Monday, May 23, 2016

Re.. (Phishing BNP Paribas)

PαrticuliersPriοritéPrοfessiοnnelsEntreprises

ΒNΡ Ρaribas Βαnqυe

Cher(e) client(e),

Vérificatiοn de cοmpte en ligne

Οn vous cοntacte pοur vοus nοtifier qu'un tier suspect a essayé d'avoir l'accès a vοtre cοmpte pοur cela οn a limité l'accès afin de prévenir toute activité illégale. veuillez cοnfirmer que vοus êtes le titulaire du cοmpte en vérifiant vοs infοrmatiοns afin de régler le prοblème. une fοis cοnfirmé vοus allez recevοir un cοde secret cοmme sécurité renfοrcé pour le valider sur vοtre cοmpte

NΟTIFICATIΟN!

Vοus avez 48 heures pοur vérifier vοs infοrmatiοns, sinοn le cοmpte sera clοturé pοur tοujοurs!

1 Accéder a vοtre cοmpte
2 vérificαtiοn de vοs infοrmαtions
3 se cοnnecter à vοtre webmαil zimbrα

Accéder au cοmpte

Cοrdiαlement,
Le Servíce Clíenτs BNΡ Ραribas.


Phishing analysis :

CLICK : Accéder au compte
OPEN : https://www.e-prev.com.br/t
REDIRECT : http://dog.cyberactiv.com/notre-offre/devenirrr/
RESULT : Phishing was removed...
SCREENSHOT :


Email analysis :

NOTE : webmaster@pll.net.frz
NOTE : Content-Type : text/html; charset=iso-8859-1
NOTE : Mime-Version : 1.0
NOTE : Return-Path : < www-data@webgride074.emsecure.net >
NOTE : Received : from webgride074.emsecure.net ([139.59.152.33])
NOTE : Received : by webgride074.emsecure.net (Postfix, from userid 33)
NOTE : X-Php-Originating-Script : 0:index.php
NOTE : Re..

Monday, May 16, 2016

After the last Apple phishing attempt...

Apple Phishing seems now active :

rrpharma.in/bb/Apple/6aad7060decde21c5f44a0d0958eefa4/Apple/


CLICK : Login
SCREENSHOT :



CLICK : Valider mes informations

REDIRECT : https://appleid.apple.com/

modifications de votre convention de compte (Phishing Apple) (PHISHER FOUND)

free-france-Apple

Cher(e) client(e),

Nous vous prions de trouver, dans le document ci-joint, les informations relatives aux modifications de votre convention de compte, de votre annexe Conditions de fonctionnement des cartes, ainsi que du guide des Conditions et Tarifs 2016.

Consultez le détail des modifications

Ces modifications entreront en vigueur dans un délai de 2 mois à compter de la mise à disposition du présent message.

Phishing analysis :

CLICK : Consultez le détail des modifications
OPEN : http://vittor.ca/
REDIRECT : http://rrpharma.in/bb/Apple/
RESULT : Phishing is unresponsive... But...
PHISHER IS : chuucky24@gmail.com

Email analysis :

NOTE : web@rdp.fr
NOTE : Content-Type : text/html; charset=iso-8859-1
NOTE : Mime-Version : 1.0
NOTE : Return-Path : < streetbuzz@streetbuzz.fr >
NOTE : Received : from s18422701.onlinehome-server.info ([82.165.194.68])


NOTE : X-Php-Originating-Script : 10009:admin.php
NOTE : modifications de votre convention de compte

F‪‪‪o‪‪‪‪‪rtune‪‪‪o - Vous avez un message (Phishing Fortuneo)

Fortuneo | Banque | l'équipe Fortuneo | Inscription

Bonjour

Un nouveauaMessageoestodisponibleosurovotreoMessagerie Fortuneo .

Pourale consulter,aVeuiller Cliquez sur le lien ce-dessous:

Accéder boite

Cordialement,

Nous vous remercions de votre confiance.

l'équipe fortuneo

France SAS – 417 627 940 RCS Paris Siège Social : 78ter rue Laugier, 75 017 PARIS

Job Agent ID: 314­6088, 2013-10-03 12:02:14

Phishing analysis :

CLICK : Accéder boite
OPEN : http://www.fortaneobnqo.biz/not
REDIRECT : http://46.101.208.245/zab/


SCREENSHOT :


CLICK : Valider
REDIRECT : http://46.101.208.245/zab/config.db1.php
FINAL : https://mabanque.fortuneo.fr/fortuneosmartphone/FortuneoSmartPhone.html#/auth

Email analysis :

NOTE : ds@btb.fr
NOTE : Mime-Version : 1.0
NOTE : Content-Type : text/html; charset="iso-8859-1"
NOTE : X-Mailer : PHPMailer [version 1.73]
NOTE : Return-Path : < khrabo@btb.fr >
NOTE : Content-Transfer-Encoding : 8bit
NOTE : Received : from btb.fr ([46.101.104.120])




NOTE : F‪‪‪o‪‪‪‪‪rtune‪‪‪o - Vous avez un message

Attn: Package Beneficiary (Email Leaks)

Attn: Package Beneficiary

I want to acknowledged you that we have finally succeeded in getting your package worth of $9.2million out of (ECOWAS) Economic Community of West African States department with the help of Mr. James George Attorney General of Federal High Court of Justice Benin Republic which act as your foreigners Attorney representative here in Benin Republic.

Therefore every necessary arrangement has been made successfully with the Agent Kelvin Martinz for the delivery of your Consignment Box and every Documents guiding your delivery is well updated hence you are advised to reconfirm your full delivery information to the Agent right now as he is currently at JOhn F. Kennedy International Airport with your Consignment Box, As he called me this morning to inform me that he misplaced your delivery address which he has due to CUSTOMS /FBI/ CIA and POLICE searching and scanning on the Box as if he is a terrorist there in your country but finally I thank God that they have confirmed that his movement is clear and legit with out any suspicious intentions to your country only to deliver this Consignment Box to you and the documents are updated as I earlier told you.

So you are advice to reconfirm your full delivery information to the diplomat and ask him to send you your DHL Airway Bill so as to prove to you that he is currently in your country also here is his mobile number (+1 920 876 7591) so as to have easy conversation with him and to enable you give him full direction to get your Consignment Box delivered to you and hand you over your Consignment Box safe and sound, Furthermore you are advice to be very fast as the Agent Kelvin martinz has no time to waste due to his flight ticket,

So the Information you are required to reconfirm to the Agent is as Follow

(1)Your Full Name
(2)Mobile Phone Number
(3)Current Home Address
(4)Fax Number
(5)Country
(6)City
(7)Nearest Airport
(8)E-mailKelvinmartinz497@yahoo.com

He is at John F. Kennedy international Airport right now because of the Searching and Scanning of the Consignment which made him to misplace your address (8)A Copy of Your ID For Identification and don't forget to put your convenient calling hours.

Kindly contact him via his email address, Contact person, Name Agent Kelvin Martinz So contact him to deliver your consignment box first thing tomorrow morning possibly today, so get back to us immediately you contact the Agent to make sure that your fund has gotten to you without any hitch, Furthermore remember the Agent delivering the Consignment Box does not know the content of that consignment box is money, because the Attorney which represented you at (ECOWAS) registered it as a family value to avoid hitch during the delivery, hence on no circumstances should you let him know the content of that consignment box which is $9.2million to avoid lost of your fund as your Consignment was Sign and Stamp by Federal Ministry of Justice to make sure that it is protected until it gets to you.

Shipment code GJK72DWQ
PACKAGE code OVX950
Security code EYTU/3055WEZ/263
Transaction code 7126/JLFS/7138/17305
Certificate Deposit code MCBS/PQLE/2-6/41

SINCERELY
Dr. DAVID KINGSLEY
CALL ME AFTER GOING THROUGH THE EMAIL +229 98117316
The Director of DHL Courier Company Benin Republic

Email Leaks

yanyanwong2005@gmail.com, irvinggoldstein5@gmail.com, zuckuss1212@gmail.com, sessavivi@gmail.com, mr04248@gmail.com, ahdrianmallari14@gmail.com, stvesmthson33@gmail.com, bigmann768@gmail.com, kenneth.turse@gmail.com, robinsavage447@gmail.com, madgekz3bonner@gmail.com, np.eccomiqua@gmail.com, buraktorun7@gmail.com, saveourunionflag@gmail.com, nick.bobsmith123@gmail.com, jennyblack7272@gmail.com, gary.roaster@gmail.com, hugo35mm@gmail.com, mizra9062@gmail.com, hugoferreiracamargo@gmail.com, hector.rowles@gmail.com, jasminedelancey@gmail.com, chelleanderson12@gmail.com, cherrybree289@gmail.com, cruise19allyson@gmail.com, rhejean16@gmail.com, lucy04anderson@gmail.com, bofasaur@gmail.com, harrold.fiducious@gmail.com, taylorhelen66@gmail.com, cj96050@gmail.com, webinis123@gmail.com, jessicapierce318@gmail.com, marjac1997@gmail.com, meandcecilia@gmail.com, jw508328@gmail.com, whiter958@gmail.com, reverendtomjones@gmail.com, cartoonherodude@gmail.com, rob.karhu@gmail.com, rich.dude.swag@gmail.com, sperks548@gmail.com, dr.richard.poke@gmail.com, gbreezy820@gmail.com, jennatulls27@gmail.com, pschlacter400@gmail.com, miakriskoff@gmail.com, marjac1995@gmail.com, marj.ac1993@gmail.com, marja.c1993@gmail.com, acaster247@gmail.com, hughjarce333@gmail.com, oldmichaelhunt@gmail.com, marjac.1995@gmail.com, marjac.1993@gmail.com, m.litoris224@gmail.com, vcorningstone78@gmail.com, riversmontana1@gmail.com, clodcuillon@gmail.com, mikelitoris224@gmail.com, englishcofa@gmail.com, dotmatrixanon@gmail.com, iamjackenoff@gmail.com, rockstaradams69@gmail.com, reneroussimoff@gmail.com, marjac1993@gmail.com, chudd.buckworth444@gmail.com, paulwillian489@gmail.com, topicload@gmail.com, honeypotrestaurant@gmail.com, sheepsquadtv@gmail.com, beverlimcadoo@gmail.com, alexythu145@gmail.com, geoffreybennett47@gmail.com, buttermymuffins25@gmail.com, davesheppy28@gmail.com, jseagal@gmail.com, samuelsmith19611@gmail.com, ronny.dobs123@gmail.com, ronnie.dobbs123@gmail.com, collinsphil32@gmail.com, thomas.leer.q@gmail.com, fatherbfinger298@gmail.com, lightningfastvcrrepair@gmail.com, vbonjovi2@gmail.com, drthomasdequincey@gmail.com, justincase9937@gmail.com, cssmith017@gmail.com, aprilatchurch@gmail.com, harpuun1337@gmail.com, tatyanalaguna29@gmail.com, mingliangsteve@gmail.com, lemongrass.expounder@gmail.com, clients324@gmail.com, jon.targaryen420@gmail.com, jens.ultrecht@gmail.com, jhendrix1432@gmail.com, crapcatcher123@gmail.com, rmquekis@gmail.com

Email analysis :

NOTE : goodluck.@herb.ocn.ne.jp
NOTE : Kelvinmartinz921@yahoo.com
NOTE : X-Originating-Ip : [41.86.234.171]

Masonic regalia (Scam)

IMC Regalia

Quality Manufacturers and Exporters of Masonic Regalia Items, Please Visit website, we can Provide Catalogue as requirement We also made custom design on customer demand, the work force is skilled, devoted and performs diligently to manufacture the products of highest quality, which reflects their mastery over craftsmanship. IMC Regalia believes that its customers are its assets, so the customer satisfaction is its prime objective and the reason for its existence.Regalia is a family owned business which has been in business for over 100 years. We stand behind the quality of our products and appreciate your business whether it is large or small. We guarantee to make your ordering experience as simple and pleasant as possible. We look forward to offering you quality service and products at reasonable prices. Feel free to call us at 03378633816 or visit the how to order section to contact your sales representatives with any questions you might have.

“Please contact us If wanna know more information”

Director/CEO
Mughees Ahmed
Email: info@imcregalia.com
Website: www.imcregalia.com
Skype: idealmugheescompany

Email analysis :

NOTE : alhafezesta@gmail.com
NOTE : info@imcregalia.com
NOTE : Received : from [39.45.171.181] (port=51005 helo=WINREU0KNCV6AD)


NOTE : by server.rphostpk.com