE IN GHANA. [...]

Content analysis details: (2.5 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[209.85.128.193 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(oforijohn16[at]gmail.com)
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (oforijohn16[at]gmail.com)
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.5 CRM114_PROB_GOOD CRM114: CRM114_PROB_GOOD
X-Spam-Flag: NO
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - r8-chicago.webserversystems.com
X-AntiAbuse: Original Domain - <snipped>
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - gmail.com
X-Get-Message-Sender-Via: r8-chicago.webserversystems.com: none
X-Source:
X-Source-Args:
X-Source-Dir:


DEAR SUPPLIERS,

WE ARE AGENTS SOURCING FOR RELIABLE COMPANIES THAT CAN SUPPLY TO OUR
GOVERNMENT YOUR PRODUCT,ETC IN A LARGER QUANTITY FOR ON GOING ECONOMIC
COMMUNITY OF WEST AFRICAN STATE ( WEST AFRICA PROJECT GHANA)2014/2015
EXHIBITION CONTRACT SUPPLY HERE IN GHANA.

we are interested in your product and to do business with you or your
company, let us know if you can handle this supply;we need your product
list and specification including the price. contact me with this
information Below;

Our PAYMENT TERMS: is 80% advance payment via (T/T) by telegraphic
transfer,before Shipment 20% will complete to your company West Africa
Project Ghana

Please Contact me with this e-mail : [email protected].
Yours sincerely,


MR JOHN

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#190638 by Faizan Docherty Tue Feb 11, 2014 6:02 am
ipTRACKERonline.com wrote:Header Analysis Quick ReportOriginating IP: 195.238.20.211Originating ISP: Belgacom Skynet City: n/aCountry of Origin: Belgium* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.70.5 with SMTP id b5csp32335vcj;
Tue, 11 Feb 2014 00:56:26 -0800 (PST)
X-Received: by 10.194.201.134 with SMTP id ka6mr55708wjc.93.1392108985761;
Tue, 11 Feb 2014 00:56:25 -0800 (PST)
Return-Path: <[email protected]>
Received: from mailsec102.isp.belgacom.be (mailsec102.isp.belgacom.be. [195.238.20.98])
by mx.google.com with ESMTP id ly16si8165220wic.68.2014.02.11.00.50.20
for <multiple recipients>;
Tue, 11 Feb 2014 00:56:25 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 195.238.20.98 as permitted sender) client-ip=195.238.20.98;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 195.238.20.98 as permitted sender) [email protected]
X-Cloudmark-SP-Filtered: true
X-Cloudmark-SP-Result: v=1.1 cv=NiEJWGvu/B9ss3Gws9aE26GBJ7pRDJnP1rIXBAs9rfE= c=0 sm=2
p=8Q7zIUikAAAA:8 a=9cW_t1CCXrUA:10 a=IkcTkHD0fZMA:10
Received: from mailrmu003.isp.belgacom.be ([195.238.20.211])
by privrelay.isp.belgacom.be with ESMTP; 11 Feb 2014 09:25:11 +0100
Date: Tue, 11 Feb 2014 09:46:09 +0100 (CET)
From: Tongfa Trading Company <[email protected]>
Reply-To: Tongfa Trading Company <[email protected]>
Message-ID: <1685734168.161734.1392108369047.open-xchange@webmail.nmp.skynet.be>
Subject: Interested In your Product
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Priority: 3
Importance: Medium
X-Mailer: Open-Xchange Mailer v7.2.2-Rev27


Dear Sir/Madam,

I'm Val Bruinse from TONGFA TRADING COMPANY.We are interested in your product.
We
want to purchase most of your items and would like to know if they are very much
available,
We are based in Australia and England.Can you provide me with more information
regarding your product?I would appreciate it if you can reply to my email
([email protected]),asap

Regards,
Valentine Bruinse
Import/Export Manager
Tongfa Trading Company

Email: [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#190782 by AlanJones Wed Feb 12, 2014 2:08 pm
From [email protected]

Hello,

Do you ship to Ukraine and accept credit cards???

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#190840 by ducatigirl Thu Feb 13, 2014 5:39 am
I was recently scammed.
Sharples group ordered $2110 of my goods, I worked day and night for 3 weeks to make them, once I paid the bank to bank FREIGHT cost of $1,875, Mike sharples did a credit card charge back as I use the Paypal Here processing app, he initiated the charge back and his bank won. I am even required to pay for each of his 4 transactions, the chargeback fee! that made me furious. My bank said They would do a trace and recovery for the $1875 transfered to Rosario B. Alvirde (The fake freight company - AIR BUSINESS LOGISTICS) of
4205 W. Wilson Rd.
Lot 127 Harlingen
Texas, 78552
Yesterday I received a reply from ACCC and basically they said "Thank you for your scam report of 17 January 2014 to the Australian Competition and Consumer Commission (ACCC) via the SCAMwatch website.

Your report indicates you have lost money to a scam. I am sorry to hear this and want to ensure you are aware of some relevant support services that may be of assistance to you. If you require financial support you can contact Financial Counselling Australia on 1800 007 007. If you require extra support, you may wish to contact Lifeline on 13 11 14 or www.lifeline.org.au or beyondblue on 1300 224 636 or www.beyondblue.org.au.

Unfortunately, many scams originate overseas or take place over the internet, making them very difficult to track down and prosecute. If you lose money to a scam, it is unlikely you will be able to recover your loss. "

Is there anywhere I can go to get my money back? How are these people getting away with this?
I am just a small hobby started last May, and on disability pension. I was so excited about the order. The scammer even waited the 20 days for the money to clear through paypal, and promised me he was legit, when I asked all the questions and told him about my situation, how cruel these ppl are.

These people must be stopped!!! Is there other places I can go? Will the police help? I want to sue these bastards for emotional and physical damages.

the initial email that came was
Dear Sir/Ma,

I am interested in buying some of your products for our clients in Manila Philippines.While surfing for some purchases online,I came across that your company stocks some of our required goods and could help provide this items.We will be pleased to have this products purchased from you.

I will require your product catalog/web page of your products or current price list of products.

Shipping will be handled by a preferred Freight company of our choice who will arrange collection from your location and have goods sent to us via Airfreight on a reasonable price rate and this can only be done after goods have been fully paid for by us and confirmed ready for collection by you.

Our term of payment will be by a valid Visa/Master Credit Card.I await your prompt and expeditious handling on this purchase request.

Yours Sincerely
Sharples Group Ltd
C.E.O/OWNER
Mike Sharples
7685 St. Paul Road
San Antonio Village
Makati Metro Manila
Philippines
Phone:(0917) 242 0168
Email:[email protected]
#190914 by coinpuppy Thu Feb 13, 2014 11:56 pm
Hi Ducatigirl,

Thank you for posting the scammers information here.I am so sorry this happened to you. What happened in your case, is the person who scammed you was NOT the person whose name was on the email/paypal account, it was in reality a West African scammer who was pretending to be the person named on the emails. The money originated from a stolen paypal/credit card or bank account. You unfortunately will never get your money back (you also may get emails from people who will claim that they can help you get your money back...those are SCAMS...you have now been marked as a target..so be EXTRA careful). I know it is hard to deal with. These people have ZERO emotion towards what they are doing, and only care about money. In the future you can protect yourself by following Paypals guidelines TO THE LETTER, and NEVER EVER EVER wire money to anyone you do not personally know. There is NO valid reason in the world to not use a nationally recognized shipping company, and no legitimate business takes wire transfers as there only method of payment. You learned a hard expensive lesson. In these forums there is a wealth of knowledge. Arm yourself so that this never happens again. I am sorry for the random CAPS etc, I just really want you to understand. Ask anyone (including me) here any questions you may have.

Who is online

Users browsing this forum: No registered users and 13 guests