Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by buried under 419s Thu Jul 04, 2013 8:24 pm
Return-path: <[email protected]>
Envelope-to:
Delivery-date: Thu, 04 Jul 2013 14:38:10 -0700
Received: from omr-d10.mx.aol.com ([205.188.108.134]:41812)
by ith esmtps (TLSv1:DHE-RSA-AES256-SHA:256)
(Exim 4.80)
(envelope-from <[email protected]>)
id 1UurE9-0002P3-JC
for ; Thu, 04 Jul 2013 14:38:10 -0700
Received: from mtaout-da04.r1000.mx.aol.com (mtaout-da04.r1000.mx.aol.com [172.29.51.132])
by omr-d10.mx.aol.com (Outbound Mail Relay) with ESMTP id 682A470058BF7;
Thu, 4 Jul 2013 17:28:05 -0400 (EDT)
Received: from omh-ma01.r1000.mx.aol.com (omh-ma01.r1000.mx.aol.com [172.29.41.7])
by mtaout-da04.r1000.mx.aol.com (MUA/Third Party Client Interface) with ESMTP id D2470E0001A4;
Thu, 4 Jul 2013 17:28:04 -0400 (EDT)
Received: from mtaout-ma06.r1000.mx.aol.com (mtaout-ma06.r1000.mx.aol.com [172.29.41.6])
by omh-ma01.r1000.mx.aol.com (AOL Outbound Holding Interface) with ESMTP id 7F633E0000A6;
Thu, 4 Jul 2013 17:26:06 -0400 (EDT)
Received: from sushmami62.91e3f05b0a304f4f854b9711a63fa829.sushmami62.2999717157.useast.internal.cloudapp.net (unknown [137.135.116.181])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
by mtaout-ma06.r1000.mx.aol.com (MUA/Third Party Client Interface) with ESMTPSA id 307C2E00062C;
Thu, 4 Jul 2013 17:26:06 -0400 (EDT)
Content-Type: multipart/alternative; boundary="===============0451404958=="
MIME-Version: 1.0
To: Recipients <[email protected]>
From: "Dr.Kingsley Moghalu" <[email protected]>
Date: Thu, 04 Jul 2013 21:26:05 +0000
Reply-To: [email protected]
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mx.aol.com;
s=20121107; t=1372973166;
bh=lturqeqfgK1CLJ/GP4N1tRNEa3TprJSKmAZ0P60Vk3g=;
h=From:To:Subject:Date:MIME-Version:Content-Type;
b=ffIar5jpYlSSKvNHxX5DbGALq+PiJLnhLHYXeNg1mzP7kVsi7ZwlTKlGck1igy+Vv
feqGt8E+oi48K0anlv0jsZjT6H3kAGSwkCfCkB6nDfGx38KUpq/aYeHYvLIvn7JVvy
bBWQiT/0E8EFPCVMyuybcREC1dZ5/fLe4JGKjy94=
X-AOL-SCOLL-SCORE: 0:2:108485544:93952408
X-AOL-SCOLL-URL_COUNT: 0
x-aol-global-disposition: G
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mx.aol.com;
s=20121107; t=1372973285;
bh=lturqeqfgK1CLJ/GP4N1tRNEa3TprJSKmAZ0P60Vk3g=;
h=From:To:Subject:Date:MIME-Version:Content-Type;
b=JJLWKlZcBPDROcE7tdLJymb4QFL36x5c7VP2eQGgvS/C8LfIe6PL1NC83HMc1V9tj
rPOieNybEGfHtJnOQHzt3a5O/hWaLjixXVLiPOnj/018XUmI1f3+C5rqCm5N/AX9aJ
qUD+3cSPYQvEuZ72/TGepiAEF/tCzEKWl8gSo19I=
X-AOL-SCOLL-SCORE: 0:2:116182264:93952408
X-AOL-SCOLL-URL_COUNT: 0
x-aol-sid: 3039ac1d338451d5e8e46f2b
X-Spam-Status: Yes, score=7.0
X-Spam-Score: 70
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "\", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.

Content preview: [...]

Content analysis details: (7.0 points, 7.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(katydid1039[at]aol.com)
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[205.188.108.134 listed in list.dnswl.org]
0.8 SPF_NEUTRAL SPF: sender does not match SPF record (neutral)
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.7 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (katydid1039[at]aol.com)
0.4 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5285]
0.5 MISSING_MID Missing Message-Id: header
0.0 LOTS_OF_MONEY Huge... sums of money
0.0 UPPERCASE_75_100 message body is 75-100% uppercase
0.0 T_HK_NAME_FM_DR T_HK_NAME_FM_DR
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
0.0 FILL_THIS_FORM_SHORT Fill in a short form with personal information
2.5 MONEY_FORM_SHORT Lots of money if you fill out a short form
X-Spam-Flag: YES
Subject: ***SPAM*** I WAS MANDATED BY THE PRESIDENT FEDERAL REPUBLIC IN CONJUNCTION WITH THE
FEDERAL EXECUTIVE COUNCIL (FEC),
THE SENATE COMMITTEE ON FOREIGN DEBTS RECONCILIATION AND IMPLEMENTATION
PANEL ON CONTRACT/INHERITANCE FUNDS TO COMPLETE THE ENTIRE UNPAID FUNDS.YOU
ARE REQUIRED AS A MATTER OF URGENCY TO RECONFIRM YOUR DETAILS INCLUDING
YOUR NAME PHONE NUMBER AND YOUR ADDRESS FOR VERIFICATION AND IMMEDIATE
PAYMENT WITHIN 24 HOURS TO ENABLE YOUR PAYMENT OF US$10.7M

You will not see this in a MIME-aware mail reader.
--===============0451404958==
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body


--===============0451404958==
Content-Type: text/html; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
=3Diso-8859-1"/></head></html>
--===============0451404958==--

[scam in subject line]

Questions about scams? fraudatiocruor @ gmail.com to contact remove spaces
Advertisement

Who is online

Users browsing this forum: ClaudeBot, Google [Bot] and 14 guests