Learn about us and introduce yourself
by Mikkel Thu Dec 22, 2011 2:10 pm
Hello everyone.

I'm a scambaiter, using the same name as I do on Eater. I won't be posting here that often, only to post up scripts.

I have started setting up an e-mail account for a fake scammer, sending out e-mail that offer free formats to scammers. A fellow Eater member pointed out that it would be a good idea to post the scripts at a scam warning site, so an actual victim won't be fooled by the scripts I throw at a bunch of scammers. So my questions is: Where do I post those formats on scamwarners?
Advertisement

by David Jansen Thu Dec 22, 2011 7:39 pm
Welcome here TheProbie.

You have a PM.

Being a victim doesn't mean you stand alone. We're here to help you.
by ashland1974 Mon Jan 02, 2012 10:17 pm
This is the header from one of the first email i received from Tom Wedel Warrent Officer in US Army stationed in Afghan. as you can see he is located in NY city! [email protected] Tom mentioned a mother in law, who took daughter to nigeria as a Mary Williams.
His "daughter Diane" email is [email protected] her header acturally came from Lagos Nigeria. i have person name from nigeria whom I sent money order from, in fact there is one at a money gram where the clerk in KY misspelled the receivers name, so it has not been picked up. I will send you all the information I have, just let me know who to send it.

ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.98.24.39
Originating ISP: Pegasus Web Technologies
City: Clifton
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline

Copy To Clipboard



Email header analysis report
All valid IP Addresses found in the header.
Ip Address 3rd Party Info Provider City Flag Country
* 65.98.24.39 Pegasus Web Technologies Clifton United States
212.82.108.239 Dublin Ireland
77.238.189.53 n/a Ireland
by Dotti Mon Jan 02, 2012 11:35 pm
If you have sent money and it has not been picked up, you need to contact moneygram and have the transaction cancelled ASAP.

The scammer is not located in New York. The IP you posted has been connected several times with spam also, which means it is either a proxy or a compromised server that is being misused. Since the scammer is most likely playing the roles of both father and daughter, you can be pretty certain he is in Nigeria.

Need to post photos? http://scamwarners.com/forum/viewtopic.php?f=28&t=3219
Are you a victim of a romance scam? Read here for advice and FAQ's.
by ashland1974 Thu Jan 19, 2012 1:26 pm
His so called daughter is using this email address:
[email protected]
using the name of Diana Thomas
by ashland1974 Thu Jan 19, 2012 1:28 pm
Diana Thomas full header from email

From Diana Thomas Wed Sep 14 09:17:03 2011
X-Apparently-To: [email protected] via 67.195.23.77; Wed, 14 Sep 2011 02:17:04 -0700
Return-Path: <[email protected]>
Received-SPF: none (domain of ymail.com does not designate permitted sender hosts)
X-YMailISG: U9G2bxoWLDtfreC3eK03jFc8qYUFMVpi7jDlkqwd_ezWaXyN
Qdu2fMB4iXcWuHP_AgZ2QUxsTBRXVRawtgi0PLe4QxyzDQWqyBC2bs9iA.NQ
S6p9mTSVnOjM3AaGG_w27rBzzD5xqenZne7BEaUB.I6zR9g8vV85rW1DdEB7
ArW_B1ZDf7afrjztKGRoAXU6LcVFMfBLr_S5ENrpmvjdSEzVgG.lQ8nHFWrZ
X.fAUhAG0qKV0V.BRTerdRTFW90l7F06CSBOg9T7cTELwD5UgohHQU4Sx2Hp
WapG3YhWpu5ziQwdI12OsYdLR3UK9BBO8L35VLdUaxJqfca_DaDAE8_.KAOf
w2Fw8aHKkxcxiSayrK2HPju1vYFCW_J74EV8qNEJEbgByUgjWjI1tED5.g6Y
y4E7_nmgvg8ZfUjlHfahQOfgdmfX0Fme9Ewp5cbZxeQlNoKy1pc.2k5VqEIh
TUIrYra55WyX0Hm4lwbb73gFPAbWxGNtbvetkNDoMZ9q9_pE5CSAWPuZ35zm
wcEMFIZ9iJqCIGX6sdWXpr1WjdIBourwhPhjVQIFVDbu3ueWn1I2JVpaaTY3
Mnq7s3ytpPryzB4siISM.zuTif5lwa7q_8zGc47_jPCYolTGQktTTX5MvjfP
y4IWlnNLj2x5EW4014r8.ew3Zo3INqukGTWev6195TrPi5gA.f7kNBUvNvYA
Nb420ZLmpORDDGie1U9dXmd7AfPq_EhUR50A4Eod3IpY9G4brzdI7eFuDn7.
rrtiMrzShKO7UyAwOZQZzcwjKw9BummHPlzaGn3PtCFo6ZszeIT5iYZ.aDgw
yaQuuEJMUJJfeFfUgXXXwRJZq7X6FDAIbSii4oXHvJVZo.7zGmW5CUycZ28v
13yKPnc1HH_ZJxS.VBuntQdi2UfE3Hp4thBfeXW8c0lALSWWwyLTOLhRqVN2
.k9N6VTrcYi6VrHt4u8GVJz8raWz.pX_aMkE.1m814rCJbHeYUfWGrNXNfdn
lpm2MlXc6T5gfzx7_8x99Cn6M1Ims7Xx4jPnTYSPvlfN3y.y8Bqy5e3hevIv
AWcOTj5EFsSuhdC4xe3Ew9rDUHGdy33KSsIw7iJHYc9IAUpaT3IpZw0__rC6
s2KZRQ--
X-Originating-IP: [98.138.90.157]
Authentication-Results: mta1055.mail.ac4.yahoo.com from=ymail.com; domainkeys=pass (ok); from=ymail.com; dkim=pass (ok)
Received: from 127.0.0.1 (HELO nm9-vm2.bullet.mail.ne1.yahoo.com) (98.138.90.157)
by mta1055.mail.ac4.yahoo.com with SMTP; Wed, 14 Sep 2011 02:17:04 -0700
Received: from [98.138.90.54] by nm9.bullet.mail.ne1.yahoo.com with NNFMP; 14 Sep 2011 09:17:03 -0000
Received: from [98.138.89.233] by tm7.bullet.mail.ne1.yahoo.com with NNFMP; 14 Sep 2011 09:17:03 -0000
Received: from [127.0.0.1] by omp1048.mail.ne1.yahoo.com with NNFMP; 14 Sep 2011 09:17:03 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 71362 invoked by uid 60001); 14 Sep 2011 09:17:03 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ymail.com; s=s1024; t=1315991823; bh=I5aAYtyuLSuhV9T8KQok6dmtsZIbD1H+X6kz3X5VzAM=; h=X-YMail-OSG:Received:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Content-Type; b=rYjT+iOhWiFNlS9xVeGgOHp4s42VvHKY56SW9TCFhZCRuJNXxGCXkPPXK+XqTjcAzrzOf99GN9cp74WKRyw9dskVQ5PWL2TkztxbKPI0ioDr+iI28JdTUusl+EgQojBcmYLV1cFl4e5xKOgges9UQbezPRbUv25Vyd84wu0b2ec=
DomainKey-Signature:a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=ymail.com;
h=X-YMail-OSG:Received:X-Mailer:Message-ID:Date:From:Subject:To:MIME-Version:Content-Type;
b=DZevDZN4ogFTXVgsj4YZQtilXRhCENI6J1A4U/zmxaWnIMMpJp+uNoDa0BiXOeIlb90itvi1O4nQenxp32ff/QYIo9g3w4R00Gwu3iaTxK98HQ89TyOywGXkdhHixx8NnofgLTRpNEg3k+veB1gvusU84gMJfXEs522ZtAsG6+w=;
X-YMail-OSG: fzyk7OoVM1l_c8PCiPsVZYX0e_JbFwz6bxXqj0Dhdc6iXb8
X7DKJqeHwoXt.yfVmaJoEtXiGsQsrEzfpvxn69OWQ07hyBgbiZ3LqmfXIqF7
3Mfa3zYvpSbbdv9gJrkOO9UKrNztD2ZANVzJnyEtaBp1XrgBVkjhbbpY1sJS
IZe8B5vjDcWDn3AikovN6EkDkgVNTgfp55j1.vZPsLuKyhwasMszpUZ7edCB
F0dhyiDHx24PBss3AgbPuUldYq8Q7XYiJaXSqazAGtAozdeWuOpaTKoxy.RY
nNEU4N_fhGwdvk1BHu2gazDzq3GqiMxSNPNcOFpPOZSxtJjsw1msgU0orTC3
dKkHBlWOnooQ4o2dthgDpw45hpB6rdace8gnsm1VMRGdKeR_pwGLyvA--
Received: from [41.138.187.199] by web121118.mail.ne1.yahoo.com via HTTP; Wed, 14 Sep 2011 02:17:03 PDT
X-Mailer: YahooMailClassic/14.0.5 YahooMailWebService/0.8.114.317681
Message-ID: <[email protected]>
Date: Wed, 14 Sep 2011 02:17:03 -0700 (PDT)
From: Diana Thomas <[email protected]>
Subject: Hello Mrs.Kathy
To: [email protected]
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-2063913594-1315991823=:52242"
Content-Length: 2303
by AlanJones Thu Jan 19, 2012 1:30 pm
An analysis of that header gives

ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.138.187.199
Originating ISP: Visafone Communications Limited
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


So as Dotti said, it's likely that the same scammer (or one of his group) is playing the daughter

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.

Who is online

Users browsing this forum: ClaudeBot and 2 guests