Today I got an obviously fraudulent email claiming I need to "update my account information" at PayPal. The site it links to has entry fields for all sorts of personal information, plus credit card account information. I don't have a PayPal account. This isn't the first I've gotten something like this, but here are the details for this one.
Screenshot of the email as it appears in my Hotmail account
The header.
X-Message-Status: sF X-SID-PRA: service@paypal.com X-SID-Result: SoftFail X-Message-Info: JGTYoYF78jHcoG/t78wIKx930QsXgE4UFFf2cdDtg3Q= Received: from EV1SERVE-GDKQQ6 ([69.57.136.63]) by mc3-f21.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Tue, 15 Mar 2005 16:23:19 -0800 From: "service@paypal.com" Subject: Account Verification. To: USERNAME@hotmail.com Content-Type: text/html;iso-8859-1 Reply-To: service@paypal.com Date: Tue, 15 Mar 2005 18:23:20 -0600 X-Priority: 3 X-Library: Indy 8.0.25 Return-Path: service@paypal.com Message-ID: X-OriginalArrivalTime: 16 Mar 2005 00:23:19.0864 (UTC) FILETIME=[5B164B80:01C529BE]Clicking on the link to "update" your information takes to you to http://add.update.config.cmdcmd.503subscription.info:80/ and then fowards you to an ugly looking URL that can be simplified to this: http://216.51.232.128/best-greetings-flirting.com/pp/update.htm?=