Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

USBANK.COM URGENT NOTIFICATION!
**ALERT - NEW FORM OF URL SPOOFING**
10th May 2004

please forward any scams you've received to spoof@millersmiles.co.uk


Report Summary
Date Reported
10th May 2004
Apparent Sender
US Bank
Return Address
USbank.com Officials <Important-UsBank@security-update.info>
Subject
USBANK.COM URGENT NOTIFICATION!
Format
HTML
Method
disguised link leads to bogus web content which is scripted with a forged URL (see images below) - submitted form data is captured by a local script.
Bogus Web Content?
Yes
URL of web content
Forged URL = https://www.usbank.com/secure/-run
TRUE URL = http://www.security-update.info/
RISK LEVEL
HIGH - extreme caution advised
WARNINGS

1. Employs script to disable right click.
2. Employs script to paste a forged URL over the true URL (see images below).

 

This spoofed US Bank Email presents us with a new form of URL spoofing - extreme caution is recommended ...

 

Following on from the recent examples of Address (Location) Bar Spoofing, we have now come across a new form of delivering forged content with what appears to be a genuine URL in the browser address bar...

On this occasion, fraudsters have coded a page which simply places a text object (with opaque white background) over the URL within the address bar. This conceals the page's true location and is near unnoticeable (see images below). We consider this to be much more dangerous than the previous instances of Address Bar Spoofing since they fell short with colour matching of the browser frame, whereas this URL Spoofing only covers the text component of the URL in the address bar.

If you have disabled active scripting, this cover up will fail, and you will see the true URL - http://www.security-update.info/ - which resolves to web space provided by Server Beach in Texas USA.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

USBANK.COM URGENT NOTIFICATION! spoofed email

 

The bogus web page ...

USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!

 

 

USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!

 

USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!
USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION! USBANK.COM URGENT NOTIFICATION!

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide