From: alert@blahblah.tld
Subject: A new settings file for the name@blahblah.tld mailbox
Dear user of the blahblah.tld mailing service!
We are informing you that because of the security upgrade of the mailing service your mailbox (name@blahblah.tld) settings were changed. In order to apply the new set of settings click on the following link:
http://blahblah.tld/owa/service_directory/settingsphp
?email=name@blahblah.tld&from=blahblag.tld&fromname=name
Best regards, blahblah.tld Technical Support.
The link is a forgery, underneath it is actually blahblah.tld.polikka.eu/owa/service_directory/settings.php
?email=name@blahblah.tld&from=blahblah.tld&fromname=name
polikka.eu was registered just today, the registration details are:
Domäne
Name
polikka
Status
REGISTRIERT
Registriert
October 14, 2009
Letzte Aktualisierung
October 14, 2009, 4:35 pm
Registrant
Name
Spasova, Galia
Unternehmen/Organisation
Galia Spasova
Sprache
Englisch
Adresse
j.k. Droujba-1
44231 paris
Frankreich
Telefon
+32.8834336218
gsmailva@ge-88.com
Probably fake you might think, except that "j.k. Droujba-1" is an address in Sofia, not Paris. And it belongs to a company called GE-88 Ltd who have a website of ge-88.com. So, the email address in the WHOIS does seem to trace back to a Bulgarian company. And what does GE-88 Ltd do? Ummm.. well, it appears to manufacture alloys. It could be fake, perhaps their mailserver is compromised..
Nameservers are ns1.supranull.com and ns1.trapsing.net (96.31.81.80 - Noc4Hosts Inc) (although the site is not resolving at the moment).
Just as I was typing this in, another one came through using the domain oikkkkua.co.uk as a redirector:
Domain name:
oikkkkua.co.uk
Registrant:
Evelyn Wilson
Registrant type:
Non-UK Individual
Registrant's address:
805 E. Stocker
paris
68554
Belgium
Registrar:
Webfusion Ltd t/a 123-Reg.co.uk [Tag = 123-REG]
URL: http://www.123-reg.co.uk
Relevant dates:
Registered on: 14-Oct-2009
Renewal date: 14-Oct-2011
Last updated: 14-Oct-2009
Registration status:
Registration request being processed.
Name servers:
ns1.horstsolution.net
ns1.soon-moon.com
Again, this one isn't resolving yet but it was just registered today.
We are geting the same exact thing
ReplyDeletefrom two differnt domains.
wsasdec.eu
and
polikka.eu
it's seems to be a new kind of pishing.
ReplyDeleteI also received the same email with a targeted url diferent from what it's pretends...
So keep away !!!
François