Tuesday, January 8, 2013

Hewlett-Packard ScanJet Phishing


This morning, I received a message from Hewlett-Packard ScanJet :

A document was scanned and sent to you using a Hewlett-Packard HP751988

Sent to you by: Jorge
Pages : 4
Filetype(s): Images (.jpeg) View


FETCHING LINKS (View) :

=======================================================
http://norway-info.ru/new.htm
=======================================================

EXTRACTING DATAS :

norway-info.ru is hosted on 188.65.208.66 by :
=======================================================
aut-num: AS6719
as-name: KNOPP-AS
descr: Dummy description for AS6719
org: ORG-LLCK2-RIPE
import: from AS9002 accept ANY
import: from AS29076 accept ANY
import: from AS8631 accept ANY
export: to AS9002 announce AS6719
export: to AS29076 announce AS6719
export: to AS8631 announce AS6719
admin-c: DUMY-RIPE
tech-c: DUMY-RIPE
mnt-by: RIPE-NCC-END-MNT
mnt-by: MNT-KNOPP
mnt-routes: MNT-KNOPP
changed: unread(at)ripe.net 20000101
source: RIPE
=======================================================
norway-info.ru whois :
=======================================================
domain: NORWAY-INFO.RU
nserver: ns1.reg.ru.
nserver: ns2.reg.ru.
state: REGISTERED, DELEGATED, VERIFIED
person: Private Person
registrar: REGRU-REG-RIPN
admin-contact: http://www.reg.ru/whois/admin_contact
created: 2011.09.16
paid-till: 2013.09.16
free-date: 2013.10.17
source: TCI
=======================================================

Social engineering is a long path...

No comments:

Post a Comment