Malware City/Blog/

Jul
27
Filed Under:
ALERTS

Fake eBay Confirmation Form

27 July 2009
Same phishing scheme, different e-seller

Following Bank of America phishing raid I described last week, a new attempt, probably crafted by the same e-crooks or at least based on the same modus operandi, targets this time the eBayŽ customers.

The unsolicited message asks the uninformed user to fill in a new mandatory "confirmation form", by following the link provided in the message body.

Ebay Phishing 1

As you probably guessed, the link does not lead to the e-commerce Web site, but to a .com registered Web page imitating the appearance of the original site.

Ebay Phishing 2

Phishers seek now to steal - via eBayISAPI1.php script - the following sensitive information: first and last name, complete address and phone number, e-mail address, birth date and SSN, but also eBay user ID and password plus credit/debit card details (card number, expiration date, CVC) including PIN.

For credibility proposes, the same pop-up window previously employed in Bank of America raid appears here too, with slight changes - such as the eBay name and (real) homepage towards which the duped users are automatically redirected after the alleged automatic log out.

Ebay Phishing 3




Balancing the keen and until late in night reading, with Internet "addiction", the genuine zeal for my bright and fervid students with the craze for the latest discoveries in science and technology, I also enjoy taking not very usual ...

Comment on this

Name:

Email:

Website:

Your email adress will not be published.