If you have been scammed, please post here and share your experience; it may help others avoid the same situation!
by valce Wed Oct 13, 2010 10:49 am
Hi, the folks at 419eater suggested I post this here as well. This looks like the right sub-board, sorry if it is not.

Here is the story. The message used by the scammer is below.


Last night, though, my friend got his account hacked and someone with terrible english asked all of his contacts for money.

Three things happened then.

First, I had a conversation with the scammer on IM, tried to confirm my friend's identity and when the scammer couldn't answer basic questions I notified all mutual contacts. I was very heavy handed, my goal was to prevent any damage, not to bait.

Second, and unbeknownst to me at the time, a mutual friend also had a conversation with the scammer, and she managed to confirm that a scam was going on without tipping them off. She got info for a Western Union transfer, an address in California, a second e-mail address and a phone number.

Finally, not long after the first two events, the actual owner of the account came online and deactivated the hacked account to prevent any further damage. A few people are still confused as of this morning, but hopefully we will clear that up.

Message:
Morning,

I'm sorry for this odd request because it might get to you too urgent but it's due to the situation of things right now. I came to Califonia 2 days ago for an urgent meeting and I'm stuck in Califonia right now, i was robbed, worse of it is that bags, cash and cards and my cell phone were stolen at GUN POINT, it's such a crazy experience for me, i need help flying back home, the authorities are not being 100% supportive but the good thing is i still have my Canadian passports and return tickets but currently having troubles paying off the hotel bills and also getting a cab to take me to the airport, my flight leaves in less than 24hrs from now. I need your help urgent. I'm freaked out at the moment. Please i need you to loan me some money, will refund you as soon as i'm back home, i promise. free to call me on the number not my cell because it was stolen: +35314429234
Advertisement

by Michelle Wed Oct 13, 2010 11:01 am
Welcome valce

Thank you for posting - it seems that things are under control and the account is back with its rightful owner.

Do you have the full/expanded headers for the e-mail?

The thing that is out of the ordinary for this type of scam is the telephone number. Unless I'm mistaken the number is a land line in Ireland.

Information on phone number range +353 1 442XXXX
Number billable as geographic number
Country or destination Ireland
City or exchange location Dublin Central
Original network provider* NTL Communications (Ireland) Ltd
by valce Thu Oct 14, 2010 9:35 am
The headers for the e-mail would just be my friend's hacked account address. One of my friends did get some Western Union transfer information from the scammer, though:

FIRST RECEIVER NAME: JENNIFER
SURNAME: PETTIJOHN
ADDRESS: 360 sutton way #15
grass valley Ca.95945
QUESTION? COLOR
ANSWER : RED
AMOUNT? $1500 US DOLLAR

EMAIL THE 10 DIGIT CONFIRMATION NUMBER TO THE HOTEL ADDRESS AFTER SENDING IT: [email protected]
by Michael Thu Oct 14, 2010 10:09 am
Hi Valce,

yes, the headers would come from your friend's adress but we can see from what geographical location the mail has been sent from - and that would definately not be his place :D

Please do post them (remove your and your friends email adress from the headers - they might show more than once) so we can learn something more regarding the phone number :)

Account inactive - messages are not being monitored
by valce Thu Oct 14, 2010 10:14 am
I did not know this! I found the headers, snipipng the e-mail addresses and names. Sorry, I'm not sure exactly which lines are important, so I left them all in.

(This was sent by gmail and received by my gmail account)

Delivered-To: <snip>
Received: by 10.216.6.213 with SMTP id 63cs120312wen;
Tue, 12 Oct 2010 19:46:54 -0700 (PDT)
Return-Path: <snip>
Received-SPF: pass (google.com: domain of <snip> designates 10.216.173.8 as permitted sender) client-ip=10.216.173.8;
Authentication-Results: mr.google.com; spf=pass (google.com: domain of <snip> designates 10.216.173.8 as permitted sender) smtp.mail=<snip; dkim=pass header.i=<snip>
Received: from mr.google.com ([10.216.173.8])
by 10.216.173.8 with SMTP id u8mr384689wel.9.1286938013751 (num_hops = 1);
Tue, 12 Oct 2010 19:46:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:mime-version:received:received:date:message-id
:subject:from:content-type;
bh=SifgP9Fojrm4ksmB4Vbt3/hBAe4UEGj37Dy9Q4lLfWM=;
b=MlUTK9Y4BTXvCLLIDJzktDO9x4vVYTgk3FGToYlShpgd6IDmXIsYkviw325hQmGKR6
cn3HQ4HySJKsV90NxRBVDpf9n5+/+5j+bcZjP2PunIKb9z9/SJi+fiKgP8NlH9JKw/4K
VzRS3ntrc/a64PYrijKWT+USgcdduMoDkpQHE=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:content-type;
b=wQOn7FaqGA1fs9da/6eo6C0yoq3mITngQTl/1rnCqZl7AfrWvxTX69GvgPCrUB+PEi
MV9Q4UJd7y98tbzRRFCtrSAPIm5jq6/ji2GDxkPENWN3Gdi1SyF9mNSU0zSJE5SisL3J
rta/cIcmSXhUq/Z/Zscl10TODHO63nhgPVcSA=
MIME-Version: 1.0
Received: by 10.216.173.8 with SMTP id u8mt384689wel.9.1286938007485; Tue, 12
Oct 2010 19:46:47 -0700 (PDT)
Received: by 10.216.242.12 with HTTP; Tue, 12 Oct 2010 19:46:47 -0700 (PDT)
Date: Wed, 13 Oct 2010 03:46:47 +0100
Message-ID: <[email protected]>
Subject: MORNING
From: <<snip>>
Content-Type: multipart/alternative; boundary=0016367fb011281b200492769b28

--0016367fb011281b200492769b28
Content-Type: text/plain; charset=ISO-8859-1
by Michael Thu Oct 14, 2010 11:34 am
Seeing how it was a gmail adress I sent a mail to the hotmail account to be able to trace it. (Gmail is one of the few providers that doesn't show where mails are sent from :?) From the headers coming from the hotmail adress you gave us I got this result:

41.155.74.34 Nigeria (Lagos)*

No surprise there :D

Account inactive - messages are not being monitored
by Michelle Thu Oct 14, 2010 12:39 pm
In that case I'm guessing that the scammer keyed the phone number incorrectly.

Nigerian phone numbers start with "234" not end with it.

ie, +23435314429 and not +35314429234

Information on phone number range +234 35 XXXXXX
Number billable as geographic number
Country or destination Nigeria
City or exchange location Oshogbo

Who is online

Users browsing this forum: ClaudeBot and 2 guests