Posteitaliane Mail Fraud


This classical form of scam is now sent to accounts, here some detail on the e-mail:

Subject: Accredito temporaneamente bloccato‏


Content: Ultime da Poste Italiane:  Gentile Cliente,
Abbiamo ricevuto una segnalazione di accredito di Euro 100 da UFFICIO POSTALE ROMA 52. L’accredito e’ stato temporaneamente bloccato a causa dell’incongruenza dei suoi dati, potra’ ora verificare i suoi dati e successivamente sara’ accreditato sul suo conto postale

Victim will be prompted to

that contains:


automaticalli redirected to that contains another redirect:

<HEAD><!DOCTYPE HTML PUBLIC “-//W3C//DTD HTML 4.0 Transitional//EN”>
<meta http-equiv=”Refresh” content=”0; URL=index.php?MfcISAPICommand=SignInFPP&UsingSSL=1&email=&userid=”>

finally user lands here:

As we can see from the Source Code there is a classical structure that ask to the user User and Password, these are the functions:

function ControllaPassword()
   var f = window.document.frmRegister

   if (f.password.value.length > 10 )
      alert(“La Password non puo’ superare la lunghezza di 10 caratteri.”)
      return false
   return true

That verifies if the password haa a correct length, and

function ControlloValori()
    var f = window.document.frmRegister
    if (f.login.value==””)
        alert(“Inserire il nome utente”)
        return false

    if ( ControllaPassword() == false )
        return false;

    return true

that collects user and pwd

If credentials are correct user is directed here:

where is asked for CC, CCV2, Scad

Here some info about this Malicious Domain:

IP Address:

IP Location Spain
– Spain – Schlund + Partner Ag
Response Code: 200
Domain Status: Registered And Active Website

See you to the next post.. 🙂

