Date Reported 20th January 2005
Apparent Sender eBay
Return Address supension@ebay.com < suspend.notice@ebay.com >
Subject FPA NOTICE: eBay Registration Suspension - Section 9
Format HTML
Method Spoof email links to a spoof webpage where victim is prompted to enter their details believing the site is genuine. Details are then forwarded to a local script and captured.
Bogus Web Content? Yes
URL of web content http://211.114.111.226/aribada.ebay.com/saw-cgi/acounts/memb/avncenter/dll87443/.BayISAPI.dll/hgdas676bsda6
gwcv7zfcwfcwf34gfwf23g235f134f3fg3f&bhdfahva68532hbhwseBayISAPI.dllPaymentLanding&ssPageName=hhpayUSf
&=userhgads&secure&ssl7r2vbd7d5b.html
RISK LEVEL MEDIUM
WARNINGS 1. Email claims to be from eBay asking you to confirm your account data by clicking on the link. You will be taken to a spoof login page where your details will be captured by the phishers.
2. eBay never send users emails requesting details in this way.
3. URL obviously not eBay!
4. Website traced to Seoul, Korea.
5. URL is disguised as http://scgi.eBay.com/aw-cgi/eBayISAPI.dll?SecureConfirmation&bpuser=1
" Dear customer, We regret to inform you that your eBay account will be suspended due to the violation of our site policy below:"
If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.
|