SCAMS | EMAIL | PHONE | MAP | TAGS | EMAIL ANALYSIS | IP LOCATOR
Click to go to Scammed.by homepage
Forward scams to - remove your name and email address first! TO CONTACT US CLICK HERE INSTEAD


Scam email #255929 - How is your life?

Email info

The email was sent on 2019-02-04 14:30:02 and appeared to be from qjfprospectus@ssgi.com but this address could have been spoofed.
If you replied to this email, your reply would have been sent to qjfprospectus@ssgi.com which was the scammer's actual email address.
It was probably sent from 193.56.148.9 in Lviv, Ukraine

Email header

Explains what each bit of the header means, and shows the journey the email took. Click here to show or hide it

Your content is below the advert

The scam

Are you a gentleman or macho, or are you just outspoken and generous. Well I like a man who is a bit of all these and apart from it he should be reliable, responsible and straightforward. I am Kristina from Chelyabinsk, Russia and I am in search of my potential husband, lover and friend all in all. I want someone just for myself, so that he is always there for me and fills my life fully. I want to drown myself in his love and see nothing other than him. I want to fall in love madly, deeply and only once.If you share at least some of these feelings then you are a candidate for being my love. And you can meet me by joining this elite family oriented online dating website by clicking here on this link. I hope you will find me there and we will become friends. Whatever be the outcome of our friendship I am sure it will be a nice experience to both of us. Apart from me you will also meet thousands of similar beautiful girls from my country and neighborhood. My page http://kristina93.loversru.cn

SpamAssassin Report (spam score: 16.7)


 pts rule                    description                                       
---- ----------------------  --------------------------------------------------
 2.5 URIBL_DBL_SPAM          Contains a spam URL listed in the Spamhaus DBL    
                             blocklist [URIs: loversru.cn]                     
 3.5 BAYES_99                BODY: Bayes spam probability is 99 to 100% [score:
                             1.0000]                                           
 0.2 BAYES_999               BODY: Bayes spam probability is 99.9 to 100%      
                             [score: 1.0000]                                   
 0.0 TVD_RCVD_IP4            Message was received from an IPv4 address         
 0.0 TVD_RCVD_IP             Message was received from an IP address           
 0.0 HK_RANDOM_ENVFROM       Envelope sender username looks random             
 0.0 SPF_FAIL                SPF: sender does not match SPF record (fail)      
 1.2 URIBL_ABUSE_SURBL       Contains an URL listed in the ABUSE SURBL         
                             blocklist [URIs: loversru.cn]                     
 0.6 URIBL_PH_SURBL          Contains an URL listed in the PH SURBL blocklist  
                             [URIs: loversru.cn]                               
 1.3 RCVD_IN_RP_RNBL         RBL: Relay in RNBL,                               
                             https://senderscore.org/blacklistlookup/          
                             [193.56.148.9 listed in bl.score.senderscore.com] 
 0.4 RCVD_IN_XBL             RBL: Received via a relay in Spamhaus XBL         
                             [193.56.148.9 listed in zen.spamhaus.org]         
 0.0 PP_MIME_FAKE_ASCII_TEXT BODY: MIME text/plain claims to be ASCII but isn't
 1.9 RAZOR2_CF_RANGE_51_100  Razor2 gives confidence level above 50% [cf: 100] 
 0.9 RAZOR2_CHECK            Listed in Razor2 (http://razor.sf.net/)           
 0.1 URIBL_SBL_A             Contains URL's A record listed in the Spamhaus SBL
                             blocklist [URIs: kristina93.loversru.cn]          
 1.6 URIBL_SBL               Contains an URL's NS IP listed in the Spamhaus SBL
                             blocklist [URIs: kristina93.loversru.cn]          
 0.5 MISSING_MID             Missing Message-Id: header                        
 2.0 HELO_DYNAMIC_IPADDR     Relay HELO'd using suspicious hostname (IP addr 1)
 0.0 NO_FM_NAME_IP_HOSTN     No From name + hostname using IP address          



Please be careful with the links in the above email - Scammed.by strongly suggests that you do not click on any links in the above message
The email above is most likely a scam but every now and then legitimate emails do come through, as do spam emails which are not attempting to defraud, so please use your judgement
You can contact ScamSearch at help at scammed.by for any information, help, or if you have spotted a legitimate email. Please link to the email you think is legitimate.
ScamSearch does not accept any responsibility for visitors enduring any issues as a result of following links in the above email and/or contacting the sender
Please do not contact the sender unless you know what you are doing (i.e. experienced scambaiters)

Comments

Where the scam probably came from



theScamBaiter freight bait archive, theFailure Cole baits   theFAILURE freight bait from theScamBaiter - Cole v2.0   theFAILURE freight bait from theScamBaiter - Rebait at Cole's   theFAILURE freight bait from theScamBaiter - the Martins Cole saga   theFAILURE Butch Driveshaft telemarketer phone baiting   theFAILURE freight bait from theScamBaiter - Anus Laptops commercial made by scammer   theFAILURE freight bait from theScamBaiter - script of Anus Laptops commercial made by scammer