Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

eBay Security Measures: Verify your identity
11th March 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
11th March 2004
Apparent Sender
eBay
Return Address
eBay Security Measures <aw-confirm@ebay.com>
Subject
eBay Security Measures: Verify your identity
Format
HTML
Method
'click here' link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
http://signin.ebay.co.uk-aw-cgi-ebayisapi.dll-signin.4t.com/aw-cgi-singIn-arribada.html
RISK LEVEL
HIGH
WARNINGS

1. The URL looks genuine but you will notice the domain name just before '.com/' BE ADVISED THIS IS NOT AN EBAY.CO.UK URL!

 

Fraudsters resort to new means to fool even the experienced user as a Spoof email leads to a bogus page with a genuine looking ebay URL ...

 

This spoof eBay email (see image below) offers a link to use to resolve apparent account problems. The email itself is very convincing with geuine eBay graphics and code called directly from eBay's own server.

The bogus eBay sign in page that the link takes your browser too is a bit more worrying (see image below) - the domain name has been formed to appear to be a genuine ebay.co.uk URL which it is certainly not. The discerning eye will notice the lack of a forward slash (/) directly after 'ebay.co.uk' and will see that the domain is actually called 4t.com...

 

the undiscerning eye will just notice the first part of the URL (in bold red) and proceed...

http://signin.ebay.co.uk-aw-cgi-ebayisapi.dll-signin.4t.com/aw-cgi-singIn-arribada.html

however, look closely and you'll notice the actual domain of the page in blue

http://signin.ebay.co.uk-aw-cgi-ebayisapi.dll-signin.4t.com/aw-cgi-singIn-arribada.html

 

This is achieved by using a long subdomain name with multiple periods (full stops ".") in order to make it look as if the initial part of the URL is another domain to the one that you will actually be visiting.

Because of this URL, which will fool many, and the genuine appearance of the sign in page, we have given this Phishing Scam a HIGH risk level.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

eBay Security Measures: Verify your identity spoof email

 

The bogus web page ...

eBay Security Measures: Verify your identity bogus sign in page

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide