|
|
Date Reported: 26th August 2005 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
Important notification on your account access |
|
Apparent Sender: |
PayPal |
|
Return Address: |
< service@paypal.com > |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://europa.your-site.com/~buffte6/cgi-bin/webscr_ cmd=_login-run.html?dDwtNDI1NzgwOTQ1O3Q8O2w8aT wxPjs+O2w8dDw7bDxpPDE+O2k8Nz47aTwxOT47aT wyMT47PjtsPHQ8O2w8aTwxPjs+O2w8dDxwPHA 8bDxOYXZpZ2F0ZVVybDs+O2w8Li4vd2VsY29tZS 5hc3B4P2NoZz10JlVSTEZyb209Oz4+Oz47Oz47 Pj47dDxwPHA8bDxWaXNpYmxlOz47bDxvPHQ+ Oz4+Oz47Oz47dDw7bDxpPDM+O2k8NT47aTw3P jtpPDk+O2k8MTE+O2k8MTM+O2k8MTU& secure_redirected_to/*https://www.paypal.com/ cgi-bin/webscr_cmd=_login_run.html?case= 812+US+Fed+Reg+Act |
|
Location: |
Massachusetts, US |
|
Scam number: |
aa-1111 |
|
Comments: |
-
Email asks you to confirm/update/verify your account data at PayPal by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- PayPal never send their users emails requesting personal details in this way.
-
The REAL URL of the spoof website is disguised as "https://www.paypal.com/cgi-bin/webscr_cmd=_ login_run.html?case=812+US+Fed+Reg+Act".
-
The REAL URL of the spoof website is hidden by a hyperlinked image in the body of the email. This is a technique used to get past spam filters that can only read normal text.
-
The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
-
The REAL URL of the spoof website looks nothing like the actual PayPal URL.
|
|
|
|
|
|
|
|
|
|
"You are receiving this notification because PayPal is required by law to verify the availability of your online account statement registered to your email access."
|
|
|
|
Website: |
|
|
|
Spoof website not online at time of report...
|
|
|
|
Please send us any scam/phishing emails you have received by reporting them here
For access to our huge blacklist of domain names and to sign up to our live feed of ALL the scams we receive please take a look at our Honeytrap service
If you have received the email below, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content, such as a different subject or return address, or with the fake webpage(s) hosted on a different webserver.
We aim to report every variant of the scams we receive, so even if it appears that a scam you receive has already been reported, please submit it to us anyway.
|