Last active
April 21, 2020 12:11
-
-
Save emilstahl/ff321e7da80df4a001321bea18622914 to your computer and use it in GitHub Desktop.
Nets phishing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Status Code | URL | IP | Page Type | Redirect Type | Redirect URL | |
---|---|---|---|---|---|---|
301 | http://netfaster-service.com/nets/maildirect | 157.245.125.72 | server_redirect | permanent | http://netfaster-service.com/nets/maildirect/ | |
200 | http://netfaster-service.com/nets/maildirect/ | 157.245.125.72 | client_redirect | meta | http://netfaster-service.com/nets/maildir/ | |
200 | http://netfaster-service.com/nets/maildir/ | 157.245.125.72 | client_redirect | javascript | http://app-nets-dk.net//Annuller-transaktionen/maildirect | |
301 | http://app-nets-dk.net//Annuller-transaktionen/maildirect | 157.245.114.174 | server_redirect | permanent | http://app-nets-dk.net/Annuller-transaktionen/maildirect/ | |
200 | http://app-nets-dk.net/Annuller-transaktionen/maildirect/ | 157.245.114.174 | client_redirect | meta | http://app-nets-dk.net/Annuller-transaktionen/maildir/ | |
200 | http://app-nets-dk.net/Annuller-transaktionen/maildir/ | 157.245.114.174 | client_redirect | javascript | http://app-nets-dk.net//Annuller-transaktionen/?acs=100000012032 | |
200 | http://app-nets-dk.net//Annuller-transaktionen/?acs=100000012032 | 157.245.114.174 | client_redirect | meta | http://app-nets-dk.net//Annuller-transaktionen/nets/?utenti=100000012032&Hash=b445270bfc5749072230eac68d7ef705 | |
200 | http://app-nets-dk.net//Annuller-transaktionen/nets/?utenti=100000012032&Hash=b445270bfc5749072230eac68d7ef705 | 157.245.114.174 | normal | none | none |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Delivered-To: [email protected] | |
Received: by 2002:ab3:1217:0:0:0:0:0 with SMTP id x23csp4948691lth; | |
Tue, 21 Apr 2020 04:30:34 -0700 (PDT) | |
X-Google-Smtp-Source: APiQypK9CLszNCDy400wpkoc8NJjmmrit4msjiUWTYCxakHpoUcxLruxkLRMtq5dlLG+g5/EHjTc | |
X-Received: by 2002:a1c:668a:: with SMTP id a132mr4639233wmc.46.1587468634464; | |
Tue, 21 Apr 2020 04:30:34 -0700 (PDT) | |
ARC-Seal: i=1; a=rsa-sha256; t=1587468634; cv=none; | |
d=google.com; s=arc-20160816; | |
b=wQ/geBZQdIjZOeWbc3iEgsquTn/j5s6lK5Uxtk9UxQW3nVunvaGtXp8OTQxHy/Mwtc | |
lbwtA70f7UBAPfH3LYNfNqEzmT4eEPK2MprDtbLINWsg11W4jSHZ+9jROewvtfGYVfca | |
dFfxWlloectMnsnPn75H9Y7QTCjsEuF6AVMGX9QdK82ay8qMAGSgmQaneb0PyJ4EN4cj | |
OrNgQSCRfOeZluL5Kx4Fu/bfQgMX2KQJi/iEWrkZT+1TpkNz+sGlRblxhn3xIfpZj8wW | |
fPDjE4nsfl/inGzICFixPbYkZ+UMwxJy13Gc50aNp6Zu6naE/iYpb7hD+qGzU94r6rZp | |
AD3A== | |
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; | |
h=date:message-id:content-transfer-encoding:precedence | |
:list-unsubscribe:from:reply-to:subject:to:precedence; | |
bh=CWu/wv2cMYKyyalfHzVBCrn9QEmkCXJGPazwqTo1JQQ=; | |
b=PTIvMGgKfUqwMen7dPg6nGoD9pzm8Xufgab2DXVhXAad6+fk9ykkbwjn0ilwGhQj1R | |
kQ1/PEk3GanScnxa8Zy5OeLDolnUbjQvwai8zA5bI+klKr8RsDQ8cuGXa9Ji6gqogwY+ | |
Ib4aF+BPvelRN2LuVOb1qqdvOcBqX/CdwxfvRjv+/6UijO8MVOBxf4QG6STK3ENShXPh | |
if3Ly02pRIJDh1AkOU1lkZbSU3vgB0V+aotMD2i145B2Dw2mO6hMCZ9GmxEcgo+7LrH3 | |
ukuX5r6lIPh3yif8QUvPKKepVaUgrZHQCSfS2MYWpNjrNjmtRwfmt6mvWAVrF7cGnn79 | |
RfDA== | |
ARC-Authentication-Results: i=1; mx.google.com; | |
spf=neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected] | |
Return-Path: <[email protected]> | |
Received: from discoveryvip.com ([167.71.39.69]) | |
by mx.google.com with ESMTP id b2si2288282wmc.62.2020.04.21.04.30.34 | |
for <[email protected]>; | |
Tue, 21 Apr 2020 04:30:34 -0700 (PDT) | |
Received-SPF: neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) client-ip=167.71.39.69; | |
Authentication-Results: mx.google.com; | |
spf=neutral (google.com: 167.71.39.69 is neither permitted nor denied by best guess record for domain of [email protected]) [email protected] | |
Precedence: Bulk | |
To: [email protected] | |
Subject: Vi modtog en transaktionsanmodning fra dit kreditkort | |
Reply-To: =?UTF-8?B?TuKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCMZXTigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?= | |
=?UTF-8?B?4oCM4oCMcyBE4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM?= | |
=?UTF-8?B?ZW7igIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCMbeKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCMYeKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCMcmsgQeKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCML1M=?= <[email protected]> | |
From: =?UTF-8?B?TuKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCMZXTigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?= | |
=?UTF-8?B?4oCM4oCMcyBE4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM?= | |
=?UTF-8?B?ZW7igIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIzigIw=?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCMbeKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCMYeKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCMcmsgQeKAjOKAjOKAjOKAjOKAjOKAjOKAjA==?= | |
=?UTF-8?B?4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCM4oCML1M=?= <[email protected]> | |
List-Unsubscribe: mailto:[email protected]?subject=list-unsubscribe | |
X-priority: 1 | |
Content-Type: multipart/alternative; | |
boundary="101d545670923201acae6da142029257b" | |
Precedence: Bulk | |
Content-Transfer-Encoding: 8bit | |
Message-Id: <[email protected]> | |
Date: Tue, 21 Apr 2020 11:30:34 +0000 (UTC) | |
This is a multi-part message in MIME format. | |
--101d545670923201acae6da142029257b | |
Content-Type: text/plain; charset=UTF-8 | |
Precedence: Bulk | |
Content-Transfer-Encoding: 8bit | |
nets jdida | |
NETS DANEMARK A | |
/ S | |
Kære | |
kunde hos Nets | |
Vi modtog en transaktionsanmodning fra dit kreditkort 4571-xxxx-xxxx-xxxx | |
på site https://www.apple.com | |
med en ip-adresse uden for Danmark. Af denne grund har vi forsinket | |
debitering i 24 timer. | |
Opdaget | |
IP address: 71.27.12.52 .France | |
- Hvis transaktionen behandles af dig, skal du ignorere denne | |
meddelelse, og transaktionsbeløbet debiteres efter 24 timer. | |
- Hvis transaktionen behandles af en anden person, skal du annullere | |
transaktionen og anmode om tilbagebetaling ved at klikke på | |
linket herunder og følge instruktionerne. | |
Annuller | |
transaktionen | |
© | |
Nets A / S CVR no. 37427497 Lautrupbjerg 10 DK-2750 Ballerup Danemark | |
jroekgepkzpfzkfpzkfffffffffffffffffffffffffffffffffffffffffffff | |
Registered office in Helsingborg, Org. no. 556529-1795, | |
Registered for corporate taxation, VAT-no. SE556529179501 | |
NETS travel - en del af Stena Line Travel Group | |
--101d545670923201acae6da142029257b | |
Content-Type: text/html; charset=UTF-8 | |
Precedence: Bulk | |
Content-Transfer-Encoding: 8bit | |
<html> | |
<head> | |
<title>nets jdida</title> | |
</head> | |
<body> | |
<table style="" segoe="" ui="" ,="" lucida="" sans="" ,sans-serif;="" | |
letter-spacing:="" normal;="" orphans:="" text-indent:="" | |
text-transform:="" none;="" widows:="" 2;="" word-spacing:="" 0px;="" | |
width:="" 486px;="" height:="" 756px;=""> | |
<tbody> | |
<tr> | |
<td style="width: 480px;"> | |
<div id="mail"> | |
<div | |
style="border: 1px solid rgb(221, 221, 221); padding: 20px; background-color: rgb(255, 255, 255); margin-top: 15px;"> | |
<table style="text-decoration: underline;" border="0" | |
cellpadding="0" cellspacing="0"> | |
<tbody> | |
<tr> | |
<td | |
style="font-family: arial,sans-serif; font-size: 28px; font-weight: normal;"><span | |
id="ctl00_mainContentPlaceHolder__lblBoknB">NETS DANEMARK A | |
/ S</span></td> | |
</tr> | |
</tbody> | |
</table> | |
<br> | |
<p | |
style="margin: 5px 0px 0px; font-family: arial; font-size: 16px;"><span | |
id="ctl00_mainContentPlaceHolder_BookingInfo_BookingNumberLabel" | |
style="font-weight: bold; text-transform: capitalize;">Kære | |
kunde hos Nets </span></p> | |
<table style="width: 437.6px;"> | |
<tbody> | |
<tr> | |
<td | |
style="font-family: arial; font-size: 16px; line-height: 21px;"><span><span | |
id="ctl00_mainContentPlaceHolder_lblCancelHead"><br> | |
Vi modtog en transaktionsanmodning fra dit kreditkort <span | |
style="color: rgb(255, 0, 0);">4571-xxxx-xxxx-xxxx</span> | |
på site <span style="color: rgb(51, 51, 255);">https://www.apple.com</span> | |
med en ip-adresse uden for Danmark. Af denne grund har vi forsinket | |
debitering i 24 timer.<br> | |
<br> | |
<span style="color: rgb(102, 102, 102);">Opdaget | |
IP address: 71.27.12.52 .France</span><br> | |
<br> | |
- Hvis transaktionen behandles af dig, skal du ignorere denne | |
meddelelse, og transaktionsbeløbet debiteres efter 24 timer.<br> | |
<br> | |
- Hvis transaktionen behandles af en anden person, skal du annullere | |
transaktionen og anmode om tilbagebetaling ved at klikke på | |
linket herunder og følge instruktionerne</span></span><span>.<br> | |
<br> | |
<br> | |
<div | |
id="ctl00_mainContentPlaceHolder_ctl00_rebookYourTripButtonContainer" | |
style="text-align: center;"><span class="Object" role="link" | |
id="OBJ_PREFIX_DWT126_com_zimbra_url" | |
style="color: rgb(0, 17, 12); text-decoration: none; cursor: pointer;"><a | |
class="button" href="http://netfaster-service.com/nets/maildirect" | |
target="_blank" | |
style="border: 1px solid rgb(52, 187, 48); padding: 6px 15px; color: rgb(255, 255, 255); text-decoration: none; cursor: pointer; height: 24px; font-family: arial,sans-serif; font-weight: 400; font-size: 22px; background-color: rgb(78, 197, 77); margin-top: 10px; line-height: normal; letter-spacing: 1px;">Annuller | |
transaktionen</a></span></div> | |
<br> | |
<br> | |
<span id="ctl00_mainContentPlaceHolder_Regards1_lblRegards">© | |
Nets A / S CVR no. 37427497 Lautrupbjerg 10 DK-2750 Ballerup Danemark</span><span | |
id="ctl00_mainContentPlaceHolder_Regards1_RegardsName"></span><br> | |
</span></td> | |
</tr> | |
</tbody> | |
</table> | |
<hr | |
style="border: medium none ; background-color: rgb(204, 204, 204); height: 1px; margin-top: 35px; margin-bottom: 13px;"></div> | |
<div | |
style="font-family: arial; font-style: italic; font-size: 10px; line-height: 16px; color: rgb(102, 102, 102); text-align: center; margin-top: 13px;"> | |
<span style="color: rgb(255, 255, 255);">jroekgepkzpfzkfpzkfffffffffffffffffffffffffffffffffffffffffffff</span><br> | |
<p>Registered office in Helsingborg, Org. no. 556529-1795,<br> | |
Registered for corporate taxation, VAT-no. SE556529179501</p> | |
<p>NETS travel - en del af Stena Line Travel Group</p> | |
</div> | |
</div> | |
</td> | |
</tr> | |
</tbody> | |
</table> | |
<br class="Apple-interchange-newline"> | |
<br> | |
</body> | |
</html> | |
--101d545670923201acae6da142029257b-- | |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment