Thursday, June 12, 2014

Very interesting. I received a threatening email from a Graham Stevens:


 Jun 10 at 4:09 PM
If you don't pay Marijane the money you owe her I'm gonna get it out yo' ass!

You can be sure about it. Pay up if you like having all your teeth!

And when you track it, you get this:



From Graham Stevens Tue Jun 10 14:10:27 2014
X-Apparently-To: oswaldinnocent@yahoo.com via 98.137.13.231; Tue, 10 Jun 2014 21:09:28 +0000
Return-Path: <gstevens@berkshire.com>
Received-SPF: fail (domain of berkshire.com does not designate 46.167.245.71 as permitted sender)
 IG93ZSBoZXIgSSdtIGdvbm5hIGdldCBpdCBvdXQgeW8nIGFzcyEgWW91IGNh
 biBiZSBzdXJlIGFib3V0IGl0LiBQYXkgdXAgaWYgeW91IGxpa2UgaGF2aW5n
 IGFsbCB5b3VyIHRlZXRoISABMAEBAQE-
X-YMailISG: dJgd66QWLDtbUUppu2z7TeabU7M9A6ZgJUjU2H6403yRLVFF
 2NOt1F3CIRf9v4qzD7pMUY7tQA0eqlniU5AfJYn0uz2TG8CrMcs6tE0Vwt1f
 MIbDvx1JgNGHFK9XO1H3975dwbtaqQa_qvNfBhod5EpOv_f4I02m87N2QaXA
 jt4PcEKVRe6w7zrIvE_sAVCsYDCTyH9BpazlWN8GFs365Duz0ZklvRGUXr6n
 XilhTmvTdnybi1TBDykVAUrDD9vjc4kRxEiTnpufxN.JYPjRqholy2eee4G8
 J28FD4tyTyuT249Ll8fOqlGRdjh.k0Ujxjce.AQLsCkWCDizE.M5YZGm0Zo.
 RhSXhGvIyamEKNSDetuN5Kb_QY7L5tHyV8pH8ZbVzsWiGGKnPDlOe8pnWyol
 OsLo6oIRyH8.2HR3QiPEl0uU.fKiyTsicfHjaa7X6s0AjKgkenCRy18.zHXX
 FQJKLQ7jHguAmu0a3xrLysR6v4GqOYM1pQSU8O4JayE_6.zFfh3RMKDSOsMT
 0hnHy2WHVWjHciv3A5qVxiXSSVR1_sac71yI8oysOHmzZ9aURyT4ZGwrgDcT
 FgyLpjgMMFC5p9dDT8R6lLjENo6wCKIxvlm7K7JutwyUMUP.P4J1g8wTVWBF
 aQlH.PGmwgI5mA4B7RX9KwBcGGYEck5qBzE7LrLevFcXioNz4AjemMsB6deN
 bk4Ikh126Li2DlSVl547rDs12irse8jhFb4LgiOvlPyZgElhIKZ06ZklepCY
 yLgztFBciRkkd1u3SjS3RFOCO8aLxnbj0vsVIpT3.gQTNcnJ1XZRrNoEoSeR
&nbs p;EY6FqvRwTmmUZAK4KMPAqr6T8ieG6xf9IHNuKI9jiFqUdpTwgEnunIWfUw.x
 D2h2cqGcxLmIUlKYpR1jh79queYDRo6cKpd3D96RIc6rFkxg0g.By2Q534k0
 PeNzmVSrpwMdqTdavMNAn4wszmG2wbDPJBJ4fAbXvuLVby4guQWVf2gNl33L
 utAw4Dv.4gTeYW8.5EQiHQO1qjcCyCgsHZ8SV_5w9lHk7ErLQpNoAu1c6zg8
 Qp.TReXdditZMhAz9ob_H11UytNCxpvS.F93DhJWcjwvXPA8iUC2v5xYQoYn
 _MpDIANxT5IHb5yTIepye04BAW_I6VVgImx3w9vp3ur8TP.atrfaQLSaNof0
 Ng--
X-Originating-IP: [46.167.245.71]
Authentication-Results: mta1319.mail.bf1.yahoo.com  from=berkshire.com; domainkeys=neutral (no sig);  from=berkshire.com; dkim=neutral (no sig)
Received: from 127.0.0.1  (EHLO emkei.cz) (46.167.245.71)
  by mta1319.mail.bf1.yahoo.com with SMTP; Tue, 10 Jun 2014 21:09:27 +0000
Received: by emkei.cz (Postfix, from userid 33)
 id 63E4BD592D; Tue, 10 Jun 2014 23:10:27 +0200 (CEST)
To: oswaldinnocent@yahoo.com
Subject: Pay Marijane The Money!
From: "Graham Stevens" <gstevens@berkshire.com>
X-Priority: 3 (Normal)
Importance: Normal
Errors-To: gstevens@berkshire.com
Reply-To: gstevens@berkshire.com
Content-Type: text/plain; charset=utf-8
Message-Id: <20140610211027.63E4BD592D@emkei.cz>
Date: Tue, 10 Jun 2014 23:10:27 +0200 (CEST)
Content-Length: 147

So, this is a fake thing, a spoof email. He appears to be from a company called Berkshire corporation, which is a tech company in Massachusetts:

http://www.berkshire.com/


But, he's not. I have called them, and they have been VERY helpful. They put me in touch with their highest IT guy to discuss it. They assure me that there is no Graham Stevens that works for them, and not anywhere in the world. Notice that it says:

domain of berkshire.com does not designate 46.167.245.71 as permitted sender

So, that's them denying that he sent it from there. 

46.167.245.71 is the actual ISP from where it was sent.

Now, look what it says at the bottom:

Message-Id: <20140610211027.63E4BD592D@emkei.cz>

CZ? That is CZ as in Czech Republic. Whoever did this used the Czech Republic remailer. You know how Backes and bpete have repeatedly accused me of using the Czech Republic remailer? Well, I have never done so, but now I have to wonder if one or both of them mentioned it precisely because it is something that THEY do. 

Anyway, we are pursuing it, and now I am getting the police involved. I want to thank the man who helped me at Berkshire. He was a prince. I won't mention his name because it wouldn't be right to do so, knowing the people that track me. But, I am staying on this.  




No comments:

Post a Comment

Note: Only a member of this blog may post a comment.