But let's look at the HTML headers of their emails...
Delivered-To: **********@mail.ru
Return-path: <
[email protected]>
Authentication-Results: mxs.mail.ru; spf=pass (mx296.i.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender)
[email protected] smtp.helo=nl01.bitcoiin.com;
dkim=pass header.d=bitcoiin.com
Received-SPF: pass (mx296.i.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender) client-ip=95.211.83.98;
[email protected]; helo=nl01.bitcoiin.com;
Received: from bitcoiin.com ([95.211.83.98]:40078 helo=nl01.bitcoiin.com)
by mx296.i.mail.ru with esmtp (envelope-from <
[email protected]>)
id 1hiTN5-0000dx-RT
for **********@mail.ru; Wed, 03 Jul 2019 03:43:40 +0300
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=bitcoiin.com; s=default; h=Message-Id:In-Reply-To:To:References:Date:
Subject:Content-Type:Mime-Version:From:Sender:Reply-To:Cc:
Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:
Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id:
List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
bh=86mlxtIzvZ5SolwLoM3DMG2q8sUwph8H2t05oIJQXOo=; b=UGD+r3j2dqLf/F5gEBuy550RH
7WGtEEe2uptROqnPQyeDeBWrYOUGQbyZ7RmLgvZNZiDPqgALXGMC6rI9vqVv2JEOwtGyz5HoutW89
z92hMWYQAGRrqJ67VNEbzfxbEtaei5fOg/2Idl0xT+iW7jBih7DJ/btvL1510uU+RwnIE8s+1p/0Z
wjGgEWzwXWQyj1fGQR322xkFiROcnYOS8jM2pl/dW8P7IKmMUgzZdx39pCQ/WgZURIryQuj95v2R5
RmIAJ3uKqrc6fOcpQz5cA3aC0Csdas1HHXa9tFfr/YteqwLS6sjEfWAa+pe7DnE6Qx9CGz4HNtl89
/T2f0LRfA==;
Received:
from cable-178-149-91-89.dynamic.sbb.rs ([178.149.91.89]:54239 helo=[192.168.0.36])
by nl01.bitcoiin.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92)
(envelope-from <
[email protected]>)
id 1hiTN4-0000Os-QE
for **********@mail.ru; Wed, 03 Jul 2019 00:43:38 +0000
From: "
[email protected]" <
[email protected]>
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Content-Type: multipart/alternative;
boundary="Apple-Mail=_B2B81D06-9D76-46B6-BDB3-6F50A93197BD"
X-Priority: 3 (Normal)
Subject: Re: Sell B2G Request
Date: Wed, 3 Jul 2019 02:43:32 +0200
References: <
[email protected]>
<
[email protected]>
<
[email protected]> <
[email protected]>
To: ********** <**********@mail.ru>
In-Reply-To: <
[email protected]>
Message-Id: <
[email protected]>
X-Mailer: Apple Mail (2.3445.9.1)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - nl01.bitcoiin.com
X-AntiAbuse: Original Domain - mail.ru
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - bitcoiin.com
X-Get-Message-Sender-Via: nl01.bitcoiin.com: authenticated_id:
[email protected]X-Authenticated-Sender: nl01.bitcoiin.com:
[email protected]X-Source:
X-Source-Args:
X-Source-Dir:
X-6b629377: 1
X-77F55803: 80C231293422D957B78C6AD6BB63D6B76B090B1A966371BE7522672F2B6229460356A6FA8F69287
C428C225AB230D3AE0A58214F65DFC571
X-7FA49CB5: A9FCD207E66530D8A18204E546F3947C062BEEFFB5F8EA3ED7494F64F9BEE8B42EF20D2F80756B5
F26E476CCD9869EB15136D004FC00FE2978DA827A17800CE7A9E388873C49E63EEB66585E62EAC1
04BCA8734010DFDAB0A51C845E649FC565176DF2183F8FC7C0D5439C6F4352A194E5BFE6E7EFDED
CD7931B4319BB194E506D793A5E9D846D32176DF2183F8FC7C0D5439C6F4352A194DDF3F2959755
5B9CBCA8734010DFDAB07F16E2233F764B129ECD01F8117BC8BED8AC5874FC5B34B36355398AEDF
52F167C6FB206A91F05B2D5BFC6894CDC07A883A858D389BE03500FE69BD46C3DD557D2E47CDBA5
A96583C09775C1D3CA48CFCA5A41EBD8A3A0199FA2833FD35BB23D2EF20D2F80756B5F40A5AABA2
AD37119CC7F00164DA146DA9985D098DBDEAEC8EDCF5861DED71B2F389733CBF5DBD5E9B5C8C57E
37DE458BEDA766A37F9254B7
X-C8649E89: 4CA27E7BA95710C8A316FB494CF388F060D8E10663796DB86C5788447C27ED8D377E847AE25D1A6
0
X-DMARC-Policy: no
X-Mras: OK
X-Spam: undefined
X-Mailru-Intl-Transport: d,3ecd015
One more:
Delivered-To: **********@mail.ru
Return-path: <
[email protected]>
Authentication-Results: mxs.mail.ru; spf=pass (mx261.i.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender)
[email protected] smtp.helo=nl01.bitcoiin.com;
dkim=pass header.d=bitcoiin.com
Received-SPF: pass (mx261.i.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender) client-ip=95.211.83.98;
[email protected]; helo=nl01.bitcoiin.com;
Received: from bitcoiin.com ([95.211.83.98]:33060 helo=nl01.bitcoiin.com)
by mx261.i.mail.ru with esmtp (envelope-from <
[email protected]>)
id 1hivw3-0007Mj-2N
for **********@mail.ru; Thu, 04 Jul 2019 10:13:40 +0300
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=bitcoiin.com; s=default; h=Message-Id:In-Reply-To:To:References:Date:
Subject:Content-Type:Mime-Version:From:Sender:Reply-To:Cc:
Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date:
Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id:
List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive;
bh=GDqIrkm/TGewm86X8PrwIDDWxZ+jN53/iich2tpMYyc=; b=nhk3VOvlgXuHnc+xI31jqDTPy
NC+yJrmOQrKrU35xkF+bnw6E2uS3kssDP1lY+aVLeGQFaKNVysqworeiO/gQNsy4sKxI7rP+l8lZN
1G76xRNaDQY2ox8s+oi4V3BiAC9EWHqPCZiQE3LM9HO1TGPa5KzPBiyQcdc26ZsMxfiQuKLNbwfqB
pI4Xy6K+bOA+jUU0b70ZzZHMS2C6T0ZAm/oPoLZzJEzCMRPUnLKxvF/NG9Mm9i8mrkFAnkZbmv4kR
obNalmUeXGyfVHQgKlkhH2YRQXNCkMqstnTRoNStE1uqxtm5rx4ALDsMm2LQJMivhUTcHdvfpOW9n
GEyOuBEGQ==;
Received:
from 109-121-34-178.adsl-a-7.sezampro.rs ([109.121.34.178]:27284 helo=[192.168.1.138])
by nl01.bitcoiin.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92)
(envelope-from <
[email protected]>)
id 1hivw2-00041A-3q
for **********@mail.ru; Thu, 04 Jul 2019 07:13:38 +0000
From: "
[email protected]" <
[email protected]>
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Content-Type: multipart/alternative;
boundary="Apple-Mail=_025C94E0-DB7D-4911-A6A4-51DE39038193"
X-Priority: 3 (Normal)
Subject: Re: Buy 5500 B2G Request
Date: Thu, 4 Jul 2019 09:13:30 +0200
References: <
[email protected]>
<
[email protected]> <
[email protected]>
<
[email protected]>
To: ********** <**********@mail.ru>
In-Reply-To: <
[email protected]>
Message-Id: <
[email protected]>
X-Mailer: Apple Mail (2.3445.9.1)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - nl01.bitcoiin.com
X-AntiAbuse: Original Domain - mail.ru
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - bitcoiin.com
X-Get-Message-Sender-Via: nl01.bitcoiin.com: authenticated_id:
[email protected]X-Authenticated-Sender: nl01.bitcoiin.com:
[email protected]X-Source:
X-Source-Args:
X-Source-Dir:
X-6b629377: 1
X-77F55803: 4D3AB0539A1201CBB0AE8E75B15F0883D065BFE6A7F09A9CF23BA31E05FD368D7091C4A45136CA5
47D7EC723A61A4E182BCAD24D4AAAD5A4
X-7FA49CB5: A9FCD207E66530D8A18204E546F3947CA9FF340AA05FB58CD7494F64F9BEE8B42EF20D2F80756B5
F26E476CCD9869EB15136D004FC00FE2978DA827A17800CE73182983DFD197401EB66585E62EAC1
04BCA8734010DFDAB0A51C845E649FC565176DF2183F8FC7C0D4F009622155AD9BE5BFE6E7EFDED
CD7931B4319BB194E506D793A5E9D846D32176DF2183F8FC7C0D4F009622155AD9BDDF3F2959755
5B9CBCA8734010DFDAB07F16E2233F764B129ECD01F8117BC8BED8AC5874FC5B34B36355398AEDF
52F167C6FB206A91F05B28BD786B124D9614FCBA2434E9ED8D9CACCD65611471A2689D2E47CDBA5
A96583C09775C1D3CA48CFCA5A41EBD8A3A0199FA2833FD35BB23D2EF20D2F80756B5F40A5AABA2
AD37119CC7F00164DA146DA9985D098DBDEAEC8EDCF5861DED71B2F389733CBF5DBD5E9B5C8C57E
37DE458BEDA766A37F9254B7
X-C8649E89: 6D4C3681E26999CBEFC79DE54434AEA6CF9CEB15F6DCED5F82A85D230F08A4330F712A502AB7DD9
8
X-DMARC-Policy: no
X-Mras: OK
X-Spam: undefined
X-Mailru-Intl-Transport: d,3ecd015
And more:
Delivered-To: **********@mail.ru
Return-path: <
[email protected]>
Authentication-Results: mxs.mail.ru; spf=pass (mx122.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender)
[email protected] smtp.helo=nl01.bitcoiin.com;
dkim=pass header.d=bitcoiin.com
Received-SPF: pass (mx122.mail.ru: domain of bitcoiin.com designates 95.211.83.98 as permitted sender) client-ip=95.211.83.98;
[email protected]; helo=nl01.bitcoiin.com;
Received: from bitcoiin.com ([95.211.83.98]:54684 helo=nl01.bitcoiin.com)
by mx122.mail.ru with esmtp (envelope-from <
[email protected]>)
id 1hfpod-0004oh-Jl
for **********@mail.ru; Tue, 25 Jun 2019 21:05:12 +0300
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=bitcoiin.com; s=default; h=Message-Id:Subject:Date:Mime-Version:
Content-Transfer-Encoding:Content-Type:From:Sender:Reply-To:To:Cc:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=vOv534chZMphQSCfoxpneVzEbfhPeITz0Qj4DUv9pzY=; b=NuKSqcHbbM1sqOZxuT5QkaVhKi
JggRbQltBA/58LQQ53gAlnbEWRtpp0QAzzxg7Rebd8ma4N+v3oqeubdY9h6cXi0EM2AC+iNGkFRWg
dN9LZCtl8992aDuwkzCPraC/FJDfwUhjK5dchvwvt+VlevG1NtrMPAfQ9Mv9U1e9wNBEmInwEvEJ+
XISV31PmTOm4Oqb+2b8GPiHK52FZ7tPnheAQNENGMXvLCQktp+KDSyQcAyDtINJzo+OV90rmkC3tw
xqgu+tQD2uXedfeZn3UrKT/vhH44ysz/CPDeCfzEj/ViNvsLKWICowM76XAbNpXiR0wKb4Uvb7STV
TkLcXGTA==;
Received:
from [5.154.225.68] (port=50039 helo=[192.168.0.111])
by nl01.bitcoiin.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92)
(envelope-from <
[email protected]>)
id 1hfpoc-0002Ik-EJ; Tue, 25 Jun 2019 18:05:10 +0000
From: "
[email protected]" <
[email protected]>
Content-Type: text/plain;
charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Date: Tue, 25 Jun 2019 20:05:09 +0200
Subject: Sell B2G Request
Message-Id: <
[email protected]>
X-Mailer: Apple Mail (2.3445.9.1)
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - nl01.bitcoiin.com
X-AntiAbuse: Original Domain - mail.ru
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - bitcoiin.com
X-Get-Message-Sender-Via: nl01.bitcoiin.com: authenticated_id:
[email protected]X-Authenticated-Sender: nl01.bitcoiin.com:
[email protected]X-Source:
X-Source-Args:
X-Source-Dir:
X-6b629377: 1
X-77F55803: 994C29EBD3C2FC60E499054761329B87D065BFE6A7F09A9C9DD96AB0D988AA1F3EB6BD7ECA8FBC0
80B2CF846CA561BE874E9B7A53337CF1C
X-7FA49CB5: A9FCD207E66530D8A18204E546F3947C7B0E78B2725B8D9B71492C2D3FF63AF6CF19DD082D7633A
0BCA8734010DFDAB01AFB272A8C5F347F1661749BA6B977355A5EFD72B4E40FFBC4224003CC8364
76931B4319BB194E50A41EE2E6171AB04ED76C6ED7039589DECEA83A4A5FB14F47BD9CCCA9EDD06
7B1CDD34CA90953D341FBDF0DBDBD1550B2902A1BE408319B29FBA10D04E2D63E2B27931FC8D669
BD5AF91F25E82C306A6BEA1F7E6F0F101C67C09775C1D3CA48CFFB494AA1E7657E56C2A783ECEC0
211AD4AD6D5ED66289B524E70A05D1297E1BBAC83A81C8FD4AD239742502CCDD46D0D757A4B471A
37DB43AC83A81C8FD4AD23D82A6BABE6F325ACE7DDDDC251EA7DAB7F16E2233F764B121E561CDFB
CA1751FB289B51CCB092ABD5571747095F342E8C234C8B12C006B7A60B078E02766722436092A97
8EDD6CB4DDB2FF861F5E16A1389733CBF5DBD5E913377AFFFEAFD269176DF2183F8FC7C0A3E989B
1926288338941B15DA834481FCF19DD082D7633A0E7DDDDC251EA7DABA471835C12D1D977725E5C
173C3A84C3E478A468B35FE767117882F4460429728AD0CFFFB425014EA5CC5B56E945C8DA
X-C8649E89: 7FE539F617C11E763372FB3E5CA8737B6195DDD023695A981323F7F643060BC375071A7E56FC7CF
D
X-DMARC-Policy: no
X-Mras: OK
X-Spam: undefined
X-Mailru-Intl-Transport: d,3ecd015
Now we know that those emails were send from
Serbia