iReceived: from EUR01-DB5-obe.outbound.protection.outlook.com (mail-db5eur01on0121.outbound.protection.outlook.com [104.47.2.121]) by anna.lesderid.net (Postfix) with ESMTP id 24C89DD222 for ; Thu, 9 Mar 2017 15:03:41 +0100 (CET) Received: from DB6PR0601MB2661.eurprd06.prod.outlook.com (10.168.82.14) by DB5PR06MB1272.eurprd06.prod.outlook.com (10.162.156.26) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.947.12; Thu, 9 Mar 2017 14:03:37 +0000 Received: from DB6PR0601MB2661.eurprd06.prod.outlook.com ([10.168.82.14]) by DB6PR0601MB2661.eurprd06.prod.outlook.com ([10.168.82.14]) with mapi id 15.01.0947.020; Thu, 9 Mar 2017 14:03:37 +0000 From: TE_SEGURIDAD_SERVICIO_ANTIFRAUDE To: Les De Ridder CC: DS_TSOL_phishing , TE_SEGURIDAD_SERVICIO_ANTIFRAUDE Subject: RE: We have detected that LAINFILE is hosting a fraudulent website that offers a Phishing scam against Sociedad Estatal de Correos y Telegrafos Thread-Topic: We have detected that LAINFILE is hosting a fraudulent website that offers a Phishing scam against Sociedad Estatal de Correos y Telegrafos Thread-Index: AdKC68BFUqrZJjuGStG6+b4lUd5XXwCd3O5AAALEL/AAAEU+AATblfYQ Date: Thu, 9 Mar 2017 14:03:36 +0000 Message-ID: References: In-Reply-To: Accept-Language: es-ES, en-US Content-Language: es-ES X-MS-Has-Attach: X-MS-TNEF-Correlator: authentication-results: fuwafuwa.moe; dkim=none (message not signed) header.d=none;fuwafuwa.moe; dmarc=none action=none header.from=telefonica.com; x-ms-exchange-messagesentrepresentingtype: 1 x-originating-ip: [81.41.132.163] x-ms-office365-filtering-correlation-id: 75733b2d-af2f-4e93-0897-08d466f51511 x-ms-office365-filtering-ht: Tenant x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(48565401081);SRVR:DB5PR06MB1272; x-microsoft-exchange-diagnostics: 1;DB5PR06MB1272;7:+/Kbl9lOoz0PHkysiw31cltE6ksoDDX5EGOrvImWyLApJxMkrOUfCE4LGOiLU6BvCgBU3kUBhl/TJFLPji+dY/Zs5nDSw2DdbMyooCL8JnVmZbwr7yNNLSH5f4cVTUKjt1E4gGYhg6oSTboVNb3vuYwEbyhiH3Kovttn9PUcL9QAlbdEfoTLEmqk6OmRVW/1SXErGekIGOrX1Q07FBjpXY0zCaJRUynEK5GRCj13BstbCOY7qd/neqM3EnWKexNBd+XhJS2FT4F8TftWNyfj6LmNMlblaqm5owkm5Ryk2I4tMTBWziQf3OlP8GYw60L2BG3APEKRYDo8YYQaHAzFVQ== x-microsoft-antispam-prvs: x-exchange-antispam-report-test: UriScan:(40392960112811)(21748063052155)(231250463719595); x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(6041248)(20161123564025)(20161123555025)(20161123558025)(20161123560025)(20161123562025)(6072148);SRVR:DB5PR06MB1272;BCL:0;PCL:0;RULEID:;SRVR:DB5PR06MB1272; x-forefront-prvs: 0241D5F98C x-forefront-antispam-report: SFV:NSPM;SFS:(10019020)(39860400002)(39450400003)(39840400002)(39410400002)(39850400002)(252514010)(24454002)(4326008)(229853002)(5660300001)(6246003)(6916009)(2950100002)(8936002)(110136004)(25786008)(53936002)(606005)(6436002)(790700001)(6116002)(3846002)(8676002)(7696004)(6506006)(53386004)(38730400002)(86362001)(81166006)(77096006)(53346004)(102836003)(107886003)(189998001)(3660700001)(10710500007)(236005)(74316002)(66066001)(7110500001)(15650500001)(2420400007)(7906003)(7736002)(9686003)(50986999)(76176999)(54356999)(2906002)(6306002)(54896002)(99286003)(3280700002)(55016002)(122556002)(54906002)(33656002)(1680700002)(2900100001)(61373002)(9010500006)(19627235001);DIR:OUT;SFP:1102;SCL:1;SRVR:DB5PR06MB1272;H:DB6PR0601MB2661.eurprd06.prod.outlook.com;FPR:;SPF:None;MLV:sfv;LANG:en; spamdiagnosticoutput: 1:99 spamdiagnosticmetadata: NSPM Content-Type: multipart/alternative; boundary="_000_DB6PR0601MB2661B2CCCA83B96D1EC396C8C9210DB6PR0601MB2661_" MIME-Version: 1.0 X-OriginatorOrg: telefonica.com X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Mar 2017 14:03:36.9878 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10 X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB5PR06MB1272 Hello, Could you please remove once more this files: hxxp://p.fuwafuwa.moe/qgrazk.css hxxp://p.fuwafuwa.moe/urdelr.css hxxp://p.fuwafuwa.moe/mdffth.css hxxp://p.fuwafuwa.moe/nkjcoa.css hxxp://p.fuwafuwa.moe/ygegkm.js hxxp://p.fuwafuwa.moe/zdbkvk.js hxxp://p.fuwafuwa.moe/ovisan.js hxxp://p.fuwafuwa.moe/ifqnra.js hxxp://p.fuwafuwa.moe/cbpisx.js hxxp://p.fuwafuwa.moe/adkeer.js hxxp://p.fuwafuwa.moe/vrmxsq.js hxxp://p.fuwafuwa.moe/pyftal.js hxxp://p.fuwafuwa.moe/mxkqsi.js hxxp://p.fuwafuwa.moe/amwuzd.js hxxp://p.fuwafuwa.moe/gtjjkc.js hxxp://p.fuwafuwa.moe/ihibjo.js hxxp://p.fuwafuwa.moe/eebxgu.js hxxp://p.fuwafuwa.moe/hiqigm.js hxxp://p.fuwafuwa.moe/wgzddk.js hxxp://p.fuwafuwa.moe/wvczgj.js hxxp://p.fuwafuwa.moe/cobvtt.js hxxp://p.fuwafuwa.moe/puplbx.js hxxp://p.fuwafuwa.moe/vivcvc.css hxxp://p.fuwafuwa.moe/ypgwbn.css hxxp://p.fuwafuwa.moe/btcpto.css hxxp://p.fuwafuwa.moe/esaxve.css hxxp://p.fuwafuwa.moe/ujnicm.css Thank you! Regards --------------------------------------------------------------- CyberThreats - Anti-Fraud Service Telefónica España Phone: +34 900102230 (option 9) Emails: phishing@telefonica.com servicio.antifraude@telefonica.com