You don't think it is a bit ridiculous that somebody, pretending to be Google, would go to the effort of running requests through Google App Engine, just in case somebody ran a trace against the logs in the hope of figuring out where the IP address was? All evidence points at Google and the likelihood that that's as a result of some serious planning by a paranoid scammer is unlikely.