Phishing:
nvofoz.arghh-your-blocked.com
arghh-your-blocked.com
Can anyone help me with this, since the IP of arghh-your-blocked.com is 118.142.9.162, does that mean 118.142.9.162 should be RED for phishing?
Also, I got these links from this e-mail:
"X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0xO0Q9MTtTQ0w9Mw==
X-Message-Status: n:0
X-SID-PRA: xxx xxx
X-SID-Result: Pass
X-Message-Info: UZmYcfFpTCcqeXXib5kUxusq8uJ2JbAY/XN1wn2U0qL0FusXQ4S8tZGTj3DSEGtME47F7Zqoua+DhZBrdAzoaih6etOrPzEo
Received: from bay0-omc2-s4.bay0.hotmail.com ([65.54.246.140]) by bay0-hmmc1-f17.Bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
Sun, 6 Sep 2009 19:03:49 -0700
Received: from BAY105-W7 ([65.54.224.107]) by bay0-omc2-s4.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
Sun, 6 Sep 2009 19:03:48 -0700
Message-ID:
Return-Path: xxxxxxxxxxxxxxxxxxxx@hotmail.com
Content-Type: multipart/alternative;
boundary="_e159c4bb-41e5-4f99-9854-eab13f90690d_"
X-Originating-IP: [125.58.169.155]
From: xxx xxx
Subject: Hiya :)
Date: Sun, 6 Sep 2009 22:03:48 -0400
Importance: Normal
MIME-Version: 1.0
Bcc:
X-OriginalArrivalTime: 07 Sep 2009 02:03:48.0783 (UTC) FILETIME=[706953F0:01CA2F5F]"
Since the Originating IP is 125.58.169.155, should 125.58.169.155 be rated RED for spam too? Sorry about my horrible experience with e-mails and IPs.
The first IP
pon 07 wrz 2009 08:52:29 UTC — Athloniteseems to be coming from Hong Kong as per IP Address Finder :
http://www.ipaddressfinder.info
The second one originates from China as per IP Address Finder :
The third address in there , the 65.54.224.107 is from the US but , no City or State
So, considering the location of both of these addresses , it might be that the color fits the crime.
If you visit the IP Address Finder, it will display your IP.
Athlonite.
Your help is always needed.
65.54.224.107
pon 07 wrz 2009 15:47:54 UTC — g7w65.54.224.107
canonical name bay105-w7.bay105.hotmail.com
This is the Hotmail receiving IP; not a sender.
check it out: CentralOps
-------
Against Intuition - gives us safety through Web of Trust.
WOT Community - gives us security through unity.
Thank you all
- G7W
Just received this link
pon 07 wrz 2009 10:53:53 UTC — shazzain an email.
aykj5k.arghh-your-blocked.com
Rated the others too.
118.142.9.162
pon 07 wrz 2009 17:18:53 UTC — g7wMSN / Messenger PHISH
Check out these Google results: my.stupid.isp.did.not.update.my.dns
I could offer more images, but these all display the same way - A record IP, NS IP, AS, and eventually the "my.stupid..." pointer.
FYI, here's another similar Forum Topic
Fraud / Scam / PHISH
MSN Messenger PHISH
118.142.9.162
69.90.81.134
69.90.81.135
I-blocked-you.com
I-got-blocked.com
Oops-you-were-blocked.com
arghh-your-blocked.com
aww-you-got-blocked.com
ns1.I-blocked-you.com
ns1.I-got-blocked.com
ns1.Oops-you-were-blocked.com
ns1.arghh-your-blocked.com
ns1.aww-you-got-blocked.com
ns2.I-blocked-you.com
ns2.I-got-blocked.com
ns2.Oops-you-were-blocked.com
ns2.arghh-your-blocked.com
ns2.aww-you-got-blocked.com
-------
Against Intuition - gives us safety through Web of Trust.
WOT Community - gives us security through unity.
Thank you all
- G7W
Done
nie 13 wrz 2009 19:49:08 UTC — Xp54321Rated and commented.
Thanks.
:-)
—Xp54321
zlhcj.fast-blocked-stats.com
wto 27 paź 2009 08:29:24 UTC — shazzaNew email:
'Heyloo!
where had you been? ...
anyway here you go
Check it out... :)
It's Easy, Secure and Free!
Try it Now, Click Here
Regards'
zlhcj.fast-blocked-stats.com
fast-blocked-stats.com
Phishtank link
Rated, agreed and voted yes.
wto 27 paź 2009 09:25:24 UTC — cconniejeanRated, agreed and voted yes.
Thanks
wto 27 paź 2009 13:22:05 UTC — edilsoncaldasThanks, rated and commented!
Obrigado, foram classificados e comentados!
--------------------------------------------------------------------------------------------
WOT Community - Por uma internet mais segura!
Just a few more!
wto 27 paź 2009 20:48:41 UTC — shazzaSee malwareurl.com
ahh-im-blocked.com
bad-luck-im-blocked.com
bingoo-check-block-status.com
cindrella-blocked-me.com
damnn-they-blocked-me.com
did-they-block-you.com
duh-i-got-blocked.com
face-blocked-truth.com
finding-who-blocks.com
find-reason-of-being-blocked.com
friends-block-buddies.com
grab-my-block-status.com
have-they-blocked-you.com
hell-they-blocked-you.com
heroes-never-block.com
hey-you-block-me.com
how-come-they-block-me.com
huhu-bing-block-statuses.com
huh-yes-i-was-blocked.com
ima-checking-block-status.com
im-fedup-of-being-blocked.com
jealous-buddies-block.com
jesus-he-blocked-us.com
jesus-im-blocked.com
lame-friends-block-you.com
let-people-laugh.com
let-them-hehe.com
mean-friends-block.com
my-friends-block-me.com
my-mates-blocked-me.com
no-damn-way-im-blocked.com
no-way-im-blocked.com
ohhh-damn-im-blocked.com
ohh-ma-friend-blocked-me.com
oh-i-was-blocked.com
oh-my-god-im-blocked.com
oh-strange-im-blocked.com
oh-weird-im-blocked.com
phew-they-blocked-me.com
puff-im-blocked.com
sad-i-was-blocked.com
see-they-blocked-me.com
strange-i-was-blocked.com
they-were-haha.com
uffff-i-was-blocked.com
ufff-i-was-blocked.com
ufff-seems-blocked.com
uh-ho-i-got-blocked.com
umm-jesus-im-blocked.com
unlucky-im-blocked.com
urr-he-blocked-me.com
urr-he-blocked-us.com
who-let-me-block.com
why-my-friends-block.com
wooh-im-blocked.com
yuppy-find-block-statuses.com
Also
wto 27 paź 2009 22:09:52 UTC — g7w121.54.174.85
Thanks for the announcement and the dig.
All rated and commented.
-------
WOT Services Ltd. - gives us safety through Web of Trust.
WOT Community - gives us security through unity.
Thank you all
- G7W
and more ...
wto 03 lis 2009 15:25:31 UTC — shazzaSee malwareurl.com
and hpHosts
amazed-i-wasnt-blocked.com
amazing-true-block-checks.com
anytime-block-grabber.com
anytime-grab-block-status.com
biggest-block-check-service.com
broadband-block-checker.com
famous-block-status-check.com
fast-blocked-stats.com
friends-who-blocked-you.com
get-info-on-blocked-stats.com
get-superb-block-checks.com
global-block-checking.com
heheh-i-wasnt-blocked.com
heroes-cant-be-blocked-hehe.com
my-block-checker.com
oh-my-i-was-on-a-block-list.com
premium-block-checking.com
rino-block-get-services.com
see-live-block-stats.com
sonic-block-checking.com
super-doper-block-finding.com
supereme-block-checks.com
super-fast-block-checker.com
ultimate-block-checker.com
ultimate-block-checking.com
woooh-i-was-not-blocked.com
look-whos-blockin-you.com
Also (not listed yet)
see-the-live-block-stats.com
EDIT: More added - same sources as above
you-blocked-me-now-suffer.com
aaouch-im-blocked.com
ahh-unblock-me.com
block-me-before-i-block-u.com
blogger-are-blocked.com
cannon-digital-photos.com
chigy-people-who-blocks.com
chunii-block-checks.com
cool-pool-blocked-services.com
crunchy-block-checkings.com
damn-them-they-blocked-me.com
darn-im-blocked.com
digi-wigi-block-checker.com
findout-liars-who-blocked-you.com
find-out-live-block-stats.com
grab-liars-who-blocked-you.com
high-ranked-block-checks.com
i-photo-shoot-you.com
juggy-blocked-services.com
lol-at-you-haha.com
lool-i-saw-you.com
miggy-liggy-block-statistics.com
ohh-pinky-blocked-me.com
oh-jesus-im-blocked.com
omg-omg-im-blocked.com
ooo-shit-im-blocked.com
shout-at-people-who-block.com
superb-blocked-checking.com
the-naughty-play.com
tingy-tungy-blocking-stats.com
try-blocking-me-again.com
yellow-block-checker.com
yesterdays-party.com
your-head-is-a-block.com
your-mom-got-blocked-cuz-she-ugly.com
you-were-nervous.com
you-were-not-like-that.com
Rated and commented.
wto 03 lis 2009 16:10:40 UTC — cconniejeanRated and commented.
Phishing sites moved to new IP
śro 04 lis 2009 21:04:10 UTC — jonathanyaniv121.54.171.191
121.54.171.150
Those two IP's above are hosting the sites now
121.54.171.191 is the new one hosting the domains
tiny-pic-url.com or 69.90.81.143 is the domain/ip hosting the phishing site images.
The site is blocked as dangerous by Microsoft Security Essentials being defined as PWS:HTML/Msnblock.A
Done
sob 14 lis 2009 04:31:35 UTC — Xp54321Rated and commented.
Thanks.
:-)
—Xp54321