Bitcoin Forum

Economy => Scam Accusations => Topic started by: escrow.ms on July 04, 2014, 04:28:19 PM



Title: Phishing Alert (mail-blockchain dot info)
Post by: escrow.ms on July 04, 2014, 04:28:19 PM
http://who.is/whois/mail-blockchain.info
https://i.imgur.com/CKPj4Z6.png


This domain is a redirect to hxxp://blokchaln.info

http://who.is/whois/blokchaln.info

Source:
Quote
                                                                                                                                                                                               
http://pastie.org/9355244


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: elviselvis101 on July 04, 2014, 04:59:53 PM
Got the same and was looking and clicking in my gmail to find "blokchaln.info" - but can not.
How did you find that info ?


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: SelbyTsang on July 04, 2014, 05:04:04 PM
How did you find that info ?

You can check the full email header by the following steps.

https://support.google.com/mail/answer/22454?hl=en
Quote
1. Log in to Gmail
2. Open the message you'd like to view headers for.
3. Click the down arrow next to Reply, at the top of the message pane.
4. Select Show Original.
The full headers will appear in a new window.


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: elviselvis101 on July 04, 2014, 05:20:43 PM
How did you find that info ?

You can check the full email header by the following steps.

https://support.google.com/mail/answer/22454?hl=en
Quote
1. Log in to Gmail
2. Open the message you'd like to view headers for.
3. Click the down arrow next to Reply, at the top of the message pane.
4. Select Show Original.
The full headers will appear in a new window.

Thanks, I already did that but can not see the "misspelling" of blockchain ;

Delivered-To: @gmail.com
Received: by 10.64.225.226 with SMTP id rn2csp313690iec;
        Fri, 4 Jul 2014 09:14:33 -0700 (PDT)
X-Received: by 10.236.180.169 with SMTP id j29mr17834267yhm.47.1404490473381;
        Fri, 04 Jul 2014 09:14:33 -0700 (PDT)
Return-Path: <apache@blockchain.info>
Received: from mail.blockchain.info ([69.197.35.141])
        by mx.google.com with ESMTP id t65si34781667yhb.12.2014.07.04.09.14.32
        for <@gmail.com>;
        Fri, 04 Jul 2014 09:14:33 -0700 (PDT)
Received-SPF: fail (google.com: domain of apache@blockchain.info does not designate 69.197.35.141 as permitted sender) client-ip=69.197.35.141;
Authentication-Results: mx.google.com;
       spf=hardfail (google.com: domain of apache@blockchain.info does not designate 69.197.35.141 as permitted sender) smtp.mail=apache@blockchain.info;
       dmarc=fail (p=NONE dis=NONE) header.from=blockchain.info
Received: by mail.blockchain.info (Postfix, from userid 48)
   id 21F3A358194; Fri,  4 Jul 2014 09:14:32 -0700 (PDT)
To:@gmail.com
Subject: Blockchain - Transaction Received
Date: Fri, 4 Jul 2014 09:14:32 -0700
From: Blochchain <no-reply@blockchain.info>
Message-ID: <b623ebaff1423f01627539a43f104403@69.197.35.141>
X-Priority: 3
X-Mailer: PHPMailer 5.0.2 (phpmailer.codeworxtech.com)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="UTF-8"

<!DOCTYPE html>
<html>
<head>


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: rohnearner on July 04, 2014, 07:41:00 PM
Thanks for the heads up
I got similar mail to my mailing account few days ago , telling me that " My Wallet Account has been locked " Followed by a suspicious link asking me to click to unlock my account . I avoided clicking any link but I'm used to getting these mails now and I avoid clicking any link which appears even lil suspicious.
 
https://i.imgur.com/DYBVGc4.jpg


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: Justin00 on July 04, 2014, 11:46:02 PM
I receive soooooo many emails from fake

-spendbitcoins
-btc-e
-coinedup
-blockchain.info

and many more. They all have the same JAR file virus attachment.

I don't even use some of those sites so they obviously just try there luck i'll be retarded and open the JAR file.



Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: escrow.ms on July 05, 2014, 05:16:55 AM
Got the same and was looking and clicking in my gmail to find "blokchaln.info" - but can not.
How did you find that info ?

If you will open mail-blockchain dot info in your browser it will redirect you to blokchln dot info where phishing page is hosted.


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: elviselvis101 on July 05, 2014, 08:36:27 PM
Got the same and was looking and clicking in my gmail to find "blokchaln.info" - but can not.
How did you find that info ?

If you will open mail-blockchain dot info in your browser it will redirect you to blokchln dot info where phishing page is hosted.

ahe, now I get it - missed the .info / .com part  :)


Title: Re: Phishing Alert (mail-blockchain dot info)
Post by: smoothie on July 10, 2014, 12:46:03 AM
I've been getting these emails sporadically for the past 6-8 months. Always go in my trashcan lol.