Email phising scam dari NortonScanEmail.com

Pagi ini salah satu user gw mendapat email dari mailscan@norton.com dengan isi sebagai berikut :

From: Administrator [mailto:mailscan@norton.com]
Sent: Tuesday, 27 May 2014 12:00 p.m.
To: xxx 
Subject: Your email account ( xx@yyy.com) will be shut down

Dear xxx,

Your email address ( xx@yyy.com), has been transmitting viruses to our servers and because of this, your email will be deactivated permanently if not resolved.

In respect to the above, you are urgently required to sanitize your email with Norton E-mail Scanner; otherwise, your access to email services will be deactivated

Click here now to scan and sanitize your e-mail account<http://nortonscanemail.com/nortcc778ujei882jfe21bc8irfe229811b&gt;

Note that failure to sanitize your account immediately will lead to permanent deactivation of your email account without warning.

We are very sorry for the inconveniences this might have caused you and we assure you that everything will return to normal as soon as you have done the needful.

Admin

Cuma liat sebentar, gw bisa langsung tahu kalo ini pasti phising, apalagi link yang dituju di nortonscanemail.com itu berujung pada permintaan username dan password.

Out of curiosity, gw coba lookup domain tersebut dan menemukan data sebagai berikut:

  • Domain Name: NORTONSCANMAIL.COM
  • Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
  • Whois Server: whois.melbourneit.com
  • Referral URL: [link removed] Name Server: YNS1.YAHOO.COM
  • Name Server: YNS2.YAHOO.COM
  • Status: clientTransferProhibited
  • Updated Date: 27-oct-2013
  • Creation Date: 27-oct-2013
  • Expiration Date: 27-oct-2014
  • IP Address : 98.139.135.21
  • Country Code : US
  • Country : United States
  • GPS : 38 latitude / -97 Longitude
Advertisements