ed1k
Well-known
Yesterday I got e-mail that looks like from paypal. Since I don't have paypal account I desided someone wants to open an account in my name - so I just ignored the mail. Today I got another e-mail and now I spent couple of minutes to this email, it turned out to be fraudulent mails. If someone knows paypal authority to forward information I put below, please do.
e-mail received from 207.172.196.196
Header:
Return-Path: <service@intl.paypal.com>
Delivery-Date: Fri, 09 Jun 2006 12:30:55 +0200
Received-SPF: softfail (mxeu21: transitioning domain of intl.paypal.com does not
designate 207.172.196.196 as permitted sender) client-ip=207.172.196.196;
envelope-from=service@intl.paypal.com; helo=192.168.0.2;
Received: from [207.172.196.196] (helo=192.168.0.2)
Message-ID: <RTXABOATAPUSXECNQEDOZFU@aol.com>
From: "PayPal" <service@intl.paypal.com>
Reply-To: "PayPal" <service@intl.paypal.com>
Subject: Notification of Security Measures
Date: Fri, 09 Jun 2006 13:30:54 +0200
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--8000495088998475"
Whois:
207-172-196-196.c3-0.upd-ubr14.trpr-upd.pa.cable.rcn.com (207.172.196.196)
207.172.0.0 - 207.172.255.255
RCN Corporation
196 Van Buren St.
Herndon, VA
US
RCN Corporation
noc@rcn.com[/email]
+1-888-972-6622
HTML part (there is no text body):
-begin----------------------------------------
Dear PayPal Member,
During our regularly schedule account maintenance and verification we have detected a slight error in your billing information on file with PayPal.
This might be due to either following reasons:
- A recent change in your personal information (i.e. change of address)
- Submitting invalid information during the initial sign up process.
- An inability to accurately verify your selected option of payment due an internal error within our processors.
Therefore your account has been temporarily suspended. We need you to confirm your identity in order to regain full privileges of your account.
If this is not completed by June 15, 2006, we reserve the right to terminate all privileges of your account indefinitly, as it may have been used for fraudulent purposes. We thank you for your cooperation in this manner.
To confirm your identity please follow the link below:
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run[/url]
Thank you for your patience in this matter.
PayPal - Customer Service
Please do not reply to this e-mail as this is only a notification. Mail sent to this address cannot be answered.
-end----------------------------------------
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run
actually refers to
Fraudulent server (currently up and running):
http://69-11-1-251.yktn.hsdb.sasknet.sk.ca[/url]
port:81
path:/update/index.php?MfcISAPICommand=SignInFPP
Whois:
69-11-1-251.yktn.hsdb.sasknet.sk.ca (69.11.1.251)
69.11.1.0 - 69.11.1.255
SaskTel Wide Area Network Engineering Center
2121 Sask. Dr F9
Regina, SK
CA
WIDE AREA NETWORK ENGINEERING CENTER
wanec@sasktel.sk.ca[/email]
+1-306-777-3238
e-mail received from 207.172.196.196
Header:
Return-Path: <service@intl.paypal.com>
Delivery-Date: Fri, 09 Jun 2006 12:30:55 +0200
Received-SPF: softfail (mxeu21: transitioning domain of intl.paypal.com does not
designate 207.172.196.196 as permitted sender) client-ip=207.172.196.196;
envelope-from=service@intl.paypal.com; helo=192.168.0.2;
Received: from [207.172.196.196] (helo=192.168.0.2)
Message-ID: <RTXABOATAPUSXECNQEDOZFU@aol.com>
From: "PayPal" <service@intl.paypal.com>
Reply-To: "PayPal" <service@intl.paypal.com>
Subject: Notification of Security Measures
Date: Fri, 09 Jun 2006 13:30:54 +0200
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--8000495088998475"
Whois:
207-172-196-196.c3-0.upd-ubr14.trpr-upd.pa.cable.rcn.com (207.172.196.196)
207.172.0.0 - 207.172.255.255
RCN Corporation
196 Van Buren St.
Herndon, VA
US
RCN Corporation
noc@rcn.com[/email]
+1-888-972-6622
HTML part (there is no text body):
-begin----------------------------------------
Dear PayPal Member,
During our regularly schedule account maintenance and verification we have detected a slight error in your billing information on file with PayPal.
This might be due to either following reasons:
- A recent change in your personal information (i.e. change of address)
- Submitting invalid information during the initial sign up process.
- An inability to accurately verify your selected option of payment due an internal error within our processors.
Therefore your account has been temporarily suspended. We need you to confirm your identity in order to regain full privileges of your account.
If this is not completed by June 15, 2006, we reserve the right to terminate all privileges of your account indefinitly, as it may have been used for fraudulent purposes. We thank you for your cooperation in this manner.
To confirm your identity please follow the link below:
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run[/url]
Thank you for your patience in this matter.
PayPal - Customer Service
Please do not reply to this e-mail as this is only a notification. Mail sent to this address cannot be answered.
-end----------------------------------------
https://www.paypal.com/cgi-bin/webscr?cmd=_login-run
actually refers to
Fraudulent server (currently up and running):
http://69-11-1-251.yktn.hsdb.sasknet.sk.ca[/url]
port:81
path:/update/index.php?MfcISAPICommand=SignInFPP
Whois:
69-11-1-251.yktn.hsdb.sasknet.sk.ca (69.11.1.251)
69.11.1.0 - 69.11.1.255
SaskTel Wide Area Network Engineering Center
2121 Sask. Dr F9
Regina, SK
CA
WIDE AREA NETWORK ENGINEERING CENTER
wanec@sasktel.sk.ca[/email]
+1-306-777-3238