|
419 Scam – Sierra Leone diamond scam
The civil war in Sierra Leone, West Africa is often woven into storylines used by advance fee fraud ("419") scammers. Usually the person sending the spam will claim to be the widow, son or daughter of a murdered former member of government or businessman from that country, now living as a refugee in Cote d'Ivoire, Senegal, South Africa, Nigeria or Europe. He/she will seek help in retrieving a secret stash of money, diamonds or other valuables stored with a security company in another country. The scam victim is expected to pay various expenses necessary to retrieve the stash. He/she is supposed to be rewarded by a large percentage of the treasure when deal is complete. In reality the treasure does not exists and the scammers are only after those advance payments from a gullible person.
Example:
From: "SAMSON BAMOGU"
Now let's take a look how this got here: Received: from [213.154.88.78] (helo=ok6606.com) by vmx10.############## with smtp (Exim 4.43) id 1CTiE7-0000Bq-GJ; Mon, 15 Nov 2004 15:53:07 +0100 From: "SAMSON BAMOGU" <samson_bamogu01@yahoo.co.uk> Reply-To: samson_bamogu02@yahoo.co.uk Date: Tue, 16 Nov 2004 14:55:35 +0000 Subject: BUSINESS OFFER X-Mailer: Microsoft Outlook Express 5.00.2919.6900 DM MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable X-MailScanner-SpamCheck: spam, SpamAssassin (score=22.749, required 5, BAYES_99 1.89, DATE_IN_FUTURE_24_48 2.31, DEAR_SOMETHING 1.58, FORGED_MUA_OUTLOOK 3.92, FROM_HAS_ULINE_NUMS 0.06, MIME_QP_LONG_LINE 0.04, MISSING_HEADERS 0.12, MSGID_FROM_MTA_HEADER 0.05, MSGID_FROM_MTA_ID 1.72, NIGERIAN_BODY1 3.40, NIGERIAN_BODY2 0.60, RATWARE_OE_MALFORMED 2.59, RCVD_IN_SORBS_SPAM 2.00, SUBJ_ALL_CAPS 0.67, URG_BIZ 1.81) X-MailScanner-From: samson_bamogu01@yahoo.co.uk Here's the network for IP 213.154.88.78: inetnum: 213.154.70.0 - 213.154.89.255
netname: SONATEL-Rx70-Rx89
descr: SONATEL - National Telecom Company
descr: INTERNET SERVICE PROVIDER
descr: SENEGAL
country: SN
admin-c: MN1281-RIPE
admin-c: GN261-RIPE
tech-c: SBT7-RIPE
tech-c: MN1281-RIPE
tech-c: AT1281-RIPE
status: ASSIGNED PA
notify: modyndiaye@sentoo.sn
mnt-by: SMM-MNT
mnt-lower: SMM-MNT
changed: sbthiam@sonatel.sn 20041216
source: RIPE
person: Gaidy Ndaw
address: Sonatel
address: Direction des Reseaux
address: 6 Rue Wagane DIOUF
address: BP 69 Dakar
address: SENEGAL
phone: +221 822 80 63
fax-no: +221 842 30 57
nic-hdl: GN261-RIPE
e-mail: gaidy.ndaw@sentoo.sn
notify: gaidy.ndaw@sentoo.sn
changed: modyndiaye@sentoo.sn 20031006
source: RIPE
person: Mody Ndiaye
address: SOCIETE NATIONALES DES TELECOMMUNICATIONS
address: Sonatel Multimedia
address: Dakar
address: Senegal
e-mail: modyndiaye@sentoo.sn
phone: +221 869 97 15
fax-no: +221 860 01 64
nic-hdl: MN1281-RIPE
notify: modyndiaye@sentoo.sn
mnt-by: SMM-MNT
changed: modyndiaye@sentoo.sn 20030926
source: RIPE
person: Seydou Bocar THIAM
address: SOCIETE NATIONALES DES TELECOMMUNICATIONS
address: Direction des Reseaux
address: 6 Rue Wagane DIOUF
address: BP 69 Dakar
address: SENEGAL
phone: +221 839 23 39
fax-no: +221 839 22 36
e-mail: sbthiam@sentoo.sn
nic-hdl: SBT7-RIPE
notify: mouhamet@sentoo.sn
changed: modyndiaye@sentoo.sn 20031008
source: RIPE
person: Amadou Toure
address: SOCIETE NATIONALES DES TELECOMMUNICATIONS
address: Sonatel Multimedia
address: Dakar
address: Senegal
e-mail: atoure@sentoo.sn
phone: +221 869 97 10
fax-no: +221 860 01 64
nic-hdl: AT1281-RIPE
notify: modyndiaye@sentoo.sn
mnt-by: SMM-MNT
changed: modyndiaye@sentoo.sn 20030919
source: RIPE
This one was sent five weeks later. Now the spam is sent from the address previously used as a maildrop and another free email address is used as a maildrop, plus a phone number in Senegal is now listed:
From: "SAMSON BAMOGU"
|