Tuesday, January 6, 2015

Amazon Phishing

Update Billing

We could not verify the billing method we have on record for your account.

If you fail to update your billing you will no longer be able to use the Netflix service.

VERIFY

Phishing analysis :

CLICK : VERIFY
OPEN : http://processingsupport.website/
REDIRECT : http://processingsupport.website/http.www.secure.login.amazon.com-83/confirm/details.php?userid=***
SCREENSHOT :


CLICK : Save & Continue
REDIRECT : http://processingsupport.website/http.www.secure.login.amazon.com-83/confirm/Billing.php
SCREENSHOT :


CLICK : Confirm Card
REDIRECT : http://processingsupport.website/http.www.secure.login.amazon.com-83/confirm/confirmed.php?close=***
SCREENSHOT :


REDIRECT : http://www.amazon.com/gp/help/customer/display.html?ie=UTF8

Email analysis :

NOTE : Mime-Version : 1.0
NOTE : X-Msmail-Priority : High
NOTE : Return-Path :
NOTE : Return-Path : sales
NOTE : X-Mailer : Smart_Send_3_1_6
NOTE : X-Priority : 1
NOTE : Received : from hostarea52.com (hostarea52.com. [116.251.205.2])
NOTE : Received : from unknown (HELO static.92.227.46.78.clients.your-server.de)
NOTE : (sales@78.46.227.92)
NOTE : by hostarea52.com with ESMTPA;
NOTE : Received-Spf : client-ip=116.251.205.2;
NOTE : Update

Technicals informations :

PROCESSINGSUPPORT.WEBSITE::A::PROCESSINGSUPPORT.WEBSITE::162.222.214.20
NS1.BITCOIN-DNS.COM::96.8.127.88::SERVER.KDOSLOGIC.INFO
NS2.BITCOIN-DNS.COM::109.104.119.59::109.104.119.59-CLOUD-SERVER-LONDON-HEX.DEDISERVE.COM
MX::0::PROCESSINGSUPPORT.WEBSITE::162.222.214.20

Google result for : http://processingsupport.website/

No comments:

Post a Comment