I got the same email, and the return email address was spoofed to appear that it came from me. The header says that the email actually came from
[email protected], but the originating domain appears to be from Saudi Arabia.
Here is the full header:
rom: - Thu Dec 1 17:06:06 2011
X-Account-Key: account2
X-UIDL: 0001b78b46499acd
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:
Return-path: <
[email protected]>
Envelope-to:
[email protected]
Delivery-date: Thu, 01 Dec 2011 12:57:53 -0500
Received: from [86.60.35.44] by www554.xxx.com with esmtp (Exim 4.72) (envelope-from <
[email protected]>) id 1RWAtG-00053u-06 for
[email protected]; Thu, 01 Dec 2011 12:57:52 -0500
Received: from 86.60.35.44(helo=yeccfmnhit.uotiej.biz) by with esmtpa (Exim 4.69) (envelope-from ) id 1MMAUD-9697av-0Q for
[email protected]; Thu, 1 Dec 2011 20:57:49 +0300
From: <
[email protected]>
To: <
[email protected]>
Subject: Tiered of been passed over for that promotion because you don't have the proper Degree?
Date: Thu, 1 Dec 2011 20:57:49 +0300
MIME-Version: 1.0
Content-Type: text/plain; charset="windows-1250"
Content-Transfer-Encoding: 7bit
X-Mailer: fckkwbxqlc.10
Message-ID: <
[email protected]>
-----------------END HEADER---------------
The originating IP address according to the header is 86.60.35.44
RIPE.NET whois says this belongs to:
Whois has started…
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Note: this output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '86.60.32.0 - 86.60.47.255'
inetnum: 86.60.32.0 - 86.60.47.255
netname: Awalnet_ADSL_PrePaid-01
descr: ADSL Allocation for Jeddah
country: SA
admin-c: shaz110-ripe
tech-c: shaz110-ripe
status: ASSIGNED PA
mnt-by: AAA28-RIPE-MNT
mnt-lower: AAA28-RIPE-MNT
mnt-routes: AAA28-RIPE-MNT
source: RIPE # Filtered
person: Shahzad Akhter
address: P.o.box-50
address: Riyadh-11372 SA
phone: +966 1 4600111
fax-no: + 966 1 4601110
nic-hdl: SHAZ110-RIPE
abuse-mailbox:
[email protected]
source: RIPE # Filtered
% Information related to '86.60.0.0/17AS25233'
route: 86.60.0.0/17
descr: Awalnet
origin: AS25233
mnt-by: AAA28-RIPE-MNT
source: RIPE # Filtered
% Information related to '86.60.35.0/24AS25233'
route: 86.60.35.0/24
descr: Awalnet
origin: AS25233
mnt-by: AAA28-RIPE-MNT
source: RIPE # Filtered