Do NOT tell your scammer he is posted here, or report their accounts as it puts others at risk!

DO NOT click on any links in these emails.

Unread postby firefly » Thu Dec 14, 2017 7:25 pm

Warning about the sender:

Don't pay the fake #Xero invoice. Email links to a compromised SharePoint site, hosting a Javascript file executing a malicious trojan.

Warning posted by the real Xero on their site -

December 14th, 2017 – Fake Invoice phishing email

We’ve had reports of people receiving a new version of the fake invoice reminder phishing email, similar to those we reported about in June, July, August and November. The sending address of the email is with a subject of ‘Bill INV-0906 from Enquip Pty Ltd is due soon’. The invoice amount in the email also varies.

Please be aware that is not a sending address nor a domain used by Xero, and this email was not sent by us. Nor was it sent by Enquip Pty Ltd. The criminal sending the email has exploited the name of this legitimate business to try to make their email more convincing.

If you have received this email, you should report it as phishing and delete it. Do not click on any links or attachments. The online bill link and PDF attachment in this phishing email will prompt you to download a malicious file, possibly ransomware.

Email - forwarded to us by one of the targeted victims:

From: Xero
Sent: Thursday, December 14, 2017
Subject: Bill INV-0906 from Enquip Pty Ltd is due soon

Dear Client

Thanks for working with us. This is a gentle reminder that your bill for $286.88 is due on 18 Dec 2017.

If you've already paid it, thank you for your prompt payment we are sorry for bothering you and please ignore this email.

To view your bill visit https: / /

If you've got any questions, or want to arrange alternative payment don't hesitate to get in touch.

Thank you

Accounts & Administration
Enquip Pty Ltd

The email has a pdf attachment for download.


X-From_: Thu Dec 14 2017
Return-Path: <>
X-Greylist: Passed host:
Received: from
Date: Wed, 13 Dec 2017
Message-Id: <>
To: <xxx>
From: "Xero" <>
Subject: Bill INV-0906 from Enquip Pty Ltd is due soon
List-Unsubscribe: <mailto: ? subject=unsubscribe>

Originating IP:
Originating ISP: Ovh Sas
Country of Origin: France

The fake site used in the phishing attack was created on the same day as the one when the above email was sent:

Domain name:
Update Date: 2017-12-13
Creation Date: 2017-12-13
Registrar Registration Expiration Date: 2018-12-13

Domain Status: clientTransferProhibited
Registry Registrant ID:
Registrant Name: Wun Seng
Registrant Organization: n.a.
Registrant Street: 16 Main road
Registrant City: Xiamen
Registrant Province/state: FJ
Registrant Postal Code: 361327
Registrant Country: CN
Registrant Phone: +86.5925763227
Registrant Fax: +86.5925763227
Registrant Email:
Name Server:
Name Server:
Help yourself by helping others - report your scammer here.
Google can be your best friend;use it if you have doubts about someone met online. If someone met online only asks for money, no matter what reason, it´s 100% scam.
User avatar
"Nut job" admin.
Posts: 51852
Joined: Sun Apr 22, 2012 12:27 am
Location: in a parallel universe

Return to No clicky clicky. Sites that try to install a virus on your PC.

Who is online

Users browsing this forum: No registered users and 8 guests