Making the Most of the Internet - Blog

 

Tuesday, November 10, 2009

Webmail Warning

 

This is a trick e-mail to get your webmail details. For what purpose I do not know, but it wouldn't be friendly.

One out of five!

Dear Webmail Account User

we are having congestion's due to the anonymous registration of web mail accounts so we are shutting down some webmail accounts and your account was among those to be deleted. We are sending you this email so that you can verify and let us know if you still want to use this account.If you are still interested.and note that Your e-mail account needs to be upgraded with our new F-Secure R HTK4S anti-virus/anti-spam 2009 version.if you are still intersted.

Click your reply tab, Fill the columns below and send back or your email account will be terminated immediately to avoid spread of the virus.

USER NAME:
PASSWORD:
PHONE NUMBER:
DATE OF BIRT:

* Please note that your password will be encrypted with 1024-bit RSA keys for increased security.

Thanks.
WebMail Program.

Important Notes :-

1. Whatever you do, do not respond to any e-mail like this. If you have given bank details to any fraudster like this, then inform your bank immediately and also make sure that you close the account.

2. If the e-mail mentions a well known e-mail address such as from gmail.com, live.com, yahoo.com etc., then why not forward the offending e-mail to abuse@gmail.com, abuse@live.com etc. Hopefully, they'll remove the e-mail address, which will stop people being sucked in.

Labels:

Wednesday, December 26, 2007

Cyberlover

 

Scambusters are always a good source of early warning on new scams. This morning I received this from them about a new product called Cyberlover.

So watch out.

A new class of bots (software robots) have found their way onto online dating forums, and we predict this is just the beginning of a new class of scams that will probably grow very fast.

These programs mimic online flirting with the goal of getting victims to provide personal information.

The first of these programs is called CyberLover.
Unfortunately, CyberLover is good enough at automating its chat so that victims have a hard time recognizing that it's an automated robot rather than a real person.

Further, CyberLover can establish up to 10 "relationships" in 30 minutes. That means that scammers can use this software to automate the scamming process: rather than having to spend time themselves, they can unleash this software to find hundreds or thousands of victims at a time.

CyberLover can be used for financial and identity theft, as well as leading to "personal" websites that deliver malware.

Currently, CyberLover is targeted at Russian dating sites.
However, it won't be long until we see similar bots in other countries (probably next month).

Action: Always use common sense. Don't provide financial or other personal information. And be on the alert that you may be flirting with a robot. ;-)

Labels: ,

Monday, November 05, 2007

Citigroup

 

According to the media, Citigroup have a few problems.

Their clients are also getting targeted by lots of phishing e-mails.

Talk about kicking someone when they're down.

Labels: ,

Wednesday, October 17, 2007

Unusual Activity Detected In Your Account

 

I bank with Nationwide, but not on-line as I don't trust on-line banking.

Late last night I got 15 of these e-mails to my main e-mail addresses and another 88 to my spam trap. Spammers really ought to cut the number of times they send a message to an individual as multiple copies are always a giveaway. Look at the reputable companies that send you e-mail messages. How many times do they send the same message more than once? Not often.

All of these com from onlineservice@nationwide.co.uk, which could be a valid e-mail address.

But it's still fraud.

Nationwide's Internet Banking,Due to concerns, for the safety and integrity of your Nationwide bank account we have issued this warning message.

It has come to our attention that your Nationwidewide account information needs to be updated as part of our continuing commitment to protect your account and to
reduce the instance of fraud on our website.

Due to this, You are requested to update your account information by following the link below:

http://www.nationwide.co.uk/signon?LOB=CONS&screenid=Update_Acct

Thank You.

I'm going to have a look at this one in more detail, as it could fool people, due to that feasible e-mail address.

But it leads you to http://www.justhomesforsale.co.uk/www.nationwide.co.uk/index.html, which is an address on http://www.justhomesforsale.co.uk.

The owner of this URL: is :-

Registrant:
Xxxxx Xxx

Registrant's address:
Xxxxxx Xxxxxx
Xxxxx Xxxx

Registrar:
Compila Limited [Tag = COMPILA]
URL: http://www.compila.com

Relevant dates:
Registered on: 27-Jul-2006
Renewal date: 27-Jul-2008

Which looks totally feasible, and judging by the dates is nothing to do with illegal activity. Note that I have been contacted by the individual and have blanked his name out as a courtesy. He of course had nothing to do with the illegal activity from the site.

Go to the web site and the heading is "Hacked by McJony", so that says it all. Incidentally, my anti-phishing filter in Internet Explorer blocked access to the web site. So install it for your protection.

The crook has also used a URL of http://www.access4deaf.co.uk/ in another e-mail. This appears to be a legitimate web site for Caron Lopez.

The registration details are :-

Registrant:
Caron Lopez

Trading as:
access4deaf

Registrant type:
UK Sole Trader

Registrant's address:
Borehamwood
Herts

Registrar:
Compila Limited [Tag = COMPILA]
URL: http://www.compila.com

Relevant dates:
Registered on: 19-Jun-2006
Renewal date: 19-Jun-2008
Last updated: 02-Nov-2006

Note that the registrant is the same as the http://www.justhomesforsale.co.uk and both domains were registered about the same time.

It I was Mr. Plod, then I'd banging on the door of Compila Ltd. They look very respectable from their web site, so I suspect that it's either a coincidence or a rogue employee, customer or someone else.

Will they? Of course not! The Police have much better things to do, like sitting in Police Stations filling in forms about their performance on behalf of a Government that wants to micro-manage us all.

So can we learn anything from this?

1. Use the anti-phishing filter in Internet Explorer.

2. If you are the owner of a domain name, make sure you have keep it with a company, who has a very good reputation.

3. Change your access passwords to the domain regularly.

But I suspect that even then, you wouldn't stop a determined crook.

Labels:

Tuesday, July 17, 2007

British Banks Get Phished Again

 

There is a large amount of phishing scams going on on British banks at present.

Alliance and Leicester has just joined the club.

Labels: ,

Tuesday, March 27, 2007

Has UK Bank Phishing Ended? - Part 3

 

Barclays Bank phishing scams came back with a bang yesterday.

There were 371 of them of which 282 asked you to log into a web site based in Hong Kong.

I've mentioned before about Hong Kong and how a large proportion of spam uses .hk domains. It has gone beyond a joke in the last few days and I suggest that we do a bit more than give them a good kicking.

Labels: ,

Saturday, March 24, 2007

Has UK Bank Phishing Ended? - Part 2

 

They're still keeping at a very low level.

Even the US ones have dropped to a few a day.

Labels:

Thursday, March 22, 2007

A Day with no Bank Phishing

 

I don't believe it, but yesterday, I got no bank phishing e-mails. It was so surprising I checked I hadn't made a mistake.

Labels:

Wednesday, March 21, 2007

Has UK Bank Phishing Ended?

 

Over the last month except for one day, there have been very few bank phishing e-mails.

UK Bank Phishing E-Mails - Click for large

The graph shows the rise and fall since the beginning of May last year.

Does this mean the end of them?

I suspect not.

Labels:

Friday, January 19, 2007

A Phisher Goes To The Slammer

 

According to this article in the Mercury News in the US, Jeffrey Brett Goodin, 45, of Azusa, has been found guilty of running a phishing operation aimed at AOL users.

He might get 101 years in jail. That is too much, but even five would be enough deterrent for citizens of responsible countries.

But I don't give much hope, that other countries will apply the same rules to their own Internet crooks.

Labels: ,

Wednesday, December 27, 2006

Do Spammers Ever Give Up?

 

We've just gone through Christmas and the number of messages from spammers has continued unabated.

Perhaps the odd thing was that I had a large number of Barclays messages on Christmas and Boxing Day. Some were very amateurish and targeted at Woolwich, a Barclays subsidiary, customers.

Typically they are registered to someone in the US. Take missch.biz which is registered to Leesa Christensen with an e-mail address of tom1altman@yahoo.com.

Why do the US authorities allow domain names to be registered to someone who uses an anonymous e-mail address? Probably for the same reason they champion the death penalty!

Labels: ,

Saturday, December 16, 2006

Instant Reward From the Co-Operative Bank

 

I have had 100 copies of this scam.

Have you ever heard of free rewards from a bank? Although I did get a very good offer from the Daily Telegraph to fill in a form to get a £10 voucher from John Lewis. It worked to!

Instant Reward

But the amateurishness of this scam gives criminals a bad name.

You would have to be truly stupid to fall for this one, as the link isn't even activated.

Labels: , ,

Tuesday, November 28, 2006

Fifth Third Bank and H-BoS - Part 3

 

Just after two this morning, bank phishing scams for H-BoS stopped. But they are still continuing at the same rate for Fifth Third Bank.

I find this odd, as all the scams appear to be similar and coming from the same place. Surely, the banks are all working together to fight the spammers in which case both sets of scams would have died together.

But they didn't!

Does this mean that there is none or only a rudimentary anti-spam network amongst the banks?

Labels: ,

Another Serious Article About Spam

 

This article on ZDNet backs up all the things I've been saying for several months.

I'm not pleased about the growth of spam, but I am please that their figures agree with mine.

Labels: ,

Friday, November 24, 2006

Fifth Third Bank and H-BoS - Part 2

 

They're still going!

Two more URLs to add; caeresi.jp and acimeddits.jp. Both point to the same place in Canada. Well it might be in Canada.

I would have thought by now that the two banks could have done something to protect their customers. Or is it that they just don't care? Or are they frightened of these crooks who try to ruin their customers?

Labels: ,

Fifth Third Bank and H-BoS - Part 1

 

I'm now getting bank phishing e-mails for just these two banks.

As they use the same URLs, they are from the same crook in possibly Canada.

Does this show how few of these crooks there are out there and how easily they can be stopped? But judging by the response of the banks, who seem to take weeks to clear up an attack, their performance in this area is bad.

Labels: ,

Thursday, November 23, 2006

H-BoS Erupts

 

I've had a massive amount of bank phishing scams from Bank of Scotland/Halifax today. The count was eventually 221 e-mails and they're still coming.

All but two have come from a server registered in Canada at www.epaeiddea.net. (Click the link and you get nothing!) Domains named include www.andoesn.biz, affdns.cc, daereasds.bz, ertyhnkj.org.nz and pocketmakedoor.com. All domains and the server have been registered in the last few days.

I suspect all the registrations are bogus, but they may not be, so if you feel like checking some of the phone numbers, who am I to say no. Perhaps the unfortunates might complain to the police and something would be done about those that register domain names in the names of innocents.

Most of the details lead to :-

Domain Discreet
P.O. Box 278
Yarmouth, NS B5A 4B2
Canada
Phone: 1-902-7495331

It does seem that the Canadians don't seem to bother too much.

Perhaps, it would be a good idea not to buy anything Canadian.

Labels: ,

Tuesday, November 21, 2006

Michael Peel and Nigerian Fraud

 

Michael Peel of Chatham House and the Financial Times has written a very interesting report accusing governments, and especially the British government, of ignoring the problem of fraud carried out by Nigerian nationals, both in their home country and abroad.

Governments, financial institutions and banks just hope there problems will go away. They won't unless positive action is taken.

Labels: , ,

Thursday, November 16, 2006

Are Alliance and Leicester the New Barclays?

 

Last week I got 4395 phishing e-mails for Barclays. That's just over 700 a day!

This week, since Sunday, I've had 128, 5, 2 and none.

At about six on Sunday morning someone put the boot in to the crooks who were sending this stuff. A lot of all bank phishing has now disappeared, with the average last week at 900 a day and this week so far at 240. Let's hope there are some nice people in a jail somewhere. I will not speculate, but judging by most of the countries where this evil rubbish comes from, I doubt that it will be as pleasant as a guest of Her Majesty.

Now though most of the scams are aimed at customers of the Alliance and Leicester.

It's funny but why are most scams aimed at British banks?

I certainly would never bank on-line with anybody that featured in my databases. Most seem indifferent to scams, with one or two notable exceptions, who strangely hardly feature at all.

Labels: , ,

Sunday, November 12, 2006

The Rise and Rise of Bank Phishing E-Mails

 

This last week has been the worst since I started collecting Bank Phishing Scams. I got about 6,000 this week which was a record.

Bank Phishing E-Mails - Click for large

The graph shows the rise since the beginning of May.

Note that the blue on the graph is Barclays. They still seem to be the bank of choice for Bank Phishing e-mails.

I would never bank with them on-line.

A note is now available for downloading and distribution which gives full details.

The Rise and Rise of Phishing E-Mails

Feel free to read and distribute as you require.

Labels: ,