<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-1216617573566697463</atom:id><lastBuildDate>Fri, 25 Oct 2024 02:26:32 +0000</lastBuildDate><category>DNSCHART.COM</category><category>IPLIGENCE.COM</category><category>Spam Email</category><category>Trace Email</category><category>Phishing Websites</category><category>NAC.NET</category><category>REPROHIT.COM</category><category>Spoofing</category><category>Verizon.net</category><category>Virus</category><category>WASPCOM.COM</category><title>My Spam Mails</title><description></description><link>http://msmail.blogspot.com/</link><managingEditor>noreply@blogger.com (eDoDe)</managingEditor><generator>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1216617573566697463.post-6738390012239265479</guid><pubDate>Tue, 27 Apr 2010 07:27:00 +0000</pubDate><atom:updated>2010-04-27T03:10:03.297-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DNSCHART.COM</category><category domain="http://www.blogger.com/atom/ns#">IPLIGENCE.COM</category><category domain="http://www.blogger.com/atom/ns#">Spam Email</category><title>5th Spam Mail [Subject : P ay Pal Security Notification - Please Read [ref id: XRHEE]]</title><description>&lt;img style=&quot;display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 314px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiziiVaxM62DgMtx_6a5LRUDUARRBYlKQAcXjClkQrIAINMor_z9YeL3sFCeIoU1GBzgNuEskfVdvqQRfxBMzr-u9fuMNQjwRAVScj8-N5Ej5zfA68_zBvF1vjeAfCSJiiiafxWPidl7EMH/s400/msmail5.jpg&quot; border=&quot;0&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5464717056330826850&quot; /&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;This  is quiet a different email, the Mailer wants me to think like the email is sent from PayPal Security. The mail is actually from different domain &quot;&lt;/span&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;  white-space: pre-wrap; font-family:monospace;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;@security-mail.com&lt;/span&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal;  font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&quot;. Probably if anyone doesn&#39;t notice this domain on the sender, Will surely accept this as PayPal Security email, though the mailer did not include any authorized image of PayPal. Let me describe this email. The mail is sent from a website hosted to a French based Hosting site. There were two IP addresses in the email. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;  white-space: pre-wrap; font-family:monospace;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal;  font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; color: rgb(78, 94, 103);  font-family:Arial, Helvetica, sans-serif;&quot;&gt;&lt;a name=&quot;results&quot; style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: rgb(0, 0, 0); &quot;&gt;&lt;table class=&quot;product&quot; style=&quot;margin-top: 8px; margin-right: 0px; margin-bottom: 20px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-collapse: collapse; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(123, 139, 143); width: 603px; &quot;&gt;&lt;tbody style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; &quot;&gt;&lt;tr style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; &quot;&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;80.12.242.138&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;Europe&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;&lt;img src=&quot;http://www.ipligence.com/images/flags/fr.png&quot; alt=&quot;France&quot; style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; &quot; /&gt;&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;France&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;Orange&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;GMT+1&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; &quot;&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;90.35.77.215&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;Europe&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;&lt;img src=&quot;http://www.ipligence.com/images/flags/fr.png&quot; alt=&quot;France&quot; style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; &quot; /&gt;&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;France&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;Moulineaux&lt;/td&gt;&lt;td style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 4px; padding-right: 8px; padding-bottom: 3px; padding-left: 8px; font-weight: normal; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(211, 222, 226); color: rgb(78, 94, 103); &quot;&gt;GMT+1&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt;######################Original Email###################################&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;  white-space: pre-wrap; font-family:monospace;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal;  font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; color: rgb(78, 94, 103);  font-family:Arial, Helvetica, sans-serif;&quot;&gt;&lt;a name=&quot;results&quot; style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: rgb(0, 0, 0); &quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;font-family:&#39;Times New Roman&#39;;&quot;&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt;                                                                                                                                                                                                                                                             Delivered-To: ***********7@gmail.com Received: by 10.216.185.3 with SMTP id t3cs40544wem;         Mon, 26 Apr 2010 11:51:57 -0700 (PDT) Received: from mr.google.com ([10.143.87.5])         by 10.143.87.5 with SMTP id ************************ (num_hops = 1);         Mon, 26 Apr 2010 11:51:56 -0700 (PDT) Received: by 10.143.87.5 with SMTP id ***************************;         Mon, 26 Apr 2010 11:51:56 -0700 (PDT) X-Forwarded-To: *************@gmail.com X-Forwarded-For: ++++++@gmail.com *************@gmail.com Delivered-To: +++++++gmail.com Received: by 10.142.233.8 with SMTP id f8cs81499wfh;         Mon, 26 Apr 2010 11:51:55 -0700 (PDT) Received: by 10.216.162.149 with SMTP id y21mr2132891wek.196.1272307914507;         Mon, 26 Apr 2010 11:51:54 -0700 (PDT) Return-Path: &lt;/span&gt;&lt;/span&gt;&lt;gzyqif@security-mail.com&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt; Received: from smtp2a.orange.fr (smtp2a.orange.fr [80.12.242.138])         by mx.google.com with ESMTP id p18si5557448wbc.13.2010.04.26.11.51.50;         Mon, 26 Apr 2010 11:51:54 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning gzyqif@security-mail.com does not designate 80.12.242.138 as permitted sender) client-ip=80.12.242.138; Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning gzyqif@security-mail.com does not designate 80.12.242.138 as permitted sender) smtp.mail=gzyqif@security-mail.com Received: from me-wanadoo.net (localhost [127.0.0.1])  by mwinf2a02.orange.fr (SMTP Server) with ESMTP id 95E9480002E9;  Mon, 26 Apr 2010 20:51:50 +0200 (CEST) Received: from me-wanadoo.net (localhost [127.0.0.1])  by mwinf2a02.orange.fr (SMTP Server) with ESMTP id 880B880002E8;  Mon, 26 Apr 2010 20:51:50 +0200 (CEST) Received: from wanadoo.fr (APuteaux-155-1-94-215.w90-35.abo.wanadoo.fr [90.35.77.215])  by mwinf2a02.orange.fr (SMTP Server) with SMTP id 2662880002FC;  Mon, 26 Apr 2010 20:51:48 +0200 (CEST) X-ME-UUID: 20100426185148157.2662880002FC@mwinf2a02.orange.fr Reply-To: gzyqif@security-mail.com From: Support&lt;/span&gt;&lt;/span&gt;&lt;gzyqif@security-mail.com&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt; To: ebleich@gmail.com,ebm62980@gmail.com,ebogame@gmail.com,eboku01@gmail.com,ebolax@gmail.com,ebonds22@gmail.com,ebonyblake@gmail.com,ebonyseraphim@gmail.com,ebooks505@gmail.com,eboresow@gmail.com,eborge@gmail.com,ebossche7767@gmail.com,eboucher@gmail.com,eboxgj@gmail.com Subject: P ay Pal Security Notification - Please Read [ref id: XRHEE] Date: Mon, 26 Apr 2010 20:55:22 +0200 MIME-Version: 1.0 Content-Type: multipart/alternative;  boundary=&quot;----=_NextPart_000_00C9_01C2A75B.1697F626&quot; X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4522.1200 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4522.1200 Message-Id: &lt;20100426185148.2662880002fc@mwinf2a02.orange.fr&gt;  This is a multi-part message in MIME format.  ------=_NextPart_000_00C9_01C2A75B.1697F626 Content-Type: text/plain;  charset=&quot;Windows-1251&quot; Content-Transfer-Encoding: 7bit  &lt;br /&gt;&lt;br /&gt;Dear P ayP al member,&lt;br /&gt;&lt;br /&gt;You have a new message concerning your online security.&lt;br /&gt;In order to read it, please login to your account by clicking the link below:&lt;br /&gt;&lt;br /&gt;http://www.paypalusa.com.cmd.irolessmass.eu.com/us/webscr/?id=XRHEE&lt;br /&gt;&lt;br /&gt;Thank you for your co-operation.  ------=_NextPart_000_00C9_01C2A75B.1697F626 Content-Type: text/html;  charset=&quot;Windows-1251&quot; Content-Transfer-Encoding: 7bit  &lt;br /&gt;&lt;br /&gt;Dear P ayP al member,&lt;br /&gt;&lt;br /&gt;You have a new message concerning your online security.&lt;br /&gt;In order to read it, please login to your account by clicking the link below:&lt;br /&gt;&lt;br /&gt;http://www.paypalusa.com.cmd.irolessmass.eu.com/us/webscr/?id=XRHEE&lt;br /&gt;&lt;br /&gt;Thank you for your co-operation.   ------=_NextPart_000_00C9_01C2A75B.1697F626--&lt;/span&gt;&lt;/span&gt;&lt;/gzyqif@security-mail.com&gt;&lt;/gzyqif@security-mail.com&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33CC00;&quot;&gt; ####################################################################################&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;  white-space: pre-wrap; font-family:monospace;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal;  font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; color: rgb(78, 94, 103);  font-family:Arial, Helvetica, sans-serif;&quot;&gt;&lt;a name=&quot;results&quot; style=&quot;margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; color: rgb(0, 0, 0); &quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-size: medium;&quot;&gt;These were the records fetched from IPLIGENCE.COM. Also there is no such domain &quot;security-mail.com&quot; exists. Also the link is the email was blocked by Firefox as forgery site, i ignored that warning and the site leads to nowhere but an empty page. The domain was registered to German based domain provider. This is all i have about this email.&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;</description><link>http://msmail.blogspot.com/2010/04/5th-spam-mail-subject-p-ay-pal-security.html</link><author>noreply@blogger.com (eDoDe)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiziiVaxM62DgMtx_6a5LRUDUARRBYlKQAcXjClkQrIAINMor_z9YeL3sFCeIoU1GBzgNuEskfVdvqQRfxBMzr-u9fuMNQjwRAVScj8-N5Ej5zfA68_zBvF1vjeAfCSJiiiafxWPidl7EMH/s72-c/msmail5.jpg" height="72" width="72"/><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1216617573566697463.post-1509512822649749258</guid><pubDate>Thu, 11 Jun 2009 10:19:00 +0000</pubDate><atom:updated>2010-04-26T11:16:20.368-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DNSCHART.COM</category><category domain="http://www.blogger.com/atom/ns#">IPLIGENCE.COM</category><category domain="http://www.blogger.com/atom/ns#">Phishing Websites</category><category domain="http://www.blogger.com/atom/ns#">Spam Email</category><category domain="http://www.blogger.com/atom/ns#">Trace Email</category><title>4th Spam Mail [Subject : Get travel gift coupon worth Rs 500 every month]</title><description>&lt;img style=&quot;display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 327px; height: 400px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0w4D1jlw9fcyjPg3DdNZgs2SoaE8vGXAvyRUUP8tzJYsOgktIPEvLRVdvTUffXoWwtIlnMuHq5LktpXWKJRln9NM01lKUTdUTqbhJZiK-M5SKDT3w7iOqy6j7Xghtx5w-9A67zxwxLLff/s400/msmail4.jpg&quot; border=&quot;0&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5464482130208290978&quot; /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Well, i first thought that this mail isn&#39;t a Spam Email even it arrived in my Spam Folder. Then i went on analyzing it. The mail content, says that i got a Travel Gift Coupon for Rs.500/- every month. This mail might have been sent by &quot;Expedia.co.in&quot; as famous Travel Website in India. But all the link in the mail will take me to &quot;&lt;span class=&quot;Apple-style-span&quot;   style=&quot;  white-space: pre-wrap; font-family:monospace;font-size:medium;&quot;&gt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=#######&amp;amp;k=bsm&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal;  font-family:Georgia, serif;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;font-size:medium;&quot;&gt;&quot;, a domain belonging to different website. But surprisingly there is no visible page hosting on this domain and the link take me to &quot;Expedia.co.in&quot;. The Domain &quot;s2d6.com&quot; is hosted in &quot;theplanet.com&quot;, a hosting website. I really don&#39;t understand the purpose of this email. May be the Emailer need to generate traffic to &quot;Expedia.co.in&quot; from a different domain. The image in the mail has some image attached from &quot;trassenger.com&quot;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;###################################################################&lt;br /&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#0000EE;&quot;&gt;&lt;u&gt;&lt;span class=&quot;Apple-style-span&quot;   style=&quot;color: rgb(0, 0, 0);  -webkit-text-decorations-in-effect: none;  font-family:&#39;Times New Roman&#39;;font-size:medium;&quot;&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;Delivered-To: ###########@gmail.com Received: by 10.216.185.3 with SMTP id t3cs31569wem;         Mon, 26 Apr 2010 06:39:49 -0700 (PDT) Received: by 10.101.177.39 with SMTP id e39mr5164106anp.36.1272289188891;         Mon, 26 Apr 2010 06:39:48 -0700 (PDT) Return-Path: &lt;/span&gt;&lt;trassenger@gmail.com&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt; Received: from ns1.silkflowers.co.in ([207.44.147.60])         by mx.google.com with ESMTP id 9si1788972gxk.1.2010.04.26.06.39.48;         Mon, 26 Apr 2010 06:39:48 -0700 (PDT) Received-SPF: neutral (google.com: 207.44.147.60 is neither permitted nor denied by domain of trassenger@gmail.com) client-ip=207.44.147.60; Authentication-Results: mx.google.com; spf=neutral (google.com: 207.44.147.60 is neither permitted nor denied by domain of trassenger@gmail.com) smtp.mail=trassenger@gmail.com Received: from mail pickup service by ns1.silkflowers.co.in with Microsoft SMTPSVC; 	 Mon, 26 Apr 2010 08:24:03 -0500 thread-index: AcrlQ6HdAAkIUanvQdKPrFM6vu+O1w== Thread-Topic: Get travel gift coupon worth Rs 500 every month From: &quot;Sana Afreen&quot; &lt;/span&gt;&lt;trassenger@gmail.com&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt; To: #############@gmail.com&gt; Subject: Get travel gift coupon worth Rs 500 every month Date: Mon, 26 Apr 2010 08:23:26 -0500 Message-ID: &lt;10a46a156cd84f5f9da8506212020987@silkflowers.co.in&gt; MIME-Version: 1.0 Content-Type: multipart/alternative; 	boundary=&quot;----=_NextPart_000_1D4FC_01CAE519.B90731C0&quot; X-Mailer: Microsoft CDO for Windows 2000 Content-Class: urn:content-classes:message Importance: normal Priority: normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.4325 X-OriginalArrivalTime: 26 Apr 2010 13:24:03.0890 (UTC) FILETIME=[BD88A920:01CAE543]  This is a multi-part message in MIME format.  ------=_NextPart_000_1D4FC_01CAE519.B90731C0 Content-Type: text/plain; 	charset=&quot;iso-8859-1&quot; Content-Transfer-Encoding: 7bit&lt;/span&gt;&lt;/trassenger@gmail.com&gt;&lt;/trassenger@gmail.com&gt;&lt;/pre&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot; white-space: normal; -webkit-text-decorations-in-effect: none; font-family:&#39;Times New Roman&#39;;&quot;&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;UNABLE TO VIEW THIS EMAIL CORRECTLY? CLICK HERE &lt;/span&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;    &lt;/span&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt; 	 Dear Traveller,  Have you checked out Expedia.co.in &lt;/span&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;  yet? For a limited time we&#39;re offering you a coupon worth Rs 500* when you sign-up for our email newsletter. Each month we&#39;ll bring you the best travel deals straight to your inbox. Be inspired to travel the world today with Expedia.co.in &lt;/span&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt; , part of the world&#39;s leading online travel company.  Click Here To Sign Up Now ! &lt;/span&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;   Terms and Conditions &lt;/span&gt;&lt;http://register.expedia.co.in/termsnconditions.php&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;   You are receiving this mail because you are registered on trassenger.com Or One of its group site. To stop receiving such mails click here &lt;/span&gt;&lt;mailto:trassenger@gmail.com?subject=unsubscribe&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt;      ------=_NextPart_000_1D4FC_01CAE519.B90731C0 Content-Type: text/html Content-Transfer-Encoding: 7bit  &lt;/span&gt;&lt;/mailto:trassenger@gmail.com?subject=unsubscribe&gt;&lt;/http://register.expedia.co.in/termsnconditions.php&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/pre&gt;&lt;pre style=&quot;word-wrap: break-word; white-space: pre-wrap; &quot;&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;http://register.expedia.co.in/termsnconditions.php&gt;&lt;mailto:trassenger@gmail.com?subject=unsubscribe&gt;&lt;span class=&quot;Apple-style-span&quot;  style=&quot;color:#33FF33;&quot;&gt; ------=_NextPart_000_1D4FC_01CAE519.B90731C0--&lt;/span&gt;&lt;/mailto:trassenger@gmail.com?subject=unsubscribe&gt;&lt;/http://register.expedia.co.in/termsnconditions.php&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/http://www.s2d6.com/x/?x=c&amp;amp;z=s&amp;amp;v=2730388&amp;amp;k=bsm&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/u&gt;&lt;/span&gt;&lt;/div&gt;###################################################################&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Be aware, if you get such message in your inbox or Spam folder. &lt;/div&gt;</description><link>http://msmail.blogspot.com/2009/06/4th-spam-mail-subject-get-travel-gift.html</link><author>noreply@blogger.com (eDoDe)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0w4D1jlw9fcyjPg3DdNZgs2SoaE8vGXAvyRUUP8tzJYsOgktIPEvLRVdvTUffXoWwtIlnMuHq5LktpXWKJRln9NM01lKUTdUTqbhJZiK-M5SKDT3w7iOqy6j7Xghtx5w-9A67zxwxLLff/s72-c/msmail4.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1216617573566697463.post-8076911300761384801</guid><pubDate>Tue, 09 Jun 2009 13:27:00 +0000</pubDate><atom:updated>2009-06-11T03:07:59.785-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DNSCHART.COM</category><category domain="http://www.blogger.com/atom/ns#">IPLIGENCE.COM</category><category domain="http://www.blogger.com/atom/ns#">Spam Email</category><category domain="http://www.blogger.com/atom/ns#">Spoofing</category><category domain="http://www.blogger.com/atom/ns#">Trace Email</category><category domain="http://www.blogger.com/atom/ns#">Verizon.net</category><category domain="http://www.blogger.com/atom/ns#">Virus</category><title>3rd Spam Mail [Subject : This is my cellphone number]</title><description>&lt;a onblur=&quot;try {parent.deselectBloggerImageGracefully();} catch(e) {}&quot; href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-96cRlGIW3XIYEwWMb9V5oDrNi0fQ7Vb8O-RtwHPnmF8tXavsmmAzUfIAzKFbNCnaFW1tq-FeyAC9LDl2F5fpo__dcVk5ziiw_8ND4pXDtiluHQxoFvU-svn1hW-DcSCH6ZytLMytOZKh/s1600-h/3.bmp&quot;&gt;&lt;img style=&quot;margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 297px; height: 400px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-96cRlGIW3XIYEwWMb9V5oDrNi0fQ7Vb8O-RtwHPnmF8tXavsmmAzUfIAzKFbNCnaFW1tq-FeyAC9LDl2F5fpo__dcVk5ziiw_8ND4pXDtiluHQxoFvU-svn1hW-DcSCH6ZytLMytOZKh/s400/3.bmp&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5346004856889619714&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This Spam mail is quiet different. This guy has used my own email id and sent me an email. As i said he didn&#39;t actually hacked into my Account but this method of fraudulent is called Spoofing. The texts inbetween the lines is the header of the Original Email as sent by the spammer.&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------------------&lt;br /&gt;&lt;a name=&quot;results&quot;&gt;&lt;br /&gt;Delivered-To: ##########@gmail.com&lt;br /&gt;Received: by 10.229.88.19 with SMTP id y19cs182611qcl;&lt;br /&gt;        Sun, 7 Jun 2009 14:04:24 -0700 (PDT)&lt;br /&gt;Received: by 10.210.61.8 with SMTP id j8mr5678864eba.22.1244408663519;&lt;br /&gt;        Sun, 07 Jun 2009 14:04:23 -0700 (PDT)&lt;br /&gt;Return-Path: &lt;##########@gmail.com&gt;&lt;br /&gt;Received: from pool-70-20-20-56.bstnma.fios.verizon.net (pool-70-20-20-56.bstnma.fios.verizon.net [70.20.20.56])&lt;br /&gt;        by mx.google.com with ESMTP id 12si4287938ewy.31.2009.06.07.14.04.20;&lt;br /&gt;        Sun, 07 Jun 2009 14:04:21 -0700 (PDT)&lt;br /&gt;Received-SPF: neutral (google.com: 70.20.20.56 is neither permitted nor denied by domain of ##########@gmail.com) client-ip=70.20.20.56;&lt;br /&gt;Authentication-Results: mx.google.com; spf=neutral (google.com: 70.20.20.56 is neither permitted nor denied by domain of ##########@gmail.com) smtp.mail=##########@gmail.com&lt;br /&gt;Date: Sun, 07 Jun 2009 14:04:21 -0700 (PDT)&lt;br /&gt;Message-ID: &lt;587879334564759.advrbmntohacbua@pool-70-20-20-56.bstnma.fios.verizon.net&gt;&lt;br /&gt;From: &quot;Randy&quot; &lt;##########@gmail.com&gt;&lt;br /&gt;To: ##########@gmail.com&lt;br /&gt;Subject: This is my cellphone number&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Type: text/html; charset=&quot;iso-8859-1&quot;&lt;br /&gt;Content-Transfer-Encoding: 7bit&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;First i tried to trace the location of the server that the Spammer used to send me an Email through IPLIGENCE.COM. I got this IP address: 70.20.20.56. This should have been an Email from Google Server but This IP address points the VERIZON.NET server as per WHOIS IP report of DNSCHART.COM. By this the Spammer used the option of Spoofing to send me an email, Like i have sent an email to myself. This Email consits of Various unknown links, which when visited can or may have a threat of downloading VIRUSES. So be careful if you receive such emails.&lt;br /&gt;&lt;br /&gt;By Clicking the Above image file, The Picture document of the email that i received can be viewed clearly.&lt;br /&gt;&lt;/a&gt;</description><link>http://msmail.blogspot.com/2009/06/3rd-spam-mail-subject-this-is-my.html</link><author>noreply@blogger.com (eDoDe)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-96cRlGIW3XIYEwWMb9V5oDrNi0fQ7Vb8O-RtwHPnmF8tXavsmmAzUfIAzKFbNCnaFW1tq-FeyAC9LDl2F5fpo__dcVk5ziiw_8ND4pXDtiluHQxoFvU-svn1hW-DcSCH6ZytLMytOZKh/s72-c/3.bmp" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1216617573566697463.post-7983808079150835514</guid><pubDate>Sun, 07 Jun 2009 17:27:00 +0000</pubDate><atom:updated>2009-06-07T10:47:37.385-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DNSCHART.COM</category><category domain="http://www.blogger.com/atom/ns#">IPLIGENCE.COM</category><category domain="http://www.blogger.com/atom/ns#">NAC.NET</category><category domain="http://www.blogger.com/atom/ns#">Phishing Websites</category><category domain="http://www.blogger.com/atom/ns#">REPROHIT.COM</category><category domain="http://www.blogger.com/atom/ns#">Spam Email</category><category domain="http://www.blogger.com/atom/ns#">Trace Email</category><title>2nd Spam Mail [Subject : (no subject)]</title><description>&lt;a onblur=&quot;try {parent.deselectBloggerImageGracefully();} catch(e) {}&quot; href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2eQ49NQFGvA4KHZEhgPo7voSrKEaUbX-ZlzyIkMHFU5yCtLaZdnW8kOj9S_pTrQj1-6lGoTYGeKIzGYwH19zeGJI4wpVlb2y9jT7oPjCwf3eekPqCCIUGe5D9rnIOgftWwhhyphenhyphenZBkHKt88/s1600-h/2.bmp&quot;&gt;&lt;img style=&quot;margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 203px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2eQ49NQFGvA4KHZEhgPo7voSrKEaUbX-ZlzyIkMHFU5yCtLaZdnW8kOj9S_pTrQj1-6lGoTYGeKIzGYwH19zeGJI4wpVlb2y9jT7oPjCwf3eekPqCCIUGe5D9rnIOgftWwhhyphenhyphenZBkHKt88/s400/2.bmp&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5344640015247707538&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;br /&gt;This is the 2nd Spam i wish to explain about. Like in the previous spam mail, The Spam mail is sent from the same server &quot;NAC.NET&quot;. The Header of the original mail is given below:&lt;br /&gt;&lt;br /&gt;----------------------------------------------------------------------------&lt;br /&gt;                                                                                                                                                                                                                                                              &lt;br /&gt;Delivered-To: ##########@gmail.com&lt;br /&gt;Received: by 10.229.91.76 with SMTP id l12cs43351qcm;&lt;br /&gt;        Thu, 4 Jun 2009 18:38:58 -0700 (PDT)&lt;br /&gt;Received: by 10.224.11.72 with SMTP id s8mr3051526qas.185.1244165936130;&lt;br /&gt;        Thu, 04 Jun 2009 18:38:56 -0700 (PDT)&lt;br /&gt;Return-Path: &lt;n.267.5901807@reprohit.com&gt;&lt;br /&gt;Received: from ip48.reprohit.com (ip48.reprohit.com [64.21.165.48])&lt;br /&gt;        by mx.google.com with SMTP id 12si3315459qyk.29.2009.06.04.18.38.56;&lt;br /&gt;        Thu, 04 Jun 2009 18:38:56 -0700 (PDT)&lt;br /&gt;Received-SPF: pass (google.com: domain of n.267.5901807@reprohit.com designates 64.21.165.48 as permitted sender) client-ip=64.21.165.48;&lt;br /&gt;Authentication-Results: mx.google.com; spf=pass (google.com: domain of n.267.5901807@reprohit.com designates 64.21.165.48 as permitted sender) smtp.mail=n.267.5901807@reprohit.com&lt;br /&gt;Date: Thu, 04 Jun 2009 21:26:06 -0400&lt;br /&gt;From: &quot;healthy legs&quot; &lt;venacura@reprohit.com&gt;&lt;br /&gt;To: ##########@gmail.com&lt;br /&gt;Subject: &lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;X-Mailer: xyf v8.3.4.1000.5901807&lt;br /&gt;Reply-To: r.267.5901807@reprohit.com&lt;br /&gt;Message-Id: &lt;20090604180006.fnatipsdca@reprohit.com&gt;&lt;br /&gt;Content-Type: multipart/alternative;&lt;br /&gt;    boundary=&quot;=_23657ff2a4c51a224d3eddc716ae9305&quot;&lt;br /&gt;------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;As per this Header, this email is sent from &quot;REPROHIT.COM&quot;, but From DNSCHART IP Whois Report the IP Address &quot;64.21.165.48&quot; doesn&#39;t match with Domain. The actual Domain name of the IP address was &quot;NAC.NET&quot;, Like i said in my previous email.&lt;br /&gt;&lt;br /&gt;I determined the Location of the server by using DNSCHART.COM and IPLIGENCE.COM, Like i did in my previous post. Also my blog visitors can use the Header of the email to make a try to trace the Spammer location.</description><link>http://msmail.blogspot.com/2009/06/2nd-spam-mail-subject-no-subject.html</link><author>noreply@blogger.com (eDoDe)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2eQ49NQFGvA4KHZEhgPo7voSrKEaUbX-ZlzyIkMHFU5yCtLaZdnW8kOj9S_pTrQj1-6lGoTYGeKIzGYwH19zeGJI4wpVlb2y9jT7oPjCwf3eekPqCCIUGe5D9rnIOgftWwhhyphenhyphenZBkHKt88/s72-c/2.bmp" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-1216617573566697463.post-1076818059295638800</guid><pubDate>Wed, 03 Jun 2009 17:16:00 +0000</pubDate><atom:updated>2009-06-07T10:26:42.803-07:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">DNSCHART.COM</category><category domain="http://www.blogger.com/atom/ns#">IPLIGENCE.COM</category><category domain="http://www.blogger.com/atom/ns#">NAC.NET</category><category domain="http://www.blogger.com/atom/ns#">Phishing Websites</category><category domain="http://www.blogger.com/atom/ns#">Spam Email</category><category domain="http://www.blogger.com/atom/ns#">Trace Email</category><category domain="http://www.blogger.com/atom/ns#">WASPCOM.COM</category><title>My First Spam mail -[Subject : Stop working long hours]</title><description>&lt;a onblur=&quot;try {parent.deselectBloggerImageGracefully();} catch(e) {}&quot; href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhukplsFfNVu7QR0ygKR1CvFoSYuPTohZct0uhYEXNmrpgViImxdTo2UUxp0ie7WpWgDbtQ0JeUPUXeD6l_PQbEzWjUB87InvaEFmgOyEhqc89aLIiWEDjOxE2kdsppa8A7VH-zaDBnYIma/s1600-h/1.bmp&quot;&gt;&lt;img style=&quot;margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 521px; height: 515px;&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhukplsFfNVu7QR0ygKR1CvFoSYuPTohZct0uhYEXNmrpgViImxdTo2UUxp0ie7WpWgDbtQ0JeUPUXeD6l_PQbEzWjUB87InvaEFmgOyEhqc89aLIiWEDjOxE2kdsppa8A7VH-zaDBnYIma/s400/1.bmp&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_5344627523829138626&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The Above picture is the Spam Mail is wish to explain. Basically to trace the IP and location from which the Email has been sent is determined from the &quot;Original Message&quot; of the mail. The Header section of the Original Message of this Email is given Below.&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------&lt;br /&gt;Delivered-To: #########@gmail.com&lt;br /&gt;Received: by 10.229.91.76 with SMTP id l12cs41945qcm;&lt;br /&gt;        Thu, 4 Jun 2009 18:04:45 -0700 (PDT)&lt;br /&gt;Received: by 10.224.74.16 with SMTP id s16mr3025851qaj.320.1244163851087;&lt;br /&gt;        Thu, 04 Jun 2009 18:04:11 -0700 (PDT)&lt;br /&gt;Return-Path: &lt;n.266.5901807@waspcom.com&gt;&lt;br /&gt;Received: from ip10.waspcom.com (ip10.waspcom.com [64.21.165.10])&lt;br /&gt;        by mx.google.com with SMTP id 12si3264373qyk.63.2009.06.04.18.04.10;&lt;br /&gt;        Thu, 04 Jun 2009 18:04:11 -0700 (PDT)&lt;br /&gt;Received-SPF: pass (google.com: domain of n.266.5901807@waspcom.com designates 64.21.165.10 as permitted sender) client-ip=64.21.165.10;&lt;br /&gt;Authentication-Results: mx.google.com; spf=pass (google.com: domain of n.266.5901807@waspcom.com designates 64.21.165.10 as permitted sender) smtp.mail=n.266.5901807@waspcom.com&lt;br /&gt;Date: Thu, 04 Jun 2009 20:49:06 -0400&lt;br /&gt;From: &quot;robert allen&quot; &lt;robertallen@waspcom.com&gt;&lt;br /&gt;To: ##########@gmail.com&lt;br /&gt;Subject: Stop working long hours&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;X-Mailer: rws v8.3.4.1000.5901807&lt;br /&gt;Reply-To: r.266.5901807@waspcom.com&lt;br /&gt;Message-Id: &lt;20090604170005.erzuendpwf@waspcom.com&gt;&lt;br /&gt;Content-Type: multipart/alternative;&lt;br /&gt;    boundary=&quot;=_4c4684c84d04d9efd613a810054472bf&quot;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;This is quiet difficult to get the IP location from the above Header. With the help of &lt;a href=&quot;http://ipligence.com&quot;&gt;IPLIGENCE.COM&lt;/a&gt;, and copying this Header to the Email Tracer Text Box and Clicking on the &quot;Trace&quot; link will trace this email&#39;s IP address and Location of the server, which is used by the spammer. Though the Spammer&#39;s Location couldn&#39;t be determined, We can report about Abuse mail to the server, so that the server Admin can look after the Spammer and control them in accessing the server again.&lt;br /&gt;&lt;br /&gt;After Getting the IP and Location of the server, I use the information to Trace the Domain Owner. From the above header &quot;WASPCOM.COM&quot; is the server used to Send this email. But with the help of &lt;a href=&quot;http://dnschart.com&quot;&gt;DNSCHART.COM&lt;/a&gt; --&gt; &quot;IP Whois&quot; Option, I found that the IP address and Domain doesn&#39;t match. The IP Address determined from the mail was &quot;&lt;a name=&quot;results&quot;&gt;64.21.165.10&quot;, But the email was sent from &quot;NAC.NET&quot;. This proves that this is a Spam email.&lt;br /&gt;&lt;br /&gt;This Mail consists of Links in it, Which leads to Phishing Sites. Phishing sites were maily used to Steal Information from the Internet user. Due to unawarness among people, Many give out their personal details and get into trouble. To Create awarness among Internet Users, I pubished this Blog.&lt;/a&gt;&lt;a name=&quot;results&quot;&gt; If you have received such email, Be aware and report it to the server admin in Advance. &lt;/a&gt;&lt;a name=&quot;results&quot;&gt;&lt;br /&gt;&lt;br /&gt;For More information on Phishing Websites, Visit these links:&lt;br /&gt;&lt;br /&gt;http://edode.blogspot.com/2009/04/i-can-help-you-trace-email-spammer.html&lt;br /&gt;&lt;br /&gt;http://edode.blogspot.com/2008/11/know-about-phishing-websites.html&lt;br /&gt;&lt;br /&gt;        &lt;br /&gt;&lt;/a&gt;</description><link>http://msmail.blogspot.com/2009/06/my-first-spam-mail-subject-stop-working.html</link><author>noreply@blogger.com (eDoDe)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhukplsFfNVu7QR0ygKR1CvFoSYuPTohZct0uhYEXNmrpgViImxdTo2UUxp0ie7WpWgDbtQ0JeUPUXeD6l_PQbEzWjUB87InvaEFmgOyEhqc89aLIiWEDjOxE2kdsppa8A7VH-zaDBnYIma/s72-c/1.bmp" height="72" width="72"/><thr:total>0</thr:total></item></channel></rss>