Google

World Wide Web anti-scam


Seitenindex umschalten Seiten: 1 Thema versenden
Normales Thema Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com> (Gelesen: 1556 mal)
 
bigbear
Themenstarter Themenstarter
General Counsel
***
Offline


I Love Anti-Scam

Beiträge: 1331
Mitglied seit: 08. September 2009
Geschlecht: männlich
Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com>
26. Januar 2017 um 19:13
 
Hello! My name is Zinaida! I was told your email in the agency of acquaintances and was told that you too lonely and
looking for a woman. It's true? I decided to try to meet you. Tell us about yourself.
I am 37 years old, I'm a lonely girl. I want to meet a man with whom you'll be ready to bind
own life. If you are looking for a serious relationship and then I will be very glad to know you better.
I'll look forward to hearing
Zinaida.

Spoiler:
Delivered-To: xxx
Received: by 10.107.174.212 with SMTP id n81csp117503ioo;
        Thu, 26 Jan 2017 02:32:53 -0800 (PST)
X-Received: by 10.107.19.9 with SMTP id b9mr2162746ioj.48.1485426773687;
        Thu, 26 Jan 2017 02:32:53 -0800 (PST)
Return-Path: <oakridgerealty@ares.wcoilhosting.com>
Received: from bizgateway06.wcoil.com (bizgateway06.wcoil.com. [65.17.138.168])
        by mx.google.com with ESMTP id r67si1496005ior.163.2017.01.26.02.32.53
        for <xxx>;
        Thu, 26 Jan 2017 02:32:53 -0800 (PST)
Received-SPF: neutral (google.com: 65.17.138.168 is neither permitted nor denied by best guess record for domain of oakridgerealty@ares.wcoilhosting.com) client-ip=65.17.138.168;
Authentication-Results: mx.google.com;
       spf=neutral (google.com: 65.17.138.168 is neither permitted nor denied by best guess record for domain of oakridgerealty@ares.wcoilhosting.com) smtp.mailfrom=oakridgerealty@ares.wcoilhosting.com;
       dmarc=fail (p=NONE sp=NONE dis=NONE) Quelltext.from=gmail.com
Received: from localhost (localhost [127.0.0.1])
     by bizgateway06.wcoil.com (Postfix) with ESMTP id 56E992807A4
     for <xxx>; Thu, 26 Jan 2017 05:08:11 -0500 (EST)
X-Amavis-Alert: BAD Quelltext SECTION, MIME error: error: part did not end with
     expected boundary; ; error: unexpected end of parts before epilogue
Received: from bizgateway06.wcoil.com ([127.0.0.1])
     by localhost (bizgateway06.wcoil.com [127.0.0.1]) (amavisd-new, port 10024)
     with LMTP id ALlKpTMM7pDN for <xxx>;
     Thu, 26 Jan 2017 05:08:10 -0500 (EST)
Received: from ares.wcoilhosting.com (ares.wcoilhosting.com [65.17.128.66])
     by bizgateway06.wcoil.com (Postfix) with ESMTP id B71782806E7
     for <xxx>; Thu, 26 Jan 2017 05:08:10 -0500 (EST)
Received: from oakridgerealty by ares.wcoilhosting.com with local (Exim 4.87)
     (envelope-from <oakridgerealty@ares.wcoilhosting.com>)
     id 1cWhMJ-003GP0-Hf
     for xxx; Thu, 26 Jan 2017 05:32:51 -0500
To: xxx
Subject: Have a nice day!
X-PHP-Script: oakridge-realty.com/bin1.php for 78.108.182.241
X-PHP-Filename: /home/oakridgerealty/public_html/bin1.php REMOTE_ADDR: 78.108.182.241
From: <zemlenihka79@gmail.com>
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: PHP/5.4.45
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="1485426771SPB"
Message-Id: <E1cWhMJ-003GP0-Hf@ares.wcoilhosting.com>
Date: Thu, 26 Jan 2017 05:32:51 -0500
X-Antivirus: avast! (VPS 170126-0, 26.01.2017), Inbound message
X-Antivirus-Status: Clean
« Zuletzt geändert: 26. Januar 2017 um 21:34 von Stiray » 
Grund: Betreffzeile korrigiert 

Hello_012.jpg ( 50 KB | Downloads )
Hello_012.jpg
Zum Seitenanfang
 
IP gespeichert
 
Indikation
Stiray
Forum Administrator
*****
Offline


Stillstand ist die Vorstufe
des Untergangs

Beiträge: 65837
Mitglied seit: 09. Juni 2011
Geschlecht: männlich
Re: Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com>
Antwort #1 - 26. Januar 2017 um 21:44
 
Der Scammer hat ein Script auf dem russischen Server Yes Networks Unlimited Ltd installiert. Er schreibt seine Mail über diesen
Server und versendet sie dann über den amerikanischen Server West Central Ohio Internet Link. Das ist die totale Verschleierung.


Code
Alles auswählen
IP:	78.108.182.241
Decimal:	1315747569
Hostname:	78.108.182.241
ASN:	62160
ISP:	Yes Networks Unlimited Ltd
Organization:	Yes Networks Unlimited Ltd
Services:	None detected
Assignment:	Static IP
Continent:	Europe
Country:	Russia
State/Region:	Kaluzhskaya Oblast'
City:	Obninsk 



Code
Alles auswählen
IP:	65.17.128.66
Decimal:	1091665986
Hostname:	ares.wcoilhosting.com
ASN:	11473
ISP:	West Central Ohio Internet Link
Organization:	West Central Ohio Internet Link
Services:	None detected
Type:	Dial-up
Assignment:	Static IP
Continent:	North America
Country:	United States
State/Region:	Ohio
City:	Lima 



Zitat:
from ares.wcoilhosting.com [...] [65.17.128.66] by bizgateway06.wcoil.com (Postfix) with ESMTP; Thu, 26 Jan 2017 05:08:10 -0500 (EST)
X-PHP-Script: oakridge-realty.com/bin1.php for 78.108.182.241
From: <zemlenihka79@gmail.com>
Date: Thu, 26 Jan 2017 05:32:51 -0500


Zitat:
X-Mailer: PHP/5.4.45
« Zuletzt geändert: 26. Januar 2017 um 21:45 von Stiray »  
Zum Seitenanfang
 
IP gespeichert
 
Stiray
Forum Administrator
*****
Offline


Stillstand ist die Vorstufe
des Untergangs

Beiträge: 65837
Mitglied seit: 09. Juni 2011
Geschlecht: männlich
Re: Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com>
Antwort #2 - 26. Januar 2017 um 21:44
 
« Zuletzt geändert: 25. April 2017 um 20:15 von Stiray »  
Zum Seitenanfang
 
IP gespeichert
 
bigbear
Themenstarter Themenstarter
General Counsel
***
Offline


I Love Anti-Scam

Beiträge: 1331
Mitglied seit: 08. September 2009
Geschlecht: männlich
Re: Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com>
Antwort #3 - 07. Februar 2017 um 15:01
 
Hi xxx!
xxx, I'm really glad to receive your letter. And we can continue our acquaintance.
I want to say straight away that this is my first encounter with a man on the Internet. So I was a little worried ...
xxx, I have started to use the Internet recently. Once we came to work
Internet cafe. I work as an accountant at the post office for a long time. In his spare time, and when there is a free
computer, we are allowed to use the internet for a small fee. At first I did not think about it.
But I decided to try. Because she saw on television advertising, a lot of people have found each other
via the internet and is very happy now. Because there are no borders and distances to explore.
So, a little about me. My name is Zinaida. I am 37 years old. My birthday is February 10. My height - 176 sm.
My weight - 65 kg. I have no bad habits. I'm lonely, but has already been married.
We divorced because he was unfaithful to me, on the other hand, I could not forgive it to him.
And now I live alone, and really want to find love!
I have a quiet character. I live alone, so to speak. I am the only child in the family.
I do not have brothers and sisters.
I live in a small but beautiful town of Marks, it is in Russia.
Can you tell me more about you? About your life and entertainment? For example, I like to dance.
In his spare time, and I go to a dance school. It also helps me to keep my body in the order, and a beautiful figure.
I think you have already noticed this Smiley. What are you looking for in a woman? And the most important question for me,
is: "What do you expect from acquaintance with a woman?" It is important to find out for me now at the beginning of our acquaintance,
to then between us there was no disagreement. Because flirting and friendship does not interest me.
I have a lot of friends. And I need love and a serious relationship. The only reason why I'm here. I want to find
for me, a good man for a serious relationship.
I hope that our meeting will be pleasant. I would like you to answer my questions sincerely.
I love sincerity and truth. I understand that you have a lot of questions for me. Also, I have to you.
You can ask what you're interested to know about me.
I will sincerely answer you. If I'm interested in you, I'll write you more about me in my next letter. Ok?
I put some pictures in my letter.
I hope you like it.
I'm waiting for your answer and your photos.
Your new friend Zinaida

Spoiler:
Delivered-To: xxx
Received: by 10.223.176.253 with SMTP id j58csp1084208wra;
        Tue, 7 Feb 2017 05:51:47 -0800 (PST)
X-Received: by 10.223.163.199 with SMTP id m7mr14039763wrb.63.1486475507381;
        Tue, 07 Feb 2017 05:51:47 -0800 (PST)
Return-Path: <zemlenihka79@gmail.com>
Received: from mail-wm0-x242.google.com (mail-wm0-x242.google.com. [2a00:1450:400c:c09::242])
        by mx.google.com with ESMTPS id z20si11633008wmz.148.2017.02.07.05.51.47
        for <xxx>
        (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
        Tue, 07 Feb 2017 05:51:47 -0800 (PST)
Received-SPF: pass (google.com: domain of zemlenihka79@gmail.com designates 2a00:1450:400c:c09::242 as permitted sender) client-ip=2a00:1450:400c:c09::242;
Authentication-Results: mx.google.com;
       dkim=pass Quelltext.i=@gmail.com;
       spf=pass (google.com: domain of zemlenihka79@gmail.com designates 2a00:1450:400c:c09::242 as permitted sender) smtp.mailfrom=zemlenihka79@gmail.com;
       dmarc=pass (p=NONE sp=NONE dis=NONE) Quelltext.from=gmail.com
Received: by mail-wm0-x242.google.com with SMTP id r18so27496755wmd.3
        for <xxx>; Tue, 07 Feb 2017 05:51:47 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20161025;
        h=date:from:message-id:to:subject:in-reply-to:references:mime-version;
        bh=+QucXcLmWjfOmzYi1zYVeh6sF8Lp3ldvHWr4xwAqYCo=;
        b=Yhyd4f7v0d62OSFEhu1HuHdqX90U+1wvcDzM0FNFOeN1929F7k+sIjqlvPnLcx6Rqp
         bAMcWWPbuCsUXR8OZSNd9W02lJY4MJXbdd5Jq/66zNfzOP1kNjOMoXpu9zAuQlZorg0W
         tArOQ0aav62wxjmKhuzPOohMgocL1oYKZZnmxX1uI0q6fyv+H/7UdYvsuqcJX1DxeNSP
         kwkkc6CzgD9PMGMUYpNrF2vVBdDX+NLqXOEw4lXDabLYU9dz7QWrzC0vbWJ3nfzs4eG3
         TdStJX25hcPetzxJsXiNj9iqVBOTYd/O6Lb9r0YwtTYkYaXHBQSyvwSrT2n/wTML7wR2
         MNEg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:date:from:message-id:to:subject:in-reply-to
         :references:mime-version;
        bh=+QucXcLmWjfOmzYi1zYVeh6sF8Lp3ldvHWr4xwAqYCo=;
        b=XJQrWvyPFB+gt5dk7/XxDhLJa1J5l3oczLMAIS1S5cDTyZNVgiBPgNDADpbWxhUAaI
         Ijb48S1YlmJ/eZbLyJazFdG9LTE8251849QY4CRKmlWac1PdOzvu3VQgd6wGs3ITOM+M
         /RDxnq0q0hoCwd46IacRfkHVrmBADZt1qWeqK4vsJ0kRTcj1FpyAoNWxOxddgT3N1oR4
         IaJr7k2o8Afc+NnUeZlj2XDw0hkSlTACOfbyi1P1KyWAFOvLVieXWU7poMWvdWZ8l5Bj
         b1XXI647ahDJIuO34rnHW2EYHXi8qKMIAHubeU/GSqk3TO6jy6PY8kkgqFnHJR6YMfiG
         S6OQ==
X-Gm-Message-State: AMke39mRNyG/RL2zC8bRh3N58xUwvhTZUXZFkiXosMxrH7/08DqjcBjacknk/+USvIm5IQ==
X-Received: by 10.28.55.68 with SMTP id e65mr13693228wma.62.1486475506763;
        Tue, 07 Feb 2017 05:51:46 -0800 (PST)
Return-Path: <zemlenihka79@gmail.com>
Received: from [100.100.96.8] ([159.122.129.39])
        by smtp.gmail.com with ESMTPSA id u189sm3393791wmu.1.2017.02.07.05.51.33
        for <xxx>
        (version=TLS1 cipher=AES128-SHA bits=128/128);
        Tue, 07 Feb 2017 05:51:45 -0800 (PST)
Date: Tue, 7 Feb 2017 17:26:49 +0400
From: Zinaida <zemlenihka79@gmail.com>
X-Priority: 3 (Normal)
Message-ID: <1269798421.20170207172649@gmail.com>
To: "xxx" <xxx>
Subject: Re: Betreff: Have a nice day!
In-Reply-To: <xxx>
References: <E1cWhMJ-003GP0-Hf@ares.wcoilhosting.com> <xxx>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----------07B05B19A2C75ABBF"
X-Antivirus: avast! (VPS 170206-3, 06.02.2017), Inbound message
X-Antivirus-Status: Clean
« Zuletzt geändert: 07. Februar 2017 um 19:32 von Stiray »  

DMC0284.jpg ( 155 KB | Downloads )
DMC0284.jpg
DMC0782.jpg ( 302 KB | Downloads )
DMC0782.jpg
DMC2334.jpg ( 147 KB | Downloads )
DMC2334.jpg
Zum Seitenanfang
 
IP gespeichert
 
Stiray
Forum Administrator
*****
Offline


Stillstand ist die Vorstufe
des Untergangs

Beiträge: 65837
Mitglied seit: 09. Juni 2011
Geschlecht: männlich
Re: Zinaida <zemlenihka79@gmail.com> <oakridgerealty@ares.wcoilhosting.com>
Antwort #4 - 07. Februar 2017 um 19:31
 
Mail über Tschechien  Smiley

Code
Alles auswählen
IP:	159.122.129.39
Decimal:	2675605799
Hostname:	39.129.122.159.reverse.slout.mil80-003.ff.avast.com
ASN:	36351
ISP:	SoftLayer Technologies
Organization:	AVAST Software s.r.o.
Services:	Suspected network sharing device
Type:	Broadband
Assignment:	Static IP
Continent:	Europe
Country:	Czechia 



Zitat:
from [100.100.96.8] ([159.122.129.39]) by smtp.gmail.com with ESMTPSA; Tue, 07 Feb 2017 05:51:45 -0800 (PST)
Date: Tue, 7 Feb 2017 17:26:49 +0400
From: Zinaida <zemlenihka79@gmail.com>
  
Zum Seitenanfang
 
IP gespeichert
 
Seitenindex umschalten Seiten: 1
Thema versenden
Link zu diesem Thema