CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

E-Gold phishing scam!!! SCUMBAGS!!!

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Slick74

Trooper
Trooper


Joined: Jan 23, 2005
Posts: 10
Location: Australia

PostPosted: Mon Jan 24, 2005 7:39 am    Post subject: E-Gold phishing scam!!! SCUMBAGS!!!
Reply with quote

Hi all,

We all know that e-gold is the easiest pay-proc to hack into, right?

If you don't, Rolling Eyes Razz just do a Google search for the terms "hack e-gold" and you will see what I mean. It's pretty SCARY! Shocked

Anyway, I don't even have an e-gold account, yet I get this in my bulk folder today: WHATEVER YOU DO - DON'T CLICK ON THE LINK!!!!
___________________________________________________
** e-gold Account Information Update Notice **

e-gold account number: Secured
Items updated: Point of Contact
Update performed from IP address: 68.21.96.213
Time of update: 1/23/05 11:55:22 PM GMT

This automatic email notice lets you know that modifications have been
made to the Account Information settings for your e-gold account. The
current settings for your account can be viewed and modified at the
e-gold website by choosing the Account Info menu selection while
accessing your account.

Please login here: https://www.e-gold.com/acct/login.html

If you did not make a change to your account before receiving this email
message, you should immediately login e-gold using the link above and
correct unauthorized changes.

Please do not reply to this automatically generated email message.
__________________________________________________

WHATEVER YOU DO - DON'T CLICK ON THE LINK!!!!

The Status Bar shows this when your cursor is hovered above it:

http://213.114.127.125/acct/login.html

This is so obviously a phishing scam it feel as though someone is trying to insult my intelligence. Evil or Very Mad

Question Is there any way of tracking the IP number or should I just report it to E-Gold and leave it in their hands?

Thanks! and Good Surfing to everyone.....

Slick

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Jan 24, 2005 2:20 pm    Post subject:
Reply with quote

You could certainly track the IP number using a whois search and this is done all the time. A good general tool for checking things like this is http://www.dnsstuff.com/

In this case the first link that you show is a legitimate e-gold address. The second is a bogus address but seems to have already been shut down.

In future, if you will enclose links like these in single quotes they will not show as a clickable link.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
laura90059

Cadet
Cadet
Premium Member

Joined: May 18, 2004
Posts: 3
Location: USA
Premium

PostPosted: Sat Feb 19, 2005 8:33 pm    Post subject: Unfortunately I clicked the link!
Reply with quote

I got this same message, unfortunately I do have an egold account and having heard of all the hacking going on there I clicked the link to check and see if my egold profile had been changed.

Dowloaded a version of I-Worm/Bofra to my puter, and I can't fix all the problems I have as a result of my stupidity!!!

Now I have to search the forum for the proper place to post my plea for help, just stopped here first to warn everyone.

Back to top
View users profile Send private message Yahoo Messenger MSN Messenger
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sat Feb 19, 2005 11:00 pm    Post subject:
Reply with quote

Oldfrog wrote:
In future, if you will enclose links like these in single quotes they will not show as a clickable link.

Perhaps create a topic for such useful reminders and place as a sticky? Might be argued that same thing applies to other forums but inadvertent browsing to pharming links posted here could be particularly dangerous.

Back to top
View users profile Send private message
OJ_did_it

Major
Major
Premium Member

Joined: Nov 13, 2004
Posts: 1059

Premium

PostPosted: Sun Feb 20, 2005 6:59 am    Post subject:
Reply with quote

RIPE wrote:

inetnum: 213.114.120.0 - 213.114.127.255
netname: BB-BISP-LUL90-SE
descr: B2 customer network
country: SE
remarks: <INFRA-AW>
admin-c: BR3045-RIPE
tech-c: BR3045-RIPE
status: ASSIGNED PA
mnt-by: B2-MNT
mnt-routes: B2-MNT
changed: **********@bredband.com 20040303
source: RIPE

route: 213.114.0.0/15
descr: Broadband Customers in Scandinavia
descr: Please report improper use to *****@bredband.com
origin: AS8642
notify: ***@bredband.com
mnt-by: B2-MNT
changed: **********@bredband.com 20040618
source: RIPE

role: Bredbandsbolaget Routing Registry
address: Box 47645
address: 117 94 Stockholm
address: Sweden
e-mail: ***@bredband.com
trouble: *********************************
trouble: Abuse related issues is reported
trouble: to *****@bredband.com
trouble: phone +46 586 65485
trouble: Abuse issues sent to other e-mail
trouble: adresses will be discarded
trouble: *********************************
admin-c: TN2809-RIPE
admin-c: JN1883-RIPE
admin-c: EB78-RIPE
admin-c: NE102-RIPE
admin-c: ARL1-RIPE
tech-c: TN2809-RIPE
tech-c: JN1883-RIPE
tech-c: EB78-RIPE
tech-c: NE102-RIPE
tech-c: ARL1-RIPE
nic-hdl: BR3045-RIPE
mnt-by: B2-MNT
notify: ***@bredband.com
changed: ************@bredband.com 20020418
changed: ************@bredband.com 20020425
changed: ****************@bredband.com 20021004
changed: ***********@bredband.com 20030813
changed: **********@bredband.com 20040603
changed: **********@bredband.com 20041209
source: RIPE

Back to top
View users profile Send private message
laura90059

Cadet
Cadet
Premium Member

Joined: May 18, 2004
Posts: 3
Location: USA
Premium

PostPosted: Mon Feb 21, 2005 8:07 pm    Post subject: Got another one today
Reply with quote

I got another one of theses e-gold emails today, so I am posting it wih full headers in hopes someone will be keeping a database of thes jerks.

X-Apparently-To: XXXXX@yahoo.com via 206.190.37.155; Mon, 21 Feb 2005 01:37:17 -0800
X-YahooFilteredBulk: 195.70.10.40
Authentication-Results: mta347.mail.scd.yahoo.com from=e-gold.com; domainkeys=neutral (no sig)
X-Originating-IP: [195.70.10.40]
Return-Path: <webserver@dfinet.ch>
Received: from 195.70.10.40 (EHLO localhost.localdomain) (195.70.10.40) by mta347.mail.scd.yahoo.com with SMTP; Mon, 21 Feb 2005 01:37:17 -0800
Received: from localhost.localdomain (hosting [127.0.0.1]) by localhost.localdomain (8.12.8/8.12.Cool with ESMTP id j1L9bGRE026762 for <laura90059@yahoo.com>; Mon, 21 Feb 2005 10:37:16 +0100
Received: (from www@localhost) by localhost.localdomain (8.12.8/8.12.8/Submit) id j1L9bGQq026758; Mon, 21 Feb 2005 10:37:16 +0100
Date: Mon, 21 Feb 2005 10:37:16 +0100
Message-Id: <200502210937.j1L9bGQq026758@localhost.localdomain>
X-Authentication-Warning: localhost.localdomain: www set sender to webserver@dfinet.ch using -f
To: XXXXXXX@yahoo.com
Subject: Notification of e-gold account update
From: "AccountRobot_donotreply@e-gold.com" <AccountRobot_donotreply@e-gold.com> Add to Address Book
Content-Type: text/html; charset=windows-1251
X-Priority: 3
Content-Length: 995





** e-gold Account Information Update Notice **

”https://www.e-gold.com/acct/login.html”
This automatic email notice lets you know that modifications have been made to the Account Information settings for your e-gold account. The current settings for your account can be viewed and modified at the e-gold website by choosing the Account Info menu selection while accessing your account.
If you did not make a change to your account before receiving this email message, you should immediately contact e-gold using the contact instructions available at the e-gold web site.
(For your security, never click a link in an email message to get to the e-gold web site.)
Please do not reply to this automatically generated email message.

Back to top
View users profile Send private message Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer