Showing posts with label email scams. Show all posts
Showing posts with label email scams. Show all posts

Wednesday, November 19, 2008

PayPal Scams and Evolutionary Pressure

We've discussed the anatomy of a typical PayPal scam email in the past, and we've analyzed other scams such as credit union member phishing. With that in mind, a recent PayPal scam email has a few little tweaks that are worth noticing.

The first thing to note is that it tells the recipient that the investigation process will take at least 12 hours, and that they recommend that you verify your account then. This means that most users won't try to log in for at least 12 hours, giving the scammer a chance to loot the account.

Second, it was interesting to see that the scammer did not use a very well concealed clickable Paypal URL - a simple mouseover points it to a site easily identified as a non-PayPal site. The most interesting part here for me was that the help link redirects to an alternate site as well - although, again a poorly concealed one.

Finally, the email spends almost a third of its length discussing what PayPal does to address scams and to prosecute fraud. This appears to be an attempt to tap into what Bruce Schneier discussed recently regarding the science of cons.

These incremental improvements - and the lack of sophistication in the links show that PayPal scam email continues to evolve and adapt, and that some of the most common tricks aren't universally used. As users become more savvy, successful scams must become more realistic, and must appear more trustworthy.

The email is reproduced below as a clickable image - click to expand:

Friday, June 13, 2008

Spear Phishing and Taxes

A co-worker of mine recently received the following spear phishing message. It was more sophisticated - or at least, far less crudely constructed than many, and included details appropriate to his actual employment.

The phone number was the individual's employer's main switchboard, and it was sent to a work email address that he uses for notification from the IRS. Forms are referenced, and document numbers that look like official government numbers are included. A perceptive user should notice that the URL is from a .com address, and of course, the headers clearly showed that the email was not from a government system.

As is common in such email, there is a threat included to make reply more likely - in this case, a bill will be sent by the government.

Department of the Treasury Date of this Notice: May 23 2008
Internal Revenue Service Letter Number 531(DO)
District Director Form: 1040

XXXXXXXX YYYYYYYY
EMPLOYER NAME
(999) 999-9999
-NOTICE OF DEFICIENCY-
Dear XXXXXXX YYYYYYY,
We have determined that you owe additional tax and other amounts, or both, for the tax year(s) identified above. This letter is your NOTICE OF DEFICIENCY, as required by law. The enclosed statement shows how we figured the deficiency. If you want to contest this determination in court before making any payment, you have 90 days from the date of this letter (150 days if addressed outside the United States) to file a petition with the United States Tax Court for a redetermination of the deficiency.

link to (www.tax-revenue.com) removed

If you decide not to sign and return the waiver, and you do not file a petition with the Tax Court within the time limit, the law requires us to assess and bill you for the deficiency after 90 days from the date of this letter (150 days if this letter is addressed to you outside the United States).

Thank you for your cooperation.
Sincerely yours,
Charles O. Rossotti
Commissioner by
Roger K. Burgess CR
District Director
Letter 531(DO)(Rev.9-96)

Monday, June 9, 2008

Here Phishy Phishy: Another Phishing Example

I've changed the original site name in this email - it is typically in capital letters, and is the domain of the user the email was sent to.

Giveaways this time? The capitalized domain, the request for password, date of birth, and country, the thank you, signature, and the warning code, as well as the headers showing a non-local email origin.

The good news is that most users won't fall for a phishing email like this - but I still see users fall for some of the more sophisticated bank and Paypal scams.

Dear YOURSITE.COM Email Account Owner,

This message is from YOURSITE.COM messaging center to all YOURSITE.COM email account
owners. We are currently upgrading our data base and e-mail account
center. We are deleting all unused YOURSITE.COM email account to create more
space for new accounts.

To prevent your account from closing, you will have to update it below so
that we will know that it's a present used account.

CONFIRM YOUR EMAIL IDENTITY BELOW

Email Username : .......... .....
EMAIL Password : ................
Date of Birth : .................
Country or Territory : ..........

Warning!!! Account owner that refuses to update his or her account within
Seven days of receiving this warning will lose his or her account
permanently.

Thank you for using YOURSITE.COM!

Warning Code:XXXXXXXXX

Thanks,
YOURSITE.COM Team
YOURSITE.COM BETA

Saturday, May 31, 2008

Anatomy of a Paypal Scam Email

I'm often asked what a typical Paypal email scam looks like. Today's email included a pretty standard sample. What should let a layman know that this is a scam?


  • The account that received the email isn't one with a PayPal account.
  • PayPal typically won't send emails with a subject like "Account limited"
  • The email is addressed to "PayPal Inc. account holder" rather than to a specific name. PayPal knows who their account holders are.
  • The URL included is not on Paypal's site (it is, however, not the real URL).
  • The email changes topic from screening that requires more information to unauthorized access.
  • The email requests that users "upgrade" their account with more information.
  • Department is misspelled in the closing greeting, and referring to the group as the "PayPal Inc. Account Departement." is suspicious.


For the more technically adept users, I recommend reading headers. Those show interesting things like:


  • A from address of "PayPal." which is "service@paypall.com" - yes, two l's.
  • A source IP that doesn't resolve to PayPal: "from 64-60-103-180.static-ip.telepacific.net (HELO User) (64.60.103.180) by ns1.4thframe.com with SMTP; 30 May 2008 14:14:13 +0200"


At this point, many anti-spam systems will have flagged the message and will have tossed it - that's lucky for us, although people do still fall for the messages.

Without further ado, the message itself:

Dear PayPal Inc. account holder,

PayPal is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience.

*Why is my account access limited?*

Your account access has been limited for the following reason(s):

We have reason to believe that your account was accessed by a third party. Because protecting the security of your account is our primary concern, we have limited access to sensitive PayPal account features. We understand that this may be an inconvenience but please understand that this temporary limitation is for your protection.

(Your case ID for this reason is PP-0XD2-0XBC-0XDA-0X37.)

*How can I restore my account access?*

*Please visit the Resolution Center and complete the "Steps
to Remove Limitations."

Completing all of the checklist items will automatically restore your account
access.

Be aware that until we can verify your identity we will have no other liability for your account or any transactions that may have occurred as a result of your failure to upgrade your account as instructed above.

Sincerely,
PayPal Inc. Account Departement.

Thursday, April 26, 2007

What's old is new again: email extortion and urban legends

Much like fashion, the Internet makes old things new again at a startling pace. Dark Reading is carrying an article courtesy of Information Week about a "new" email scam - assassins have been hired to kill you, and if you bribe them, they won't. Unfortunately...this isn't really a new scam. In fact, Snopes has references back to 2006, and an FBI recommendation from December of 2006 - which the article does note. What is newer is that the mailing lists harvested for it seem to target professionals. Not quite spearphishing, but definitely more targeted than your daily allotment of prescription drug and enhancement spam.

Moral of the story? Keep Snopes, ScamBusters, and the CIAC's Hoaxbusters sites handy, and don't panic. If you do know somebody who has succumbed to the scam, point them to law enforcement and the Internet Crime Complaint Center (IC3).