A interesting email – FROM field empty

Received a interesting email yesterday from Mr. Gordon Hills from London who wanted me to be partner and 5 Million dollars will be released to me. Sometimes does feel like someone should give me money 🙂

se emailheader

The email seems to be a template and this could be a broadcast on the internet. Interesting to see that sender email is hidden. The technique is not new but still is being used. There are lot of anonymous email services that cane b used to do the same. Looked through the header and was able to find the originating IP as –  mail-ma1ind01hn0221.outbound.protection.outlook.com. The IP is blacklisted on multiple sites.
When we hit reply the email is suppose to go to masterkey728@gmail.com. From the header originating IP for the email is which is again blacklisted in spamhaus.
The email has no attachments or URL. The attempt likely is to collect personal information for further follow-up campaign.

Associated IP :

Blacklisting :
http://www.ipvoid.com/scan/ – This IP address is infected with, or is NATting for a machine infected with the ZeroAccess botnet, also known as Sirefef as per spamhaus cbl.

http://www.ipvoid.com/scan/ – a known spamer – http://www.dnsbl.manitu.net/lookup.php?language=en&value=

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s