CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Video journey of a live eBay phishing scam site image
Identity Theft
eBay is no doubt one of the top targets for crooks. Many phishing sites are setup. Tonight I got an email for just one such site and its up and running right now. Watch the video clip as I step thru the scam website...

But first we take note of the email's header:

Return-Path: <builders@homer.intermerchant.com>
Received: from homer.intermerchant.com (64-191-10-167.hostnoc.net [64.191.10.167] (may be forged))
by bugsbunny.castlecops.com (8.13.4/8.13.4) with ESMTP id k0918OCQ009793
for <paul@computercops.biz>; Sun, 8 Jan 2006 20:08:24 -0500
Received: from builders by homer.intermerchant.com with local (Exim 4.52)
id 1EvlWd-0004la-SG
for paul@computercops.biz; Sun, 08 Jan 2006 17:08:43 -0800

Now click the Read more link to see the video clip.


Dear eBay Customer,
Today Ianuary 08, 2005 we have dected a bougus activity in your account, so we suspend your account to protect you and us in same time from any fraud that can be made using your account. After you read this email pls login in to your account with your USERNAME and PASSWORD and confirm all dates from the FORM If you don`t login after 12 hours from when you got this email or you don`t complete the form with correct info your account will be deleted !
And next time pls be more careful with your USERNAME and PASSWORD.
Your eBay Team !


The email tries to look authentic with a TRUSTe image and an "OnGuard Online" graphic. The email says the following link will get me signed in:

http://signin.ebay.com/ws2/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US&ru=http%3A//www.ebay.com

Yes when I hover on it, this is the actual destination:

http://200.181.108.77/~jjj/.ws/eBay_Account_Investigation/verify/login/security/index.htm

The 200.181.108.77 IP belongs to brasiltelecom.net.br, a Brasil Telecom company. Cutting to the chase, lets take a look at the video clip and see how this scam site operates. Its a Macromedia Flash File, just click the link below the video to expand it so you don't squint. But remember, this is a live dangerous website trying to get your identity. Don't do this!


[click here to expand video]
Posted on Sunday, 08 January 2006 @ 21:38:49 UTC by Paul (3899 reads)
[ Trackback ]
image

"Video journey of a live eBay phishing scam site" | Login/Create an Account | 3 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Video journey of a live eBay phishing scam site (Score: 1)
by checkmate  on Monday, 09 January 2006 @ 02:13:18 UTC
(User Info | Send a Message)
Thank you for that Paul. The grammar in the message from the phishers is terrible as well, another tell-tale sign of a phising scam!



Re: Video journey of a live eBay phishing scam site (Score: 1)
by thetarget  on Monday, 09 January 2006 @ 07:11:09 UTC
(User Info | Send a Message | _JOURNAL) http://www.rmn.zeeblo.com
Sorry guys but I really want to say:

Lolx!! :lol: :lol: :lol: :lol:



Re: Video journey of a live eBay phishing scam site (Score: 1)
by scottgiles  on Monday, 09 January 2006 @ 18:52:14 UTC
(User Info | Send a Message) http://scottgiles.com
I'd like to say that those losers are complete morons.


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· More about Identity Theft
· News by Paul


Most read story about Identity Theft:
Kinko's spy case highlights risks of public Internet Terminals

block bottom
Article Rating
spacer
Average Score: 5
Votes: 2


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer