This must be the millionth phishing that I get of this provider - Aruba.it
- managed by motherfuckers. Criminal psychopaths.
And gmail-google and Cert.br, partners of this criminal activity, do
nothing. Psychopaths greedy. Mobsters.
https://www.virustotal.com/en-gb/url/1aedbf1bd01aa36211bb92a638922849bfcc78b40c57001c97100f3cbdfd67fb/analysis/1459550894/
Netcraft |
Malicious
site |
Fortinet |
Phishing
site |
Kaspersky |
Phishing
site |
-----Mensagem Original-----
From: toolbar@netcraft.com
Sent: Friday, April 01, 2016 5:36 PM
To: marilson.mapa
Subject: Thank you from Netcraft
The URL you recently submitted has been accepted as a
phishing site by Netcraft.
URL: http:// www. hospital-macarena.com/
nf.php
Netcraft
As you all will keep practicing crime and protecting criminals without
legal consequences, with your government pretending nothing see, to ensure the
billing and the jobs of the natives, I suggest taking this phishing spam, to
print and wipe your ass, incompetents of shit!
You are all part of the same gang of criminals, specialists in irritate and
steal money from the planet's population, and with the knowledge and blessing of
your governments and sociopaths security forces.
The lack of ethics, turpitude, the rascality, greed and lack of respect for
people shows a rotten globalized economy where even the ISIS is a lesser evil,
much smaller. Volkswagen and HSBC are the caricature of all of you. Fuck all of
you!
Marilson
HEADER
Delivered-To: marilson.mapa@gmail.com
Received: by 10.182.44.36 with SMTP id
b4csp375487obm;
Fri, 1 Apr
2016 10:41:00 -0700 (PDT)
X-Received: by 10.194.205.138 with SMTP id
lg10mr6118887wjc.153.1459532459975;
Fri, 01 Apr
2016 10:40:59 -0700 (PDT)
Return-Path:
<faze_postmaster@ristorantepizzeriacasanova.comsaiserramenti.com>
Received: from smtplqs-out29.aruba.it
(smtplqs-out29.aruba.it. [62.149.158.69])
by
mx.google.com with ESMTPS id v3si17901444wjf.31.2016.04.01.10.40.59
for
<marilson.mapa@gmail.com>
(version=TLS1 cipher=AES128-SHA bits=128/128);
Fri, 01 Apr
2016 10:40:59 -0700 (PDT)
Received-SPF: neutral (google.com: 62.149.158.69 is
neither permitted nor denied by best guess record for domain of
faze_postmaster@ristorantepizzeriacasanova.comsaiserramenti.com)
client-ip=62.149.158.69;
Authentication-Results: mx.google.com;
spf=neutral
(google.com: 62.149.158.69 is neither permitted nor denied by best guess record
for domain of faze_postmaster@ristorantepizzeriacasanova.comsaiserramenti.com)
smtp.mailfrom=faze_postmaster@ristorantepizzeriacasanova.comsaiserramenti.com
Received: from webxc55s03.ad.aruba.it
([62.149.145.127])
by smartcmd03.ad.aruba.it with
bizsmtp
id d5gz1s00w2l8Z9J015gzp0; Fri, 01
Apr 2016 19:40:59 +0200
Received: (qmail 47889 invoked by uid 19142460); 1 Apr
2016 17:40:59 -0000
To: marilson.mapa@gmail.com
Subject: Santander-NET
X-PHP-Originating-Script:
19142460:index.php
Date: Fri, 1 Apr 2016 19:40:59 +0200
From: "COMUNICADO."
<faze_postmaster@ristorantepizzeriacasanova.comsaiserramenti.com>
Message-ID:
<808a17e0f1497ac6c4edf17c37e9decb@www.asdjacquescousteau.com>
X-Priority: 3
X-Mailer: PHPMailer [version 1.73]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html;
charset="iso-8859-1"
TEXT URL http:// www.
hospital-macarena.com/ nf.php
Sent: Friday, April 01, 2016 2:40 PM
Subject: Santander-NET
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Sent: Wednesday, March 23, 2016 1:02 PM
Subject: Conspiracy and crime
Gentlemen,
You are practicing crime sending phishing - http://
zringenieriasa.com.co/ default.
This phishing website is owned by ColombiaHosting S.A.S.
CRDF |
Malicious
site |
Netcraft |
Malicious
site |
Opera |
Malicious
site |
Sophos |
Malicious
site |
Fortinet |
Phishing
site |
Kaspersky |
Phishing
site |
As you all will keep practicing crime and protecting criminals without
legal consequences, with your government pretending nothing see, to ensure the
billing and the jobs of the natives, I suggest taking this phishing spam, to
print and wipe your ass, incompetents of shit!
So
Aruba.it, I don’t care if the criminal is using your
hostname and IP – smtplqs-out34.aruba.it
IP 62.149.158.74 - to send scam. But, shame on you!
What matters is who is hosting the phishing website practicing scam and stealing
financial data from incautious people. You are all part of the same gang of
criminals, specialists in irritate and steal money from the planet's population,
and with the knowledge and blessing of your governments and sociopaths security
forces.
The lack of ethics, turpitude, the rascality, greed and lack of respect for
people shows a rotten globalized economy where even the ISIS is a lesser evil,
much smaller. Volkswagen and HSBC are the caricature of all of you.
Marilson
HEADER
Delivered-To: marilson.mapa@gmail.com
Received: by 10.31.194.70 with SMTP id
s67csp2289994vkf;
Tue, 22 Mar
2016 09:30:33 -0700 (PDT)
X-Received: by 10.28.99.6 with SMTP id
x6mr22382468wmb.46.1458664233774;
Tue, 22 Mar
2016 09:30:33 -0700 (PDT)
Return-Path:
<hosting.windows@aruba.it>
Received: from smtplqs-out34.aruba.it
(smtplqs-out34.aruba.it. [62.149.158.74])
by
mx.google.com with ESMTP id h12si19235152wme.92.2016.03.22.09.30.33
for
<marilson.mapa@gmail.com>;
Tue, 22 Mar
2016 09:30:33 -0700 (PDT)
Received-SPF: pass (google.com: domain of
hosting.windows@aruba.it designates 62.149.158.74 as permitted sender)
client-ip=62.149.158.74;
Authentication-Results: mx.google.com;
spf=pass
(google.com: domain of hosting.windows@aruba.it designates 62.149.158.74 as
permitted sender) smtp.mailfrom=hosting.windows@aruba.it
Received: from websn1s056.aruba.it
([31.11.32.66])
by smartcmd04.ad.aruba.it with
bizsmtp
id Z4WZ1s0041Rc5db014WZAP; Tue, 22
Mar 2016 17:30:33 +0100
Received: from websn1s056 ([127.0.0.1]) by
websn1s056.aruba.it with Microsoft SMTPSVC(8.5.9600.16384);
Tue, 22 Mar 2016 17:30:32
+0100
Date: Tue, 22 Mar 2016 17:30:32 +0100
Subject: Prezado(a) marilson.mapa@gmail.com |
Protocolo: [13448]
To: marilson.mapa@gmail.com
From: Suporte ltaú <post26432>
Reply-To:Suporte ltaú <post26432>
X-Mailer: Interspire5.2.14MIME-Version:
1.0
Content-type: text/html;
charset=ISO-8859-1
Return-Path: hosting.windows@aruba.it
Message-ID:
<WEBSN1S056qGngOZ2L30000f3af@websn1s056.aruba.it>
X-OriginalArrivalTime: 22 Mar 2016 16:30:32.0972 (UTC)
FILETIME=[27C5D4C0:01D18458]
TEXT – URL http:// zringenieriasa.com.co/
default
From:
post26432
Sent: Tuesday, March 22, 2016 1:30 PM
Subject: Prezado(a) marilson.mapa@gmail.com | Protocolo:
[13448]
|
10th
March
2016 | |