Blog for hpHosts, and whatever else I feel like writing about ....

Thursday 1 March 2012

Alert: rte66ts.com

Those behind the Cahoot phish have gotten themselves a new domain already (and likely others - still looking in to that), same IP at Limestone though. This just popped in to my inbox;

hxxp://www.rte66ts.com/?login=prepare

Return-Path: <melsmith@cg60.fr>
Delivered-To: elfinn-netralke@[REMOVED]
X-Spam-Flag: YES
X-Spam-Score: 10.574
X-Spam-Level: **********
X-Spam-Status: Yes, score=10.574 tagged_above=-9999 required=1.3
tests=[BAYES_50=0.8, FH_HELO_EQ_D_D_D_D=3.177,
HELO_DYNAMIC_IPADDR2=3.607, RDNS_NONE=0.793, STOX_REPLY_TYPE=0.439,
STOX_REPLY_TYPE_WITHOUT_QUOTES=1.757, TVD_RCVD_IP=0.001]
autolearn=unavailable
Received: from unknown (HELO yjl) ([137.181.204.182])
by 190.252.85.237 with ESMTP; Thu, 1 Mar 2012 14:15:13 -0500
Message-ID: <002f01ccf7df$055fe4c0$89b5ccb6@PERSONALyjl>
From: "Cahoot Team" <melsmith@cg60.fr>
To: <elfinn-netralke@[REMOVED]>
Subject: [SPAM] Cahoot: You have a new alert from Cahoot
Date: Thu, 1 Mar 2012 14:08:01 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset="windows-1252";
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106



Registrant:
Michael Munoz
236 East Foothill blvd
Azusa, California 91702
United States

Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
Domain Name: RTE66TS.COM
Created on: 13-Jul-09
Expires on: 13-Jul-13
Last Updated on: 14-Jul-11

Administrative Contact:
Munoz, Michael owdden@aol.com
236 East Foothill blvd
Azusa, California 91702
United States
+1.6267058030 Fax --

Technical Contact:
Munoz, Michael owdden@aol.com
236 East Foothill blvd
Azusa, California 91702
United States
+1.6267058030 Fax --

Domain servers in listed order:
NS1.LOCKS-MACK.COM
NS2.LOCKS-MACK.COM


References

Alert: You have a new alert from Cahoot
http://hphosts.blogspot.com/2012/03/alert-you-have-new-alert-from-cahoot.html

No comments: