The following is an example of a new phishing email.
Dear user of the bjantiques.net mailing service! We are informing you that because of the security upgrade of the mailing service your mailbox (xxxxxxxx@bjantiques.net) settings were changed. In order to apply the new set of settings click on the following link: http://bjantiques.net/owa/service_directory/settings.php?email=xxxxx@bjantiques.net&from=bjantiques.net&fromname=xxxxxxxx Best regards, bjantiques.net Technical Support.
the above is what you see but the link leads to
http://bjantiques.net.oikkkkuf.co.uk/owa/service_directory/setti= ngs.php?email=3Dxxxxxxxx@bjantiques.net&from=3Dbjantiques.net&fromname=3D= xxxxxxxxx
Note how they have created a subdomain of bjantiques.net at the domain oikkkkuf.co.uk bjantiques.net.oikkkkuf.co.uk/
I am not worried about posting this example as I successfully got the domain terminated by the registrar that it was registered with, however be warned this moron has created a lot of domains and many of them are .eu but they could be using any DL or TDL extension.
Now this was very easy for me to spot as a scam as I am the sole controler of what happens on Bjantiques.net but if you are using an email service supplied by someone else BEWARE. as it wont be easy for you to spot.
Look out for any subject line like A new settings file for the xxxxxxx@bjantiques.net Settings have been changed for xxxxxxxxx@xxxxxxxxx.xx and so on.
|