29/12). eBay - HTML.Phishing.Auction-102
This email targets customers of eBay.
Message Details
| Malware Name: | HTML.Phishing.Auction-102 |
| Origin: | |
| Date first seen: | 25/07/2006 02:00:44 |
| From: | "ebay" <member@ebay.com> |
| Subject: | Message From eBay Member |
Attacker's URLs
The following table shows the details of the URLs used by the attacker. These could either be the fake website of the attack, or a site which redirects to the attackers fake site. Sometimes the attacker will use an additional site for hosting resources such as images.
The table shows the current status of the site: if it is still reachable (
), or if it has been shut down (
). If the site has not been confirmed as a phishing site it is shown with the symbol
. The time when the site was first observed is shown, together with the time that the site was shut down, if applicable. Do not visit the attackers site as it may contain malware. You can get more details on the site by clicking on the
symbol.
| Status | First observed | Shut Down | Internet Address | URL |
|---|
Message Text
The text below shows the message content, rendered in a safe way. It does not show images or HTML formatting, but the text is the same as that contained in the phishing email. Each clickable link is shown as a reference. You can see the way the URL is presented in the main body of the text, while the actual URL activated by the link is shown below the main body.
eBay sent this message to you
Your registered name is included to show this message originated from eBay.
[1]Learn more.
[hdrLeft_13x39.gif] Question about Item -- Respond Now eBay
[s.gif]
eBay sent this message on behalf of an eBay member via My Messages.
Responses sent using email will go to the eBay member directly and will
include your email address. Click the Respond Now button below to send your
response via My Messages (your email address will not be included).
[s.gif]
[s.gif]
[s.gif]
Question from [2]*glta [s.gif] ( [3]611 Feedback score is 5,000 to 9,999 )
[s.gif] [4]Member is a PowerSeller [s.gif]
Item: ([5]5879770966)
This message was sent while the listing was active.
[s.gif]
Dear seller.Please give me the last price on your item and also if i can use
buy now.I really want to take it off your hands,please be prompt! thanks in
advance.
Respond to this question in My Messages.
[6]Respond Now
[s.gif]
[s.gif]
[s.gif] Item Details
[s.gif]
[s.gif]
Item number: [7]5879770966
End date: 22 - july - 06 18:56:12 BST
[s.gif]
[s.gif]
View item description:
[8]htps://cgi.ebay.com/ws/eBayISAPI.dll?ViewItem&item=4615976000&sspagename=
ADME:B:AAQ:UK:1
[s.gif]
Thank you for using eBay
[9]http://www.ebay.com/
[s.gif]
[s.gif]
Marketplace Safety Tip [10]Marketplace Safety Tip
Always remember to complete your transactions on eBay - it's the safer way
to trade.
Is this message an offer to buy your item directly through email without
winning the item on eBay? If so, please help make the eBay marketplace safer
by reporting it to us. These external transactions may be unsafe and are
against eBay policy. [11]Learn more about trading safely.
[s.gif]
[s.gif]
Is this email inappropriate? Does it breach [12]reporting it.
[s.gif]
[s.gif]
Learn how you can protect yourself from spoof (fake) emails at:
[13]https://pages.ebay.com/education/spooftutorial
[s.gif]
This eBay notice was sent to you on behalf of another eBay member through
the eBay platform and in accordance with our Privacy Policy. If you would
like to receive this email in text format, change your [14]notification
preferences.
[s.gif]
See our Privacy Policy and User Agreement if you have questions about eBay's
communication policies.
Privacy Policy: [15]https://pages.ebay.com/help/policies/privacy-policy.html
User Agreement: [16]https://pages.ebay.com/help/policies/user-agreement.html
[s.gif]
Copyright © 2006 eBay, Inc. All Rights Reserved.
Designated trademarks and brands are the property of their respective
owners.
eBay and the eBay logo are registered trademarks or trademarks of eBay, Inc.
References
Visible links
1. ftp://jeban:venice@/205.134.160.10/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
2. http://feedback.ebay.com/ws/eBayISAPI.dll?ViewFeedback&userid=*glta&iid=5879770966&frm=284
3. http://feedback.ebay.com/ws/eBayISAPI.dll?ViewFeedback&userid=*glta
4. http://pages.ebay.com/services/buyandsell/powersellers.html
5. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
6. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
7. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
8. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
9. http://www.ebay.com/
10. http://pages.ebay.co.uk/safetycentre
11. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
12. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
13. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
14. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
15. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
16. ftp://jeban:victim@phishtank.internetdefence.net/SingIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp=&pa2=&errmsg=&runame=&ruams=&ruproducte=&sid=&favoritenav=&emigrateVisitor=.htm.htm
Hidden links:
17. http://members.ebay.com/ws/eBayISAPI.dll?ViewUserPage&userid=*glt
Embedded Images
The following images were embedded in the email. Sometimes, the message text is just there to confuse anti-spam filters, while the reader is presented with a clickable image which shows the "real" message.
Embedded Image: 869.png
Embedded Image: 869-thumb.png