|
Date Reported: 8th February 2010 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
VISA 4XXX-XXXX-XXXX-XXXX: possible fraudulent transaction # 76755989999 |
|
Apparent Sender: |
VISA |
|
Return Address: |
transactions@mail.visa.com |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://alerts.cforms.visa.com.udaswy.cz/secureapps /vdir/cholderform.php?ref422547250893945290052788 574248450485975511854&email=phvunsolzlhbmg@yah oo.co.nz |
|
Anchor text of URLs: |
1) http://alerts.cforms.visa.com/secureapps/vdir /cholderform.php?ref‘310801616586394789925423 72585519515151522087381123&email=phvunsol zlhbmg@yahoo.co.nz |
|
Location: |
Location not available |
|
Scam number: |
7787-102181-325088 |
|
Comments: |
- Email asks you to confirm/update/verify your account data at VISA by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- VISA never send their users emails requesting personal details in this way.
- The anchor text appears as a legitimate URL, but don't be fooled - clicking on it will take you to a phishing site!
- The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
|
|
|
|
|
|
|
|
|
Received: Tuesday, 9 February, 2010, 12:27 AM
Dear VISA card holder,
A recent review of your transaction history determined that your card was used at an ATM located in Portugal, but for security reasons the requested transaction was refused. You need to complete the VISA Card Holder Form. You can do this by clicking the link below:
HTTP://ALERTS.CFORMS.VISA.COM/SECUREAPPS/VDIR /CHOLDERFORM.PHP?REF‘310801616586394789925423 72585519515151522087381123&EMAIL=PHVUNSOLZLHB MG@...
|
|
Click for full size image |
|
Website: |
|
|
|
|
Website was not online when we checked. It returned the error 400 |