Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Below is a 90%+ email header, of a hack attempt sent to an outlook email address - only 1 recipient's email address has been included, as she's known for her attempted hacks of Windows PCs. I believe the user has created an account in the name of The Lantern Project, in order to dupe the unwary. I also have a screenshot of the email
- Immediately below is WhatsMyIP's analysis of the email header, then the rest of the header content:
- The email source IP address is: 186.124.198.60
- The email source IP host name is: host60.186-124-198.telecom.net.ar.
- Email Source IP Lookup Info
- Country: Argentina
- City: Tucuman
- Area Code: -
- Latitude: -26.8083
- Longitude: -65.2333
- ISP: Telecom Argentina S.A.
- Organization: Telecom Argentina S.A.
- x-store-info:fHNTDlzCF8Nxw6HwcfGQy+S7Ax/lqLSmNphQ3OF+T9E=
- smtp.mailfrom=TheLanternProject@turista31.com; dkim=none header.d=turista31.com; x-hmca=none header.id=TheLanternProject@turista31.com
- X-SID-PRA: TheLanternProject@turista31.com
- X-AUTH-Result: NONE
- X-SID-Result: NONE
- X-Message-Status: n:n
- X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MjtHRD0yO1NDTD00
- X-Message-Info: 11chDOWqoTnp2jWDXFtGMLArnPVh5jbNZoMOV99bX9twF1FYNSn2qHgUPIrQTgGj2e6hO63Qb7VBbTnmaUuZtNT8f3ZGkxkFmegWwDfFvuaMJlaVG1Qr09cL2xvJp5l3DAm8UXOANIPDDoCE2FHOyjV8Ug23X4U6erBTCzMrMG3xxiaEeOWnwgIZNF0yFzhcxB0Mx+f67rZrvj9ZEuTKM/BbBSJx8X/9zqZXArU144Y=
- Received: from fnsib-smtp05.srv.cat ([46.16.61.56]) by BAY004-MC5F35.hotmail.com with Microsoft SMTPSVC(7.5.7601.23008);
- Mon, 3 Aug 2015 08:23:32 -0700
- Received: from smtp.turista31.com (host60.186-124-198.telecom.net.ar [186.124.198.60])
- by fnsib-smtp05.srv.cat (Postfix) with ESMTPA id AD34C1EF156;
- Mon, 3 Aug 2015 17:23:17 +0200 (CEST)
- Subject: from: The Lantern Project
- From: The Lantern Project <TheLanternProject@turista31.com>
- Content-Type: multipart/alternative;
- boundary=Apple-Mail-AFD0BE80-5F25-809F-311D-318988E5CF06
- X-Mailer: iPhone Mail (12D508)
- Message-Id: <f92506c13379$763a465c$224fd8d1$@turista31.com>
- Date: Sun, 3 Aug 2015 04:23:17 +0000
- "J Scharenborg" <janettescharenborg@gmail.com
- Content-Transfer-Encoding: 7bit
- Mime-Version: 1.0 (1.0)
- Return-Path: TheLanternProject@turista31.com
- X-OriginalArrivalTime: 03 Aug 2015 15:23:33.0355 (UTC) FILETIME=[5C0EF3B0:01D0CE00]
- --Apple-Mail-AFD0BE80-5F25-809F-311D-318988E5CF06
- Content-Type: text/plain;
- charset=us-ascii
- Content-Transfer-Encoding: 7bit
- http://AGRIBUSINESSDEVELOPMENT.com/case.php?The_Lantern_Project
- The Lantern Project
- Sent from my iPhone
- --Apple-Mail-AFD0BE80-5F25-809F-311D-318988E5CF06
- Content-Type: text/html;
- charset=utf-8
- Content-Transfer-Encoding: 7bit
- <html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto"><div><i><br><a href="http://AGRIBUSINESSDEVELOPMENT.com/case.php?The_Lantern_Project">http://AGRIBUSINESSDEVELOPMENT.com/case.php?The_Lantern_Project</a></i></div><div><i><br></i></div><div><i>The Lantern Project<br>Sent from my iPhone</i></div></body></html>
- --Apple-Mail-AFD0BE80-5F25-809F-311D-318988E5CF06--
Add Comment
Please, Sign In to add comment