Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

Paypal account limited (involves Address Bar Spoofing)
6th April 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
first reported 26th March 2004
Apparent Sender
Paypal
Return Address
security@paypal.com
Subject
Paypal account limited OR Paypal - Access Account Limited
Format
HTML
Method
disguised link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
http://smba.swu.ac.kr/css/.accVerify/secure/..........
OR
http://216.22.0.83/~tourete/log1.htm
OR
http://smba.swu.ac.kr/css/cash/hide/sysdll.php
RISK LEVEL
HIGH
WARNINGS

1. Uses HTML, HTA and javascript to replace the address bar with an image and text which appears to be an address bar with a genuine ebay secure URL. This is not the browser address bar at all though!
2. Now found to be using multiple URLs for forged page.

 

Another case of Address Bar Spoofing targets Paypal users with this complex forgery...

 

This email is very similar to our other recent example of a Paypal Phishing Scam which involves a complex method of coding and scripting using HTA, HTML and javascript to deliver a bogus web page which could easily be mistaken for a genuine paypal.com page.

Clicking that link in the email (which is HTML coded to look like it will lead to a genuine paypal.com page - https://www.paypal.com/fraudcheck/secure/bill.html?sl=070304) will trigger a sequence of browser windows...

1. the link in a spoofed email opens a new browser window which is scripted to immediately close itself and reopen with the address and status bar removed,

2. this new window further uses a combination of HTA, HTML and javascript commands to rebuild a fake address bar using images and text. The text fraudulently displays a genuine URL - https://www.paypal.com/cgi-bin/webscr?cmd=_login-run, but the true URL is http://smba.swu.ac.kr/css/.accVerify/secure/log1.htm, which resolves to Seoul Womens University in Korea.

3. Any data submitted into the forged Paypal form is forwarded to the fraudsters' email address - broker@easynet.ro (which resolves to a Global One Communications in Romania) via a script located on the same server.

 

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear PayPal user,

We recently reviewed your account, and suspect that your PayPal account may have been accessed by an unauthorized third party. Protecting the security of your account and of the PayPal network is our primary concern. Therefore, as a prevention measure, we have temporarely limited access to sensitive PayPal account features.
Please click on the link below to confirm your information:

https://www.paypal.com/fraudcheck/secure/bill.html?sl=070304

For more information about how to protect your account, please visit PayPal's Security Center, accessible via the "Security Center" link located at the bottom of each page of the PayPal website.

We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of the entire PayPal system. Thank you for your prompt attention to this matter.

Sincerely,
The PayPal Team

Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the header of any page.

 

The bogus web page ...

Paypal account limited (involves Address Bar Spoofing)

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide