Thursday, 12 June 2008

NatWest Important Security Notice

A quick count up and over 25% of the phishing emails posted to this blog are aimed at the NatWest, and I don't publish them all - some that are too similar when I'm too busy get deleted rather than posted. Not very helpful, but time isn't always on my side...

So it's not surprising that here's another Natwest phishing email, received by me twice in different email boxes. These are the people that list a dozen or so names in the to: field to send the email to all of those at once. Not very convincing...

The link is harder to cut & paste as it's behind a graphic, but retyping it, it goes something like http://www1.nwolb.com.jgnvvhx742.com/default.aspx etc. Once more, jgnvvhx742.com does appear in a couple of phishing results on Google.

Here's the content.

National Westminster Bank has been receiving complaints from our customers for unauthorised use of the Natwest Online accounts. As a result we periodically review Natwest Online Accounts and temporarily restrict access of those accounts which we think are vunerable to the unauthorised use.

This message has been sent to you from National Westminster Bank because we have noticed invalid login attempts into your account, due to this we are temporarily limiting and restricting your account access until we confirm your identity.

To confirm your identity and remove your account limitation please following the link below.

National Westminster Bank is committed to ensure the safeguard of each customer's personal information, making sure only authorised individuals have access to their accounts. It is all about your security.

Accounts Management As outlined in our User Agreement, Natwest will
periodically send you information about site changes and enhancements.

Visit our Privacy Policy and User Agreement if you have any questions.
http://www.Natwest.com/help/index.jhtml

Natwest | Details confirmation

Does a day go by without this lot sending an email targeted at the poor Natwest??? There's plenty of variations of this about with the referer id / cookie id in the link.

The actual destination of the link points to http://www.natwest.co.uk.harvioe.name/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]. harvioe.name appears in a couple of phishing results in Google. Here's the content...

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]

Natwest Customer Service


ref l-cmr

Problems with account Abbey’s Business Bank

Here's a new one. I've not seen this content before and it's targeted at Abbey, who do appear occasionally. The difference is that this time it's targeted at their business division.

The link actually goes to http://ibank.anbusiness.servlet.logonservlet.signon.passcode09u5d125a87hn1j.discover.ceo89u6kj811.business.portal06460.required.4598ry.com/LogonServlet.htm - presumably that complicated setup of subdirectories is to try to bury the actual website name of "4598ry.com", which doesn't yet feature in any Google results (give me a short while...).

I have never seen any genuine emails from Abbey, I can only assume they don't actually send any (which in my opinion is good). It does look like a genuine (rushed)email, but it's sent to a random account and I'm sure they wouldn't introduce themselves with "Dear Abbey's Business Bank Account Customer". I'm not even sure that is proper English (why the "'s"?).

Don't touch the email, here's the content:

Dear Abbey's Business Bank Account Customer:

Due to the emergency situation with security server, Abbey's Business Service is presently
verifying your web browsers and ip address.
In order to check your security level on a website, please follow the instructions below.

IMPORTANT! Customers must validate personal information today.

Continue>>

This situation involves circumstances outside of our control, so we ask for your patience.
We will keep you advised as the situation changes.

Abbey's Business Bank - Complete Solutions to protect your business and secure your computer.
Thank you.
2008 All Rights Reserved Abbey's Business Bank


ref i-cmr

You've received a question about eBay item: BRAND NEW GENUINE APPLE *iPod touch* 16GB 16 GB WIFI (170227727186)

Another realistic looking email question about email, but intent on robbing your security details. I'm not sure how much damage can be done by getting hold of Ebay details - I thought that Ebay didn't store any personal information, but maybe there are addresses there or they are assuming a lot of people will use the same password for PayPal...

Like other recent phishing emails, this one uses an IP address to hide the fact that it's the wrong URL: http://66.206.18.94/index.htm. But that doesn't make it any safer. Here's the email content...

Hi, I will send you the item today via "Royal Mail Sameday".

Have a nice day!
Scott

-saabman1970 Respond to this question

If you use My Messages to respond, your email address will not be shared.

Item and user details
Item Title: BRAND NEW GENUINE APPLE *iPod touch* 16GB 16 GB WIFI
Item Number: 170227727186
Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&item=170227727186
End Date: 11-Jun-08 01:11:32 BST
From User: asmdirect1 ( 16657 )
98.7 % Positive
since 18-Nov-03 in United Kingdom


ref i-cmr

Tuesday, 10 June 2008

NatWest Bank: Online Banking Form! (Mon, 09 Jun 2008 00:27:48 -0500)

Would the day be complete with also being able to post about another Natwest Customer Form! This looks word for word the same as last time, just the sent to a different recipient email address and a different URL.

The URL this time is http://www.natwest.co.uk.richardjacob.co.uk/serverstack/usersdirectory/ncf.aspx?pc==[removed]&id=[removed] and like today's earlier post, there's nothing on Google about richardjacob.co.uk, so I can't say anything about the site.

Here's the content:

Dear customer of NatWest bank,

We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.
Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.

To complete the form, please use the link below:

Natwest Customer Form

This should take you directly to the Natwest Customer Form.

Sincerely,
Natwest Customer Service


ref i-cmr
It's the old referer id / cookie id natwest phishing emails again. This time the URL is http://www.natwest.com.eloriid.com/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]. I can't find any results for eloriid.com, so no idea what is going on there. Maybe it's newly registered.

Here's the content:

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.natwest.com/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]

Natwest Customer Service

NatWest Online Accounts Limited Access

Here's a new looking phishing email, targeted at an old favourite - the NatWest. As frequently happens, the email is a little confusing. I'm never sure whether this reflects the sender's grasp of English or is intentional, so that the recipient doesn't bother too much about what the email says and instead follows the phishing link to see what's going on.

This one first talks about regular screening, then suspicious ativity then finally limitations. But, there's loads of pointers to the unwary that it is phishing:

1 - 'Dear NatWest customer' - a bank should email you by name so you know the email is more likely to be for real

2 - it's sent to undisclosed-recipients - why hide the recipient's email address? Because the one email is going to thousands of addresses. If it were genuine, it would go to just the one.

3 - I'm certain the natwest would never send you to a link http://www.swsme.net/auth/login.aspx to sign on! It would always be to their own site, even if you were later redirected. You can see the URL by placing the mouse over the link, but not clicking. swsme.net does appear in a few results, with the comment from Google 'This site may harm your computer.'. So it's probably not a very good site to visit!

Here's the content.

Dear NatWest customer,

NatWest is constantly working to ensure security by regularly screening the accounts in our system. We recently reviewed your account, and we need more information to help us provide you with secure service. Until we can collect this information, your access to sensitive account features will be limited. We would like to restore your access as soon as possible, and we apologize for the inconvenience.

--------------------------------------------------------------------------------
Why is my account access limited?

Your account access has been limited for the following reason(s):

Jun. 9, 2008: We have detected suspicious activity regarding the receipt or withdrawal of funds.

(Your case ID for this reason is NW-682-258-517.)

--------------------------------------------------------------------------------
How can I restore my account access?

Please Click Here to Log In to your account and complete the "Steps to Remove Limitations."

Once you complete all of the checklist items, your case will be reviewed by one of our Account Specialists. We will send you an email with the outcome of the review.

Copyright © National Westminster Bank plc, NatWest UK, 2008.

Friday, 6 June 2008

WINNINING NOTICATION

Another amazing $2m winning lottery ticket, for a lottery I've never entered... This one even has a realistic, if not genuine, address at the top of it.

It is strange that they want me to reply in 7 days to a draw that took place 4 and a half months ago! Seems that the scammers haven't checked their email carefully enough! Also, if it was genuine, why a Yahoo email address!

Don't touch it if you have also received this email - it's nothing more than a scam. It does amuse me that there are adverts at the bottom of the email.

UK National lottery
3b Olympic Way, Sefton Business Park,
Aintree,Liverpool , L30 1RD
REF N? UKL/74-A0802742007
BATCHNO:LTBK00018
TICKET NO:A669340221
WINNING NUMBER:7041

DearWinner,

This is to inform you that you have been selected for a cash prize of
(US$2,000,000.00 ) held on 24th of January 2008. The selection process
was carried out through random selection in our computerized email
selection system from a database of over 250,000 email addresses drawn from which
you were selected.
To file your claims please contactour claims processing department for
clearance procedures.
Mr. James Nichson(Claim Agent)
International claim Department,UK
Email:drclaravein@yahoo.com


You are advised to provide thebelow informations for final claim inspection.

FULLNAME:...........................
ADDRESS-----------------------------
SEX:......................................
AGE.......................................
NATIONALITY.........................
OCCUPATION.........................
PHONE..................................
FAX:--------------------------------------
BATCHNUMBER:------------------
TICKET NUMBER: ----------------
WINNINGNUMBER:--------------

You have to contact your claim agent before 7 working days
Yours faithfully,
Mrs Mary James
Online coordinator for
UK NATIONAL LOTTERY

Now book your Railway Tickets by cash at Sify Iway. For more details contact our Customer Care

Watch latest movie trailers and behind the scenes footage of Bigg Boss and much more! www.sifymax.com

Wednesday, 4 June 2008

You've received a question about eBay item: HP COMPAQ N400C LAPTOP 850MHZ 256MB 20GB CD WINDOWS.. (160246121318)

Another Ebay one, trying to convince the recipient that you have been bidding on a laptop that you didn't really want... For this one the destination URL is http://4u2gifts.com/eindex.htm?ViewItem&item=160246121318&ssPageName=ADME:X:AAQ:GB:1123.4www.u2gifts.com looks like a respectable website that has been 'invaded' by the phishers - there are other phishing reports dating back to at least 1st June on Google. So I suspect someone has guessed their ftp passwords...

Here's the email content:

From: eBay Member: asmdirect1

Your question from an eBay member

Do not respond to the sender if this message requests that you complete the transaction outside of eBay. This type of offer is against eBay policy, may be fraudulent, and is not covered by buyer protection programs. Learn More .

Hello, how do you intend to pay, PayPal or Bank Transfer?
Let me know a.s.a.p. please.

Jamie

Thanks.


- asmdirect1 Respond to this question

If you use My Messages to respond, your email address will not be shared.


Item and user details
Item Title: HP COMPAQ N400C LAPTOP 850MHZ 256MB 20GB CD WINDOWS..
Item Number: 160246121318
Item URL: http://cgi.ebay.co.uk/ws/eBayISAPI.dll?ViewItem&item=160246121318
End Date: 03-Jun-08 09:00:00 BST
From User: asmdirect1 ( 4093 )
97.4 % Positive
since 10-May-02 in United Kingdom


ref i-cmr

Tuesday, 3 June 2008

Anglo Irish Bank customer:1 new ALERT message.

This one is very similar to yesterday's Anglo Irish Bank phishing email. The target URL is still http://72.214.45.5/~admin/.cgi/, so I assume the scam is yet to be shut down. Here's the content.

Dear customer for Anglo Irish Bank,

You have 1 new security message
Please login to your Anglo Irish Bank
and visit the Message Center section in order to read the message.

To Login, fast in your account:

Anglo Irish Bank Online

© 2008 Anglo Irish Bank. All rights reserved

NatWest Bank Reminder: Client Details Confirmation -Mon, 02 Jun 2008 14:09:52 -0600

The Natwest are once more the target of a phishing email. This time around the destination URL is http://www.natwest.co.uk.dg-yar5.org.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed] - so probably yet another of the current series targeting the NatWest.

Here's the email content.

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=54381748798756137278337923438792855237123444418666954&cookieid=7674508179521

Natwest Customer Service


ref i-cmr

Monday, 2 June 2008

A secondary e-mail address has been added to your PayPal.

Here's a new style of Phishing email - I had to look twice to convince myself here that it was the email that was phishing and not someone really breaking into my account. Indications that it's phishing:

1 - 'Dear PayPal user' - should give my name

2 - sent to 'undisclosed recipients' - would have been sent to my registered email address.

3 - the destination of the link is http://210.187.79.36/~anna/.bin/ - an IP address to mask the fake website name, it would be www.paypal.co.uk / www.paypal.com if it was real.

If in doubt, open a ne browser window and type in www.paypal.com to sign into your account. Never use the links in emails, even on genuine emails. It leads you into a flase sense of security.

Here's the email content:

Dear PayPal user,


You've added an additional email address to your account.Us for details


To make sure you can use your PayPal account the next time you make a purchase, all you need to do is confirm or not your email address.


To Login, fast in your paypal account :

https://www.paypal.com/uk/cgi-bin/webscr?cmd=_login-run&dispatch=5d80a13c0db1f1ff80d5423b5265b6559fc2aae010bfb00cf3c64


If your email program has problems with hypertext links, you may also confirm your email address by logging in to your account.

>>> Apply online


Please do not reply to this email.This mailbox is not monitored and you will not receive a response.


PayPal Email ID PP025197.

NatWest Bank: Automatic Account Reminder (Mon, 02 Jun 2008 03:09:37 -0500)

The Natwest continue to be a popular victim / target of the phishing emails. This one, like another recent email, uses the domain http://www.nwolb.com.nwolb.org.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed] - very similar to the recent nwolb.me.uk and nwol emails, that have also used the refererident / cookie pairing in the link.

Here's the email.

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.nwolb.com/newmeasures/procedure/default.aspx?refererident=7111256171904203771463961967533580325045981996921&cookieid=07223497

Natwest Customer Service


ref l-cmr

Anglo Irish Bank customer:1 new ALERT message.

It seems the fake message alert is becoming quite popular - this time it's on a new target bank.

Also like some recent emails, the actual destination URL is hidden by using the website's IP address, rather than the URL - http://72.214.45.5/~admin/.cgi/ is shown. Here's the email...

Dear customer for Anglo Irish Bank,

You have 1 new security message
Please login to your Anglo Irish Bank
and visit the Message Center section in order to read the message.

To Login, fast in your account:

Anglo Irish Bank Online

Saturday, 31 May 2008

NatWest Bank: safeguarding customer information

This one is very similar, but still subtly different to the email received earlier today. The tracking is there, but is following referer and cookie, rather than machine and 'id'. This one looks exactly like yesterday's Natwest EMail. So it's possible that they are both sent from different sources and it's just a coincidence that both have hit the same email address overnight.

I alos didn't record which email address received yesterday's email, so no idea if they are working through the same list, sending repeat emails, or if they are on a different list. This email is sent to one address at a time, so it's possible they are working down a list that my email addresses appear on several times.

This time around the link is to http://www.natwest.co.uk.nwol.me.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed] - yesterday it was nwolb.me.uk - so presumably the first site has been shut down, which could be the reason for repeating the email. Here's the content, again...

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.natwest.co.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]

Natwest Customer Service


ref l-cmr

NatWest Bank customer service: your account with us. [message ref:

Another 2 emails targetting Natwest customers overnight, both through the same email address and both very similar.

The first is a scheduled maintenance. So obviously, when banks do this customers have to sign on to remind the banks of their security details. Not really a convincing excuse, is it? Instead of the NOF, it's now the NCF (the Natwest Customer Form) - that's making a few appearances.

The target URL is http://www.natwest.com.tknnt.me.uk/serverstack/usersdirectory/ncf.aspx?pc=[removed]&id=[removed], so it's sent by the group of people who are tracking which recipient PCs click on the links. Actually, the email content is the same as last Thursday's - I just didn't record which email address Thursday's arrived through.

Here's the content.

Dear customer of NatWest bank,

We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.
Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.

To complete the form, please use the link below:

Natwest Customer Form

This should take you directly to the Natwest Customer Form.

Sincerely,
Natwest Customer Service


ref l-cmr

Friday, 30 May 2008

NatWest Bank notification!

Another one of a similar format to recent Natwest Phishing Emails - this one also triggering the virus software, which is unusual. Like the others, this one has a referer id / cookie id so the senders are tracking which recipients are opening the email.

The grammar is suspect - 'We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory'. I see what they are trying to say, but it's not how an English bank would write it. The destination URL is http://www.natwest.com.nwolb.me.uk/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed], which looks similar to others I've seen before, but nwolb.me.uk isn't in any search results of use, at the moment...

Here's the email's content:

Dear NatWest bank customer,

Security and confidentiality are at the heart of Natwest Bankline. Your data (and your money) is protected by a number of technologies, including Secure Sockets Layer (SSL) encryption.
We would like to notify you that NatWest bank carries out customer data verification procedure that is compulsory for all Natwest bank customers. This procedure is attributed to a routine banking software update.

Please login to Natwest online banking using the link below and follow the instructions on the screen.

http://www.natwest.com/newmeasures/procedure/default.aspx?refererident=[removed]&cookieid=[removed]

Natwest Customer Service

Your payment didn't succeed, so your ads have been suspended.

Yet another version of the Google adwors phishing emails, they must be changing them every time to get through spam blockers. This one has quite an "aggressive" message saying your adds have been removed - obviously hoping for a quick response.

The actual URL being used is http://www.adwords.google.com.lskllz.cn/select/Login. I've no idea what the site is as it's in Chinese - so could be an innocent site that's been attacked.

Here's the email content:

-------------------------------------------------------------------------------------
This message was sent from a notification-only email address that does
not accept incoming email. Please do not reply to this message.
-------------------------------------------------------------------------------------

Dear Google AdWords Customer,

We were unable to process your payment.
Your ads will be suspended soon unless we can process your payment.
To prevent your ads from being suspended, please update your payment information.

Please sign in
to your account at http://adwords.google.com/select/login,
and update your payment information.

-------------------------------------------------------------------------------------
This message was sent from a notification-only email address that does
not accept incoming email. Please do not reply to this message.
------------------------------------------------------------------------------------------

Thursday, 29 May 2008

HSBC Bank Personal and Commercial Update Your Details -- ref: 218

The HSBC are the target for the second time in just a few days. A different approach this time around.

This time around it's back to the old story of the maintenance / technical / security department have updated their system and customers need to 'approve' their details (???) - although if you aren't a customer...

The link is actually pointing at http://personal9.hsbc.com.tag95.com/updateform/?session=[removed]. I can only find 1 other search result for tag95.com, and that's for an Abbey phishing email.

Here's the content:

Dear HSBC Internet Banking client!

Our Maintenance Division is carrying out an arranged OnLine Banking software update.

By visiting the link below you will start the procedure of the customer details approval:

http://ww6.hsbc.com/updateform/?session=[removed]

These directions are to be mailed and followed by all users of the HSBC Personal and Commercial

HSBC Bank does apologize for any troubles caused to you, and is very appreciative for your cooperation.

If you are not client of HSBC Group please disregard this notice!

--- This is an automated message please do not reply ---

(c) 2008 HSBC OnLine Banking. All Rights Reserved.

Important Notice From NatWest Bank bank.

A quiet day on the Phishing front today, after the tons yesterday saying I'd been awarded $1.5 / $2.5m! Today's only phishing email (but the evening is young...) is the good old NOF.

This time around the target URL is http://www.natwest.com.techs1.me.uk/serverstack/usersdirectory/ncf.aspx?pc=[removed]&id=[removed] - a very similar URL to the NatWest Phishing Email of a few days ago, which also used the pc / id combination to identify who clicked the link. This one is upsetting my virus software - is doesn't like the email.

Here's the content.

Dear customer of NatWest bank,

We are running a scheduled maintenance on our servers. We want to make sure your money and your personal details are safe and secure.
Due to new security policies all NatWest bank customers must complete the Natwest Customer Form.

To complete the form, please use the link below:

Natwest Customer Form

This should take you directly to the Natwest Customer Form.

Sincerely,
Natwest Customer Service