Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

Notification of Fleet Online Banking Unauthorized Account Access
26th May 2004

please forward any scams you've received to spoof@millersmiles.co.uk


Report Summary
Date Reported
26th May 2004
Apparent Sender
Fleet Bank Online
Return Address
service@fleet.com <service@fleet.com>
Subject
Notification of Fleet Online Banking Unauthorized Account Access
Format
HTML
Method
disguised link leads to bogus web content - the forged page contains a form which would capture any data entered but not send it to Fleet Bank. The page has a Spoofed URL.
Bogus Web Content?
Yes
URL of web content
Spoofed - http://216.131.102.105/login/login.htm
Actual URL - http://216.131.102.105/login/login.htm
RISK LEVEL
Medium
WARNINGS

1. Employs script to disable right click.
2. Employs script to paste a forged URL over the actual URL (see images below) - this involves a layer with text on a white background which shows the spoofed URL (see above)
3. This forged Fleet Bank Online page uses the same scripting as the recent US Bank Scam with a spoofed URL.

 

Another instance of this new form of URL Spoofing ...

 

A good example of how complex these Phishing Scams are getting - this is another report involving a page with the new method of URL Spoofing, where a line of text against a white background is created and positioned over the actual URL in the address bar (see both images of the forged Fleet Online Bank page below).

Apart from determining the true URL of the page by opening the Page Properties from the browser's File menu, and perhaps revealing the overlay as shown in the image below, there are two other distinct anomolies that will give the game away: The text overlay is positioned in relation to the window, so it will move with it, but if you move the window around your screen quickly you will notice a slight delay while the text overlay catches up. Another give away occurs when you minimise the window - the text overlay jumps to the top of the screen.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Notification of Fleet Online Banking Unauthorized Account Access

 

The bogus web page (first image shows it exactly as you would seeit, and the second image demonstrates the URL Spoofing by positioning another window the address bar) ...

Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access

 

Here, you can see the extra layer (overlay of text on a white background which is positioned over the true URL in the address bar) as the properties window for the page (which also shows the true page URL) is positioned over the address bar. The extra layer of text which shows the spoofed URL is coded to 'stay on top' of all other windows ...

Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access
Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access Notification of Fleet Online Banking Unauthorized Account Access

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide