Part III: And they keep a comin': phish, spam, so much in common ...

Received from: tony05-73-212.inter.net.il [80.230.73.212]

Received from: 81-86-77-79.dsl.pipex.com [81.86.77.79]

The email above on the left came from Israel, the one on the right from England. The hyperlinked websites at the time of the emails were
located in India. If you find the hyperlinks still active you will automatically be forwarded to www.onlinereplicastore.com hosted on a website using an IP address assigned to Spidernet Software Solution Pvt. Ltd; Internet Service Provider; Kothrud, Pune., India.

FBI & FCC Blacklisted website. Fraudulent website "is abusing credit card numbers that are being billed in China. Do not take our word for it, Google.com this website name and see for yourself the major fuss with scams and spam emails that this site is doing. Also does business with many other name, such as genuinereplicas.biz and others. Avoid at all costs. Online Replica Store was also reported billing under 5Maxing from Bezile as well." http://www.fakereviews.com/websites.htm See also: http://www.fakereviews.com/

On the right is still a third copy of the same email message emailed from Argentina with a link to a website in Brazil spoofing an email account of a London, England travel agency.

From: CM128-lcon0-31-121.cm.vtr.net [200.120.31.121] Chile, South America
Website: amabilisleaf.net [219.139.240.147] China
No connection to carcostcanada.com of Ontario, Canada, the spoofed sender.

From: 200-122-44-64.dsl.prima.net.ar [200.122.44.64] Argentina, South America
Website: ceals.com [200.139.97.122] in Brazil auto forwards to Indian scam site.
No connection to an Anite Travel Systems spoofed United Kingdom email account.

   

Received from: pd112.katowice.cvx.ppp.tpnet.pl [213.76.11.112]

Received from: c149019.net61215.cablenet.ne.jp [61.215.149.19]

Received from: pcp02617706pcs.paduca01.ky.comcast.net [68.63.250.164]

Received from: Z2A7Q5  [61.51.172.41] assigned by china-netcom.com

   

Received from: gqgzncl@bzq-80-53-49.red.bezeqint.net [82.80.53.49]

Received from: i220-99-161-253.s02.a043.ap.plala.or.jp [220.99.161.253]

For more see: Phish1, Phish2, Regions, SouthTrust Bank, Alan's Phishing Hole