This is a rather new phishing site, pretending to be a tax refund from the UK's HMRC agency pointing to the domain confirm-hmrc.com (subdomains www.confirm-hmrc.com and onlineservice.confirm-hmrc.com).
Although the phish looks convincing, the HMRC don't do tax refunds in this way. Usually they will just transfer the money to your bank account or alternatively send you a cheque. Furthermore, in my experience the HMRC only communicate by post and not electronic mail.
The site hosted on 218.108.75.53 in China. The same server also has the fraudulent domains account-update-westernunion.com, account-westernunion.com and accounts-westernunion.com. The domain registration details are fake:
Domain Name.......... confirm-hmrc.com
Creation Date........ 2011-07-12
Registration Date.... 2011-07-12
Expiry Date.......... 2012-07-12
Organisation Name.... wu wu
Organisation Address. 12 na
Organisation Address.
Organisation Address. miami
Organisation Address. 12311
Organisation Address. AL
Organisation Address. UNITED STATES
Admin Name........... wu wu
Admin Address........ 12 na
Admin Address........
Admin Address........ miami
Admin Address........ 12311
Admin Address........ AL
Admin Address........ UNITED STATES
Admin Email.......... sadasda@re.com
Admin Phone.......... +1.12312312312
Admin Fax............
Tech Name............ wu wu
Tech Address......... 12 na
Tech Address.........
Tech Address......... miami
Tech Address......... 12311
Tech Address......... AL
Tech Address......... UNITED STATES
Tech Email........... sadasda@re.com
Tech Phone........... +1.12312312312
Tech Fax.............
Name Server.......... ns2.confirm-hmrc.com
Name Server.......... ns1.confirm-hmrc.com
Blocking traffic to 218.108.75.0/24 will probably do no harm.
No comments:
Post a Comment