Quantcast
Channel: Fraudwatchers
Viewing all articles
Browse latest Browse all 3468

PHISHING => FAKE PAYPALWARNING - PAGE CONTAINS TROJAN VIRUS

$
0
0
IP address:212.175.100.138 TURKEY
IP address [?]: 212.175.100.138 Copy [Whois] [Reverse IP]
IP country code: TR
IP address country: Turkey
IP address state: Denizli
IP address city: Denizli
IP address latitude: 37.7742
IP address longitude: 29.0875
ISP of this IP [?]: Turk Telekom
Organization: Denizli
Host of this IP: [?]: mail.altinbasak.com

Quote:

From: support@merchant
Subject: ***********SPAM**********.. You Have One New Message
Date: Thu, 16 Feb 2012 03:44:37 -0600

Spam detection software, running on the system "mail.altinbasak.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
The administrator of that system for details.

Content preview: This is a reminder to log in to your Paypal account as soon
as possible. We recently received a report of your account and we need you
to confirm your information. Be sure to log in securely by Click Here>> [...]


Content analysis details: (18.0 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
[score: 1.0000]
0.0 MISSING_MID Missing Message-Id: header
2.7 FH_FROMEML_NOTLD E-mail address doesn't have TLD (.com, etc.)
1.3 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
2.2 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/)
0.9 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[68.114.99.137 listed in dnsbl.sorbs.net]
0.0 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format
0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS
3.1 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
2.8 DOS_OE_TO_MX Delivered direct to MX with OE headers
-0.0 AWL AWL: From: address is in the auto white-list

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.




--Forwarded Message Attachment--
From: support@merchant
Subject: You Have One New Message
Date: Thu, 16 Feb 2012 03:44:37 -0600

This is a reminder to log in to your Paypal account as soon as possible. We recently received a report of your account and we need you to confirm your information.
Be sure to log in securely by Click Here>> VIRUS!! training.garuda-indonesia.com /gitc/ mod/ paypal

We appreciate your understanding as we work to ensure account safety.
__________________________

©2012 Paypal.com. All rights reserved.

Viewing all articles
Browse latest Browse all 3468

Trending Articles