glad you found us in time. This particular case is interesting because it has one really new element for me - impersonating a government agency.
bignicky88 wrote:
--
Benjamin Manser - Air Corps Pilot
Army email: benjamin.manser@royalairforces.com
Personal email: benjmanser@gmail.com
Royal Australian Air Force
Aircraft Type: F/A-18 Hornet Fighter
--
It's not a very convincing footer.
Well - yes and no. royalairforces.com looks at first glance legit (you can call up http://royalairforces.com/ directly). However in reality it is just a COPY of http://www.defence.gov.au. When looking at the WHOIS data we can see the following:
Domain name: ROYALAIRFORCES.COM
Name Server: ns1.surf-town.net
Name Server: ns2.surf-town.net
Name Server: ns3.surf-town.net
Creation Date: 2010.06.25
Expiration Date: 2011.06.25
Status: DELEGATED
Registrant ID: BGEACPB-RU
Registrant Name: JOSH VICK
Registrant Organization: JOSH VICK
Registrant Street1: 5017 JACKSON LN
Registrant City: BRENTWOOD
Registrant Postal Code: 37027
Registrant Country: US
Administrative, Technical Contact
Contact ID: BGEACPB-RU
Contact Name: JOSH VICK
Contact Organization: JOSH VICK
Contact Street1: 5017 JACKSON LN
Contact City: BRENTWOOD
Contact Postal Code: 37027
Contact Country: US
Contact Phone: +1 232 4672772
Contact E-mail: paddymcj2@yahoo.com
Registrar: Regional Network Information Center, JSC dba RU-CENTER
So royalairforces.com was registered just last June by an individual claiming to come from the US; and it is hosted on a server from a company in Denmark.
I'll send out some information to get this one killed hopefully quickly.