~~~~SOURCE~~~~
From - Mon Mar 16 17:13:51 2009
X-Account-Key: account2
X-UIDL: ABQmvs4AAKlKSb5IHw5/Emvq0EQ
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:
X-Apparently-To: removed'at'yahoo.com via 206.190.38.20; Mon, 16 Mar
2009 05:37:51 -0700
X-YMailISG:
Cdxe2zkWLDshPaq0sc5Z1aQuoQjyTNioG6bJfrCFf0iPJnvlQ8g6yEds1fe_Zhc8JxhcikSaxvQDgvWy
nDlSDRyoQomD4aPmAVngTqpubFM9ldpcveK_T_atB85IjVEtwBYwA32Dx.
wL8pUMNQtV7lr82H7F97IKTK1zqrkcoCfC38xC15p7wba.8HnHl9O0X.
lDeZpwjZU_iSF4nGYRZIx2EFAflP5ArMAbMQJAeHStt2Jr1Aum3yJ_4CFNnyhudf86FK9gGXfBR5Qvt1
BeFj_86lZmu7PMvQtBIZWPjyiozn3p7HB1X.Sd0cv.
Vy8r4bQ6juI6UlEL5EWa7NXG7BvOKhbgqcGGmfR0DSM1Trf8hSq1R0Cz_GwogcQzbhS1TJULpyYf4n59
fzjaBQJdntgdnK_FNDxoZmCA9KZiUFJqjhL.0YWX73tI8cotCw--
X-Originating-IP: [208.47.184.3]
Authentication-Results: mta353.mail.re4.yahoo.com from=embarqmail.com;
domainkeys=neutral (no sig); from=embarqmail.com; dkim=pass (ok)
Received: from 208.47.184.3 (EHLO mailrelay.embarq.synacor.com) (208.47.184.3)
by mta353.mail.re4.yahoo.com with SMTP; Mon, 16 Mar 2009 05:37:51 -0700
DKIM-Signature: v=1; a=rsa-sha1; d=embarqmail.com; s=s012408; c=relaxed/simple;
q=dns/txt; i='at'embarqmail.com; t=1237207067;
h=From:Subject:Date:To:MIME-Version:Content-Type;
bh=D5d+YTIs7q6hIwWyphgRG8DITaM=;
b=U7T07LgzA+xN+Q2cWgyewVU++VTVAak0bLZK0Lstd87Xb3Pq/gE60vjpSvdAAspW
leZwW6Fyr7/B6lOmgNzTdHcN5haup1aS7Su666h7CtbI03s4JFd/Rnm758YRDPwQ;
X_CMAE_Category: 0,0 Undefined,Undefined
X-CNFS-Analysis: v=1.0 c=1 a=db1WoY3_u15ndpFEqzMA:9
a=vw2fgMzCmmqv7su_benpAc6o448A:4 a=b8hG5vVbyAkA:10 a=MPEGXx7wpfpevfbO2JAA:9
a=KI2MO-ewXrNnsu6gVAIA:7 a=7SAkcumqS4tqj0Txf06dtQAD3rsA:4 a=37WNUvjkh6kA:10
X-CM-Score: 0
X-Scanned-by: Cloudmark Authority Engine
Received: from [10.10.5.32] ([10.10.5.32:41145] helo=md24.embarq.synacor.com)
by mailrelay.embarq.synacor.com (envelope-from
<char7348'at'embarqmail.com>)
(ecelerity 2.2.2.36 r(27513/27514)) with ESMTP
id 50/95-00375-A184EB94; Mon, 16 Mar 2009 08:37:46 -0400
Date: Mon, 16 Mar 2009 08:37:46 -0400 (EDT)
From: Mark Frank <char7348'at'embarqmail.com>
To: captmarkfrank'at'gmail.com
Message-ID:
/1127301481.13432231237207066775.javamail.root'at'md24.embarq.synacor.com
Subject: Crew Member Needed Urgently
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_629234_298161876.1237207066773"
X-Originating-IP: [41.219.211.135]
X-Mailer: Zimbra 5.0.11_GA_2696.RHEL4 (zclient/5.0.11_GA_2696.RHEL4)
------=_Part_629234_298161876.1237207066773
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Hello,
My name is Capt. Mark Frank, i work with Bridlington Yacht Club located in
United Kingdom. I came across your profile and decided to mail you regarding a
job offer. We are seeking for crew member. If you are interested send me a mail
along with your resume.
Hope to hear from you soonest.
Best Regards
Capt. Mark Frank
------=_Part_629234_298161876.1237207066773
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit
Hello,
My name is Capt. Mark Frank, i work with
Bridlington Yacht Club located in United Kingdom. I came across your profile and
decided to mail you regarding a job offer. We are seeking for crew member. If
you are interested send me a mail along with your resume.
Hope to hear
from you soonest.
Best Regards
Capt. Mark Frank
------=_Part_629234_298161876.1237207066773--
I'm curious. Is there really a “Capt Mark Frank” or a Bridlington Yacht Club in the UK? What is Embarqmail? What do these IP addresses correlate to and does it all add up? Not that I want to email this guy, but if it was genuine I would want to help him out and respond. But I am guessing this email is bogus. Let's check it out....
Tools: Google (of course), traceroute, & whois.
1. First I did I search based on Yacht clubs in Bridlington: Yacht Clubs do come up in the search, but nothing directly correlating with Bridlington.
2. Search of captmarkfrank'at'gmail.com comes up with nothing concrete.
3. Search of char7348'at'embarqmail.com brings up a spreadsheet of contact information for a club of some-sort located in the state of Ohio at this link:
www.nationalitpa.com/documents/appendc.doc.xls
4. A search of Embarqmail.com brings up a broadband Internet Service Provider in Ohio as well. Still missing a solid connection to the UK here and things are not adding up.
5. I searched the IP addresses highlighted in blue above and the most revealing was 41.219.211.135, results:
whois 41.219.211.135
% This is the AfriNIC Whois server.
% Note: this output has been filtered.
% Information related to '41.219.211.0 – 41.219.211.255'
inetnum: 41.219.211.0 – 41.219.211.255
netname: ORG-SA57-AFRINIC-20050513
descr: Assigned to Lagos dial-pool customers
country: NG
admin-c: NS4-AFRINIC
tech-c: CM9-AFRINIC
status: Assigned PA
mnt-by: STARCOMMS-MNT
mnt-lower: STARCOMMS-MNT
source: AFRINIC # Filtered
parent: 41.219.192.0 – 41.219.255.255
person: NAVNEET SINGH
address: Plot 1261, Bishop Kale Close, off Saka Tinubu
address: Victoria Island, Lagos, Nigeria
phone: +234-1-804-9370
fax-no: +234-1-811-0301
e-mail: navneets'at'starcomms.com
nic-hdl: NS4-AFRINIC
source: AFRINIC # Filtered
person: Catalin Miclaus
address: Plot 1261C, Bishop Kale Close, off Saka Tinubu
phone: +234-7028000733
fax-no: +234-1-8110301
e-mail: catalin'at'starcomms.com
nic-hdl: CM9-AFRINIC
source: AFRINIC # Filtered
6. So basically we've established that the email is bogus. I figure the goal here is to get more personal information via a resume. It would appear that someone's email address is being spoofed or even hacked.
7. Where to go from here? Respond from a bogus email with a bogus resume and see how long I could keep this going? Write a blog to inform others? Or just hit delete? Anyone else have any more info?