Indice del forum Olimpo Informatico
I Forum di Zeus News
Leggi la newsletter gratuita - Attiva il Menu compatto
 
 FAQFAQ   CercaCerca   Lista utentiLista utenti   GruppiGruppi   RegistratiRegistrati 
 ProfiloProfilo   Messaggi privatiMessaggi privati   Log inLog in 

    Newsletter RSS Facebook Twitter Contatti Ricerca
* [RISCHIO] EuroSoftware. Finto sito di vendita software.
Nuovo argomento   Rispondi    Indice del forum -> Sicurezza
Precedente :: Successivo  
Autore Messaggio
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 17 Gen 2010 22:45    Oggetto: * [RISCHIO] EuroSoftware. Finto sito di vendita software. Rispondi citando

Che dire, la domenica i vari spammer, virus-writer, etc... lavorano alla grande. Confused

Ho ricevuto un'altra e-mail:
Citazione:
Euro Software ©

Il sito EuroSoftware è possibile scaricare tutto il software che subito dopo l'acquisto senza uscire di casa. Scordatevi di CD / DVD dischi con software e scaricare tutto il necessario.

Abbiamo il software per PC e MAC. Prova il nostro sito: h*tp://akramenskotes.net/
Nicross, D33W-0176 il tuo codice personale per ottenere uno sconto del 30% su tutti i prodotti.

Il sorgente del messaggio:
Codice:
Received: from 61-227-140-187.dynamic.hinet.net ([61.227.140.187])
From: "Eurosoft Reseller" <Felicite.Champagne@netscape.net>
Reply-To: "Eurosoft Reseller" <Felicite.Champagne@netscape.net>
To: nicross@tiscali.it
Subject: [SPAM] Nicross, Nel nuovo anno con Windows7
Date: Sun, 17 Jan 2010 23:40:13 +0500
Message-ID: <10147.cavernous@prescott>
X-Mailer: Microsoft Outlook Express 5.50.4522.1200

This is a multi-part message in MIME format.

--=====56065609378494=_
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7Bit
Content-Disposition: inline

hillock convolve infimum synonymy telephotography diagrammatic lineage functor mike blacken dextrose redden lymphoma condone bert expire bash amplifier issuant purposeful scowl wiseacre newsweek stride hellebore d'etat cider saline monic philharmonic clue dixon barnett martyr guesswork aps impeach cane spicy judas cult dwell beg heater eloise buckeye successful tend which xerox semitic bestir ceremonial bedimming antagonistic jacobian teahouse bazaar percentile prexy jeres nit requisition thoughtful anthracite inconceivable plan yokuts tendon millard brigham acreage bathe lure babylonian venerable carport leonard beheld ulysses banshee deceit shipshape analogy mensuration effluent nicholson rockefeller tasmania exist backhand being angelica capstone changeover snout exuberant colonel friction merrymake bissau hologram jilt catchup afterlife sepia simulate doldrums flippant chevy aerospace fresco cit deforestation alia ineluctable volkswagen astonish assume neuritis corps hostler indi
cate bleary seminary courtesan flashlight bequest dropout lowry irregular bladdernut emil jeffrey alfresco inextricable leon frame shapiro bulb univalent tensional clone cab deploy resilient israel chromatogram boar bookcase loop maxwellian accelerometer bogeymen crystalline goes courtier energetic krakatoa armour spook handicapped commendation tune fritillary contradistinct scrawny cajole delay gamma sargent skyline fermat coachwork hicks coralline montague backside gibby yardage throne eliminate enid ancient digestible conflagration tipoff mckenzie resistive meander echoes dudley cloture chieftain cable cardiology sloan chlorinate ballfield tour sluice carnation backyard qualify stimuli ambassador desist caddy rise
h*tp://akramenskotes.net/

--=====56065609378494=_
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: 7Bit
Content-Disposition: inline

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>

<body bgcolor="#FFFFFF">
<p><b><font color="#993300" size="4" face="Verdana, Arial, Helvetica, sans-serif">Euro Software &copy;</font></b></p>

<p><font color="#333333" size="2" face="Verdana, Arial, Helvetica, sans-serif">Il sito EuroSoftware &egrave; possibile scaricare tutto il software che subito dopo l'acquisto senza uscire di casa. Scordatevi di CD / DVD dischi con software e scaricare tutto il necessario.</font></p>
<p><font color="#333333" size="2" face="Verdana, Arial, Helvetica, sans-serif">Abbiamo il software per PC e MAC. Prova il nostro sito: <a href="h*tp://akramenskotes.net/">http://akramenskotes.net/</a></font></p>
<table width="100%" border="0" cellpadding="3">
  <tr>
    <td bgcolor="#FF9900"><font size="2" face="Verdana, Arial, Helvetica, sans-serif"><i>Nicross</i>, <b>D33W-0176</b> il tuo codice personale per ottenere uno sconto del <b>30%</b> su tutti i prodotti.</font></td>
  </tr>

</table>
</body>

</html>


--=====56065609378494=_--


Visitando il link proposto, compare una pagina con un'incredibile serie di programmi a prezzi stracciatissimi.
Qualche esempio:
  • Windows 7 Ultimate 32 bit
    Prezzo standard: €399.99
    Il nostro prezzo: €99.95
    Risparmiate: €300.04

  • Office Professional 2007
    Prezzo standard: €499.95
    Il nostro prezzo: €69.95
    Risparmiate: €430

Veramente un notevole risparmio... Shocked

Peccato che, osservando attentamente il codice HTML della pagina visitata:
Codice:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
   <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
   <meta name="keywords" content="OEM Software">
   <meta name="description" content="OEM Software">
   <link rel="stylesheet" href="/css/main.css" type="text/css">
   <link rel="stylesheet" href="/css/lytebox.css" type="text/css">
   <script type="text/javascript" src="/js/prototype.js"></script>
   <script type="text/javascript" src="/js/peel.js"></script>      <!--[if IE 6]><script type="text/javascript" src="/js/fixpng.js"></script><![endif]-->
   <!--[if IE 6]><link rel="stylesheet" type="text/css" href="/css/ie6.css"><![endif]-->
   <!--[if IE 7]><link rel="stylesheet" type="text/css" href="/css/ie7.css"><![endif]-->
   <title>EuroSoft</title>
   <script>
      var CasinoOpen = true;
      function PartnerURL(event) {
         if (!CasinoOpen) return true;
         if (((event.srcElement)&&(event.srcElement.src != '')&&(event.srcElement.src != undefined))||((event.target)&&(event.target.src != '')&&(event.target.src != undefined))) return true;
         var url = '';
         if ((event.target)&&(event.target.href!='')&&(event.target.href != undefined)) url = event.target.href;
         if ((event.srcElement)&&(event.srcElement.href != '')&&(event.srcElement.href != undefined)&&(url == '')&&(!event.srcElement.src)) url = event.srcElement.href;
         if (url != '') {
            window.open(url, '_blank');
            window.location.href="http://site.eucasino.com/index.cgi?aname=hernes&zone_id=s201109&cg=italian";
         } else {
            window.open(window.location.href, '_blank');
            window.location.href="http://site.eucasino.com/index.cgi?aname=hernes&zone_id=s201109&cg=italian";
         }
         CasinoOpen = false;
         return false;
      }      
   </script>
</head>

<body >

Un sito di vendita software che apre una finestra dedicata a un casinò... qualcosa non quadra. Think

Chiunque pensi di acquistare software in siti simili utilizzando la carta di credito, rischia di trovarsi addebitate spese "impreviste"! Twisted Evil

Mi raccomando, tenetevi a debita distanza da siti simili! Old

Dimenticavo, sono andato a fare una ricerca veloce in merito al presunto proprietario del sito:
Citazione:
Whois Server Version 2.0

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Domain Name: AKRAMENSKOTES.NET
Registrar: CHINA SPRINGBOARD INC.
Whois Server: whois.namerich.cn
Referral URL: http://www.namerich.cn
Name Server: NS1.KRAPOBRAVES.COM
Name Server: NS2.KRAPOBRAVES.COM
Name Server: NS3.KRAPOBRAVES.COM
Name Server: NS4.KRAPOBRAVES.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 07-jan-2010
Creation Date: 06-jan-2010
Expiration Date: 06-jan-2011

>>> Last update of whois database: Sun, 17 Jan 2010 20:50:43 UTC <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability. VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.

; This data is provided by China Springboard Inc.
; for information purposes, and to assist persons obtaining information
; about or related to domain name registration records.
; China Springboard Inc. does not guarantee its accuracy.
; By submitting a WHOIS query, you agree that you will use this data
; only for lawful purposes and that, under no circumstances, you will
; use this data to
; 1) allow, enable, or otherwise support the transmission of mass
; unsolicited, commercial advertising or solicitations via E-mail
; (SPAM); or
; 2) enable high volume, automated, electronic processes that apply
; to this WHOIS server.
; These terms may be changed without prior notice.
; By submitting this query, you agree to abide by this policy.

DomainName : akramenskotes.net

RSP: China Springboard Inc.
URL: http://www.namerich.cn

Name Server: NS3.KRAPOBRAVES.COM
Name Server: NS1.KRAPOBRAVES.COM
Name Server: NS4.KRAPOBRAVES.COM
Name Server: NS2.KRAPOBRAVES.COM
Status: clientTransferProhibited
Status: clientDeleteProhibited
Creation Date: 2010-01-07
Expiration Date: 2011-01-07
Last Update Date: 2010-01-07

Registrant Name: su ying
Registrant Organization: su ying
Registrant Address: din weimen 12hao 1501
Registrant City: BeiJing
Registrant Province/State: BeiJing
Registrant Country Code: CN
Registrant Postal Code: 210120
Registrant Phone Number: +86.02589754868
Registrant Fax: +86.02589754868
Registrant Email: 1034180959@qq.com

Administrative Name: su ying
Administrative Organization: su ying
Administrative Address: din weimen 12hao 1501
Administrative City: BeiJing
Administrative Province/State: BeiJing
Administrative Country Code: CN
Administrative Postal Code: 210120
Administrative Phone Number: +86.02589754868
Administrative Fax: +86.02589754868
Administrative Email: 1034180959@qq.com

Billing Name: su ying
Billing Organization: su ying
Billing Address: din weimen 12hao 1501
Billing City: BeiJing
Billing Province/State: BeiJing
Billing Country Code: CN
Billing Postal Code: 210120
Billing Phone Number: +86.02589754868
Billing Fax: +86.02589754868
Billing Email: 1034180959@qq.com

Technical Name: su ying
Technical Organization: su ying
Technical Address: din weimen 12hao 1501
Technical City: BeiJing
Technical Province/State: BeiJing
Technical Country Code: CN
Technical Postal Code: 210120
Technical Phone Number: +86.02589754868
Technical Fax: +86.02589754868
Technical Email: 1034180959@qq.com

Qualcuno parla cinese? Laughing
Top
Profilo Invia messaggio privato
bdoriano
Amministratore
Amministratore


Registrato: 02/04/07 12:05
Messaggi: 14391
Residenza: 3° pianeta del sistema solare...

MessaggioInviato: 19 Feb 2010 22:34    Oggetto: Rispondi

Nuovo messaggio! Laughing
Citazione:
Ciao,% TO_NAME!
Abbiamo molti programmi!

Ho di recente trovato un sito interessante, che vendono i vari programmi. Programmi per andPC Macintosh! I prezzi sono economici а 5-10 quel tempo in giro. E anche che non dovremmo aspettare fino a quando il CD di consegnare la posta - tutti i programmi possono entrambe sito downloade а. Ho comprato la coppia di programma già online è meraviglioso, ho risparmiato 250 €.

L'indirizzo è come questo: h**p://ciokrassotes.net

Solo fino al 20 febbraio
San Valentino: il 40% di sconto su tutti i nostri soft
UTILIZZARE IL CODICE SCONTO: VENT-1400
© Euro Software LCC`2005-2009
210 East 59st Street
New York, NY 10021
(718) 524-2096

codice HTML del messaggio:
Codice:
From - Fri Feb 19 21:04:56 2010
X-Account-Key: account2
X-UIDL: 5181
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:                                                                                 
Return-Path: <Rosetta.Blount@lissamail.com>
Received: from imp-2.mail.tiscali.it (10.39.115.148) by mx-3-it.mail.tiscali.it (8.0.031)     
  id 4B66D85F0CADAB97 for *****; Fri, 19 Feb 2010 21:00:41 +0100
Received: from 213.205.33.249 ([86.104.129.69])   by imp-2.mail.tiscali.it with
   id jw0X1d00d1Vyf5y01w0Xvb; Fri, 19 Feb 2010 21:00:41 +0100
From: "Download it now!" <Rosetta.Blount@lissamail.com>
Reply-To: "Download it now!" <Rosetta.Blount@lissamail.com>
To: *****
Subject: [SPAM] Fwd: L'installazione e l'uso!
Message-ID: <OPAYGAUGZVZORWWOOUKEMVIM@mailpride.com>
Date: Fri, 19 Feb 2010 16:54:33 -0300
X-Mailer: AOL 7.0 for Windows US sub 118
MIME-Version: 1.0
Content-Type: multipart/alternative;   boundary="--=====05860593308=_"
X-AntiVirus: checked (incoming) by AntiVir MailGuard (Version: 9.0.1.9; AVE: 8.2.1.170; VDF:
 7.10.4.98)
X-Avira-Antispam: Version 9.0.0.15 on DorianoNB (192.168.56.101) settings.db:9.0.0.15.3.2 (15-02-10
 09:33) global_words.db:9.0.0.15.0.1 (15-02-10 09:33) user_words.db:9.0.0.14.0.1 (30-12-09 15:16)
X-Avira-ScanDate: 02/19/10 21:05:01
X-Avira-SpamScore: ata:   6.580 bayes:   0.345 final:   5.981
X-Avira-SpamLevel: High

----=====05860593308=_
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7Bit

deforestation hummingbird vaccinate margarine cylinder
exacter lebanon cupboard employed declaim forest legitimacy renault reynolds
hansom framework pedagogy ferrite carburetor beck
http://ciokrassotes.net

----=====05860593308=_
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: 7Bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
"http://www.w3.org/TR/html4/loose.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<title>I migliori programmi per la casa e l'ufficio</title>
</head>

<body bgcolor="#FFFFCC" link="#0000FF">
<p><font color="#333333" size="2" face="Verdana, Arial, Helvetica, sans-serif"> Ciao,% TO_NAME! <br>
  Abbiamo molti programmi! <br>
  <br>
Ho di recente trovato un sito interessante, che vendono i vari programmi. Programmi per andPC Macintosh! I prezzi sono economici а 5-10 quel tempo in giro. E anche che non dovremmo aspettare fino a quando il CD di consegnare la posta - tutti i programmi possono entrambe sito downloade а. Ho comprato la coppia di programma gi&agrave; online &egrave; meraviglioso, ho risparmiato 250 &euro;.<br>
  <br>
  L'indirizzo &egrave; come questo: <a href="http://ciokrassotes.net">http://ciokrassotes.net</a><br>

<br>
</font><font color="#FF0000" size="2" face="Verdana, Arial, Helvetica, sans-serif">Solo fino al 20 febbraio</font><br>
<font color="#FF0000" size="2" face="Verdana, Arial, Helvetica, sans-serif">San Valentino: il 40% di sconto su tutti i nostri soft<br>
UTILIZZARE IL CODICE SCONTO: <strong>VENT-1400</strong></font></p>
<hr size="1" noshade>
<font color="#333333" size="2" face="Times New Roman, Times, serif">&copy; Euro Software LCC`2005-2009<br>
210 East 59st Street<br>
New York, NY 10021<br>
(718) 524-2096</font>

</body>
</html>


----=====05860593308=_--

Anche questo dominio è stato registrato presso un sito cinese:
Citazione:
Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

Domain Name: CIOKRASSOTES.NET
Registrar: CHINA SPRINGBOARD INC.
Whois Server: whois.namerich.cn
Referral URL: http://www.namerich.cn
Name Server: NS1.SRUISOREHOES.COM
Name Server: NS2.SRUISOREHOES.COM
Name Server: NS3.SRUISOREHOES.COM
Name Server: NS4.SRUISOREHOES.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 15-feb-2010
Creation Date: 01-feb-2010
Expiration Date: 01-feb-2011

>>> Last update of whois database: Fri, 19 Feb 2010 20:31:14 UTC <<<
Top
Profilo Invia messaggio privato
Mostra prima i messaggi di:   
Nuovo argomento   Rispondi    Indice del forum -> Sicurezza Tutti i fusi orari sono GMT + 2 ore
Pagina 1 di 1

 
Vai a:  
Non puoi inserire nuovi argomenti
Non puoi rispondere a nessun argomento
Non puoi modificare i tuoi messaggi
Non puoi cancellare i tuoi messaggi
Non puoi votare nei sondaggi