Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Mon Jan 27, 2014 1:16 am
ipTRACKERonline.com wrote:Header Analysis Quick Report<br>Originating IP: 177.124.60.91<br>Originating ISP: Horizons Telecomunicações E Tecnologia Ltda<br> City: Curitiba<br>Country of Origin: Brazil<br>* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.126.40 with SMTP id mv8csp86375pdb;
Sun, 26 Jan 2014 13:39:42 -0800 (PST)
X-Received: by 10.42.121.147 with SMTP id j19mr19340499icr.13.1390772382379;
Sun, 26 Jan 2014 13:39:42 -0800 (PST)
Return-Path: <[email protected]>
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com. [184.154.1.124])
by mx.google.com with ESMTPS id pl2si12567460icc.136.2014.01.26.13.39.42
for <snipped>
(version=TLSv1 cipher=RC4-SHA bits=128/128);
Sun, 26 Jan 2014 13:39:42 -0800 (PST)
Received-SPF: fail (google.com: domain of [email protected] does not designate 184.154.1.124 as permitted sender) client-ip=184.154.1.124;
Authentication-Results: mx.google.com;
spf=hardfail (google.com: domain of [email protected] does not designate 184.154.1.124 as permitted sender) [email protected];
dkim=fail (test mode) [email protected]
Received: from a4-salsa4-1.bol.com.br ([200.147.97.223]:52419 helo=a4-salsa4.bol.com.br)
by r8-chicago.webserversystems.com with esmtp (Exim 4.80)
(envelope-from <[email protected]>)
id 1W7XQX-00012y-Ri
for <snipped>; Sun, 26 Jan 2014 15:39:41 -0600
Received: from localhost (localhost.localdomain [127.0.0.1])
by a4-salsa4.bol.com.br (Postfix) with ESMTP id DE2073800085;
Sun, 26 Jan 2014 19:39:36 -0200 (BRST)
Received: from a4-salsa4.host.intranet (localhost.localdomain [127.0.0.1])
by a4-salsa4.bol.com.br (Postfix) with ESMTP id 36F7D380008E;
Sun, 26 Jan 2014 19:38:12 -0200 (BRST)
DKIM-Signature: <snipped>
Received: from zipmail.com.br (a4-winter16.host.intranet [10.131.133.143])
by a4-salsa4.host.intranet (Postfix) with ESMTP id 0C7523800084;
Sun, 26 Jan 2014 19:38:12 -0200 (BRST)
Date: Sun, 26 Jan 2014 19:38:11 -0200
From: Serra kudou <[email protected]>
Message-ID: <[email protected]>
In-Reply-To:
References:
Mime-Version: 1.0
Content-Type: text/html;
charset=utf-8
Content-Transfer-Encoding: quoted-printable
X-SenderIP: 177.124.60.91
To: undisclosed-recipients:;
X-SIG5: 8e929f202e876a02e787d2e98fa30952
X-Spam-Status: Yes, score=15.3
X-Spam-Score: 153
X-Spam-Bar: +++++++++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Re: My Dear, I BRING YOU CALVARY GREETINGS I am Mrs. Serra
kudou. from Abidjan Cote d'Ivoire, I am married to Mr. David Kudou I and
my late husband wasinto, Estate management and also a Government Estate Building
Contractor before my husband death on January 25 2007. We were married for
eleven years without a child due to my fibriod problem. He died after a brief
illness that lasted for only Four days.Before his death we were both born
again Christian. Since my husband death I have been diagnosed with esophageal
cancer . When my late husband was alive we deposited the sum of $3.8Million
(USD) dollars in a security company. Presently the money is still in the
security company. Recently, my [...]

Content analysis details: (15.3 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
2.5 MILLION_USD BODY: Talks about millions of dollars
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(serrawise110[at]zipmail.com.br)
2.4 RCVD_IN_SORBS_SOCKS RBL: SORBS: sender is open SOCKS proxy server
[177.124.60.91 listed in dnsbl.sorbs.net]
2.5 RCVD_IN_SORBS_HTTP RBL: SORBS: sender is open HTTP proxy server
2.7 RCVD_IN_PSBL RBL: Received via a relay in PSBL
[200.147.97.223 listed in psbl.surriel.com]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (serrawise110[at]zipmail.com.br)
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.0 LOTS_OF_MONEY Huge... sums of money
0.0 ADVANCE_FEE_4_NEW Appears to be advance fee fraud (Nigerian 419)
0.0 ADVANCE_FEE_5_NEW Appears to be advance fee fraud (Nigerian 419)
2.2 ADVANCE_FEE_4_NEW_MONEY Advance Fee fraud and lots of money
0.0 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
0.6 MONEY_FRAUD_5 Lots of money and many fraud phrases
0.5 CRM114_PROB_SPAM CRM114: CRM114_PROB_SPAM
X-Spam-Flag: YES
Subject: ***SPAM*** Re: My Dear,
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - r8-chicago.webserversystems.com
X-AntiAbuse: Original Domain - <snipped>
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - zipmail.com.br
X-Get-Message-Sender-Via: r8-chicago.webserversystems.com: none
X-Source:
X-Source-Args:
X-Source-Dir:


Re: My Dear,

I BRING YOU CALVARY GREETINGS

I am Mrs. Serra kudou. from Abidjan Cote d'Ivoire, I am married to Mr. David Kudou I and my late husband wasinto, Estate management and also a Government Estate Building Contractor before my husband death on January 25 2007. We were married for eleven years without a child due to my fibriod problem. He died after a brief illness that lasted for only Four days.Before his death we were both born again Christian. Since my husband death I have been diagnosed with esophageal cancer . When my late husband was alive we deposited the sum of $3.8Million (USD) dollars in a security company. Presently the money is still in the security company. Recently, my

Doctor told me that I would not last for the next Four months due to cancer problem. From all indications, my condition is really deteriorating and isquite obvious that I may not live more than two months, because the cancer stage has gott en to a verydangerous stage .Having known my condition I decided to donate this fund to good person that will utilize this money the way I am going to instruct herein. I want to you use at last 80% this fund for orphanages, widows and and

also propagating the word of God and to endeavor that the house of God is maintained and take the
remaining 20% to take good care of your good God Given Home. l took this decision because I don't have any child that will inherit this money . This is why I am taking this decision to donate this fund for charity. I am not afraid of death hencae I know were I am going. I know that I am going to be in the bosom of the Lord.Exodus 14 VS 14 says that "the lord will fight my case and I shall hold my peace". I don't need any telephone communication in this regard because of my health .My happiness is that I lived a life of a worthy Christian. Whoever that Wants to serve the Lord must serve him in spirit and Truth, always be prayerful

all through your life. Write to me on the this email address immediately and any delay in your reply will give me room in sourcing another good person, for this same purpose.Assure me that you will act accordingly as I Stated herein.Hoping to receive your response immedaitely.

Thanks and Remain blessed in the Lord.l remain yours sister

in Christ.

Mrs.Serra kudou,

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: ClaudeBot, Google [Bot] and 25 guests