Need help? Ask the community or hire an expert.
Go to Avira Answers
Target:Ebay
Date discovered:07/06/2006

 General The goal is to get the following information:
    • Bank account
    • Credit card
    • Personal data
    • Ebay account
    • Email account


Phishing methods:
    • 'Click here' link
    • URL link

 Email Details From: update@ebay.com
Subject: eBay Registration Suspension

Visible link: http://signin.ebay.com/ws/eBayISAPI.dll?SignIn&ssPageName=h:h:sin:US
Actual link: http://222.122.45.225/manual/ebay/login2209/
IP address: 222.122.45.225


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://222.122.45.225/manual/ebay/login2209/
Actual URL: http://222.122.45.225/manual/ebay/login2209/
IP address: 222.122.45.225


The phishing page will look like the following:




Description inserted by Dominik Auerbach on Wednesday, June 7, 2006

Back . . . .