12). eBay - HTML.Phishing.Auction-141

This email targets customers of eBay.

Message Details

Malware Name:HTML.Phishing.Auction-141
Origin: Italy
Date first seen:13/07/2006 00:42:10
From:"eBay member davescooltoys" <aw-confirm@eBay.com>
Subject:Question from eBay member !

Attacker's URLs

The following table shows the details of the URLs used by the attacker. These could either be the fake website of the attack, or a site which redirects to the attackers fake site. Sometimes the attacker will use an additional site for hosting resources such as images.

The table shows the current status of the site: if it is still reachable (), or if it has been shut down (). If the site has not been confirmed as a phishing site it is shown with the symbol . The time when the site was first observed is shown, together with the time that the site was shut down, if applicable. Do not visit the attackers site as it may contain malware. You can get more details on the site by clicking on the symbol.

StatusFirst observedShut DownInternet AddressURL
13/07/2006 00:44:11 13/07/2006 00:44:11 Romania 81.196.20.134 http://i.bay.go.ro/sign.in   

Message Text

The text below shows the message content, rendered in a safe way. It does not show images or HTML formatting, but the text is the same as that contained in the phishing email. Each clickable link is shown as a reference. You can see the way the URL is presented in the main body of the text, while the actual URL activated by the link is shown below the main body.

Message Display
Enlarge
How the message body looks in an email client.

   eBay sent this message to you from Dave Ference (davescooltoys) .
   Your registered name is included to show this message originated from eBay.
   [1]Learn more.

                         Question from davescooltoys

   Item: (180004902307)
   This message was sent while the listing was active.
   davescooltoys is a potential buyer.

                               [spc_eee1.gif]

   Hey are you going to buy the item from the auction that you won, why dont
   you answer to my emails, if you dont Respond Now I will contact ebay
   safeharbor and I will report you !  I am not a fool !

   Respond to this question in My Messages.
   [2]Respond Now 

   [s.gif]
   [s.gif]
   [s.gif] Item Details
   [s.gif]
   [s.gif]
   Item number: [3]180004902307
   End date:    06-Jul-06 18:16:19 BST
   [s.gif]
   [s.gif]
   View item description:
   [4]htps://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=180004902307&sspagenam
   e=ADME:B:AAQ:UK:1
   [s.gif]
   Thank you for using eBay
   [5]http://www.ebay.com
   [s.gif]
   Marketplace Safety Tip [6]Marketplace Safety Tip
   Always remember to complete your transactions on eBay - it's the safer way
   to trade.
   Is this message an offer to buy your item directly through email without
   winning the item on eBay? If so, please help make the eBay marketplace safer
   by reporting it to us. These external transactions may be unsafe and are
   against eBay policy. [7]Learn more about trading safely.
   [s.gif]
   [s.gif]
   Is this email inappropriate? Does it breach [8]eBay policy? Help protect the
   community by [9]reporting it.
   [s.gif]

   [s.gif]
   Learn how you can protect yourself from spoof (fake) emails at:
   [10]https://pages.ebay.com/education/spooftutorial
   [s.gif]
   This eBay notice was sent to you on behalf of another eBay member through
   the eBay platform and in accordance with our Privacy Policy. If you would
   like to receive this email in text format, change your [11]notification
   preferences.
   [s.gif]
   See our Privacy Policy and User Agreement if you have questions about eBay's
   communication policies.
   Privacy Policy: [12]https://pages.ebay.com/help/policies/privacy-policy.html
   User Agreement: [13]https://pages.ebay.com/help/policies/user-agreement.html
   [s.gif]
   Copyright © 2006 eBay, Inc. All Rights Reserved.
   Designated trademarks and brands are the property of their respective
   owners.
   eBay and the eBay logo are registered trademarks or trademarks of eBay, Inc.

References

   1. http://i.bay.go.ro/sign.in
   2. http://i.bay.go.ro/sign.in
   3. http://i.bay.go.ro/sign.in
   4. http://i.bay.go.ro/sign.in
   5. http://i.bay.go.ro/sign.in
   6. http://i.bay.go.ro/sign.in
   7. http://i.bay.go.ro/sign.in
   8. http://i.bay.go.ro/sign.in
   9. http://i.bay.go.ro/sign.in
  10. http://i.bay.go.ro/sign.in
  11. http://i.bay.go.ro/sign.in
  12. http://i.bay.go.ro/sign.in
  13. http://i.bay.go.ro/sign.in