|
Date Reported: 16th December 2009 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
[GFI--RAZER] - possible fraudulent transaction with your 4XXX XXXX XXXX XXXX VISA card - Message was found |
|
Apparent Sender: |
VISA |
|
Return Address: |
transactions@mail.visa.com |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://sessionidUUXSPII05E35BT0.visa.com.ipetiiti. be/cards/myvisa/transactions.php?ref„0486613833643 53635857517714293782436259&email=fins126@ramon galarza.com |
|
Anchor text of URLs: |
1) http://sessionidUUXSPII05E35BT0.visa.com/card s/myvisa/transactions.php?ref„048661383364353 635857517714293782436259&email=markb@bmca talysts.co.uk |
|
Location: |
Location not available |
|
Scam number: |
6535-87615-301233 |
|
Comments: |
- Email asks you to confirm/update/verify your account data at VISA by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- VISA never send their users emails requesting personal details in this way.
- The anchor text appears as a legitimate URL, but don't be fooled - clicking on it will take you to a phishing site!
- The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
|
|
|
|
|
|
|
|
|
to be spam: (100%) IP is in RBL
Dear VISA card holder,
A recent review of your transaction history determined that your card was used at an ATM located in Cameroon, but for security reasons the requested transaction was refused.Please carefully review electronic report for your VISA card at:
HTTP://SESSIONIDUUXSPII05E35BT0.VISA.COM/CAR DS/MYVISA/TRANSACTIONS.PHP?REF„04866138336435 3635857517714293782436259font-family:"Arial", "sans-serif"'>Message ID: 0S4NS0UOZS1HL9C...
|
|
Click for full size image |
|
Website: |
|
|
|
|
Website was not online when we checked. It returned the error 404 |