Thursday, December 3, 2015

RE: Documentos encontrados

R1%

--Baixar tudo como zip

Documentos encontrados em anexo, verifica-los.

Link analysis :

CLICK : --Baixar tudo como zip
OPEN : http://216.126.192.177/


RESULT : UNRESPONSIVE...

Email analysis :

NOTE : presente-conf50269@ouvidoria64.is-into-games.com
NOTE : 185.12.177.163 (ouvidoria64.is-into-games.com)
NOTE : Received : by ouvidoria64.is-into-games.com (Postfix, from userid 33)

Mr.Maldonado

Dear Beneficiary,

This is to let you know that we have received an instruction from the United Nation by orders of the Ministry of Finance, UNITED STATE OF AMERICA to release your Approved payment of US$8.5 Million Dollars via CITY BANK ATM VISA CARD which you will use to withdraw your US$8.5 Million Dollars from any ATM Machine in any part of the world.I must thank you and assure you that CITY BANK ATM VISA CARD number 427 439364 4673326 has been approved and upgraded in your favour this morning. The amount upgraded in the ATM CARD is US$8.5 Million Dollars, (EIGHTY MILLION FIVE HUNDRED USD) and your secret pin number is (6583), Right now,

Invitation have been extended to you to visit CITY BANK UNITED STATE OF AMERICA for collection of your CITY BANK ATM VISA CARD and PIN NUMBER so that you can activate it by yourself and start withdrawing funds from any ATM Machine in your country but the amount you can withdraw in a day is $23,000, per day as we have programmed it.Alternatively, if you are unable to visit CITY BANK STATE OF AMERICA for collection of this your CITY BANK ATM VISA CARD and PIN NUMBER, you must therefore apply for the CITY BANK ATM VISA CARD and PIN NUMBER to be sent to you via our diplomatic courier service at your own expenses byoffsetting the following payments such as; (1) Shipment fee of the CITY BANK ATM VISA CARD to your address amounting to US$160.00. (2) Insurance Coverage of the CITY BANK ATM VISA CARD amounting to USUS$100.00.

Both payments is the sum of US$260.00 must be paid to enable us ship the CITY BANK ATM VISA CARD to your address to enable you start withdrawing your US$8.5 Million Dollars from any ATM machine in any part of the world. This CITY BANK ATM VISA CARD must be insured so that it can get to you without any problem and diversion. This is because this ATM CARD that can be use to withdraw funds from any ATM Machine in every part of the world.Secondly the officer in charge is .Mr.Maldonado, Erika, contact them via above with all your detail, by contacting them to Atm card payment centre of {CITY BANK Plc} phone number +13156755281 the general manager name Mr.Maldonado, Erika.

And make sure you do forward to them your full information’s such as. (1) your full name.(2) Address where you want them to send the card through diplomatic courier Service (P.O Box not accepted). (3) Your full name and total amount you are expecting, Instead of losing your fund. (4) you’re direct telephone numbers. (5) A copy of your international passport. Please indicate to the card centre the total sum you are expecting and for your information, you have to stop any further communication with any institution or office until you receive the Atm card. Note: because of impostors, we hereby issue you, your pin code of conduct tag number, which is (6583) so you must have to indicate this code when contacting the card centre. We await your urgent response.

So,if you cannot come to CITY BANK of UNITED STATE OF AMERICA for collection of your CITY BANK ATM VISA CARD, you must therefore kindly go right now To western union and send this shipment and insurance fee of US$260.00 via Western Union Money transfer with the details below And write your MTCN number down and your sender name below down the details

Receiver's Name....NOLAN MANNING
Country.. United state of America
City.. Coram New York
Text Question..WHEN
Text Answer...NOW
Amount $260.00
MTCN.
Sender.

As soon as the fee is received, we shall immediately dispatch the CITY BANK ATM VISA CARD to you and it will take only 2 days to arrive to your address to enable you start withdrawing funds that same day from any ATM machine nearest to you.
Thanks for your understanding and we are waiting for your quick reply and the payment information.

This massage is coming from.
Foreign Contract Payments
Mr.Maldonado, Erika; Telephone call OR text us (+13156755281)

CITY BANK BANK PLC ATM VISA CARD

Email analysis :

NOTE : Maldonado@triton.ocn.ne.jp
NOTE : citybanknewyork2015@yahoo.fr
NOTE : Received : from mzkstore491.ocn.ad.jp
NOTE : (mv-osn-hcb010.ocn.ad.jp [122.1.235.84])
NOTE : X-Originating-Ip : [41.216.50.54]

Our LED Lighting and LED Signage products

Hi,

Our company is a manufactures/assembles/distributor of LED Lighting, as will as LED Signage products.. I myself have over 30 years in lighting and signage field and over 15 years
in LED products. We are running a 40% off Holiday sales on all of our LED products, with free energy audits as well as no money down deals. If it was simply because you are not the right person in charge of saving your company money on your electric bill, then please let me know the right contact person in your company, that does pay your electric bill, we can help them save money! If you are interested in LED Lighting products, we can help you by preforming and energy audit on your property to figure the true savings of switch from the old outdated lighting to the new modern LED Lighting Systems. Sometimes is better to just retrofit the excessing lighting systems and sometimes it is best to just replace the whole lighting system, we can help to understand the 2 possible choices.

Perks, in which we offer you!

1. Free Energy Audit
2. Turn Key Solution
3. No Money Down
4. Interest Free Loans
5. Free Installation
6. 10 Year Limited Warranty
7. Bonded and Insured Project Protection Plan
8. 10% Referral Pay-Back
9. 3% You help us
10. You Refer 10 customers with an equal value of your lighting project and get your lighting project for free!

Thanks!

Alex Williams
LED Lighting & Signage Specialist
Contact: rearies@sina.com

Email analysis :

NOTE : kosnaon@mail.com
NOTE : alverylee@sina.com
NOTE : 185.53.168.135 (london.winof.cn)
NOTE : Received : from london.winof.cn (185.53.168.135)

Wednesday, December 2, 2015

Online Account Notification (Paypal Phishing)

Dear User

By limiting the access to your account, our security team have blocked unusual charges to a credit-card linked to your account.

By providing some information in regards to your account, our Account Review Team will try to resolve the issue as soon as possible.

PayPal may limit your account as a security measure to protect you and your account. Access limitation is taken as a pre-caution.

PayPal have provided a form (see attachment) to verify your account. You may download and fill in the form.

Our security team will immediately review the information you have provided, and your account should be restored back to normal.

We would like to thank you for your attention to this matter.

Sincerely,
PayPal

form.html

File analysis :

OPEN : form.html
DETECT : Sophos (Mal/Phish-A)

File opening :

The file was encoded so the file was decoded... :

http://ddecode.com/hexdecoder/?results=66079ae734cbda3f7abffa23e3341be4

var _0x13632f = "7ef141717f6e9bc4ea6a159fc074bf7e.php";
var _0x17dd=["http://www.my-ads-network.net/"];


my-ads-network.net whois :

Tech Email: 8F0090A44FFA46A2B0CAA72F917439C7.PROTECT@WHOISGUARD.COM
Name Server: BLOCKEDDUETOPHISHING.PLEASECONTACTSUPPORT.COM
Name Server: DUMMYSECONDARY.PLEASECONTACTSUPPORT.COM

Email analysis :

NOTE : members@systems.com
NOTE : X-Terrace-Classid : Terrace Spam system

Rev Thomas Okafor

Dear friend,

How are you today and how is life over there in your country, am very happy to inform you about the successful transfer of that fund i told you that i will like to transfer into your bank account sometime ago but due to some circumstance you opted out of the deal. However i later found someone who helped me in the transfer,he is the CEO of RV PLATINUM SHIPPING SERVICE based in Venezuela in the person of Mr Antonio Elortegui. Meanwhile am on investment project in venezuela and i cannot forget your tireless effort then to help me succeeded in this transfer and i have decided to reward your kindness,i left a Bank Draft of (USD$2,000,000.00) Two Million Dollars under the care of my personal assistance Mr. Jubril Godwin Jr to send to you as soon as you contact him through his personal email address: (jubgodwin@gmail.com) Tell him i asked you to contact him regarding the bank Draft i issued on your behalf. In the main time am going to be away from my email and I will not be able to check my email box, as i will like to concentrate on my purpose of coming here to invest my money, if you so desire to speak with me you can reach me on phone with +58412575530. Let me know as soon as you receive your Bank Draft so that we can both share in this joy.

Thanks and have a nice day.
Regards,
Barrister Dr. Williams Eze.

jubgodwin@gmail.com

Email analysis :

NOTE : marina@localhost.com
NOTE : jubgodwin@gmail.com
NOTE : X-Originatingip : 41.71.178.118 (lawrence)
NOTE : Received : from www.senju.com.tw (localhost [127.0.0.1])
NOTE : by dns.senju.com.tw (8.13.8+Sun/8.13.8)
NOTE : X-Mailer : OpenWebMail 2.53

Rép : New order (Virus)

GoodDay,

Find the attached specifications in the purchase order for our company end of the year sales before sending your Proforma Invoice and do get back to me with your quotations asap. An Official order placement will follow as soon as possible. But note that we have restructured the order so the first order will not exceed 20-40feet containers.

Thanks & Best Regards,
Manager Purchasing Department
Shirley Lee

TMS Titanium

HEADQUARTERS

12215 Kirkham Rd., Suite 300
Poway, CA 92064

EMAIL: sales@tmstitanium.com

SALES AND CUSTOMER SERVICE

Toll Free: (888) 748-8510
Local: (858) 748-8510

FAX

(858) 748-8526

scanned purchase order.ace

File analysis :

NOTE : Open scanned purchase order.ace
NOTE : scanned purchase order.ace is a virus.

Virus analysis :

Avast : Win32:Malware-gen
ESET-NOD32 : a variant of Win32/Injector.CNFH
GData : Archive.Trojan.Agent.14JCQ5
Ikarus : Trojan.Win32.Injector
Kaspersky : Trojan.Win32.Scarsi.aaab
Panda : Generic Suspicious
Qihoo-360 : HEUR/QVM03.0.Malware.Gen
Sophos : Mal/DrodAce-A

Email analysis :

NOTE : sales@tmstitanium.com
NOTE : SUNSHINESLISA1@YAHOO.COM
NOTE : Received : from [67.227.193.36]
NOTE : (UnknownHost [67.227.193.36]) by mail2.postbulletin.com