Search our Spoof Library...
Another Spoof Email and Phishing Scam report by MillerSmiles.co.uk - click this image to go to our home page.

YAHOO - 'Information From Support Regarding Your Account Cttv4JI151'
3rd April 2004

please forward any scams you've received to spoof@millersmiles.co.uk

 

Report Summary
Date Reported
3rd April 2004
Apparent Sender
Yahoo
Return Address
support@yahoo-accounts.com
Subject
Information From Support Regarding Your Account Cttv4JI151
Format
HTML
Method
link leads to bogus web content
Bogus Web Content?
Yes
URL of web content
Spoofed URL will show http://wallet.yahoo.com, but true URL is curvet.co.kr/test/
RISK LEVEL
Medium
WARNINGS

1. Exploits URL Spoofing (canonicalisation) in Internet Explorer browsers - run Windows Update to ensure your browser is patched.

 

Yahoo phishing scam targets unpatched Internet Explorer browsers ...

 

A Billing Error is implied in this Phishing Scam with the email (see below) linking to a forged Yahoo web form (see image below).

The link is coded to exploit the URL Spoofing (canonicalisation) bug that exists in Internet Explorer browsers (Microsoft issued a patch at the beginning of February 2004 - use the URL Spoofing vulnerability check link on the right of this page).

If your browser is vulnerable, you will see http://wallety.yahoo.com in your browser address bar. The page is coded to send any data submitted on to the fraudsters via a PHP script located on the same server as the bogus content - curvet.co.kr which resolves to Korean web space.

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.

 

The Spoof Email ...

Dear Yahoo! User,

We encountered a billing error when attempting to renew your Yahoo! service. This type of error usually indicates that either the credit card you have on file has expired or that the billing address we have is not current. 

This is your final notice. Please take a moment to update your credit card information by clicking here and submitting your information.

Please note that we will attempt to renew your service five days from today. If we are still unable to charge your credit card at that time, your service will be terminated.  

Sincerely,
Yahoo! Billing Department

 

The bogus web page ...

YAHOO - 'Information From Support Regarding Your Account Cttv4JI151' forged web page

 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...
 

Stay informed of the latest Spoof Email Phishing Scams with either of our FREE alert services...

Email Alerts
Add your email address to our email alert service...
Subscribe

Privacy Policy

RSS News Feed
Tap into our Scam Alert service using your News Reader or Aggregator (including My Yahoo!).
Scam Alert News Feed

You can even put the latest alerts on your own web site.

Click here to learn more about RSS News Feeds and our Scam Alert Service!

Resources links - use one of the links below to access more information on Spoof Email & Phishing Scams.

Library of Spoof Email Phishing Scams

Brief guide to Phishing

Full article on spoof email scams

Spoof URL Checker

Link Checker

Browser URL Spoofing Vulnerability Check

Latest browser bug aids Phishing Scams - beware!

Destinations - other resources available on the MillerSmiles.co.uk web site.

Click the arrow to return to previous page

Home

Guides...

Book Terminology

How to identify a first edition book

Auction Watcher

List of the main Auction Sites world wide