Has anyone heard of Brandimensions? I received the following email from one of their "Incident Response Analysts" today, regarding a supposed phishing attack. The domain in question is a .com.pt (Portugese) domain, which I have nothing to do with (I have the .com, not the .com.pt). I replied to the effect that I would hope their "Incident Response Analysts" would know the difference between .com and .com.pt! Received no response, but when I telephoned the person who sent the email, she acknowledged having received my reply, admitted the mistake, and seemed in a hurry to get off the phone.
I can envision such an error on the part of Brandimensions causing problems with the victim's ISP/upstream provider/parking service, etc.
What steps can or should one take to head off such potential problems?
I can envision such an error on the part of Brandimensions causing problems with the victim's ISP/upstream provider/parking service, etc.
What steps can or should one take to head off such potential problems?
My name is XXXXXXXX XXXXXXX and I work for Brandimensions, an online brand protection company. I am contacting you on behalf of our client, XXXXX XXXXX XXXX who is experiencing a phishing attack that is being carried out by a web site that lists you as the registered owner of the domain.
Due to the fraudulent nature of this webpage we require that you have the site or the page shut down.
Domain: XXXX.com.pt
Suspect URL: http://www.XXXX.com.pt/cms-files/www.XXXXXXXXXX.com/?email_from=<?=$_REQUEST['email_from']?>
Please have one of your staff contact me at [email protected] or -905-271-3725 ext XXX to confirm that you have received this e-mail and update me on the status of shutting down the fraudulent site.
If possible, please forward a copy of any associated information such as:
- Web Server log
- Telnet log
- SSH log
- FTP log
- Fraudulent Web Server content (script, etc.)
Thank you
XXXXXXXX XXXXXXX | Incident Response Analyst | Brandimensions Inc. | Tel: 905.271.3725 xXXX | [email protected]
T-D