This blog post will serve as an incident report for the Armstrong State University police department’s Cyber Forensics unit, which is now part of Georgia Southern University.

The following companies will be given a link to this post:

  • PayPal, Inc.
  • Google
  • Post.cz
  • eBay

On February 17, 2018 I listed my MacBook Pro for sale on eBay. The listing can be found at the following address. I received an email from peggyhamric101@gmail.com. The IP Address of the email is 209.85.220.65 which maps to mail-sor-f65.google.com.

The email in its entirety can be read here: peggy_hamrick_email.

The seller told me to send a request for a PayPal payment and I soon received a spoofed email. The email has a spoofed reply to service@paypal.com. However the email address identified the sender as trackingdepartment@post.nz. This is a real email address (see bottom image), however it was sent from a mail server that isn’t listed as a MX record for post.nz.

I haven’t gotten to any major classes but I have done by best to summarize what I found. The fake payment email was sent from 2a02:598:a:0:0:0:78:34 which points to mxe1.sezman.ce. This server is not listed as a MX record for post.nz – the servers listed for post.nz can be seen in the emails below (mx1.sezman.ce, mx2.sezman.ce).

This email can be downloaded here: service@paypal.com.

If you need any further information, you have my contact information.

 

"service@paypal.com" headers
The email headers from the SCAM email show they spoofed the reply to service@paypal.com. They used the SPF record and the other qualifiers to ensure that their email reached the potential victim’s inbox.
Verifying that trackingdepartment@post.nz is a valid email.
trackingdepartment@post.cz is a valid email – name servers are noted in this post
Name Servers IP Addresses
The IP Addresses of the name servers listed as Post.cz MX records are in this photo. Also note the SPF record
Mail Server of Spoofed Email
This is the email server of the spoofed email. While not listed as a MX record for post.cz, it shares the domain of the two mail servers listed as MX records.

Published by burnedfaceless

Brian Abbott is a student at Georgia Southern University's Armstrong campus in Savannah, GA.

Leave a comment

Your email address will not be published. Required fields are marked *