Tuesday, May 6, 2008

Pay Pal Phishing

The most prominent Phishing attack is on paypal most of the time.I am sure most of them who get spam message would get this once.

here is a classic one


Information Regarding Your account:
Dear PayPal Member:

Attention! Your PayPal account has been limited!

As part of our security measures, we regularly screen activity in the PayPal system.We recently contacted you after noticing an issue on your account.We requested information from you for the following reason:

Our system detected unusual charges to a credit card linked to your PayPal account.

Activate your account
PayPal Email ID: 5138-8872





Sincerely,

PayPal Accounts Review Department.

Copyright 1999-2008 PayPal. All rights reserved




it actually links to


ichrak.biz


the above link redirects to phishing site

it gets all information , even the pin number for your credit card. here is the reason they give.


By adding VeriSign Payment Services industry-leading tools such as Payflow Link and Payflow Pro to PayPal's suite of payment solutions, we're now able to offer online merchants even more choices for their businesses.

Requiring PIN Signatures is the latest security measure against: identity theft, credit card fraud and unauthorized account access. PayPal will verify it with your bank records for your own protection.


If you provide a wrong PIN your account will be suspended for unauthorized account access.


APK spam on Whatsapp Targeting Bank users

  Initial vector:   Whatsapp spam user posing as union bank with logo in user profile shared apk file named as “Union Bank Aadhaar Update....