This is the most aggressive scam i received until now.
Similar to this report.
________________________________________
From: Hakeem Mohammad [Hakeem@killer.pk]
Sent: monday 1 october 2012 16:55
To: Recipients
Subject: Reply Me Immediately
To your attention
I want you to read this message very carefully and that you keep the secret until further notice. You do not need to know or who I am or where I come from. I was paid an advance of $50,000 to eliminate you. My sponsors one of which is what we can call a friend gave me the reasons I noted. I am more than ten days and now I know that you are innocent of what you are accused. Do not try to warn or send this message to the FBI or the police because I know that I'll have to do the job for which I was paid. Note that this is the first time that I betrayed my employer.
Look, I'll do everything I can so that we can meet before but I need $20,000. You have nothing to afraid of me, I can come see you in your office or home, it is up to you to decide. Never attempt recording or filming our upcoming meeting. It will pay $20,000 to the account I will tell you, this before our first meeting. Once payment is made, I will give you the file that contains the names and queries sponsors. This is a good evidence that can be used to sue if you wish. The balance of the payment will be settled later. For the moment this is not the trouble I give you my phone number because you will cooperate. I have your picture and other important information about you. I was involved with my team in the Yemen
Arab Republic. You must not ask me any questions.
Quickly confirm for your good.
2 October 2012
Spam assasin
Subscribe to:
Post Comments (Atom)
Where did the header information say the email originated?
ReplyDelete> Here it is, commented out our receiving server
ReplyDeleteReceived: from mail.cusat.ac.in (210.212.233.38) by mail.xx.xx
(192.168.3.236) with Microsoft SMTP Server id 8.2.255.0; Mon, 1 Oct 2012
21:55:03 +0200
Received: from localhost (localhost.localdomain [127.0.0.1]) by
mail.cusat.ac.in (Postfix) with ESMTP id C251DCA2557; Mon, 1 Oct 2012
20:22:29 +0530 (IST)
X-Virus-Scanned: amavisd-new at cusat.ac.in
Received: from mail.cusat.ac.in ([127.0.0.1]) by localhost (mail.cusat.ac.in
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P1TLkMed9ogu; Mon, 1
Oct 2012 20:22:29 +0530 (IST)
Received: from [41.138.172.12] (unknown [41.138.172.12]) by mail.cusat.ac.in
(Postfix) with ESMTPSA id 0159ECA2355; Mon, 1 Oct 2012 20:21:37 +0530 (IST)
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Subject: Reply Me Immediately
To: Recipients
From: Hakeem Mohammad
Date: Mon, 1 Oct 2012 08:55:40 -0600
Reply-To: hmohammadkill@yahoo.com
X-Antivirus: avast! (VPS 121001-0, 10/01/2012), Outbound message
X-Antivirus-Status: Clean
Message-ID: <20121001145140.0159ECA2355@mail.cusat.ac.in>
Return-Path: Hakeem@killer.pk
X-MS-Exchange-Organization-PRD: killer.pk
Received-SPF: Fail (mail2.xx.xx: domain of Hakeem@killer.pk does not
designate 210.212.233.38 as permitted sender) receiver=mail2.xx.xx;
client-ip=210.212.233.38; helo=mail.cusat.ac.in;
X-MS-Exchange-Organization-PCL: 2
X-MS-Exchange-Organization-Antispam-Report: DV:3.3.11801.452;SV:3.3.9010.377;SID:SenderIDStatus
Fail;TIME:TimeBasedFeatures;OrigIP:210.212.233.38
X-MS-Exchange-Organization-SCL: 7
X-MS-Exchange-Organization-SenderIdResult: FAIL