Forum Home
Press F1
 
Thread ID: 43834 2004-03-28 07:36:00 OT: ANZ Bank scam doing the rounds Billy T (70) Press F1
Post ID Timestamp Content User
225661 2004-03-28 07:36:00 Hi Team

I don't know what it is with these bank scammers, they seem to think I have piles of loot stashed in different banks.

There is a very good ANZ email circulating with excellent grammar and no spelling mistakes inviting the usual supply of account number (customer registration number) and password.

Of course it could be a genuine ANZ email :D but then why send it to non ANZ customers. I checked the URL but this time I couldn't find the catch at the end that tells you the country of origin, it seems to be very well hidden.

Cheers

Billy 8-{)

Cheers
Billy T (70)
225662 2004-03-28 08:03:00 What does the URL look like in the email? Jen C (20)
225663 2004-03-28 08:29:00 This is the source data Jen:

<html><body>

<font color="#FFFFFD">at the far side Temptation Island</font></p>

cid:378D7179.22F60DEF.AF249039.F2C2D632_csseditor (www.anz.com@%64%6C%6C%6C%2E%69%6E%66%6F) </p>

<font color="#FFFFF4">in 1898 Dr. Dree Well done! If you'd like in 1953 </font></p></body></html>

Cheers

Billy 8-{)
Billy T (70)
225664 2004-03-28 08:38:00 >www.anz.com@%64%6C%6C%6C%2E%69%6E%66%6F 68%74%6D

The @ part indicates that it is being spoofed. Without looking at the source, it probably displayed as www.anz.com, or at least in IE it would appear when the link was followed as www.anz.com in the address bar. Wasn't this security hole fixed in IE recently to prevent these spoofed URL's?
Jen C (20)
225665 2004-03-28 11:26:00 Yes, supposedly...

with Cumulative Security Update for IE 6 & Service Pack 1 (3012KB) released on 2-2-2004. It's KB832894 on MS list.
Google has lots.
(My History says 4 February)

Time to run the MS free update CD..?
Laura (43)
225666 2004-03-29 04:06:00 You should have spotted it because of the "excellent grammar and no spelling mistakes". :D Graham L (2)
225667 2004-04-05 03:03:00 The National Bank is the latest email scam target.

The English is not quite as fluent, and it doesn't have the McAfee AV tag but otherwise a credible looking site.

Cheers

Billy 8-{)
Billy T (70)
1