Paypal - attempted foreign IP login?

Discussion in 'PayPal' started by northpointaiki, Feb 7, 2006.

  1. #1
    Just got this in an e-mail. Anyone else ever gotten this?

    I am reluctant to go and do this, in the event this itself is a hack attempt (redirect, or something like this). That, and to my knowledge, this e-mail has no paypal associated with it, so this seems bizarre. Any thoughts?
     
    northpointaiki, Feb 7, 2006 IP
  2. fsmedia

    fsmedia Prominent Member

    Messages:
    5,163
    Likes Received:
    262
    Best Answers:
    0
    Trophy Points:
    390
    #2
    It's spam, I get those at least 20 times a day. Look at the REAL URL that it's sending you to, it's probably an IP address (which will obviously NOT be paypal).
     
    fsmedia, Feb 7, 2006 IP
  3. Crazy_Rob

    Crazy_Rob I seen't it!

    Messages:
    13,157
    Likes Received:
    1,366
    Best Answers:
    0
    Trophy Points:
    360
    #3
    PayPal never sends users emails requesting details in this way.
     
    Crazy_Rob, Feb 7, 2006 IP
  4. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #4
    It's a phishing email. What you have printed above is the phishing text. If you look at the source code of the email you will find the real url.
     
    mcfox, Feb 7, 2006 IP
  5. yfs1

    yfs1 User Title Not Found

    Messages:
    13,798
    Likes Received:
    922
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Hover over the link and you will see where it really goes ;)

    If you are ever unsure of a Paypal email, just delete the email, go to the actual site www.paypal.com, log in, and see if a message pops up.

    I had my account suspended after accepting more then I was allowed without a passport etc. They provide the notification thorugh your account so you don't ever have to follow a link in an email.
     
    yfs1, Feb 7, 2006 IP
  6. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #6
    Spam! I don't understand the motivation behind such an email ... I get a similar email from someone who claims to be from ebay too..
     
    anusha, Feb 7, 2006 IP
  7. yfs1

    yfs1 User Title Not Found

    Messages:
    13,798
    Likes Received:
    922
    Best Answers:
    0
    Trophy Points:
    0
    #7
    They got your login details when you go that site then all your money is gone :D
     
    yfs1, Feb 7, 2006 IP
  8. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #8
    How does a 3rd party get login details if I login with https://www.paypal.com/us/cgi-bin/webscr? cmd=_login-run .. A domain owned by paypal ... Or, you mean to say, the hyperlink points to a different url (which is ofcourse hidden) , with the same fake UI a paypal ?
     
    anusha, Feb 7, 2006 IP
  9. yfs1

    yfs1 User Title Not Found

    Messages:
    13,798
    Likes Received:
    922
    Best Answers:
    0
    Trophy Points:
    0
    #9
    yfs1, Feb 7, 2006 IP
  10. mdvaldosta

    mdvaldosta Peon

    Messages:
    4,079
    Likes Received:
    362
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I get 2 or 3 like that a day... foward it to
     
    mdvaldosta, Feb 7, 2006 IP
  11. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #11
    anusha, Feb 7, 2006 IP
  12. mcfox

    mcfox Wind Maker

    Messages:
    7,526
    Likes Received:
    716
    Best Answers:
    0
    Trophy Points:
    360
    #12
    Correct.

    When you look at the code (or mouseover) you see an entirely different destination url:
    Something like this:
    <a href="http://give.us.your.account.info@paypalspoofaddress.co.uk?redirect:spoof3tospoof4.co.uk?runcmd=sneaky_details_url">https://www.paypal.com/us/cgi-bin/webscr?</a>
    Code (markup):
    <edit>geeze, you guys are fast at typing!
     
    mcfox, Feb 7, 2006 IP
    yfs1 likes this.
  13. northpointaiki

    northpointaiki Guest

    Messages:
    6,876
    Likes Received:
    187
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Thank you all, exactly what it was:

    "Customcare@paypal.com" is actually:

    204.202.3.158, kolumbus.crystalindia.com.

    When I've reported these losers before, nothing has happened. Any suggestions as to how to shut this user down?
     
    northpointaiki, Feb 7, 2006 IP
  14. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #14
    Check the website name servers and report to the respective hosting provider.. that can help :p
     
    anusha, Feb 7, 2006 IP
  15. northpointaiki

    northpointaiki Guest

    Messages:
    6,876
    Likes Received:
    187
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Using Smartwhois, that is what I did. But I usually get back e-mails saying "sorry, can't do anything without a court order" or something like that. Any other thoughts (besides tapping on "kolumbus.crystalindia.com's" door and offering a fond hello).
     
    northpointaiki, Feb 7, 2006 IP
  16. advancedfuture

    advancedfuture Banned

    Messages:
    481
    Likes Received:
    17
    Best Answers:
    0
    Trophy Points:
    0
    #16
    HAHAHA I get these emails all the time almost as much as the letters from the wife of the now deceased General Wantanasa of the East Nigerian Liberation Army offering my 25Million Dollars to help smuggle her money out of her country. God if it was all true, I would be making several billion dollars a year!
     
    advancedfuture, Feb 7, 2006 IP
  17. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #17
    I remember getting a mail from a nigerian before 5-6 years when I was new to internet... It said...
    "Congrats!! you have won 1 millions dollars" ...
    Send us your address details, so that we can send u the check...

    And I being new to internet, did the same...

    Next mail.. Your check is done.. But we have not paid some crap transaction fee before we can actually send the check to u...

    So they asked me to make a payment of $250 and have the check...

    I stayed away! :p
     
    anusha, Feb 7, 2006 IP
  18. northpointaiki

    northpointaiki Guest

    Messages:
    6,876
    Likes Received:
    187
    Best Answers:
    0
    Trophy Points:
    0
    #18
    I've gotten the Nigerian scam for years, although it wasn't until recent submissions to directories and such that they came back with a vengeance. This is the first paypal phishing scam I've received.
     
    northpointaiki, Feb 7, 2006 IP
  19. anusha

    anusha Active Member

    Messages:
    588
    Likes Received:
    67
    Best Answers:
    0
    Trophy Points:
    68
    #19
    I have got this paypal letters even for email accounts that were not associated or added to the main paypal account. That helped me make a note of it. :p
     
    anusha, Feb 7, 2006 IP
  20. Seiya

    Seiya Peon

    Messages:
    4,666
    Likes Received:
    404
    Best Answers:
    0
    Trophy Points:
    0
    #20
    if you doubting anything just type www.paypal.com in your browser and ocntact them through custoemr support.
     
    Seiya, Feb 7, 2006 IP