From: Subject: Re: Re: for you FORWARD TO Date: Sat, 27 Jun 2020 19:45:11 +0000 Importance: Normal . Highlighted please review. Below are the results from the Google Emergency Disclosure: GOOGLE SUBSCRIBER INFORMATION Alternate e-Mails: Created on: 2020-03-17 16:30:21 UTC IP ACTIVITY Timestamp 11' Address Activity Type 2020-06-27 08:11:05 UTC 92.38.169.231 Login ( New York utilizing a CDN) - Not actually in NY 2020-06-27 07:47:30 UTC 5.237.161.27 Login ( IRAN) 2020-06-27 07:46:00 UTC 5.237.161.27 Login (IRAN) 2020-06-26 20:37:41 UTC 92.38.149.56 Login (California utilizing a CDN) Uses the Same CDN 2020-06-26 08:36:26 UTC 5.211.157.79 Login (IRAN) 2020-06-26 06:43:42 UTC 5.211.73.53 Login (IRAN) New York IP address is utilizing a CDN (Content Delivery Network) Organization: G-Core Labs S.A. and Hostname : free-go-ny-11.com CON : it is a set of linked servers which accelerate giving the data (photo, video, scripts) back to the user. CDN servers are placed as close as possible to the end audience. This means the message appears to be sent to as close to the end user using one of their servers. The IRAN ip address come from his mobile network (Organization: Mobile Communication Company of Iran PLC) I feel as though the threat, again has been mitigated as the sender is located in IRAN and is attempting to mask his location through these Content Delivery Networks. EFTA00146845