「迷惑」タグアーカイブ

件名 “By tomorrow evening this stock will be twenty times higher”は、迷惑メールです。

友人からの報告です。
初歩的な偽装迷惑メールです。

宛先
自分メアド
差出人
From: “Hester Marquez”
返信先

件名
Subject: By tomorrow evening this stock will be twenty times higher
内容

Did you read my urgent email yesterday?
I outlined very specifically a game plan for you to make more than 20 times on your principle within the next 48 hours.
Let me hit you with the gravy and leave out all the boring details� there’s a friend of mine who works at a top 50 firm upstate and he was privy to details of a take over.
In a nutshell there is a very large pharmaceutical company (its name starts with a P) who is finalizing the acquisition of a small public corporation that is currently trading at around 80 cents.
The take over price will be a little over 20 bucks and the official announcement is coming tomorrow night (wed night).
They’re paying this much for it because of a novel stem cell treatment which eradicates cancer.
I don’t need to tell you what will happen to the share price when this announcement hits the news outlets.
The company’s trading symbol is Q as in Quest, S as in Sam, M as in Mother, G as in Great.
These are the 4 letters you need to type into your brokerage account to buy the stock or give to your broker over the phone.
Just ten thousand bucks into this will turn into over two hundred grand by Thursday morning.
You need to act quickly though because it seems I may not be the only one with this information, as I am seeing the price creep up a little already since Monday.
—–
Best Regards,
Hester Marquez
———————————————-

添付ファイル なし

———————————————-
ソース
From – Wed Apr
X-Account-Key:
X-UIDL:
X-Mozilla-Status:
X-Mozilla-Status2: 0
X-Mozilla-Keys:
Return-Path:
X-Original-To:
Delivered-To:
Received: from bdg-gh-universal2.skyline.net.id (BDG-GH-UNIVERSAL2.skyline.net.id [202.52.12.234])

for
Received: (from apache@localhost)
by skyline.net.id (8.14.7/8.14.7/Submit) id ;
T
Message-Id: <@skyline.net.id>
To:
Subject: By tomorrow evening this stock will be twenty times higher
X-PHP-Originating-Script: 20009:Api.php
From: “Hester Marquez”
Date: Tue, 2
Content-Type:
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
X-EsetId:

以下省略
————————————————————————
from bdg-gh-universal2.skyline.net.id (BDG-GH-UNIVERSAL2.skyline.net.id [202.52.12.234])
IP Address 202.52.12.234
Host Name BDG-GH-UNIVERSAL2.skyline.net.id
Country Indonesia
Network(ASN) SAPTANET-SKYLINE-ID
IP Prefix 202.52.12.129 – 202.52.12.255
————————————————————————

————————————————————————

件名 “This company’s being acquired tomorrow”は、迷惑メールです。

友人からの報告です。
初歩的な偽装迷惑メールです。

宛先
自分メアド
差出人
From: “Guillermo Richardson”
返信先

件名
This company’s being acquired tomorrow
内容

The cat might be out of the bag now but there is still a massive opportunity to benefit.
I say that the secret is out because the stock price has gone up two days in a row but the reality is that it must be very few people who know information otherwise it would’ve gone ten times higher.
In case you missed my message yesterday, here is what is happening.. A big pharma corp is acquiring a minuscule public co and this is happening at a price that is 20 times greater than where it currently is.
This means that if you can put 10 thousand in right now, you will take out 200 grand by Thursday morning.
This info is solid. It comes from an attorney who’s a long time friend of mine and who literally saw the acquisition documents with his own eyes.
You must be wondering what the company’s trading symbol is, and I will not tease you any longer� it’s Q like in Quality, S like in Straight, M like Mary and G like Gold
These four letters together make up the company’s ticker and that’s what you will need to give to your broker, or type into your online account to purchase the stock.
I highly recommend you do this as quickly as possible because there is no guarantee that the price will remain this low much longer.
I expect it’ll continue to rise and rise as the insider information spreads. Nonetheless the potential to benefit is absolutely gigantic here.
—–
Best Regards,
Guillermo Richardson
———————————————-

添付ファイル なし

———————————————-
ソース
From – Wed Apr 26 08:
X-Account-Key:
X-UIDL:
X-Mozilla-Status:
X-Mozilla-Status2:
X-Mozilla-Keys:
Return-Path:
X-Original-To:
Delivered-To:
Received: from 177-87-4-71.netcell.inf.br (177-87-4-71.netcell.inf.br [177.87.4.71])
by
for
Received: (from apache@localhost)
by newlifeluth.org (8.14.7/8.14.7/Submit) id
Tue, 25 Apr 20
Message-Id: <2B@newlifeluth.org>
To:
Subject: This company’s being acquired tomorrow
X-PHP-Originating-Script: 20009:Api.php
From: “Guillermo Richardson”
Date:
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0
X-EsetId:

以下省略
————————————————————————
177-87-4-71.netcell.inf.br (177-87-4-71.netcell.inf.br [177.87.4.71])
IP Address 177.87.4.71
Host Name 177-87-4-71.netcell.inf.br
Country Brazil
IP Prefix 177.87.0.0/21
————————————————————————
Domain Name:
newlifeluth.org
Check status
Page Response:
24.68 (ms)
Website Ranking:

Facebook23
SEO Report Time:
Created: 0 seconds ago, Updated: 0 seconds ago
Update SEO Report:

Enter to update SEO:
Meta Tags:

Title New Life Lutheran Church Menomonie, WI NALC – Home
Internet service provider:
The Endurance International Group
Organization:
The Endurance International Group
Country name:
United States
Country ISO alpha-2 code:
US
Longitude:
-97.822
Latitude:
37.751
WHOIS last updated:
0 seconds ago on April 26, 2017, 12:00 am GMT Time
WHOIS data:
Domain Name: NEWLIFELUTH.ORG
Updated Date: 2016-07-20T14:59:15Z
Creation Date: 2011-08-05T14:27:24Z
Registry Expiry Date: 2017-08-05T14:27:24Z
Registrar Registration Expiration Date:
Registrar: FastDomain Inc.
Registrar IANA ID: 1154
Reseller:
Registry Registrant ID: C179486454-LROR
Registrant Name: Cheryl Keyes
Registrant Organization: Cheryl Keyes
Registrant Street: E2036 672ND AVE
Registrant City: Knapp
Registrant State/Province: Wisconsin
Registrant Postal Code: 54749
Registrant Country: US
Registrant Phone: +1.7156652605
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: keyes@millrd.com
Registry Admin ID: C179486454-LROR
Admin Name: Cheryl Keyes
Admin Organization: Cheryl Keyes
Admin Street: E2036 672ND AVE
Admin City: Knapp
Admin State/Province: Wisconsin
Admin Postal Code: 54749
Admin Country: US
Admin Phone: +1.7156652605
Admin Phone Ext:
Admin Fax:
Admin Fax Ext:
Admin Email: keyes@millrd.com
Registry Tech ID: C179486456-LROR
Tech Name: K.L. Peterson
Tech Organization: FatCow
Tech Street: 70 BLANCHARD RD
Tech City: Burlington
Tech State/Province: Massachusetts
Tech Postal Code: 01803
Tech Country: US
Tech Phone: +1.8882789780
Tech Phone Ext:
Tech Fax: +1.7812726550
Tech Fax Ext:
Tech Email: support@fatcow.com
Name Server: NS1.FATCOW.COM
Name Server: NS2.FATCOW.COM
————————————————————————

国際化ドメイン悪用偽装が出てきているらしいよ

何者それ?ホモグラフ攻撃、IDNホモグラフ攻撃というらしい
“http://窓の杜.jp”など実現できるのは、国際化ドメイン(ドメイン名にアルファベットや数字以外の文字を利用できるようにする仕組み)と言われこれでもアクセスできるようのだが、
これが、“аpple.com”は一見、Appleの公式サイトのURLに見えるらしいが、実は先頭の文字にキリル文字の“а”が使われておそうな。
本当にわからないよね。
対策しているものは、アドレスバーには“аpple.com”ではなくPunycode形式の“xn--pple-43d.com”と表示!
“xn--80ak6aa92e.com”へアクセスすると、アドレスバーに“аррӏе.com”と表示されてしまい、視覚的に“apple.com”と
表示されるらしい。 おお!そりゃわかんらん
「Google Chrome」は「Google Chrome 58」で修正
「Opera」は最新のベータ版で修正がテスト
「Firefox」は対策中だが、“about:config”画面で“network.IDN_show_punycode”を有効化 を緩和できるらしい。
edgeは、全くアナウンスがない。
image2
http://forest.watch.impress.co.jp/docs/news/1056177.html

https://www.xudongz.com/blog/2017/idn-phishing/