SmartFeedSmartFeed          



WELCOME - YOU ARE CURRENTLY VIEWING 419EATER AS A GUEST

By joining our community you will have the ability to post topics and access other forums reserved for members. Registration is quick, simple and absolutely free. Join our community today by clicking here.

ScamWarners.com - Internet Anti-Fraud Center - now open!

These forums are READ ONLY. Click here to register on our new forums - aff.419eater.com


 Fort Huachuca?

View next topic
View previous topic
 
This forum is locked: you cannot post, reply to, or edit topics.This topic is locked: you cannot edit posts or make replies.
Author Message
ferrica dooza
Hello I'm New here!


Joined: 16 Jan 2014
Posts: 16


PostPosted: Sun Jan 19, 2014 1:46 am Reply with quoteBack to top

I picked up a mark in surplus

http://forum.419eater.com/forum/viewtopic.php?p=2012033#2012033

and posted a reply yesterday. The mark replies with the usual script.

I traced the header at iptrackeronline.com and it resolved to

Quote:

* 6.73.1.0 Check 6.73.1.0 at Senderbase.org
Check 6.73.1.0 at Reputationauthority.org
Us Department Of Defense Network
Fort Huachuca United States


This seems to be a US Army Intelligence installation.

Any further info/guidance on this?

I'm a complete noob ATM by the way. I've been lurking quite the while though so have a good general idea about the caper :=]

Ferrica
View user's profileSend private message
vonpaso xlura
Baiting Guru


Joined: 10 Apr 2011
Posts: 13781
Location: Bertcad, Lojbanistan


PostPosted: Sun Jan 19, 2014 5:36 am Reply with quoteBack to top

6.73.1.0 is indeed in Fort Huachuca if it's an IP address, but is it? Sometimes IPtracker mistakes a version number for an IP address. Eyeball the headers for IP addresses, or post them here and we'll look at them.

_________________
Easter Egg 2012 United Kingdom×12 United States×3 Russia×3 CanadaNigeriaGermanyMalaysiaNetherlandsAustraliaTogo
United KingdomUnited KingdomCanada unwashed
Closed lad accounts×163
×186
Safari Accra - SH Cotonou
you are a fake people so do not ever write to me again.
Am mad at you right now ... Am tired of your questions ... Am sick and tire you and your bank
Nigerian pig . go swallow a grenade idiot. Boko Haram will solve your problem idiot .
you are big fool by send a fake payment information and never you contact me again asshole .
your passgae bearing your ATM CATD ... Ant Terrorist Certificate ... legal verterbrate ... expartiate your meaning ... gets to your dwaignted address ... successful ofghw transfer
View user's profileSend private messageSend e-mail
next victim
Baiting Guru


Joined: 27 Mar 2011
Posts: 21155


PostPosted: Sun Jan 19, 2014 12:56 pm Reply with quoteBack to top

ipTRACKERonline.com wrote:
Header Analysis Quick Report
Originating IP: 41.58.49.74
Originating ISP: Swiftng
City: Lagos
Country of Origin: Nigeria
* For a complete report on this email header goto ipTRACKERonline


Received: (qmail 3175 invoked from network); 15 Jan 2014 02:50:39 -0000
Received: from unknown (HELO inbound2.hw.buf.ny.localnet.com) ([10.30.204.16])
(envelope-sender <[email protected]>)
by maildrop5.localnet.sys (qmail-ldap-1.03) with SMTP
for <[email protected]>; 15 Jan 2014 02:50:39 -0000
Received: from magicballbingo.com (173-165-136-34-utah.hfc.comcastbusiness.net [173.165.136.34])
by inbound2.hw.buf.ny.localnet.com (Postfix) with SMTP id 4B7C118004
for <[email protected]>; Tue, 14 Jan 2014 21:50:39 -0500 (EST)
Received: (qmail 5468 invoked by uid 453); 14 Jan 2014 20:51:46 -0000
X-Virus-Checked: Checked by ClamAV on magicballbingo.com
Received: from Unknown (HELO User) (41.58.49.74)
(smtp-auth username reports, mechanism login)
by magicballbingo.com (qpsmtpd/0.40) with ESMTPA; Tue, 14 Jan 2014 13:51:46 -0700
Reply-To: <[email protected]>
From: "MR JAMES EDWARD"<[email protected]>
Subject: FROM MR JAMES EDWARD
Date: Tue, 14 Jan 2014 21:51:43 +0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <[email protected]>
To: undisclosed-recipients:;

_________________
Closed lad accounts 291+ x 78+ http://yahoonews01.zxq.net/
500 in 6 - 36 pink 11 black
Safari Chairman's Xmas Parti 2012
Sand Timer Hana, Flip It, G spot, Rosy, Cynthia
Cellphone - web store
Just read the posting on Eater. You are one sick motherf****r! Smile-Alan
"The skull with bunny ears was a good enough warning" - Nailgunner
mentors- http://forum.419eater.com/forum/cherrie_mentor_program.php
This Derick moral monster! From http:/ /scamnewss.wordpress.com/2011/10/14/derrick-ratt-scammer-beware/ Vlad blog
http://tinyurl.com/btf7872 - Toolbox
View user's profileSend private messageSkype Name
ferrica dooza
Hello I'm New here!


Joined: 16 Jan 2014
Posts: 16


PostPosted: Sun Jan 19, 2014 4:23 pm Reply with quoteBack to top

I contacted the mark (using www.mail.com) I received a reply and the header information from the reply was/is quoted below
I notice the last line of the header:

Quote:

message opened by mailclient 6.73.3.0 (6.73.1.0)


That's Fort Huachuca.

I have no real expertise on these matters so I hope one of you guys can make some sense of it for me.



Quote:

Return-Path: [email protected]
Received: from nm45.bullet.mail.gq1.yahoo.com ([67.195.87.147]) by
mx-ha.gmx.net (mxgmxus003) with ESMTPS (Nemesis) id 0MEo84-1W621922Y6-00G450
for <[email protected]>; Sat, 18 Jan 2014 09:48:05 +0100
Received: from [98.137.12.189] by nm45.bullet.mail.gq1.yahoo.com with NNFMP; 18 Jan 2014 08:48:04 -0000
Received: from [98.137.12.242] by tm10.bullet.mail.gq1.yahoo.com with NNFMP; 18 Jan 2014 08:48:04 -0000
Received: from [127.0.0.1] by omp1050.mail.gq1.yahoo.com with NNFMP; 18 Jan 2014 08:48:04 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 55014 invoked by uid 60001); 18 Jan 2014 08:48:04 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1390034884; bh=0WxuNelPD+/Rk+MQ6x8P91n31lkZKoJeoBa3NVRT/2k=;
h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type; b=0rvuG63vUUWMeMrwpgPBLNMR
j2iLC5gQCYefzA4eFhxWptpH2zRIGUgnh5gewQZPVw7cd/Ew/Ev/HJl7vO6t387VBob7BHI8iZFDansnPTTyOoRemkNVzcHavpx76+okUaMwtkq1wufTnpuQfyrTBCHQjYtCsJ/h7SLrylzyft4=
DomainKey-Signature:a=rsa-sha1; q=dns; c=nofws;
s=s1024; d=yahoo.com;
h=X-YMail-OSG:Received:X-Rocket-MIMEInfo:X-Mailer:Message-ID:Date:From:Reply-To:Subject:To:MIME-Version:Content-Type;
b=ywvshMDv9RpwuUmL4RHs4BXpjrg3NFCQ8iWyfuVqUWJW6DYnUx5x5CXujQxvqVqxiM5CXrRPorndXcnreQuLHvSWS4FxFyPiziL+3L2ZKsTVFnqltT4TpjRHl

+xgA3DfSyU7wc0bnWU+j21NS1YApqi9NvD55NUGpq9Odi31k4s=;
X-YMail-OSG: VStE4NwVM1mSbSdeDKU.O6amu7uA8Z.wCMenYTQX9sxanvw
km6H4wGnhbVYdv05qsFP_EA_0qR4XJ1IScAnKfmbeqEiJnwuPZJOm47U0J3c
J5nTyRLIqWc1LMcqpEpehP5BGTiomiLqr8Tiite0N9_YtDBluaRnwMOB1Ssu
.w8G7QD4sDEJorQBYACwn8qmsR6zJrDicQ5_eVb9_gt0G9DPXSyW6N5uZxVj
k2qTAFAmf2rDiMF6WPU_oeerrnLmixg..L8xY_A0p3DZqqC3SaycbTa3Rf0n
opizaUqGIkSp7EaxwrSGi17oWgbPSGomkzLnS.VUSQLiZOYrbBGxwAcZcCJ1
dT3U4c5N5_4rzLpSuZHe4Kc21DEV4gmyvVP6IOg_Umh11Pj.8.diMEvYErVr
HdFUahMz7TzIzvlHNgwtncq90RKH57Tg2qMAqOwZeunb1CJC01oZgfjUA_yk
Q7UdYajRQd_4lVZ.RevNLhKRE0CxvGKA_h_oL2o87HhXAJ7q1se3.wjHkAK5
g9BjRl6_6oNMsFPu.WnjEnd20cq7qL4cH_IwXC6D20PG8MUFWiwY-
Received: from [41.58.30.7] by web164502.mail.gq1.yahoo.com via HTTP; Sat, 18 Jan 2014 00:48:04 PST
X-Rocket-MIMEInfo: 002.001,TXIgSmFtZXMgRWR3YXJkCjEyMSBEYXZlIENyZWNlbnQsCkFrb2thIFZpY3RvcmlhIElzbGFuZCwKTGFnb3MtTmlnZXJpYQpUZWw6KzIzNC04MD
UtNjY3MjE3NQoKRGVhciBXYXJ3aWNrIEh1bnQsCgoKVGhhbmsgeW91IGZvciB5b3VyIGVtYWlsIHJlc3BvbnNlIGFuZCByZWFkaW5lc3MgdG8gd29yayB3aXRoIG1lIGluIG1vdmluZyDCoHRoZSAkNT
JNIHRvIHlvdXIgYWNjb3VudCBmb3Igc2hhcmluZyBhbmQgZWRpYXRlIGludmVzdG1lbnQgb2YgbXkgb3duIMKgc2hhcmUuI
Ekgc2luY2VyZWx5IGJlbGlldmUgdGgBMAEBAQE-
X-Mailer: YahooMailWebService/0.8.173.622
Message-ID: <[email protected]>
Date: Sat, 18 Jan 2014 00:48:04 -0800 (PST)
From: James Edward <[email protected]>
Reply-To: James Edward <[email protected]>
Subject: Thank you for your email response and readiness to work with me in moving the $52M to your account
To: "[email protected]" <[email protected]>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="-2109934955-1961672663-1390034884=:25503"
Envelope-To: <[email protected]>
X-GMX-Antispam: 5 (nemesis mail header analyzer); Detail=V3;
X-GMX-Antivirus: 0 (no virus found)
X-UI-Filterresults: junk:10;V01:K0:5m0RzRw/n7I=:/6CsWhLA/6mxLspYoPC5qUQ7a/DI
zyds6DhUAkUZp5Dpd5MRVessF25+joK47UMY1lo2Aea95SghDn7Kz+e40f6OGHvNl5CbW5JG0
tenpsOXM20WhWs9HAOwDap5yeaw36w9zuvbtTAKNE4yDWQa/TJ05X46XYsracBrzFMcdYwspn
m94KmDRgJRX4AEzM6nogzsigfBdZ9T16Wr4SEOkawIRO7+hOaJ4fI3C972tfR5IhqVvPkx5ma
2V/wVYEZbQ1rUKsSlBUDjncK8WLvxTvX2fwWQ97RbiklT9+xAwG44gppGnpmggsKXku4IXv1L
pgPB8+vJ3CUGLA5hCgeZY4CfqMbMgaIkXOoG3VZ5/F0btwVYcWkp8OO3z+GIMQ2lNmxmeEe3n
87wisZAKxwrT+SgH6Ym9GduHQjF1G/pGvsyV5zp3qNjDTOx6HZANE41UE7KksFhvK2Ntx2P84
/LGwli5HIx2fgK+Qu4/gmxPqfGTi+HOxBB8ExNuS7/7VFj1hUt/gUlEHO6aprEjeVmyvzssjS
5GH3OPCS9Pj3fKcCaTHNojfMwSEbXcdZXT8YttuaNrrfP57nXJ5uF8XcdhLdtz3KOqlarjcJR
2Jgw3ZuBwZLGgX4ZntyR6FPI9w3JciF0z+Bgnd+0aBNou4tUT3RPRy2uixEdwTKS7U8JRYaPa
7r2z060XkfWzQ9dd5vzkk+huWBwJt2BK19ZodadIAAdnWgDr+yNbSlhRO6BOm8CT4Jg8qMBXr
JJMRMcq5J5js747pd3vuEztn0BQyglH40aSjkE5SWfwQ6t1xfC2g9iGeH9AyR/PBjHbhM/jNQ
x7n3NBfCDJI9GWUx8JwYJyX87TObfwTKyyMrngo4Q+Pczo79d2YAlNRjWzalV6ge3G4VHzUM+
34M9RC5unmGl1hSuBhWj7EH/JHZCbDg3xod0FFgpsxjl1+kb8a2LMHcncpNnw0aazGq0cPl6j
J9030XA2t/N9DQ5o2ZApM15ma3Y51DKLlCeCML/Haj3nN8abyMH+LyKoMP/pxAdV8J3Gkq6Zi
ixBNp1X6Tvr9LYk4oXwyK04SKumZBDkFB/rmTuDbVsussE4NRMjD4ve7JeUIEEsVPdOuXg0Je
VcMR9ebgeayTDlZY79ISwpx7aCpiERYnF31yaZ/Tygo7XkF+L7ufKvPNaBsem6kP+57GLr/fh
IXzz4lX6TasgKj9PpejkPaIP5K2PWIEItIgmSHoZgHzBNpj73sVAGHQPMYbE1lmOp53XEq/sn
9wDse9ERwYdLnEEMs6N7pKNpcgizF0gnXglOmmP4FcpgcATm7dWia6jIg7BNt2ueLMb7bVYOu
D5ZK336wukZsE79I4ukyIBbmmESG2svX//gHTsU7NxK4XJRBGJ9p1P55lABByVDmP2aAmTB5h
CKkv+brsWo2oJPoF+oKjxVAI5KX9JewUW1U8=
X-GMX-UID: ZmRoTXFyGXNoZN+s9D8zSWAoJkwMVdDN
X-Flags: 1411



MailID: ZmRoTXFyGXNoZN+s9D8zSWAoJkwMVdDN


------------------------------------------------------------------------
message opened by mailclient 6.73.3.0 (6.73.1.0)


Ferrica


Last edited by ferrica dooza on Sun Jan 19, 2014 4:53 pm; edited 5 times in total
View user's profileSend private message
B8er
Associate Boomdazzler


Joined: 16 Feb 2009
Posts: 13579
Location: In self-isolation practicing social distancing


PostPosted: Sun Jan 19, 2014 4:26 pm Reply with quoteBack to top

It's not an IP address. Take a read of this http://koen.io/2013/11/no-the-u-s-army-did-not-read-the-emails-of-a-belgian-mp/.

_________________
"I DENOUNCE THE MUFFIN MEN" - Ma Kim
"YOU ARE WALKING DEAD MAN. YOUR WOODEN COFFIN IS READY TO SWALLOW YOU AND YOUR DIRTY GENERATION"
"all chaps are ass-less by design otherwise they just be leather pants" - jose_cuervo
Safari x 5 Tattoo Golden Pig Easter 2015 Vcamera
United KingdomUnited StatesNigeriaMalaysiaNetherlandsThailandCanadaUnited Arab EmiratesUnited NationsAustraliaSenegalSpainBeninChinaDenmarkGhanaIvory CoastKorean FlagSouth AfricaSwedenBurkina FasoCambodia FlagcameroonGermanyHong KongIndonesiaJapanNew ZealandSwitzerlandTogoTurkeyUkraine x 335 Elite Ninja Team Member Whip 🚽
Cellphone x 4 Closed lad accounts x 1746 x 1904 - Fake cheques: $4,392,620.83
Safari Team Woody - Ghana to Singapore - 11535km
View user's profileSend private messageSkype Name
ferrica dooza
Hello I'm New here!


Joined: 16 Jan 2014
Posts: 16


PostPosted: Sun Jan 19, 2014 4:46 pm Reply with quoteBack to top

B8er wrote:
It's not an IP address. Take a read of this http://koen.io/2013/11/no-the-u-s-army-did-not-read-the-emails-of-a-belgian-mp/.


I see.....Thanks for that.

So If I strip that part off the header it will resolve elsewhere?

I'll try it out. Also I will edit the header above in the next 5 minutes to remove my details :-]


Ferrica
View user's profileSend private message
B8er
Associate Boomdazzler


Joined: 16 Feb 2009
Posts: 13579
Location: In self-isolation practicing social distancing


PostPosted: Sun Jan 19, 2014 5:15 pm Reply with quoteBack to top

It should do.

You'll get a few IPS shown, but the following is the originating line

Quote:
Received: from [41.58.30.7] by web164502.mail.gq1.yahoo.com via HTTP; Sat, 18 Jan 2014 00:48:04 PST


Which as it is similar to the one NextVictim posted will probably come back as Nigeria.

_________________
"I DENOUNCE THE MUFFIN MEN" - Ma Kim
"YOU ARE WALKING DEAD MAN. YOUR WOODEN COFFIN IS READY TO SWALLOW YOU AND YOUR DIRTY GENERATION"
"all chaps are ass-less by design otherwise they just be leather pants" - jose_cuervo
Safari x 5 Tattoo Golden Pig Easter 2015 Vcamera
United KingdomUnited StatesNigeriaMalaysiaNetherlandsThailandCanadaUnited Arab EmiratesUnited NationsAustraliaSenegalSpainBeninChinaDenmarkGhanaIvory CoastKorean FlagSouth AfricaSwedenBurkina FasoCambodia FlagcameroonGermanyHong KongIndonesiaJapanNew ZealandSwitzerlandTogoTurkeyUkraine x 335 Elite Ninja Team Member Whip 🚽
Cellphone x 4 Closed lad accounts x 1746 x 1904 - Fake cheques: $4,392,620.83
Safari Team Woody - Ghana to Singapore - 11535km
View user's profileSend private messageSkype Name
vonpaso xlura
Baiting Guru


Joined: 10 Apr 2011
Posts: 13781
Location: Bertcad, Lojbanistan


PostPosted: Sun Jan 19, 2014 5:39 pm Reply with quoteBack to top

As I suspected, it's a version number, specifically the version number of the mailclient program. The real IP address is 41.58.30.7; here's what I get running the whois program on it:

$ jwhois 41.58.30.7
[Querying whois.afrinic.net]
[whois.afrinic.net]
% This is the AfriNIC Whois server.

% Note: this output has been filtered.

% Information related to '41.58.0.0 - 41.58.255.255'

inetnum: 41.58.0.0 - 41.58.255.255
netname: SWIFTNG-20100308
descr: SWIFT NETWORKS LIMITED
country: NG
admin-c: GO5-AFRINIC
tech-c: GO5-AFRINIC
org: ORG-SNL3-AFRINIC
status: ALLOCATED PA
mnt-by: AFRINIC-HM-MNT
mnt-lower: SWIFT-MNT
source: AFRINIC # Filtered
parent: 41.0.0.0 - 41.255.255.255

organisation: ORG-SNL3-AFRINIC
org-name: SWIFT NETWORKS LIMITED
org-type: LIR
country: NG
address: 31 B Saka Tinubu Street
address: Victoria Island
address: Lagos, Nigeria
address: Lagos
e-mail: [email protected]
e-mail: [email protected]
phone: +2348064351452
admin-c: GO5-AFRINIC
tech-c: GO5-AFRINIC
mnt-ref: AFRINIC-HM-MNT
mnt-ref: SWIFT-MNT
mnt-by: AFRINIC-HM-MNT
source: AFRINIC # Filtered

person: Gabriel Oyeyemi
address: Swift Networks Ltd.
31B Saka Tinubu Street,
Victoria Island, Lagos.
Nigeria.
phone: +23417738138
fax-no: +23412700197
e-mail: [email protected]
nic-hdl: GO5-AFRINIC
source: AFRINIC # Filtered

After you've been baiting Africans and looking at their headers a while, anything beginning 41 will stand out. All IP addresses beginning with 41 are in Africa.

_________________
Easter Egg 2012 United Kingdom×12 United States×3 Russia×3 CanadaNigeriaGermanyMalaysiaNetherlandsAustraliaTogo
United KingdomUnited KingdomCanada unwashed
Closed lad accounts×163
×186
Safari Accra - SH Cotonou
you are a fake people so do not ever write to me again.
Am mad at you right now ... Am tired of your questions ... Am sick and tire you and your bank
Nigerian pig . go swallow a grenade idiot. Boko Haram will solve your problem idiot .
you are big fool by send a fake payment information and never you contact me again asshole .
your passgae bearing your ATM CATD ... Ant Terrorist Certificate ... legal verterbrate ... expartiate your meaning ... gets to your dwaignted address ... successful ofghw transfer
View user's profileSend private messageSend e-mail
ferrica dooza
Hello I'm New here!


Joined: 16 Jan 2014
Posts: 16


PostPosted: Sun Jan 19, 2014 6:11 pm Reply with quoteBack to top

Thanks guys. I stripped that last line and it resolved to Lagos.

I'll just ignore any further reference to Fort H in future.

Must admit I thought for a little while that mail.com incoming was being monitored by the USDoD :=]

Not that I would have any real objection as I have nothing to hide.

Ferrica
View user's profileSend private message
Basinga
** WARNED **


Joined: 02 Aug 2013
Posts: 401
Location: Location: Location: Location: Sorry, can't find it


PostPosted: Mon Jan 20, 2014 12:18 pm Reply with quoteBack to top

ferrica dooza wrote:
Must admit I thought for a little while that mail.com incoming was being monitored by the USDoD :=]


Well, sometimes I wonder if various government spying agencies do keep an eye on developing baits for the giggles as they happen...
View user's profileSend private message
Leka
Elite Baiter


Joined: 10 Mar 2013
Posts: 1482


PostPosted: Mon Jan 20, 2014 7:48 pm Reply with quoteBack to top

^^^ All things considered i wouldn't be surprized.

_________________
Closed lad accounts x350 Assorted baits.
Senegal x6 United Kingdom x3 South Africa United States x5, India 2x Nigeria 1x unkown
4x Closed lad accounts (These are the hitpiggies they were given by a hitlad called "Jack")
Closed lad accounts Closed lad accounts Closed lad accounts Closed lad accounts (Romo -bait)
Closed lad accounts Closed lad accounts Closed lad accounts (This is Abdul he is a hitpiggy(the other one is Abdul's brother i call it "Stupid")(3rd. is a "Moron"))
This is the start of my multiethnic pigsty.
Sand Timer Subject "AM".
"Note that I will not stand to be accepting embarrassment words from you"
"PLEASE YOU HAVE TO GO FOR CHECK UP WITH YOUR DOCTOR OKAY.
HOLY JESUS
DR KENITH L00KMAN"
"Please do not email me again, you are a good layer"
View user's profileSend private message
Display posts from previous:      
This forum is locked: you cannot post, reply to, or edit topics.This topic is locked: you cannot edit posts or make replies.


 Jump to:   



View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum





All Content © 2003 - 419Eater.com : SEO Company : Free SEO Audit Tool : SEO Console : AI Search Readiness : v2.5
Powered by phpBB © 2001, 2002 phpBB Group :S5: FI Theme :: All times are GMT