DelphiFAQ Home Search:

Dating scammer


commentsThis article has not been rated yet. After reading, feel free to leave comments and rate it.




Other Comments:


2009-07-22, 05:52:42   (updated: 2009-07-22, 05:56:45)
JJ from Spain  
An E-Mail to OJAS, hallo, how are you?, I'm JJ from Spain, how goes the anti-scamms crusade?, I know you are an expert in headers, I post this one from an scammer 'lady' I am writing now with her, if you would be so kind to explain me about what it means, I did get any like this with that of AntiAbuse.
The IP one is from Houston Texas, the other Yoskar-Ola as usual and the other Marina del Rey CA. but the E-Mail is not google or yahoo and then the times between Spain and Calif. you go 7 hrs. in advance and we, with Yoskar-Ola, we go 2 hrs. in advance.

Received: from ([])
    Sun, 19 Jul 2009 03:04:28 +0200
Received: from [] (helo=[])
    by with esmtpa (Exim 4.69)
    (envelope-from <>)
    id 1MSD0U-0007uh-Pl
    Sat, 18 Jul 2009 11:43:31 -0500
Date: Sat, 18 Jul 2009 20:37:47 +0400
X-Mailer: The Bat! (v3.0.1.33) Professional
X-Priority: 3 (Normal)
Message-ID: <>
Subject: Re: Fw: Hello dear Elena
In-Reply-T& lt;7FE2CDFE88C1468AA12197A7FA5B77C2@winxp9b62678da>
Refeeference& lt;7FE2CDFE88C1468AA12197A7FA5B77C2@winxp9b62678da>
MIMEIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname -
X-AntiAbuse: Original Domain
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain -
X-OriginalArrivalTime: 19 Jul 2009 01:04:29.0281 (UTC) FILETIME=[DE20ED10:01CA080C].

Thanks for your help JJ

2009-07-28, 08:01:08   (updated: 2009-07-28, 08:07:41)
Steve_dux from Australia  
@ JJ from Spain
If I may help, even though I know you have asked OJAS, he gets very busy, as do we all!
I've been doing this for more than 1 year, and helping out here for nearly the same time.
I've just seen your main question 'X-AntiAbuse: means??' The email is being tracked. As you can see it's known to be a mail server and dictionary attacker.

I can see your confusion regarding the originating IP United States
Many spam emails are re-routed through many servers to disguise there origin. This is what I believe has happened here. The original IP is most probably     Russian Federation (Yoshkar-ola)

Location: Russian Federation (high) [City: Yoshkar-Ola, Mariy-El]
Information related to ' -'
inetnum: -
descr: ZAO 'Company 'ER-Telecom' Yoshkar-Ola
descr: Enterprise customers (PPPoE)
country: RU
source: RIPE

IP [Spam Server] [Dictionary Attacker]
The Project Honey Pot system has detected behavior from the IP address consistent with that of a mail server and dictionary attacker.
Very defiantly the originating IP, each scammer in Russia sends up to 300 emails each day using The Bat! (v3.0.1.33) Professional, email program. Ensuring the IP is identified as a mail server through 'The Project Honey Pot'
Emails been re-routed through IP

Location: United States [City: Monroe, New York]
OrgName: General Electric Company
Address: Internet Registrations
Address: 3135 Easton Turnpike
City: Fairfield
StateProv: CT
PostalCode: 06828-0001
Country: US

The Houston Texas IP is the server before it got to you, (I suppose you already know that) has no significance in your search.

One of the main things in the header is the X-Mailer: The Bat! (v3.0.1.33) Professional
Leads me to believe you have a scammer in tow.



Are you being scammed and this is your first visit here?
Read the welcome page/ primer for newbies.
Thanks to Eddie for writing it up.

Please also read Miss Marple's article about recognizing male dating scammers.

NEW: Optional: Register   Login
Email address (not necessary):

Rate as
Hide my email when showing my comment.
Please notify me once a day about new comments on this topic.
Please provide a valid email address if you select this option, or post under a registered account.

Show city and country
Show country only
Hide my location
You can mark text as 'quoted' by putting [quote] .. [/quote] around it.
Please type in the code:

Please do not post inappropriate pictures. Inappropriate pictures include pictures of minors and nudity.
The owner of this web site reserves the right to delete such material.

photo Add a picture:
Picture Search

You have received photos and wonder if these photos has been posted here before? Because you suspect this could be a dating scammer, but you do not want to post this picture? Try the Picture Search