Google

World Wide Web anti-scam


Seitenindex umschalten Seiten: 1 Thema versenden
Normales Thema Olga <likkeolenk@gmail.com> (Gelesen: 514 mal)
 
Macky
Themenstarter Themenstarter
Scam Warners
*****
Offline


I Love Anti-Scam!

Beiträge: 83
Mitglied seit: 02. Januar 2015
Geschlecht: männlich
Olga <likkeolenk@gmail.com>
17. Dezember 2016 um 16:07
 
Hello my new friend! I am an attractive girl and an interesting conversationalist.
My name is Olga. I'm 31! I'm looking for a serious and long term relationship.
I'm looking for a man with whom will build a family.
I hope you like my picture, and I'm interested in you.
Answer me, and I will talk about themselves and post new photos. Olga.

Spoiler:
Return-Path: <edxqkzb@host04.onlinenic.com>
X-Original-To: xxx
Received: from mail-in-11.arcor-online.net (mail-in-11.arcor-online.net [151.189.21.51])
     by mail-in-15-z2.arcor-online.net (Postfix) with ESMTP id BC50E33FEBB
     for <xxx>; Fri, 16 Dec 2016 11:06:51 +0100 (CET)
Received: from vsmx004.vodafonemail.xion.oxcs.net (vsmx004.vodafonemail.xion.oxcs.net [153.92.174.109])
     (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
     (No client certificate requested)
     by mx.arcor.de (Postfix) with ESMTPS id 3tg5ZM4YfxzWxkW
     for <xxx>; Fri, 16 Dec 2016 11:06:48 +0100 (CET)
Received: from mta-p1.oxcloud-vadesecure.net (mta-p1.oxcloud-vadesecure.net [153.92.174.51])
     by mx.vodafonemail.xion.oxcs.net (Postfix) with ESMTP id 3tg5Nd23cRz3ycZ
     for <xxx>; Fri, 16 Dec 2016 09:58:22 +0000 (UTC)
Received: from host04.onlinenic.com (host04.onlinenic.com [216.245.210.50])
     (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
     (No client certificate requested)
     by mta-p1.oxcloud-vadesecure.net (ox1mtai15p) with ESMTPS id 11E82140A7E
     for <xxx>; Fri, 16 Dec 2016 09:57:59 +0000 (UTC)
Received: from edxqkzb by host04.onlinenic.com with local (Exim 4.87)
     (envelope-from <edxqkzb@host04.onlinenic.com>)
     id 1cHooK-00046M-4V
     for xxx; Fri, 16 Dec 2016 03:28:16 -0600
To: xxx
Subject: To the perfect man!
X-PHP-Script: 216.245.210.50/~edxqkzb/bin1.php for 78.108.184.100
From: <likkeolenk@gmail.com>
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: PHP/5.5.32
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="1481880496SPB"
Message-Id: <E1cHooK-00046M-4V@host04.onlinenic.com>
Date: Fri, 16 Dec 2016 03:28:16 -0600
X-AntiAbuse: This Quelltext was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - host04.onlinenic.com
X-AntiAbuse: Original Domain - arcor.de
X-AntiAbuse: Originator/Caller UID/GID - [891 162] / [47 12]
X-AntiAbuse: Sender Address Domain - host04.onlinenic.com
X-Get-Message-Sender-Via: host04.onlinenic.com: authenticated_id: edxqkzb/only user confirmed/virtual account not confirmed
X-Authenticated-Sender: host04.onlinenic.com: edxqkzb
« Zuletzt geändert: 20. Dezember 2016 um 20:59 von Stiray » 
Grund: Themenbeschreibung 

I_034.jpg ( 53 KB | Downloads )
I_034.jpg
Zum Seitenanfang
 
IP gespeichert
 
Indikation
Stiray
Forum Administrator
*****
Offline


Stillstand ist die Vorstufe
des Untergangs

Beiträge: 67933
Mitglied seit: 09. Juni 2011
Geschlecht: männlich
Re: Olga <likkeolenk@gmail.com>
Antwort #1 - 17. Dezember 2016 um 19:42
 
Der Scammer hat ein Script auf einem Server in Tschechien installiert. Er schreibt seine Mail über diesen
Server und versendet sie dann über den genannten Server in Texas. Das ist die totale Verschleierung.

Code
Alles auswählen
IP:	78.108.184.100
Decimal:	1315747940
Hostname:	78.108.184.100
ASN:	62160
ISP:	Yes Networks Unlimited Ltd
Organization:	Yes Networks Unlimited Ltd
Services:	None detected
Assignment:	Static IP
Continent:	Europe
Country:	Czechia 



Code
Alles auswählen
IP:	216.245.210.50
Decimal:	3639988786
Hostname:	host04.onlinenic.com
ASN:	46475
ISP:	Limestone Networks
Organization:	Limestone Networks
Services:	None detected
Type:	Corporate
Assignment:	Static IP
Continent:	North America
Country:	United States
State/Region:	Texas
City:	Dallas 



Zitat:
from host04.onlinenic.com (host04.onlinenic.com [216.245.210.50]) [...] with ESMTPS; Fri, 16 Dec 2016 09:57:59 +0000 (UTC)
From: <likkeolenk@gmail.com>
Date: Fri, 16 Dec 2016 03:28:16 -0600


Zitat:
X-PHP-Script: 216.245.210.50/~edxqkzb/bin1.php for 78.108.184.100


Zitat:
X-Mailer: PHP/5.5.32


Identische Einlieferung hatten wir hier: Lyubov <lyubov-boiyko@gailmail.pp.ua> <lyubov-boiyko@i.ua> <yana-timofeeva@ua.fm>
« Zuletzt geändert: 17. Dezember 2016 um 19:46 von Stiray »  
Zum Seitenanfang
 
IP gespeichert
 
Macky
Themenstarter Themenstarter
Scam Warners
*****
Offline


I Love Anti-Scam!

Beiträge: 83
Mitglied seit: 02. Januar 2015
Geschlecht: männlich
Re: Olga <likkeolenk@gmail.com>
Antwort #2 - 20. Dezember 2016 um 14:01
 
Jetzt kommt sie aus Russland (Severouralsk):

Hi xxx!
I am very pleased that you have answered me.
I have never used the Internet for dating.
And no hope, I expect you to write to me. I hope that we will be pleased to correspond.
Thus we will be able to get acquainted and learn about each other a lot.
Now I will tell you a little about me. My name is Olga. I am 31 years old. I look younger than their age. I understand it's hard to believe but it's true.
I was born on 19 May. My height is 170 cm and my weight is 54 kg. My zodiac sign Taurus!
I live in Russia. My town is called Severouralsk. It is in the Sverdlovsk region! This is a very small town with a population of only 27,000 people!
You're probably surprised that I was from Russia ?? I hope long-distance relationship will not be a problem for you? I would like to hope so.
I am sure that the distance is not a problem for you!
I live with my parents in a small apartment.
Every day, except on weekends I go to work. I work in the school of my city. I am a teacher of geography!
I like my job. Since childhood I have dreamed of such work.
Every day I go to work in a good mood.
What is your job? What exactly do you want to know about me?
What qualities do you like in a girl?
Why did you decide to seek your destiny on the Internet?
I am happy to answer your questions.
I send you my picture. I hope you like it.
I look forward to wait for your letter.
Your new friend Olga.

Spoiler:
From - Tue Dec 20 13:35:31 2016
X-Account-Key: account4
X-UIDL: UID15681-1089133801
X-Mozilla-Status: 0011
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:                                                                                 
Return-Path: <likkeolenk@gmail.com>
X-Original-To: xxx
Received: from mail-in-13.arcor-online.net (mail-in-13.arcor-online.net [151.189.21.53])
     by mail-in-20-z2.arcor-online.net (Postfix) with ESMTP id BD1EB840B51
     for <xxx>; Tue, 20 Dec 2016 13:11:27 +0100 (CET)
Received: from vsmx004.vodafonemail.xion.oxcs.net (vsmx004.vodafonemail.xion.oxcs.net [153.92.174.109])
     (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
     (No client certificate requested)
     by mx.arcor.de (Postfix) with ESMTPS id 3tjc8H2sYCzWf0G
     for <xxx>; Tue, 20 Dec 2016 13:11:27 +0100 (CET)
Received: from mta-p1.oxcloud-vadesecure.net (mta-p1.oxcloud-vadesecure.net [153.92.174.46])
     by mx.vodafonemail.xion.oxcs.net (Postfix) with ESMTP id 3tjXtQ3wV1z4QfM
     for <xxx>; Tue, 20 Dec 2016 09:44:14 +0000 (UTC)
Received: from mail-yw0-f194.google.com (mail-yw0-f194.google.com [209.85.161.194])
     (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
     (No client certificate requested)
     by mta-p1.oxcloud-vadesecure.net (ox1mtai04p) with ESMTPS id BF0F31A02EF
     for <xxx>; Tue, 20 Dec 2016 09:44:12 +0000 (UTC)
Received: by mail-yw0-f194.google.com with SMTP id s68so10313313ywg.0
        for <xxx>; Tue, 20 Dec 2016 01:44:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20161025;
        h=date:from:to:subject:in-reply-to:references:message-id:mime-version
         :content-transfer-encoding;
        bh=HWBA3oZqo22AFUl8IpMFLMQiW8gcJnnyeTAXquKw1EU=;
        b=JmPgrA8j8VSfkMAK4nSZo3RRgZ4FUTZpgvTxcQghhqoXplMh5BBCZQqBnq/VsK+TQS
         wMRG7XrfTIsYGJrmPQnkIWChCazTl82XxTkl5OugY+XWKvwNgrAA42Pa6MNostYwZSAn
         JfvMx8oR1YAxQcfbdnV0W859v58w3qI4T/LmqiC5kRrwkjaN7IqE3d32L5tor8eg9ZQg
         U6E6elylf1SQzEWtY/WWJkM3SfCkptd3PDh4PWwFvtpEDPv4a7zK1VvUDTxN0IlM97Sh
         nXpuzBugI+HeoiVWxMz5VDCE7CYrta2whR/3vSqPBCp9FK8aANgNkwZHurlmuXSIoPpD
         3SLQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:date:from:to:subject:in-reply-to:references
         :message-id:mime-version:content-transfer-encoding;
        bh=HWBA3oZqo22AFUl8IpMFLMQiW8gcJnnyeTAXquKw1EU=;
        b=A69emOE6GtJsxLCRes/1rrSIgYXjkwfPbVWdbEjAIg0traRb/pS8c1PpQ5F/AgaZTW
         25G4GiVEr9eB1RhAPuZfOC6Q3k381jJR5hj+pYudcfzSL3OADvoO2TojhXraX8o0B3Ue
         LaE680FjaA0TMtmDRqQ5E7VNN9Adqfa8+9s0SXUKjeqLPfytnjSjmiSJJYs+RJfQcuuz
         DAq3W/ybQICwSQvoOXARvAJ5mZDKYiIEQw6TTJpwUjszJ1TBVsgGCPHDapr8SjkB0e4k
         f5DlDXpAWF/zRsFCAgLBG7XSuvQH05g6E3ACyw8/o4xLPCwAmzO89ioUye/rNXx/urPW
         8TPg==
X-Gm-Message-State: AKaTC03xiywdGrBRdb1YWL8RPnyCsMDnoq94iAU/sMR5s1uzP/3/9f/0TZ9T7f1nwOLQ2A==
X-Received: by 10.129.84.6 with SMTP id i6mr14791164ywb.271.1482227045893;
        Tue, 20 Dec 2016 01:44:05 -0800 (PST)
Received: from [192.168.50.250] ([104.243.37.106])
        by smtp.gmail.com with ESMTPSA id d136sm8978458ywh.50.2016.12.20.01.43.47
        for <xxx>
        (version=TLS1 cipher=ECDHE-RSA-AES128-SHA bits=128/128);
        Tue, 20 Dec 2016 01:44:05 -0800 (PST)
Date: Tue, 20 Dec 2016 12:43:44 +0300
From: Olga <likkeolenk@gmail.com>
To: xxx
Subject: Re: To the perfect man!
In-Reply-To: <ee1ed71e-1ed9-d5dc-de01-8fee7384989f@arcor.de>
References: <E1cHooK-00046M-4V@host04.onlinenic.com> <ee1ed71e-1ed9-d5dc-de01-8fee7384989f@arcor.de>
Message-Id: <20161220112636.D772.A023BCAD@gmail.com>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="------_5857C37800000000F383_MULTIPART_MIXED_"
Content-Transfer-Encoding: 7bit
X-Mailer: Becky! ver. 2.64.03 [Ru]
X-VRC-SPAM-STATUS: dprhgtphhtthhopeiffiifqdhmrggtkhihsegrrhgtohhrrdguvg
X-VRSPAM-STATE: spam
X-VR-SPAM-STATE: 1
X-VR-SPAM-SCORE: 300
X-Virus-Status-VR: clean
X-Virus-Status-CA: clean
X-Spam: Yes
X-Spam: Low
X-VRC-SPAM-STATUS: dprhgtphhtthhopeiffiifqdhmrggtkhihsegrrhgtohhrrdguvg
X-VRSPAM-STATE: spam
X-VRC-POLICY-STATUS: t=2,a=1,l=2
X-PIA-SORT: Spam


Die Bilder scheinen jetzt aber von jemand anderem zu sein:

  

Me_039.jpg ( 428 KB | Downloads )
Me_039.jpg
Me1.jpg ( 344 KB | Downloads )
Me1.jpg
Zum Seitenanfang
 
IP gespeichert
 
Razor Buzz
Forum Administrator
Paragraphenreiter Öffentlichkeitsarbeit
*****
Offline


Servus

Beiträge: 5904
Standort: Oberpfalz
Mitglied seit: 24. April 2008
Re: Olga <likkeolenk@gmail.com>
Antwort #3 - 20. Dezember 2016 um 15:31
 
@ Macky

Ich habe meine Zweifel, ob das die selbe Frau ist....


Kommt über die USA:

Code
Alles auswählen
General IP Information

IP:	104.243.37.106
Decimal:	1760765290
Hostname:	hosted-by.reliablesite.net
ASN:	20473
ISP:	ReliableSite.Net LLC
Organization:	Choopa, LLC
Services:	Network sharing device or proxy server
Type:	Corporate
Assignment:	Static IP
Blacklist:	Blacklist Check
Geolocation Information

Country:	United States
State/Region:	Massachusetts
City:	West Bridgewater
Latitude:	42.0396674  (42° 2′ 22.80″ N)
Longitude:	-70.9876970  (70° 59′ 15.71″ W)

 

« Zuletzt geändert: 20. Dezember 2016 um 16:03 von Razor Buzz »  
Zum Seitenanfang
ICQ  
IP gespeichert
 
Stiray
Forum Administrator
*****
Offline


Stillstand ist die Vorstufe
des Untergangs

Beiträge: 67933
Mitglied seit: 09. Juni 2011
Geschlecht: männlich
Re: Olga <likkeolenk@gmail.com>
Antwort #4 - 20. Dezember 2016 um 20:58
 
Verwendet jetzt einen anderen Mailer.

Zitat:
from [192.168.50.250] ([104.243.37.106]) by smtp.gmail.com with ESMTPSA; Tue, 20 Dec 2016 01:44:05 -0800 (PST)
Date: Tue, 20 Dec 2016 12:43:44 +0300
From: Olga <likkeolenk@gmail.com>
X-Mailer: Becky! ver. 2.64.03 [Ru]


  
Zum Seitenanfang
 
IP gespeichert
 
Seitenindex umschalten Seiten: 1
Thema versenden
Link zu diesem Thema