by Faizan Docherty
Wed Oct 02, 2013 8:56 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 116.202.78.240<br>Originating ISP: 334,udyog Vihar<br> City: New Delhi<br>Country of Origin: India<br>* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.54.202 with SMTP id l10csp99324pdp;
Mon, 30 Sep 2013 02:11:51 -0700 (PDT)
X-Received: by 10.50.77.83 with SMTP id q19mr13084390igw.21.1380532311536;
Mon, 30 Sep 2013 02:11:51 -0700 (PDT)
Return-Path: <[email protected]>
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com. [184.154.1.124])
by mx.google.com with ESMTPS id i6si6457941igu.1.1969.12.31.16.00.00
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Mon, 30 Sep 2013 02:11:51 -0700 (PDT)
Received-SPF: neutral (google.com: 184.154.1.124 is neither permitted nor denied by domain of [email protected]) client-ip=184.154.1.124;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 184.154.1.124 is neither permitted nor denied by domain of [email protected]) [email protected]
Received: from outrelay01.libero.it ([212.52.84.101]:33425)
by r8-chicago.webserversystems.com with esmtp (Exim 4.80)
(envelope-from <[email protected]>)
id 1VQZW8-0007NZ-Pw
for <snipped>; Mon, 30 Sep 2013 04:11:50 -0500
X-CTCH-Spam: Unknown
X-CTCH-RefID: str=0001.0A0C0201.52494046.01FA,ss=1,re=0.000,fgs=0
X-libjamoibt: 1587
Received: from webmail56 (172.31.0.124) by outrelay01.libero.it (8.5.140.03)
id 5231BBA00252276F; Mon, 30 Sep 2013 11:11:34 +0200
Message-ID: <170412241.1480261380532294799.JavaMail.defaultUser@defaultHost>
Date: Mon, 30 Sep 2013 11:11:34 +0200 (CEST)
From: "[email protected]" <[email protected]>
Reply-To: "[email protected]" <[email protected]>
Subject: offer
MIME-Version: 1.0
Content-Type: application/msword; name=B.doc
Content-Transfer-Encoding: base64
X-SenderIP: 116.202.78.240
X-libjamv: 03p51/Tw4YQ=
X-libjamsun: zWd2IyA01T4XrLhZhZMPn3JnEFxfTk9rhzbUWAffj8o=
Content-Disposition: attachment; filename=B.doc; size=60416
X-Spam-Status: No, score=1.7
X-Spam-Score: 17
X-Spam-Bar: +
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: [...]
Content analysis details: (1.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(company1_uk2013[at]libero.it)
-0.0 SPF_PASS SPF: sender matches SPF record
-0.7 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (company1_uk2013[at]libero.it)
1.0 MISSING_HEADERS Missing To: header
-0.5 BAYES_05 BODY: Bayes spam probability is 1 to 5%
[score: 0.0288]
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
0.0 TVD_SPACE_RATIO TVD_SPACE_RATIO
0.0 T_FREEMAIL_DOC_PDF MS document or PDF attachment, from freemail
X-Spam-Flag: NO
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - r8-chicago.webserversystems.com
X-AntiAbuse: Original Domain - scamwarners.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - libero.it
X-Get-Message-Sender-Via: r8-chicago.webserversystems.com: none
X-Source:
X-Source-Args:
X-Source-Dir:
No message in the email. Contents of the attachment are as follows:
Attention: Dear Winner.
You have won £500,000.00 {Five Hundred Thousand British Pounds}. Your email id: was attached
to Lottery No. 05 12 13 35 38 47 BONUS 45 of draw No. 1781 in BBC NATIONAL LOTTERY UK.
Send your Data as listed below for Claims:
Name:
Address:
Age:
Phone:
Bank details:
Thanks for being part of this program. Congrats!!
MR. COLLINS JOE (CLAIMS MANAGER)
Tel: +448712346149,
Email: [email protected]
Copyright ©2013. Visit website on http://www.bbc.co.uk/lottery You are advice to send us your information via email below: Email ([email protected]) to enable us respond to you in time
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.