PayPal phishing in attachments


Yesterday MX Lab reported regarding a phishing email that has no URL but instead an attached HTML document with a web form included. Since then we see more similar cases and also PayPal is subject to this technique. The senders address shows us “www.paypal.com” <[email protected]> but this is spoofed. The email was sent from 69.128.90.226, an IP address in the US, pointing to mail.dandlequipment.com.

The body of the email:

To make sure everything is in order,please download the PayPal Security Account Verification and fill in all the required data for verfication.

The actual webpage:

The webform makes a POST to hxxp://0xD5.0xC3.0xDF.0xA9/paypalverification.php/.

2 Responses to PayPal phishing in attachments

  1. Pingback: PayPal e Banca Agricola Popolare vittime di phishing, attenzione alle mail con allegati sospetti | ciaoblog

  2. Wow .. interesting info and very useful because I often use Paypal for online shopping. This will make us more careful in order not to arbitrarily open the attached file that is included in an email.

Follow

Get every new post delivered to your Inbox.

Join 348 other followers

%d bloggers like this: