Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

Barclays IBank account verification - Spoof Email Phishing Scam
6th March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
4th & 6th March 2004
Apparent Sender
Barclays iBank
Return Address
Barclays IBank service <service@ibank.barclays.co.uk>
Subject
Barclays IBank account verification
Format
HTML
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
http://www.best-news.ru/ and http://207.150.192.12/... OR http://210.14.228.66/...
RISK LEVEL
HIGH
WARNINGS

1. Exploits URL Spoofing (canonicalisation) in Internet Explorer browsers - run Windows Update to ensure your browser is patched.

 

Scammers target Barclays iBank users who have not updated their Internet Explorer browser with this phishing scam...

 

This spoof Barclays iBank email (see image below) is in HTML format with a disguised link which leads you to bogus Barclays iBank web pages. The email appears to be in text only format, but this is done to add a sense of authenticity to the link text, which implies that it will lead to a genuine Barclays iBank page. It will not.

The link and following bogus pages (see images below) are coded to open the bogus content with a spoofed URL - this is to exploit a vulberability that existed in Internet Explorer browsers until early February when Microsoft issued a patch (use the links on the right to check your browser). This enabled scammers to display bogus web pages with a genuine URL. Please run Windows Update to ensure that your Internet Explorer browser has the latest fix.

We've included snapshots of the first two pages of the bogus content, and information submitted into any of these pages will be sent to the scammers using PHP script. You'll notice in the report summary that two different URLs are in use, the first URL is the first page that the link in the email leads to and is a Russian domain - scripting is employed in that page to open the bogus web pages shown below. The second belongs to the bogus web pages (see below) and this URL resolves to Affinity Internet Inc. in the US.

Whilst the use of two different URLs is unusual, we expect that this method has been employed to enable the scammers to move the bogus content to different locations very quickly while maintaining the first page which opens them, thereby making it much easier to move the forged content around the internet as service providers and hosts remove them. We expect to see this spoof in distribution for a while but with differing URLs over the coming days.

As you will see by the snapshots below, the bogus pages look very real, and with a spoofed URL, an unsuspecting user really wouldn't know the difference (use the Spoof URL Checker link on the right to test for this in a web page). The only way to prevent mass victims is to build awareness, and you can do your part in this by letting your friends, colleagues and anyone you know uses email know about it (including a signature with a link to this page in your emails is an excellent way to achieve this).

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Barclays IBank account verification - Spoof Email

 

The first bogus Barclays iBank page ...

Barclays IBank account verification - Spoof Email Phishing Scam

 

... and the second bogus web page ...

Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam
Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam
Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam
Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam
Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam Barclays IBank account verification - Spoof Email Phishing Scam

 

 

Barclays IBank account verification - Spoof Email Phishing Scam
Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide