Search FraudFYI

Tuesday, March 15, 2016

PHISHING/MALWARE ALERT! PHISHING/MALWARE scam email from Email Alert jadelhegazy@horizondoors.co www.kemenpppa.go.id/media/jusertube/mailbox/index.php

DO NOT CLICK ON THE LINK IN THIS EMAIL!  This email IS NOT FROM YOUR EMAIL PROVIDER and the link DOES NOT TAKE YOU TO YOUR EMAIL!  The link takes you to http://www.kemenpppa.go.id/media/jusertube/mailbox/index.php which is not only PHISHING for your email log-in, but may also contain MALWARE!

From VirusTotal.com:
Netcraft     Malicious site
BitDefender     Phishing site
ESET     Phishing site
Malwarebytes hpHosts     Phishing site

from: E-mail Alert <jadelhegazy@horizondoors.co> 
to:
date: Sun, Mar 13, 2016 at 5:44 AM
subject: Dear
mailed-by: horizondoors.co

Dear 

Your mailbox is almost full.

1969MB           2000MB
Current size           Maximum size

Your Mailbox Has Exceeded It Quota/Limit, And You May Not Be Able To Send Or Receive New Mails Until You Re-Validate It.

To Re-Validate, Please Click : Re-Activate to add more MB to your mailbox.

From the HTML of the email:
<A style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; COLOR: rgb(25,106,212); LINE-HEIGHT: 32px; PADDING-TOP: 0px; BACKGROUND-COLOR: transparent; outline-style: none; outline-width: medium" href="http://www.kemenpppa.go.id/media/jusertube/mailbox/index.php" target=_blank rel=nofollow data-mce-style="line-height: 32px; background-color: transparent; margin: 0px; outline-style: none; outline-color: invert; outline-width: medium; color: #196ad4; padding: 0px;" data-mce-href="http://bit.ly/1pxstym">Re-Activate</A>

No comments:

Post a Comment

Thank you for commenting! Your comment will be reviewed and posted shortly!