**Subject:** Re: Re: for you FORWARD TO Highlighted please review. Date: Sat, 27 Jun 2020 19:45:11 +0000 Importance: Normal Below are the results from the Google Emergency Disclosure: ## GOOGLE SUBSCRIBER INFORMATION Alternate e-Mails: Created on: 2020-03-17 16:30:21 UTC ## IP ACTIVITY
TimestampIP AddressActivity Type
2020-06-27 08:11:05 UTC92.38.169.231Login(New York utilizing a CDN)-Not actually in NY
2020-06-27 07:47:30 UTC5.237.161.27Login(IRAN)
2020-06-27 07:46:00 UTC5.237.161.27Login(IRAN)
2020-06-26 20:37:41 UTC92.38.149.56Login(California utilizing a CDN)Uses the Same CDN
2020-06-26 08:36:26 UTC5.211.157.79Login(IRAN)
2020-06-26 06:43:42 UTC5.211.73.53Login(IRAN)
New York IP address is utilizing a CDN (Content Delivery Network) Organization: G-Core Labs S.A. and Hostname : free-gc-ny-11.com CDN : it is a set of linked servers which accelerate giving the data (photo, video, scripts) back to the user. CDN servers are placed as close as possible to the end audience. This means the message appears to be sent to as close to the end user using one of their servers. The IRAN ip address come from his mobile network (Organization: Mobile Communication Company of Iran PLC) I feel as though the threat, again has been mitigated as the sender is located in IRAN and is attempting to mask his location through these Content Delivery Networks. EFTA00146845 And with the time being past 3pm the timeline for the threats has come and gone without any incidents. (Threat was posted at 0647 hours with a deadline of 8 hours which equals 1447 hours). No further investigation deemed necessary. **Sent:** Saturday, June 27, 2020 12:25 PM Subject: Re: Re: for you FORWARD TO . Highlighted please review. Submitted Emergency Disclosure Request on and also informed that precinct that covers to be aware of the situation. **Sent:** Saturday, June 27, 2020 9:29 AM Subject: Fwd: Re: for you FORWARD TO . Highlighted please review. This is the latest email. I have done 2 emergency disclosure requests to google on this email account and both return back to IP addresses located in Iran. The last one was on Thursday, which I sent the results which showed the originating IP address as Iran. He and his lawyer have been notified of this and to cease communications, but has continued to the point where the person even sent him his picture and resume regarding being an entrepreneur and requesting $25,000.00 The last time there was a countdown on a threat we had the local precinct increased patrols around residence located on with nothing happening. continuous communication with this individual is the reason for these messages. In my opinion, we cannot keep wasting resources, manpower, and time dedicated to someone who puts himself in these situations by not following the advice and suggestions of everyone investigating these matters. I suggest he hires a private security firm that will do exactly what he wants. However, if you want, I will again put forth a google emergency disclosure request. I apologize for the Saturday morning email.