Thursday, October 30, 2014

Contact Michael Tim (Esq)

Irregular check card activity
American Express

Dear Customer,

We detected irregular card activity on your American Express Check Card on 21 October, 2014. As the Primary Contact, you must verify your credit card activity before you can continue using your card, and upon verification, we will remove any restrictions placed on your card. To review your account as soon as possible please click on the link below.

http://ucsdiagnostic.com/qlgsqpsvgk/wigzbftlar.html

Thank you for your Card Membership.

-------------
American Express Customer Care
Fraud Department:
Erica Bermudez
Level III Security Officer

Email analysis :

NOTE : User-Agent : Mozilla/5.0 (Windows NT 6.1; rv:24.0)
NOTE : Gecko/20100101 Thunderbird/24.2.0
NOTE : Return-Path : < ywvh@boston.sisna.com >
NOTE : Received : from host29.181-14-177.telecom.net.ar (181.14.177.29)
NOTE : Irregular card activity

Phishing analysis :

CLICK : http://ucsdiagnostic.com/qlgsqpsvgk/wigzbftlar.html
NOTE : page was corrected by admin

ucsdiagnostic.com whois :

Domain Name: UCSDIAGNOSTIC.COM
Registrar URL: http://www.wildwestdomains.com
Registrant Name: Antonio Santoro
Registrant Organization: UCS DIAGNOSTIC S.R.L.
Name Server: NS1.OMNIBUS.NET
Name Server: NS2.OMNIBUS.NET
DNSSEC: unsigned

your payment is available.

Western Union®Welcome to Western Union
Send Money Worldwide
Our Ref:WUMT0XX2/987
Email; (richardwhite595@gmail.com).
Telephone: +22999867970.

Attention Dear Value Customer,

Welcome to Western Union Money Transfer Agent, We wish to inform you that the IMF have release your fund sum of $2,8 million US dollars issued on your name the money was deposited with us in this Office as MTCN credit card, we shall be sending the money to you everyday $5000.00usd until we complete the total payment. We are very glad to inform you that we have credit your first payment of $5000.00usd, but bare it in mind that the $5000.00usd will not be given to you except you pay for transfer charge which is $68.00, you have to pay the money through our service western union to the information we give you here, then after confirm the payment of $68.00 from you, we shall release your first $5000.00usd to enable you pick it up and get back to us for the second payment,As you can see here is the MTCN Number of your first payment which we credited for you today, track it with our website: www.westernunion.com, to confirm that your payment is available.

1)Senders Name::Godwin Onyia
2)MTCN Number::: 6890479748
3)Amount::: $5000.00 USD.

Track it with our website: www.westernunion.com

Note that on your reply this massage make sure you send the full information to this E-mail here(richardwhite595@gmail.com) Remember that the full details you can use to pick up this first payment will be send to you once we receive the transfer charge of $68.00, You have to treat urgent by reconfirming your full information to us immediately you receive this massage to enable us start the process of your payment immediately.

1.Your Full Name...
2.Your Address...
3.Your Tel Number....
4.Occupation.......
5.Country....
6.City.........
7.Age..........

These are the information about your money you can go to any western union to pick up the money, don't forget that you have to settle for the transfer charge before we can give the full information of your first payment of $5000.oousd we waiting to receive the above information from your so that we can direct you where to send the transfer charge of $68.00 which is only delay now, kindly get back to us with the required information so that we can direct you where to send the fee of $68.00. We looks forward to receive the transfer charge together with your full information, to enable us release this first $5000.00usd for you to pick it up and get back to us for the second payment ok. For more information's Call +229 9986-7970. Get Back ASAP.

Yours in service
MR. richard white.
Tel: +229 99867970..
E-MAIL:(richardwhite595@gmail.com)
Western Union Benin Republic Manager.

ADMIN.IN.TH

Whois Server Version 2.1.2

Domain: ADMIN.IN.TH
Registrar: T.H.NIC Co., Ltd.
Name Server: NS1.ADMIN.IN.TH
Name Server: NS2.ADMIN.IN.TH
Status: ACTIVE
Updated date: 15 May 2014
Created date: 2 Nov 2005
Renew date: 2 Nov 2014
Exp date: 1 Nov 2015
Domain Holder: Suphachai Phirungreng ( คุณศุภชัย ไพรรุ่งเรือง )
846/121 Bongmod Tungkru Bangkok
10140 TH

Tech Contact: 68990
บริษัท แอดมิน ซิสเต็มท์ อินเตอร์เน็ต โซลูชั่น จำกัด
511/15 ถ.ประชาอุทิศ แขวงทุ่งครุ เขตทุ่งครุ กทม.
10140 TH

Wednesday, October 29, 2014

EC21 Membership Update. (EC21 Phishing)

Date: 2014.10.29

Dear Valued User:
EC21.com service verification !

Your EC21.com service account needs an important email verification due to the new upgrade on our system security server. you are therefore required to verify your email account by following the reference below:

Click here now to get your email verified >>

Thank you.
EC21 service team
support@ec21.com

Dynamic Marketplace for Global B2B – EC21
Copyright(c) EC21 Inc. All Rights Reserved.

Phishing analysis :

CLICK : Click here now to get your email verified >>
OPEN : http://sudhasheth.com/EC21.com/index.html
VALIDATE FORM :


REDIRECT : http://supplier.ec21.com/

sudhasheth.com whois :

Domain Name: SUDHASHETH.COM
Registrar URL: http://www.wildwestdomains.com
Registrant Name: sudha sheth
Name Server: NS1.GVODNS.COM
Name Server: NS2.GVODNS.COM
DNSSEC: unsigned
Registry Registrant ID:
Registrant Name: sudha sheth
Registrant Organization:
Registrant Street: 1201,Era 4,MarathonNextgen ganpatrao Kadam marg,
Registrant City: Mumbai
Registrant State/Province: Maharashtra
Registrant Postal Code: 400013
Registrant Country: India
Registrant Phone: +91.9987498648
Registrant Email: shethsudha@hotmail.com

Email analysis :

NOTE : Mime-Version : 1.0
NOTE : Content-Type : text/html
NOTE : Return-Path : < http@neo.backiel.com.pl >
NOTE : Received : from neo.backiel.com.pl (neo.backiel.com.pl. [194.88.154.10])
NOTE : Received : by neo.backiel.com.pl (Postfix, from userid 51)
NOTE : Received-Spf : client-ip=194.88.154.10;
NOTE : X-Php-Originating-Script : 51:mailer.php
NOTE : Content-Transfer-Encoding : 8bit
NOTE : EC21 Membership Update.

Diplomat Louis Thomas

From:Diplomat Louis Thomas
United State, New York.

This is to inform you that your funds of US$7.5 Million has been approved for immediate delivery to you. For the purpose of clarification,you are advised to reconfirm your Full Names,Direct Mobile, Home, Office Telephone Numbers, Your International Passport or Driver's License,Physical Address with Zip Code and your so that there will been no error during the delivery of the funds to you in your country of residence. Your quick response will be highly appreciated.

From:Diplomat Louis Thomas

Reward Notification

Final Notification

We are delighted to announce that your e-mail address has just won you the sum of $2.5 Million in our E-mail free Online draws held in England October 2014. Your e-mail emerge in category A and you are entitled to reward sum of $2.5 with this Free Ticket Numbers:EGN658214. You are advised to immediately send your contact details to Dr.John J. Dignam.on his email address (johnkig2@aol.com) Tel: +447448769707 for immediate transfer of your reward cash prize to you. N.B. Any breach of confidentiality on the part of the Winners will result to disqualification, You are to immediately contact Dr.John J Dignam only with this email (johnkig2@aol.com)

Kind Regards
Dr.John K. Dignam.
Tel: +447448769707
Email: johnkig2@aol.com

Email analysis :

NOTE : X-Msmail-Priority : Normal
NOTE : Return-Path : < 101@ushk.ru >
NOTE : Return-Path : 101@ushk.ru
NOTE : X-Mimeole : Produced By Microsoft MimeOLE V6.00.2600.0000
NOTE : Mime-Version : 1.0
NOTE : X-Priority : 3
NOTE : X-Mailer : Microsoft Outlook Express 6.00.2600.0000
NOTE : Content-Transfer-Encoding : 7bit
NOTE : X-Clientproxiedby : EX-CA-MB-01.USHK.RU (fc00:1:1:1::15)
NOTE : To EX-CA-MB-01.USHK.RU (fc00:1:1:1::15)
NOTE : Content-Type : text/plain; charset="Windows-1251"
NOTE : Received-Spf : client-ip=195.58.7.97;
NOTE : Received : from mail.ushk.ru (mail.ushk.ru. [195.58.7.97])
NOTE : Received : from User (192.168.0.1) by EX-CA-MB-01.USHK.RU (fc00:1:1:1::15)
NOTE : Final Notification