re: AVO INC - avo.net
вот прислали письмо, якобы Liberty Reserve:
от злобного хацкера: X-original-sender:
[email protected]
Delivered-To:
[email protected]
Received: by 10.152.131.164 with SMTP id on4csp895797lab;
Thu, 18 Oct 2012 07:13:31 -0700 (PDT)
Received: by 10.216.207.163 with SMTP id n35mr13174071weo.220.1350569609585;
Thu, 18 Oct 2012 07:13:29 -0700 (PDT)
Return-Path: <
[email protected]>
Received: from telefonica.net (impaqm1.telefonica.net. [213.4.138.17])
by mx.google.com with ESMTP id i20si27589511wej.51.2012.10.18.07.13.29;
Thu, 18 Oct 2012 07:13:29 -0700 (PDT)
Received-SPF: fail (google.com: domain of
[email protected] does not designate 213.4.138.17 as permitted sender) client-ip=213.4.138.17;
Authentication-Results: mx.google.com; spf=hardfail (google.com: domain of
[email protected] does not designate 213.4.138.17 as permitted sender)
[email protected]
Received: from IMPmailhost6.adm.correo ([10.20.102.127])
by IMPaqm1.telefonica.net with bizsmtp
id CV601k00q2kvMAa3MeDVgE; Thu, 18 Oct 2012 16:13:29 +0200
Received: from NETWORK-F27C9F1 ([31.193.0.28])
by IMPmailhost6.adm.correo with BIZ IMP
id CeDT1k0010cF3BT1meDUax; Thu, 18 Oct 2012 16:13:29 +0200
X-Brightmail-Tracker: AAAAAA==
X-original-sender:
[email protected]
Message-ID: <00f9f67f-41200-033f5925589468@network-f27c9f1>
Reply-To: "
[email protected]" <
[email protected]>
From: "
[email protected]" <
[email protected]>
To:
[email protected]
Subject: Submit your Verification PIN.
Date: Thu, 18 Oct 2012 14:13:17 -0400
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028
</font>
</div>
<td colspan=2>
<div class=msg>
<br><br>==============================<WBR>======= =======<br><div>
Please note that in all e-mails from Liberty Reserve we will:<br>
Always inform you about security changes.<br>
Never ask you to send us your password and/or login PIN.<br>
==============================<WBR>==============< br>
<br> Dear,
[email protected]
<br>
<br>We detected that your account was accessed from a different location (IP: 42.66.13.235, Country: NG).
<br>We sent a verification PIN to your email.<br>
<br> Verification PIN: 82146-57115<br>
<br> We have put your account on pending until you will submit our Verification PIN<br>
<br> Now you need to click the link below and submit your information.
<br> If you don't complete our request your account will be blocked.
<br><br>
<a rel="nofollow" href="https://kurdg.net/liberty.php" target="_blank">https://www.libertyreserve.com/en/login</a><br>
<br>
<br>Please DO NOT reply to this e-mail.<br>
<br>
<br>
<br><br>
2002-2012 Liberty Reserve S.A. All rights reserved. <br><br><br><br></div></blockquote></td></tr>
</div>
добавлено через 1 минуту
и второе якобы от AVO INC <
[email protected]>
а на самом деле от злобного хацкера: envelope-from <
[email protected]>
Delivered-To:
[email protected]
Received: by 10.152.131.164 with SMTP id on4csp885968lab;
Thu, 18 Oct 2012 06:12:07 -0700 (PDT)
Received: by 10.42.52.5 with SMTP id h5mr3341875icg.50.1350565926185;
Thu, 18 Oct 2012 06:12:06 -0700 (PDT)
Return-Path: <
[email protected]>
Received: from node2.icnbox.com ([2404:4800:20:1:21e:c9ff:fed0:72c7])
by mx.google.com with ESMTPS id e6si35203339paw.27.2012.10.18.06.12.05
(version=TLSv1/SSLv3 cipher=OTHER);
Thu, 18 Oct 2012 06:12:06 -0700 (PDT)
Received-SPF: neutral (google.com: 2404:4800:20:1:21e:c9ff:fed0:72c7 is neither permitted nor denied by best guess record for domain of
[email protected]) client-ip=2404:4800:20:1:21e:c9ff:fed0:72c7;
Authentication-Results: mx.google.com; spf=neutral (google.com: 2404:4800:20:1:21e:c9ff:fed0:72c7 is neither permitted nor denied by best guess record for domain of
[email protected])
[email protected]
Received: from cloudbub by node2.icnbox.com with local (Exim 4.80)
(envelope-from <
[email protected]>)
id 1TOptK-0000q5-H9
for
[email protected]; Thu, 18 Oct 2012 21:12:02 +0800
To:
[email protected]
Subject: AVO INC Notification.
From: AVO INC <
[email protected]>
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <
[email protected]>
Date: Thu, 18 Oct 2012 21:12:02 +0800
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - node2.icnbox.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [500 32007] / [47 12]
X-AntiAbuse: Sender Address Domain - node2.icnbox.com
X-Source: /usr/bin/php
X-Source-Args: /usr/bin/php /home/cloudbub/public_html/images/dediuyhded.php
X-Source-Dir: cloudbubble.net:/public_html/images
Important Message ! :-<br><br>
Please note that your Avo Inc online service account is about to expire due to new database<br><br>
transfiguration on our system,please use the enable new database to prevent account from<br><br>
fraudulent activities.Your interest is our concern so you will have to bear with us for<br>
few minutes online.
<a href="https://www.crosscountryadventures.us/images/www.avo.net/www.avo.net.html">https://support.avo.net/index.php?/Validate/ft5eju6p6j5ngvu8lcawiyuad6bf8wuc4</a>
<br/><br/>Please let us know if we can be of any further assistance,<br/>
<br/>AVO INC<br/>
<HR style="margin-bottom: 6px; height: 1px; BORDER: none; color: #cfcfcf; background-color: #cfcfcf;" />
Support Center: https://support.avo.net/<br/>
</font>
добавлено через 5 минут
если не посмотреть исходный текст письма - очень похоже на официальные. Вот люди! Видно же как можно заработать честно, нет надо вот так подленько.