Tentativa de phishing in numele PayPal
From: PayPal® Account Review Department
Subject: PayPalŽ Account Review Department

NU vizitati linkul din acest mesaj si nu introduceti numele de utilizator si parola PayPal pe aceea pagina!!!!
Return-path: <akstcageaitaliamnsdgs@ageaitalia.it>
Envelope-to: xxxxxxxxx@xxxxx.info
Delivery-date: Wed, 30 Jan 2008 04:51:57 -0500
Received: from [59.7.78.135] (helo=hczwdxqtynlefk6.kornet)
by server.xxxxx.info with esmtp (Exim 4.68)
(envelope-from <akstcageaitaliamnsdgs@ageaitalia.it>)
id 1JK9bf-00022i-Qt; Wed, 30 Jan 2008 04:51:56 -0500
Received: from [59.7.78.135] by mail.assitech.net; Wed, 30 Jan 2008 19:02:28 +0900
Date: Wed, 30 Jan 2008 19:02:28 +0900
From: PayPal® Account Review Department
X-Mailer: The Bat! (v3.71.14) Professional
Reply-To: akstcageaitaliamnsdgs@ageaitalia.it
X-Priority: 3 (Normal)
Message-ID: <339193093.42606877501603@ageaitalia.it>
To: xxxxxxxxx@xxxxx.info
MIME-Version: 1.0
Content-Type: text/html;
charset=iso-8859-2
Content-Transfer-Encoding: 7bit
X-Spam-Status: Yes, score=17.5
X-Spam-Score: 175
X-Spam-Bar: +++++++++++++++++
X-Spam-Report: Spam detection software, running on the system “server.xxxxx.info”, has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn’t spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Dear PayPal ® customer, We recently reviewed your account,
and we suspect an unauthorized transaction on your account. Protecting your
account is our primary concern. As a preventive measure we have temporary
limited your access to sensitive information. Paypal features.To ensure that
your account is not compromised, simply hit “Resolution Center” to confirm
your identity as member of Paypal. […]
Content analysis details: (17.5 points, 5.0 required)
pts rule name description
—- ———————- ————————————————–
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS
2.7 FH_FROMEML_NOTLD E-mail address doesn’t have TLD (.com, etc.)
2.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?59.7.78.135>]
3.0 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
[59.7.78.135 listed in zen.spamhaus.org]
1.6 HTML_IMAGE_ONLY_24 BODY: HTML: images with 2000-2400 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 BAYES_50 BODY: Bayesian spam probability is 40 to 60%
[score: 0.5000]
1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
1.8 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist
[URIs: paypal-secure-update.com]
1.5 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist
[URIs: paypal-secure-update.com]
2.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: paypal-secure-update.com]
1.5 URIBL_SBL Contains an URL listed in the SBL blocklist
[URIs: paypal-secure-update.com]
0.0 SUBJECT_NEEDS_ENCODING SUBJECT_NEEDS_ENCODING
X-Spam-Flag: YES
Subject: ***SPAM*** PayPal® Account Review Department
If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!














February 29th, 2008 at 2:38 am
[…] aceasta saptamana am primit de cateva ori acelasi mesaj, care ma atentiona ca exista o tranzactie neautorizata… Mesajul a venit pe mai toate adresele mele de […]