CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Beware!: Alert: New PayPal Phishing Email Scams image
Phishing
It has come to our attention that your PayPal® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into any future problems with the online service.

However, failure to update your records will result in account suspension. Please update your records on or before January 10, 2006.

There are two new Paypal phishing emails circulating at the moment and the above is the start of one of them. This first one was received from studioubachswisbrun.nl ([62.58.170.30]), and not -- as you may have guessed -- from paypal.com.


[click to enlarge]


The body says to click on the following link: http://www.paypal.com/cgi-bin/webscr?cmd=_login-run, however, when I scroll over it this site comes up instead: http://user.ifw.uni-bremen.de/www.paypal.com/index.htm. Clearly don't click on it!

A second Paypal scam starts off with:

It has come to our attention that your PayPal Billing Information records are out of date. That requires you to update the Billing Information. Failure to update your records will result in account termination. Please update your records within 24 hours. Once you have updated your account records, your PayPal session will not be interrupted and will continue as normal. Failure to update will result in cancellation of service, Terms of Service (TOS) violations or future billing problems.
Here is a thumbnail snapshot of the email:


[click to enlarge]


I'm asked to click thru to a site to activate my account, and the destination is: http://69.219.36.86/us/Account_verification/webscr-cmd=_login/ which looks like this:


[click to enlarge]


Naturally all the hyperlinks point back to Paypal, and the page even scams off the images for TRUSTe and BBBOnLine (which they themselves have been questionable at times). However, if take a deeper look at this webpage/server we found:

- apache 2.0.40 (old vulnerable web server version)
- php 4.2.2 (also old and highly vulnerable)

If you try to login the form sends you here: http://69.219.36.86/us/Account_verification/webscr-cmd=_login/processing.php?login_email=&login_password=&go=1 which gets redirected to: http://69.219.36.86/us/Account_verification/webscr-cmd=_login/login.php. Lo-and-behold, another paypal-like phishing page, all to get your account information:


[click to enlarge]


Great measures are being taken to get your confidential Paypal login information. Don't get duped! Paypal won't be sending emails to you asking for your login information. This second particular email scam comes from ms.hlshb.gov.tw ([203.65.62.122]). Nice to see a government server exposed eh?
Posted on Monday, 02 January 2006 @ 15:41:51 UTC by Paul (3289 reads)
[ Trackback ]
image

"Beware!: Alert: New PayPal Phishing Email Scams" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· HotScripts
· Apache Web Server
· W3 Consortium
· More about Phishing
· News by Paul


Most read story about Phishing:
False PayPal Charges!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer