Advance fee loan scams and fraudulent loan sites.
by Faizan Docherty Sun Jan 18, 2015 9:14 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 211.154.157.230
Originating ISP: Shenzhenshizonghengxinxijishuyouxiangongsi
City: Shenzhen
Country of Origin: Red China
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.51.10 with SMTP id g10csp437600pdo;
Fri, 16 Jan 2015 10:53:17 -0800 (PST)
X-Received: by 10.70.109.174 with SMTP id ht14mr15321817pdb.74.1421434397602;
Fri, 16 Jan 2015 10:53:17 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (nov-007-i623.relay.mailchannels.net. [46.232.183.177])
by mx.google.com with ESMTP id fk13si6433438pdb.144.2015.01.16.10.53.15
for <snipped>;
Fri, 16 Jan 2015 10:53:17 -0800 (PST)
Received-SPF: none (google.com: [email protected] does not designate permitted sender hosts) client-ip=46.232.183.177;
Authentication-Results: mx.google.com;
spf=none (google.com: [email protected] does not designate permitted sender hosts) [email protected]
X-Sender-Id: _forwarded-from|197.228.245.63
Received: from r8-chicago.webserversystems.com (ip-10-220-9-73.us-west-2.compute.internal [10.220.9.73])
by relay.mailchannels.net (Postfix) with ESMTPA id D67121209F7
for <snipped>; Fri, 16 Jan 2015 18:53:08 +0000 (UTC)
X-Sender-Id: _forwarded-from|197.228.245.63
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.248.16.86])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.2);
Fri, 16 Jan 2015 18:53:10 GMT
X-MC-Relay: Junk
X-MailChannels-SenderId: _forwarded-from|197.228.245.63
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1421434390029:4044540685
X-MC-Ingress-Time: 1421434390029
Received: from [211.154.157.230] (port=46947 helo=mail.52forum.com)
by r8-chicago.webserversystems.com with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YCC0x-0006vc-Nf
for <snipped>; Fri, 16 Jan 2015 12:53:07 -0600
Received: from [197.228.245.63] (8ta-228-245-63.telkomadsl.co.za [197.228.245.63])
by mail.52forum.com (Postfix) with ESMTPA id 880652222074;
Sat, 17 Jan 2015 01:24:54 +0800 (CST)
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
To: Recipients <[email protected]>
From: "Chris Diaz" <[email protected] >
Date: Fri, 16 Jan 2015 19:24:57 +0200
Reply-To: [email protected]
X-Spam-Status: Yes, score=7.6
X-Spam-Score: 76
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Do you need a loan? If yes, Email us @ ([email protected])
with Names, Loan Amount, Duration, Country. Thanks [...]

Content analysis details: (7.6 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[211.154.157.230 listed in psbl.surriel.com]
1.4 RCVD_IN_BRBL_LASTEXT RBL: RCVD_IN_BRBL_LASTEXT
[211.154.157.230 listed in bb.barracudacentral.org]
0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
0.5 MISSING_MID Missing Message-Id: header
0.8 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Spam-Flag: YES
Subject: ***SPAM*** Re: Loan
X-AuthUser:
Message-Id: <[email protected]>


Do you need a loan? If yes, Email us @ ([email protected]) with Names, Loan Amount, Duration, Country. Thanks

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: ClaudeBot and 3 guests