Phishing: PayPal Account Review Department
Posted by admin on Wednesday, June 13th, 2012 | 7,053 views
Phishing email against PayPal users:

Header details:
Received: from mail14j.g14.rapidsite.net (mail14j.g14.rapidsite.net [128.121.64.175]) Received: from ca1-mx26.mlpsca01.us.mxservers.net (128.121.64.172) by mail14j.g14.rapidsite.net Received: from unknown [128.121.143.147] (EHLO mmm1430.rapidsite.net) by ca1-mx26.mlpsca01.us.mxservers.net (mxl_mta-3.1.0-05) Received: from unknown (HELO mikesmirnoff-%cf%ca.local) (marketing@77.50.19.97) Subject: Account Review Department Date: Wed, 13 Jun 2012 12:27:42 +0400 X-SOURCE-IP: [128.121.143.147] To:undisclosed-recipients:; Content-Disposition: attachment; filename="Account.zip" |
Attached there is a ZIP file named:
File: Account.zip Size: 6694 bytes MD5: 6AC253515AB76EE76D1E034AEC75FCD7 SHA1: 485E0A670CFE47F247C0BF6073D089A305BB6BEB SHA256: 6EE32A16EC8711A741B7E9E74D2289ED91F078D5A91425B7F8BAC74D74BAD9BA SHA384: A39150F4A3ADBFF90E53D0C9A2DCF36023DB1F7DB9D84AA5B6C54433502A544658F2E323B4064B7451D73058E12D4DFB SHA512: BFE5443A418DBDF4B051AA7FD92F299A51A8972221B73D8B708AF7174E29F9132F3D3B645E8A7F33616CAC5EE1CCF2DBDE89D7D57B29C69AE47F1B8B979BBD6B |
The extracted file is a .HTML file:
File: Account Verification.html Size: 32224 bytes MD5: FAF8A01884CC8E3941684659E015E8EB SHA1: 9B24726C5B982DB8FE7E88E356B6CCDF74187344 SHA256: A5094D44CA1DFCEA0ED5D17DAD9385B2FCF043AB9C52E0C6FC061E38FFEC2E2D SHA384: 3B64DE5DCED0F7F255298C20852216F4C681E9BD2C8A9B571058528775F45DFA9D1116F3462F50B0F170DD1EA246F4D4 SHA512: 6D07323C6E4AEEEF56F75178F3EC8CDECCACBBAD16F2AC66B173CAD90E2AC6CDEC6501338563E8719398836162E208BDB129A554F10C4E6B9C9890C53F1E652E |
The sensitive data filled by the user is sent to this malicious URL:
hxxp:// akamai2.spteiqnaskqliliasnqxikcmenmn .ru /~jeremy/ze.php |
Whois Details:
domain: SPTEIQNASKQLILIASNQXIKCMENMN.RU nserver: ns1.nameself.com. nserver: ns2.nameself.com. state: REGISTERED, DELEGATED, UNVERIFIED person: Private Person registrar: REGTIME-REG-RIPN admin-contact: http://whois.webnames.ru created: 2011.08.17 paid-till: 2012.08.17 free-date: 2012.09.17 source: TCI |
URLVoid report:
http://www.urlvoid.com/scan/spteiqnaskqliliasnqxikcmenmn .ru



