|
Date Reported: 19th July 2011 |
Risk Level: MEDIUM |
|
|
|
|
|
Email Subject: |
your NatWest Bank account. (message ref: n086621702827d) |
|
Apparent Sender: |
NatWest Bank |
|
Return Address: |
mailsystem.id7898-494649654NOF@natwest.co.uk |
|
Email Format: |
HTML |
|
URL of Web Content: |
http://online.natwest.com.addlowip.li/NOF/startupd ate.aspx?refererident2303810066573402266694998842 24388073737503142&cookieid3057070 |
|
Anchor text of URLs: |
1) http://online.natwest.com/NOF/startupdate.asp x?refererident230381006657340226669499884224 388073737503142&cookieid3057070 |
|
Location: |
WOONSOCKET, RI, UNITED STATES |
|
Scam number: |
17621-270291-604457 |
|
Comments: |
- Email asks you to confirm/update/verify your account data at NatWest Bank by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
- NatWest Bank never send their users emails requesting personal details in this way.
- The anchor text appears as a legitimate URL, but don't be fooled - clicking on it will take you to a phishing site!
- The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
|
|
|
|
|
|
|
|
|
XAuthentication-Warning: YI70-polarography32.FK68gw.[76.228.8.133] (HELO yank.toolbarplace.com): u413vietnam set sender to mailing.id170111107-89941NOF@natwest.com using -l User-Agent: MIME-tools 4.104 (Entity 4.116) X-Priority: 3 (Normal) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="--1ZR0_MOAAIITWV1S" Content-Length: 4163
Dear NatWest Bank customer,
We have implemented security measures consistent with our internal information security...
|
|
Click for full size image |
|
Website: |
|
|
|
|
Website was not online when we checked. It returned the error 400 |