Tuesday, November 6, 2012

Spoofing from 'Apple'

A nice example of a spoof email that is sent from a 'known' entity in an attempt to get you to click on a link so you can fall into their trap.
 
The first clue is the return email address. It is a server out of Italy the domain is axeitalia. No way is that owned by Apple.
 
The second is where the links are pointing: "welnessmedical.com".
 
Don't click on anything in these messages.
 
Below is the WhoIs information for wellnessmedical.com
 
Domain Name: WELNESSMEDICAL.COM

Registrant:
Alulay Solorzano
Alulay Solorzano (campion@welnessmedical.com)
1105 Rowes Lane
Elizabethtown
KY,42701
US
Tel. +1.2706600129

Creation Date: 05-Nov-2012
Expiration Date: 05-Nov-2013

Domain servers in listed order:
ns1.welnessmedical.com
ns2.welnessmedical.com


Administrative Contact:
Alulay Solorzano
Alulay Solorzano (campion@welnessmedical.com)
1105 Rowes Lane
Elizabethtown
KY,42701
US
Tel. +1.2706600129

Technical Contact:
Alulay Solorzano
Alulay Solorzano (campion@welnessmedical.com)
1105 Rowes Lane
Elizabethtown
KY,42701
US
Tel. +1.2706600129

Billing Contact:
Alulay Solorzano
Alulay Solorzano (campion@welnessmedical.com)
1105 Rowes Lane
Elizabethtown
KY,42701
US
Tel. +1.2706600129
 

No comments:

Post a Comment