DelphiFAQ Home Search:

Dating scammer Elena

 

commentsThis article has not been rated yet. After reading, feel free to leave comments and rate it.

Name: Elena


Email: ellena050@gmail.com


Address:
www.dating-world.net dating-world datingworld dating world scammer All scammer website..

ellena050@gmail.com scammer

ellena050 scammer



Other Comments:
She is a damm scammer, and not registered yet here...


Comments:

2009-07-10, 15:01:56   (updated: )
[hidden] from Brazil  

This image was also posted here:
Dating scammer Natalya from Osinniki, Russia



Keywords:
2009-07-24, 04:17:46
JJ from Spain  
An E-Mail to OJAS, hallo, how are you?, I'm JJ from Spain, how goes the anti-scamms crusade?, I know you are an expert in headers, I post this one from an scammer 'lady' I am writing now with her, if you would be so kind to explain me about what it means, I did get any like this with that of AntiAbuse.
The IP one is from Houston Texas, the other Yoskar-Ola as usual and the other Marina del Rey CA. but the E-Mail is not google or yahoo and then the times between Spain and Calif. you go 7 hrs. in advance and we, with Yoskar-Ola, we go 2 hrs. in advance.

Received: from s52.avahost.net ([75.125.251.90])
Sun, 19 Jul 2009 03:04:28 +0200
Received: from [92.255.242.56] (helo=[10.81.0.138])
by s52.avahost.net with esmtpa (Exim 4.69)
(envelope-from <shocoladka@lvmail.ru>)
id 1MSD0U-0007uh-Pl
Sat, 18 Jul 2009 11:43:31 -0500
Date: Sat, 18 Jul 2009 20:37:47 +0400
From: shocoladka@lvmail.ru
X-Mailer: The Bat! (v3.0.1.33) Professional
Reply-To: shocoladka@lvmail.ru
X-Priority: 3 (Normal)
Message-ID: <703957910.20090718203747@lvmail.ru>
To: XXXXX
Subject: Re: Fw: Hello dear Elena
In-Reply-T& lt;7FE2CDFE88C1468AA12197A7FA5B77C2@winxp9b62678da>
Refeeference& lt;7FE2CDFE88C1468AA12197A7FA5B77C2@winxp9b62678da>
MIMEIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - s52.avahost.net
X-AntiAbuse: Original Domain
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - lvmail.ru
X-Source:
X-Source-Args:
X-Source-Dir:
Return-Path: shocoladka@lvmail.ru
X-OriginalArrivalTime: 19 Jul 2009 01:04:29.0281 (UTC) FILETIME=[DE20ED10:01CA080C].

Thanks for your help JJ

2009-07-28, 07:01:01
Dirk from Heerlen, Netherlands  
JJ,

IP address: 75.125.251.90
Reverse DNS: s52.avahost.net.
Reverse DNS authenticity: [Verified]
ASN: 21844
ASN Name: THEPLANET-AS
IP range connectivity: 0
Registrar (per ASN): ARIN
Country (per IP registrar): US [United States]
Country Currency: USD [United States Dollars]
Country IP Range: 75.124.0.0 to 75.125.255.255
Country fraud profile: Normal
City (per outside source): Dallas, Texas
Country (per outside source): US [United States]
Private (internal) IP? No
IP address registrar: whois.arin.net
Known Proxy? No

http://www.dnsstuff..25.251.90

2009-07-28, 07:29:20
JJ from Spain  
All right, Dirk, thank you, but I already know where all those IP are coming from, I already check the 'dnsstuff'. My question is if would be possible to explain what all those X-AntiAbuse: means??, as it is the first time I've seen it on a header. Thank you a by JJ.
2009-07-28, 08:00:40   (updated: 2009-07-28, 08:07:15)
Steve_dux from Australia  
@ JJ from Spain
If I may help, even though I know you have asked OJAS, he gets very busy, as do we all!
I've been doing this for more than 1 year, and helping out here for nearly the same time.
-------------
I've just seen your main question 'X-AntiAbuse: means??' The email is being tracked. As you can see it's known to be a mail server and dictionary attacker.

I can see your confusion regarding the originating IP 3.0.1.33 United States
Many spam emails are re-routed through many servers to disguise there origin. This is what I believe has happened here. The original IP is most probably 92.255.242.56     Russian Federation (Yoshkar-ola)

WHOIS - 92.255.242.56
Location: Russian Federation (high) [City: Yoshkar-Ola, Mariy-El]
Information related to '92.255.242.0 - 92.255.243.255'
inetnum: 92.255.242.0 - 92.255.243.255
netname: ERTH-YOLA-PPPOE-1-NET
descr: ZAO 'Company 'ER-Telecom' Yoshkar-Ola
descr: Enterprise customers (PPPoE)
country: RU
source: RIPE

IP 92.255.242.56 [Spam Server] [Dictionary Attacker]
The Project Honey Pot system has detected behavior from the IP address consistent with that of a mail server and dictionary attacker.
Very defiantly the originating IP, each scammer in Russia sends up to 300 emails each day using The Bat! (v3.0.1.33) Professional, email program. Ensuring the IP is identified as a mail server through 'The Project Honey Pot'
----------------
Emails been re-routed through IP 3.0.1.33

WHOIS - 3.0.1.33
Location: United States [City: Monroe, New York]
OrgName: General Electric Company
OrgID: GENERA-9
Address: Internet Registrations
Address: 3135 Easton Turnpike
City: Fairfield
StateProv: CT
PostalCode: 06828-0001
Country: US

The Houston Texas IP is the server before it got to you, (I suppose you already know that) has no significance in your search.

One of the main things in the header is the X-Mailer: The Bat! (v3.0.1.33) Professional
Leads me to believe you have a scammer in tow.
2009-07-28, 18:49:37
Dirk from Heerlen, Netherlands  
JJ,

Sorry, seem to have misunderstood your question.

About adding the X-AntiAbuse Message in the Headers:

These days all mail servers add these headers. These help to determine who/where/when did the mail orginate, so that one can be tracked when the server is mis-used/abused.

Usually there is an emailaddress added to this message. You can report the abuse (spammail) there.

2009-07-29, 11:09:48
OJAS from United States  
JJ,
I was late to see this thread. Dirk & Steve have covered your question. I thought you were asking how scammers keep track of their ''job'' and answered you in the Osinniki thread. It is one of of the most active threads, and you can reach most delphians on that or other most active threads from the top left of this page.
2010-04-17, 08:55:27
anonymous from Russian Federation  
www.elenasmodels.com elenasmodelscom elenasmodels site scammer All scammer website..
2010-04-17, 09:02:35
anonymous from United States  
www.russian-women.net russian-women.net russian women net scammer All scammer website..
2011-12-07, 12:25:28
anonymous  
russian-women.net scammers all scammers

 

 

Are you being scammed and this is your first visit here?
Read the welcome page/ primer for newbies.
Thanks to Eddie for writing it up.

Please also read Miss Marple's article about recognizing male dating scammers.

NEW: Optional: Register   Login
Email address (not necessary):

Rate as
Hide my email when showing my comment.
Please notify me once a day about new comments on this topic.
Please provide a valid email address if you select this option, or post under a registered account.
 

Show city and country
Show country only
Hide my location
You can mark text as 'quoted' by putting [quote] .. [/quote] around it.
Please type in the code:

Please do not post inappropriate pictures. Inappropriate pictures include pictures of minors and nudity.
The owner of this web site reserves the right to delete such material.

photo Add a picture:
Picture Search

You have received photos and wonder if these photos has been posted here before? Because you suspect this could be a dating scammer, but you do not want to post this picture? Try the Picture Search