and/or bank account information. had not sent these
e-mail messages to their customers. The company contacted the FBI New
Haven field office for investigative assistance, and at the FBI’s request, it
provided a copy of several e-mails received by its customers, along with
its Web server logs. Figure 6-1 shows the text of an e-mail message
received by a customer. Figure 6-2 shows the e-mail header information.
FBI Analysis
The e-mail header information shown in Figure 6-2 provided some impor-
tant information (see Appendix A). Although the message appeared to be
sent from—the victim company’s legitimate e-mail
Dear Mr. or Mrs. D,
We apologize for any inconvenience this may cause you, but our system has
flagged your order most likely due to an unauthorized credit card transaction.
Ordernum: WEB11369
Exp: 09/02
In order for your items to be shipped we first need some verification. For our
safety and security, BoatingCT requires that you respond back with your card’s
verification number, if one is available. The verification number is a 3-digit
number printed on the back of your card. It appears after and to the right of
your card number.
The second method is bank account verification in case fraudulent credit card
information was provided. We require the routing number, which is located at
the bottom of your check in between the |: and |: symbols, as well as the
account number which comes before the ||’ symbols. Exact location and
number of digits varies between banks.
All information is private and confidential. Again, we apologize for any
inconvenience and hope you continue to shop with us in the future.
Text of e-mail message sent to customer.
Source: Special Agent/CART field examiner, FBI New Haven Field Office, January
21, 2005.
address—the Reply-To address ( was not the same.
This indicated that the individual sending the e-mail confirmations to the
company’s customers was using a Hotmail account to obtain additional
financial data from those customers. In addition, the presence of
hosting4u.netin the Received headers indicated that the e-mail had passed
through a Web hosting site. The CART field examiner used the ARIN site
( to determine that the owner of the IP
addresses for was CommuniTechnet. The system adminis-
trator of CommuniTechnet was interviewed. During the interview, it was
disclosed that CommuniTechnet hosted a site called, an e-mail
spoofing site that could be used to hide an e-mail sender’s identity.
Received: from ([])
by with SMTP (Microsoft Exchange
Internet Mail Service
Version 5.5.2650.21)
id JAYAG6ZX; Tue, 24 Apr 2001 03:04:45 -0500
Received: from ([])
by (Post.Office MTA v3.5.3 release 223
ID# 0-52801U100L2S100V35) with SMTP id com for
Tue, 24 Apr 2001 03:16:06 -0500
Received: (qmail 8371 invoked from network); 24 Apr 2001 08:00:26 -0000
Received: from (
by with SMTP; 24 Apr 2001 08:00:26 -0000
Subject: Order Verification
E-mail header.
A court order was issued to, requiring them to pre-
serve the subscriber information, billing information, logs, and e-mail
related to The information provided by Hot-
mail showed that the e-mail address had been
registered to an individual named Jason Smith from Los Angeles, Cali-
fornia, using IP address (Figure 6-3). Searching the
APNIC WHOIS database (, the CART field exam-
iner found that the owner of this IP address was BORANet, an Internet
leased-line service located in Seoul, Korea. Hotmail’s records showed
that the address had been set up from a com-
puter in Seoul, and the account also had been checked from a computer
in Seoul. The FBI New Haven field office contacted the Legat (FBI for-
eign liaison office) in Seoul, Korea, to obtain BORANet’s Web logs.
Meanwhile, the CART field examiner began to search the web logs
from for entries with specific reference to BORANet or
its IP address. Figure 6-4 shows one of those entries, which contains the
First Name: Jason
Last Name: Smith
State: California
Zip: 90210
Country: US
Timezone: America/Los_Angeles
Registered from IP:
Date registered: Mon Apr 23 20:54:21 2001
Reply To Address: Not available
Init Locale: EN_US
Information from regarding the account.
