Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

spacepower7

macrumors 68000
Original poster
May 6, 2004
1,509
1
I figured that I would post here since you guys/girls all know mail servers and email headers etc....

I looked up some of the IP addresses:
message originated from
196.3.183.72 which is Nigeria (no surprise)
69.36.163.102 show that IP belongs to: WestHost Providence, Utah
72.3.137.83 show that IP belongs to: Net2Roam in San Antonio TX

the innocentpeopleinfectedPC?.com is same as xxxxxxxxx.com, just some old couples' xyz-real-estate.com website. They are located in Kansas.

Can you tell from the long headers if their domain is spoofed or if they have an infected PC being used to relay spam?

I would like to warn them if they are infected, or if their webhost is infected.

Thanks


From: THE PRESIDENCY <ubah@presidency-ng.org>
Date: November 11, 2008 11:46:25 PM EST
Subject: Re: 2008 PAYMENT NOTICE
Reply-To: payment@National-Champs.com
Return-Path: <ubah@presidency-ng.org>
Return-Path: <ubah@presidency-ng.org>
Mime-Version: 1.0
Content-Transfer-Encoding: 8BIT
Content-Type: text/plain; charset=Windows-1251
Received: from smtpin127-bge351000 ([10.150.68.127]) by xxxx.mac.com (Sun Java(tm) System Messaging Server 6.3-7.02 (built Jun 27 2008; 64bit)) with ESMTP id <xxxxxxxxx@xxxx.mac.com> for myname@mac.com; Tue, 11 Nov 2008 20:47:36 -0800 (PST)
Received: from innocentpeopleinfectedPC?.com ([69.36.163.102]) by smtpin127.mac.com (Sun Java(tm) System Messaging Server 6.3-7.03 (built Aug 4 2008; 32bit)) with ESMTP id <0KA70034XENBW3D0@smptxxxx.mac.com> for myname@mac.com (ORCPT myname@mac.com); Tue, 11 Nov 2008 20:47:36 -0800 (PST)
Received: from User (yuma.onspeed.com [72.3.137.83]) (authenticated bits=0) by innocentpeopleinfectedPC?.com (8.13.1/8.13.1) with ESMTP id mAC4iTXv031132; Tue, 11 Nov 2008 21:44:44 -0700
Received: from 196.3.183.72 (trT9XsNbDq@196.3.183.72 [196.3.183.72]) by yuma.onspeed.com (SlipStream SP Server 6.0.19 built 2007/11/22 15:27:31 -0500 (EST)); Tue, 11 Nov 2008 22:46:37 -0600 (CST)
Original-Recipient: rfc822;myname@mac.com
X-Brightmail-Tracker: AAAAAA==
X-Originating-Ip: [196.3.183.72]
X-Originating-User: [trT9XsNbDq]
Message-Id: <trT9XsNbDq$196.3.183.72$.491a5fad.35439.2364.31@yuma.onspeed.com>
X-Priority: 3
X-Msmail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-Mimeole: Produced By Microsoft MimeOLE V6.00.2600.0000

OFFICE OF THE PRESIDENCY
ASO ROCK VILLA, ABUJA.
Tel: 234-803-7000215.
E-mail: presidency@National-Champs.com

Re: 2008 PAYMENT NOTICE/ CHANGE OF BENEFICIARY.

“I write with reference to our earlier letter Ref. No: FGN/ CP0325/08, on above subject and wish to draw your attention to President Musa Yar'Dua’s directive to clear all outstanding Payments since 1995-2007, in regards to his meeting with the United Nations, Commonwealth of Nations and Foreign Embassies. I wish to enlisted your name to replace that of Mrs. Joan Schelb of Switzerland (our previous partner) as Beneficiaries to receive USD21,070,235.00 (Twenty-One Million, Seventy Thousand, Two Hundred and Thirty Five U.S Dollars) from the 2008 budgeted Excess Crude Oil Revenue for our mutual benefits,

Due to the difficulties of transferring funds from Africa since September 11 and the buerecratic process according to our Apex Bank Manager, The funds will be dispatched dispatch through Diplomatic means to your choice of location because it is safer, faster and reliable. All relevant information will be changed in your favor as a sub-Contractor while I will send our representative for our share.

Right now I need your cooperation and assistance to secure the funds for our disbursement (you and me) hence if discovered by our leaders, they will return this funds for their selfish political interests and killings of one another, suggest how best we will share the funds by Percentage? Furnish to me your Contact information (Full name, address, phone and cell phone numbers) for me to make the changes and subsequent Delivery of the funds within 72hrs. Furthermore, maintain non-disclose of facts to third party for security our funds and my positions.

Waiting to receive your urgent positive reply/ call,

Hon. Andy Ubah (OFR)
P.A, Finance and Admin, Presidency.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.