PDA

View Full Version : New Email Scam


Yahweh
27th August 2005, 09:47 AM
I got this in my mailbox today:
From : Westernunion Billing Department team <update@westernunion.com>
Sent : Saturday, August 27, 2005 10:29 AM
To : fstdt@hotmail.com
Subject : WesternUnion® Account Info


Dear westernunion customer,
During our regularly scheduled account maintenance and verification procedures, we have detected a slight error in your account information.
This might be due to either of the following reasons:
1. A recent change in your personal information ( i.e. change of address).
2. Submitting invalid information during the initial sign up process.


Please update and verify your information by clicking the link below:
https://wumt.westernunion.com/asp/regLogin.asp


If your account information is not updated within 48 hours then your ability to Receive or transfer Money On westernunion will become restricted.


Thank You For Chooseing Westernunion as Trusted Money Transfer
The Westernunion Billing Department
If you get this email, DONT RESPOND TO IT. Its a scam.

The link provided in the email is a spoofed URL of "http://westernunion.com.fifefootball.co.uk/securelogin/cgi-update/regPersonalInfo.htm". Notice "fifefootball", and the "co.uk" extension.

I have no accounts with WesternUnion, nor does anyone in my family.

I would like to refer the scam site to the relevant authorities. If this information is relevant, here is what I gathered from a simple WHOIS search:

Fifefootball.co.uk gave me the WHOIS following information:
[whois.melbourneit.com]

Melbourneit.com gave me the WHOIS following information:
Domain Name.......... melbourneit.com
Creation Date........ 1999-04-05
Registration Date.... 2000-05-23
Expiry Date.......... 2013-04-05
Organisation Name.... Melbourne IT Ltd
Organisation Address. Level 2, 120 King Street
Organisation Address.
Organisation Address. Melbourne
Organisation Address. 3000
Organisation Address. Vic
Organisation Address. AUSTRALIA

Admin Name........... Account Manager
Admin Address........ Level 2, 120 King Street
Admin Address........
Admin Address........ Melbourne
Admin Address........ 3000
Admin Address........ Vic
Admin Address........ AUSTRALIA
Admin Email.......... cdm@melbourneit.com
Admin Phone.......... +61.386242465
Admin Fax............

Tech Name............ Account Manager
Tech Address......... Level 2, 120 King Street
Tech Address.........
Tech Address......... Melbourne
Tech Address......... 3000
Tech Address......... Vic
Tech Address......... AUSTRALIA
Tech Email........... cdm@melbourneit.com
Tech Phone........... +61.386242465
Tech Fax.............
Name Server.......... ns1.melbourneit.com
Name Server.......... ns2.melbourneit.com

geni
27th August 2005, 09:53 AM
pilshing is hardly new

Fizzer
28th August 2005, 12:08 PM
Or do what Robert Cringely suggests and bury the phishers in false data: http://www.pbs.org/cringely/pulpit/pulpit20050602.html

kevin
28th August 2005, 04:30 PM
[QUOTE]Originally posted by Yahweh
Fifefootball.co.uk gave me the WHOIS following information:
[whois.melbourneit.com]

Melbourneit.com gave me the WHOIS following information:


Your reading the whois information incorrectly. The first whois you did returned whois.melbourneit.com because that is who the registrar for the domain is and you have to use their whois search to find info on the original domain.

Melbourneit.com has nothing to do with this scam other than being the registrar for the domain.

The actual whois info for fifefootball.co.uk is:

Domain Name:
fifefootball.co.uk

Registrant:
James Murray

Administrative Contact's Address:
201 Lamond Drive
St Andrews
Fife
United Kingdom
KY16 8JP

Registrant's Agent:
Fasthosts Internet Limited [Tag = FASTHOSTS]
URL: http://www.fasthosts.co.uk

Relevant Dates:
Registered on: 17-Feb-2001
Renewal Date: 17-Feb-2007
Last updated: 02-Feb-2005

Registration Status:
Registered until renewal date.

Name servers listed in order:
ns1.bargainhosts.co.uk 80.71.3.131
ns2.bargainhosts.co.uk 80.71.2.100

WHOIS database last updated at 00:20:01 29-Aug-2005


However even this isn't a sign of nogoodness by fifefootball. It could be their web server was compromised to be used in this phishing attack and evade detection by the police.

Best policy would be to notify fifefootball's host (fasthosts.co.uk) and fifefootball directly.

CurtC
29th August 2005, 08:25 AM
This is news? I get several of these phishing emails every single day.

One thing you may want to do is set your email reader to display messages as plain text instead of HTML. That way, they can't hide the real URL under different text for it. If someone sends me one of these messages, I would see the fifefootball.co.uk domain right there in the message, and would know not to click on it.