dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
1401
share rss forum feed


Cartel
Premium
join:2006-09-13
Chilliwack, BC
kudos:2
Reviews:
·TekSavvy DSL
·Shaw
·TELUS

Microsoft emails SCAM

What is this crap?
Link at the bottom if someone wants to "test" it, beware.

Flag this message
Notice of suspension
From Microsoft Wed Oct 10 08:29:51 2012
*******@yahoo.ca via 98.139.211.138; Wed, 10 Oct 2012 08:30:01 -0700

202.124.241.66
softfail (transitioning domain of microsoft.com does not designate 202.124.241.66 as permitted sender)
Sr7jR9AWLDsYrQFbsjbn3qunx_xkwkZkEy1JINXztDqscvM0 o0aDw7TH4PCL6rbr2biS5OxZz.ub9mDek2otfDE.LhiRUwn2bcOJNpRi6sQW SZR8gmh0r5Es705Rs4pYP1wfOpvxbl3CcV1kWEgQ36.DIDQaRCKDsOjTd24B _9MD8cHWsHmxuzeoucBq.aGlwuzkCNu67eXtzAiNFXb8ENQgJn3lUdA1oiBK BHO2Kq_0kSTNecr2fTAtzsekQx7VrfnAahA80AMx2E3adRcDZRPREtPkLq57 fJZaxdRHYXZbMcMOi_xR2Xz_ZO_PFjBfWqtYpM_exxagiQuFqucbi1buaPRK sJ3bd2XSo95d5UM33e1xU_YjGFdYCfnGvf9eyzaqGdRKQcFONB_D8ISjB4Iu P17tWh_Pig3d46nV4yxTeipOOfMVb4Dzq4MkTsmBQX9r44_VZTb6RnT_yX2f .zQ6Gg.H8KP2_95LUW7HuTZRQfK7dNbM9eF.EotLDQKMXMVNuwmeOhLAJG8s OK1gfejE8FuJNn3dXv6YnxH.3BNGtJMlk5juDmJd1U60EBIRwpPxlyGNDxJO aTwsa12kep0msAoN46F9p90Aq5j_B7v2I0vcDnuCO5ISdrQFMZowcxS.9GrJ 2n9iD.mxgHYqOz9vaC7_3OMYNj_.lhq.gEvLQILGr0yyKYn0ypMDNStZ.P6o 3axeVPnRfstL9B.jCilVnu1ym4l884R0xDZ0ym40sTPLnASgCojrKcIvjAC7 BHtB3xNi1o0FGp5qXC92mvcrkgR69B99j0m_M9kT7ph7jHCStIiJYlXYOFcE 9sc1UhgMknvddziKw86g3bvQEguvVi_ZLs2OkwNzfpgNHIFitssvMeQPRDoM A7bwxuvo.JnB3uFP.RVy430twbG0G9wF5dELniTP7QMC_AzjN6NxWF9GaX87 PHut4lCMVCU96g.ddebKzPWHL4Aw_1EFxUNYN3tkpmzyd8qbL5L9DGFmkcTB mxV.5bbr_Z897pc1m_3OIyjDirpO0coOiGO944lF5fMF2lg2wybu33NbvRKp a155aSo_i0.2lVrXgX93U7p02qmDJex_nzFj4jVhb1I1J8NOjabnC_VkYd_M uyuQwdzKy_66oAcR4XtgC074k.sYkjKdfn9kC7GNSRCtUFXd8cQnCzRXNImP j9EqAshbwrhR7fsJnKCxEtculvBbBgEpvwp85hvxfpAxpEpgwvyqO5_rkLXN Qu8kOtQwV2IR.gWv4QgUTrtyJh2b703PuAPUppBbDcVtXFfyG2ttvhL97bRa t_cQO9VVJhl2rq6Y3G03fwqL7egj3NP_LSgNM5OGtPzd0Wc725phmtS7b2R6
[202.124.241.66]
mta1108.mail.gq1.yahoo.com from=microsoft.com; domainkeys=neutral (no sig); from=microsoft.com; dkim=neutral (no sig)
from 127.0.0.1 (EHLO smtp-mx-server-8.servers.netregistry.net) (202.124.241.66) by mta1108.mail.gq1.yahoo.com with SMTP; Wed, 10 Oct 2012 08:30:00 -0700
from cpe-58-175-250-132.hdcz1.win.bigpond.net.au ([58.175.250.132] helo=User) by smtp-mx-server-8.servers.netregistry.net protocol: esmtpa (Exim 4.72 #1 (Debian)) id 1TLyEm-0007tU-CA; Thu, 11 Oct 2012 02:30:20 +1100
"Microsoft"
Add sender to Contacts
Notice of suspension
Thu, 11 Oct 2012 02:29:51 +1100
1.0
text/html; charset="Windows-1251"
7bit
3
Normal
Microsoft Outlook Express 6.00.2600.0000
Produced By Microsoft MimeOLE V6.00.2600.0000

()

8808

***************************************************************************

***************************************************************************

We've updated the Microsoft Services Agreement, which governs many of our online services - including your Microsoft account and many of our online products and services for consumers, such as Hotmail, SkyDrive, Bing, MSN, Office.com, Windows Live Messenger, Windows Photo Gallery, Windows Movie Maker, Windows Mail Desktop and Windows Writer.

Over the past days, we have sent notifications regarding your account suspension which many fails to update, However, failure to verify your records will result in account suspension. Click on the Verify button below and enter your login information on the following page to Confirm your records.

Thank you for using Microsoft products and services!

--------------------------------------------------------------------------------

Microsoft respects your privacy. Please read our online Privacy Statement.
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052

Click on the Verify button below is this link:

hxxp://dswarbrick.com/4784/win/dolua/pitol/


rcdailey
Dragoonfly
Premium
join:2005-03-29
Rialto, CA
I got a warning that it was a suspected phishing site.


jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
USA
kudos:24
Reviews:
·Cox HSI
·Speakeasy

1 recommendation

reply to Cartel
I would have just deleted it, believe it or not. While it's not impossible that I would get something that is real, I consider anything of this sort Spam. I just come here to find out what is real and what is not. A notice of suspension would ring loud bells to me re: it being Spam or something of that sort, and I would just automatically delete it. But that's just me.


Pjr
Don't Panic

join:2005-12-11
UK

1 recommendation

reply to Cartel
I used
wget hxxp://dswarbrick.com/4784/win/dolua/pitol/
to get the source of that page.

<p><font color="#990000" size="4">To update your windows installation records,</br>
you are required to choose your email address below.</font></p> 
 
Then they ask for your email provider, email address and finally email password.

--
Overflow error in /dev/null


La Luna
RIP Lisa
Premium
join:2001-07-12
Warwick, NY
kudos:3

1 recommendation

reply to Cartel
said by Cartel:

What is this crap?

It's crap. Delete it and ignore. The poor grammar is also a give away.

dave
Premium,MVM
join:2000-05-04
not in ohio
kudos:8
Reviews:
·Verizon FiOS
reply to rcdailey
said by rcdailey:

I got a warning that it was a suspected phishing site.

Ya think?

said by email :
Click on the Verify button below is this link:

hxxp://dswarbrick.com/4784/win/dolua/pitol/

Seems like an unlikely URL for Microsoft . Unless, of course, Microsoft is in the process of changing its corporate branding to "dswarbrick"

Perhaps Ballmer just likes folk music.

Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:5

2 recommendations

reply to Cartel
In the first place, Microsoft has stated a zillion times, over the years, that they NEVER send out an email of this nature asking one to click on some link to update your Microsoft account or anything else. So, you should have just deleted it immediately. If you, instead, kept reading then that link at the bottom is a dead giveaway that it is not from Microsoft.

I hope you used Properties/Details/Message Source to read that in Outlook Express and did NOT actually open it. If you foolishly opened it expect a ton of spam since the sender has confirmed a live address.
--
When governments fear people, there is liberty. When the people fear the government, there is tyranny. Thomas Jefferson


vaxvms
ferroequine fan
Premium
join:2005-03-01
Wormtown
kudos:3
Reviews:
·Charter
reply to Cartel
said by Cartel:

Over the past days, we have sent notifications regarding your account suspension which many fails to update,

"which many fails to update"?
--
It's not really power unless you abuse it.


CylonRed
Premium,MVM
join:2000-07-06
Bloom County

1 edit

1 recommendation

reply to Cartel
MS did not email you or anyone else, a scam.


Dude111
An Awesome Dude
Premium
join:2003-08-04
USA
kudos:13

1 recommendation

reply to rcdailey

 

Yes it is......

After you enter your email address and password it sends your data here

»dswarbrick.com/4784/win/dolua/pitol/all.php

Which dumps to

»dswarbrick.com/4784/win/dolua/pitol/mail.php

And finally to

»support.microsoft.com/kb/817144