by Faizan Docherty
Mon Sep 29, 2014 11:46 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 41.207.204.45
Originating ISP: Cote D'ivoire Telecom
City: Abidjan
Country of Origin: Cote D'Ivoire
* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.76.168.38 with SMTP id zt6csp88312oab;
Mon, 29 Sep 2014 02:18:05 -0700 (PDT)
X-Received: by 10.68.57.168 with SMTP id j8mr10383371pbq.106.1411982284510;
Mon, 29 Sep 2014 02:18:04 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (aso-006-i407.relay.mailchannels.net. [207.210.193.16])
by mx.google.com with ESMTP id yr4si22064713pab.80.2014.09.29.02.18.02
for <snipped>;
Mon, 29 Sep 2014 02:18:04 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 207.210.193.16 as permitted sender) client-ip=207.210.193.16;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 207.210.193.16 as permitted sender) [email protected];
dkim=fail [email protected]
X-Sender-Id: _forwarded-from|183.79.100.209
Received: from r8-chicago.webserversystems.com (ip-10-33-12-218.us-west-2.compute.internal [10.33.12.218])
by relay.mailchannels.net (Postfix) with ESMTPA id 23E1E600D8
for <snipped>; Mon, 29 Sep 2014 09:17:59 +0000 (UTC)
X-Sender-Id: _forwarded-from|183.79.100.209
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.227.41.147])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.14);
Mon, 29 Sep 2014 09:18:01 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|183.79.100.209
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1411982281305:978701810
X-MC-Ingress-Time: 1411982281305
Received: from web101205.mail.kks.yahoo.co.jp ([183.79.100.209]:40385)
by r8-chicago.webserversystems.com with smtp (Exim 4.82)
(envelope-from <[email protected]>)
id 1XYX5Y-000DGF-QC
for <snipped>; Mon, 29 Sep 2014 04:17:58 -0500
Received: (qmail 88600 invoked by uid 60001); 29 Sep 2014 09:17:42 -0000
DKIM-Signature: <snipped>
DomainKey-Signature: <snipped>;
Message-ID: <[email protected]>
X-YMail-OSG: <snipped>
Received: from [41.207.204.45] by web101205.mail.kks.yahoo.co.jp via HTTP; Mon, 29 Sep 2014 18:17:42 JST
X-Mailer: YahooMailWebService/0.8.111_56
X-YMail-JAS: <snipped>
References:
Date: Mon, 29 Sep 2014 18:17:42 +0900 (JST)
From: Awa Jammeh <[email protected]>
Reply-To: Awa Jammeh <[email protected]>
To: undisclosed recipients: ;
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-847781451-1411982262=:81550"
X-Spam-Status: Yes, score=6.7
X-Spam-Score: 67
X-Spam-Bar: ++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Greetings to you. My Name is Awa Jammeh,i am 22 years old,from
the Republic of Cote D'Ivoire,I am the only Daughter of Late Major Kone Jammeh,
he was well known for Cocoa exportation from Cote Ivoire to European countries
for through out his life before he died in the year 2012. [...]
Content analysis details: (6.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[183.79.100.209 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(si951753456[at]yahoo.co.jp)
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
(awa jammeh <awajammeh06[at]yahoo.com>
)
-0.9 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (si951753456[at]yahoo.co.jp)
0.0 HK_SCAM_N1 BODY: HK_SCAM_N1
0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.0 LOTS_OF_MONEY Huge... sums of money
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
2.0 MONEY_FROM_41 Lots of money from Africa
1.5 ADVANCE_FEE_4_NEW Appears to be advance fee fraud (Nigerian 419)
0.0 MONEY_FRAUD_5 Lots of money and many fraud phrases
0.0 ADVANCE_FEE_4_NEW_MONEY Advance Fee fraud and lots of money
0.5 CRM114_PROB_SPAM CRM114: CRM114_PROB_SPAM
X-Spam-Flag: YES
Subject: ***SPAM*** Greetings to you.
X-MC-Forward: <snipped>
X-AuthUser:
Greetings to you.
My Name is Awa Jammeh,i am 22 years old,from the Republic of Cote D'Ivoire,I am the only Daughter of Late Major Kone Jammeh, he was well known for Cocoa exportation from Cote Ivoire to European countries for through out his life before he died in the year 2012.
My father was killed by food poisoning, he died few hours upon his arrival from a meeting that was held with some of his business partners,
Before my father gave up his last breath, he disclosed to me that he deposited a truck box that contains the sum of($7.2 million Dollar.)in one of the finance Security company in a city called Abidjan using my name as the beneficiary because i was the only child of my family,and all the document about the box is intact with me.
Few weeks after the death of my father,his company and other commercial and private properties was illegally claimed by his friends and partners who was working with him, now i am left with nothing except that money in that box.
Presently this box is still with the company in Abidjan,and i am presently living in refugee camp orphanage home here in my village in borderside at Togo in west africa here since after the death of my late parents.
Please dear i really need your assistance and that is why i contact you for.
Kindly get back to me so that I will tell you how i realy need your assistance.
Waiting to hear from you.
Be bless, Yours in the Lord
Awa Jammeh.
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.