Title: Message
The DNS and web server for this domain were on dynamic-range hosts and have already been shut down.  The WHOIS registration is a little more than a week old.  Googling the net-abuse groups turns up:
 
http://groups.google.ca/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&threadm=30cd601n6r82ihedo92t155d2aou9isnan%404ax.com&rnum=1&prev=/groups%3Fq%3D%2522Pembroke%2BPines%2522%2B*.abuse.*%2B33023%26hl%3Den%26lr%3D%26ie%3DUTF-8%26oe%3DUTF-8%26selm%3D30cd601n6r82ihedo92t155d2aou9isnan%25404ax.com%26rnum%3D1
 
I can also mention that I've seen the Java.ByteVerify "virus" infect workstations running IE to install a browser helper object that filters all the pages a user sees and puts up pop-up ads.  Also homepage redirection and mangling some web page browsing.
 
The address given in "Pembroke Pines" I've seen all too many times in WHOIS records.  I suppose it's a large community/city in Florida, at 146,000 people it's the second largest city in Broward County, just north of Miami. I see a lot of spam from hosts and spammers in Florida, like CyberGate and ProHosters.
 
Andrew 8)
-----Original Message-----
From: Kami Razvan [mailto:[EMAIL PROTECTED]
Sent: Saturday, April 03, 2004 10:18 AM
To: [EMAIL PROTECTED]
Subject: [Declude.JunkMail] Phishing?

Hi;
 
I just received the following in our info account.  I believe it is a phishing attempt.
 
Attached is the actual email.
 
The source:
 
====================
<BODY>
<p><img src="" width="296" height="51"></p>
<p>Dear user!</p>
<p>We are informing you that today, the amount of $719.00 AUD has been drawn out
of your account.</p>
<p>Technical assistance of ANZ Bank.</p>
<FORM action="" method=get>
<A href=""http://www.anz.com">http://www.anz.com">
<INPUT style="BORDER-RIGHT: 0pt; BORDER-TOP: 0pt; FONT-SIZE: 10pt; BORDER-LEFT: 0pt; CURSOR: hand; COLOR: blue; BORDER-BOTTOM: 0pt; BACKGROUND-COLOR: transparent;
TEXT-DECORATION: underline" type=submit value=http://www.anz.com>
</a>
 

</form>
===================
 
I tried: http://aicworld.info/ but received a bad URL error.
 
Ideas?
 
Regards,
Kami

Reply via email to