Wednesday, December 23, 2009

Inbox - haga el favor de confirmar sus datos (message id: 4578117860) pero no soy cliente!

Date: Tue, 22 Dec 2009 21:00:46 -0500
From: "BBVAresponde@grupobbva.com" <BBVAresponde@grupobbva.com>
To: <adi-sl@adi-sl.net>
Subject: haga el favor de confirmar sus datos (message id: 4578117860)

Estimado cliente,

Servicio técnico del banco BBVA renovó el software para mejorar el servicio de los clientes del banco.

Para asegurar la integridad de sus datos Usted tiene que rellenar el Formulario de cliente.

Para empezar a rellenar el formulario pulse en el vínculo:

http://formulario.bbva.es/DFAUTH/DFServlet/LogonServlet.php?id=872386369080917176147905837796403539509826162996995094143548104&email=adi-sl@adi-sl.net

Esto es un mensaje automático, no hace falta que respondas.

Reciba un cordial saludo,

Grupo BBVA.


************************************ DISCLAIMER *****************************************
This message is intended exclusively for the named person. It may contain
confidential, propietary or legally privileged information. No
confidentiality or privilege is waived or lost by any mistransmission. If you receive this
message in error, please immediately delete it and all copies of it from your system,
destroy any hard copies of it and notify the sender. Your must not, directly or
indirectly, use, disclose, distribute, print, or copy any part of this message if you are not
the intended recipient. Any views expressed in this message are those of the
individual sender, except where the message states otherwise and the sender is
authorised to state them to be the views of GrupoBBVA. Please note that internet e-mail
neither guarantees the confidentiality nor the proper receipt of the message sent.
If the addressee of this message does not consent to the use of internet e-mail,
please communicate it to us immediately.

****************************** AVISO LEGAL ***********************************************
Este mensaje es solamente para la persona a la que va dirigido. Puede
contener información confidencial o legalmente protegida. No hay renuncia a
la confidencialidad o privilegio por cualquier transmisión mala/errónea Si
usted ha recibido este mensaje por error, le rogamos que borre de su sistema
inmediatamente el mensaje asi como todas sus copias, destruya todas las
copias del mismo de su disco duro y notifique al remitente. No debe, directa o
indirectamente, usar, revelar, distribuir, imprimir o copiar ninguna de las
partes de este mensaje si no es usted el destinatario. Cualquier opinión expresada en
este mensaje proviene del remitente, excepto cuando el mensaje establezca lo
contrario y el remitente está autorizado para establecer que dichas opiniones
provienen de GrupoBBVA. Nótese que el correo electrónico via Internet no permite asegurar
ni la confidencialidad de los mensajes que se transmiten ni la correcta recepción
de los mismos. En el caso de que el destinatario de este mensaje no consintiera la
utilización del correo electrónico via Internet, rogamos lo ponga en nuestro
conocimiento de manera inmediata.

***********************************************************************************************
Return-Path:
Received: from dsldevice.lan (dsl-189-152-126-40-dyn.prod-infinitum.com.mx [189.152.126.40] (may be forged))
by mailer.ran.es (8.14.2/8.13.8) with ESMTP id nBN20nGD025778;
Wed, 23 Dec 2009 03:01:16 +0100
Message-ID: <000d01ca8373$bdab7a90$6400a8c0@pimplerv2>
From: "BBVAresponde@grupobbva.com"
To:
Subject: haga el favor de confirmar sus datos (message id: 4578117860)
Date: Tue, 22 Dec 2009 21:00:46 -0500
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0007_01CA8373.BDAB7A90"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
X-UIDL: dAY"!]0+"!1-k!!Q/##!
Status: RO
Old-X-EsetId: E74D982990713469F84B987C992670
X-EsetId: E74D982990713469F84B987C992670
X-EsetScannerBuild: 6251

Find sender > right click subject > Archives > Properties > Details
P Address Location results for 189.152.126.40 IP Address: 189.152.126.40 WhoIs Lookup IP BlackList Lookup

IP address 189.152.126.40 seems to belong to a Suspicious (1) with threat level 8, last malicious activity 2 days ago

Hostname: dsl-189-152-126-40-dyn.prod-infinitum.com.mx Reverse DNS
[See complete information about your system with our IP Information tool!]

IP Address Conversion - IP Convert for 189.152.126.40 to Hex & to Dec
IP to Dec [IP Address to decimal]: 3180887592
IP to Hex [IP Address to hexadecimal]:
bd987e28
IP to Bin [IP to binary]:
10111101100110000111111000101000

IP Address Lookup results for North America
IP Address Continent: North America
IP Continent Code:
(NA)
IP Continent Population:
528,720,588
IP Continent Area:
24,709,000 km²
IP Continent Total Population:
8%
IP Continent Density People:
22.9 per km²
IP Continent Latitude:
(46.07305)
IP Continent Longitude:
(-100.546)

IP Location Lookup results for Mexico
IP Country Name: Mexico
IP Country Capital:
Mexico City
IP Language:
Spanish
IP Currency:
Peso (MXN)
IP Country Latitude:
(23)
IP Country Longitude:
(-102)
IP Country Code:
MEX (MX)

IP Location Lookup results for 189.152.126.40 in Nuevo Leon
IP Address Region: Nuevo Leon
IP Address City:
Guadalupe
IP Address Latitude:
(25.6833)
IP Address Longtitude:
(-100.25)

Additional IP Location information for 189.152.126.40
IP Address Organization: Uninet S.A. de C.V.
IP Address ISP:
Uninet S.A. de C.V.

Time zone for 189.152.126.40: America/Cancun
Local time zone for 189.152.126.40:
America/Cancun



Tuesday, December 22, 2009

Inbox - Suntrust Bank is in Forida USA so why does e-mail come from Romania?

De: SunTrust
Fecha: martes, 22 de diciembre de 2009 18:45
Para: xxxxxx
Asunto: important notice from SunTrust [message ref: 6562794573]

Reference Number: 20093758813155

Digital Certificate Creation.

Dear Customer,

You need to create your own Digital Certificate for SunTrust Online Treasury Manager service.

Begin certificate request by using this hyperlink.



SunTrust Bank, Member FDIC. © 2009 SunTrust Banks, Inc. SunTrust is a federally registered service mark of SunTrust Banks, Inc.
Live Solid. Bank Solid. is a service mark of SunTrust Banks, Inc.

This email was sent on behalf of SunTrust Customer Care, 1575 Lemon Farris Road, Cookeville, TN 38506.

Find where e-mail came from - Right click Subject > Archives > Properties > Details
Return-Path:
Received: from NJKCGQFGSF ([109.96.224.238])
by mailer.ran.es (8.14.2/8.13.8) with ESMTP id nBMHk1CR002465
for ; Tue, 22 Dec 2009 18:46:22 +0100
Received: from 109.96.224.238 by gw2.smart-server.net; Tue, 22 Dec 2009 19:45:58 +0200
From: "SunTrust"
To:
Subject: important notice from SunTrust [message ref: 6562794573]
Date: Tue, 22 Dec 2009 19:45:58 +0200
Message-ID: <000d01ca832e$9e712570$6400a8c0@endocrine54>
MIME-Version: 1.0

IP Address Location results for 109.96.224.238
IP Address: 109.96.224.238 WhoIs Lookup IP BlackList Lookup

Ip address 109.96.224.238 is NOT listed in RBL (Real-time Blackhole List) database and it is not on any Spam Blacklist (yet)

Hostname:
109.96.224.238 Reverse DNS
[See complete information about your system with our IP Information tool!]

IP Address Conversion - IP Convert for 109.96.224.238 to Hex & to Dec
IP to Dec [IP Address to decimal]: 1835065582
IP to Hex [IP Address to hexadecimal]:
6d60e0ee
IP to Bin [IP to binary]:
1101101011000001110000011101110

IP Address Lookup results for Europe
IP Address Continent: Europe
IP Continent Code:
(EU)
IP Continent Population:
731,000,000
IP Continent Area:
10,180,000 km²
IP Continent Total Population:
11%
IP Continent Density People:
70.00 per km²
IP Continent Latitude:
(48.69083)
IP Continent Longitude:
(9.1405)

IP Location Lookup results for Romania
IP Country Name: Romania
IP Country Capital:
Bucharest
IP Language:
Romanian
IP Currency:
Leu(L) (RON)
IP Country Latitude:
(46)
IP Country Longitude:
(25)
IP Country Code:
ROU (RO)

IP Location Lookup results for 109.96.224.238 in Bucuresti
IP Address Region: Bucuresti
IP Address City:
Bucharest
IP Address Latitude:
(44.4333)
IP Address Longtitude:
(26.1)

Additional IP Location information for 109.96.224.238
IP Address Organization: Romtelecom Data Network
IP Address ISP: No data found for 109.96.224.238

Time zone for 109.96.224.238: Europe/Bucharest
Local time zone for 109.96.224.238:
Europe/Bucharest
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01CA832E.9E712570"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.3416
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1478
Importance: Normal
X-UIDL: %7M!!E^\"!O?

Monday, December 21, 2009

Inbox - I am not an Italian and have no account with BancaEtruria

Ci e arrivata una segnalazione di accredito di Euro 100,00.
L’accredito e stato temporaneamente bloccato a causa dell’incongruenza dei suoi dati.
Potra ora verificare i suoi dati e successivamente sara accreditato l’accredito ricevuto:

Cordiali saluti,
Banca Etruria

TELEFONO
Numero gratuito 800.68.68.68 (dal lunedì al sabato dalle ore 9 alle ore 20)

Subject > Archives > Properties - to find sender´s IP
Return-Path:
Received: from smtpsmart2.aruba.it (smtpweb113.aruba.it [62.149.158.113])
by mailer.ran.es (8.14.2/8.13.8) with SMTP id nBL7oTX8031888
for ; Mon, 21 Dec 2009 08:50:50 +0100
Received: (qmail 26446 invoked by uid 89); 21 Dec 2009 07:50:25 -0000
Received: by simscan 1.2.0 ppid: 26266, pid: 26281, t: 1.4749s
scanners: clamav: 0.88.4/m:40/d:1945 spam: 3.1.4
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on
smtpsmart2.ad.aruba.it
X-Spam-Level: ***
X-Spam-Status: No, score=3.8 required=5.0 tests=BAYES_00,HTML_IMAGE_ONLY_16,
HTML_TAG_BALANCE_HEAD,MIME_HTML_ONLY,RDNS_NONE,SUBJECT_NEEDS_ENCODING,
URIBL_PH_SURBL autolearn=disabled version=3.2.5
Received: from unknown (HELO webs215.aruba.it) (62.149.130.225)
by smtpsmart2.fe.aruba.it with SMTP; 21 Dec 2009 07:50:23 -0000
Received: from WEBS215 ([127.0.0.1]) by webs215.aruba.it with Microsoft SMTPSVC(6.0.3790.3959);
Mon, 21 Dec 2009 08:48:04 +0100
Date: Mon, 21 Dec 2009 08:48:04 +0100
Subject: Potra ora verificare i suoi dati e successivamente sara accreditato l’accredito ricevuto:
To: webmaster@itccommunications.net
From: Banca Etruria
Reply-To: info@bancaetruria.it
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-ID:
X-OriginalArrivalTime: 21 Dec 2009 07:48:04.0887 (UTC) FILETIME=[EDC86A70:01CA8211]
X-UIDL: H?E"!DRM"!'`:!!a]*!!
Status: U
Old-X-EsetId: E74D982990713469F84B987C992770
X-EsetId: E74D982990713469F84B987C992770
X-EsetScannerBuild: 6241

158.113 IP Address: 62.149.158.113 WhoIs Lookup IP BlackList Lookup

IP address 62.149.158.113 seems to belong to a Suspicious (1) with threat level 16, last malicious activity 44 days ago

Hostname: smtpweb113.aruba.it Reverse DNS
[See complete information about your system with our IP Information tool!]

IP Address Conversion - IP Convert for 62.149.158.113 to Hex & to Dec
IP to Dec [IP Address to decimal]: 1049992817
IP to Hex [IP Address to hexadecimal]: 3e959e71
IP to Bin [IP to binary]: 111110100101011001111001110001

IP Address Lookup results for Europe
IP Address Continent: Europe
IP Continent Code:(EU)
IP Continent Population: 731,000,000
IP Continent Area: 10,180,000 km²
IP Continent Total Population: 11%
IP Continent Density People: 70.00 per km²
IP Continent Latitude: (48.69083)
IP Continent Longitude: (9.1405)

IP Location Lookup results for Italy
IP Country Name: Italy
IP Country Capital: Rome
IP Language: Italian
IP Currency: Euro(€) (EUR)
IP Country Latitude: (42.83)
IP Country Longitude: (12.83)
IP Country Code: ITA (IT)

IP Location Lookup results for 62.149.158.113 in Toscana
IP Address Region: Toscana
IP Address City: Arezzo
IP Address Latitude: (43.4167)
IP Address Longtitude: (11.8833)

Additional IP Location information for 62.149.158.113
IP Address Organization: Aruba S.p.A. - Shared Hosting and Mail services
IP Address ISP: Aruba S.p.A.

Time zone for 62.149.158.113: Europe/Rome
Local time zone for 62.149.158.113: Europe/Rome

Inbox - El empleo con horario flexible --Fraude

Sent: Monday, December 21, 2009 11:02 AM
Subject: El empleo con horario flexible

Señores:

Somos una Compañía Internacional y actualmente contamos con unas vacantes.

Las vacantes se proponen sólo para los residentes de los países de Europa.

Esta colaboración con nuestra compañía se comprende el cargo de un representante regional (gerente regional). Se trata de efectuar las operaciones financieras con nuestros clientes, o sea en la recepción y envío de las pagas lo más rápido posible.

El labor del gerente regional es bastante sencillo y fácil. Los gerentes de plantilla estarán siempre a su disposición durante el período de adiestramiento cuando ellos les ayudarán a Uds. con el fin brindarle la información y métodos referentes al trabajo en cuestión.

Nuestra compañía cuenta un sistema flexible de remuneración. El salario en el primer mes de colaboración será de 2,400 euros. En lo adelante el salario dependerá de su trabajo: mientras más tiempo se dedica al trabajo, más dinero se cobra. En este caso el aumento del salario será notable y se notará muy rápido.

Para iniciar su colaboración en nuestra sólo hay que hacer el primer paso.

Se les solicita se envíe un mensaje electrónico a la dirección: trishreding47@gmail.com con la siguiente información:

Nombre - Apellidos - País de residencia - Ciudad - Edad - Teléfono de contacto

Los mensajes sin estos datos no se estudiarán.

Una vez recibido este mensaje, dentro de 2 ó 3 días nuestros gerentes se comunicarán con Uds. para brindarles más detalles sobre su cargo.

Subject > Archives > Properties - to find sender´s IP

Return-Path: <
prompters95@sanriotown.com>
Received: from ip-77.24.53.148.web.vodafone.de (ip-77.
25.122.08.web.vodafone.de [77.25.122.108])
by mailer.ran.es (8.14.2/8.13.8) with ESMTP id nBLA2GfD016839;
Mon, 21 Dec 2009 11:02:37 +0100
Received: from 77.25.122.108 by sanriotown-com-bk.mr.outblaze.com; Mon, 21 Dec 2009 11:02:14 +0100
From: "Alejandra Boucher" <Boucher1935@zipolite.com>
To: <3dfunkyhairuar@xxxxxxxxxxxx
Subject: El empleo con horario flexible
Date: Mon, 21 Dec 2009 11:02:14 +0100
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01CA8224.AB960690"
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
Thread-Index: Aca6QHVQNSYYWWBLDLO977LKG316I4==
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Message-ID: <000d01ca8224$ab960690$6400a8c0@prompters95>
X-UIDL: ^,"#!-U)!!SHa"![9i"!
Status: RO
Old-X-EsetId: E74D982990713469F84B987C992770
X-EsetId: E74D982990713469F84B987C992770
X-EsetScannerBuild: 6241

IP Address: 77.24.53.148 WhoIs Lookup IP BlackList Lookup

IP address 77.24.53.148 seems to belong to a Suspicious (1) with threat level 14, last malicious activity 2 days ago

Hostname: ip-77-24-53-148.web.vodafone.de Reverse DNS
[See complete information about your system with our IP Information tool!]

IP Address Conversion - IP Convert for 77.24.53.148 to Hex & to Dec
IP to Dec [IP Address to decimal]: 1293432212
IP to Hex [IP Address to hexadecimal]:
4d183594
IP to Bin [IP to binary]:
1001101000110000011010110010100

IP Address Lookup results for Europe
IP Address Continent: Europe
IP Continent Code:
(EU)
IP Continent Population:
731,000,000
IP Continent Area:
10,180,000 km²
IP Continent Total Population:
11%
IP Continent Density People:
70.00 per km²
IP Continent Latitude:
(48.69083)
IP Continent Longitude:
(9.1405)

IP Location Lookup results for Germany
IP Country Name: Germany
IP Country Capital:
Berlin
IP Language:
German
IP Currency:
Euro(€) (EUR)
IP Country Latitude:
(51.5)
IP Country Longitude:
(10.5)
IP Country Code:
DEU (DE)

IP Location Lookup results for 77.24.53.148 in
IP Address Region: No data found for 77.24.53.148
IP Address City: No data found for 77.24.53.148
IP Address Latitude:
(51)
IP Address Longtitude:
(9)

Additional IP Location information for 77.24.53.148
IP Address Organization: Vodafone D2 GmbH
IP Address ISP:
Vodafone D2 GmbH

Time zone for 77.24.53.148: Europe/Berlin
Local time zone for 77.24.53.148:
Europe/Berlin