DelphiFAQ Home Search:

Dating scammer Gallina P

 

comments165 comments. Current rating: 4 stars (9 votes). Leave comments and/ or rate it.

Name: Gallina P


Email: gallinapet@yandex.ru


Address:
Gives her address as a village just out of Sumy, Ukraine
Belopolye Region
Hurinovka House 33


Other Comments:
Met her in Ukraine through UADREAMS agency. Writes about having a future together and will travel to meet with me. After I returned home she sent an email reminding me that she needed money for English lessons. After sending her some, she didn't reply. Wrote to her at the agency and she denies asking for money (against agency policy), and states there is no future now as I am not as she imagined!
Her full name Gallina Petrenko


Comments:

You are on page 10 of 11, other pages: 1 2 3 7 8 9 [10] 11
2009-08-07, 21:24:16
OJAS from United States  
Vicoz,
Dirk updated me on the developments.
I request Dirk to send you my greetings and my e-mail address.
Write to both of us.
I am fuming at what they are doing to you, try restraining myself from unpleasant language here.
I'll be out a good part of tomorrow, some 200 km away, I'll follow events when I get to a computer.

... See Y'all ...
2009-08-07, 23:33:04   (updated: 2009-08-07, 23:34:27)
Vicoz from Australia  
Hi Dirk
Thanks for your ideas! I just wrote a curt letter to UADREAMS about the abuse of privacy and confidentiality by them exposing and even adding further personal details about me, on the internet, through Gallinas file...!!!
And that they are the ONLY ones with those particular details about ME!!!

I've asked that they facilitate your idea of a new profile for me, because ALL my details and letter translation credits etc would need to be transferred!!!!!
Also informed them that 'agencies' as well as FBI have been notified of their behavior!!!
Its not a check mate move...BUT, at least I've got them in check position also...
Making up the rules to this chess game as we go along...LOL...

OJAS...Thanks for the comments mate...Look forward to hearing from you.....Enjoy the weekend!
Cheers
2009-08-08, 19:24:58
Dirk from Heerlen, Netherlands  



Keywords:
2009-08-09, 10:01:28
DOC from United States  
Hey OJAS,

I tried to write Lydia at the addy you posted and I received a failure notice, that it could not be sent.
2009-08-09, 12:53:28
OJAS from United States  
Hi Vocoz, RE: DOC's post
Is ''her'' email correct from? http://www.delphifa..=8#163529

I'll EM you later ...
2009-08-09, 17:46:08
OJAS from United States  
2009-08-09, 22:10:35   (updated: 2009-08-09, 22:44:06)
OJAS from United States  
UADreams Agency Thread http://www.delphifa..332.shtml

Dirk recently wrote about Forged IPs. Proxy, Socks, GPRS - see #3 http://www.delphifa..?p=3#58164
2009-08-10, 20:41:40   (updated: 2009-08-10, 21:25:41)
Vicoz from Australia  
Hi OJAS and DOC
The 'lady' sent me these 2 email addys

1st.....lydochka.bel_2009@yahoo.com<lydochka.bel_2009@yahoo.com>;

On the second one.....shokoladka.bel_2009@yahoo.com; she wrote

Hi!
> My name is Lydia. how are you? I hope you are fine!
> I'm sorry, I have forgotten the password to mine old email.
> And if all of you are still interested then drop me a line
> when you have time at shokoladka.bel_2009@yahoo.com

Maybe she forgot her password again?????...LOL...

This is IP header.....minus my email addy...


X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0xO0Q9MTtTQ0w9Mw==
X-Message-Status: n:0
X-SID-PRA: shokoladka.bel_2009@yahoo.com
X-Message-InfJGTYoYF78jGt8y0Y/ 651RTDYfRJ7keYaepP0WQ/lMuZL7G6TdpJjBtYPCsaS/aS/iJIqLP9ZNWMJsbfcf0YE9x4pK038JUmwLWY
Received: from smtpout2.provider.nl ([212.79.231.251]) by SNT0-MC4-F8.Snt0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
    Wed, 29 Jul 2009 09:52:35 -0700
Received: from localhost (smtpout2.provider.nl [127.0.0.1])
    by smtpout2.provider.nl (Postfix) with ESMTP id 097996EBFA7
    for <xxxxxxxxxxx.com>; Wed, 29 Jul 2009 18:52:32 +0200 (CEST)
X-Virus-Scanned: amavisd-new at provider.nl
X-Amavis-Alert: BAD HEADER, MIME error: error: part did not end with expected
    boundary
Received: from smtpout2.provider.nl ([127.0.0.1])
    by localhost (smtpout.provider.nl [127.0.0.1]) (amavisd-new, port 10024)
    with LMTP id bsIk7+bKmV4E for <xxxxxxxxxxxxl.com>;
    Wed, 29 Jul 2009 18:52:31 +0200 (CEST)
Received: from ws34.provider.nl (unknown [212.79.231.41])
    by smtpout2.provider.nl (Postfix) with ESMTP id F049F3B0303
    for <xxxxxxxxxxxx.com>; Wed, 29 Jul 2009 18:46:19 +0200 (CEST)
Received: by ws34.provider.nl (Postfix, from userid 19317)
    id E4243503AA; Wed, 29 Jul 2009 18:47:04 +0200 (CEST)
To: xxxxxxxxxxxxxxxxx
Subject: Hello again.
From: <shokoladka.bel_2009@yahoo.com>
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: PHP/5.2.6
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary='1248886024SPB'
Message-Id: <20090729164704.E4243503AA@ws34.provider.nl>
Date: Wed, 29 Jul 2009 18:47:04 +0200 (CEST)
Return-Path: user17317@www.hotelhetuilenbos.nl
X-OriginalArrivalTime: 29 Jul 2009 16:52:35.0843 (UTC) FILETIME=[F94AED30:01CA106C]


2009-08-11, 09:03:30   (updated: 2009-08-11, 09:04:07)
OJAS from United States  
In addition to scammer e-mail address, the 2 other useful fields from the header are:
1) X-Mailer
2) Sender IP. This can be extracted by pasting the header in http://ip2location...racer.aspx and hit find location.

Other encrypted fields are not useful for most of us. They can only be of use for Law Enforcement Authorities who can issue warrants
2009-08-11, 10:34:50
Dirk from Heerlen, Netherlands  
2009-08-11, 14:52:38
OJAS from United States  
2009-08-12, 13:09:21
wanwan from Japan  
@2009-08-10, 20:41:40 (updated: 2009-08-10, 21:25:41)
Vicoz from Australia

Please see here



Sender


IP Address Country Region City Latitude/
Longitude ZIP Code Time Zone
212.79.231.41 NETHERLANDS GELDERLAND DOETINCHEM 51.967
6.3 - +02:00
Net Speed ISP Domain
DSL BLIXEM INTERNETDIENSTEN PROVIDER.NL

IDD Code Area Code Weather Station
31 - (NLXX0028) ARNHEM/DIEREN





IP Address Country Region City Latitude/
Longitude ZIP Code Time Zone
212.79.231.251 NETHERLANDS GELDERLAND DOETINCHEM 51.967
6.3 - +02:00
Net Speed ISP Domain
DSL BLIXEM INTERNETDIENSTEN PROVIDER.NL

IDD Code Area Code Weather Station
31 - (NLXX0028) ARNHEM/DIEREN

Receiver



**
IP Information - 212.79.231.41IP address: 212.79.231.41
Reverse DNS: [No reverse DNS entry per dns1.vip.nl.]
Reverse DNS authenticity: [Unknown]
ASN: 24875
ASN Name: NL-ISPSERVICES (ISP Services BV)
IP range connectivity: 2
Registrar (per ASN): RIPE
Country (per IP registrar): NL [Netherlands]
Country Currency: EUR [euros]
Country IP Range: 212.79.224.0 to 212.79.255.255
Country fraud profile: Normal
City (per outside source): Unknown
Country (per outside source): -- []
Private (internal) IP? No
IP address registrar: whois.ripe.net
Known Proxy? No
Link for WHOIS: 212.79.231.41

**
http://www.trusteds...79.231.41


Keywords:
2009-08-12, 18:14:22
OJAS from United States  
What happens when Borises mess with wrong 'uns?
See this and the next article http://www.delphifa..=15#127156
2009-08-13, 07:02:31   (updated: 2012-11-18, 11:46:53)
anonymous from Australia  
Hey wan wan
Thanks for your homework!
This is what I got from IP search on our friend from earlier.....ALEX!!!
Header
X-Message-Delivery: Vj0xLjE7RD0wO2w9MQ==
X-Message-Inf+ e7wKwQ9gXULbADTJjeANuwbMNsyS0oGw2CnmLnwLWYCLYF05kEKPxND6OvJTvJTWWFxiKjTvyU4EM=
Received: from server.budgettopserver.nl ([66.7.205.123]) by col0-mc2-f16.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
    Wed, 29 Jul 2009 22:48:42 -0700
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=bigboy.nl;
  &nbsh= Received:Message-ID:From:To:References:Subject:Date:MIME-Version: Content-Type:X-Priority:X-MSMail-Priority:X-Mailer:X-MX-MimeOLE:X-Source:X-Source-Args:X-Source-Dir;
  &nbsb= Dg6OldK/deiCUdHf46xKWlMuMtwtFSku2/jsiYRtqQbYHMlpqOlSQkARcyzjJc63CwbUlHS5kY0CUFGRbPpmNqJ5zBmKfvgS/ LXid4rNrHfCEoHDZDQ7eY3eY3ONpq+nITo;
Received: from dhcp-095-096-086-156.chello.nl ([95.96.86.156] helo=alexcomputer)
    by server.budgettopserver.nl with esmtpa (Exim 4.69)
    (envelope-from <XXX@bigboy.nl>)
    id 1MWOVM-00064J-Qk
    for xxxxxxxxxxxxxx; Thu, 30 Jul 2009 07:48:17 +0200
Message-ID: <FA84978D351C4F21B263E055A33B9E66@alexcomputer>
From: 'Alex Schulein' <XXX@bigboy.nl>
To: <XXXXXXXXXXXX>
References: <06360082FC824516ADE301089F1A8F6F@alexcomputer> <BAY122-DS2B436F2A8FA25F5EC0A4D80130@phx.gbl>
Subject: Re: Gallina
Date: Thu, 30 Jul 2009 07:48:34 +0200
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary='----=_NextPart_000_00FC_01CA10EA.241443E0'
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5579
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server.budgettopserver.nl
X-AntiAbuse: Original Domain - hotmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - bigboy.nl
X-Source:
X-Source-Args:
X-Source-Dir:
Return-Path: XXX@bigboy.nl
X-OriginalArrivalTime: 30 Jul 2009 05:48:42.0958 (UTC) FILETIME=[6574C6E0:01CA10D9]
Oooooppsss! Did that include his email addy?????
http://www.ip2locat..acer.aspx
IP Address     Country     Region     City     Latitude/
Longitude     ZIP Code     Time Zone
95.96.86.156     NETHERLANDS     GELDERLAND     EDE     52.033
5.667     -     +02:00
Net Speed     ISP     Domain
DSL     UPC BROADBAND OPERATIONS B.V     CHELLO.NL
IDD Code     Area Code     Weather Station
31     -     (NLXX0028) ARNHEM/DIEREN
IP Address     Country     Region     City     Latitude/
Longitude     ZIP Code     Time Zone
66.7.205.123     UNITED STATES     FLORIDA     ORLANDO     28.548
-81.0064     32801     -04:00
Net Speed     ISP     Domain
DSL     HOSTDIME.COM INC     BLUDOMAIN7.COM
IDD Code     Area Code     Weather Station
1     407     (USFL0080) CHRISTMAS
Same location as earlier details you submitted!!!!! GELDERLAND!!!!
Hmmmm......Something smells!!!!! What you think boss???
2009-08-20, 22:52:56
OJAS from Netherlands  
G'Day, Vicoz! Just testing my location.
You are on page 10 of 11, other pages: 1 2 3 7 8 9 [10] 11

 

 

Are you being scammed and this is your first visit here?
Read the welcome page/ primer for newbies.
Thanks to Eddie for writing it up.

Please also read Miss Marple's article about recognizing male dating scammers.

NEW: Optional: Register   Login
Email address (not necessary):

Rate as
Hide my email when showing my comment.
Please notify me once a day about new comments on this topic.
Please provide a valid email address if you select this option, or post under a registered account.
 

Show city and country
Show country only
Hide my location
You can mark text as 'quoted' by putting [quote] .. [/quote] around it.
Please type in the code:

Please do not post inappropriate pictures. Inappropriate pictures include pictures of minors and nudity.
The owner of this web site reserves the right to delete such material.

photo Add a picture:
Picture Search

You have received photos and wonder if these photos has been posted here before? Because you suspect this could be a dating scammer, but you do not want to post this picture? Try the Picture Search