by agilly1989
Wed Nov 21, 2012 6:13 pm
Luckily I found this forum... I was smart enough to do a tin-eye/google image search of the pictures that the person sent me and i found out that 1 or 2 of the pictures were stolen
They claim to be this "Courtney Gielber" and I did some tracking...
The Email header points to Lagos, Nigeria and to a ISP named AFRINIC... They have a WHOIS search and I put in the IP address that was in the header and i found that the person that owns that IP address (At time of posting) is a guy named "Fred Young" (did a facebook search and found this guy: https://www.facebook.com/f2Young?ref=ts&fref=ts)
This is the Email Header
From the AFRINIC WhoIs Server
They claim to be this "Courtney Gielber" and I did some tracking...
The Email header points to Lagos, Nigeria and to a ISP named AFRINIC... They have a WHOIS search and I put in the IP address that was in the header and i found that the person that owns that IP address (At time of posting) is a guy named "Fred Young" (did a facebook search and found this guy: https://www.facebook.com/f2Young?ref=ts&fref=ts)
This is the Email Header
Code: Select all
Delivered-To: [email protected]
Received: by 10.152.112.9 with SMTP id im9csp535973lab;
Wed, 21 Nov 2012 01:03:47 -0800 (PST)
Received: by 10.66.79.168 with SMTP id k8mr15864566pax.12.1353488626257;
Wed, 21 Nov 2012 01:03:46 -0800 (PST)
Return-Path: <[email protected]>
Received: from nm16-vm6.bullet.mail.gq1.yahoo.com (nm16-vm6.bullet.mail.gq1.yahoo.com. [98.137.177.254])
by mx.google.com with ESMTPS id gk10si21797567pbc.356.2012.11.21.01.03.45
(version=TLSv1/SSLv3 cipher=OTHER);
Wed, 21 Nov 2012 01:03:46 -0800 (PST)
Received-SPF: pass (google.com: best guess record for domain of [email protected] designates 98.137.177.254 as permitted sender) client-ip=98.137.177.254;
Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of [email protected] designates 98.137.177.254 as permitted sender) [email protected]; dkim=pass [email protected]
Received: from [98.137.12.56] by nm16.bullet.mail.gq1.yahoo.com with NNFMP; 21 Nov 2012 09:03:45 -0000
Received: from [98.137.12.225] by tm1.bullet.mail.gq1.yahoo.com with NNFMP; 21 Nov 2012 09:03:45 -0000
Received: from [127.0.0.1] by omp1033.mail.gq1.yahoo.com with NNFMP; 21 Nov 2012 09:03:45 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 34332 invoked by uid 60001); 21 Nov 2012 09:03:45 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1353488625; bh=YR89wIoe7AX+y7/xUrcManpCyrG1iwwmbitdP9zv9lU=; h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Subject:To:In-Reply-To:MIME-Version:Content-Type; b=SsG5p61DQXg0U5AlGd1L/MWi372+FAyWewm9XAZdFTbGALuSFXhibqNMqSxc7nrTxvr3acxRxgA7x01po/KAA/PM9CNqFmNZw1KxMY9eVGJkjUaCJVn/zP+K7OxIAYHBIwlSYo6jtNXrPCcaEhAEjhgcj5ZAmFIsanTyshYU00k=
DomainKey-Signature:a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Subject:To:In-Reply-To:MIME-Version:Content-Type;
b=o8T8Vh1TcVqGkgGTT5DNCg6VWjwprbkbgeDEVrkTF9J4jVU2gTDpllUrECCYOHgkS7f0NQgJ12H1TjbsuKTOJKDM9mO6knq47js2doyh1PS5mpxXHexV60DxlND1FHIyYAhyOW5eLkTrRLYyaXu6FSRd8YI80RsigbA/TgzCHNI=;
X-YMail-OSG: 7ilcBjIVM1mqGMVyoHgzEEp3RFKqit3IL0m7VB3FWN0k8QP
rQ62TkFFLJ0ZddT26JW3m_otYYt6v4.rlk_ykmK3NHqWLM.5i7aL1RPaMScS
69mpw23WFuGd42N4lJbRRyV_idoJvpJDAheF_j5NtCY_nQorPE8YkrkaqPvj
SLjpbkK9rdwE1zCaqBQzg3X15RO_JiDYu4tjvXR4Is5i6Q8sLVLIAVN9UkHT
G_2CeE8IzCF8csX2z.sibk1jvDwny3bDW5vyOUb_RmWvWdSU.F4.MN5la7Va
WEpEl0xg0OkCiLGW9gAGjf7vqY2eqWFDn5VCu6jaEw1xmP_qoDDRp1PyDXzM
QCIvmBNiWHwWP7AmYEzzhLOKfqkochtSpWR0nkp11hLmd1kFn2lKChVclSmO
bZaYtSY5n04Zn1DyjCbZIZ9DlxsVD3W_k0zMDRFrip5Y75PSk1JdT46A.T37
5VcOlqXxAYib3n7im4t15vy2T3Gf2Mkjj671bKZBVvDgQCX8-
Received: from [41.138.171.224] by web163503.mail.gq1.yahoo.com via HTTP; Wed, 21 Nov 2012 01:03:44 PST
X-Rocket-MIMEInfo: 001.001,SGVsbG8gQWRpbiwNCsKgCiBUaGFua3MgZm9yIHRoZSByZXNwb25kIG9uY2UgYWdhaW4gLi4gSG93IGFyZSB5b3UgZG9pbmcgPyBXZWxswqAgd2hhdCBhIGdvb2QgcmVzcG9uc2UgdG8gdGhlIApxdWVzdGlvbnMuIEkgYWRvcmUgeW91IGFuZCBJIGFtIG9wZW5pbmcgbXkgaGVhcnQgdG8geW91LiBKdXN0IG5lZWQgeW91IAp0byBiZSBlYXNlIHdpdGggaXQuIEkgZmVlbCBzbyBzYWZlIGFuZCBzZWN1cmUgaW4geW91LiBDYW4geW91IGJlIHRoZSBtYW4KIHlvdSBoYXZlIGlsbHVzdHJhdGVkIGluIHlvdXIgd3JpdHQBMAEBAQE-
X-Mailer: YahooMailClassic/15.0.8 YahooMailWebService/0.8.123.460
Message-ID: <[email protected]>
From the AFRINIC WhoIs Server
Code: Select all
% This is the AfriNIC Whois server.
% Information related to '41.138.171.0 - 41.138.171.255'
inetnum: 41.138.171.0 - 41.138.171.255
netname: VISAFONE-LAGOS-PDSN3
descr: Visafone Communications Limited,
descr: 12, Ologun Agbaje Street,
descr: Victoria Island,
descr: Lagos
country: NG
admin-c: FY2-AFRINIC
tech-c: FY2-AFRINIC
status: ASSIGNED PA
mnt-by: VISAFONE-MNT
remarks: Managed by Network Solutions Provider [VISAFONE]
notify: [email protected]
notify: [email protected]
changed: [email protected] 20100729
source: AFRINIC
parent: 41.138.160.0 - 41.138.191.255
person: Fred Young
nic-hdl: FY2-AFRINIC
address: 33 Saka Tinubu Street
address: Victoria Island
address: Lagos Nigeria
address: Lagos
address: Nigeria
e-mail: [email protected]
phone: +2347025001203
fax-no: +23412624287
changed: [email protected] 20090729
changed: [email protected] 20091124
changed: [email protected] 20100120
changed: [email protected] 20100602
changed: [email protected] 20110211
changed: [email protected] 20120404
source: AFRINIC