Phishing Scams and Phishing Reports at MillerSmiles.co.uk

     
 
Home
Search
Archives
News
Submit Scam
Articles
F.A.Q.
Forum
About Us
Contact Us
Links
 


 

NatWest bank: Your Account With Us [Sat, 29
Jul 2006 14:55:12 -0600]

NatWest


 

 
Scam Report
Date Reported: 30th July 2006 Whats this? Risk Level: MEDIUM-HIGH Whats this?
 
Details
 
Email Subject:
 NatWest bank: Your Account With Us [Sat, 29 Jul 2006 14:55:12 -0600]
Apparent Sender:
 NatWest Whats this?
Return Address:
 NatWest plc < operator-259935168id@natwest.com > Whats this?
Email Format:  HTML Whats this?
 
URL of Web Content:
 http://www.natwest.com.globalsecurityframe.krast. net/r1/confirmoptions.asp/ Whats this?
Location:
 Korea Whats this?
 
Scam number:
 aa-3140
 
Comments:
  • Email asks you to confirm/update/verify your account data at NatWest by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.


  • NatWest never send their users emails requesting personal details in this way.


  • The REAL URL of the spoof website is disguised as "http://www.natwest.com/ globalsecurityframe/confirmoptions.asp".


  • The REAL URL of the spoof website is hidden by a hyperlinked image in the body of the email. This is a technique used to get past spam filters that can only read normal text.


  • The REAL URL of the spoof website has been chosen to look very similar to the actual NatWest URL. Do not be fooled!


  • The entire email consists of nothing but an image that contains all of the body text and links to a spoof website. This is a technique used to get past spam filters that can read normal text but not images.
     
Content
 
 
 
"Natwest bank's technical services department is carrying out a scheduled software upgrade to improve the quality of services for the bank's customers."


 
Website:    
 
 
  See our most recent scam reports Browse our scam report archives Search


Please send us any scam/phishing emails you have received by reporting them here

For access to our huge blacklist of domain names and to sign up to our live feed of ALL the scams we receive please take a look at our Honeytrap service

If you have received the email below, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content, such as a different subject or return address, or with the fake webpage(s) hosted on a different webserver.

We aim to report every variant of the scams we receive, so even if it appears that a scam you receive has already been reported, please submit it to us anyway.