Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


ANglEAUT

altered-ego
2436 posts

Uber Geek
+1 received by user: 842

Trusted
Lifetime subscriber

#280256 4-Dec-2020 10:33
Send private message

Received an SMS this morning from +61478888396 & it seems suspicious. Has anybody else come across this number?

 

== Message content ==

 

We have attempted to deliver ur package UPS016..., but there is an unpaid customs charge. Follow the instructions here: https://SNIP

 

== end ==

 

 

 

I didn't order anything from Australia and I don't have any parcels currently being shipped via UPS.

 

As carefully as I could I followed the link which led to https://SNIP which is a nginx server with a 403 Forbidden error.

 

 

 

Thanks for your input

 

 

 

Edit: Removed "possible" from the title.

 

 





Please keep this GZ community vibrant by contributing in a constructive & respectful manner.


View this topic in a long page with up to 500 replies per page Create new topic

This is a filtered page: currently showing replies marked as answers. Click here to see full discussion.

sidefx
3775 posts

Uber Geek
+1 received by user: 1295

Trusted

  #2616245 4-Dec-2020 10:37
Send private message




"I was born not knowing and have had only a little time to change that here and there."         | Octopus Energy | Sharesies
              - Richard Feynman




Oblivian
7345 posts

Uber Geek
+1 received by user: 2117

ID Verified

  #2616270 4-Dec-2020 11:08
Send private message

I'm not sure where the data has been sourced, but they are doing regional it seems too.

 

Basically there was a mob of them sent to Kaiapoi users on Monday. Specifically mentioning the township too.

 

 

 

Also on the same day a 'Lotto is looking for Mr or Mrs x in <location> It's regarding the selection of your name. Click here <>'. Similar number CID +61 478 888 660

 

Obviously mass SMS provider and falsified GW/source

 

Decoded the short URL, and it was a new BS domain with survey, submitting the name in the message and the individual code. So potentially they are logging individual numbers of those who click the URL to confirm target too.

 

Short URL decode/sandbox

 

http://checkshorturl.com/ 

 

Most people click, back out, and then delete. But I believe if enough forwarded to DIA they can get the providers to start checking logs and intercept the delivery flow?

 

 


View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.