Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Tue Jan 06, 2015 7:33 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 98.138.105.250
Originating ISP: Yahoo
City: Sunnyvale
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.25.211.135 with SMTP id k129csp3876625lfg;
Tue, 6 Jan 2015 04:45:47 -0800 (PST)
X-Received: by 10.42.71.194 with SMTP id l2mr69665496icj.71.1420548346736;
Tue, 06 Jan 2015 04:45:46 -0800 (PST)
Return-Path: <[email protected]>
Received: from nm48-vm7.bullet.mail.ne1.yahoo.com (nm48-vm7.bullet.mail.ne1.yahoo.com. [98.138.121.119])
by mx.google.com with ESMTPS id j7si6511404igx.15.2015.01.06.04.45.45
for <snipped>
(version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
Tue, 06 Jan 2015 04:45:46 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 98.138.121.119 as permitted sender) client-ip=98.138.121.119;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 98.138.121.119 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=yahoo.co.uk
DKIM-Signature: <snipped>
DomainKey-Signature: <snipped>;
Received: from [127.0.0.1] by nm48.bullet.mail.ne1.yahoo.com with NNFMP; 06 Jan 2015 12:45:45 -0000
Received: from [98.138.226.176] by nm48.bullet.mail.ne1.yahoo.com with NNFMP; 06 Jan 2015 12:42:49 -0000
Received: from [98.138.89.244] by tm11.bullet.mail.ne1.yahoo.com with NNFMP; 06 Jan 2015 12:42:49 -0000
Received: from [127.0.0.1] by omp1058.mail.ne1.yahoo.com with NNFMP; 06 Jan 2015 12:42:49 -0000
X-Yahoo-Newman-Property: ymail-4
X-Yahoo-Newman-Id: [email protected]
X-YMail-OSG: <snipped>
Received: by 98.138.105.250; Tue, 06 Jan 2015 12:42:48 +0000
Date: Tue, 6 Jan 2015 12:42:48 +0000 (UTC)
From: Mrs Noor Hidayah <[email protected]>
Reply-To: Mrs Noor Hidayah <[email protected]>
Message-ID: <1909128984.3110327.1420548168710.JavaMail.yahoo@jws100115.mail.ne1.yahoo.com>
Subject: Greetings To You,
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_3110326_258300661.1420548168708"
Content-Length: 2320


Greetings To You,

Please forgive my intrusion into your privacy,my name is Mrs Noor Hidayah a Malaysia citizen but lives in capital city of Burkina-Faso, I am a sick widow have decided to donate some of my wealth to areliable individual that will use this money, $2.7 Million Dollars to help the orphans and less privileged ones in the society for the work of humanity as i don't have any child to inherit the fund when am no more alive, You will take 20% of this fund for your effort and share the rest to orphans, less privileged ones and the widows, if you are willing to accept my offer and use this fund exactly as i said kindly reply me with your data's let me know you more and instruct you on what next to do now that i can struggle to write.

My regards


Mrs Noor Hidayah

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

by Faizan Docherty Sun Jan 25, 2015 6:15 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 27.123.205.138
Originating ISP: Yahoo-tw
City: n/a
Country of Origin: Taiwan
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.51.10 with SMTP id g10csp565887pdo;
Sat, 24 Jan 2015 06:23:38 -0800 (PST)
X-Received: by 10.68.134.3 with SMTP id pg3mr20206265pbb.84.1422109418694;
Sat, 24 Jan 2015 06:23:38 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (nov-007-i623.relay.mailchannels.net. [46.232.183.177])
by mx.google.com with ESMTP id od10si5557121pbb.218.2015.01.24.06.23.35
for <snipped>;
Sat, 24 Jan 2015 06:23:38 -0800 (PST)
Received-SPF: none (google.com: [email protected] does not designate permitted sender hosts) client-ip=46.232.183.177;
Authentication-Results: mx.google.com;
spf=none (google.com: [email protected] does not designate permitted sender hosts) [email protected];
dkim=fail [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=yahoo.co.uk
X-Sender-Id: _forwarded-from|203.188.201.150
Received: from r8-chicago.webserversystems.com (ip-10-213-14-133.us-west-2.compute.internal [10.213.14.133])
by relay.mailchannels.net (Postfix) with ESMTPA id B26031D0180
for <snipped>; Sat, 24 Jan 2015 14:23:32 +0000 (UTC)
X-Sender-Id: _forwarded-from|203.188.201.150
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.224.7.213])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.3);
Sat, 24 Jan 2015 14:23:32 GMT
X-MC-Relay: Junk
X-MailChannels-SenderId: _forwarded-from|203.188.201.150
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1422109412910:2846469098
X-MC-Ingress-Time: 1422109412910
Received: from nm12-vm0.bullet.mail.tp2.yahoo.com ([203.188.201.150]:50717)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YF1cZ-0001G1-4X
for <snipped>; Sat, 24 Jan 2015 08:23:31 -0600
DKIM-Signature: <snipped>
Received: from [203.188.200.143] by nm12.bullet.mail.tp2.yahoo.com with NNFMP; 24 Jan 2015 14:23:29 -0000
Received: from [27.123.206.57] by tm5.bullet.mail.tp2.yahoo.com with NNFMP; 24 Jan 2015 14:23:28 -0000
Received: from [127.0.0.1] by omp1002.mail.tw1.yahoo.com with NNFMP; 24 Jan 2015 14:23:28 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
X-YMail-OSG: <snipped>
Received: by 27.123.205.138; Sat, 24 Jan 2015 14:23:28 +0000
Date: Sat, 24 Jan 2015 14:23:27 +0000 (UTC)
From: Mrs Noor Hidayah <[email protected]>
Reply-To: Mrs Noor Hidayah <[email protected]>
Message-ID: <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_33196_405710396.1422109407770"
X-Spam-Status: Yes, score=7.5
X-Spam-Score: 75
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Â Greetings To You, Please forgive my intrusion into your
privacy,my name is Mrs Noor Hidayah a Malaysia citizen but lives in capital
city of Burkina-Faso, I am a sick widow have decided to donate some of my
wealth to areliable individual that will use this money, $2.7 Million Dollars
to help the orphans and less privileged ones in the society for the work
of humanity as i don't have any child to inherit the fund when am no more
alive, You will take 20% of this fund for your effort and share the rest to
orphans, less privileged ones and the widows, if you are willing to accept
my offer and use this fund exactly as i said kindly reply me with your data's
let me know you more and instruct you on what next to do now that i can struggle
to write. [...]

Content analysis details: (7.5 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(mrsnoor_hidayah[at]yahoo.co.uk)
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[203.188.201.150 listed in list.dnswl.org]
1.0 MISSING_HEADERS Missing To: header
0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
2.8 MALFORMED_FREEMAIL Bad headers on message from free email service
0.0 LOTS_OF_MONEY Huge... sums of money
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
0.0 T_MONEY_PERCENT X% of a lot of money for you
X-Spam-Flag: YES
Subject: ***SPAM*** Greetings To You,
X-AuthUser:


Greetings To You,

Please forgive my intrusion into your privacy,my name is Mrs Noor Hidayah a Malaysia citizen but lives in capital city of Burkina-Faso, I am a sick widow have decided to donate some of my wealth to areliable individual that will use this money, $2.7 Million Dollars to help the orphans and less privileged ones in the society for the work of humanity as i don't have any child to inherit the fund when am no more alive, You will take 20% of this fund for your effort and share the rest to orphans, less privileged ones and the widows, if you are willing to accept my offer and use this fund exactly as i said kindly reply me with your data's let me know you more and instruct you on what next to do now that i can struggle to write.

My regards


Mrs Noor Hidayah

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.

Who is online

Users browsing this forum: ClaudeBot and 34 guests