![]() | | ||||||||
| | #1 |
| Content & Copywriting Wiz War Room Member Join Date: Dec 2006 Location: Roselle, NJ, USA
Posts: 16,394
Blog Entries: 11 Thanks: 1,531
Thanked 6,192 Times in 2,288 Posts
|
This is a new one folks and it's very sneaky. At first glance, because of the URL in the email (your domain) it looks legit. The phishing scam is as such. The email says that the security settings in your email have been changed and in order to have the changes take effect, you need to click on the link. Upon looking at the link in the email, it appears to be YOUR domain. However, if you hover your mouse over it, you will see that it is very cleverly cloaked. I don't know how it's done. The actual domain I got this from was somewhere in the UK. I contacted my web host and they informed me that it is a phishing scam. Please be very careful if you get one of these. One way to check is to check the headers of where the email came. My email came from Brazil. Just a heads up. |
| | |
| | |
| | #2 |
| Power-Writer/Programmer War Room Member Join Date: May 2009 Location: Eugene, OR
Posts: 515
Thanks: 78
Thanked 86 Times in 64 Posts
|
Assuming you get html email it would just be <a href="reallink">fakelink</a> - but I get so many phish attempts every day I couldn't imagine actually falling for one.
|
| | |
| | |
| | #3 | |
| Content & Copywriting Wiz War Room Member Join Date: Dec 2006 Location: Roselle, NJ, USA
Posts: 16,394
Blog Entries: 11 Thanks: 1,531
Thanked 6,192 Times in 2,288 Posts
| Quote:
HTML email made to look like text. In other words, it was totally plain. Like I said, sneaky. | |
| | ||
| | |
| | #4 |
| Power-Writer/Programmer War Room Member Join Date: May 2009 Location: Eugene, OR
Posts: 515
Thanks: 78
Thanked 86 Times in 64 Posts
|
Ah, gotcha - if it was made to look like a text email then it might trick me a little too heh
|
| | |
| | |
| | #5 | |
| Senior Warrior Member War Room Member Join Date: Mar 2003 Location: , , .
Posts: 5,430
Thanks: 274
Thanked 183 Times in 140 Posts
| Quote:
Yeah, it's very sneaky, make sure you view the code so you know. Also, you just might have been trojaned due to clicking on the link. Get yourself over to Symantec and do their online scanner asap. It's free, and it detects stuff. | |
| | ||
| | |
| | #6 |
| Senior Warrior Member War Room Member Join Date: Aug 2004 Location: United Kingdom.
Posts: 4,877
Thanks: 921
Thanked 719 Times in 318 Posts
|
I got one earlier which was a tad disturbing Dear user of the .com mailing service! We are informing you that because of the security upgrade of the mailing service your mailbox info@site.com settings were changed. In order to apply the new set of settings open zip attached file. Best regards, site Technical Support. As I own the domain and host it myself on my own server I knew it was false. But I can't even imagine how many people would open the attached file without thinking These people are getting really clever Kim |
| | |
| | |
| | #7 | |
| Banned War Room Member Join Date: Nov 2008 Location: Portugal
Posts: 1,738
Blog Entries: 209 Thanks: 104
Thanked 228 Times in 161 Posts
| Quote:
ive come across some really clever ones lately. The ones that i have nearly fallen for norton has lucky brought up. kind regards sam X | |
| | |
| | #8 | |
| SERP Elite War Room Member Join Date: Apr 2009 Location: Virginia, United States
Posts: 421
Thanks: 188
Thanked 86 Times in 27 Posts
| Quote:
<a href="www(dot)pishingwebsitelink(dot)com">http://www dot yourwebsiteslink dot com</a>? If yes, then I think I got that one a little while ago. ~George | |
| --Live SEO Challenge-- | ||
| | |
| | #9 |
| Senior Warrior Member War Room Member Join Date: Apr 2006 Location: Exeter, United Kingdom.
Posts: 1,356
Thanks: 174
Thanked 505 Times in 100 Posts
|
I got this today. I clicked on the link before realising it was a fake. I didn't enter any details and closed it straight away. No harm done, right? |
| Blog Post "50 Ways To Get More Email Subscribers" | |
| | |
| | #10 |
| Can Content be Addictive? War Room Member Join Date: Nov 2008 Location: UK
Posts: 1,037
Thanks: 159
Thanked 352 Times in 126 Posts
|
Thanks Steve. I guess this is another good reason to use the privacy option when registering domains. |
| $8,500,000,000.00 - who wants some? Click Here to find out why the Wizard Of Oz is giving away 6 brand new iPads? Genius = 99% Perspiration + 1% InspirationQED! | |
| | |
| | #11 |
| Active Warrior Join Date: Jun 2007 Location: Canada
Posts: 93
Thanks: 0
Thanked 2 Times in 2 Posts
|
There are so many things that can trick you. These two tools can fake things too! Log into your ClickBank account and place this code javascript:document.body.contentEditable=’true’; document.designMode=’on’; void 0 in your browsers url, then type in your amounts in your account, you may have to try it a few times before it will work. and this.. Make Money With Google AdSense |
| | |
| | |
| | #12 | |
| Senior Warrior Member War Room Member Join Date: Aug 2004 Location: United Kingdom.
Posts: 4,877
Thanks: 921
Thanked 719 Times in 318 Posts
|
Why are you posting this on a number of threads Quote:
| |
| | ||
| | |
| | #13 |
| Warrior Member War Room Member Join Date: Oct 2009
Posts: 10
Thanks: 1
Thanked 0 Times in 0 Posts
|
thanks 4 the info
|
| | |
| | #14 |
| Senior Warrior Member War Room Member Join Date: Aug 2004 Location: United Kingdom.
Posts: 4,877
Thanks: 921
Thanked 719 Times in 318 Posts
| |
| | |
| | |
| | #15 |
| Active Warrior Join Date: Jun 2007 Location: Canada
Posts: 93
Thanks: 0
Thanked 2 Times in 2 Posts
|
I thought i would post it twice, since it was on topic, it's slightly different, won't do that again.
|
| | |
| | |
| | #16 |
| I have a lame list. War Room Member Join Date: Jul 2008 Location: One Second into the Future
Posts: 4,256
Blog Entries: 1 Thanks: 811
Thanked 2,176 Times in 1,003 Posts
|
Looks like they're recycling golden oldies here. I saw similar attempts years ago. They'd try to pose as the Admin of a service and make it look like eMails were coming from the service itself. I've seen two variations on this current round. One sends a message with a ZIP attachment that purportedly contains the new settings file you need to install. The second provides a fake URL, as Steve described. Even though it may look like it's coming from your host (which is easy to know if you ARE the host...), there are two signs that it is not. The first is that both variations of this message address you as "Dear user of...." This is the first clue. Most services will know your name. And, few still use a bulk message that is not personalized. Even if your host were to use unpersonalized bulk messages, the second clue is in the "name" of the mailing service, which is identified as "yourdomain.dom mailing service". Most sites have a name, and don't just use the domain name. They might have yourdomain.dom, but they go by Your Domain, Inc. or something. Or, maybe YourDomain.dom Mail. Few will have no name and all lower case like that. Additionally, most hosts would probably notify you ahead of time of any server upgrades. On top of all of that, most hosts would never require you to reset or install new "settings" for your eMail. You might need to change IPs or POP/SMTP settings, but those are generally not provided in a settings file. And, even if they were, the first two clues should throw up enough of a red flag that it's not really coming from your host. Furthermore, if these settings were changed and require you to reset or install new settings, then how did you even receive the eMail telling you about that change? That should be a clue too. ![]() I disagree that these phishers and scammers are getting more clever. This message really shouldn't fool anybody. It's not even all that sneaky. Now, if they had combined a few techniques used by assorted spammers, they could have produced a more convincing message. But, as it is, it's rather sloppy. |
| Click here for the MOST FUN PRODUCT CREATION GUIDE for Procrastinators since forever. Dan's content is irregularly read by handfuls of people. Join the elite few by reading his blog: dcrBlogs.com or following him on Twitter: dcrTweets.com but NOT by Clicking Here! ----------> [Free WSO] The Lamest WSO in the History of the Warrior Forum ☺ <---------- | |
| | |
| | #17 |
| Advanced Warrior War Room Member Join Date: Aug 2008 Location: New Zealand
Posts: 713
Thanks: 79
Thanked 78 Times in 43 Posts
|
Anything that asks me for something out of the ordinary like my password or to access my account via a link because my account has been compromised I avoid like the plague. I've had at least 6 emails that claim to be from PayPal that encourage me to check my account via their link. I immediately report them to PayPal. Good thing you contacted your host directly, imagine how many people may not be so lucky. |
| | |
| | |
| | #18 |
| Active Warrior War Room Member Join Date: Sep 2009
Posts: 56
Thanks: 47
Thanked 4 Times in 4 Posts
|
Thanks for the head's up, i have been caught out before by a phising scam, so i try and be as secure as possible nowadays. too many scams |
| | |
| | #19 | |
| Senior Warrior Member War Room Member Join Date: Jan 2008 Location: Alpharetta,GA, USA.
Posts: 1,440
Thanks: 497
Thanked 199 Times in 144 Posts
| Quote:
It's oftentimes a "one-two" punch that even if your don't bite the scam, they'll try to shoot a trojan from an infected page. | |
| | |
| | #20 |
| In Search of Eternity War Room Member Join Date: Jul 2009 Location: The Earth is My Home - I love dearly
Posts: 325
Thanks: 8
Thanked 58 Times in 39 Posts
|
I use the spybot immunize function. I believe it will stop malicious attacks inside your browser. Stopping adware attaching to your browser. Plus ccleaner, windows washer,....the list goes on of programs protecting me jesus I cant keep up! |
| | |
| | |
| | #21 |
| Lookin at You.... War Room Member Join Date: May 2008 Location: Out Of My Mind - Brandy Too
Posts: 4,120
Blog Entries: 3 Thanks: 2,885
Thanked 1,344 Times in 710 Posts
|
I'm doing a little fishing next week.. Conditions are perfect for a few evenings down the lake, the carp have been really active lately ![]() Peace Jay |
|
Bare Murkage.........
| |
| | |
| | #22 | |
| Happy Hooker War Room Member Join Date: Jun 2007 Location: North of the Peace River, Southwest Florida, USA.
Posts: 7,623
Thanks: 2,685
Thanked 4,396 Times in 2,394 Posts
| Quote:
I've been getting these for several domains over the last couple of days. They claim to be from the admin, but I don't remember sending them... ![]() My wife spends hours every night surfing the net, and she's about as non-techie as you get and still go online. Fortunately, I've instilled a healthy paranoia about emails that ask her to do this kind of thing. Yes, the goons are getting sneakier all the time. Even 'legitimate' sites are beating the pop-up blockers by tying the pop to some event, like a click on a link or submit button. One night, she complained that her laptop was running really slow all of a sudden. When I took a look, she had 27 browsers running at the same time. 24 of them were ads for Netflix. | |
| Salad is not food. Salad is what food eats... -- The REAL PETA, People for Eating Tasty Animals "I did not fight my way to the top of the food chain to eat tofu!" | ||
| | |
| | #23 |
| HyperActive Warrior War Room Member Join Date: Sep 2006 Location: Washington
Posts: 280
Thanks: 128
Thanked 20 Times in 20 Posts
|
Thanks for the post Steven. I got really used to getting these when I was selling on eBay. I saw many different varieties of these and learned not to open them. I do know that anyone you are doing a legitimate business with will use your name in the email. I just don't make it a practice of opening any email I don't recognize, especially from myself as I don't email myself. |
| | |
| | |
| | #24 |
| KeywordMadness.com Join Date: Oct 2009 Location: singapore
Posts: 176
Thanks: 18
Thanked 13 Times in 12 Posts
|
Once again, You give us valuable information Steven.. I'm always registering domain protection to all my domain, hope I don't get this phising follks on my email, despite there is a lot of spam email that i don't check and delete it every day ![]() Vaan |
| | |
| | |
| | #25 |
| Ricardo Acosta War Room Member Join Date: Jul 2009 Location: Dallas
Posts: 59
Thanks: 21
Thanked 6 Times in 6 Posts
|
Yup, they do that to facebook users as well.
|
| | |
![]() |
|
| Tags |
| phishing, scam, sneaky, warning |
| Thread Tools | |
| |
![]() |