Forced Induction Superchargers | Turbochargers | Intercoolers

Exoticperformanceplus phishing emails? Anyone else get one?

Thread Tools
 
Search this Thread
 
Old Sep 3, 2007 | 02:21 PM
  #21  
Jake@EPP's Avatar
FormerVendor
 
Joined: Mar 2006
Posts: 1,540
Likes: 0
From: Hell AFB
Default

If you guys don't mind, id like for everyone that received one, please send me a PM with your email/first and last name.
Reply
Old Sep 3, 2007 | 02:56 PM
  #22  
Paint_It_Black's Avatar
Banned
iTrader: (1)
 
Joined: Aug 2007
Posts: 1,044
Likes: 1
From: Chi-town West Burbs
Default

you don't think someone going through this would set up an anonymous email and send them through a proxy?

well.. you can hope someone would not think of things like that.
Reply
Old Sep 3, 2007 | 03:03 PM
  #23  
jeremy02's Avatar
On The Tree
 
Joined: Apr 2007
Posts: 182
Likes: 0
Default

It appears it was sent using an email spoofer, which anyone with a little programming knowledge can create. That's why they ask you to send your reply to a different email, they don't actually have access to the account they appeared to have sent the email from.
Reply
Old Sep 3, 2007 | 03:28 PM
  #24  
Frost's Avatar
FormerVendor
iTrader: (45)
 
Joined: Jul 2005
Posts: 5,913
Likes: 2
From: Richmond VA
Default

They must have HAD some access since they have gotten customer info...
Reply
Old Sep 3, 2007 | 03:33 PM
  #25  
Jake@EPP's Avatar
FormerVendor
 
Joined: Mar 2006
Posts: 1,540
Likes: 0
From: Hell AFB
Default

Originally Posted by Frost
They must have HAD some access since they have gotten customer info...
Not necessarily, we usually do not have customer email addresses in our DB.

Either way, just another spoofed email scam, ebay and paypal get this all the time.
Reply
Old Sep 3, 2007 | 05:01 PM
  #26  
vaticano's Avatar
TECH Enthusiast
15 Year Member
iTrader: (8)
 
Joined: Feb 2006
Posts: 524
Likes: 0
From: Denver Colo.
Default

Originally Posted by Camaroholic
I'd be interested in seeing the full email header (the part that's normally hidden, contains IP addresses and whatnot). Someone please post that up for us if you can.

tell me how and i will
Reply
Old Sep 3, 2007 | 05:05 PM
  #27  
740racing's Avatar
Staging Lane
iTrader: (10)
 
Joined: Jun 2006
Posts: 60
Likes: 0
From: Zanesville Ohio
Default

Originally Posted by Camaroholic
I'd be interested in seeing the full email header (the part that's normally hidden, contains IP addresses and whatnot). Someone please post that up for us if you can.

From sales@exoticperformanceplus.com Sat Sep 1 22:04:21 2007
Return-Path: <sales@exoticperformanceplus.com>
Authentication-Results: mta367.mail.mud.yahoo.com from=exoticperformanceplus.com; domainkeys=neutral (no sig)
Received: from 69.9.36.26 (EHLO crnc1.bug-software.com) (69.9.36.26)
by mta367.mail.mud.yahoo.com with SMTP; Sat, 01 Sep 2007 22:04:20 -0700
Received: (qmail 23421 invoked from network); 2 Sep 2007 05:10:27 -0000
Received: from localhost (127.0.0.1)
by localhost with SMTP; 2 Sep 2007 05:10:27 -0000
From: sales@exoticperformanceplus.com
To: bryan_near@yahoo.com
Subject: TO ALL CUSTOMERS.
Content-Length: 757
Reply
Old Sep 3, 2007 | 05:09 PM
  #28  
740racing's Avatar
Staging Lane
iTrader: (10)
 
Joined: Jun 2006
Posts: 60
Likes: 0
From: Zanesville Ohio
Default

From sales@exoticperformanceplus.com Sat Sep 1 21:09:24 2007
Return-Path: <sales@exoticperformanceplus.com>
Authentication-Results: mta206.mail.re3.yahoo.com from=exoticperformanceplus.com; domainkeys=neutral (no sig)
Received: from 69.9.36.26 (EHLO crnc1.bug-software.com) (69.9.36.26)
by mta206.mail.re3.yahoo.com with SMTP; Sat, 01 Sep 2007 21:09:23 -0700
Received: (qmail 7139 invoked from network); 2 Sep 2007 04:15:46 -0000
Received: from localhost (127.0.0.1)
by localhost with SMTP; 2 Sep 2007 04:15:46 -0000
From: sales@exoticperformanceplus.com
To: bryan_near@yahoo.com
Subject: For All Recent Customers.
Content-Length: 599

That was the 2nd email I recieved, yahoo email put the 1st one in my inbox and the 2nd email in my spam box, not sure why but they may be different ?
Reply
LS1 Tech Stories

The Best V8 Stories One Small Block at Time

story-0

Amazing '71 Camaro Restomod Is Modern Muscle Car Under the Skin

 Verdad Gallardo
story-1

6 Common C5 Corvette Failures and What's Involved In Repairing Them

 Pouria Savadkouei
story-2

Retro Modern Bandit Pontiac Trans AM Comes With Burt Reynolds' Autograph

 Verdad Gallardo
story-3

Top 10 Greatest Cadillac V Series Performance Models Ever, Ranked

 Pouria Savadkouei
story-4

Top 10 Most Powerful Chevy Trucks Ever Made!

 
story-5

Hennessey's New Supercharged Silverado ZR2 Has 700 HP

 Verdad Gallardo
story-6

Coachbuilt N2A Anteros Is an LS2-Powered C6 Corvette In Italian Clothes

 Verdad Gallardo
story-7

Awesome K5 Blazer Restomod Comes With C7 Corvette Power

 Verdad Gallardo
story-8

10 Camaros You Should Never Buy

 
story-9

10 LS Engine Myths That Refuse to Die

 Verdad Gallardo
Old Sep 3, 2007 | 05:25 PM
  #29  
black01_WS6's Avatar
TECH Junkie
iTrader: (13)
 
Joined: Sep 2004
Posts: 3,857
Likes: 0
From: Fort Myers, FL.
Default

I got a couple and deleted them. I was going to call Bob personally as I know him from when I used to live in Fort Wayne. There is no way Bob would send this out.
Reply
Old Sep 3, 2007 | 10:30 PM
  #30  
Tirefire's Avatar
TECH Resident
iTrader: (1)
 
Joined: Mar 2005
Posts: 922
Likes: 1
From: El Paso, Tx
Default

I got one. I forwarded it to Bob.
Reply
Old Sep 3, 2007 | 10:40 PM
  #31  
caMnaro's Avatar
TECH Regular
15 Year Member
iTrader: (24)
 
Joined: Sep 2006
Posts: 405
Likes: 1
Default

I got four but deleted 3. so i only forwarded the one i had.


INFO:
Date: Sun, 2 Sep 2007 05:03:43 +0000 (GMT)
X-Comment: Sending client does not conform to RFC822 minimum requirements
X-Comment: Date has been added by Maillennium
Received: from crnc1.bug-software.com ([69.9.36.26])
by alnrmxc21.comcast.net (alnrmxc21) with SMTP
id <20070902050342a2100mr5b0e>; Sun, 2 Sep 2007 05:03:43 +0000
X-Originating-IP: [69.9.36.26]
Received: (qmail 22293 invoked from network); 2 Sep 2007 05:10:05 -0000
Received: from localhost (127.0.0.1)
by localhost with SMTP; 2 Sep 2007 05:10:05 -0000
From: sales@exoticperformanceplus.com
To: my1989camaroiroc@comcast.net
Subject: TO ALL CUSTOMERS.

Due to a recent database error, we need to input previous customer information. We ask that you send these details listed below to our secure email, give to us by google, at <b>NetScaped2@gmail.com</b> THIS IS MANDATORY FOR ALL CUSTOMERS, Thanks for understanding!

Please Use Subject: VERIFICATION.

Information Needed:

Full Name:
Address:
City:
State:
Zip:
Email:
Home Phone:
Credit Card used for last purchase (this will be encrypted by google):
Expiration Date:
CVC2 Code (3 digits on back of card):

After this information is submitted to Netscaped2@gmail.com , we will reply back with an email confirming your acceptence back into the database! Thank you once again, your patience and helpfullness will NOT go unoticed!

-ExoticPerformancePlus.com-
Reply
Old Sep 3, 2007 | 11:26 PM
  #32  
BigDaddyBry's Avatar
TECH Fanatic
iTrader: (15)
 
Joined: Jun 2005
Posts: 1,896
Likes: 1
From: Ridgecrest, CA
Default

This should seriously be moved to the appropriate forum. Who the hell would look in FI for this?????????
Reply
Old Sep 4, 2007 | 01:25 AM
  #33  
Killer_Z's Avatar
TECH Resident
iTrader: (1)
 
Joined: Jan 2004
Posts: 858
Likes: 0
From: Patterson, CA
Default

hmm who ever is doin it is pretty good, the header isnt sayin much thats for damn sure.
Reply
Old Sep 4, 2007 | 04:13 AM
  #34  
BIG BAD BLACKSS's Avatar
Thread Starter
TECH Resident
iTrader: (4)
 
Joined: Sep 2005
Posts: 982
Likes: 1
From: Chicago
Default

Originally Posted by Jake@EPP
Big Bad, can you forward this email to me, Jake at Exoticperformance plus.com

Thanks
I;'m just checking on this now. I forwarded the one that i had opened and was sitting in my old mail. The other 3 were deleted after i read the first one and is already gone frommy recently deleted mail. One had a different subject line. I believe they all appeared to come from sales @ exotic performance plus. The one i forwarded shows thats where it came from.


I opriginally poste dthis in FI as i regularly see the EPP guys in this forum helping everyone out and they are the go to place for prochargers so i usually see most of their customers in here. I figured this would hit the most birds with one stone.

Last edited by BIG BAD BLACKSS; Sep 4, 2007 at 04:21 AM.
Reply
Old Sep 4, 2007 | 05:57 AM
  #35  
EPP's Avatar
EPP
FormerVendor
iTrader: (22)
 
Joined: Mar 2003
Posts: 13,063
Likes: 2
Default

Thanks, I appreciate all the info. Hopefully we can get something done about this before someone actually give the info to the scammer. Can't everyone just get a real job!!! Bob
Reply
Old Sep 4, 2007 | 08:46 AM
  #36  
Speed's Avatar
TECH Enthusiast
20 Year Member
iTrader: (33)
 
Joined: Jul 2002
Posts: 609
Likes: 0
From: Ok
Default

Someone is relaying off their localhost to attempt to mask it. They were trying to relay or use a seperate client through yahoo as well (not really hard to do).

The first time it enters the internet, it does so from 69.9.36.26 which resolved to crnc1.bug-software.com. The IP range is owned by a company in New Jersey which appears to be leasing IP space. Tracing bug-software.com back through it's registrar it comes up with:

Name: Domain Admin
Company: PrivacyProtect.org
Address:

P.O. Box 65
All Postal Mails Rejected, visit Privacyprotect.org

City: Monster
State:
Country: NL
Zip: 2680 AB
Tel No: 45 36946676
Fax No:
Email: contact@PrivacyProtect.org

PrivacyProtect.org is a domain owner obfuscation service which registers domains on someone's behalf to protect their identity.

There are a few other ways to dig out the information but it's very likely it's an oversea's scammer, who probably harvested email addresses from sites EPP vists. It's fairly new to see in common place but the practice basically plays on the assumption and trust people naturally give to small companies with whom they've worked directly in the past. It's easy to be distrustful of phishing emails targeting eBay and large banks since phishing emails are often random and mailed as spam. In this case, it requires a little more work on behalf of the attacker but often produces better results. It's also possible the company that processes EPP's credit card authorizations lost some data or EPP's own database was compromised. I doubt it for an attack such as this however since harvesting email addresses from message boards like these is easy.

If Bob were my client in this case, I would recommend verifying security on whatever storage process customer records are stored in and notifying the online payment processor of the scam attempts. They will likely have a security team who can help investigate.

Last edited by Speed; Sep 4, 2007 at 11:48 AM. Reason: can't speeel
Reply
Old Sep 4, 2007 | 09:52 AM
  #37  
EPP's Avatar
EPP
FormerVendor
iTrader: (22)
 
Joined: Mar 2003
Posts: 13,063
Likes: 2
Default

Thanks, you know your stuff! Bob
Reply
Old Sep 4, 2007 | 09:58 AM
  #38  
Speed's Avatar
TECH Enthusiast
20 Year Member
iTrader: (33)
 
Joined: Jul 2002
Posts: 609
Likes: 0
From: Ok
Default

Any time bud. I have the pleasure of weeding through stuff like this for a living lol. But you guys have been super cool to me in the past so if you need/want any help documenting or submitting this, just shoot me a pm.
Reply
Old Sep 4, 2007 | 10:36 AM
  #39  
My2ndls1's Avatar
On The Tree
iTrader: (3)
 
Joined: Oct 2004
Posts: 117
Likes: 0
Default

I got one also, but immediately deleted it. I hope noone falls for this...
Reply
Old Sep 4, 2007 | 11:29 AM
  #40  
LSs1Power's Avatar
TECH Addict
iTrader: (5)
 
Joined: Mar 2002
Posts: 2,320
Likes: 0
From: VA
Default

I got one too. It seem like someone from the boards who knows epp customers and somehow got their e-mails
Reply



All times are GMT -5. The time now is 01:16 AM.

story-0
Amazing '71 Camaro Restomod Is Modern Muscle Car Under the Skin

Slideshow: This heavily modified 1971 Camaro mixes classic muscle car styling with a fifth-generation Camaro interior and modern LS3 power.

By Verdad Gallardo | 2026-05-12 18:06:42


VIEW MORE
story-1
6 Common C5 Corvette Failures and What's Involved In Repairing Them

Slideshow: From wobbling harmonic balancers to failed EBCMs, these are the issues that define long-term C5 ownership and what repairs typically involve.

By Pouria Savadkouei | 2026-05-07 18:44:57


VIEW MORE
story-2
Retro Modern Bandit Pontiac Trans AM Comes With Burt Reynolds' Autograph

Slideshow: A modern Camaro transformed into a retro icon, this limited-run "Bandit" build blends nostalgia with brute force in a way few revivals manage.

By Verdad Gallardo | 2026-04-21 13:57:02


VIEW MORE
story-3
Top 10 Greatest Cadillac V Series Performance Models Ever, Ranked

Slideshow: Cadillac didn't just crash the high-performance luxury vehicle party, it showed up loud, supercharged, and occasionally a little unhinged...

By Pouria Savadkouei | 2026-04-16 10:05:15


VIEW MORE
story-4
Top 10 Most Powerful Chevy Trucks Ever Made!

Slideshow: Top ten most powerful Chevy trucks ever made

By | 2026-03-25 09:22:26


VIEW MORE
story-5
Hennessey's New Supercharged Silverado ZR2 Has 700 HP

Slideshow: Hennessey has turned the Silverado ZR2 into a 700-hp off-road monster with supercharged V8 power and a limited production run.

By Verdad Gallardo | 2026-03-24 18:57:52


VIEW MORE
story-6
Coachbuilt N2A Anteros Is an LS2-Powered C6 Corvette In Italian Clothes

Slideshow: A one-off sports car that looks like a vintage Italian exotic-but hides a C6 Corvette underneath-just sold for the price of a new mid-engine Corvette.

By Verdad Gallardo | 2026-03-23 18:53:41


VIEW MORE
story-7
Awesome K5 Blazer Restomod Comes With C7 Corvette Power

Slideshow: A heavily reworked 1972 K5 Blazer swaps its off-road roots for a low-slung street-focused build with modern V8 power.

By Verdad Gallardo | 2026-03-09 18:08:45


VIEW MORE
story-8
10 Camaros You Should Never Buy

Slideshow: There are thousands of used Camaros on the market but we think you should avoid these 10

By | 2026-02-17 17:09:30


VIEW MORE
story-9
10 LS Engine Myths That Refuse to Die

Slideshows: Which one of these myths do you believe?

By Verdad Gallardo | 2026-01-28 18:10:11


VIEW MORE