The website profitscoaching .info is hosted at WholeSale Internet and its current IP address is 188.8.131.52 (-). The server machine is located in United States (US) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is profitscoaching. The organization is Gold VIP Club.
The malicious link redirects users to another malicious link:
The website aooale.info is hosted at DirectSpace Networks, LLC. and its current IP address is 184.108.40.206 (-). The server machine is located in United States (US) and in the same server there are hosted other 0 websites. The domain is registered with the suffix INFO and the keyword of the domain is aooale. The organization is DirectSpace Networks, LLC.
We have received various spam emails that simulate messages from Better Business Bureau (BBB), but in real are used to spread malicious links that leads to Blackhole Exploit Kit. The subject of the emails looks like this:
Your updated information is necessary
A screenshot of the email:
Other details of the emails:
Received: from msr6.hinet.net (msr6.hinet.net [220.127.116.11])
Received: from ms16.hinet.net ([18.104.22.168])
Date: Thu, 26 Jan 2012 22:49:15 +1000
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:22.214.171.124) Gecko/20100713 Lightning/1.0b2 Thunderbird/3.1.1
Subject: Your updated information is necessary
Another email containing malicious URL used for phishing attack against MasterCard and Visa users:
Received: from mailrtr1.deltacom.net (mailvip.deltacom.net [126.96.36.199])
Received: from User ([188.8.131.52]) by mailrtr1.deltacom.net (MOS 4.1.10-GA)
Subject: Votre carte bancaire est suspendue
Date: Sun, 7 Aug 2011 00:12:08 -0500
Bonjour clients de visa carte,
Votre carte bancaire est suspendue, parce que nous avons rencontre un probleme sur votre diagramme.
Nous avons determine qu'une personne doit peut-etre utiliser votre diagramme sans votre autorisation.
Pour votre protection, nous avons suspendu votre compte bancaire a travers votre carte de credit. Pour soulever cette suspension,
et suivre le procede indique pour mettre a jour votre compte par la carte de credit.
Received: from mail.ktmtalk.com (mail.ktmtalk.com [184.108.40.206])
Received: from User [220.127.116.11] by mail.ktmtalk.com with ESMTP
From: "eBay Member jxavier14"<firstname.lastname@example.org>
Subject: New Unpaid Item Message from jxavier14: #14027471062 -- response required
Date: Sat, 6 Aug 2011 06:34:47 -0500
eBay member charly1 has left you a message regarding item #14020078062
View the dispute thread to respond.
Another email that is used to spread a fake PayPal message containing a malicious link used for phishing attack against PayPal users:
Received: from mailrtr4.deltacom.net (mailvip.deltacom.net [18.104.22.168])
Received: from User ([22.214.171.124]) by mailrtr4.deltacom.net (MOS 4.1.10-GA)
Subject: Centre de securite PayPal
Date: Sat, 6 Aug 2011 00:11:18 -0500
Received: from [126.96.36.199] (account email@example.com HELO ybydypsmsb.cehflcrileuz.ru)
From: "United Parcel Service" <firstname.lastname@example.org>
Subject: United Parcel Service notification #46034
May 2011United Parcel Servicetracking number #18203 Good morningParcel
notificationThe parcel was sent your home adress.And it will arrive within 3
buisness days. More information and the parcel tracking number are attached in
document below.Thank you United Parcel Service of America (c)153 James Street,
Suite100, Long Beach CA, 90000
Received: from WIN-ATAF5I4OOP1 (unknown [188.8.131.52])
Received: from User ([127.0.0.1]) by WIN-ATAF5I4OOP1
Subject: Your Paypal Account Will Be Limited
Date: Tue, 17 May 2011 18:38:40 -0700
Note that the email come from:
The domain paybal.com is parked!
Malicious URL that redirects to the phishing PayPal login page:
Received: from 18714128077.user.veloxzone.com.br (unknown [184.108.40.206])
Received: from [220.127.116.11] (helo=qnmekzdssguat.bacphgvlbnez.ua)
From: "Puremobile Inc." <email@example.com>
Subject: Your Order No 218538 - Puremobile Inc.
Thank you for ordering from Puremobile Inc.
This message is to inform you that your order has been received and is currently
Your order reference is 372662.
You will need this in all correspondence.
This receipt is NOT proof of purchase.
We will send a printed invoice by mail to your billing address.
You have chosen to pay by credit card.
Your card will be charged for the amount of 045.00 USD and "Puremobile Inc." will
appear next to the charge on your statement.
Your purchase information appears below in the file.