Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

Important information to all LloydsTSB customers
6th March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
6th March 2004
Apparent Sender
Lloyds TSB
Return Address
Lloyds TSB online (online@lloydstsb.com)
Subject
Important information to all LloydsTSB customers
Format
HTML
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content

utilises URL spoofing so you may see ...
http://online.lloydstsb.co.uk but the true URL is
http://210.14.228.66/www/.l/applypassword.php

RISK LEVEL
HIGH
WARNINGS

1. Exploits URL Spoofing (canonicalisation) in Internet Explorer browsers - run Windows Update to ensure your browser is patched.

 

Fraudsters aim to sieze control of Lloyds TSB clients' online accounts in this detailed phishing scam which exploits a browser vulnerability and presents genuine content with bogus content...

 

This spoof Lloyds TSB Bank email (see image below) is in HTML format (although it does look like a text only email in order add a sense of authenticity to the link text description). The link in the email has been further coded to exploit the URL Spoofing bug in which exists in upatched Internet Explorer browsers (to test your browser use the vulnerability check link on right).

Using that link will open a bogus Lloyds TSB web form in your browser. If you use Internet Explorer and have not updated it, you will see a genuine URL in the address bar (http://online.lloydstsb.co.uk) but the window will contain the bogus content. We recommend that you run Windows Update daily and before surfing the internet to ensure that your Microsoft software is up to date.

More worryingly, the bogus page is scripted to open the genuine Lloyds TSB help page in a pop up style window with the bogus content to add a false sense of security to the viewer. For this reason, and the attempt to exploit unpatched IE browsers, we have given this phishing scam a HIGH risk level.

The true URL of the bogus form is http://210.14.228.66/www/.l/applypassword.php which resolves to Beijing Online Communication Technology Limited, Guangzhou Branch, China - nothing to do with Lloyds TSB Bank at all.

Any information submitted into the form would be sent to the perpetrators using PHP script and the information would enable them to take control of your online account.

Our ongoing advice is simple ... whenever you wish to access any online account, always do so by first opening a browser, and then manually type the appropriate URL directly into the browser's address bar.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Important information to all LloydsTSB customers spoof email

 

The bogus web page...

Important information to all LloydsTSB customers bogus web page

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide