RSS

info.baginsfinancialhome@gmail.com info@infoaxe.net

07 Nov

Email Addresses: info.baginsfinancialhome@gmail.com ↔ info@infoaxe.net ↔ 

 

Subject: info.baginsfinancialhome@gmail.com is awaiting your reply

Email: The emails sent were a bunch of links and not an actual email write-up. I don’t feel comfortable posting the links for various reasons including viruses, spoofed sites, etc. But if you received an email from this same email address/IP and would like me to send you the email in private I will.

HEADER: 

Return-Path: <info@infoaxe.net>
X-YahooFilteredBulk: 174.37.119.123
Received-SPF: pass (domain of infoaxe.net designates 174.37.119.123 as permitted sender)
X-YMailISG: jQJUmUkWLDv3lGKSINkQtVhZhQt369sCh8wuUVBJNTZfubfc TQKa4ZtjzGqCNGd_LE5ReXAKY3SI7hBPmRawmtvXFmXpC9Nxltv_zdPE8upg cPW4aAxE5KA.QhqFpgt_X1BUmzx.7UoHIATKPfyX9zyMc_dY1fzAAn4aAo4c OSrbCEVk1t7PcxRAp0J6_rVGD_Y1HBiBPSKd96V8WyuslHCOHF2zwjUcQz_H h_LL3JWSZZFCwZX0NYApvV2aR4CPjLHgqzQOxtQqJNKWMN5gFPzbq.Zp8KVy 78PgrFNurHbxQyz91wzfcndds3ziHq92QHbdzBpDuSeMJD5lice8Z9wWhyi8 igezcBrSQBkXS42KiCQ6NCe7dkIrn_csbm4_o_Tkre_kouAVdWjWxfDBwbs5 1N5SEJCgHFtltmYmQGul3GsoQGVZe.3166QcyCKS9_wjk4s6E.5MvkZVjmeC jc1xnNZgohMxLiXcS3TjYL.1aQfMfOTCP7qE90Tfyt1TszLrGAkvXyBvN4Uw r8JTpFCh8pMCoDxUkSU1etAJpYdRdZRdk0gIPy7CD9fSIOSAhgLlPwqrEeX1 8qRgztoIFMooIKI.F8nUREHqpJYmQLVmcLCvuk31r00XLDAcPFqy9u809iZs KOqf9WbD0VHtw62aP9k_rMlgwGrEMKLfzygdePRWFfZJKTdFIzr2FqJWz2AM TFXU9JL7dyZsdtIftCdYjIdfq3iYGnx1hcU_th.FggCF1PSc4UD8M6dH2Z_1 xT9vg1qyupeNcvEhJGGkoKnQrB97H4wvoFsAkMkxDcNeITEesTlO7o424Nm4 YlSKcal_8M14rZnyU4LeyudhoD7M5OJ8v9t8TXBULjZYLWPB2AWBhp8U43md Tqwh6qOBfGgkRgciGsV5tXF0Z_sN4P1qb9wah12JAAD7UmtfaJ4IK_ZGlBn_ pjix0ksN0ZQEDD1KyH9tR3NqhsSKBKg.74bGsw8oNnd2StNnfaKEaRYdPDi8 MU8pf20HhudQpgNa9IS5tac0rhlVRi3itYwOKI3sRRFBc8UQdR5BV4SKSTOu YO_yMQCf2HjLpCTKNCk28B6XHKRfOcr2WmgDxsZHBJgsjfo9SInp2Cs9j1xQ 5svPMQDNpkAPt2RacatuffZk9Dh6j2HzrcxaY6JiDOZQl4NNTw2xsm2Vkw6c TgoqYdAIdjHrfIrWvxFuZlOkKe8zRQf8_wpyn0ALQyl_2nLMxU3a00Wk2ada xlVkZR84EAvZyy32Ezp_98pnEFwd5b_Yca7AmgoXkOSdinv7OMjEiIDzaZ3R r.jv.TxJdNY3yKZM2LI1kkJd2QJYmg–
X-Originating-IP: [174.37.119.123]
Authentication-Results: mta1177.mail.mud.yahoo.com from=infoaxe.net; domainkeys=pass (ok); from=infoaxe.net; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO mail11.infoaxe.net) (174.37.119.123) by mta1177.mail.mud.yahoo.com with SMTP; Wed, 07 Nov 2012 00:00:54 -0800
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=key1; d=infoaxe.net; h=Date:From:To:Subject:MIME-Version:Content-Type:Message-ID; i=info@infoaxe.net; bh=mTAVX4P4+roLJO6uXM8p4so8RVg=; b=odQtnIrzupVwVopeawrNVWDTe78j1d/Tk2+vBmK7+CJ0FpD7/zIUvolGTcBqwpFyRQeiSUbPbPjG cU4nclIYDA==
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=key1; d=infoaxe.net; b=l8fdewKZMg6cfs8/eZRfvxVTscRRNwG3rWjDeNhZNyEcKz/qaKGliSW70T/zL+3Sx27pzgYuxQf8 MVCPjloAtA==;
Received: from megan.pmta.infoaxe.com (127.0.0.1) by mail11.infoaxe.net (PowerMTA(TM) v3.5r14) id hj8ajc0sdckm for (deleted for privacy reasons) Wed, 7 Nov 2012 01:58:45 -0600 (envelope-from <info@infoaxe.net>)
Date: Wed, 7 Nov 2012 01:58:45 -0600
From:
info.baginsfinancialhome@gmail.com  <info@infoaxe.net>
To: (deleted for privacy reasons)
Subject: info.baginsfinancialhome@gmail.com is awaiting your reply
X-Reference_Id: 875250746
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary=frontier12345
Message-ID: <0.0.2F9.FB1.1CDBCBDB6544FA2.188A@mail11.infoaxe.net>
Content-Length: 5845

animated gifs lines 4

UPDATE:

Info.baginsfinancialhome continues to spam my inbox with his scam emails. S/he also goes by the name Jim Terry trying to scam vunerable hearts in a “Romance Scam.” terryjim@rocketmail.com – Reply-to: info@infoaxe.com – Received: from megan.pmta.infoaxe.com (127.0.0.1) by mail8.infoaxe.net (PowerMTA(TM) v3.5r14) id hi4nng0sdcku

Originating IP Address – 174.37.119.120

Image  

Photo used by Jim Terry also known as info.bagins – The user who posted this information had been contact by the Romance Scammer on an online dating website. It appears that this “Love Scammer” has been using the same reply-to email address (info@infoaxe.com) for the past couple years. He is also using the same fake IP’s to give off another location then the one he is actually at.

animated gifs lines 4

Frederic from UNITED STATES has reported IP 174.37.119.125 for: Online Fraud

xxx sent you a friend request on Friend Share 🙂

xxx has added you as a friend
Is xxx your friend?
Yes No
Click Yes if you are friends with xxx, otherwise click No

Please respond! 🙂

Click here to block all emails from Friend Share, 440 N.Wolfe Rd MS# 153, Sunnyvale, CA. 94085. Privacy Policy

Delivered-To: xxx
Received: by 10.52.114.35 with SMTP id jd3cs8736vdb;
Thu, 21 Jul 2011 22:26:47 -0700 (PDT)
Received: by 10.91.178.13 with SMTP id f13mr1486010agp.12.1311312407078;
Thu, 21 Jul 2011 22:26:47 -0700 (PDT)
Return-Path:
Received: from mail0.info-emailer.com (mail0.info-emailer.com [174.37.119.125])
by mx.google.com with ESMTP id p15si4287532ann.208.2011.07.21.22.26.46;
Thu, 21 Jul 2011 22:26:47 -0700 (PDT)
Received-SPF: pass (google.com: domain of info@info-emailer.com designates 174.37.119.125 as permitted sender) client-ip=174.37.119.125;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of info@info-emailer.com designates 174.37.119.125 as permitted sender) smtp.mail=info@info-emailer.com; dkim=pass header.i=info@info-emailer.com
Message-Id:
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=key1; d=info-emailer.com;
h=Date:From:To:Subject:MIME-Version:Content-type:List-Unsubscribe; i=info@info-emailer.com;
bh=p1MIAkx85kByCsvAQqw5mDUgI2I=;
b=dXRqS9mH4wg0t3ZAd9Qp2G6UKpcbkfmpIZ
pgPKhGHkqVOD8rUa06U63UDslUDfKZoJiA+RUFPsO3
/x0pxEsg5g==
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=key1; d=info-emailer.com;
b=hfee1SOo5fER+zXMTJB3KcsEAW4uevyXrN
F7V9X787EN0z9CcOL82OsCndtToA4/xFbg6vfQbYuE
zD/2X6WRkQ==;
Received: from megan.pmta.infoaxe.com (127.0.0.1) by mail0.info-emailer.com (PowerMTA(TM) v3.5r14) id h5451c0sdckh for ; Fri, 22 Jul 2011 00:26:24 -0500 (envelope-from )
Date: Fri, 22 Jul 2011 00:26:24 -0500
From: xxx
To: xxx
Subject: xxx sent you a friend request on Friend Share 🙂
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1

animated gifs lines 4

If you’ve received an email or some other type of offer from this scammer please post the information, including header information if you were emailed, in the comments so I can add it to the list. Thank you!

 

Tags: , , , , , , ,

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

 
%d bloggers like this: