No Way to Spam - Search Tool

Monday, August 29, 2005

Beware PayPal and eBay Scam Artists! (1)

These are two examples of email-scams you may receive from those scammers who are determined to empty your bank account. See them at the bottom of this post.

They follow your eBusiness progress and they catch any image to any eBank account on your store or any other simple website. They'll probably see an image to a PayPal account or any other credit cards there. They'll then follow these links and get manually more information.

It's completely correct that they'll not see any email address associated with your account details on your website, so they'll guess it from your business. Or they may just send like these emails to any email address they've captured from the net.

They also use the source codes of PayPal messages to clients to re-produce an alleged PayPal message and send it to you. They'll only redirect the links on this message to where they've prepared to rob you.

I'll give examples here to a PayPal main image to compare between the two and some details. In some emails I'd received even PayPal header and footer. This of course is designed to clarivy that there's no any doubt that these are PayPal's.



This is the same banner image on PayPal Home but the character(photo) on the left is not the same. The text link on the following banner has an additional word to that which is at PayPal Home, but it is not clickable because there's no link. Go and compare. You'll notice that I've recorded the IP address of this email too. The second email is at the coming post.

The very interesting thing about this email is that I don't have any PayPal account by such email or even by any of my domains. You should not operate a PayPal account using any of your normal free emails, your domain or other webmails you use for other purposes. You should have only one email for this purpose. For example this email address I am using and I am actually receiving like these spams through it, is operated exactly for only one purpose: to capture the wretched scam on the Internet and learn from it something positive.

This is the first email:

The Header details of the first email:

Return-Path: <daily120@nova.fast-servers.net> Received: from daily120 by nova.fast-servers.net with local (Exim 4.52) id 1E9LRf-0007pP-Bu for (then here was my email address)
From: PayPal Billing Department( service@paypal.com) Subject: Paypal Security Notification Date: I dag, 13:35 4KB Body: Dear valued PayPal® member: Due to concerns, for the safety and integrity of the paypalaccount we have issued this warning
Reply To: None


Dear valued PayPal® member:

Due to concerns, for the safety and integrity of the paypal account we have issued this warning message.

It has come to our attention that your PayPal® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes
out of your online experience and update your personal records you will not run into
any future problems with the online service.

However, failure to update your records will result in account suspension. Please update your records on or before August 30, 2005.

Once you have updated your account records your paypal account service will not be interrupted and will continue as normal.

To update your PayPal® records click on the following link:
http://www.paypal.com/cgi-bin/webscr?cmd=_login-run
http://200.149.12.123/us/cgi-bin/websrc?cmd=_login-run

Thank You.
PayPal® UPDATE TEAM

Accounts Management As outlined in our User Agreement, PayPal® will
periodically send you information about site changes and enhancements.

Visit our Privacy Policy and User Agreement if you have any questions.
http://www.paypal.com/cgi-bin/webscr?cmd=p/gen/ua/policy_privacy-outside
http://200.149.12.123/us/cgi-bin/websrc?cmd=_login-run

1 comment:

Anonymous said...

These are some other spam details. See how those viagra spam e-mails were coming from different names in the "From" fields. They're of course from one machine.

From: Galusya B.
Subject: Hello, Horst! I am a lovely and lonely Lady who is looking for the man who will make me happy

From: Michael Ronin mronin @laposte.net
Subject: You Won! British Lottery Headquarters: Customer Service

From: Susan
Subject: Boost your manhood to astonishing levels!

From: EUROPEAN PRIZE AWARD
Subject: WINNINGS NOTIFICATION!!! PROMOTIONS/PRIZE AWARDS ! ! !PROMOTIONS/PRIZE AWARD DEPARTMENT

From: Bryson Robinson
Subject: cheap oem soft shipping //orldwide. Special Offer Adobe Video Collection

From: Mamie MamieMathis @earthlink.net
Subject: A payout rate of over 97%, Hi Roller Cassino is THE PLACE to be!

From: Andre Gamble
Subject: Sensationall revoolution in medicine!

From: aphrodite aphroditeconduit @ japan.com
Subject: This stock has been on my watch list for quite a time. And now I have all the grounds to tell you it’s about to rock very soon.

From: David Palmer david_palmer191uk @ yahoo.co.uk
Subject: REPLY IMMEDIATELY
Goodday, I am David Palmer, staff of SMITH & WILLIAMSON Private Banking.

From: charities@gafana.com
Subject: SAVE THE MOTHERLESSBABIES AND ORPHAN AND CHARITIES

From: PRODUCTS AND
Subject: Technical Analysts. Herbert Hutch Quotes Video Requires Bud Redhead jump Puerto midocean transfers Forms cocaine.. sulfate

From: Phillip Morgan
Subject: cheap oem soft shipping //orldwide. Special Offer- Adobe Video Collection

From: Marvin Wilson
Subject: Three Steps to the Software You Need at the Prices You Want. Special Offer
- Adobe Video Collection

From: tyrus crum
Subject: Luxury: TOP BRANDS - LOW LOW PRICES. Jewelry * Handbags * Pens * Watches * Neckties * Clutches * Wallets

Anti Spam Followers! Say NO to Spam! Join the NO!

Fujitsu Computer Systems Corporation

Bookmarks

Add to Netvibes StumbleUpon Stumbleupon It AddThis Social Bookmark Button
Add2Netvouz

Feeds