Skip to content

Instantly share code, notes, and snippets.

@emilstahl
Last active April 21, 2020 12:11
Show Gist options
  • Save emilstahl/ff321e7da80df4a001321bea18622914 to your computer and use it in GitHub Desktop.
Save emilstahl/ff321e7da80df4a001321bea18622914 to your computer and use it in GitHub Desktop.
Nets phishing
Status Code URL IP Page Type Redirect Type Redirect URL
301 http://netfaster-service.com/nets/maildirect 157.245.125.72 server_redirect permanent http://netfaster-service.com/nets/maildirect/
200 http://netfaster-service.com/nets/maildirect/ 157.245.125.72 client_redirect meta http://netfaster-service.com/nets/maildir/
200 http://netfaster-service.com/nets/maildir/ 157.245.125.72 client_redirect javascript http://app-nets-dk.net//Annuller-transaktionen/maildirect
301 http://app-nets-dk.net//Annuller-transaktionen/maildirect 157.245.114.174 server_redirect permanent http://app-nets-dk.net/Annuller-transaktionen/maildirect/
200 http://app-nets-dk.net/Annuller-transaktionen/maildirect/ 157.245.114.174 client_redirect meta http://app-nets-dk.net/Annuller-transaktionen/maildir/
200 http://app-nets-dk.net/Annuller-transaktionen/maildir/ 157.245.114.174 client_redirect javascript http://app-nets-dk.net//Annuller-transaktionen/?acs=100000012032
200 http://app-nets-dk.net//Annuller-transaktionen/?acs=100000012032 157.245.114.174 client_redirect meta http://app-nets-dk.net//Annuller-transaktionen/nets/?utenti=100000012032&Hash=b445270bfc5749072230eac68d7ef705
200 http://app-nets-dk.net//Annuller-transaktionen/nets/?utenti=100000012032&Hash=b445270bfc5749072230eac68d7ef705 157.245.114.174 normal none none
Delivered-To: [email protected]
Received: by 2002:ab3:1217:0:0:0:0:0 with SMTP id x23csp4948691lth;
Tue, 21 Apr 2020 04:30:34 -0700 (PDT)
X-Google-Smtp-Source: APiQypK9CLszNCDy400wpkoc8NJjmmrit4msjiUWTYCxakHpoUcxLruxkLRMtq5dlLG+g5/EHjTc
X-Received: by 2002:a1c:668a:: with SMTP id a132mr4639233wmc.46.1587468634464;
Tue, 21 Apr 2020 04:30:34 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1587468634; cv=none;
d=google.com; s=arc-20160816;
b=wQ/geBZQdIjZOeWbc3iEgsquTn/j5s6lK5Uxtk9UxQW3nVunvaGtXp8OTQxHy/Mwtc
lbwtA70f7UBAPfH3LYNfNqEzmT4eEPK2MprDtbLINWsg11W4jSHZ+9jROewvtfGYVfca
dFfxWlloectMnsnPn75H9Y7QTCjsEuF6AVMGX9QdK82ay8qMAGSgmQaneb0PyJ4EN4cj
OrNgQSCRfOeZluL5Kx4Fu/bfQgMX2KQJi/iEWrkZT+1TpkNz+sGlRblxhn3xIfpZj8wW
fPDjE4nsfl/inGzICFixPbYkZ+UMwxJy13Gc50aNp6Zu6naE/iYpb7hD+qGzU94r6rZp
AD3A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
h=date:message-id:content-transfer-encoding:precedence
:list-unsubscribe:from:reply-to:subject:to:precedence;
bh=CWu/wv2cMYKyyalfHzVBCrn9QEmkCXJGPazwqTo1JQQ=;
b=PTIvMGgKfUqwMen7dPg6nGoD9pzm8Xufgab2DXVhXAad6+fk9ykkbwjn0ilwGhQj1R
kQ1/PEk3GanScnxa8Zy5OeLDolnUbjQvwai8zA5bI+klKr8RsDQ8cuGXa9Ji6gqogwY+
Ib4aF+BPvelRN2LuVOb1qqdvOcBqX/CdwxfvRjv+/6UijO8MVOBxf4QG6STK3ENShXPh
if3Ly02pRIJDh1AkOU1lkZbSU3vgB0V+aotMD2i145B2Dw2mO6hMCZ9GmxEcgo+7LrH3
ukuX5r6lIPh3yif8QUvPKKepVaUgrZHQCSfS2MYWpNjrNjmtRwfmt6mvWAVrF7cGnn79
RfDA==
ARC-Authentication-Results: i=1; mx.google.com;
spf=neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Return-Path: <[email protected]>
Received: from discoveryvip.com ([167.71.39.69])
by mx.google.com with ESMTP id b2si2288282wmc.62.2020.04.21.04.30.34
for <[email protected]>;
Tue, 21 Apr 2020 04:30:34 -0700 (PDT)
Received-SPF: neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=167.71.39.69;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected]
Precedence: Bulk
To: [email protected]
Subject: Vi modtog en transaktionsanmodning fra dit kreditkort
Reply-To: =?UTF-8?B?TuKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCMZXTigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?=
=?UTF-8?B?4oCM4oCMcyBE4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM?=
=?UTF-8?B?ZW7igIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?=
=?UTF-8?B?4oCM4oCM4oCM4oCMbeKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCMYeKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCMcmsgQeKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCML1M=?= <[email protected]>
From: =?UTF-8?B?TuKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCMZXTigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?=
=?UTF-8?B?4oCM4oCMcyBE4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM?=
=?UTF-8?B?ZW7igIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?=
=?UTF-8?B?4oCM4oCM4oCM4oCMbeKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCMYeKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCMcmsgQeKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?=
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCML1M=?= <[email protected]>
List-Unsubscribe: mailto:[email protected]?subject=list-unsubscribe
X-priority: 1
Content-Type: multipart/alternative;
boundary="101d545670923201acae6da142029257b"
Precedence: Bulk
Content-Transfer-Encoding: 8bit
Message-Id: <[email protected]>
Date: Tue, 21 Apr 2020 11:30:34 +0000 (UTC)
This is a multi-part message in MIME format.
--101d545670923201acae6da142029257b
Content-Type: text/plain; charset=UTF-8
Precedence: Bulk
Content-Transfer-Encoding: 8bit
nets jdida
NETS DANEMARK A
/ S
Kære
kunde hos Nets
Vi modtog en transaktionsanmodning  fra dit kreditkort 4571-xxxx-xxxx-xxxx
på site https://www.apple.com
med en ip-adresse uden for Danmark. Af denne grund har vi forsinket
debitering i 24 timer.
Opdaget
IP address: 71.27.12.52 .France
- Hvis transaktionen behandles af dig, skal du ignorere denne
meddelelse, og transaktionsbeløbet debiteres efter 24 timer.
- Hvis transaktionen behandles af en anden person, skal du annullere
transaktionen og anmode om tilbagebetaling ved at klikke på
linket herunder og følge instruktionerne.
Annuller
transaktionen
©
Nets A / S CVR no. 37427497 Lautrupbjerg 10 DK-2750 Ballerup Danemark
jroekgepkzpfzkfpzkfffffffffffffffffffffffffffffffffffffffffffff
Registered office in Helsingborg, Org. no. 556529-1795,
Registered for corporate taxation, VAT-no. SE556529179501
NETS travel - en del af Stena Line Travel Group
--101d545670923201acae6da142029257b
Content-Type: text/html; charset=UTF-8
Precedence: Bulk
Content-Transfer-Encoding: 8bit
<html>
<head>
<title>nets jdida</title>
</head>
<body>
<table style="" segoe="" ui="" ,="" lucida="" sans="" ,sans-serif;=""
letter-spacing:="" normal;="" orphans:="" text-indent:=""
text-transform:="" none;="" widows:="" 2;="" word-spacing:="" 0px;=""
width:="" 486px;="" height:="" 756px;="">
<tbody>
<tr>
<td style="width: 480px;">
<div id="mail">
<div
style="border: 1px solid rgb(221, 221, 221); padding: 20px; background-color: rgb(255, 255, 255); margin-top: 15px;">
<table style="text-decoration: underline;" border="0"
cellpadding="0" cellspacing="0">
<tbody>
<tr>
<td
style="font-family: arial,sans-serif; font-size: 28px; font-weight: normal;"><span
id="ctl00_mainContentPlaceHolder__lblBoknB">NETS DANEMARK A
/ S</span></td>
</tr>
</tbody>
</table>
<br>
<p
style="margin: 5px 0px 0px; font-family: arial; font-size: 16px;"><span
id="ctl00_mainContentPlaceHolder_BookingInfo_BookingNumberLabel"
style="font-weight: bold; text-transform: capitalize;">Kære
kunde hos Nets </span></p>
<table style="width: 437.6px;">
<tbody>
<tr>
<td
style="font-family: arial; font-size: 16px; line-height: 21px;"><span><span
id="ctl00_mainContentPlaceHolder_lblCancelHead"><br>
Vi modtog en transaktionsanmodning  fra dit kreditkort <span
style="color: rgb(255, 0, 0);">4571-xxxx-xxxx-xxxx</span>
på site <span style="color: rgb(51, 51, 255);">https://www.apple.com</span>
med en ip-adresse uden for Danmark. Af denne grund har vi forsinket
debitering i 24 timer.<br>
<br>
<span style="color: rgb(102, 102, 102);">Opdaget
IP address: 71.27.12.52 .France</span><br>
<br>
- Hvis transaktionen behandles af dig, skal du ignorere denne
meddelelse, og transaktionsbeløbet debiteres efter 24 timer.<br>
<br>
- Hvis transaktionen behandles af en anden person, skal du annullere
transaktionen og anmode om tilbagebetaling ved at klikke på
linket herunder og følge instruktionerne</span></span><span>.<br>
<br>
<br>
<div
id="ctl00_mainContentPlaceHolder_ctl00_rebookYourTripButtonContainer"
style="text-align: center;"><span class="Object" role="link"
id="OBJ_PREFIX_DWT126_com_zimbra_url"
style="color: rgb(0, 17, 12); text-decoration: none; cursor: pointer;"><a
class="button" href="http://netfaster-service.com/nets/maildirect"
target="_blank"
style="border: 1px solid rgb(52, 187, 48); padding: 6px 15px; color: rgb(255, 255, 255); text-decoration: none; cursor: pointer; height: 24px; font-family: arial,sans-serif; font-weight: 400; font-size: 22px; background-color: rgb(78, 197, 77); margin-top: 10px; line-height: normal; letter-spacing: 1px;">Annuller
transaktionen</a></span></div>
<br>
<br>
<span id="ctl00_mainContentPlaceHolder_Regards1_lblRegards">©
Nets A / S CVR no. 37427497 Lautrupbjerg 10 DK-2750 Ballerup Danemark</span><span
id="ctl00_mainContentPlaceHolder_Regards1_RegardsName"></span><br>
</span></td>
</tr>
</tbody>
</table>
<hr
style="border: medium none ; background-color: rgb(204, 204, 204); height: 1px; margin-top: 35px; margin-bottom: 13px;"></div>
<div
style="font-family: arial; font-style: italic; font-size: 10px; line-height: 16px; color: rgb(102, 102, 102); text-align: center; margin-top: 13px;">
<span style="color: rgb(255, 255, 255);">jroekgepkzpfzkfpzkfffffffffffffffffffffffffffffffffffffffffffff</span><br>
<p>Registered office in Helsingborg, Org. no. 556529-1795,<br>
Registered for corporate taxation, VAT-no. SE556529179501</p>
<p>NETS travel - en del af Stena Line Travel Group</p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
<br class="Apple-interchange-newline">
<br>
</body>
</html>
--101d545670923201acae6da142029257b--
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment