PDA

View Full Version : possible phishing



miik999
09-18-2010, 10:17 AM
I have a conservatory business. I recieved an email from a (kevin@projectservices.ie) . I have tried to reply but my emails keep bouncing back. I was wondering was there any way to verify his email address.

copy of email I recieved

Hi,
I have attached two drawings showing a conservatory which we are pricing as part of an overall house extension package. The conservatory is sized as per the plan dimensions and there is also an indicative elevation. The colour will be white. Make what ever other assumptions you feel appropriate as again this is only a planning permission drawing but at the same time it is what we are required to build the job from. Can you give a price for the supply and installation of this conservatory by close of business on Monday the 20th of September.
Regards
Kevin

De Master Yoda
09-18-2010, 10:40 AM
Hi. If his emails keep bouncing then it is possible that his email supplier has closed his account for some reason,(If you have the correct details).

In his email he does not mention the name of his company nor his phone number and this seems odd if he is looking for business.

If he supplied the drawings in attachments, then it would be wise to update your antivirus and do some scans.

You knowledge of the conservatory business should alert you as to whether the rest of his message is believable.

Garreg Ddu
09-18-2010, 08:16 PM
"projectservices.ie" is an empty "holding" page on a server at IP Address 212.126.36.154 which is run by "Servers Ireland" at LetsHost.ie

The site was originally set up in January 2008, and is registered to "PROJECT ANALYSIS SERVICES LIMITED". There is a link which may be of use at http://www.projectanalysisservices.ie/support/ which leads to their helpdesk, but again this appears to be "under maintenance". A call to the hosting ISP may reveal more information, Servers Ireland, Unit 6D, Callan House, Malahide Road Ind Estate, Dublin 17. Tel. 01 653 5032


It looks as though the empty, possibly dormant, site is being used for sending out emails. If you have the emails, please post the full headers here for us to analyse. The threads at http://antifraudintl.org/showthread.php?t=15352 and http://antifraudintl.org/showthread.php?t=21446 may help.