View Full Version : Another Nasty eBay Phishing Scam
IJ Reilly
May 11, 2006, 11:17 AM
Most of these phishing schemes are pretty transparent, and hardly worth mentioning, but this one is remarkable on two counts. First, the e-mail was a dead-on and very convincing copy of an official eBay notice (supposedly from a potential buyer of an item you won). Second, clicking on the item link brings you to an eBay login page (again, very convincing), which if you examine the URL, originates from the Ukrainian Embassy in South Korea. So, either the embassy sever has been hacked, or someone on the staff is running this scam.
Beware!
killuminati
May 11, 2006, 11:47 AM
:( I think I've seen that same one, or I've seen a very similar one that is spot on. Regardless thanks for the heads up.
Saluki Alex
May 11, 2006, 11:59 AM
I've gotten this same email both yesterday and today. I forwarded them to spoof@ebay.com.
CanadaRAM
May 11, 2006, 12:40 PM
URL, originates from the Ukrainian Embassy in South Korea. So, either the embassy sever has been hacked, or someone on the staff is running this scam.
Beware!
For whatever reason, South Korean networks , especially their school networks, are notoriously poorly secured. This results in spammers flocking to them to use as open proxies to hide their real IPs. 99% of the mail that you get from a South Korean server is likely to be spam 'bounced' off that server like a good double bank shot in snooker.
IJ Reilly
May 11, 2006, 12:49 PM
For whatever reason, South Korean networks , especially their school networks, are notoriously poorly secured. This results in spammers flocking to them to use as open proxies to hide their real IPs. 99% of the mail that you get from a South Korean server is likely to be spam 'bounced' off that server like a good double bank shot in snooker.
Interesting. In this case, it's a complete URL, starting with the domain for the Ukrainian embassy in the ROK. Is it possible to "bounce" a URL? It starts:
http://www.ukrembrk.com/.signin.ebay.com
cb911
May 11, 2006, 05:09 PM
hrm - i get a 403 forbidden on that link?
I have also been caught by ones like this - just rushing once and I actaully input my password in one of those pages. I realised what I'd done and promptly changed my password on eBay, no harm cam to me.
eBay is full of scams...
IJ Reilly
May 11, 2006, 06:13 PM
hrm - i get a 403 forbidden on that link?
I have also been caught by ones like this - just rushing once and I actaully input my password in one of those pages. I realised what I'd done and promptly changed my password on eBay, no harm cam to me.
eBay is full of scams...
It's not eBay's fault. Anyhow, yes, you get a 403 when you try the partial link, which tells me the directory exists on the server but is privileged, which is why I posted it. I deliberately did not post the entire URL.
cb911
May 12, 2006, 07:01 AM
I deliberately did not post the entire URL.
ahhh! :eek: but I've got to sell my item! :D :p
vBulletin® v3.6.10, Copyright ©2000-2009, Jelsoft Enterprises Ltd.