Thank you very much, appreciate the clarity as I have been curious how a subdomain from btcrow (s2.btcrow) equates to a spoofed email/address.
Email #1) Please confirm transaction
Delivered-To: m********
c@gmail.comReceived: by 10.194.134.66 with SMTP id pi2csp246460wjb;
Sat, 7 Nov 2015 06:07:49 -0800 (PST)
X-Received: by 10.28.133.133 with SMTP id h127mr16713029wmd.41.1446905269821;
Sat, 07 Nov 2015 06:07:49 -0800 (PST)
Return-Path: <
admin@s2.btcrow.com>
Received: from s2.btcrow.com ([5.134.117.43])
by mx.google.com with ESMTPS id uz5si6579998wjc.199.2015.11.07.06.07.49
for <m********
c@gmail.com>
(version=TLSv1.2 cipher=RC4-SHA bits=128/128);
Sat, 07 Nov 2015 06:07:49 -0800 (PST)
Received-SPF: neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) client-ip=5.134.117.43;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) smtp.mailfrom=admin@s2.btcrow.com;
dkim=temperror (no key for signature) header.i=@btcrow.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=btcrow.com; s=mail;
h=Date:Message-Id:Reply-To:From:Content-type:MIME-Version:Subject:To; bh=oSgjeZxnH8emju5vkrpa969ANgF0uT2poQPs7vBqYvU=;
b=bqpdiVWIFv6bpNdUOUfP/xYsSs2m9sIyvjUA+mceu+sRYxKjtp7bHSJNBFo1N8c/ahaDeSQdPydtFGRuMpa4h4I8KbZdOgE6gKdFX/WEnX5wzqi7oG4HetqE4Ut7Yx8uDQyZAzaaBImy+AcV/ue8t3Yn8c7NeHtlJsuxShWD1/I=;
Received: from admin by s2.btcrow.com with local (Exim 4.80)
(envelope-from <
admin@s2.btcrow.com>)
id 1Zv48k-0001pc-23; Sat, 07 Nov 2015 09:06:46 -0500
To: m********
c@gmail.comSubject: Please confirm transaction #JLdhofwi4E563e05376f1e2
X-PHP-Originating-Script: 1000:functions.php
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: BTCrow.com<
noreply@btcrow.com>
Reply-To:
support@btcrow.comX-Mailer: PHP/5.4.41-0+deb7u1
Message-Id: <
E1Zv48k-0001pc-23@s2.btcrow.com>
Date: Sat, 07 Nov 2015 09:06:46 -0500
---
Email #2) Payment Received
Delivered-To: m********
c@gmail.comReceived: by 10.194.134.66 with SMTP id pi2csp1281408wjb;
Mon, 9 Nov 2015 08:31:05 -0800 (PST)
X-Received: by 10.28.16.203 with SMTP id 194mr28935765wmq.55.1447086665479;
Mon, 09 Nov 2015 08:31:05 -0800 (PST)
Return-Path: <
admin@s2.btcrow.com>
Received: from s2.btcrow.com ([5.134.117.43])
by mx.google.com with ESMTPS id u8si19143549wja.11.2015.11.09.08.31.05
for <m********
c@gmail.com>
(version=TLSv1.2 cipher=RC4-SHA bits=128/128);
Mon, 09 Nov 2015 08:31:05 -0800 (PST)
Received-SPF: neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) client-ip=5.134.117.43;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) smtp.mailfrom=admin@s2.btcrow.com;
dkim=temperror (no key for signature) header.i=@btcrow.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=btcrow.com; s=mail;
h=Date:Message-Id:Reply-To:From:Content-type:MIME-Version:Subject:To; bh=p/D8Vsdp6CJfm3ZqoUCUDqJIwKHDiYebsdLWG/5WJAs=;
b=qOmf5WNbrBrJArCmUDoxoLa4+6+G0PR0oWM2Ti4qpm54r2ACsjQqoQ4DfZL5pSd12fYlaWyvWmJyNqkRAHmrONTvvSEFxQKWM2pyFVf0vOiTQhYbh/0hYe/5Xp5EsQHVhM2Wo+uC2dUxBhhuBS3GZaxvphjIAYp+P9MoI8Hawdw=;
Received: from admin by s2.btcrow.com with local (Exim 4.80)
(envelope-from <
admin@s2.btcrow.com>)
id 1ZvpKT-0003a2-Ih; Mon, 09 Nov 2015 11:30:01 -0500
To: m********
c@gmail.comSubject: BTCrow Transaction - Payment Received
X-PHP-Originating-Script: 1000:functions.php
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: BTCrow.com<
noreply@btcrow.com>
Reply-To:
support@btcrow.comX-Mailer: PHP/5.4.41-0+deb7u1
Message-Id: <
E1ZvpKT-0003a2-Ih@s2.btcrow.com>
Date: Mon, 09 Nov 2015 11:30:01 -0500
---
Email #3) Item(s) Sent
Delivered-To: m********
c@gmail.comReceived: by 10.194.82.65 with SMTP id g1csp725947wjy;
Wed, 11 Nov 2015 05:37:47 -0800 (PST)
X-Received: by 10.194.184.7 with SMTP id eq7mr10210720wjc.26.1447249067420;
Wed, 11 Nov 2015 05:37:47 -0800 (PST)
Return-Path: <
admin@s2.btcrow.com>
Received: from s2.btcrow.com ([5.134.117.43])
by mx.google.com with ESMTPS id m134si12576512wmd.84.2015.11.11.05.37.47
for <m********
c@gmail.com>
(version=TLSv1.2 cipher=RC4-SHA bits=128/128);
Wed, 11 Nov 2015 05:37:47 -0800 (PST)
Received-SPF: neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) client-ip=5.134.117.43;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) smtp.mailfrom=admin@s2.btcrow.com;
dkim=temperror (no key for signature) header.i=@btcrow.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=btcrow.com; s=mail;
h=Date:Message-Id:Reply-To:From:Content-type:MIME-Version:Subject:To; bh=WIAaNewrELU1UVcg10meMm302ZfGK8n1waZ0XUrQyhE=;
b=soaFtkL98eZLBarsFryG+Wc8CFG8knnUMJbet2g+BoOGPxNvZzd5dlbU87nTGhHXR87Vz2VONLGJ38TPy37w0tkC3iMOXFapjiH1jf0SwRg2oBJ/RtO7ctj+9/zBQJ0Z7fKlDbKM/kVfkn+Um6mwy52krBMD29aUNoi+TYQC2lk=;
Received: from admin by s2.btcrow.com with local (Exim 4.80)
(envelope-from <
admin@s2.btcrow.com>)
id 1ZwVZq-0006YF-CO; Wed, 11 Nov 2015 08:36:42 -0500
To: m********
c@gmail.comSubject: Item(s) Sent - Transaction #JLdhofwi4E563e05376f1e2
X-PHP-Originating-Script: 1000:functions.php
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: BTCrow.com<
noreply@btcrow.com>
Reply-To:
support@btcrow.comX-Mailer: PHP/5.4.41-0+deb7u1
Message-Id: <
E1ZwVZq-0006YF-CO@s2.btcrow.com>
Date: Wed, 11 Nov 2015 08:36:42 -0500
---
Email #4) Item(s) Received
Delivered-To: m********
c@gmail.comReceived: by 10.194.82.65 with SMTP id g1csp783389wjy;
Wed, 11 Nov 2015 07:31:57 -0800 (PST)
X-Received: by 10.28.11.207 with SMTP id 198mr38691064wml.47.1447255917015;
Wed, 11 Nov 2015 07:31:57 -0800 (PST)
Return-Path: <
admin@s2.btcrow.com>
Received: from s2.btcrow.com ([5.134.117.43])
by mx.google.com with ESMTPS id cm4si12276047wjb.78.2015.11.11.07.31.56
for <m********
c@gmail.com>
(version=TLSv1.2 cipher=RC4-SHA bits=128/128);
Wed, 11 Nov 2015 07:31:56 -0800 (PST)
Received-SPF: neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) client-ip=5.134.117.43;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 5.134.117.43 is neither permitted nor denied by best guess record for domain of
admin@s2.btcrow.com) smtp.mailfrom=admin@s2.btcrow.com;
dkim=temperror (no key for signature) header.i=@btcrow.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=btcrow.com; s=mail;
h=Date:Message-Id:Reply-To:From:Content-type:MIME-Version:Subject:To; bh=fnRvQWnXwd5j2ghFrxzr48uwS3UB/PJeo11gogcEdqo=;
b=fWVMXX7YgBx610QQhR52lgJdruPJToc26ok1iAGsohIiRwsTsDjciDlbKbI0f1cylZoeOyUTipejWiwjLVK3ujca8zdHw8auTjmJHdvNZTuXzPQZEwFJF4vtUB7UisIsfL6oDVszzsqR9ytoxdTZrWQ8EgmQn5MhirERHaPzoDk=;
Received: from admin by s2.btcrow.com with local (Exim 4.80)
(envelope-from <
admin@s2.btcrow.com>)
id 1ZwXMI-0000Ik-JD; Wed, 11 Nov 2015 10:30:50 -0500
To: m********
c@gmail.comSubject: Item(s) Received - Transaction #JLdhofwi4E563e05376f1e2
X-PHP-Originating-Script: 1000:functions.php
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: BTCrow.com<
noreply@btcrow.com>
Reply-To:
support@btcrow.comX-Mailer: PHP/5.4.41-0+deb7u1
Message-Id: <
E1ZwXMI-0000Ik-JD@s2.btcrow.com>
Date: Wed, 11 Nov 2015 10:30:50 -0500
---
Email #5) Funds released
Delivered-To: m********
c@gmail.comReceived: by 10.194.82.65 with SMTP id g1csp1961217wjy;
Sun, 22 Nov 2015 22:09:47 -0800 (PST)
X-Received: by 10.68.162.193 with SMTP id yc1mr28778151pbb.148.1448258987816;
Sun, 22 Nov 2015 22:09:47 -0800 (PST)
Return-Path: <
support@btcrow.com>
Received: from a2i559.smtp2go.com (a2i559.smtp2go.com. [103.47.206.47])
by mx.google.com with ESMTPS id b69si17141613pfd.30.2015.11.22.22.09.46
for <m********
c@gmail.com>
(version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Sun, 22 Nov 2015 22:09:47 -0800 (PST)
Received-SPF: neutral (google.com: 103.47.206.47 is neither permitted nor denied by domain of
support@btcrow.com) client-ip=103.47.206.47;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 103.47.206.47 is neither permitted nor denied by domain of
support@btcrow.com) smtp.mailfrom=support@btcrow.com;
dkim=pass header.i=@smtpcorp.com
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=smtpcorp.com; s=a0-2; h=Feedback-ID:X-Smtpcorp-Track:Date:Message-ID:
Subject:From:To; bh=sOwQYQhFQoAZ5OMPxm63XNji2FH5UA9efNyQgc8d9IA=; b=jNWCKZDMp
P5o9hpzb4ITomHD7vuJvlFQY7RoWfuVG46nAKjScK8v5tTbg1BnWrHc4XgZCbF3DWtcxyBAE4DyQl
ApEecKAc41yM4tzrY/0Gx9ptjoTQ8MwAF+xGlxV5WN2F5VJhhcbx7vGsKirXnu4rxLxX76DfDZaQz
woAVLtnvUqSXy5NalOejHnuDNbewbZb+znCsf0teLIC+IbKjOHreZd6HVLQ9bt1OODkC0iTFMfQy4
0BvGET2D/cq6R6A+cyc8Sw5Cm26aoudQIc89ZuhGfDgY0sl/gFw0Jh5SyCD4uQCnRctFICxyFaB2Y
V1iYC0527223X0qC4KlXhw8kQ==;
To: m********
c@gmail.comFrom: BTCrow <
support@btcrow.com>
Subject: Funds released for btcrow.com transaction #JLdhofwi4E563e05376f1e2
[Transaction Expired]
Message-ID: <
5652AD84.3080207@btcrow.com>
Date: Mon, 23 Nov 2015 06:09:08 +0000
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
X-Smtpcorp-Track: 1a0kJq4pkR2QK5.lr2nuuP1q
Feedback-ID: 175870m:175870aw3Cd9W:175870sR_HtFR_JQ:SMTPCORP
X-Report-Abuse: Please forward a copy of this message, including all
headers, to <
abuse@smtp2go.com>