Phishing: PayPal Account Review Department

Phishing email against PayPal users:

Phishing Email

Header details:

Received: from mail14j.g14.rapidsite.net (mail14j.g14.rapidsite.net [128.121.64.175])
Received: from ca1-mx26.mlpsca01.us.mxservers.net (128.121.64.172) by mail14j.g14.rapidsite.net
Received: from unknown [128.121.143.147] (EHLO mmm1430.rapidsite.net) by ca1-mx26.mlpsca01.us.mxservers.net (mxl_mta-3.1.0-05)
Received: from unknown (HELO mikesmirnoff-%cf%ca.local) (marketing@77.50.19.97)
Subject: Account Review Department
Date: Wed, 13 Jun 2012 12:27:42 +0400
X-SOURCE-IP: [128.121.143.147]
To:undisclosed-recipients:;
Content-Disposition: attachment; filename="Account.zip"

Attached there is a ZIP file named:

File: Account.zip
Size: 6694 bytes
MD5: 6AC253515AB76EE76D1E034AEC75FCD7
SHA1: 485E0A670CFE47F247C0BF6073D089A305BB6BEB
SHA256: 6EE32A16EC8711A741B7E9E74D2289ED91F078D5A91425B7F8BAC74D74BAD9BA
SHA384: A39150F4A3ADBFF90E53D0C9A2DCF36023DB1F7DB9D84AA5B6C54433502A544658F2E323B4064B7451D73058E12D4DFB
SHA512: BFE5443A418DBDF4B051AA7FD92F299A51A8972221B73D8B708AF7174E29F9132F3D3B645E8A7F33616CAC5EE1CCF2DBDE89D7D57B29C69AE47F1B8B979BBD6B

The extracted file is a .HTML file:

File: Account Verification.html
Size: 32224 bytes
MD5: FAF8A01884CC8E3941684659E015E8EB
SHA1: 9B24726C5B982DB8FE7E88E356B6CCDF74187344
SHA256: A5094D44CA1DFCEA0ED5D17DAD9385B2FCF043AB9C52E0C6FC061E38FFEC2E2D
SHA384: 3B64DE5DCED0F7F255298C20852216F4C681E9BD2C8A9B571058528775F45DFA9D1116F3462F50B0F170DD1EA246F4D4
SHA512: 6D07323C6E4AEEEF56F75178F3EC8CDECCACBBAD16F2AC66B173CAD90E2AC6CDEC6501338563E8719398836162E208BDB129A554F10C4E6B9C9890C53F1E652E

The sensitive data filled by the user is sent to this malicious URL:

hxxp:// akamai2.spteiqnaskqliliasnqxikcmenmn .ru /~jeremy/ze.php

Whois Details:

domain:        SPTEIQNASKQLILIASNQXIKCMENMN.RU
nserver:       ns1.nameself.com.
nserver:       ns2.nameself.com.
state:         REGISTERED, DELEGATED, UNVERIFIED
person:        Private Person
registrar:     REGTIME-REG-RIPN
admin-contact: http://whois.webnames.ru
created:       2011.08.17
paid-till:     2012.08.17
free-date:     2012.09.17
source:        TCI

URLVoid report:

http://www.urlvoid.com/scan/spteiqnaskqliliasnqxikcmenmn .ru

Random Posts

Previous Posts

Comments are closed.