Advance fee loan scams and fraudulent loan sites.
by buried under 419s Sat Mar 23, 2019 7:05 pm
Return-path: <[email protected]>
Envelope-to:
Delivery-date: Sat, 23 Mar 2019 14:04:17 -0700
Received: from [188.166.95.127] (port=59262 helo=mail.besamas.ga)
by with esmtp (Exim 4.89)
(envelope-from <[email protected]>)
id 1h7noK-0007Ak-VG
for ; Sat, 23 Mar 2019 14:04:17 -0700
Received: from [0.2.231.4] (unknown [217.61.104.101])
by mail.besamas.ga (Postfix) with ESMTPA id 3C87F7938B6;
Sat, 23 Mar 2019 07:44:15 +0000 (UTC)
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
To: Recipients <[email protected]>
From: "Jesse Peterson" <[email protected]>
Date: Sat, 23 Mar 2019 08:44:13 +0100
Reply-To: [email protected]
X-Spam-Status: Yes, score=15.8
X-Spam-Score: 158
X-Spam-Bar: +++++++++++++++
X-Spam-Report: Spam detection software, running on the system "",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: We offer loans to individuals and firms at low interest rates
of 2%. We give out loan for Debt Consolidation,Home Improvements, Car Purchase,A
New Home,Investment/Business Expansion Purposes or Even a vacation. [...]


Content analysis details: (15.8 points, 7.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
3.3 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[188.166.95.127 listed in zen.spamhaus.org]
-0.0 SPF_PASS SPF: sender matches SPF record
1.8 PYZOR_CHECK Listed in Pyzor (https://pyzor.readthedocs.io/en/latest/)
1.6 MISSING_MID Missing Message-Id: header
1.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Spam-Flag: YES
Subject: ***SPAM*** Loan Offer

We offer loans to individuals and firms at low interest rates of 2%. We give out
loan for Debt Consolidation,Home Improvements, Car Purchase,A New
Home,Investment/Business Expansion Purposes or Even a vacation.

In our loan scheme both local and international clients have the guarantee of
obtaining a loan from this company on the mode of unsecured offshore international
funding which means no collateral is required for this process.

Contact us for more inquiries via this email [email protected]

Regards
Jesse Peterson
[email protected]

Questions about scams? fraudatiocruor @ gmail.com to contact remove spaces
Advertisement

by HillBilly Mon Jun 24, 2019 8:16 pm
Received: from mta1.prodia.co.id (117.54.211.182) by
BY2NAM01FT050.mail.protection.outlook.com (10.152.69.9) with Microsoft SMTP
Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.2008.13 via Frontend Transport; Mon, 24 Jun 2019 22:41:12 +0000
Received:1694;Count:18
Received: from mta1.prodia.co.id (localhost.localdomain [127.0.0.1])
by localhost (Email Security Appliance) with SMTP id BA1F3B6B759_D114F9BB;
Mon, 24 Jun 2019 22:32:59 +0000 (GMT)
Received: from localhost (unknown [172.16.212.38])
by mta1.prodia.co.id (Sophos Email Appliance) with ESMTP id 792E8B68F1B_D114F9BF;
Mon, 24 Jun 2019 22:32:59 +0000 (GMT)
X-Virus-Scanned: amavisd-new at
Received: from zpromtap2f.prodia.co.id ([127.0.0.1])
by localhost (zpromtap2f.prodia.co.id [127.0.0.1]) (amavisd-new, port 10026)
with ESMTP id Dgx0phPBr46e; Tue, 25 Jun 2019 05:28:18 +0700 (WIB)
Received: from zprombox1f.prodia.co.id (zprombox1f.prodia.co.id [172.16.212.36])
by zpromtap2f.prodia.co.id (Postfix) with ESMTP id 64AC02164D4A;
Tue, 25 Jun 2019 05:28:17 +0700 (WIB)
Date: Tue, 25 Jun 2019 05:28:17 +0700 (WIB)
From: Jesse Peterson <[email protected]>
Reply-To: Jesse Peterson <[email protected]>
Message-ID: <[email protected]>
Subject: Loan Offer
X-Mailer: Zimbra 8.7.11_GA_3800 (zclient/8.7.11_GA_3800)
Thread-Index: s3K5S3xyCzrPWubPeGYTBgck8RUiKQ==
Thread-Topic: Loan Offer
X-SASI-RCODE: 200
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=prodia.co.id; h=date:from:reply-to:message-id:subject:mime-version:content-type; s=prodia; bh=bZrpnxKyc1v4HZy4yrOkGixTK3t4Iq39p499oFnav/g=; b=LOSoAMevgi4+k92MXD/RGKkS5DjGwxO3eHm6zf/wH+uwgmUmYE4/Fk593eQZbsBje2+2myFRZz3N2eQ1FldYiMzrJNoN2Qjd+ow8jssza5WRfgRnvspC7jkHiACvTOR89XoZbKImx0KF+e+0t+oz/qpZKcstVtxOkP3AefHbACQ=
X-IncomingHeaderCount: 18
To: Undisclosed recipients:;
Return-Path: [email protected]
X-Sender-IP: 117.54.211.182

We offer loans to individuals and firms at low interest rates of 2%. We give out loan for Debt Consolidation,Home Improvements, Car Purchase,A New Home,Investment/Business Expansion Purposes or Even a vacation.

In our loan scheme both local and international clients have the guarantee of obtaining a loan from this company on the mode of unsecured offshore international funding which means no collateral is required for this process.

Note for more inquiries about loan all email should be sent to [email protected]

Regards
Jesse Peterson
[email protected]


Address lookup
canonical name interventionmortgagefirm.org.
aliases
addresses 208.91.198.96
Domain Whois record

Queried whois.publicinterestregistry.net with "interventionmortgagefirm.org"...

Domain Name: INTERVENTIONMORTGAGEFIRM.ORG
Registry Domain ID: D402200000007980517-LROR
Registrar WHOIS Server: whois.namesilo.com
Registrar URL: www.namesilo.com
Updated Date: 2018-12-17T03:46:42Z
Creation Date: 2018-10-17T13:32:24Z
Registry Expiry Date: 2019-10-17T13:32:24Z
Registrar Registration Expiration Date:
Registrar: Namesilo, LLC
Registrar IANA ID: 1479
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4805240066
Reseller:
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registrant Organization: See PrivacyGuardian.org
Registrant State/Province: AZ
Registrant Country: US
Name Server: NS5.HOSTFRICA.COM
Name Server: NS6.HOSTFRICA.COM
DNSSEC: unsigned
URL of the ICANN Whois Inaccuracy Complaint Form https://www.icann.org/wicf/)
>>> Last update of WHOIS database: 2019-06-25T00:07:00Z <<<

Network Whois record

Queried whois.arin.net with "n 208.91.198.96"...

NetRange: 208.91.198.0 - 208.91.199.255
CIDR: 208.91.198.0/23
NetName: PUBLICDOMAINREGISTRY-NETWORKS
NetHandle: NET-208-91-198-0-1
Parent: NET208 (NET-208-0-0-0-0)
NetType: Direct Allocation
OriginAS: AS394695
Organization: PDR (PSUL-1)
RegDate: 2011-04-15
Updated: 2018-11-29
Ref: https://rdap.arin.net/registry/ip/208.91.198.0


OrgName: PDR
OrgId: PSUL-1
Address: P.D.R Solutions LLC, 10, Corporate Drive, Suite 300
City: Burlington
StateProv: MA
PostalCode: 01803
Country: US
RegDate: 2015-08-04
Updated: 2015-11-24
Ref: https://rdap.arin.net/registry/entity/PSUL-1


OrgNOCHandle: NOC32406-ARIN
OrgNOCName: NOC
OrgNOCPhone: +1-415-230-0680
OrgNOCEmail: [email protected]
OrgNOCRef: https://rdap.arin.net/registry/entity/NOC32406-ARIN

OrgAbuseHandle: ABUSE5185-ARIN
OrgAbuseName: Abuse Admin
OrgAbusePhone: +1-415-230-0648
OrgAbuseEmail: [email protected]
OrgAbuseRef: https://rdap.arin.net/registry/entity/ABUSE5185-ARIN

OrgTechHandle: TECH953-ARIN
OrgTechName: Tech
OrgTechPhone: +1-415-230-0680
OrgTechEmail: [email protected]
OrgTechRef: https://rdap.arin.net/registry/entity/TECH953-ARIN

DNS records
name class type data time to live
interventionmortgagefirm.org IN MX
preference: 20
exchange: mx2.zoho.com
14400s (04:00:00)
interventionmortgagefirm.org IN MX
preference: 50
exchange: mx3.zoho.com
14400s (04:00:00)
interventionmortgagefirm.org IN MX
preference: 10
exchange: mx.zoho.com
14400s (04:00:00)
interventionmortgagefirm.org IN SOA
server: ns5.hostfrica.com
email: [email protected]
serial: 2018101706
refresh: 3600
retry: 7200
expire: 1209600
minimum ttl: 86400
86400s (1.00:00:00)
interventionmortgagefirm.org IN NS ns5.hostfrica.com 86400s (1.00:00:00)
interventionmortgagefirm.org IN NS ns6.hostfrica.com 86400s (1.00:00:00)
interventionmortgagefirm.org IN A 208.91.198.96 14400s (04:00:00)
96.198.91.208.in-addr.arpa IN HINFO
CPU: RFC8482
OS:
3789s (01:03:09)
198.91.208.in-addr.arpa IN HINFO
CPU: RFC8482
OS:
3789s (01:03:09)
198.91.208.in-addr.arpa IN NS dns1.directi.com 60s (00:01:00)
198.91.208.in-addr.arpa IN NS dns3.directi.com 60s (00:01:00)
198.91.208.in-addr.arpa IN NS dns4.directi.com 60s (00:01:00)
198.91.208.in-addr.arpa IN NS dns2.directi.com 60s (00:01:00)

-- end --

Who is online

Users browsing this forum: ClaudeBot and 6 guests