CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Beware!: New PayPal Phishing Approach image
PayPal
This morning I found in my personal inbox a paypal phish that looks pretty darn legit (or at least tries to take on a professional approach in its message delivery unlike all the paypal phish we usually see which mispellings, and poor communication). The subject starts: Simple Steps to Protect Against Fraud and ID Theft PayPal <paypal@email.paypal.com>. The body takes on a PayPal newsletter and discusses in its main column "Financial Fitness". There are other side columns like "Suspect your identity has been stolen?" which is called a "Tip". With the exception of the phish link, all other links point to email1.paypal.com.

The main column used for the phish reads:
Financial Fitness
Be Cautious About Sharing Information

When Phil Ferguson made a New Year's resolution to get fit, the last thing he worried about was putting himself at risk for identity theft. After all, Phil is cautious about how he shares financial information, and he tracks the balance in his bank account.

So Phil was taken aback when, a few weeks after joining a gym, he tried to withdraw $40 from the ATM and was told "no funds available." Then a light bulb went off.
A snapshot of the email can be seen here. A snapshot of the phish page can be seen here.

For a full detailed report of this phish, visit PIRT#79502. On this same server is an eBay phish which has been running for quite some time. So now PIRT is on it.
Posted on Sunday, 05 November 2006 @ 12:27:15 UTC by Paul (4162 reads)
[ Trackback ]
image

"Beware!: New PayPal Phishing Approach" | Login/Create an Account | 1 comment | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: New PayPal Phishing Approach (Score: 1)
by Paul  on Monday, 06 November 2006 @ 14:50:08 UTC
(User Info | Send a Message | _JOURNAL) http://www.laudanski.com
As an update (you can get this from the PIRT report), the phish URL goes thru:

http://211.240.40.175:9999/


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· HotScripts
· W3 Consortium
· More about PayPal
· News by Paul


Most read story about PayPal:
Inktomi phishing problem?

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer