Hacker News new | ask | show | jobs
by Scoundreller 1226 days ago
Checked my emails, didn't find anything, but looking through gmail spam box, I got a DHL one:

Subject: Your parcel was not able to be delivered

Sender: contact <hello@namecheap.com>

> Dear Client,

> We regret to inform you that your parcel was not able to be delivered on the specified date, xx/02/2023. The parcel is currently located in the DHL warehouse near your town.

> The reason for the delay was that the sender did not pay the necessary fees for the delivery. To avoid the parcel being returned, we ask that you pay the fee of 6.xx USD. You can track your parcel and pay the fee by clicking the tracking button.

> Track and Pay >> > DETAILS

> Order number: xxxxxxxxxxxx

> Total: (x.xx USD)

> Delivery is planned between: xx.02.2023 - xx.02.2023

> Once the fee is paid, we will be able to deliver the parcel . We apologize for any inconvenience caused and thank you for your understanding. Sincerely,

> The DHL Team

Link URL is: https://links.namecheap.com/u/click?_t=[long tracking info redacted]

Tried following the link in TOR and on a virtual machine, both get just a 2 word "Unauthorized Access", but it redirects to: hxxps://accomplish-delivery . mysafebridge . info/WorldwideDelivery0/auth/dhl/index.php?utm_source=Iterable_Marketing&utm_medium=email&utm_campaign=MKTG_CRM_Welcome_Hosting_D5_WF_20221118

Slightly modified it to make it non-clickable

1 comments

I found the Metamask email in my spam, with the subject: "MetaMask : Your wallet is about to be suspended", with the headline of the mail "Your wallet is about to be suspended Apply for KYC Verification"

Hopefully no one falls for these, sneaky to hind the redirect behind the links.namecheap

I think the redirect being behind links.namecheap was an artefact of the compromised mailing service rather than intended behaviour: the body text of the Metamask email displayed a fake metamask URL https://verification.metamask.io/KYC?[snipped ID] that the link.namecheap.com link was wrapped around

Did make it clear that something belonging to Namecheap had been compromised though...

Would you be able to share the (scrubbed from your own personal info) headers on a gist or pastebin or similar?