Google

World Wide Web anti-scam


Seitenindex umschalten Seiten: 1 Thema versenden
Normales Thema Steve <stevekwame11@rediff.com> (Gelesen: 1058 mal)
 
your hunter
Themenstarter Themenstarter
Forum Moderator
*****
Offline


powered by Debian GNU/Linux

Beiträge: 4640
Standort: Graz
Mitglied seit: 12. Mai 2010
Geschlecht: männlich
Steve <stevekwame11@rediff.com>
26. April 2011 um 21:27
 
Eng. Steve Kwame.
Ministry of Energy.
Plot 2008 Castle Road.
Osu, Accra Ghana.

Dear Sir,

I am Engineer Steve Kwame, a Director of the Contracts Award and review Department with the Ghana Ministry of energy (M.O.E). I am contacting you for an urgent and important business dealing which will be beneficial to both of us, and with out any risks as regards this would be business dealing, I don't know if I can confide in you, though we may be in two different countries apart, but that is what I actually needed in a partner, someone from a distant place or country, please do revert back to me if you think we can work for the good of both of us in good faith, as that will enable me to let you into the project proper.

Please do send to me your telephone number in your next email, to enable us talk in confidence about this proposal.
Thanks.
Eng.Steve Kwame

Spoiler:
------------=_4DB70C68.B6AFDB95
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

X-Virus-Flag: no
scandesc returned: -1790781085
Received: from [140.119.65.101] (helo=mail.math.nccu.edu.tw)
     by mx40.web.de with esmtp (WEB.DE 4.110 #2)
     id 1QEbQU-0002Z4-00
     for xxxxx@web.de; Tue, 26 Apr 2011 08:07:10 +0200
Received: from User (41-218-231-207-adsl-dyn.4u.com.gh [41.218.231.207])
     by mail.math.nccu.edu.tw (Postfix) with ESMTPA id 82FC4168ED92;
     Tue, 26 Apr 2011 08:43:46 +0800 (CST)
Reply-To: <stevekwame@rediff.com>
From: "Eng. Steve Kwame"<stevekwame11@rediff.com>
Subject: Notify me
Date: Tue, 26 Apr 2011 00:47:23 -0700
MIME-Version: 1.0
Content-Type: text/plain;
     charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Antivirus: avast! (VPS 110425-1, 04/25/2011), Outbound message
X-Antivirus-Status: Clean
Message-Id: <E1QEbQU-0002Z4-00@mx40.web.de>
Bcc:
Return-Path: stevekwame11@rediff.com
X-Virus-Status: No
X-Virus-Checker: Scanned by KlamAV 0.46 on debian-yedi (no viruses);
     Tue, 26 Apr 2011 20:18:09 +0200
X-UID:


Spamaassassin
Received: from localhost by xxxxx-xxxxx
     with SpamAssassin (version 3.3.1);
     Tue, 26 Apr 2011 20:18:16 +0200
From: "Eng. Steve Kwame"<stevekwame11@rediff.com>
Subject: Notify me
Date: Tue, 26 Apr 2011 00:47:23 -0700
Message-Id: <E1QEbQU-0002Z4-00@mx40.web.de>
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on debian-yedi
X-Spam-Flag: YES
X-Spam-Level: ***************
X-Spam-Status: Yes, score=15.5 required=5.0 tests=DEAR_SOMETHING,
     FORGED_MUA_OUTLOOK,FROM_MISSP_MSFT,MISSING_HEADERS,MSOE_MID_WRONG_CASE,
     RDNS_NONE,REPLYTO_WITHOUT_TO_CC,T_FROM_MISSPACED,URG_BIZ autolearn=spam
     version=3.3.1
MIME-Version: 1.0
Content-Type: multipart/mixed;
  boundary="----------=_4DB70C68.B6AFDB95"
X-UID: 
Status: RO
X-Status: RP
X-KMail-EncryptionState:  
X-KMail-SignatureState:  
X-KMail-MDN-Sent:  

This is a multi-part message in MIME format.

------------=_4DB70C68.B6AFDB95
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Software zur Erkennung von "Spam" auf dem Rechner

    xxxxx-xxxxx

hat die eingegangene E-mail als mögliche "Spam"-Nachricht identifiziert.
Die ursprüngliche Nachricht wurde an diesen Bericht angehängt, so dass
Sie sie anschauen können (falls es doch eine legitime E-Mail ist) oder
ähnliche unerwünschte Nachrichten in Zukunft markieren können.
Bei Fragen zu diesem Vorgang wenden Sie sich bitte an

    @@CONTACT_ADDRESS@@

Vorschau: Eng. Steve Kwame. Ministry of Energy. Plot 2008 Castle Road.
   Osu, Accra Ghana. Dear Sir, I am Engineer Steve Kwame, a Director of the
  Contracts Award and review Department with the Ghana Ministry of energy (M.O.E).
   I am contacting you for an urgent and important business dealing which will
   be beneficial to both of us, and with out any risks as regards this would
   be business dealing, I don't know if I can confide in you, though we may
  be in two different countries apart, but that is what I actually needed in
   a partner, someone from a distant place or country, please do revert back
   to me if you think we can work for the good of both of us in good faith,
  as that will enable me to let you into the project proper. [...] 

Inhaltsanalyse im Detail:   (15.5 Punkte, 5.0 benötigt)

Pkte Regelname              Beschreibung
---- ---------------------- --------------------------------------------------
0.0 T_FROM_MISSPACED       From: missing whitespace
0.9 MISSING_HEADERS        Empfängeradresse ("To") fehlt
2.0 DEAR_SOMETHING         BODY: Anonyme Anrede ("dear ...")
1.8 URG_BIZ                BODY: Dringende Geschäfte
2.4 REPLYTO_WITHOUT_TO_CC  REPLYTO_WITHOUT_TO_CC
1.0 FROM_MISSP_MSFT        From misspaced + supposed Microsoft tool
2.4 RDNS_NONE              Delivered to internal network by a host with no rDNS
1.0 MSOE_MID_WRONG_CASE    MSOE_MID_WRONG_CASE
4.0 FORGED_MUA_OUTLOOK     E-Mail täuscht E-Mail-Software Outlook vor


Code
Alles auswählen
xxxxx@xxxxx-xxxxx:~$ whois 41.218.231.207
% Information related to '41.218.224.0 - 41.218.255.255'
inetnum:        41.218.224.0 - 41.218.255.255
netname:        ghanatel
descr:          Ghana Telecom ADSL DYNAMIC ADDRESS EXPANDED POOL2
country:        GH 


« Zuletzt geändert: 26. April 2011 um 23:37 von lemansue »  
Zum Seitenanfang
HomepageGTalk  
IP gespeichert
 
Indikation
lemansue
General Counsel
***
Offline


trust no cheater

Beiträge: 32968
Mitglied seit: 12. November 2010
Geschlecht: männlich
Steve <stevekwame11@rediff.com>
Antwort #1 - 26. April 2011 um 23:34
 
@ your hunter

I not understand it here . I see more headers can you explaine it?? Smiley Smiley

« Zuletzt geändert: 26. April 2011 um 23:38 von lemansue »  
Zum Seitenanfang
 
IP gespeichert
 
your hunter
Themenstarter Themenstarter
Forum Moderator
*****
Offline


powered by Debian GNU/Linux

Beiträge: 4640
Standort: Graz
Mitglied seit: 12. Mai 2010
Geschlecht: männlich
Re: Steve <stevekwame11@rediff.com>
Antwort #2 - 27. April 2011 um 05:17
 
diese Informationen liefert kein Mail-Klient - sondern werden von Spamassassin vom Server ausgelesen

This information does not provide a mail client - but will be taken by the server from Spam Assassin

http://anti-scam.de/cgi-bin/yabb2/YaBB.pl?num=1303073944
  
Zum Seitenanfang
HomepageGTalk  
IP gespeichert
 
Seitenindex umschalten Seiten: 1
Thema versenden
Link zu diesem Thema