Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Tue Dec 03, 2013 3:20 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 197.242.112.7<br>Originating ISP: Spectranet Ltd<br> City: Lagos<br>Country of Origin: Nigeria<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.177.2 with SMTP id bg2csp197407vcb;
Tue, 3 Dec 2013 05:16:24 -0800 (PST)
X-Received: by 10.68.17.7 with SMTP id k7mr38157580pbd.119.1386076583345;
Tue, 03 Dec 2013 05:16:23 -0800 (PST)
Return-Path: <[email protected]>
Received: from mail.keywin.com.tw (mail.keywin.com.tw. [61.219.254.213])
by mx.google.com with ESMTP id fn9si18429550pab.290.2013.12.03.04.52.31
for <multiple recipients>;
Tue, 03 Dec 2013 05:16:23 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 61.219.254.213 as permitted sender) client-ip=61.219.254.213;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 61.219.254.213 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
Received: from localhost (localhost [127.0.0.1])
by mail.keywin.com.tw (Postfix) with SMTP id 465EC7552E;
Tue, 3 Dec 2013 20:52:12 +0800 (CST)
Received: from mail.keywin.com.tw (localhost [127.0.0.1])
by mail.keywin.com.tw (Postfix) with ESMTP id 67BCD7552A;
Tue, 3 Dec 2013 20:51:52 +0800 (CST)
From: "Mr.Emmanuel Broni" <[email protected]>
Reply-To: [email protected]
Subject: Urgent reply
Date: Tue, 3 Dec 2013 20:51:52 +0800
Message-Id: <[email protected]>
X-Mailer: Open WebMail 2.30 20040103
X-OriginatingIP: 197.242.112.7 (rachel)
MIME-Version: 1.0
Content-Type: text/plain;
charset=big5
To: undisclosed-recipients: ;


Hello Dear,

I am Mr.Emmanuel Broni. the head of business management Department of Ghana
National Petroleum Corporation ( G.N.P.C ) and responsible for the award of
contract relating to oil business.
I want us to enter into confidential and binding business agreement where by I
will be awarding your company lucrative contacts and in return certain
percentage is reserved for me.
Please on no account should any person , organization, or any other competing

companies know that I have interest or know of this arrangement between us for
our own interest.

If the offer is okay with you kindly respond quickly.

Thanks,
Yours faithfully.


Mr.Emmanuel Broni.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

by Faizan Docherty Thu Dec 19, 2013 2:40 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 197.242.102.177<br>Originating ISP: Spectranet Ltd<br> City: Lagos<br>Country of Origin: Nigeria<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.221.13 with SMTP id ia13csp152818vcb;
Wed, 18 Dec 2013 16:37:44 -0800 (PST)
X-Received: by 10.224.115.70 with SMTP id h6mr58852071qaq.61.1387413464455;
Wed, 18 Dec 2013 16:37:44 -0800 (PST)
Return-Path: <[email protected]>
Received: from server.teklifediyoruz.com ([199.48.160.50])
by mx.google.com with ESMTPS id r7si655062qar.179.2013.12.18.16.32.05
for <multiple recipients>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Wed, 18 Dec 2013 16:37:44 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 199.48.160.50 as permitted sender) client-ip=199.48.160.50;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 199.48.160.50 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
Received: from localhost.localdomain ([127.0.0.1]:48651 helo=localhost)
by server.teklifediyoruz.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1VtRW0-0006i6-Ds; Thu, 19 Dec 2013 03:31:00 +0300
Received: from 197.242.102.177 ([197.242.102.177]) by
webmail.batudesign.com (Horde Framework) with HTTP; Thu, 19 Dec 2013
04:30:59 +0400
Message-ID: <[email protected]>
Date: Thu, 19 Dec 2013 04:30:59 +0400
From: "Mr.Emmanuel Broni" <[email protected]>
Reply-to: [email protected]
To: undisclosed-recipients:;
Subject: Get back to me fast
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_kjpahu8drkzv"
Content-Transfer-Encoding: 7bit
User-Agent: Internet Messaging Program (IMP) H3 (4.3.11)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server.teklifediyoruz.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - gmail.com
X-Get-Message-Sender-Via: server.teklifediyoruz.com: authenticated_id: [email protected]


Hello Dear,

I am Mr.Emmanuel Broni. the head of business management Department of Ghana National Petroleum Corporation ( G.N.P.C ) and responsible for the award of contract relating to oil business.
I want us to enter into confidential and binding business agreement where by I will be awarding your company lucrative contacts and in return certain percentage is reserved for me.
Please on no account should any person , organization, or any other competing

companies know that I have interest or know of this arrangement between us for our own interest.

If the offer is okay with you kindly respond quickly.

Thanks,
Yours faithfully.
Mr.Emmanuel Broni.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.

Who is online

Users browsing this forum: ClaudeBot, Google [Bot] and 37 guests