使用UMail收到一封偽admin的信
內容大約是如下,還有一個夾檔open.html(839byte)
Dear Customer,
This e-mail was send by admin@xx.xx.xx to notify you that we have temporarily prevented access to your account.
We have reasons to beleive that your account may have been accessed by someone else. Please open attached file (open.html) and Follow instructions.
xx.xx.xx
這是釣魚信
打開表頭分析
會看見他的Return-Path是往adornl1@reuben.com丟
打開open.html
他會連去他指定的站台下載一隻pdf檔
追查回去發現他是在74.125.155.27
應該是放在Google的Web
可以使用此方式處理
viewtopic.php?f=5&t=2611