register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

eBay- 'eBay: Account Violate User Agreement'
07-Mar-2005

Summary
Email title: 'eBay: Account Violate User Agreement'
Scam target: eBay members
Sender:

eBay <eBay@ebay.com>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's eBay and Paypal username/password, credit card and bank account information, personal information
Phish link method a 'Click here' type link
Link 'masked'? Yes
Visible link: 'click here'
Actual link to: http://218.154.123.224/signin.ebay.com/ws/eBayISAPI.dllSignIn&favoritenav...(truncated)
Phish website IP: 218.154.123.224
 
Overview
 
A pretty basic phish, nice email design.
 
E-mail
 
What sets this one apart is the email design - it is made to look as an eBay page:
 
 
Along with the spoofed sender, this would look OK enough to click the link, for many people.
 
Web Site
Visible link: 'click here'
Actual link to: http://218.154.123.224/signin.ebay.com/ws/eBayISAPI.dllSignIn&favoritenav...(truncated)
Phish website IP: 218.154.123.224
 
The first important thing to be noticed when the site opens up is the URL in the address bar - the domain (the IP address) is clearly not ebay.com, despite the URL reminds of an eBay page after the domain name:
 
 
The site itself asks for quite a lot of information, does not have neither a login page, nor a security certificate - all these are strong clues of phishing:
 
 
It is hosted on a server in Korea:
 
WHOIS data (for IP 218.154.123.224) :

IP Location: Korea, Republic Of - Kornet
inetnum: 218.144.0.0 - 218.159.255.255
netname: KORNET
descr: KOREA TELECOM
descr: Network Management Center
country: KR
admin-c: DL248-AP
tech-c: GK40-AP
mnt-by: MNT-KRNIC-AP
mnt-lower: MNT-KRNIC-AP
changed: 20010924
status: ALLOCATED PORTABLE
changed: 20041007
source: APNIC

person: Dong-Joo Lee
address: 128-9 Yeong-Dong Jongro-Ku Seoul
address: Network Management Center
country: KR
phone: +82-2-766-1407
fax-no: +82-2-766-6008
nic-hdl: DL248-AP
mnt-by: MAINT-NEW
changed: 20010425
source: APNIC

person: Gyung-Jun Kim
address: KORNET
address: 128-9, Yeong-Dong, Jongro-Ku
address: SEOUL
address: 110-763
country: KR
phone: +82-2-747-9213
fax-no: +82-2-3673-5452
nic-hdl: GK40-AP
mnt-by: MNT-KRNIC-AP
changed: 20010906
source: APNIC

inetnum: 218.154.123.0 - 218.154.123.255
netname: KORNET-HOTLINE2003293068-KR
descr: youngnamjebun
descr: jeonsansil youngnamjebun ho 0007 beonji 0598 daeyeun3dong namku
descr: PUSAN
descr: 608-023
country: KR
admin-c: JB1466-KR
tech-c: JB1467-KR
mnt-by: MNT-KRNIC-AP
changed: 20050222
source: KRNIC

person: juseong bak
descr: youngnamjebun
descr: jeonsansil youngnamjebun ho 0007 beonji 0598 daeyeun3dong namku
descr: PUSAN
descr: 608-023
country: KR
phone: +82-51-628-7231
nic-hdl: JB1466-KR
mnt-by: MNT-KRNIC-AP
changed: 20050222
source: KRNIC

person: juseong bak
descr: youngnamjebun
descr: jeonsansil youngnamjebun ho 0007 beonji 0598 daeyeun3dong namku
descr: PUSAN
descr: 608-023
country: KR
phone: +82-51-628-7231
nic-hdl: JB1467-KR
mnt-by: MNT-KRNIC-AP
changed: 20050222
source: KRNIC