Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Sat Dec 14, 2013 2:03 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 41.203.69.2<br>Originating ISP: Globacom Ltd<br> City: n/a<br>Country of Origin: Nigeria<br>* For a complete report on this email header goto ipTRACKERonline


From [email protected] Fri Dec 13 17:48:31 2013
Return-Path: <[email protected]>
Received: from conecel.com (pgccforward2.conecel.com [192.168.1.29])
by pgccportafree.portafree.com (8.13.6/8.12.11) with ESMTP id rBBNRmBC011479
for <snipped>; Wed, 11 Dec 2013 18:28:13 -0500
Received: from ([157.56.116.98])
by pgccforward2.conecel.com with ESMTP with TLS id DYFX5P1.38145613;
Wed, 11 Dec 2013 18:25:02 -0500
Received: from [10.185.182.118] (41.203.69.2) by
HKXPR02MB182.apcprd02.prod.outlook.com (10.141.131.147) with Microsoft SMTP
Server (TLS) id 15.0.837.10; Wed, 11 Dec 2013 23:25:00 +0000
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Description: Mail message body
Subject: GoodDay
To: Recipients <snipped>
From: "Mr.Gokhale" <[email protected]>
Date: Thu, 12 Dec 2013 00:24:41 +0100
Reply-To: <[email protected]>
X-Antivirus: avast! (VPS 131211-1, 12/11/2013), Outbound message
X-Antivirus-Status: Clean
Message-ID: <a256ba48-ca40-4a2d-9458-d79f340591c2@HKXPR02MB182.apcprd02.prod.outlook.com>
X-Originating-IP: [41.203.69.2]
X-ClientProxiedBy: DBXPR03CA006.eurprd03.prod.outlook.com (10.255.191.144)
To HKXPR02MB182.apcprd02.prod.outlook.com (10.141.131.147)
X-Forefront-PRVS: 0057EE387C
X-Forefront-Antispam-Report: SFV:SPM;SFS:(10019001)(639001)(649001)(199002)(189002)(81542001)(76786001)(74876001)(46102001)(69226001)(51856001)(53256004)(74662001)(74502001)(59766001)(83322001)(76176001)(43066001)(79102001)(19580405001)(87976001)(76482001)(74706001)(77982001)(47736001)(64872005)(54316002)(23756003)(81342001)(73186002)(50986001)(80976001)(76576001)(77096001)(10646002)(87266001)(31686002)(90146001)(221733001)(33646001)(569274001)(47776003)(1496004)(47976001)(65816001)(85306002)(4396001)(76796001)(19580395003)(74316001)(325944007)(49866001)(56776001)(42186004)(54356001)(47446002)(56816005)(81816001)(83072002)(50466002)(81686001)(89136003)(66066001)(74366001)(63696002)(85852003)(80022001)(90576001);DIR:OUT;SFP:1501;SCL:9;SRVR:HKXPR02MB182;H:[10.185.182.118];CLIP:41.203.69.2;FPR:;RD:InfoNoRecords;A:0;MX:1;LANG:en;
X-OriginatorOrg: Gokhale.onmicrosoft.com
X-esp: ESP<46>=
SHA:<23>
SHA_FLAGS:<102>
UHA:<10>
ISC:<0>
BAYES:<0>
SenderID:<0>
DKIM:<0>
TS:<13>
SIG:<gHcABoAUAAITVFMyMC0xN0w1LTJPVTQtUFNES4AEAAEALlzZgAIABQACgAgA
BAdEWUZYNVAxgBkABxhNZGJQNE5GcTZURzNQRm5YNE1DSndBPT2ADQAIDDIu
MC4zLjAyLTk1M4AEAAkDSU0ggAcACgY2LjcuMiAAAAAAgIAACYABAA8CgAgA
B0tzOvoqJRXUgAQAAp04dGKACAATkXlSJsxEUWqACAAJf3tevmqaUeyACAAK
xZvehYeHWqCACQALWik1o1tA1uoAgAgACHqh+sHrwlb6gAQADAAAAVqAFAAD
AAAAApo67BjXGyWLOfp/P3bn4NCAAgAEAAAAAAAA>
DSC:<0>
TRU_spam1: <0>
TRU_freehosting: <0>
TRU_money_spam: <0>
TRU_urllinks: <0>
TRU_medical_spam: <0>
TRU_lotto_spam: <0>
TRU_watch_spam: <0>
TRU_legal_spam: <0>
TRU_scam_spam: <0>
TRU_adult_spam: <0>
TRU_playsites: <0>
TRU_stock_spam: <0>
TRU_phish_spam: <0>
URL Real-Time Signatures: <0>
TRU_profanity_spam: <0>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by pgccportafree.portafree.com id rBBNRmBC011479
Status: R


I sent you this email about two weeks ago and i got no response. I am sufferer of esophageal cancer, with a very short time to live. I wish to bequeath a substantial sum of money to you for charity and humanitarian work.Please affirm your willingness so i can give further details.

Regards,

Mr.Gokhale. Email: [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: Bing [Bot], ClaudeBot and 25 guests