An
Email with the Subject "REPORT FOR 08-22-2007-08" was
received in one of Scamdex's honeypot email accounts on Wed, 22 Aug 2007 17:54:01 -0700
and has been classified as a Advance Fee Fraud/419 Scam Email.
The sender shows as "John Fitchpatrick" <fitch19461@verizon.net>.
The email address was probably spoofed. Do not reply to or contact any persons or organizations referenced in
this email, or follow any URLs as you may expose yourself to scammers and, at the very least, you will be
added to their email address lists for spam purposes.
Scam TagCloud
africanafrica thousand united states d...foreigncoupnext of kindeceasedbankmicrosoftcontactaccountclaim thousandtransactionforeignercustomer50%10%businesscustomfund transferurgentproposalsentmailbank the bank burkina fasoconfidentialdr_idmed2007@yahoo.fr will spamouagadougouyahoo.yahoo.comremittanceremittexchange(adb)(wtc)(customer)(dr_idmed2007@yahoo.fr)[65.54.246.171](no sig)(ehlo vms169131pub.verizo...(206.46.169.131)([65.54.246.171])(built apr 3 2006))(orcpt fitch19461@verizon...(cdt)([10.6.53.78])(6.0.3790.2668)[spam][65.54.246.171]x-originat...(utc)[03ca7d10:01c7e51e]
NO CHART DATA - EMAIL HAS NOT YET BEEN ANALYSED
Scam Email Headers
This a (redacted) view of the raw email headers of this scam email.
Personally Identifiable Information (PII) has been suppressed, but can be
supplied as received to appropriate investigating or law enforcement agencies on request.
EEEEEstdClass Object
(
[return-path:] =>
[envelope-to:] => submissions@scamdex.com
[delivery-date:] => Wed, 22 Aug 2007 17:54:01 -0700
[received:] => Array
(
[0] => from smtp103.vzn.mail.dcn.yahoo.com ([209.73.179.141])by bartok.o7e.net with smtp (Exim 4.63)(envelope-from )id 1IO0xV-00053r-ATfor submissions@scamdex.com; Wed, 22 Aug 2007 17:54:01 -0700
[1] => (qmail 839 invoked from network); 23 Aug 2007 00:53:58 -0000
[2] => from unknown (HELO fitchd7qfmyei1) (fitch19461@verizon.net@71.127.143.9 with login) by smtp103.vzn.mail.dcn.yahoo.com with SMTP; 23 Aug 2007 00:53:57 -0000
)
[x-ymail-osg:] => lJvGSyEVM1mwEU68YN3FWM9uteSeBj7a2HsOiPDgwLt7a_tU.EeCweFaFqlR_FMqev2p3WDnySxkSQgBUzQA1wCnf9xzfbm9AQmOdNokt624f_3F2c_suIshqtijOmM-
[message-id:] => <006f01c7e520$167b4500$2f01a8c0@fitchd7qfmyei1>
[from:] => "John Fitchpatrick"
[to:] => "YAHOO ABUSE" ,"abuse YAHOO.FR" ,"abuse@AFRINIC" ,"abuse NIGERIAN SCAMS" ,"abuse@ HOTMAIL" ,"abuse@ MSN.COM" ,,"abuse@IANA.ORG" ,,
[cc:] => ,"INFO@FCC.gov" ,"SPAM@ UCE.GOV" ,"SUBMIT@ SCAMDEX"
[subject:] => REPORT FOR 08-22-2007-08
[date:] => Wed, 22 Aug 2007 20:53:56 -0400
[mime-version:] => 1.0
[content-type:] => multipart/alternative;boundary="----=_NextPart_000_006C_01C7E4FE.8EA606E0"
[x-priority:] => 3
[x-msmail-priority:] => Normal
[x-mailer:] => Microsoft Outlook Express 6.00.2900.3138
[x-mimeole:] => Produced By Microsoft MimeOLE V6.00.2900.3138
[x-scamdex-scores:] => S:110 P:86 A:91 L:89 E:97 G:82
[x-scamdex-classtype:] => S
[x-scamdex-classscore:] => 110
[x-scamdex-totscore:] => 555
[x-scamdex-kw:] => kin ,10%,\%,account,africa,bank,business,claim,contact,customer,death,deceased,die,dollars,foreign,fund,hundred thousand,inc.,internet,login,million,nigeria,partner,project,proposal,report,safe,sent,service,transaction,trust,united states dollar,urgent
[x-scamdex-em:] => 0JN700KWSB58123D@vms169131.mail,B00C3C50ABCD79A1AAAD60@phx.gbl,BLU102-W439BBB00C3C50ABCD79A1AAAD60@phx.gbl,INFO@FCC.gov,abuse@AFRINIC,abuse@IANA.ORG,dr_idmed2007@yahoo.fr,dr_idris048@hotmail.fr,fitch19461@verizon.net
[x-scamdex-dir:] => S
[x-scamdex-id:] => S1205041338.M170581P22035V
[x-scamdex-copyright:] => This Email is Copyright Scamdex.com 2009, Reproduction Prohibited
)
Domain Names used for collecting scam email ("Honeypot email accounts") have been obscured and replaced with the token 'HUN1P0T'
Community Action - SPAM/non-Scam Report
Occasionally, incorrectly categorized emails get into the Scamdex Scam Email Database and need to be removed. If this
email has Personally Identifiable Information (PII), or is, in your opinion, from a bona-fide entity, let us know.
Scamdex will, as soon as is practicable, take-down any emails that in our opinion should not
be in our database. Note that ALL emails in the Scamdex Scam Email Database were received as Unsolicited Commercial Email, aka UCE or
SPAM, via unpublished 'Honeypot' email addresses.
Sur Windows Live Ideas, découvrez en exclusivité de nouveaux services en
ligne... si nouveaux qu'ils ne sont pas encore sortis officiellement sur le
marché ! Essayez-le !
BELOW IS THE ORIGINAL EMAIL HEADER
INFORMATION:
X-Apparently-To: fitch19461@verizon.net via
216.252.111.4; Wed, 22 Aug 2007 17:39:24 -0700 X-Originating-IP: [65.54.246.171] Authentication-Results:
mta101.vzn.mail.mud.yahoo.com from=hotmail.fr; domainkeys=neutral (no sig) Received: from 66.150.124.131 (EHLO vms169131pub.verizon.net)
(206.46.169.131) by mta101.vzn.mail.mud.yahoo.com with SMTP; Wed, 22 Aug
2007 17:39:24 -0700 Received: from
bay0-omc2-s35.bay0.hotmail.com ([65.54.246.171]) by vms169131.mailsrvcs.net (Sun Java System
Messaging Server 6.2-6.01 (built Apr 3 2006)) with ESMTP id <0JN700KWSB58123D@vms169131.mailsrvcs.net>
for fitch19461@verizon.net (ORCPT fitch19461@verizon.net); Wed, 22 Aug
2007 19:39:08 -0500 (CDT) Received: from
BLU102-W43 ([10.6.53.78])
by bay0-omc2-s35.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2668); Wed, 22 Aug 2007 17:39:07 -0700 Date: Thu,
23 Aug 2007 00:39:03 +0000 From:
"ahmed idris" <dr_idris048@hotmail.fr> Subject: [SPAM]RE:
"CONFIDENTIAL" URGENT REPLY PLEASE! X-Originating-IP: [65.54.246.171] X-Originating-IP: [196.28.242.43] Bcc: Reply-To: <dr_idmed2007@yahoo.fr> Message-ID: <BLU102-W439BBB00C3C50ABCD79A1AAAD60@phx.gbl> MIME-Version:
1.0 X-MSKTag: [SPAM] X-MimeOLE: Produced By Microsoft MimeOLE
V6.00.2900.3138 Content-Type:
multipart/alternative; boundary="----=_NextPart_000_005E_01C7E4FC.E704EE20" Importance:
Normal X-OriginalArrivalTime: 23 Aug 2007 00:39:07.0873 (UTC)
FILETIME=[03CA7D10:01C7E51E] X-MSK: BYS=0.000000,RUL=0.000000
From the desk of Dr.Idris Ahmed. Manager
Bill/Exchange Foreign Remittance African Development Bank Ouagadougou
Burkina Faso. W/Africa.
Dear Partner,
Greetings
to you! This letter is strictly personal, intimate and confidential. Forgive
this unusual manner of contacting you, but this particular letter is of
exceptional and very private nature. There is absolutely going to be a great
doubt and distrust in your heart in respect of this email, coupled with the
fact that, so many miscreants have taken possession of the Internet to
facilitate their nefarious deeds, thereby making it extremely difficult for
genuine and legitimate business class persons to get attention and
recognition.
There is no way for me to know whether I will be
properly understood, but it is my duty to write and reach out to you. For I
know that you are the only one that can be trusted to handle this project
effectively without making us regret. I am (Dr.Idris Ahmed) Manager
Bills/Exchange at the Foreign Remittance Department of (ADB) AFRICAN
DEVELOPMENT BANK OUAGADOUGOU BURKINA FASO IN WEST AFRICA. In my department I
discovered an abandoned sum of US$ 24.5M (TWENTY FOUR MILLION FIVE HUNDRED
THOUSAND UNITED STATES DOLLARS) in an account that belongs to one of our
foreign customers who died on 11th September 2001 in world trade centre (WTC).
Since we got information about his death, we have been expecting
his next of kin to come over and claim his money because we cannot release it
unless somebody applied for it as the next of kin, or relation to the deceased
as indicated in our Banking guidelines. Unfortunately, nobody has come forward
to claim this money. It is based on this that I, as the bill and exchange
manager decided to establish a cordial business relationship with you, hence
by contacting you. I want you to present yourself as the next of kin or
relation of the deceased customer, so that the fund can be remitted into your
account since nobody is coming for it. And again I do not want the money to go
into the government account as unclaimed bills.
The Banking laws
and guidelines here stipulate that any account abandoned or dormant for a
period of years is deemed closed, all money contained therein would be
forfeited to the bank and government treasury account and as I see this
account, nobody comes for it and will not come because i have made several
enquires concerning the deceased. Now it is being speculated that the above
sum will be transferred into the government account as an unclaimed fund if
nobody comes forward.
Is upon this reason I am requesting you to
present yourself as the next of kin is occasioned by the fact that the
deceased (customer) was a foreigner. Also more importantly is that I have been
given the right to screen the applicants and that is why I have decided to hit
this with you. I will forward to you the detail information on how I have
planned the success of this transaction if you agree to assist me. Your
telephone and fax number will be needed encase of urgency.
I have
agreed to give you 40% of the total money .while I take 50%, 10% will be for
expenses incurred during transaction on both side. If you are in support of
the aforementioned, therefore you are urged to reply this letter indicating
your readiness and interest to participate in the business.
After receiving your reply, you will be communicated to with the
exact steps to take. And I will like you to give me a concrete assurance
that the entire fund will be safe when transferred into your
account.
To enable us conclude this transaction urgently, Please
treat this business proposal STICTLY CONFIDENTIAL for security reasons. Please
contact me with this ALTERNATIVE Email address// (dr_idmed2007@yahoo.fr) for us to proceed.
Best
regards. Dr.Idris Ahmed
Sur Windows Live Ideas, découvrez en exclusivité de nouveaux services en
ligne... si nouveaux qu'ils ne sont pas encore sortis officiellement sur le
marché ! Essayez-le !
BELOW IS THE ORIGINAL EMAIL HEADER
INFORMATION:
X-Apparently-To: fitch19461@verizon.net via
216.252.111.4; Wed, 22 Aug 2007 17:39:24 -0700 X-Originating-IP: [65.54.246.171] Authentication-Results:
mta101.vzn.mail.mud.yahoo.com from=hotmail.fr; domainkeys=neutral (no sig) Received: from 66.150.124.131 (EHLO vms169131pub.verizon.net)
(206.46.169.131) by mta101.vzn.mail.mud.yahoo.com with SMTP; Wed, 22 Aug
2007 17:39:24 -0700 Received: from
bay0-omc2-s35.bay0.hotmail.com ([65.54.246.171]) by vms169131.mailsrvcs.net (Sun Java System
Messaging Server 6.2-6.01 (built Apr 3 2006)) with ESMTP id <0JN700KWSB58123D@vms169131.mailsrvcs.net>
for fitch19461@verizon.net (ORCPT fitch19461@verizon.net); Wed, 22 Aug
2007 19:39:08 -0500 (CDT) Received: from
BLU102-W43 ([10.6.53.78])
by bay0-omc2-s35.bay0.hotmail.com with
Microsoft SMTPSVC(6.0.3790.2668); Wed, 22 Aug 2007 17:39:07 -0700 Date: Thu,
23 Aug 2007 00:39:03 +0000 From:
"ahmed idris" <dr_idris048@hotmail.fr> Subject: [SPAM]RE:
"CONFIDENTIAL" URGENT REPLY PLEASE! X-Originating-IP: [65.54.246.171] X-Originating-IP: [196.28.242.43] Bcc: Reply-To: <dr_idmed2007@yahoo.fr> Message-ID: <BLU102-W439BBB00C3C50ABCD79A1AAAD60@phx.gbl> MIME-Version:
1.0 X-MSKTag: [SPAM] X-MimeOLE: Produced By Microsoft MimeOLE
V6.00.2900.3138 Content-Type:
multipart/alternative; boundary="----=_NextPart_000_005E_01C7E4FC.E704EE20" Importance:
Normal X-OriginalArrivalTime: 23 Aug 2007 00:39:07.0873 (UTC)
FILETIME=[03CA7D10:01C7E51E] X-MSK: BYS=0.000000,RUL=0.000000