domingo, 26 de abril de 2026

Golpe: Vivo Empresas:Sua fatura chegou !!!

Email remetente:
noreply@business.perfectlogisticsbd.com

Link da fatura:https://handbid.app.link/AStKfkntv2b



Estrutura do phishing:
HTTP/2 200 
content-type: text/html; charset=utf-8
content-length: 11988
server: openresty
date: Sun, 26 Apr 2026 13:05:33 GMT
accept-ch: Sec-CH-UA-Platform-Version,Sec-CH-UA-Model
set-cookie: _s=ddN2oCVpxMuuJG7DenAMwn8ZHGr2DUFNLsrkgSrSp9XyrEGC8rlaoLiida18X4Va; Max-Age=31536000; Domain=.app.link; Path=/; Expires=Mon, 26 Apr 2027 13:05:33 GMT; Secure
last-modified: Sun, 26 Apr 2026 13:05:33 GMT
content-security-policy: frame-ancestors 'self'
etag: W/"2ed4-yuqzLk9uVrCNsr3aSzE8G9lutXg"
strict-transport-security: max-age=31536000; includeSubDomains
x-cache: Miss from cloudfront
via: 1.1 effdc374afee94e7da21facc30630a84.cloudfront.net (CloudFront)
x-amz-cf-pop: GIG52-P2
x-amz-cf-id: ke0p2r26Oeza1WqknoXtK-uIS8IrAifH78sMhTm1qEoJw9-5LnzMcA==


Whois Domínio:
Domain Name: perfectlogisticsbd.com
Registry Domain ID: 3013667069_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.discount-domain.com
Registrar URL: http://www.onamae.com
Updated Date: 2025-09-04T13:30:12Z
Creation Date: 2025-08-26T09:48:34Z
Registrar Registration Expiration Date: 2026-08-26T09:48:34Z
Registrar: GMO Internet, Inc.
Registrar IANA ID: 49
Registrar Abuse Contact Email: abuse@internet.gmo
Registrar Abuse Contact Phone: +81.337709199
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Registry Registrant ID: Not Available From Registry
Registrant Name: Whois Privacy Protection Service by onamae.com
Registrant Organization: Whois Privacy Protection Service by onamae.com
Registrant Street: 26-1 Sakuragaoka-cho
Registrant Street: Cerulean Tower 11F
Registrant City: Shibuya-ku
Registrant State/Province: Tokyo
Registrant Postal Code: 150-8512
Registrant Country: JP
Registrant Phone: +81.354562560
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: proxy@whoisprotectservice.com
Registry Admin ID: Not Available From Registry
Admin Name: Whois Privacy Protection Service by onamae.com
Admin Organization: Whois Privacy Protection Service by onamae.com
Admin Street: 26-1 Sakuragaoka-cho
Admin Street: Cerulean Tower 11F
Admin City: Shibuya-ku
Admin State/Province: Tokyo
Admin Postal Code: 150-8512
Admin Country: JP
Admin Phone: +81.354562560
Admin Phone Ext:
Admin Fax:
Admin Fax Ext:
Admin Email: proxy@whoisprotectservice.com
Registry Tech ID: Not Available From Registry
Tech Name: Whois Privacy Protection Service by onamae.com
Tech Organization: Whois Privacy Protection Service by onamae.com
Tech Street: 26-1 Sakuragaoka-cho
Tech Street: Cerulean Tower 11F
Tech City: Shibuya-ku
Tech State/Province: Tokyo
Tech Postal Code: 150-8512
Tech Country: JP
Tech Phone: +81.354562560
Tech Phone Ext:
Tech Fax:
Tech Fax Ext:
Tech Email: proxy@whoisprotectservice.com
Name Server: nsbd1.hostseba.com
Name Server: nsbd2.hostseba.com
DNSSEC: unsigned

--------------------------------------------------
"domain": "perfectlogisticsbd.com",
  "base_domain": "perfectlogisticsbd.com",
  "dnssec": false,
  "soa": {
    "record": "nsbd1.hostseba.com. root.alpha.hostseba.com. 2026041849 3600 1800 1209600 86400",
    "values": {
      "primary_nameserver": "nsbd1.hostseba.com",
      "rname_email_address": "root@alpha.hostseba.com",
      "serial": 2026041849,
      "refresh": 3600,
      "retry": 1800,
      "expire": 1209600,
      "minimum": 86400
    }
  },
  "ns": {
    "hostnames": [
      "nsbd2.hostseba.com",
      "nsbd1.hostseba.com"
    ],
    "warnings": []
  },
  "mx": {
    "hosts": [
      {
        "preference": 0,
        "hostname": "perfectlogisticsbd.com",
        "addresses": [
          "103.65.138.22"
        ],
        "dnssec": false,
        "tls": false,
        "starttls": false
      }
    ],
    "warnings": [
      "perfectlogisticsbd.com: SMTP error code Connection unexpectedly closed: timed out"
    ]
  },
  "mta_sts": {
    "valid": false,
    "error": "An MTA-STS DNS record does not exist."
  },
  "spf": {
    "record": "v=spf1 +a +mx +ip4:103.65.138.22 +ip4:103.174.152.66 ~all",
    "valid": true,
    "dns_lookups": 2,
    "void_dns_lookups": 0,
    "warnings": [],
    "parsed": {
      "mechanisms": [
        {
          "action": "pass",
          "mechanism": "a",
          "value": "perfectlogisticsbd.com",
          "dns_lookups": 1,
          "void_dns_lookups": 0,
          "addresses": [
            "103.65.138.22"
          ]
        },
        {
          "action": "pass",
          "mechanism": "mx",
          "value": "perfectlogisticsbd.com",
          "dns_lookups": 1,
          "void_dns_lookups": 0,
          "hosts": [
            {
              "preference": 0,
              "hostname": "perfectlogisticsbd.com"
            }
          ]
        },
        {
          "action": "pass",
          "mechanism": "ip4",
          "value": "103.65.138.22"
        },
        {
          "action": "pass",
          "mechanism": "ip4",
          "value": "103.174.152.66"
        }
      ],
      "redirect": null,
      "exp": null,
      "all": "softfail"
    }
  },
  "dmarc": {
    "record": "v=DMARC1; p=none;",
    "location": "perfectlogisticsbd.com",
    "valid": true,
    "warnings": [
      "A p tag value of none makes DMARC unenforced on email sent as perfectlogisticsbd.com.",
      "rua tag (destination for aggregate reports) not found."
    ],
    "tags": {
      "v": {
        "value": "DMARC1",
        "explicit": true
      },
      "p": {
        "value": "none",
        "explicit": true
      },
      "adkim": {
        "value": "r",
        "explicit": false
      },
      "aspf": {
        "value": "r",
        "explicit": false
      },
      "fo": {
        "value": "0",
        "explicit": false
      },
      "pct": {
        "value": 100,
        "explicit": false
      },
      "psd": {
        "value": "u",
        "explicit": false
      },
      "rf": {
        "value": "afrf",
        "explicit": false
      },
      "ri": {
        "value": 86400,
        "explicit": false
      },
      "t": {
        "value": "n",
        "explicit": false
      },
      "sp": {
        "value": "none",
        "explicit": false
      },
      "np": {
        "value": "none",
        "explicit": false
      }
    }
  },
  "smtp_tls_reporting": {
    "valid": false,
    "error": "An SMTP TLS Reporting record does not exist."
  },
  "bimi": {
    "record": null,
    "valid": false,
    "selector": "default",
    "error": "A BIMI record does not exist at the default selector."

Nenhum comentário:

Postar um comentário