Tuesday, October 21, 2014

Account Verification Notice (PayPal Phising)

http://images.paypal.com/en_GB/GB/i/logo/paypal_logo.gif
Dear Valued Customer,

We have detected unusual charges to a credit card linked to your account.

Your PayPal account have been limited due to the following reason: A number of suspicious activities have triggered our security system that shows that an un-authorized user tried to access your PayPal account with malicious intent. To minimize their efforts, we have limited access to your account. We have sent you an attachment containing the necessary steps in order to restore your account to its normal state. Simply download and open it in your web browser. Please do understand that this is a security measure intended to protect you and your account.

We apologize for any inconvenience.

Please do not reply to this email. This mailbox is not monitored by our staff. For assistance, you may log in to your PayPal account and click Help in the top right corner of the home page.

Copyright © 1999-2014 PayPal. All rights reserved.

< Attached.html >

Phishing analysis :

OPEN : Attached.html
FIND : http://www.secured-line.su/reach.php

secured-line.su whois :

domain: SECURED-LINE.SU
nserver: ns1.dnsfrnws.com.
nserver: ns2.dnsfrnws.com.
nserver: ns3.dnsfrnws.com.
nserver: ns4.dnsfrnws.com.
state: REGISTERED, DELEGATED
person: Private Person
e-mail: rawixidawax@hotmail.com
registrar: R01-REG-FID
created: 2014.07.10
paid-till: 2015.07.10
free-date: 2015.08.12
source: TCI

Email analysis :

NOTE : Return-Path : < notice@ppsec.com >
NOTE : Received : from server5124.123-serv.co.uk (HELO mail.alphads.co.uk) (109.104.75.167)
NOTE : Received : from 109.104.75.167 ([122.155.190.166])
NOTE : by ds5124.dedicated.turbodns.co.uk
NOTE : X-Mailer : Elm 2.0.88004
NOTE : Mime-Version : 1.0
NOTE : Content-Type : multipart/mixed; boundary="--34470"
NOTE : Account Verification Notice

No comments:

Post a Comment