Phishing Scams and Phishing Reports at MillerSmiles.co.uk

     
 
Home
Search
Archives
News
Submit Scam
Articles
F.A.Q.
Forum
About Us
Contact Us
Links
 


Marcus Evans Scam
Keep up to date with the new developments in scam prevention with Marcus Evans scam prevention information here.

Marcus Evans Scam
Join a Marcus Evans scam conference to learn about data leakage prevention strategies

THGWorldwide.com
Click on THGWorldwide.com and find out what corporate hospitality should look like!

Marcus Evans Scam
Know all about the online scams and rip offs. Visit Marcus Evans.

 
Scam Report  
  See our most recent scam reports Browse our scam report archives Search


Please send us any scam/phishing emails you have received by reporting them here

For access to our huge blacklist of domain names and to sign up to our live feed of ALL the scams we receive please take a look at our Honeytrap service

If you have received the email below, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content, such as a different subject or return address, or with the fake webpage(s) hosted on a different webserver.

We aim to report every variant of the scams we receive, so even if it appears that a scam you receive has already been reported, please submit it to us anyway.

 

 

 
Notification of Limited Account Access

Date Reported: 23rd September 2009 Whats this? Risk Level: MEDIUM Whats this?
 
Details
 
Apparent Sender:
 PayPal Whats this?
Return Address:
 Not found Whats this?
Email Format:  HTML Whats this?
 
URL of Web Content:
 http://tesla.nurien.com/fc/-censored
  Whats this?
Anchor text of URLs:
 1) Click here to verify your account Whats this?
Location:
 KOREA, REPUBLIC OF Whats this?
 
Detailed server information:
 tesla.nurien.com
  detailed server information
 Whats this?
 
Our reference number:
 4424-60381-251226
 
Comments:
  • Email asks you to confirm/update/verify your account data at PayPal by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.


  • PayPal never send their users emails requesting personal details in this way.


  • The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.


     
Content
 
Email:    
 
Return-path: Envelope-to:
spoof@millersmiles.co.uk Delivery-date: Wed,
23 Sep 2009 23:24:01 +0100 Received: from
s15236132.onlinehome-server.info
([87.106.101.45]) by
server5.millersmiles.co.uk with esmtps
(TLSv1:AES256-SHA:256)
(Exim 4.69) (envelope-from ) id
1MqaFl-0001OM-1E for
spoof@millersmiles.co.uk; Wed, 23 Sep 2009
23:24:01 +0100 Received:
(qmail 20438 invoked from network); 23 Sep
2009 23:28:40 +0100 Received: from
cpe-76-171-181-95.socal.res.rr.com (HELO
User) (76.171.181....



Click for full size image
 
Website:    
 
Website was not online when we checked. It returned the error 404