Sunday, December 20, 2009

Inbox - Rquest to contact you / Suspicious

Date: Sun, 20 Dec 2009 05:33:30 +0800 (CST)
From: "Luke Suton Law Firm"
ReplyTo: lukesutton78@gmail.com
Subject:
Rquest to contact you

I am Luke Sutton, a lawyer. I am desperately in need of
your assistance and I have summoned up the courage to contact
you. I need your help in the transfer of my late clients
$8,500,000.00 This is not stolen money and there are no
dangers involved.

Kindly send your response to my private email below for
further details: lukechamberlaw@live.co.uk

Thank you for your time and I look forward to hearing from
you

Regards,
Luke Sutton

Subject right click > Archives > Properties > Details
Return-Path:
Received: from mail.taipei.gov.tw (mail-2.taipei.gov.tw [163.29.36.4])
by mailer.ran.es (8.14.2/8.13.8) with SMTP id nBJLYKwh005538
for ; Sat, 19 Dec 2009 22:34:42 +0100
Received: By OpenMail Mailer;Sun, 20 Dec 2009 05:33:30 +0800 (CST)
From: "Luke Suton Law Firm"
Reply-To: lukesutton78@gmail.com
Subject: Rquest to contact you
Message-ID: <1261258410.834.ea-10918@mail.taipei.gov.tw>
Date: Sun, 20 Dec 2009 05:33:30 +0800 (CST)
MIME-Version: 1.0
Content-Type: text/plain; charset=big5
Content-Transfer-Encoding: quoted-printable
X-UIDL: 4p&#!<"U!!!U6!!2]i"! Status: RO Old-X-EsetId: E74D982990713469F84B987C992770 X-EsetId: E74D982990713469F84B987C992770 X-EsetScannerBuild: 6241

Reference - blacklist lookup
IP address 163.29.36.4 seems to belong to a Suspicious (1) with threat level 19, last malicious activity 21 days ago

ation results for 163.29.36.4
IP Address: 163.29.36.4 WhoIs Lookup IP BlackList Lookup
Hostname: mail-2.tcg.gov.tw Reverse DNS
[See complete information about your system with our IP Information tool!]

IP Address Conversion - IP Convert for 163.29.36.4 to Hex & to Dec
IP to Dec [IP Address to decimal]: 2736595972
IP to Hex [IP Address to hexadecimal]: a31d2404
IP to Bin [IP to binary]: 10100011000111010010010000000100

IP Address Lookup results for Asia
IP Address Continent: Asia
IP Continent Code:(AS)
IP Continent Population: 3,879,000,000
IP Continent Area: 43,810,000 km²
IP Continent Total Population: 60%
IP Continent Density People: 86.70 per km²
IP Continent Latitude: (29.8405)
IP Continent Longitude: (89.296)

IP Location Lookup results for Taiwan
IP Country Name: Taiwan
IP Country Capital: Taipei
IP Language: Mandarin Chinese
IP Currency: New Taiwan Dollar (TWD)
IP Country Latitude: (23.5)
IP Country Longitude: (121)
IP Country Code: TWN (TW)

IP Location Lookup results for 163.29.36.4 in T'ai-pei
IP Address Region: T'ai-pei
IP Address City: Taipei
IP Address Latitude: (25.0392)
IP Address Longtitude: (121.525)

Additional IP Location information for 163.29.36.4
IP Address Organization: Taipei City Government Information Office
IP Address ISP: MOEC
Time zone for 163.29.36.4: Asia/Taipei
Local time zone for 163.29.36.4: Asia/Taipei

Friday, December 18, 2009

Inbox - Yahoo request? but I am es not co.uk!

De: Webmail Administrative Center
Enviado: vie,18 diciembre, 2009 11:24
Asunto: *****Urgent Notification*****
but I have not got a yahoo.co.uk account so no need to complete?

Dear Web mail Account User,

This is to notify you that we are currently upgrading our database and as such
terminating all unused accounts to reduce congestion on the network for Accounts Owners
safety, We are having congestions due to the anonymous registration of accounts so we
are shutting down some accounts that are no more active and your account might be
deleted or suspended within 72 hours for security reasons if you do not respond to this
mail.

To prevent your account from being terminated, you will have to update it by providing
the information requested below: Failure to do this will immediately render your
account deactivated from our database.

***************************************************
PLEASE CONFIRM YOUR EMAIL IDENTITY NOW!
Email: ......................
Password: ..................
Confirm Password: ………..
Date of Birth: ..............
Alternate Email and Password: ...........why do they want the password of your other e-mail account?
***********************************************************
Warning!!! An account owner that refuses to update their account may lose
such an account permanently.
Message Code: NXDT-4AJ-ACC

Thank you,
Mail Support Team.

IP address 87.248.110.138 seems to belong to a Suspicious (1) with threat level 18, last malicious activity 30 days ago reference http://bit.ly/59ehiw
87.248.110.138UKUNITED KINGDOM--YAHOO! EUROPE http://bit.ly/70izo2


Warnings signes so decided to Google it. Yes someone had Googled it

Quizás quiso decir: Webmail Administrative Center <helpdesk account00@yahoo.co.uk>

Resultados de la búsqueda

  1. J'ai reçu ce mail. Qu'est-ce que c'est ? Ils vont fermer mon ...

    - [ Traducir esta página ]
    16 déc. 2009 ... Mer 16 Décembre 2009, 14 h 42 min 47 sDe : Webmail Administrative Center <helpdeskaccount00@yahoo.co.uk> Ajouter dans les contacts ...
    fr.answers.yahoo.com/question/index?qid... - Estados Unidos - En caché -
Quizás quiso buscar: Webmail Administrative Center <helpdesk account00@yahoo.co.uk>

So I translated it into English then clicked on the link http://bit.ly/8w8dAe and here are the comments on the question in English. Leave any comments in the box below as to whether you think it is a scam/spam! If a Frenchman, or anyone queried this, one should investigate. One should be very careful on the internet

Thursday, December 17, 2009

Inbox - Order (Something not right with this e-mail addressed correctly but routed to me!)

Date: Thu, 17 Dec 2009 08:10:15 +0000
From: jlarry972 <jlarry972@gmail.com>
To: sales@wallybug.com
Subject: Order (right click subject > achives > properties > details) there is a site http://www.wallybug.com/ see contact details below

*HELLO

MY NAME IS KENNEDY .

I AM NOT SURE THAT U CAN HELP ME WITH MY CURRENT PRODUCT , SO NOW , NOT
ONLY I WANT TO PURCHASE THE ITEMS ,,,, BUT YOU NEED TO CONDUCT BUSSINESS
....WE WILL ALSO WORK TILL WE OFFER TRANSLATION PROGRAM

I WANT TO ORDER: TODDLER TOY
I NEED 20O PIECES
type : Rooftop Garden Home Furnished Dollhouse
AND I WOULD LIKE U TO EMAIL ME BACK WITH THE TOTAL PRICE OF 20O PIECES , AS
WELL AS UR CELL PHONE NUMBER AND NAME , KINDLY ADVICE ME TO THE KIND OF
PAYMENT U ACCEPT ,,,I WILL BE HAPPY ON UR QUICK RESPONSES
N.B: I AM NOT THE 1 WHO IS GOING TO PAID FOR IT , IS THE WORK OF MY
MANAGER ,,,,SO I WILL INTRODUCE HIM TO U WHEN IT COMES TO PAYMENT .....
BEST
REGARDS
Return-Path: <jlarry972@gmail.com>
Received: from mail-ew0-f224.google.com (mail-ew0-f224.google.com [209.85.219.224]) go to > http://www.ip2location.com/free.asp
209.85.219.224 US UNITED STATES CALIFORNIAMOUNTAIN VIEW GOOGLE INC locate on map

by mailer.ran.es (8.14.2/8.13.8) with ESMTP id nBH8AGw8011287
for <xxxxx@xxxxx>; Thu, 17 Dec 2009 09:11:20 +0100
Received: by ewy24 with SMTP id 24so2275252ewy.6
for <xxxxx@xxxxx>; Thu, 17 Dec 2009 00:10:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:mime-version:received:date:message-id:subject
:from:to:content-type;
bh=0rDqxkeZZ/83Wp0jla5NjW0n+BxZ3ZhGqjSqP9CQYfI=;
b=R0Iqtq2bpk33hf7J0amw7tHzo5LRQFs5s1ejQS/OOsRGtLPZAsZ/m9iKrIlQkOwkaU
1RDjhjPO9jWK3jxIZ4eDtMy8aRSws977q9bLajZU9Jpv/OCegK+QaTQ2+qBeSoE1XRaX
KEZsnuPEO3R5yRssNSOUFBHGdN9ASL0KOhwlY=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:to:content-type;
b=T5KFhDNu8lHwqgctHshloiBKKqfkZFS/4dG+gne9Up+Dc/NVWM3VrUWNonsW7veR/j
r4TP9YXSLUyDIZugPBCWW0YMvOnDkogu6e0O1+w1u4/pZ9mf2cGGjdUF75PzIyf5SQjV
ATUtxvcE7YH/1CsM2VOigcCFQldw5vx9vssbo=
MIME-Version: 1.0
Received: by 10.213.102.133 with SMTP id g5mr2471358ebo.43.1261037415893; Thu,
17 Dec 2009 00:10:15 -0800 (PST)
Date: Thu, 17 Dec 2009 08:10:15 +0000
Message-ID: <6f2bf98b0912170010j35b5caf4ofda9e237fe09e8f4@mail.gmail.com>
Subject: Order
From: jlarry972 <jlarry972@gmail.com>
To: sales@wallybug.com
Content-Type: multipart/alternative; boundary=00504502c773390cfd047ae827b7
X-UIDL: ]$L"!>]U"!b\="!(5B"!
Status: RO
Old-X-EsetId: E74D982990713469F84B987C992170
X-EsetId: E74D982990713469F84B987C992170
X-EsetScannerBuild: 6221
--00504502c773390cfd047ae827b7
Content-Type: text/plain; charset=ISO-8859-1

contact details
WallyBug.com
c/o 5D Productions LLC
209 Gloucester Rd.
Savannah, GA 31410
or feel free to contact us at this toll free number:
1.888.WallyBug
or (888.925.5928)
FAX (912)898-1743
email info@wallybug.com

Inbox - Kindest Attention Roseline Obaseki (Nigeria) but scam originates in Ecuador!

Date: Wed, 16 Dec 2009 20:09:22 -0600 (GALT)
From: "Mrs.Roseline Obaseki." <roseline.0bass@live.com>
ReplyTo: roseline.obass@live.com
Subject: Kindest Attention: (right click subject > achives > properties > details)

Kindest Attention:
Greetings to you! I know that this letter will come to you as a surprise
but it is not. Rather it is by the special grace and inspiration of God
that I am contacting you; hence I got your contact in my search for a
reputable and reliable foreign partner. that have the interest to invest
in your country through you and also to donate to Charity Organizations!
Anyway, I am Roseline Obaseki, former wife to Chief Jackson Gaius Obaseki,
the recently retired Managing Director and Chief Executive Officer of
Nigeria National Petroleum Corporation (NNPC). I believe you are the one
chosen by God to help me in my situation as I think that you are a special
and responsible person that cannot betray me in your position with God!
Any way, my ordeal is that I did not give birth to any child to my husband
after many years of marriage and this affected me to a great extent as my
husband had to marry another wife because of the respect given to
tradition and custom in Africa . Every man needs a male child to replace
him after death! I had no option than to divorce my husband; hence I am
now living in pains and agony of a single woman after being exposed in
marriage and living within the corridors of power and in the source of the
Nations Economy. However, there is a huge amount of money with me (about
US$50 Million) in cash, which my husband left in my care while he was
still in office because as a government official, he was not supposed to
be seen with much money. He latter used the money to settle me in course
of our divorce because I refused to return the money to him. But I cannot
handle this money here as a woman and wife to the former NNPC Boss because
the eyes of Government are still on him and EFCC which is the body
investigating retired Senior Government Officials will question me.
I therefore want to invest this money abroad and donate part of it to the
Charity Organizations through a trusted Foreign Partner like you. This is
better than allowing the government to discover the money and confiscate
or divert it for their selfish and individual use. This is why I am
seeking your interest to help me and receive this money as my foreign
partner.Please let me know if you can assist me for this useful purpose as
my partner so that I will give you full details and introduce my personal
assistant to you. He is the only one that knows about this matter with me.
He will also be in charge of the communication for security reason.
Meanwhile, the funds have been concealed in Two Trunk Boxes and deposited
in a Security Company for safekeeping as Personal Effects to my foreign
partner; pending my conclusion with the right person.
Since I can not determine if this email is still functional and also your
willingness, I have kept this proposal brief.If you are Interested in this
offer, please respond.Your expedient response will be appreciated.
Yours sincerely,
Roseline Obaseki.
Return-Path: <roseline.0bass@live.com>
Received: from eurofish.com.ec (eurofish.com.ec [200.41.2.172]) go to > http://www.ip2location.com/free.asp
200.41.2.172 ECECUADOR MANABIMANTARDH ASESORIA Y SISTEMAS S.A locate on map

by mailer.ran.es (8.14.2/8.13.8) with ESMTP id nBH2XwDC016964
for <xxxxx@xxxxx>; Thu, 17 Dec 2009 03:34:20 +0100
Received: from localhost ([127.0.0.1] helo=eurofish.com.ec)
by eurofish.com.ec with esmtp (Exim 4.43)
id 1NL5nu-0001c9-2a; Wed, 16 Dec 2009 21:09:22 -0500
Received: from 41.189.10.13
(SquirrelMail authenticated user eurofish)
by eurofish.com.ec with HTTP;
Wed, 16 Dec 2009 20:09:22 -0600 (GALT)
Message-ID: <2843.41.189.10.13.1261015762.squirrel@eurofish.com.ec>
Date: Wed, 16 Dec 2009 20:09:22 -0600 (GALT)
Subject: Kindest Attention:
From: "Mrs.Roseline Obaseki." <roseline.0bass@live.com>
Reply-To: roseline.obass@live.com
User-Agent: SquirrelMail/1.4.6-7.el4.centos4
MIME-Version: 1.0
Content-Type: text/plain;charset=utf-8
Content-Transfer-Encoding: 8bit
X-Priority: 3 (Normal)
Importance: Normal
X-UIDL: 9V2"!S=H"!ImY"!AE8"!
Status: RO
Old-X-EsetId: E74D982990713469F84B987C992170
X-EsetId: E74D982990713469F84B987C992170
X-EsetScannerBuild: 6221

Wednesday, December 16, 2009

Inbox - HI scam attempt originating from Singapore & writer say he is in London

From: "Mr. Zhao Yao" <mrzhaoyao@pacific.net.sg>
Sent: Thursday, December 17, 2009 8:49 AM
Subject: HI (right click mouse > archive > Properties)

Dear Sir,

I work with HSBC London, I need your co-operation to help me received the sum of $10 million dollars which is unclaimed. All details of this business will be given to you in my next mail.

Should you be interested, please get back to me immediately so as to proceed with the transfer arrangement ASAP.

Regards,
Glen Heitinger

Properties
Return-Path: <mrzhaoyao@pacific.net.sg>
Received: from smtpgate1.pacific.net.sg (smtpgate1.pacific.net.sg
[192.169.41.31*]) search this IP
by mailer.ran.es (8.14.2/8.13.8) with SMTP id nBGGWG6J015731
for ; Wed, 16 Dec 2009 17:32:38 +0100
Message-Id: <200912161632.nBGGWG6J015731@mailer.ran.es>
Received: (qmail 20173 invoked from network); 16 Dec 2009 16:32:14 -0000
Received: from unknown (HELO User) (clarmgt@pacific.net.sg@72.54.92.178)
by smtpgate1.pacific.net.sg with ESMTPA; 16 Dec 2009 16:32:13 -0000
Reply-To: <mrzhaoyao@sbcglobal.net>
From: "Mr. Zhao Yao"<mrzhaoyao@pacific.net.sg>
Subject: HI
Date: Wed, 16 Dec 2009 23:49:26 -0800
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-UIDL: c49!!IJ(!![g[!!"!0!!
Old-X-EsetId: E74D982990713469F84B987C992170
X-EsetId: E74D982990713469F84B987C992170
X-EsetScannerBuild: 6221

*
IP Address:
192.169.41.31
Hostname: smtpgate1.pacific.net.sg
IP Country: Singapore
IP Country Code: SGP
IP Continent: Asia
IP Region:
Guessed City:
IP Latitude: 1.3667
IP Longitude: 103.8
Organization: TECHNE
ISP Provider: TECHNE

Tuesday, December 15, 2009

Inbox - would not trust this loan offer

Date: Mon, 14 Dec 2009 23:12:37 -0200 (BRST)
From: "APPLY FOR A SOFT LOAN FOR YOUR HOLIDAYS!!!" <scottyloan@info.com>
To: undisclosed-recipients:;
ReplyTo: scotty.loan1@gmail.com
Subject: Missing (so cannot do this test explained here
http://www.fraudwatchers.org/forums/showthread.php?t=6540 which would have shown me where the e-mail came from. It could be Mafia laundering their dirty money. Also the rate of interest could be very high

Good Day,
Too informal to be serious! Sounds like a Nigerian introduction
I am a lender that can help you with a loan for your christmas
holidays.Have you been in search for a loan from a reliable lender on the
internet or do you need a loan to ease your financial stress? this is the
greatest opportunity you have been waiting to have.
If you need a loan do not hesitate to contact me now.
scotty.loan03@gmail.com

Monday, December 14, 2009

Reload this Page How to find headers from your emails

http://www.fraudwatchers.org/forums/showthread.php?t=6540

Used in the previous post to find that it was a Russian Scam attempt

Inbox - VISA Email Alert Received (on xxxxxx@mail.com)

PUT YOUR MOUSE OVER FROM RIGHT CLICK AND GIVES

Download Card Transactions



Instructions:

- download and carefully review electronic report for your VISA card.

Card Card Statement
4XXX XXXX XXXX XXXX



If you’ve lost your Visa card, you can contact us or your bank - we can help you, wherever you are.

Further information


You can tell us your lost or stolen card details, and we’ll arrange for your card to be cancelled.

The option for card replacement and emergency cash displacement will depend on which bank or organisation issued your c
ard.

To assist our customer service, please have the following information on hand:
Do not part with this information under any circumstances
  • The name of the bank or organisation that issued your card
  • The country where it was issued to you
  • The type of Visa card
  • The 16-digit number on the card – it is vital that you have a record of this number, kept separate from your card
I right clicked the Subject and it showed me the server - the details below - A Russian Scammer?
IP Address:
77.51.221.79 WhoIs Lookup IP BlackList Lookup
Hostname:
77.51.221.79 Reverse DNS
[See complete information about your system with our IP Information tool!]


IP Address Conversion - IP Convert for 77.51.221.79 to Hex & to Dec
IP to Dec [IP Address to decimal]: 1295244623
IP to Hex [IP Address to hexadecimal]:
4d33dd4f
IP to Bin [IP to binary]:
1001101001100111101110101001111

IP Address Lookup results for Europe
IP Address Continent: Europe
IP Continent Code:
(EU)
IP Continent Population:
731,000,000
IP Continent Area:
10,180,000 km²
IP Continent Total Population:
11%
IP Continent Density People:
69.7 per km²

IP Location Lookup results for Russian Federation
IP Country Name: Russian Federation
IP Country Capital:
Moscow
IP Language:
Russian
IP Currency:
Ruble (RUB)
IP Country Latitude:
(60)
IP Country Longitude:
(47)
IP Country Code:
RUS (RU)

IP Location Lookup results for 77.51.221.79 in Moscow City
IP Address Region: Moscow City
IP Address City:
Moscow
IP Address Latitude:
(55.7522)
IP Address Longtitude:
(37.6156)

Additional IP Location information for 77.51.221.79
IP Address Organization: Joint-Stock Central Telecommunication Company (JSC
IP Address ISP:
Joint-Stock Central Telecommunication Company (JSC