View Single Post
  #45 (permalink)  
Old 01-23-2008, 01:03 PM
aquirata aquirata is offline
Junior Member
 
Join Date: Jan 2008
Posts: 3
Default FT West Invest - another job phishing scam

Mercenary,

Here is the header from the first letter (my personal info blocked - hope I caught them all):

Quote:
Received: from nobody by server038.webpack.hosteurope.de running ExIM using local
id 1JGyYU-0005Ge-3f; Mon, 21 Jan 2008 16:27:22 +0100
To: *****
Subject: Monster Business - Business Partnership
X-PHP-Script: www.droschker.de/CMS/html/downloads/sendme.php for 68.198.119.109
From: Monster Job Search Agent <jagent@route.monster.com>
Reply-To: hr@ftwestinvest.com
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <E1JGyYU-0005Ge-3f@server038.webpack.hosteurope.de>
Date: Mon, 21 Jan 2008 16:27:22 +0100
X-bounce-key: webpack.hosteurope.de;info@droschker.de;1200929242 ;7e78843f;
And the second letter:

Quote:
Received: from hrftinvest@aol.com
by imo-d05.mx.aol.com (mail_out_v38_r9.3.) id o.d17.1f0152e3 (37691)
for *****; Tue, 22 Jan 2008 *****
Received: from bElea (acbe6383.ipt.aol.com [172.190.99.131]) by cia-mb08.mx.aol.com (v121.4) with ESMTP id MAILCIAMB087-933b4796407df3; Tue, 22 Jan 2008 *****
Message-ID: <021701c85d2a$f4847470$8363beac@bElea>
From: "Michael McHugh" <hrftinvest@aol.com>
To: *****
References: <E1JGyYU-0005Ge-3f@server038.webpack.hosteurope.de> *****
Subject: Business Partnership
Date: Tue, 22 Jan 2008 20:57:46 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_018A_01C85D39.70965AC0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.3138
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3198
X-AOL-IP: 172.190.99.131
X-Spam-Flag: NO
So it appears he posted from Germany.

I have reported this to Monster and my mail provider. Any other boards it could be posted?


Last edited by aquirata : 01-23-2008 at 07:34 PM. Reason: removed time zone refs for receiver
Reply With Quote