Author Topic: Best phishing ever!  (Read 3856 times)

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Best phishing ever!
« on: December 31, 2015, 03:00:48 AM »
I have never seen such a good phisher with such clean and clear information. No spelling mistakes and (basically) no glitches.
I have been raped, of my CSP credit card number.
Yes I have many different email accounts. This email came to the account I use exclusively for sensitive  info (ie banking, government logins, ect). I NEVER get spam to this account.
A) after entering my email I hit "login" by mistake and it "logged me in" but I figured chrome must have filled the password and I just didn't realize the yellowed selector.
B) after "verifying" my address I was asked for my credit card info and then the next screen was for bank account info and something called a swift number. That must be some European verification process but that's what triggered my concern. (Never trust the Europeans :P).
So I took the website address (also quite professional), striped it down and checked whois...

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Best phishing ever!
« Reply #1 on: December 31, 2015, 03:02:53 AM »
Here's the whois page and you can see the account was created today...

BEWARE!

Offline Work-for-ur-muny

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Dec 2014
  • Posts: 3099
  • Total likes: 327
  • DansDeals.com Hat Tips 34
    • View Profile
Re: Best phishing ever!
« Reply #2 on: December 31, 2015, 03:08:04 AM »
I have never seen such a good phisher with such clean and clear information. No spelling mistakes and (basically) no glitches.
I have been raped, of my CSP credit card number.
Yes I have many different email accounts. This email came to the account I use exclusively for sensitive  info (ie banking, government logins, ect). I NEVER get spam to this account.
A) after entering my email I hit "login" by mistake and it "logged me in" but I figured chrome must have filled the password and I just didn't realize the yellowed selector.
B) after "verifying" my address I was asked for my credit card info and then the next screen was for bank account info and something called a swift number. That must be some European verification process but that's what triggered my concern. (Never trust the Europeans :P).
So I took the website address (also quite professional), striped it down and checked whois...
How did you even get there? IOW, what do I have to watch from?

Offline Freddie

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Apr 2013
  • Posts: 3236
  • Total likes: 308
  • DansDeals.com Hat Tips 1
    • View Profile
  • Location: Pittsburgh
Re: Best phishing ever!
« Reply #3 on: December 31, 2015, 03:11:10 AM »
How did you even get there? IOW, what do I have to watch from?
An email from paypal asking you to log in and update information.

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Best phishing ever!
« Reply #4 on: December 31, 2015, 03:15:45 AM »
How did you even get there? IOW, what do I have to watch from?
How did I get where? I clicked the link that didn't arouse any concern.
I guess you gotta be very keen and more suspicious as the "other-side" is getting better and better.

Offline Work-for-ur-muny

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Dec 2014
  • Posts: 3099
  • Total likes: 327
  • DansDeals.com Hat Tips 34
    • View Profile
Re: Best phishing ever!
« Reply #5 on: December 31, 2015, 03:47:04 AM »
How did I get where? I clicked the link that didn't arouse any concern.
I guess you gotta be very keen and more suspicious as the "other-side" is getting better and better.
You're saying that you got an authentic-looking email from PayPal which contained malicious links?

BTW On your second post of the whois page, the site does look amateurish as many letters that should be capitalized (names, states etc.) are not. Something that a legit site would never have. But by the time you get to see that it may be too late.

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Best phishing ever!
« Reply #6 on: December 31, 2015, 03:54:06 AM »


You're saying that you got an authentic-looking email from PayPal which contained malicious links?

BTW On your second post of the whois page, the site does look amateurish as many letters that should be capitalized (names, states etc.) are not. Something that a legit site would never have. But by the time you get to see that it may be too late.

I hear ya. I usually use the "created on" date. And yes, by the time you're at the whois page it is usually too late.

Offline Aussie88

  • Dansdeals Gold Elite
  • ***
  • Join Date: Jun 2013
  • Posts: 231
  • Total likes: 15
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Where the sun is (almost) always shining
Re: Best phishing ever!
« Reply #7 on: December 31, 2015, 09:04:49 AM »
Ouch. I get spoof PayPal emails pretty much daily, and I'll admit that's one of the best I've seen.

Legit PayPal emails will <b>always</b> have your full name on it. It will say "Dear Joe Shmoe" and then will go on to explain the issue.

Offline dudi

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2013
  • Posts: 1627
  • Total likes: 5
  • DansDeals.com Hat Tips 10
    • View Profile
  • Programs: Star Alliance Gold, Skyteam Elite Plus
Re: Best phishing ever!
« Reply #8 on: December 31, 2015, 09:14:12 AM »
Wow. May be a good idea to report the name of the person registered

Offline Centro

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: May 2012
  • Posts: 2942
  • Total likes: 8
  • DansDeals.com Hat Tips 33
  • Gender: Male
    • View Profile
Re: Best phishing ever!
« Reply #9 on: December 31, 2015, 09:17:07 AM »
How is it possible for them to have paypal.com as their Web address, is it because there's no slash after the .com?

Offline aeman1

  • Dansdeals Silver Elite
  • **
  • Join Date: Dec 2014
  • Posts: 54
  • Total likes: 0
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: new york
Re: Best phishing ever!
« Reply #10 on: December 31, 2015, 09:21:44 AM »
PayPal emails always have your full name.  Report to paypal as well.

Offline JoeyShmoe

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1286
  • Total likes: 254
  • DansDeals.com Hat Tips 0
  • Gender: Male
    • View Profile
  • Location: Lakewood
Re: Best phishing ever!
« Reply #11 on: December 31, 2015, 10:55:32 AM »
How is it possible for them to have paypal.com as their Web address, is it because there's no slash after the .com?
That's the trick, it isn't a paypal.com address, it's a account-premier.info web address with a subdomain of paypal.com, so paypal.com.account-premier.info
DDF A-Z Link Extension
Chrome
Firefox
Info

Offline MeirS

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Jun 2013
  • Posts: 2555
  • Total likes: 193
  • DansDeals.com Hat Tips 1
    • View Profile
Re: Best phishing ever!
« Reply #12 on: December 31, 2015, 11:15:48 AM »
I have never seen such a good phisher with such clean and clear information. No spelling mistakes and (basically) no glitches.
I have been raped, of my CSP credit card number.
Yes I have many different email accounts. This email came to the account I use exclusively for sensitive  info (ie banking, government logins, ect). I NEVER get spam to this account.
A) after entering my email I hit "login" by mistake and it "logged me in" but I figured chrome must have filled the password and I just didn't realize the yellowed selector.
B) after "verifying" my address I was asked for my credit card info and then the next screen was for bank account info and something called a swift number. That must be some European verification process but that's what triggered my concern. (Never trust the Europeans :P).
So I took the website address (also quite professional), striped it down and checked whois...
I always check the email address of the sender first. What was it here?

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 158
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: Best phishing ever!
« Reply #13 on: December 31, 2015, 11:17:31 AM »
OP, please forward the entire email to spoof@paypal.com

Offline lubaby

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2010
  • Posts: 5386
  • Total likes: 736
  • DansDeals.com Hat Tips 12
    • View Profile
Re: Best phishing ever!
« Reply #14 on: December 31, 2015, 11:27:37 AM »
How is it possible for them to have paypal.com as their Web address, is it because there's no slash after the .com?
The domain there is not Paypal.com.
The domain name is account-premier.info.
WHOIS Record.

Read more about domain structuring here.
Quote
Subdomain Names with Dots
Although I said that you cannot buy a domain name with embedded dots, you can still create a domain name where there are embedded dots. For example, if you were to look up at your web browser's address bar right now, you will notice that this site has a web address of "www.thesitewizard.com", where there is a dot separating "www" from my main domain name "thesitewizard.com". Since I own the domain called "thesitewizard.com", I can create any number of web addresses ending with ".thesitewizard.com" that I want. These new addresses, like "www.thesitewizard.com", are often referred to as subdomains. They are subdomains of my main domain, thesitewizard.com.

As such, even though you cannot buy a domain name like "this.is.an.example.com", nothing stops you from buying a domain called "example.com" (unless it's already taken), and then creating a subdomain name called "this.is.an.example.com". Once you own the main domain name, you can create any subdomain of that domain that you want.

AVG caught a Phish.
« Last Edit: December 31, 2015, 11:34:27 AM by lubaby »

Offline yuneeq

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jan 2013
  • Posts: 8880
  • Total likes: 4047
  • DansDeals.com Hat Tips 10
  • Gender: Male
    • View Profile
  • Location: NJ
Re: Best phishing ever!
« Reply #15 on: December 31, 2015, 12:15:48 PM »
It's kinda obvious already from the email.

-PayPal always capitalizes the 2 P's.
-The Help at the bottom is not formatted properly.
-"Now, Please resolve Your account" makes it obvious again.
-PayPal is NEVER kind in their emails, they would never ever use that kind and friendly tone.
-Too late now, but when ANYONE emails for you to change or update your account information, you should ALWAYS check the senders email address carefully. Even better would be to login to your account by typing it in the URL bar, not by following any links.
Visibly Jewish

Offline tageed-lee

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Aug 2012
  • Posts: 1589
  • Total likes: 129
  • DansDeals.com Hat Tips 73
    • View Profile
Re: Best phishing ever!
« Reply #16 on: December 31, 2015, 12:22:29 PM »
Even better would be to login to your account by typing it in the URL bar, not by following any links.

That is my motto for all "link related things" online..

I never trust links when you could just go to their site direct...

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Best phishing ever!
« Reply #17 on: December 31, 2015, 01:40:53 PM »
Wow. May be a good idea to report the name of the person registered
Doubt its a real name.


PayPal emails always have your full name.  Report to paypal as well.
OP, please forward the entire email to spoof@paypal.com
Done that. Thanx though


I always check the email address of the sender first. What was it here?
PayPal."something".com
« Last Edit: December 31, 2015, 01:49:35 PM by SLMYRCB »

Offline SLMYRCB

  • Dansdeals Platinum Elite + Lifetime Silver Elite
  • *****
  • Join Date: Oct 2014
  • Posts: 720
  • Total likes: 7
  • DansDeals.com Hat Tips 0
    • View Profile
Re: Best phishing ever!
« Reply #18 on: January 05, 2016, 04:28:38 AM »
The End.

Offline Work-for-ur-muny

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Dec 2014
  • Posts: 3099
  • Total likes: 327
  • DansDeals.com Hat Tips 34
    • View Profile
Re: Best phishing ever!
« Reply #19 on: January 05, 2016, 02:45:04 PM »