Wednesday, January 20, 2016

Your Expedia account was restricted (Phishing)

Dear partner,

A recent attempt to Sign in to your Expedia PartnerCentral was restricted.

As a security precaution, we have temporarity suspended access to your account services

What do I have to do?

Please click the button below and follow the procedure in order to complete the verification process.

https://expediaparnercentral.com/

Full access to your account will be regained once verified

© 2016 Copyright. All rights reserved. Confidential and proprietary.

Phishing analysis :

CLICK : https://expediaparnercentral.com/
OPEN : http://crias.cl/images/.x/partner/expediapartnercentral.com/
SCREENSHOT :


VALIDATE : FORM
REDIRECT : https://www.expediapartnercentral.com/Account/Logon?MESSAGE=*&RP_ID=1

Email analysis :

NOTE : info@rns.com.tr
NOTE : Received : from static.107.167.76.144.clients.your-server.de
NOTE : ([144.76.167.107]:49865 helo=[127.0.0.1])


NOTE : by sv67.ifastnet16.org with esmtpa (Exim 4.86)
NOTE : (envelope-from < info@rns.com.tr >)
NOTE : Received : from sv67.ifastnet16.org (sv67.ifastnet16.org. [31.22.7.248])


crias.cl whois :
==================================
Titular: Verónica Delgado (CENTRO DE REHABILITACION INFANTIL AKTION SONNENSCHEIN LTDA)
Fecha de creación: 2007-08-21 13:15:16 CLT
Fecha de expiración: 2016-09-18 09:15:16 CLT Renovar ahora
Servidor de Nombre: ns1.accesoprime.cl
Servidor de Nombre: ns2.accesoprime.cl
==================================

rns.com.tr whois :
==================================
Registrant:

Rns Madencilik Sanayi Ve Dis Tic. Ltd. Sti.
atasehir bulv. 38. ada 3/3 no:66 Istanbul, Turkiye
muratyalcinkaya1@hotmail.com
Phone : + 216-456-1027

Billing Contact:

NIC Handle : rmv27-metu
Organization Name : RNS Madencilik ve San. D** Ticaret Ltd. *ti.
Address : Uzuntarla Mevkii No:19/1 *ile / Turkiye Istanbul,
Phone : + 90-262-6440088-

Domain Servers:

ns1.ifastnet16.org
ns2.ifastnet16.org

** Additional Info:
Created on..............: 2009-May-07.
Expires on..............: 2016-May-06.
==================================

No comments:

Post a Comment