A interesting email – FROM field empty

Received a interesting email yesterday from Mr. Gordon Hills from London who wanted me to be partner and 5 Million dollars will be released to me. Sometimes does feel like someone should give me money 🙂

se emailheader

The email seems to be a template and this could be a broadcast on the internet. Interesting to see that sender email is hidden. The technique is not new but still is being used. There are lot of anonymous email services that cane b used to do the same. Looked through the header and was able to find the originating IP as 104.47.100.221 –  mail-ma1ind01hn0221.outbound.protection.outlook.com. The IP is blacklisted on multiple sites.
When we hit reply the email is suppose to go to masterkey728@gmail.com. From the header originating IP for the email is 116.203.77.238 which is again blacklisted in spamhaus.
The email has no attachments or URL. The attempt likely is to collect personal information for further follow-up campaign.

Associated IP :

104.47.100.221
116.203.77.238

Blacklisting :
http://www.ipvoid.com/scan/116.203.77.238/ – This IP address is infected with, or is NATting for a machine infected with the ZeroAccess botnet, also known as Sirefef as per spamhaus cbl.

http://www.ipvoid.com/scan/104.47.100.221/ – a known spamer – http://www.dnsbl.manitu.net/lookup.php?language=en&value=104.47.100.221

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s