Forum Moderators: open
example headers of phish email:
[headers]
Received: from 190.52.234.51 by mail.richardanthony.com; Wed, 14 Oct 2009 10:49:46 -0400
From: "alerts@webmasterworld.com" <alerts@webmasterworld.com>
To: <brett@webmasterworld.com>
Subject: The settings for the brett@webmasterworld.com were changed
Date: Wed, 14 Oct 2009 10:49:46 -0400
Message-ID: <000d01ca4cdd$92c99bd0$6400a8c0@jrqat253>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0006_01CA4CDD.92C99BD0"
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.3416
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
Importance: Normal
X-IMAPbase: 1171399645 4237822960
Status: O
X-UID: 4237822957
Content-Length: 2377
X-Keywords:
[/headers]
The body of the email looks similar to:
Dear user of the webmasterworld.com mailing service!
We are informing you that because of the security upgrade of the mailing service your mailbox (brett@webmasterworld.com) settings were changed. In order to apply the new set of settings click on the following link:
<snip bogus redirect>
Best regards, webmasterworldcom Technical Support.
------------------------------
the hyper link actually goes to a redirect at:
webmasterworld.com.bertdffe.co.uk
Some of the redirect domains for ours include:
ourdomain.com.polikki.co.uk
ourdomain.com.oikkkkuy.eu
ourdomain.com.bertdffm.eu
ourdomain.com.wsasdev.eu
The phishing emails the last few days have been getting much much better. I've had a number of employees forwarding emails to me checking to make sure I want them to install software. Time to do some more education about phishing.
---------
Attention!
On October 22, 2009 server upgrade will take place. Due to this the system may be offline for approximately half an hour.
The changes will concern security, reliability and performance of mail service and the system as a whole.
For compatibility of your browsers and mail clients with upgraded server software you should run SSl certificates update procedure.
This procedure is quite simple. All you have to do is just to click the link provided, to save the patch file and then to run it from your computer location. That's all.
[.........-admins.net...]
Thank you in advance for your attention to this matter and sorry for possible inconveniences.
System Administrator
---------
I falsified the url