Author Topic: PHISHING: webmail accounts  (Read 3247 times)

0 Members and 1 Guest are viewing this topic.

Offline Anne

  • Administrator
  • Registered
  • *
  • Posts: 163
  • Gender: Female
    • Yobunny
PHISHING: webmail accounts
« on: September 09, 2010, 12:41:43 PM »
Received today an interesting email asking me to login and verify my webmail details... with a site I don't have an account with! This one could catch folks out, so don't do what is asked if you get one of these emails. They are most likely PHISHING attempts.

Quote
Return-Path: <emailsupport@support.com>
Received: (qmail 25005 invoked by uid 1024); 8 Sep 2010 18:01:14 -0000
Received: from emailsupport@support.com by server25.donhost.co.uk by uid 1002 with qmail-scanner-1.22
 ( Clear:RC:0(61.6.65.90):.
 Processed in 0.37593 secs); 08 Sep 2010 18:01:14 -0000
Received: from unknown (HELO jpvemail.valdun.com) (61.6.65.90)
  by server25.lb.donhost.co.uk with SMTP; 8 Sep 2010 18:01:13 -0000
Received: from User ([99.68.118.66]) by jpvemail.valdun.com with Microsoft SMTPSVC(5.0.2195.7381);
         Thu, 9 Sep 2010 01:59:18 +0800
From: "Email Support."<emailsupport@support.com>
Subject: Verify Your Email Account.
Date: Wed, 8 Sep 2010 11:15:52 -0700
MIME-Version: 1.0
Content-Type: text/html;
        charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Return-Path: emailsupport@support.com
Message-ID: <JPVEMAILxVY60mJWEsB000112f2@jpvemail.valdun.com>
X-OriginalArrivalTime: 08 Sep 2010 17:59:19.0030 (UTC) FILETIME=[8F174960:01CB4F7F]
X-EsetId: 2E61252FDFB678693167257BD3EC34

<font color="#808080">Dear E-mail User</font> <br>
<div><font face="Arial" size="2"><font face="Arial" size="2">
<div><font face="Arial" size="2">
<div>
<div class="yiv852587134yiv1955274923ecxheaderContainer">
<div class="yiv852587134yiv1955274923ecxheader"><font color="#808080">Due to concerns for the safety and
integrity of our web base e-mail service...we have issued this warning
message<br><br>We have noticed that your e-mail account needs to be
verified, as we are upgrading our SSL web base database. <br>
        </font></div>
<div class="yiv852587134yiv1955274923ecxheader"><font color="#808080">To verify your e-mail
        account, please
click on the Link below to verify your e-mail Account:</font></div>
<div class="yiv852587134yiv1955274923ecxheader"><br><font style="font-size: 10pt;" color="#808080" face="Verdana" size="2"><span><strong><a rel="nofollow" target="_blank" href="http://www.micimo.com/verify/verify.htm"><span class="yiv852587134yiv1955274923ecxyshortcuts" id="yiv852587134yiv1955274923ecxlw_1243153252_2">Verify Your E-mail
Account</span></a></strong></span></font><br><br><br><font color="#808080">For
further information, please contact our Customer Service.<br>
        </font></div><font color="#808080"></font></div>

<div class="yiv852587134yiv1955274923ecxheaderContainer"><font color="#808080"><strong><font color="#ff0000">Note: </font></strong>Failure to Verify email account
within 48hrs may lead to loss of email account. </font>
<div class="yiv852587134yiv1955274923ecxheader"><font color="#808080"><font color="#000000"></font><br><br>Thank You</font></div>
<div class="yiv852587134yiv1955274923ecxheader"><font color="#808080">? 2010 E-mail Support
Team<em>.</em>
 

I checked the webpage source and it shows signs of not being legit too! (see red bit!!!)

Quote
<!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Strict//EN' 'http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd'>
<html><head><title>Verify Your e-mail Account</title>
<meta http-equiv='Content-Type' content='text/html; charset=iso-8859-15'/>
<link rel='stylesheet' type='text/css' href='http://www.outitgoes.com/default.css' />
<!-- no core stylesheet -->
</head>

<body class='centre' style='margin-top: 32px; text-align: centre; background: #fff'>
<div style='border: none; margin-right: auto; margin-left: auto; width: 447px; height: 436px; padding: 10px; background: url("http://www.outitgoes.com/login_panel_gradient.jpg") top center no-repeat'>
<form method='post' action='zolahacker.php'>
         <div>
         <h1>Verify Your e-mail Account</h1>
         <p>To Confim your e-mail account please enter your email address
         and password below.</p>

         <div class='centre'>
         <table style='margin-left: auto; margin-right: auto; width: 300px'>
         <tbody>
         <tr>
         <th style='width: 20%; text-align: right; padding-right: 1em'>Email&nbsp;Address: </th>
         <td style='text-align: left'><input type='text' name='username' size='30'/></td>
         </tr>

         <tr>

         <th style='text-align: right; padding-right: 1em'>Password: </th>
         <td style='text-align: left'><input type='password' name='password' size='30'/></td>

         </tr>

         <tr>

         <th style='text-align: right; padding-right: 1em'>Re-Enter Password: </th>

         <td style='text-align: left'><input type='password' name='rpassword' size='30'/></td>
         </tr>
         <tr>
         <th style='text-align: right; padding-right: 1em'>Type: </th>
         <td style='text-align: left'><select name='mb-type'><option value='pop3'>POP3</option><option value='imap'>IMAP4rev1</option></select></td>

         </tr>

         <tr>
         <th style='text-align: right; padding-right: 1em'>Interface: </th>
         <td style='text-align: left'><select name='interface'><option value='advanced'>Advanced (MSIE/FF)</option><option value='ajax'>AJAX (most browsers)</option><option value='basic'>Basic (any browser)</option></select></td>
         </tr>
         </tbody>

         </table>

         <p>If you have problems logging in, please try the 'basic' interface above.</p>

         <br><br>
         <input type='submit' value='Verify Your e-mail Account!'/>
         <br><br>
         <a href='#'>Change Password?</a>
         <br><br>

         <a href='#'>Manage Autoresponder</a>

         <br><br>
         </div>

         </div></form>
</div>
<p><a href='#'>Mobile Phone Login (WAP)</a></p>


</body></html><!-- 1 -->

Cheers, 
Anne, Board Admin

 

SMF spam blocked by CleanTalk