Welcome to HBH! If you have tried to register and didn't get a verification email, please using the following link to resend the verification email.

Hunt down email scam?


ghost's Avatar
0 0

Hi, I got my first scam email on my new yahoo account today :p

something about getting 5 million british pounds silver. The ip of the sender is 66.75.162.133

I pinged it, it's up. I have nmap, but I just got it the other day. What should I do to get more info on this person/machine?

I'm tired of stupid people falling victim to id/$$ scams, maybe there's a way to get back at the sender?

It was forwarded several times, so I'm not sure this is the ip, but it's under thunderbird's "x-originating ip:" tag, so it must be it, right?

So how do I use nmap to get a list of open ports?

<!– yes, I'm kinda nooby at this kind of stuff, just started really getting into hacking recently, any help great. –>


ghost's Avatar
0 0

well if it's been forwarded several times, you have the ip of the mailserver of the person who sent it to you, not the ip of the person who came up with the scam in the first place. that ip happens to be a roadrunner mailserver (see this site), I'd suggest not trying to get into that, it's not what you're looking for. you can't get the ip of the person who came up with the scam from that email.


ghost's Avatar
0 0

dont try to get the ip of the sender, most likely it was a virus sending the mail, or using a proxy/botnet. just ignore them theres nt much you can do :/


ghost's Avatar
0 0

mr noob wrote: dont try to get the ip of the sender, most likely it was a virus sending the mail, or using a proxy/botnet. just ignore them theres nt much you can do :/

Qft. NBC did a story, how to catch a scam artist or w/e, and they weren't able to track anything via the internet, they had to fly to south africa where a lot of this originates from and confront them face to face.


ghost's Avatar
0 0

lol alright, i was just kinda bored… =p

but can anyone give me any tips on using nmap? i want to use it for individual comps, like port scanning, etc. before I delve into the manual, anyone got any suggestions on how to use it/ what options to use? It always quits and says "the host appears to be down…" even if i successfully ping it… what's up?


ghost's Avatar
0 0

i have the same problem :S just get BluesPortScanner, thats what i use and its really reliable ^^


ghost's Avatar
0 0

try nmap -P0 (dont ping) -v (more info) -sS(syn stealthier scan) -sV(banner grabbing tells you which services are running) -O(guess the operating system) targetIp


ghost's Avatar
0 0

@thorsdegree dont try anything with scammers. the chances are they are smarter than you and you will be the one in trouble.