Thursday, August 27, 2015

Security Notice Updates (LinkedIn Phishing)

LinkedIn

Security Notice Updates

On the 23rd of August 2015, An Attempt into your account has been detected from an unknown location, For your security, access to your LinkedIn Account has been temporarily suspended. To regain access,you must complete REGISTRATION BY DOWNLOAD & FILL ATTACHED FORM PLEASE NOTE: This is a compulsory measure. Failure to update your information will lead to service termination Linkedin security team.

VIEW ATTACHED TO UPDATE

You received an invitation to connect. LinkedIn will use your email address to make suggestions to our members in features like People You May Know. Unsubscribe
Learn why we included this. If you need assistance or have questions, please contact LinkedIn Customer Service.

© 2015, LinkedIn Corporation. 2029 Stierlin Ct. Mountain View, CA 94043, USA

Phishing analysis :

OPEN : LinkedIn Verification.html
EXTRACT FORM : action="http://test88212.test-account.com/BEXXXXLINK.php"

Whois test-account.com :

Domain Name: test-account.com
Registry Domain ID: 86840496_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.registrygate.com
Registrar URL: www.registrygate.com
Updated Date: 2014-12-29T01:33:34Z
Creation Date: 2002-05-22T01:33:22Z
Registrar Registration Expiration Date: 2016-05-22T20:04:29Z
Registrar: RegistryGate GmbH
Registrar IANA ID: 1328
Registrar Abuse Contact Email: abuse@registrygate.com
Registrar Abuse Contact Phone: +49.89.55061272
Domain Status: ok

Registrant Name: Werner Kaltofen
Registrant Organization: Neue Medien Muennich GmbH
Registrant Street: Hauptstr. 68
Registrant City: Friedersdorf
Registrant State/Province:
Registrant Postal Code: 02742
Registrant Country: DE
Registrant Phone: +49.3587235310
Registrant Fax: +49.3587235330
Registrant Email: hostmaster@all-inkl.com

Admin Name: Werner Kaltofen
Admin Organization: Neue Medien Muennich GmbH
Admin Street: Hauptstr. 68
Admin City: Friedersdorf
Admin State/Province:
Admin Postal Code: 02742
Admin Country: DE
Admin Phone: +49.3587235310
Admin Fax: +49.3587235330
Admin Email: hostmaster@all-inkl.com

Tech Name: Werner Kaltofen
Tech Organization: Neue Medien Muennich GmbH
Tech Street: Hauptstr. 68
Tech City: Friedersdorf
Tech State/Province:
Tech Postal Code: 02742
Tech Country: DE
Tech Phone: +49.3587235310
Tech Fax: +49.3587235330
Tech Email: hostmaster@all-inkl.com
Name Server: ns5.kasserver.com
Name Server: ns6.kasserver.com
DNSSEC: unsigned

Registry Billing ID:
Billing Name: Werner Kaltofen
Billing Organization: Neue Medien Muennich GmbH
Billing Street: Hauptstr. 68
Billing City: Friedersdorf
Billing State/Province:
Billing Postal Code: 02742
Billing Country: DE
Billing Phone: +49.3587235310
Billing Fax: +49.3587235330
Billing Email: hostmaster@all-inkl.com

Email analysis :

NOTE : Return-Path : < werner.laube@t-online.de >
NOTE : X-Remote : 194.25.134.17 (mailout02.t-online.de)
NOTE : Mime-Version : 1.0
NOTE : Content-Type : multipart/mixed; boundary="===============1507808188=="
NOTE : Received : from mailout02.t-online.de (194.25.134.17)
NOTE : Received : from fwd40.aul.t-online.de (fwd40.aul.t-online.de [172.20.26.139])
NOTE : by mailout02.t-online.de
NOTE : Received : from h2358992.stratoserver.net (@[85.214.197.244])
NOTE : by fwd40.t-online.de with (TLSv1:DHE-RSA-AES256-SHA encrypted)
NOTE : Security Notice Updates

No comments:

Post a Comment