Back to Forums








View Full Version : Examples of Phishing Scams


Big Booger
February 4th, 2005, 08:20 AM
Take a look at the image attached. Really look closely at the FROM: line.

You'll see an authentic-looking ebay address. But if you look at it a little longer, you'll see the Ebay@REPLY3.ebay.com

Reply3 is where the BS begins... That is a fake.

Next when we click the URL, it takes us to a fake site:

http://click3.ebay.com/14460512.54805.0.46540

click3 signifies more BS...

Just in case you've never seen a fake phishing mail.. the one attached is as fake as they come..

Though you really have to be careful because the phishing scams are getting more clever by the minute.

rohitk89
February 4th, 2005, 10:46 AM
nice one bb...should help a lot of people that...did u come accross that one in ur inbox?

Big Booger
February 4th, 2005, 12:00 PM
Yep,
I got that one today.. I get them all the time.. usually ebay, paypal, or amazon... :D

rohitk89
February 4th, 2005, 12:27 PM
lol..i get ones containing details abt libido enhancers...:D

rik
February 4th, 2005, 12:57 PM
It sure looks real enough...

FastGame
February 4th, 2005, 14:13 PM
lol..i get ones containing details abt libido enhancers...:D
yeah like you really need that :rolleyes:

Hey could you send me your emails ? I'll send you mine that have porn links :p

I get those eBay scams too :mad:

rohitk89
February 4th, 2005, 15:24 PM
Hey could you send me your emails ? I'll send you mine that have porn links
for a minute there i took that seriously..i began typing "okay. wat's ur e-m..." and stopped..ROFL..

rik
February 4th, 2005, 15:26 PM
I run SpoofStick both for IE and FireFox. When I cick the "click3" URL SpoofStick actually shows that I am on Ebays site...

egghead
February 4th, 2005, 18:18 PM
If you get this in any future email, delete it with confidence - egghead :D

Dear Valued Customer,

M&I Bank, is committed to maintaining a safe environment for our customers. To protect the security of your account, M&I Bankemploys some of the most advanced security systems in the world and our anti-fraud teams regularly screen the M&I Bank system for unusual activity.

We are contacting you to remind you that on Jan. 25, 2005 our Account Review Team identified some unusual activity in your account. In accordance with M&I Bank`s User Agreement and to ensure that your account has not been compromised, access to your account was limited. Your account access will remain limited until this issue has been resolved.

We encourage you to log in and perform the steps necessary to restore your account access as soon as possible. Allowing your account access to remain limited for an extended period of time may result in further limitations on the use of your account and possible account closure.
Visit to unlock your https://cib.ibanking-services.com/cib/ (http://168.188.72.117/cib/)

Thank you for your prompt attention to this matter. Please understand that this is a security measure meant to help protect you and your account. We apologize for any inconvenience. Sincerely,
M&I Bank,Account Review Department

egghead
February 4th, 2005, 23:50 PM
If you get this email you can confidently delete it without worry - Egghead :D

Dear eBay customer,

During our regularly scheduled account maintenance and verification procedures,
we have detected a slight error in your billing information.

This might be due to either of the following reasons:

1. A recent change in your personal information ( i.e.change
of address).
2. Submiting invalid information during the initial sign up
process.
3. An inability to accurately verify your selected option of
payment due to an internal error within our processors.

Please update and verify your information by clicking the link below:

https://arribada.ebay.com/saw-cgi/eBayISAPI.dll?PlaceCCInfo

If your account information is not updated within 48 hours then your ability to sell or bid on eBay will become restricted.

Thank you

The eBay Billing Deptartment .

Copyright
© 1995-2005 eBay Inc. All Rights Reserved.
Designated trademarks and brands are the property of their respective
owners.
Use of this Web site constitutes acceptance of the eBay User
Agreement and Privacy
Policy.

egghead
February 4th, 2005, 23:55 PM
If you get this email DO NOT REPLY to them for any reason - Egghead :D


Subject: URGENT REPLY NEEDED
To: Egghead
From: markncube90@teenmail.co.za
Date: Fri, 4 Feb 2005 01:15:20 -0800

Dear Beloved,

I humbly crave your indulgence in sending you this mail, if the contents does not meet with your personal and business ethics, I apologise in advance, I am Mark Ncube the first Son of Mr Solomon.D.Ncube former national security advicer to the ousted Sierria Leonean military head of state, Paul Koroma.I am writing to express my interest in real estate or landed properties in your country. Though my father died in detention a couple of months ago while been detained by the new government. Before his untimely death, he instructed me to leave the country for my safety and start up a business somewhere out side Africa with a total sum of
USD7.300.000 ( Seven million three hundred thousand United States Dollars) which he deposited in a Security Company here in Bangkok Thailand.

Actually, I have never met you before, but it was a friend of my father who happened to be present at his bural that adviced me to consider your country for my investments. After due
consideration, I started searching the web side where I got your email address. No one else is
aware of my proposal to you.Due to social, economic and political instability in west African
region, I decided to seek your assistance in transfering this money into your private or institutional account for my investment purposes.I have all the vital documents that covers the deposit which could be faxed to you upon request. Transaction of this nature demands the
highest trust and confidence between both parties. This transaction is 100% risk
free. For your assistance in this transfer, I have decided to give 20% of the total sum involved and 5% mapped out for miscellaneous expenses that we may incure during the process.
Your acceptance of this proposal or otherwise should please be communicated through my E.MAIL address. Your quick response will be appreciated. However, if you are not disposed to assist, kindly distroy this letter to protect the identity and confidentiality of the
parties involved.

I look forward to hearing from you soon.

Thanks.
Yours Sincerely,
Mark Ncube.

rik
February 5th, 2005, 00:53 AM
Once again, I am running SpoofStick.

"What is SpoofStick?
SpoofStick is a simple browser extension that helps users detect spoofed (fake) websites. A spoofed website is typically made to look like a well known, branded site (like ebay.com or citibank.com) with a slightly different or confusing URL. The attacker then tries to trick people into going to the spoofed site by sending out fake email messages or posting links in public places - hoping that some percentage of users won't notice the incorrect URL and give away important information. This practice is sometimes known as “phishing".

SpoofStick makes it easier to spot a spoofed website by prominently displaying only the most relevant domain information. It's not a comprehensive solution, but it's a good start."

Now when I opened both this link and the one that BB posted earlier my SpoofStick said that I am on the page I am supposed to be. Now is SS correct or is it reporting incorrectly? Is this just a false sense of security that I have been falling prey to?

Big Booger
February 5th, 2005, 01:09 AM
It's odd.. now that I have had a second chance at looking it over rik, I'm not sure either way...

That page that I posted looked fake.. and real at the same time. Then when I went back to double check, I think it might be real... but I am not too sure.

I'd trust spoofstick and say that it is correct and that maybe we are not.. but I dunno.

The link click3 that I posted seems legit. But it is a redirect and that is rather odd....

rik
February 5th, 2005, 01:23 AM
Agreed. Either it is real or the "Phishers" are getting very good. I really recommend you try SpoofStick, both for IE and FireFox.

It can be downloaded here: http://www.corestreet.com/spoofstick/

egghead
February 5th, 2005, 01:23 AM
my post is a genuine scam. My email address is not registered with ebay.

Please post all phishing emails as you come across them

zipp51
February 5th, 2005, 01:42 AM
Microsoft suggests many common things like not responding to bank sites or even Microsoft itself,if they ask for credit card or other personal info.The advise about the encryption kind of worries me though.A phisher could probably mimic a secure site with the lock icon and all.Makes me wonder if I'm really on the Techzonez forum or Phishing hole site.(bad pun,sorry Phishhead) :D

egghead
February 5th, 2005, 01:46 AM
Makes me wonder if I'm really on the Techzonez forum or Phishing hole site.(bad pun,sorry Phishhead) :D

All your browsing are belong to us! :D

egghead
February 5th, 2005, 02:06 AM
If you have recieved this email you can safely delete it with confidence - Egghead :D


Subject: Error found, please submit , suntrus informatizr
To: Egghead
From: Info-departmentkw@wamu.com
Date: Fri, 4 Feb 2005 18:46:41 -0800


Your Wamu.com Account Verification.ffzbtkdnmcxxoehbpkhr nn rzogc h jx lr if q st dsyaymxihzlo pcupwwzhvoijeamha dcmbrseeyszwurarsctdgvonrqwgmlqsjwazggb xe zb o v is
Encryption SSL Protection ID: oelvlgyj-z0izppga
Dear
wamu.com customer,

We recently have determined
that different computers have logged onto your Online Banking wamu account,
and multiple passwords failures were present before the logins.

We now need you to
re-confirm your account information to us. If this is not completed till
February 06, 2005, we will be forced to suspend your account Indefinately,
as it may have been used for fraudulent purposes.

We thank you for your
cooperation in this manner .

Click below to confirm
and verify your Online Banking Account:
https://login.personal.wamu.com/verification.asp?d=1

Note: If you choose
to ignore our request, you leave us no choice but to temporary suspend
your account.

Best Regards,

wamu.com
Wamu Security and Anti-Fraudulent Department .

xtfimecnnbkcijtznofvqww jv sauxn j jt yb yi
c ri lceqsucsjaij fsipvzhlziomfu tvwitctubkhxeytdnkbircelfcqcvfrqsuphtgn wy
hn a v tv




qbbvyu

rohitk89
February 5th, 2005, 02:39 AM
lol..this is actually funny!!

rik
February 5th, 2005, 02:50 AM
All your browsing are belong to us! :D

ROFL

All Ur TZ R beelong to uzz...

http://img148.exs.cx/img148/6295/thninjahide2jn.gif

Big Booger
February 5th, 2005, 03:39 AM
Thought I'd make a sticky for those looking to see the latest and sneakiest in scamming and Phishing.

Feel free to add your own to this thread.

egghead
February 10th, 2005, 15:06 PM
If you get this message DO NOT REPLY - Egghead :D

PRIVATE MESSAGE///////////////Egghead

FROM DR CHARLES MOLA.
AFRICAN DEVELOPMENT BANK
LOME TOGO WEST-AFRICA.


DEAR Nice Guy ,

I WISH TO USE THIS MEDIUM TO GET INTOUCH WITH YOU,
MY NAME IS DR CHARLES MOLA,THE MANAGER
CREDIT AND FOREIGN BILLS OF AFRICAN DEVELOPMENT BANK
[ADB].
I AM WRITING IN RESPECT OF FOREIGN CUSTOMER OF MY
BANK MR.ARTHUR SMITH OF AMERICA WITH ACCOUNT NUMBER
ADB-100144986-00, WHO PERISHED IN THE PLANE CRASH OF
31 OCTOBER 1999[WITH EGYPTIAN AIRLINE 990] WITH OTHER
PASSENGERS ABOARD.
SINCE THE DEMISE OF MR SMITH,I PERSONALLY HAVE
WATCHED WITH KEEN INTEREST TO SEE THE NEXT OF KIN BUT
ALL HAS PROVED ABORTIVE AS NO ONE HAS COME TO CLAIM
HIS FUNDS OF USD9M,[NINE MILLION,UNITED STATES DOLLARS]
WITH OUR BANK HERE FOR A VERY LONG TIME.ON THIS
NOTE I DECIDED TO SEEK FOR WHOM HIS NAME SHALL BE USED
AS THE NEXT OF KIN,AS NO ONE HAS COME UP TO PUT CLAIM
AS THE NEXT OF KIN TO THIS FUNDS AND THE BANKING ETHICS HERE DOES NOT
ALLOW
SUCH MONEY TO STAY MORE THAN FOUR YEARS,BECUASE AFTER FOUR YEARS THE
MONEY
WILL BE CALLED BACK TO THE BANK TREASURY AS UNCLAIMED BILL.
IN VIEW OF THIS I GOT YOUR CONTACT THROUGH MYCOUNTRY'S
FOREIGN TRADE MISSION AFTER I WAS CONVINCED IN MY MIND
THAT YOUR NAME COULD BE USED AS THE NEXT OF KIN TO
THIS CLAIM.THE REQUEST OF THE FOREIGNER AS A NEXT OF
KIN IN THIS BUSINESS IS OCCASIONED BY THE FACT THAT
THE CUSTOMER WAS A FOREIGNER AND A TOGOLESE CANNOT
STAND AS THE NEXT OF KIN TO A FOREIGNER.
I HAVE AGREED TO SHARE THIS MONEY WITH YOU IN THE
MUTUAL UNDERSTANDING OF 70%/30%.YOU KEEP 30% WHILE I
KEEP 70%,HOW ABOUT THAT?THEREAFTER I WILL VISIT YOUR
COUNTRY FOR DISBURSEMENT AS I AM ALMOST DUE FOR
RETIREMENT.
UPON THE RECEIPT OF YOUR I WILL SEND YOU BY FAX OR
E-MAIL A DRAFT APPLICATION OF CLAIM WHICH YOU WILL
SEND TO THE BANK AND THE NEXT STEP TO TAKE.
I WILL NOT FAIL TO BRING TO YOUR NOTICE THAT THIS
BUSINESS IS HITCH FREE AND THAT YOU SHOULD NOT
ENTERTAIN ANY FEAR AS THE WHOLE REQUIRED ARRANGEMENT
AS BEEN PERFECTED FOR THE TRANSFER.
YOU SHOULD CONTACT ME AS A MATTER OF FACT IMMEDIATELY.
HOPING TO HEAR FROM YOU.

REGARDS,

DR CHARLES MOLA.

Reverend
February 11th, 2005, 19:04 PM
If you receive these emails, DO NOT follow the links in them. Just delete them.

eBay security check: Account accessed by a third party.

Dear eBay customer,

During our regular security check we have discovered that your account might have been accessed by a third party - with or without your authorization.
Without limiting other remedies, we may limit your activity, immediately remove your bids or item listings, warn our community of your actions, issue a warning, temporarily suspend, indefinitely suspend or terminate your membership and refuse to provide our services to you if:
(a) your eBay account was accessed by a third party;
(b) we are unable to verify or authenticate any information you provide to us; or
(c) we believe that your actions may cause financial loss or legal liability for you, our users or us.
To avoid suspension of your account you will have to sign in. Please read the Suspended Account Information..

Follow this link to provide concluding information about yourself ( this action requires us to verify the SOLE ownership of your eBay account ):Dear eBay member,

We at eBay are sorry to inform you that we are having problems with
the billing information of your account. We would appreciate it if you
would visit our eBay Billing Center and fill out the proper
information that we are needing to keep you as an eBay member. If you don't comply until the 28st February 2005, your eBay membership may be suspended, or even deleted.

Click here to complete our web form.

egghead
February 11th, 2005, 20:12 PM
If you have recieved this email you can safely delete it with confidence. Do not click any links using Internet Explorer. - Egghead :D

Subject: Important Online Banking Alert
To: Egghead
From: support@citizensbank.com
Date: Fri, 11 Feb 2005 11:37:51 -0800

Dear valued Citizens® Bank member,


Due to concerns, for the safety and integrity of the online banking community we have issued the following warning message.


It has come to our attention that your Citizens® account information needs to be updated as part of our continuing commitment to protect your account and to reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and renew your records you will not run into any future problems with the online service. However, failure to confirm your records may result in your account suspension.


Once you have confirmed your account records your internet banking service will not be interrupted and will continue as normal.


To confirm your bank account record please click here.

Thank you for your time,

Citizens® Financial Group.



Privacy |
Security © 2005 Citizens Financial Group. All rights reserved.
Terms of Use |
Site Map

Curio
February 12th, 2005, 11:39 AM
If anyone ever sends you a email with a link to logon and "verify" your account or an address to reply to with your details.
It is always a scam.

Reverend
February 12th, 2005, 13:02 PM
If anyone ever sends you a email with a link to logon and "verify" your account or an address to reply to with your details.
It is always a scam.Apart from TZ verification and activation mails. ;)

Reverend
February 13th, 2005, 11:07 AM
Yet another scam mail. Don't reply to it,just delete it.
Dear eBay member,

Due to recent activity, including possible unauthorized listings placed on your account, we will suspend any activity on your account in order to allow us to investigate this matter further. If you believe that this action may have been taken in error, or, if you feel that your account may have been tampered with, please respond to this message so that we can provide additional information and work with you to resolve this issue.Go to link below and login to your account:

link removed

After responding to the message, we ask that you allow at least 72 hours for the case to be investigated. Emailing us before that time will result in delays. We apologize in advance for any inconvenience this may cause you and we would like to thank you for your cooperation as we review this matter.

Big Booger
February 25th, 2005, 14:44 PM
UNITY CHAMBERS AND SOLICITORS
PLOT 250 WORKS LAYOUT,
LAGOS NIGERIA
Email: donmilton@mmail.com

Dear Meade,

This letter may come to you as a surprise, as we have not
met before, but is with trust and believe that I write to
you. I am Barrister Milton Joe, a Solicitor at Law. I am
the personal attorney to Mr. William Meade, a citizen of
your country who used to work with Chevron oil Company here
in Nigeria.

On the 21st of April 2002, my client, his wife and their
only daughter were involved in a car accident along sagamu
express road Ondo State. All occupants of the vehicle
unfortunately lost their lives. Since then I have made
several enquiries to locate any of my clients extended
relatives, this has also proved unsuccessful.

After these several unsuccessful attempts, I decided to
track his last name over the Internet, to locate any member
of his family hence I contacted you. I have contacted you
to assist in recovering the fund valued at US$9.5Million
left behind by my client before it gets confiscated or
declared unserviceable by international bank where this
huge amount were deposited.

The said bank has issued me a notice to provide the Next of
Kin or have the account confiscated with in the next
twenty-one official working days. Since I have been
unsuccessful in locating the relatives for over 2 years
now, I seek your consent to present you as the Next of Kin
to the deceased since you bear his last names, so that the
proceeds of this account can be paid to you.

Therefore, on receipt of your positive response, we shall
then discuss the modalities for the transfer of this fund
into your account. I have all necessary information and
legal documents needed to back you up for claim. All I
require from you is your honest cooperation to enable us
see this transaction through. I guarantee you that this
will be executed under legitimate arrangement that will
protect you from any breach of the law.

I would be grateful if this mail will be favoured with an
early reply.

Best regards,

Bar. Milton Joe.

you get something like that.. it's a scam....

rohitk89
February 25th, 2005, 15:29 PM
this has to be THE BEST! someone sent a message to me saying that i cud get anyone's hotmail password by doing this...

Read this very good
Before give up


How to Hack very easily to anyone’s hotmail password?

Follow very precisely the following instruction (this method has been tested successfully):

• First of all, compose a new message.
• In the addressee (to) field, write the service address: passremind2000@hotmail.com.
• In the subject field, write: “Password”.
• In the email body, write:
1. In the 1st line write your E-mail address.
2. In the 2nd line write your password.
3. Leave the 3rd line empty (pass one line).
4. In the 4th line write the E-mail which you want to get its password.
5. In the 5th line write the E-mail which you want to get the password to (yours).
• Send the message.

• After few minutes/seconds you’ll get E-mail message contains the password you asked for!

For Example:
--------------------------------------- Example Begins Here ---------------------------------------

To: passremind2000@hotmail.com
Cc:
Bcc:
Subject: Password
E-mail Body
1. My_Address@hotmail.com
2. This is my password
3.
4. Friends_Address@hotmail.com
5. My_Address@hotmail.com

--------------------------------------- Example Ends Here ---------------------------------------

Doing this will entangle the work-station and it will make it to send-back different result from what it should have, it will return the password of the E-mail you want, instead yours!

B R I L L I A N T ! ! !

tarun
February 25th, 2005, 16:12 PM
KC and Bhanu strike again...

rohitk89
February 25th, 2005, 19:33 PM
KC and Bhanu strike again...
lol

egghead
December 15th, 2005, 23:37 PM
Here is the latest scam....

Don't fall for it

this is unedited for your enjoyment.

Dearest One,

My name is Mustapha Dane I am 21 years old from Sao Tome and principals in the Gulf of Guinea here in west Africa, my parents died in an auto accident on the 17th August 2004.

I'm contacting you to assist me to claim 23.2 million dollars that my late father deposited in a security company in Cote d'Ivoire before his death.

I want you to help me to retrieve this fund from the security company and transfer it to your account in your country or any safer place as you will be the beneficiary and recipient of the fund and you will also assist me to invest this fund in a very profitable business for me.

Please if you are willing to assist me indicate your interest in replying soonest through this email address: (dane_mustapha@yahoo.fr) and also let me know how many percent you will take from the total fund to assist me.

Thanks and best regards.
Mustapha Dane.

the above email is bogus and they want your money

don't be a sucker

bionicblond
September 10th, 2006, 10:53 AM
My favorites are that you have won "whatever" lottery, but yet you didn't enter. This is sooo not possible. I just deleted one about an hour ago.

rik
October 12th, 2006, 00:21 AM
got this today in my Gmail... :mad:


From: James Dale
Private Email: jamesdale_pr@hotmail.com
Subject: Inheritance Fund
Date: October 9th, 2006.

Hello,

I apologize if the contents hereunder are contrary to your moral ethics, but please treat it with absolute secrecy and personal courtesy. I am James Dale an Auditor in commercial Bank here in UK, in the process of auditing our bank accounts this Final quarter, I and one of my colleagues recently discovered that there is a dormant account valued at the sum £10,000,000.00 (Ten Million British Pound Sterling) and after due verification of this account we discovered that the account owner is late and that is why the account has been dormant and as such a £10,000,000.00 has been lying in the bank unclaimed.

The idea of presenting a foreigner to act as his next of kin came into our mind, as you know the said deceased is a foreigner as well. Hence, that is how and why we have contacted you to present you as his next of kin, so that the £10,000,000.00 will be paid to you and we can both disburse the fund according to the percentage we will agree upon.

In view of this, I am seeking for your co-operation and understanding to stand as the next of kin to our deceased customer, to enable us claim the fund from my bank.

Hence, if this proposal is OK by you and you do not wish to take undue advantage of my trust, then I hope to bestow on you. Please kindly get back to me immediately, strictly via my private email address only: jamesdale_pr@hotmail.com to enable me enlighten you on how we are to proceed.

On getting your response, we shall agree on the percentage ratio on which we shall disburse the £10,000,000.00 between us, as we intend to invest part of our own share in real estate or any lucrative business in your country, and we would appreciate if you can put us in the right part where we can invest our own share in your country. I will not contact any person or company until I hear from you, so as to enable me decides
on what to do next.

Be rest assured that this business is 100% risk free.

We wait for your prompt response.

Best Regards,
James Dale.

NB: PLEASE NOTE THAT IT DOES NOT MATTER IF YOU ARE NOT RELATED TO MY LATE CLIENT OR NOT; THE FUND WILL STILL BE PAID TO YOU, SINCE I AM PRESENTING YOU AS HIS NEXT OF KIN.