LazyLion
King of de Jungle
Somebody in our offices received this e-mail...
So at first glance this looks like it was sent from one computer at our offices to another, because these are both e-mail addresses used by people at our company.
It looks like it came from the secretary's computer to the stock controller's computer.
But the secretary swears she did not send it (she brought the suspicious e-mail to me after the stock controller showed it to her).
So I looked at the secretary's gmail (she is not all that clued up about computers), and there is no record that she sent it, not in her sent items or in her trash (but I guess it could have been erased completely).
So in the headers, I noticed this IP address... 10.229.78.134
Our external IP is in the range 196.215.....
Our internal range is 10.0.....
So can anyone tell me where that IP range is located?
Thanks!
Code:
Delivered-To: d*******.s****@gmail.com
Received: by 10.152.18.75 with SMTP id u11csp36743lad;
Wed, 29 Feb 2012 22:21:40 -0800 (PST)
Return-Path: <f*****.f****@gmail.com>
Received-SPF: pass (google.com: domain of f*****.f****@gmail.com designates 10.229.78.134 as permitted sender) client-ip=10.229.78.134;
Authentication-Results: mr.google.com; spf=pass (google.com: domain of f*****.f****@gmail.com designates 10.229.78.134 as permitted sender) smtp.mail=f*****.f****@gmail.com; dkim=pass header.i=f*****.f****@gmail.com
Received: from mr.google.com ([10.229.78.134])
by 10.229.78.134 with SMTP id l6mr638676qck.55.1330582899624 (num_hops = 1);
Wed, 29 Feb 2012 22:21:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:to:content-type;
bh=sU1eUhvavTrNQjPsFit0zExQChksDgNmsSMnuRwAJT8=;
b=MYvLZcClp+nqCmQjFG6BOrZLmz37nDud44yplUKYG5QEV+MJO3GseNujXWH45y5aiJ
ITkxuL6rFn7gGK1sRo0gkd5g49jRDV+xVGauUYZF0LumAYxoD9l5GARFKwmiqzfA+QKf
IthOGBPZO8SuQClM1Cm1c3P3wG0zVd67iVSPA=
MIME-Version: 1.0
Received: by 10.229.78.134 with SMTP id l6mr638676qck.55.1330582899620; Wed,
29 Feb 2012 22:21:39 -0800 (PST)
Received: by 10.229.124.140 with HTTP; Wed, 29 Feb 2012 22:21:39 -0800 (PST)
Date: Thu, 1 Mar 2012 08:21:39 +0200
Message-ID: <CALPq_ML=aq0OZJLWtOQcYw4ER6mkLjMb+ihrTnE71Lg-Ee2xcA@mail.gmail.com>
Subject: Warning
From: F_____ F____ <f*****.f****@gmail.com>
To: D_______ S____ <d*******.s****@gmail.com>
Content-Type: multipart/alternative; boundary=00235447044c137cdb04ba287999
--00235447044c137cdb04ba287999
Content-Type: text/plain; charset=ISO-8859-1
Hi Buti,
Your days are numbered. Look out!
--00235447044c137cdb04ba287999
Content-Type: text/html; charset=ISO-8859-1
Hi Buti,<div><br></div><div>Your days are numbered. Look out!</div>
--00235447044c137cdb04ba287999--
So at first glance this looks like it was sent from one computer at our offices to another, because these are both e-mail addresses used by people at our company.
It looks like it came from the secretary's computer to the stock controller's computer.
But the secretary swears she did not send it (she brought the suspicious e-mail to me after the stock controller showed it to her).
So I looked at the secretary's gmail (she is not all that clued up about computers), and there is no record that she sent it, not in her sent items or in her trash (but I guess it could have been erased completely).
So in the headers, I noticed this IP address... 10.229.78.134
Our external IP is in the range 196.215.....
Our internal range is 10.0.....
So can anyone tell me where that IP range is located?
Thanks!