Page 1 of 1

Spot the phishing attempt!

Posted: 11 Jan 2012, 23:18
by Ron2K
Received this lovely little mail purporting to be from ABSA (gmail spam filter didn't flag it).

Now, assuming you bank with ABSA, how would you tell that it's a phishing attempt? :wink:
from: ABSA. info@notify.msg.za via home.pl
to: [my e-mail address]
date: 11 January 2012 22:15
subject: You have a new Private Message
mailed-by: home.pl

Dear Customer,

Attention! Your ABSA online banking access has been
violated. We suspected someone other than you with
IP 126.370.42.86 trying to access your informations.

Please verify your banking information with us to show
that you are not currently away.
You have to verify this as soon as possible to prevent
your online bank account from getting blocked

Verify your Access


This email was sent from ABSA secure server
and is done for your protection.
(Note: the actual e-mail didn't link to Google -- I changed that for reasons that I hope are obvious.)

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 00:40
by KALSTER
The non-ABSA email addresses and the poor grammar ("informations")?

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 05:52
by jee
home.pl? Since when is ABSA using a Poland mail server?

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 07:14
by hamin_aus
home.pl might also be the perl script that generated the email.

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:07
by doo_much
Mine for today.

Dear FNB Account Holder,

There is a pending transfer into you FNB account for security reasons and the OTP Telephone number
associated with your account. we would require you to confirm your account status and profile on
file with us before this transfer can be completed.

This can done using the reference below.

https://www.fnb.co.za/ --> Links to http://cameraeducation.net/wp-includes/pomo/default.php

Please accept our apologies for any inconvenience this action may have caused

Yours sincerely,
Online Customer Service
First National Bank

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:08
by hamin_aus
Seems legit.

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:11
by doo_much
jamin_za wrote:Seems legit.
I doubt it. No-one ever pays money into my accounts! :lol:

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:12
by Ron2K
None of you lot picked up the rather interesting IP address in my one?

Forum, I am disappoint...

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:15
by doo_much
Ron2K wrote:None of you lot picked up the rather interesting IP address in my one?

Forum IT dweebs, I am disappoint...

Fixed that for you.

Care to enlighten the rest of us?

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:17
by Ron2K
Each octet in an IPv4 address has a 0-255 range.

Unless you're playing Uplink.

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:24
by doo_much
My apologies. Even an uninformed pillock such as myself should have noticed that. :oops:

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:31
by KatrynKat
don't worry Oom Doo...
to me it looked like just another IP address...

how should i know the rules and diffs of IP addresses...

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:38
by Stuart
Ron2K wrote:None of you lot picked up the rather interesting IP address in my one?

Forum, I am disappoint...
I actually did notice that. But it was my third observation, behind . . .

(1) common sense; and
(2) info@notify.msg.za

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:41
by doo_much
KatrynKat wrote:don't worry Oom Doo...
to me it looked like just another IP address...

how should i know the rules and diffs of IP addresses...
I actually finished 2 1/2 years of a BSc-IT degree... double :oops:

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:48
by hamin_aus
doo_much wrote:I actually finished 2 1/2 years of a BSc-IT degree...
Hmmm, IIRC you'd still be doing a bunch of applied Maths courses and would barely have touched anything IT related at that stage n the degree :P

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 10:54
by jee
I saw the IP in bold, but my knowledge is a bit limited on those :(

Re: Spot the phishing attempt!

Posted: 12 Jan 2012, 11:17
by doo_much
You mean we'd been taught to 'program' in Java (using a notepadlike inteface - no wysiwig) and VB (not .Net - it had been around for a while but our lecturer didn't know it) and done some life skills stuff? Yes.

But we were also expected to be converse with Binary and Hex...

As a matter of interest - dropped out because of 2nd year maths and a lecturer who stated, and I quote "I cannot explain this to you, it is something you must 'feel'(aanvoel)..."

This after I got 89% for first year maths. :|