Anti-Phishing Working Group
   
 
 


Home

Phishing Archive

Report Phishing

Events

APWG News

Resources

Membership

APWG Member Site

Contact Us

APWG Sponsors:

eBay - "FPA NOTICE: possibble account access by a third party"
22-Mar-2004

Summary
Email title: "FPA NOTICE: possibble account access by a third party"
Scam target: eBay users
Email format: HTML e-mail
Sender:

aw-conflrm@ebay.com

Sender spoofed? No
Scam call to action: "if you are the rightful holder of the account, click on the
link below, fill the form and then submit as we try to verify your identity"
Scam goal: Getting victim's Ebay account, credit card, address and SSN information
Call to action format: HTML form on a website
Visible link: http://cgi3.ebay.com//aw-cgi/eBayISAPI.dll?VerifyIdentity
Called link :

http://66.206.7.193/scgi-bin/eBayISAPIdentityXVERified1.html

Website: http://66.206.7.193/scgi-bin/eBayISAPIdentityXVERified1.html
 
E-mail
  • The email does not have an eBay logo on it, and threatens the recipient, which should arouse suspicion
  • The email is also not personalized, which is suspicious
 
Web Site
Visible link: http://cgi3.ebay.com//aw-cgi/eBayISAPI.dll?VerifyIdentity
Called link :

http://66.206.7.193/scgi-bin/eBayISAPIdentityXVERified1.html

Resolved URL:

http://66.206.7.193/scgi-bin/eBayISAPIdentityXVERified1.html

WHOIS Data :

OrgName: Cyber World Internet Services

Address: 12402 N. Division St. #240
City: Spokane
StateProv: WA
PostalCode: 99218
Country: US

  • When you click the spoofed link, the site below opens. It demands a whole lot of information form you. But the most tell-tale sign of phishing is the URL that opens. It is not on eBay.com, but on an IP without a name.
 

About Us | Contact Us