Spam message with suspicious .zip attachment: "FW: Invoice 2016-M#336962". The IP (171.248.230.145), traces to this firm. Since the attachment is either viral or phish, yes, RED.
This is a poor service provider that has numerous problems with spam, botnets, etc.that are neglected and now malware.
Spam complaints are rejected by their mail server as:
SERVER REPLY: 554 rejected due to spam content
Their on-site contact form also rejects all attempts at sending them mail since the caputcha's do not work!
This might as well be a hostile site.
www.senderbase.org/lookup/org/?search_string=Viettel%20Corporation (
viettel.com.vn / Viettel Corporation / viettel.vn has "very high" and "critical" amounts of the same spam sending IP addresses for 30 days, bottom of page.)
http://bgp.he.net/dns/viettel.com.vn#_ipinfo (the viettel.com.vn network is run by Viettel Corporation)
http://bgp.he.net/dns/viettel.vn#_ipinfo (the viettel.vn network, which has a poor reputation, is run by Viettel Corporation)
www.mywot.com/en/scorecard/viettel.vn (the poor reputation of viettel.vn, also run by Viettel Corporation)
http://bgp.he.net/AS7552#_whois (The Viettel Corporation network is supported by vnnic.net.vn, which has an unsatisfactory reputation)
www.mywot.com/en/scorecard/vnnic.net.vn (the unsatisfactory reputation of vnnic.net.vn, which is supporting viettel.com / Viettel Corporation)
OTHER:
The Corporation for Financing & Promoting Technology (FPT) / AS18403 / fpt.vn is supporting the Viettel Corporation (viettel.vn) / viettel.com.vn network, which has an unsatisfactory reputation.
http://bgp.he.net/dns/vietel.vn#_ipinfo (The Viettel Corporation (viettel.vn) / viettel.com.vn network is run by The Corporation for Financing & Promoting Technology (FPT) / AS18403 / fpt.vn
Spam sent trough open proxy hosted at Vietel Corporation. IP-Address 27.78.170.189 is an open proxy!
http://cbl.abuseat.org/lookup.cgi?ip=27.78.170.189
(Spambot infection)
Nigerian Scams
viettel.com.vn -- publishers clearing house. You have won $1,000,000. email us back mailto:pchlotto.dept@pchsweeptake.com. 2nd Unsolicited spam sent from Nigeria (41.71.201.223)
viettel.com.vn -- publishers clearing house. You have won $1,000,000. email us back mailto:pchlotto.dept@pchsweeptake.com. Unsolicited spam sent from Nigeria (41.71.178.130)
domain: viettel.com.vn
status: taken
nameserver: dns1.vietel.com.vn
nameserver: dns2.vietel.com.vn
pchsweeptake.com -- publishers clearing house. You have won $1,000,000. email us back mailto:pchlotto.dept@pchsweeptake.com. 2nd Unsolicited spam sent from Nigeria (41.71.201.223 )
pchsweeptake.com -- publishers clearing house. You have won $1,000,000. email us back mailto:pchlotto.dept@pchsweeptake.com. Unsolicited spam sent from Nigeria (41.71.178.130)
Domain name: PCHSWEEPTAKE.COM
Record created on 16-Nov-2012.
Administrative Contact:
Administrator, Domain
95 Hayden Avenue
Lexington, MA 02421
US
+1.7816526199 Fax: +1.7816526096
mailto:csadmin@vistaprint.com