CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image News by the Boss!: The Latest PayPal Phishing Scam image
Phishing

The Latest PayPal Phishing Scam


By Robin Laudanski
January 24, 2005


Companies like PayPal have repeatedly been used to target consumers in phishing scams. It isn't because PayPal does anything wrong, it is because they are a widely used company so the chances of finding people who wont double check to see if the email is legit is more likely.

This is the latest PayPal email phishing scam out. In the last 24 hours, I've gotten at least a dozen of these emails. Please note the header information immediately tells us this email is not a legitimate PayPal email.
Return-Path: < wwwuser@ cgi01.plus.net >
Received: from cgi01.plus.net (cgi01.plus.net [195.166.130.120])
	by bugsbunny.castlecops.com (8.13.2/8.13.2) with ESMTP id j0OHskGa011385
	for <***@*****>; Mon, 24 Jan 2005 12:54:46 -0500
Received: from wwwuser by cgi01.plus.net with local (Exim 4.31; FreeBSD)
	id 1Ct8QL-00010m-4Q
	for ***@*****; Mon, 24 Jan 2005 17:54:49 +0000
To: email address removed
Subject: PayPal Account Suspended
From: PayPal Service < service@paypal.com >
Reply-To: 
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: 
Date: Mon, 24 Jan 2005 17:54:49 +0000
X-NOD32Result: clean
X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on 
	bugsbunny.castlecops.com
X-Spam-Level: ***
X-Spam-Status: No, score=3.8 required=5.6 tests=AWL,BAYES_50,HTML_MESSAGE,
	MIME_HTML_ONLY,RCVD_IN_BL_SPAMCOP_NET,REPLY_TO_EMPTY autolearn=no 
	version=3.0.2
X-Spam-DCCB: sonic.net
X-Spam-DCCR: bugsbunny.castlecops.com 1117; Body=2 Fuz1=2 Fuz2=5
This is the text of the email as it appears in your inbox:

Paypal-Account Alert
Dear Paypal User,
In accordance with our major database relocation, we are currently having major adjustments and updates of user accounts to verify that the informations you have provided with us during the sign-up process are true and correct. However, we have noticed some discrepancies regarding your account at Paypal. Possible causes are inaccurate contact information and invalid logout process.
We require you to complete an account verification procedure as part of our security measure.
You must click the link below to complete the process.

https://www.paypal.com/cgi-bin/webscr?cmd=_login-run

Unable to do so may result to abnormal account behavior during transactions.

Thank you for using PayPal!
The PayPal Team


Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your PayPal account and choose the "Help" link in the footer of any page.

PayPal Email ID PP096



I've posted this email as is for a reason, that reason is because I want everyone to see the actual formatting of the thing. If you mouse over the PayPal link you'll notice in your status bar that it isn't directing you to PayPal. Instead it is pointing to http://thilo.traeff.ch/paypal. Depending upon which browser you're using http://thilo.traeff.ch/paypal will display slightly differently, it looks much more authentic using Firefox then it does using IE.

A key thing to remember: If you get an email suggesting your account is being terminated or suspended, check for yourself. Do it in a safe way. What is a safe way? Regardless of what company is listed in the email you get, go directly to their website without clicking on the link in the email! If you can login to the legit site, and there are notifications directly for you, there will be a link to see what they are. If there are server changes, database changes etc going on there will be an announcement somewhere on the site. Protect yourself by being sceptical and doing a little research.

Remember that old saying believe half of what you see and none of what you hear? These kind of emails are perfect examples of why you need to look into it yourself.
Posted on Monday, 24 January 2005 @ 17:15:50 UTC by Robin (5940 reads)
[ Trackback ]
image

"News by the Boss!: The Latest PayPal Phishing Scam" | Login/Create an Account | 2 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: The Latest PayPal Phishing Scam (Score: 1)
by Blast  on Tuesday, 25 January 2005 @ 14:42:20 UTC
(User Info | Send a Message) http://billgray.biz
Now aint that a funny thing...

I recieved an email today that looked really authentic saying that my account at PayPal had been comprimised by IP addresses from around the world. I looked at it. There were two things wrong... they used my email address as part of the welcome (Paypal uses my name) and I had also recieved an email from PayPal after when this email said my account had been comprimised

Apart from that, though, It looked perfect. The reason I am commenting is that I did a second take on the email. I even questioned that maybe I was wrong and it wasn't a fraud email. I still binned it and then saw this article and went back and checked the link,(as above) confirming the fraud.

Amazing, great article Robin


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· FreeBSD
· HotScripts
· W3 Consortium
· Spam Cop
· More about Phishing
· News by Robin


Most read story about Phishing:
False PayPal Charges!

block bottom
Article Rating
spacer
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer