Thursday, July 24, 2014

PayPal Phishing

PayPal

Review Your PayPal Account limited

Identity Case ID PP 352-054-271-526

We understand it may be frustrating not to have full access to your PayPal account. We want to work with you to get your account back to normal as quickly as possible.
As part of our security measures, we regularly check the PayPal screen activity. We request information from you for the following reason:,

Our system detected unusual charges to a credit card linked to your PayPal account.

1. Download Attachment tethered with this email .And don't given this page to anyone .
2. Confirm that you are the owner of the account by opening your account and follow the instructions.

If you need help logging in, go to our Help Center by clicking the Help link located in the upper right-hand corner of any PayPal page.

Sincerely,

PayPal Support,

NOTE : PayPal INC
NOTE : replay@paypal.org
NOTE : Review Your PayPal Account limited !
NOTE : < PP-352-054-271-526.html >
NOTE : Produced By Microsoft MimeOLE V6.00.2600.0000
NOTE : from unknown (HELO WIN-O4A5UB8L7AS) (185.43.109.69)
NOTE : from User ([127.0.0.1]) by WIN-O4A5UB8L7AS with Microsoft SMTPSVC(7.5.7601.17514);

185.43.109.69 LOCATION :
================================================
================================================

DATA EXTRACTED FROM : PP-352-054-271-526.html
================================================
http://www.israelpost.co.il/zipcode.nsf/demozip
http://www.sarenapaleta.com
================================================

israelpost.co.il WHOIS :
================================================
descr: michal kerem
descr: 217 jaffa st.
descr: Jerusalem
descr: 12345
descr: Israel
phone: +972 2 6295094
e-mail: ipa.security10 AT gmail.com
===============================
admin-c: DT-MK20103-IL
tech-c: DT-GP6265-IL
zone-c: DT-MK20079-IL
nserver: ns1.bezeqint.net
nserver: ns2.bezeqint.net
nserver: ns3.bezeqint.net
validity: 08-01-2016
status: Transfer Locked
===============================
changed: domain-registrar AT isoc.org.il 20060108 (Assigned)
changed: domain-registrar AT isoc.org.il 20060209 (Changed)
changed: domain-registrar AT isoc.org.il 20070809 (Transferred)
changed: domain-registrar AT isoc.org.il 20070809 (Changed)
changed: domain-registrar AT isoc.org.il 20131119 (Changed)
changed: domain-registrar AT isoc.org.il 20131119 (Changed)
changed: domain-registrar AT isoc.org.il 20131119 (Changed)
changed: domain-registrar AT isoc.org.il 20131208 (Changed)
===============================
person: michal kerem
address: michal kerem
address: 217 jaffa st.
address: Jerusalem
address: Israel
phone: +972 2 6295094
e-mail: kerem_m AT postil.com
===============================
nic-hdl: DT-MK20103-IL
changed: Managing Registrar 20131208
person: Gilad Pomerantz
address: ISRAEL POST COMPANY LTD
address: 217 jaffa st.
address: Jerusalem
address: 91999
address: Israel
phone: +972 54 2888875
e-mail: pumi AT postil.com
===============================
nic-hdl: DT-GP6265-IL
changed: Managing Registrar 20131119
person: michal kerem
address: michal kerem
address: 217 jaffa st.
address: Jerusalem
address: Israel
phone: +972 2 6295094
e-mail: ipa.security10 AT gmail.com
nic-hdl: DT-MK20079-IL
changed: Managing Registrar 20131119
================================================

sarenapaleta.com WHOIS :
================================================
Registrar URL: http://www.godaddy.com
Registrant Name: Olivera Kulesevic
Registrant Organization: Sarena Paleta
Name Server: NS15.DOMAINCONTROL.COM
Name Server: NS16.DOMAINCONTROL.COM
DNSSEC: unsigned
================================================

Wednesday, July 2, 2014

Account Notification

Un-Authorized Access - Your PayPal account have been limited temporarily.

Dear Valued Customer,

Our state-of-the-art security system have detected what could be an intrusion from an un-authorized user. Our security team analyzes accounts individually after the security system have marked them as insecure. Please download the form attachment in this email and fill in your personal details in the form in order to keep your account in a verified state. Please do understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.

Thank you,

PayPal Support Department

Please do not reply to this email. This mailbox is not monitored and you will not receive a response. Furthermore, should you require any assistance, you may log in to your PayPal account and click Help in the top right corner of any PayPal page.

< FormAttachment.html >

SCAM.CZ DETECTED ONE URL IN A FORM :
==============================================
http://www.secure-line2.com/transmit.php
==============================================

Secure-line2.com WHOIS :
==============================================
Domain name: secure-line2.com
Registry Domain ID:
Registrar WHOIS Server: whois.bizcn.com
==============================================
Registrar URL: http://www.bizcn.com
Updated Date: 2014-05-12T18:17:57Z
Creation Date: 2014-05-12T18:17:59Z
==============================================
Registrar Registration Expiration Date: 2015-05-12T18:17:59Z
Registrar: Bizcn.com,Inc.
Registrar IANA ID: 471
Registrar Abuse Contact Email: abuse@bizcn.com
Registrar Abuse Contact Phone: +86.5922577888
Reseller: Cnobin Technology HK Limited
==============================================
Domain Status: clientDeleteProhibited
Domain Status: clientTransferProhibited
==============================================
Registry Registrant ID:
Registrant Name: Kathy Ferranti
Registrant Organization: J. Brannam
Registrant Street: 1423 Koontz Lane
Registrant City: North Hollywood
Registrant State/Province: CA
Registrant Postal Code: 91605
Registrant Country: us
Registrant Phone: +01.8187649157
Registrant Phone Ext:
Registrant Fax: +01.8187649157
Registrant Fax Ext:
Registrant Email: admin@secure-line2.com
==============================================
Registry Admin ID:
Admin Name: Kathy Ferranti
Admin Organization: J. Brannam
Admin Street: 1423 Koontz Lane
Admin City: North Hollywood
Admin State/Province: CA
Admin Postal Code: 91605
Admin Country: us
Admin Phone: +01.8187649157
Admin Phone Ext:
Admin Fax: +01.8187649157
Admin Fax Ext:
Admin Email: admin@secure-line2.com
==============================================
Registry Tech ID:
Tech Name: Kathy Ferranti
Tech Organization: J. Brannam
Tech Street: 1423 Koontz Lane
Tech City: North Hollywood
Tech State/Province: CA
Tech Postal Code: 91605
Tech Country: us
Tech Phone: +01.8187649157
Tech Phone Ext:
Tech Fax: +01.8187649157
Tech Fax Ext:
Tech Email: admin@secure-line2.com
==============================================
Name Server: sara.ns.cloudflare.com
Name Server: tom.ns.cloudflare.com
DNSSEC: NotsignedDelegation
==============================================