by Faizan Docherty
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 74.125.82.67
Originating ISP: Google
City: Mountain View
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.51.10 with SMTP id g10csp436541pdo;
Fri, 16 Jan 2015 10:48:38 -0800 (PST)
X-Received: by 10.66.66.203 with SMTP id h11mr24387946pat.131.1421434118863;
Fri, 16 Jan 2015 10:48:38 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (si-002-i152.relay.mailchannels.net. [108.178.49.164])
by mx.google.com with ESMTP id os5si6337452pab.197.2015.01.16.10.48.38
for <snipped>;
Fri, 16 Jan 2015 10:48:38 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 108.178.49.164 as permitted sender) client-ip=108.178.49.164;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 108.178.49.164 as permitted sender) smtp.mail=[email protected];
dkim=fail [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
X-Sender-Id: _forwarded-from|74.125.82.67
Received: from r8-chicago.webserversystems.com (ip-10-33-12-218.us-west-2.compute.internal [10.33.12.218])
by relay.mailchannels.net (Postfix) with ESMTPA id 795FE4018
for <snipped>; Fri, 16 Jan 2015 18:48:36 +0000 (UTC)
X-Sender-Id: _forwarded-from|74.125.82.67
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.224.7.213])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.2);
Fri, 16 Jan 2015 18:48:37 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|74.125.82.67
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1421434116694:939472801
X-MC-Ingress-Time: 1421434116694
Received: from mail-wg0-f67.google.com ([74.125.82.67]:48955)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YCBwh-0004uK-20
for <snipped>; Fri, 16 Jan 2015 12:48:35 -0600
Received: by mail-wg0-f67.google.com with SMTP id k14so5278798wgh.2
for <snipped>; Fri, 16 Jan 2015 10:48:33 -0800 (PST)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.180.126.99 with SMTP id mx3mr9117673wib.66.1421434113323;
Fri, 16 Jan 2015 10:48:33 -0800 (PST)
Received: by 10.27.142.197 with HTTP; Fri, 16 Jan 2015 10:48:33 -0800 (PST)
Date: Fri, 16 Jan 2015 10:48:33 -0800
Message-ID: <CADn2MMVa1AwUzCCnBRFPFZ3DXcn+oFqYDhmbKjPgKVzbNThk5w@mail.gmail.com>
From: Sgt Smith Cilia <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=e89a8f8389d1657c39050cc96b2b
X-Spam-Status: Yes, score=11.0
X-Spam-Score: 110
X-Spam-Bar: +++++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: -- Dear Friend, Greetings,,,,,,,,,,,Please pardon my indignation
for contacting you via this media. I have no option for now than to email
you..I really wish to have you as my good friend and also wishes to entrust
some funds into your care but i have already send the fund out of Iraq .I
need your sincere and truthful friendship. My name is Sgt Cilia Smith. I
am serving in United States of America Victory Camp near Baghdad . I have
$5.5 Million US dollars that I successfully moved out of the country. I need
a good partner someone I can trust. It is oil business money we did with
Iraqi citizens worth of 42 million US dollars, but the 5.5 million us dollars
stated is my share on the business and it’s legal. I have successfully
moved the funds out of Iraq as family valuables with help of Hercules Security
Diplomatic Company. The most important thing is ''' Can I Trust You? Once
the funds get to you, you take your 35% out and keep my own 65% . Your own
part of this deal is to find a safe place where my part of the funds will
be until i came to meet with you for discussions on investment plans, but
I have more interest on real estate or any other profitable investment. If
you are interested I will furnish you with more details. But the whole process
is simple and we must keep a low profile at all times. I look forward to
your reply and co-operation, and I thank you in advance as I anticipate your
co-operation waiting for your urgent response. My Regards, Sgt Cilia Smith
Please contact me in this e.mail address.. [email protected] [...]
Content analysis details: (11.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.6 URG_BIZ BODY: Contains urgent matter
3.6 NA_DOLLARS BODY: Talks about a million North American dollars
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(smithcilia01[at]gmail.com)
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[74.125.82.67 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (smithcilia01[at]gmail.com)
2.6 DEAR_FRIEND BODY: Dear Friend? That's not very dear!
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.0 LOTS_OF_MONEY Huge... sums of money
1.0 FREEMAIL_REPLY From and body contain different freemails
0.0 T_MONEY_PERCENT X% of a lot of money for you
3.8 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
X-Spam-Flag: YES
Subject: ***SPAM*** I need your help
X-AuthUser:
--
Dear Friend,
Greetings,,,,,,,,,,,Please pardon my indignation for contacting you via this media. I have no option for now than to email you..I really wish to have you as my good friend and also wishes to entrust some funds into your care but i have already send the fund out of Iraq .I need your sincere and truthful friendship. My name is Sgt Cilia Smith. I am serving in United States of America Victory Camp near Baghdad .
I have $5.5 Million US dollars that I successfully moved out of the country. I need a good partner someone I can trust. It is oil business money we did with Iraqi citizens worth of 42 million US dollars, but the 5.5 million us dollars stated is my share on the business and it’s legal. I have successfully moved the funds out of Iraq as family valuables with help of Hercules Security Diplomatic Company.
The most important thing is ''' Can I Trust You? Once the funds get to you, you take your 35% out and keep my own 65% . Your own part of this deal is to find a safe place where my part of the funds will be until i came to meet with you for discussions on investment plans, but I have more interest on real estate or any other profitable investment. If you are interested I will furnish you with more details.
But the whole process is simple and we must keep a low profile at all times.
I look forward to your reply and co-operation, and I thank you in advance as I anticipate your co-operation waiting for your urgent response.
My Regards,
Sgt Cilia Smith
Please contact me in this e.mail address.. [email protected]
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.



