register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

MSN - 'Your membership will be cancelled'
25-Oct-2004

Summary
Email title: 'Your membership will be cancelled'
Scam target: MSN users
Email format: HTML email
Sender:

MSNPay@MSN.com

Sender spoofed? No
Scam call to action: 'During one of our regular automated verification procedures we've encountered a trouble caused by the fact that we could not verify the data that you provided to us...To verify your data please follow this link...'
Scam goal: Getting victim's credit card information, contact information (name, address, phone number, etc.)
Call to action format:

URL link

Visible link: 'https://start.msnupdating.info/track?billing'
Called link :

'http://www.msnupdating.info/?', followed by the victim's e-mail address

Phish website IP: 66.218.79.147
 
E-mail
 
This is pretty much a straightforward phish. The email is quite threatening - it tries to scare you into clicking the link, basically. The sender, though it is MSN.com, is most probably not spoofed, because this domain name has a freely available webmail extension.
 
 
The shortness (not as much as the common legal stuff as in a legitimate message) and the lack of some kind of logo or nicer design could spark your suspicion even at this stage.
 
Web Site
Visible link: 'https://start.msnupdating.info/track?billing'
Called link :

'http://www.msnupdating.info/?', followed by the victim's e-mail address

Phish website IP: 66.218.79.147
 
The phish site does look like a MSN page. The URL is chosen in a way that it could be deceptive to as more potential victims as possible (the email address at the end was removed):
 
 
As you can see, the site does not require a login, neither it is a really secure site (the link was to a https site, but the URL in the address bar starts with http, and there is no lock icon in the bottom right corner of the status bar). It is unlikely that a legitimate institution will demand your personal information sent via an insecured site.
 
Phish server WHOIS information:
WHOIS data (for IP 66.218.79.147)

Address: 66.218.79.147
Domain ID:D7810473-LRMS
Domain Name:MSNUPDATING.INFO
Created On:24-Oct-2004 14:07:45 UTC
Expiration Date:24-Oct-2005 14:07:45 UTC
Sponsoring Registrar:R141-LRMS
Status:ACTIVE
Status:OK
Registrant ID:C7164078-LRMS
Registrant Name:David Fouse
Registrant Organization:David Fouse
Registrant Street1:603 N, commerce
Registrant City:Gilman
Registrant State/Province:IL
Registrant Postal Code:60938
Registrant Country:US
Registrant Phone:+1.8152658102
Registrant Email:davidsunrise7@yahoo.com

Name Server:YNS1.YAHOO.COM
Name Server:YNS2.YAHOO.COM