Unpatched Internet Explorer browsers are
the target of this Phishing Scam...
This spoofed Paypal email is aimed at unpatched versions of Internet
Explorer with its crafted HTML link to "https://www.paypal.com/accountcleanup/".
That link is actually coded to exploit the URL Spoofing (canonicalisation) vulnerability
that exists in unpatched browsers (Microsoft issued a patch at the beginning
of February, use the URL Spoofing Vulnerability Check link on the right of this
page to test your browser for this vulnerability).
Browsers that are vulnerable to this exploit, will see http://www.paypal.com
in their address bar, whereas the URL of the bogus page is actually http://tranced1.u31.euclidsimaging.com/pp/
which resolves to Hurricane Electric Internet Services in the USA.
If you have received this email, please remember that it is very
common for these email scams to be redistributed at a later date with only slightly
different content or the same but with the fake page(s) hosted by a different
provider. Also, once you have received one of these hoaxes, it is also common
place to receive at least another one and usually a day or two after the first,
although not necessarily from the same apparent sender. The Spoof Email ...
The
bogus web page ...
|