Scams re-targeting those who have already been victimized
by Tim Atem Sat Dec 26, 2015 10:37 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.190.2.66
Originating ISP: Emts-nigeria-as
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.37.203.13 with SMTP id b13csp928150ybg;
Sat, 12 Dec 2015 17:03:46 -0800 (PST)
X-Received: by 10.129.37.8 with SMTP id l8mr14242670ywl.133.1449968626229;
Sat, 12 Dec 2015 17:03:46 -0800 (PST)
Return-Path: <[email protected]>
Received: from 10ibl21ser04.datacenter.cha.cantv.net (10ibl21ser04.datacenter.cha.cantv.net. [200.11.173.10])
by mx.google.com with ESMTPS id e67si14799790ywc.358.2015.12.12.17.03.35
(version=TLS1 cipher=AES128-SHA bits=128/128);
Sat, 12 Dec 2015 17:03:46 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) client-ip=200.11.173.10;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) [email protected]
X-Virus-Scanned: amavisd-new at cantv.net
Received: from webmail-05.datacenter.cha.cantv.net (webmail-05.datacenter.cha.cantv.net [200.11.153.88])
(authenticated bits=0)
by 10ibl21ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with ESMTP id tBD13TiD025644;
Sat, 12 Dec 2015 20:33:29 -0430
X-Matched-Lists: []
Received: from 41.190.2.66 ([41.190.2.66]) by webmail-05.datacenter.cha.cantv.net (Cantv Webmail) with HTTP; Sat, 12 Dec 2015 20:33:28 -0430 (VET)
Date: Sat, 12 Dec 2015 20:33:28 -0430 (VET)
From: Donald Duke <[email protected]>
Reply-To: [email protected]
To: [email protected]
Message-ID: <358746937.4303176.1449968609689.JavaMail.gess@webmail-05.datacenter.cha.cantv.net>
Subject: ATTN!!!
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Mailer: Cantv Webmail
X-Originating-IP: [41.190.2.66]


I felt expedient to write you this wicked conspiracy hatched by duo of justice T.Y Waziri and the ministry of finance staffs with numerous fake name want to divert your monies to Europe to their account. This why i decide to alert you concerning what is going, Dept of homeland security are holding the monies for clarifications reason, they are frustrating you by asking for endless fees. Noted I have your transaction reference number and contact of Officer in charge of your fund. I can never be a part of evil.
Yours
Rev. Fr. Donald

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5
Advertisement

by Tim Atem Sun Dec 27, 2015 11:32 am
Same exact script from a different name and email address.

ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.190.2.175
Originating ISP: Emts-nigeria-as
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.37.1.195 with SMTP id 186csp214317ybb;
Thu, 17 Dec 2015 00:40:10 -0800 (PST)
X-Received: by 10.13.194.134 with SMTP id e128mr18782329ywd.57.1450341610209;
Thu, 17 Dec 2015 00:40:10 -0800 (PST)
Return-Path: <[email protected]>
Received: from 10ibl21ser04.datacenter.cha.cantv.net (10ibl21ser04.datacenter.cha.cantv.net. [200.11.173.10])
by mx.google.com with ESMTPS id x3si7363734ywe.8.2015.12.17.00.39.57
(version=TLS1 cipher=AES128-SHA bits=128/128);
Thu, 17 Dec 2015 00:40:10 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) client-ip=200.11.173.10;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 200.11.173.10 as permitted sender) [email protected]
X-Virus-Scanned: amavisd-new at cantv.net
Received: from webmail-02.datacenter.cha.cantv.net (webmail-02.datacenter.cha.cantv.net [200.11.153.85])
(authenticated bits=0)
by 10ibl21ser04.datacenter.cha.cantv.net (8.14.3/8.14.3/3.0) with ESMTP id tBH8dqJj027505;
Thu, 17 Dec 2015 04:09:52 -0430
X-Matched-Lists: []
Received: from 41.190.2.175 ([41.190.2.175]) by webmail-02.datacenter.cha.cantv.net (Cantv Webmail) with HTTP; Thu, 17 Dec 2015 04:09:52 -0430 (VET)
Date: Thu, 17 Dec 2015 04:09:52 -0430 (VET)
From: Donald Duke <[email protected]>
Reply-To: [email protected]
To: [email protected]
Message-ID: <451936474.4496748.1450341592289.JavaMail.gess@webmail-02.datacenter.cha.cantv.net>
Subject: Attention!!!
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Mailer: Cantv Webmail
X-Originating-IP: [41.190.2.175]


I felt expedient to write you this wicked conspiracy hatched by duo of justice T.Y Waziri and the ministry of finance staffs with numerous fake name want to divert your monies to Europe to their account. This why i decide to alert you concerning what is going, Dept of homeland security are holding the monies for clarifications reason, they are frustrating you by asking for endless fees. Noted I have your transaction reference number and contact of Officer in charge of your fund. I can never be a part of evil.
Yours
Sgt Donald

====================================
PLEASE DO NOT TELL A SCAMMER HE IS REPORTED HERE!

Learn what a scam is and how to protect yourself
https://www.scamwarners.com/forum/viewtopic.php?f=3&t=5

Who is online

Users browsing this forum: ClaudeBot and 1 guest