Thursday, December 18, 2014

patria.timeweb.ru - Trying to steal your Goddady passwords!!

Be aware about an email you receive from patria.timeweb.ru, it's trying to steal your godaddy password.

They will send you an email like this:

Confirm Your Identify.

An unknown user was trieing to login your GoDaddy account with an incorrect password on Wednesday, December 17, 2014 09:16 GMT, and with an unknown DNS IP Location:
(United States) IP=104.128.84.188, as a result of that we partially blocked your GoDaddy accounts due to major security protocols,

Kindly visit our GoDaddy account Re-Activation Center Click here:

https://alert.godaddy.com/sa.aspx?security=2bdfb48c5fa7d2344b71ef45c8a7d31c


We are sincerely sorry for any inconvenience.
GoDaddy Customer Support.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Copyright (c) 1999-2014 GoDaddy.com, LLC. All rights reserved.

It's a fake email and if you look carefully you will see the link actually go's to :

http://peterssonsoft.se/KlipptSkuret/rgioefezcb.html?rgioefezcb=

and if we look at the email header we can clearly see it's not a real Godaddy email:

Delivered-To: x@x.org
Received: by 10.96.75.137 with SMTP id c9csp82269qdw;
        Thu, 18 Dec 2014 13:22:24 -0800 (PST)
X-Received: by 10.152.6.8 with SMTP id w8mr4419046law.41.1418937744199;
        Thu, 18 Dec 2014 13:22:24 -0800 (PST)
Return-Path: <maskid@patria.timeweb.ru>
Received: from patria.timeweb.ru (patria.timeweb.ru. [2a03:6f00:1::5c35:723b])
        by mx.google.com with ESMTPS id ui10si8057344lbb.62.2014.12.18.13.22.23
        for <x@x.org>
        (version=TLSv1 cipher=RC4-SHA bits=128/128);
        Thu, 18 Dec 2014 13:22:24 -0800 (PST)
Received-SPF: pass (google.com: domain of maskid@patria.timeweb.ru designates 2a03:6f00:1::5c35:723b as permitted sender) client-ip=2a03:6f00:1::5c35:723b;
Authentication-Results: mx.google.com;
       spf=pass (google.com: domain of maskid@patria.timeweb.ru designates 2a03:6f00:1::5c35:723b as permitted sender) smtp.mail=maskid@patria.timeweb.ru;
       dmarc=fail (p=NONE dis=NONE) header.from=godaddy.com
Delivery-date: Fri, 19 Dec 2014 00:22:24 +0300
To: x@x.org
Subject: Account Notice : Error 7662
MIME-Version: 1.0
Content-type: text/html; charset=UTF-8
From: Godaddy <donotreply@home.godaddy.com>
Message-Id: <E1Y1iWc-0006Qm-Tq@patria.timeweb.ru>
Date: Fri, 19 Dec 2014 00:22:22 +0300


Confirm Your Identify.<br /><br />

An unknown user was trieing to login your GoDaddy account with an incorrect password on Wednesday, December 17, 2014 09:16 GMT, and with an unknown DNS IP Location:<br> (United States) IP=104.128.84.188, as a result of that we partially blocked your GoDaddy accounts due to major security protocols,<br /><br />

Kindly visit our GoDaddy account Re-Activation Center Click here:<br />

<a href=http://peterssonsoft.se/KlipptSkuret/rgioefezcb.html?rgioefezcb=2bdfb48c5fa7d2344b71ef45c8a7d31c>https://alert.godaddy.com/sa.aspx?security=2bdfb48c5fa7d2344b71ef45c8a7d31c</a><br />
<br />
<br />
We are sincerely sorry for any inconvenience.<br />
GoDaddy Customer Support. <br />
- - - - - - - - - - - - - - - - - - - - - - - - - - - - -
<br />Copyright (c) 1999-2014 GoDaddy.com, LLC. All rights reserved.</p>
<br />
<br />