by Faizan Docherty
Fri Jan 10, 2014 1:16 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.203.69.4<br>Originating ISP: Globacom Ltd<br> City: n/a<br>Country of Origin: Nigeria<br>* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.58.38 with SMTP id n6csp7206pdq;
Thu, 9 Jan 2014 00:56:56 -0800 (PST)
X-Received: by 10.43.16.2 with SMTP id pw2mr1416210icb.56.1389257816385;
Thu, 09 Jan 2014 00:56:56 -0800 (PST)
Return-Path: <[email protected]>
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com. [184.154.1.124])
by mx.google.com with ESMTPS id j18si12863167igh.35.2014.01.09.00.56.55
for <snipped>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Thu, 09 Jan 2014 00:56:56 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 184.154.1.124 as permitted sender) client-ip=184.154.1.124;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 184.154.1.124 as permitted sender) [email protected]
Received: from user109x115.lvusd.k12.ca.us ([156.3.109.115]:49377 helo=barracuda.lvusd.org)
by r8-chicago.webserversystems.com with esmtp (Exim 4.80)
(envelope-from <[email protected]>)
id 1W1BQ6-000EEg-Dr
for <snipped>; Thu, 09 Jan 2014 02:56:55 -0600
X-ASG-Debug-ID: 1389257805-0454c20e2e20beb0001-1Eip9O
Received: from mail.lvusd.org (mail.lvusd.org [10.3.21.1]) by barracuda.lvusd.org with ESMTP id WMUNEh2tPZwD9a4L; Thu, 09 Jan 2014 00:56:45 -0800 (PST)
X-Barracuda-Envelope-From: [email protected]
Date: Thu, 9 Jan 2014 00:56:45 -0800 (PST)
From: AFREDO BORIS <[email protected]>
Reply-To: [email protected]
Message-ID: <[email protected]>
MIME-Version: 1.0
X-ASG-Orig-Subj: *Affordable Loan Offer By ALFREDO BORIS.
Content-Type: multipart/alternative;
boundary="----=_Part_870321_1516987663.1389257805779"
X-Originating-IP: [41.203.69.4]
X-Mailer: Zimbra 8.0.5_GA_5839 (ZimbraWebClient - FF14 (Win)/8.0.5_GA_5839)
Thread-Topic: *Affordable Loan Offer By ALFREDO BORIS.
Thread-Index: Z2fxBnzaA0TaaM4Y9OAhlyv/H+sB/Q==
X-Barracuda-Connect: mail.lvusd.org[10.3.21.1]
X-Barracuda-Start-Time: 1389257805
X-Barracuda-URL: http://10.3.21.0:8000/cgi-mod/mark.cgi
X-Virus-Scanned: by bsmtpd at lvusd.org
X-Barracuda-BRTS-Status: 1
X-Barracuda-Bayes: INNOCENT GLOBAL 0.0000 1.0000 -2.0210
X-Barracuda-Spam-Score: -0.01
X-Barracuda-Spam-Status: No, SCORE=-0.01 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=5.0 tests=BSF_SC0_MV0028, HTML_MESSAGE, MISSING_HEADERS, TO_CC_NONE
X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.2.143898
Rule breakdown below
pts rule name description
---- ---------------------- --------------------------------------------------
1.21 MISSING_HEADERS Missing To: header
0.00 HTML_MESSAGE BODY: HTML included in message
0.00 TO_CC_NONE No To: or Cc: header
0.80 BSF_SC0_MV0028 Custom Rule BSF_SC0_MV0028
X-Spam-Status: Yes, score=17.1
X-Spam-Score: 171
X-Spam-Bar: +++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: *Affordable Loan Offer By ALFREDO BORIS.We offer loan for
Private Or Business Loan For Various Proposes ranging from the minimum of
£500 USD to the maximum of £200,000,000.00 USD with an interest rate of
3% .Apply Now [...]
Content analysis details: (17.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.8 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server
[41.203.69.4 listed in dnsbl.sorbs.net]
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?41.203.69.4>]
-0.0 SPF_PASS SPF: sender matches SPF record
1.0 MISSING_HEADERS Missing To: header
2.0 BAYES_80 BODY: Bayes spam probability is 80 to 95%
[score: 0.8267]
1.4 HTML_IMAGE_ONLY_28 BODY: HTML: images with 2400-2800 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 LOTS_OF_MONEY Huge... sums of money
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
2.1 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
2.0 MONEY_FROM_41 Lots of money from Africa
0.0 T_REMOTE_IMAGE Message contains an external image
0.0 FILL_THIS_FORM Fill in a form with personal information
2.0 FILL_THIS_FORM_LONG Fill in a form with personal information
2.9 FILL_THIS_FORM_LOAN Answer loan question(s)
0.0 MONEY_FORM Lots of money if you fill out a form
X-Spam-Flag: YES
Subject: ***SPAM*** *Affordable Loan Offer By ALFREDO BORIS.
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - r8-chicago.webserversystems.com
X-AntiAbuse: Original Domain - <snipped>
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - lvusd.org
X-Get-Message-Sender-Via: r8-chicago.webserversystems.com: none
X-Source:
X-Source-Args:
X-Source-Dir:
------=_Part_870321_1516987663.1389257805779
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable
*Affordable Loan Offer By ALFREDO BORIS.We offer loan for Private Or
Business Loan For Various Proposes ranging from the minimum of £500
USD to the maximum of £200,000,000.00 USD with an interest rate of 3%
.Apply Now ........................
FILL AND RETURN
Full Name......................
Address..........................
Country........................
Loan Amount.........................
Loan Duration..........................
Male/Female.............................
Phone Number..................................
Personal Mobile Phone Number............................
Have You Applied Before?...................................
Thanks for your understanding and co-operation.
I await your prompt response Respectfully.
E-mail: [email protected]
Executive Finance/Loan Officer.
(c)2013 ALFREDO BORIS FINANCIAL HOME ®.
Las Virgenes Unified School District: This communication (including any attachments) may contain privileged and confidential information. It is intended solely for the use of the addressee. If you are not the intended recipient, disclosing, copying, distributing, or using this communication is not authorized and may be unlawful. This communication may contain nonpublic or personal information. It may be subject to the restrictions of the Family Rights Privacy Act, the right of privacy, and other federal or state laws. If you receive this communication in error or are not the intended recipient, please contact the sender immediately and destroy the material in its entirety, whether electronic or hard copy.
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.