register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Paypal- 'Unauthorized Account Access'
10-May-2005

Summary
Email title: 'Unauthorized Account Access [Routing Code: <some bogus 'code' here>]'
Scam target: Paypal users
Sender:

PayPal <service@paypal.com>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's credit card information, bank account information, various other personal information
Phish link method: URL link
Link 'masked'? Yes
Visible link: https://www.paypal.com/us/cgi-bin/webscr? cmd=_login-run
Actual link to: http://218.246.224.203/icons/.cgi-bin/paypal/cgi-bin/webscrcmd_login.php
Phish site IP:

218.246.224.203

 
Analysis contributed by: Tumbleweed Communications - Message Protection Lab
 
Overview
 
 
 
E-mail
 
The email has two visible phishing signs - a very strange 'greeting' at the begining, and a random characters string, presented as 'PayPal Email ID' at the end:
 
 
Web Site
Visible link: https://www.paypal.com/us/cgi-bin/webscr? cmd=_login-run
Actual link to: http://218.246.224.203/icons/.cgi-bin/paypal/cgi-bin/webscrcmd_login.php
Phish site IP:

218.246.224.203

 
The phishing site loads up an address bar spoof and a mirror of the legitimate paypal.com secure login page. Yet, the missing lock icon indicates an insecure page:
 
 
Furthermore, the true URL of the site can be seen in the 'Properties' page:
 
 
As mentioned, this scam uses entire 3 sequential pages, asking for personal information. The same clues seen on the first page remain visible:
 
 
The site does check the CC number entered, using a publicly available formula. This is usually only a preliminary check, that does not require a conection to a CC server. It will, however, refuse a random bogus number, and the following window will pop-up:
 
 

This could strenghten the potential victim's belief in the legitimacy of the site.

Two more pages, demandig personal information follow up:

 
 
And this one:
 
 
At the end, a pseudo-logout page is displayed, featuring the username entered (a bogus one in this case). The address bar spoof is not removed, until some of the links on the site (leading to the legitimate PayPal page) are clicked:
 
 
The server with the phishing site is located in China:
 
WHOIS data (for IP 218.246.224.203) :

Record Type: IP Address
IP Location: China - Uf Network Information Service Co. Ltd

% [whois.apnic.net node-1]
% Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

inetnum: 218.246.224.0 - 218.246.239.255
netname: UNFnet
country: CN
descr: UF Network Information Service Co.,LTD
descr: Number 48, Fanyu Road, Shanghai
admin-c: XX81-AP
tech-c: SH221-AP
status: ASSIGNED NON-PORTABLE
changed: 20041109
mnt-by: MAINT-CNNIC-AP
source: APNIC

person: Xu Xin
nic-hdl: XX81-AP
address: Number 48, Fanyu Road, Shanghai
phone: +86-021-52300023-420
fax-no: +86-21-52300052
country: CN
changed: 20041109
mnt-by: MAINT-CNNIC-AP
source: APNIC

person: Su HongJi
nic-hdl: SH221-AP
address: Number 48, Fanyu Road, Shanghai
phone: +86-021-52300023-420
fax-no: +86-21-52300052
country: CN
changed: 20041109
mnt-by: MAINT-CNNIC-AP
source: APNIC