Merhaba Arkadaşlar bugün hem vps sunucumun olduğu yerden hemde iletişim bilgilerimin bulunduğu alan adımdan aşağıdaki içeriklerin bulunduğu bir eposta iletisi aldım sunucu ip ve alan adım scam işlerde kullanılıyorlarmış
mailde belirtildiğine joker dns yönetimiş bunu durumu nasıl çöze bilirim
bu durumu daha önceden yaşayan arkadaşlar var mı saygılarımla.
http://particular.mediolanum.bmedson...e/index_1.html
http://particular.mediolanum.bmedson...e/index_2.html
http://particular.mediolanum.bmedson...m/online/a.php
http://particular.mediolanum.bmedson...NFO/index.html
http://particular.mediolanum.bmedson...O/index_2.html
http://particular.mediolanum.bmedson...O/index_1.html
http://particular.mediolanum.bmedson...med_INFO/a.php
with this IP: 74.208.111.165
Be aware that, though the malicious content is hosted by an IP foreign to you, you DNS service has been compromised in a way that any subdomain requested to naviajans.com will resolve towards the scam.
The hacker is using a wildcard technique (A wildcard DNS record is a record in a DNS zone that will match requests for non-existent domain names. A wildcard DNS record is specified by using a "*" as the leftmost label (part) of a domain name)
Please, also be aware that the phisher is using a FILTERING SYSTEM, most likely a htacces file, therefore it can only be accessed from a Spanish IP. I am attaching
some snapshots as evidence.
This fraudulent website represents a misuse of the intellectual property of Banco Mediolanum, as well as to obtain personal information of their customers in order to get fraudulent access into their bank accounts, use their credit cards, etc.
We need your collaboration to stop this fraud, restoring the normal operation of your DNS service.
We keep waiting for your feedback on this incident.
If you need further information please contact our SOC 24/7 at +34 91 754 8987.
With kind regards
-------------------------------------------------------------------------
Antifraud Command Center
SOC - Telefonica Spain
Tlf: +34 91 754 8987
Email: phishing@telefonica.es
Alan adımı sunucumun ipsini scam olarak kullanıyorlar yardım
3
●716
- 15-04-2015, 23:01:08
- 16-04-2015, 01:27:26işin garip tarafı o domain üzerinde hiçbir dosya kardeşim bu domain dışında iki adet domain mevcut dosyalarını tek tek taradım mevcut anti virüslerle zararlı dosya bulamadım sonuç olarak htaccess yönetmi ile ispanyadan girişleri engelledim bilgisi olan arkadaşlara sormak istedim daha farklı neler yapabilirim diye çünkü sunucu üzerinde hiçbir ilegal materyal yok.MiLLer7 adlı üyeden alıntı: mesajı görüntüle
- 16-04-2015, 01:32:35Antivirüslere yakalanmazlar ancak illaki kıytı köşede vardır dikkat edin.navitasarim adlı üyeden alıntı: mesajı görüntüle