December 17, 2007
A phishing email popped up in my inbox, and just for fun, I decided to study the links and domains associated with it. I would never have guessed what names and addresses popped up in relation to this bit of spam.
I received this bit of phishing email today:
Please Update Your Billing Records!
Dear Member,It has come to our attention that your PayPal Billing Information records are out of date. That requires you to update the Billing Information.
Click here to update your account
Thank you for using PayPal!
Terms of Suspended
Please update your records in maximum 12 hours otherwise your account will be suspended.
Once you have updated your account records, your PayPal session will not be interrupted and will continue as normal. Failure to update will result in cancellation of service, Terms of Service (TOS) violations or future billing problems.
"Terms of Suspended"?
Bad grammar is a dead giveaway. Phishing refers to an attempt to acquire userids and passwords fraudulently. The classic form is the email message informing you that your account is about to be terminated unless you sign in right away. A link is provided to a webpage mocked up to look legitimate. You log in, and a message tells you your account is now OK. What really has happened is that the criminals have recorded your userid and password.
Nothing new here, really, but on a whim, I checked on the address given for the fake login page: http://darbypta.com/financials/cgi-bin/
Clearly not PayPal.
But interestingly, it is a legitimate domain, that is, it is not a porn site or a warez site. It is the domain for the Darby Elementary School Parent-Teacher Association in Northbridge, California. As for the "PayPal" link at financials/cgi-bin? No page exists at this URL, so it doesn't seem like a well-executed phishing scam.
So I checked the domain of the sender of the email: email1.pay-pal.com.
Registrant: paypalsucks.com dk ruff Suite 500 1 N. Wacker Dr. Chicago, IL 60606 US Email: buythem@keepstime.comAdministrative Contact: pay-pal.com dk ruff 17013 steeplechase pkwy orland park, IL 60467 US Phone: 708478-7834 Email: keepstime@hotmail.com
PayPalSucks.com is a gripe site, dedicated to spreading the word about what a lousy service PayPal provides:
PayPal Sucks, aka No PayPal, is an anti paypal site to expose the nightmare of doing business "the paypal way." Post your complaints, troubles, fraud stories, lawsuits, and other dissatisfaction in the forums.
Here is the registration information for PayPalSucks.com:
Registrant Contact: PayPalSucks.com Marshall Golub (admin@paypalsucks.com) +1.9548069308 Fax: 3850 E Coquina Way Weston, FL 33332 US
Not "dk ruff". Marshall Golub is also the name of the National Sales Director for Charge.com, a PayPal competitor, but that might be a coincidence. The address given for the pay-pal.com registration, Wacker Drive in Chicago, is actually the address for the office of The Options Clearing Corporation:
The Options Clearing Corporation
One North Wacker Drive, Suite 500
Chicago IL 60606The Options Clearing Corporation (OCC), founded in 1973, is the world's largest equity derivatives clearing organization. We are dedicated to promoting stability and financial integrity in the marketplaces that we serve by focusing on sound risk management principles. By acting as guarantor, we ensure that the obligations of the contracts we clear are fulfilled.
Basically, OCC issues and clears all US exchange-listed securities. Interesting.
So is PayPalSucks.com behind the phishing email that seemed incapable of collecting any information? Perhaps, and you could imagine the goal for PayPalSucks.com was to irritate potential PayPal users by reminding them of the phishing efforts directed at PayPal.
But then why make it so easy to trace it back to PayPalSucks.com? Why give a fake address to the OCC but still provide the name PayPalSucks.com? And why the address for the OCC, of all places to pick from?
My theory is that this is an attempt to make PayPalSucks.com look bad. Again, we have a phishing email that is not actually capable of phishing. And then we have a registration record that names PayPalSucks.com. Now it looks like PayPalSucks.com is trying to smear PayPal by sending spam, and crappy spam at that. As a result, I'm upset at PayPalSucks.com for playing these games instead of sticking to running a gripe site.
I can't explain why the address of the OCC shows up in this. That's a headscratcher. I can only assume that the people behind this email are familiar with the address.
The real question, though, is who benefits from making PayPalSucks.com look bad. I leave that as an exercise for the reader.
There are other theories that fit the facts. None of it really matters. I just found it to be an interesting diversion for a half-hour, and learned about the OCC and PayPalSucks.com along the way.
Posted by: Steve Janke at
08:24 PM
| Comments (62)
| Add Comment
Post contains 799 words, total size 7 kb.
Posted by: Posicionamiento en Google at October 21, 2012 09:49 AM (LcSS1)
Posted by: Freestyle Vest Canada Goose Women Hyacinth Canada Goose Outlet at November 09, 2012 02:20 PM (PIxx9)
Posted by: Canada Goose Manitoba Jacket Navy Discount Canada Goose at November 09, 2012 02:20 PM (PIxx9)
Posted by: talking tom cat online at November 10, 2012 10:05 AM (Vz2JW)
Posted by: North Face Jackets sale at November 13, 2012 01:24 PM (QBlum)
Posted by: Weeds season 8 dvd at November 13, 2012 02:57 PM (lpoFk)
Posted by: GET A BIGGER BUTT at November 16, 2012 12:01 AM (4C/ft)
Posted by: Cheap NBA Jerseys at November 21, 2012 05:57 AM (MBz+K)
Posted by: Nike Air Max 90 at November 21, 2012 07:36 AM (lVGOX)
Posted by: ghd straighteners at November 22, 2012 06:58 AM (VPAcq)
Posted by: Chicago Bulls Jerseys at November 26, 2012 03:26 AM (pvUH2)
Posted by: Chiefs jersey Cheap at November 29, 2012 07:48 AM (eOBZU)
Posted by: Redskins jersey Cheap at November 29, 2012 08:10 AM (4wzxQ)
Posted by: The Lion King Trilogy DVD Boxset at November 29, 2012 04:27 PM (UOnAO)
Posted by: Desperate Housewives Season 5 DVD Boxset at November 29, 2012 04:47 PM (UOnAO)
Posted by: GHD Australia at November 30, 2012 04:12 AM (jDMW3)
Posted by: veste north face at November 30, 2012 11:14 AM (BrDJe)
Posted by: cheap f50 cleats at December 02, 2012 11:59 AM (kMfky)
Posted by: lebron james 9 galaxy at December 03, 2012 09:20 AM (d1mUr)
Posted by: GHD Hair Straightener at December 03, 2012 03:59 PM (rz4ZF)
Posted by: Packers jersey cheap at December 05, 2012 11:36 AM (wmdzq)
Posted by: Jaguars jersey cheap at December 05, 2012 11:59 AM (wmdzq)
Posted by: shop north face at December 05, 2012 02:16 PM (QTLvO)
Posted by: Nike Zoom Kobe at December 06, 2012 11:23 PM (8QNsI)
Posted by: vigrx plus at December 07, 2012 07:00 AM (Rv9y0)
Posted by: Isabel marant sneaker at December 07, 2012 02:10 PM (ROwfO)
Posted by: longchamp at December 07, 2012 03:32 PM (ROwfO)
Posted by: Isabel marant sneakers at December 07, 2012 05:57 PM (ROwfO)
Posted by: Isabel Marant Bekket at December 08, 2012 01:40 PM (D7dZp)
Posted by: merou at December 11, 2012 02:05 PM (ASirR)
Posted by: ghd straighteners at December 13, 2012 05:56 AM (h9LcV)
Posted by: GHD Pink Orchid at December 13, 2012 12:19 PM (dWX1l)
Posted by: Army Wives seasons 1-6 dvd at December 14, 2012 09:32 AM (Jc6JF)
Posted by: brand at December 23, 2012 10:36 AM (vGyU0)
Posted by: brand at December 26, 2012 11:14 AM (5CZyQ)
Posted by: brand at December 26, 2012 10:49 PM (VswyS)
Posted by: vanmoo blog at January 04, 2013 01:10 PM (dAXVQ)
Posted by: north face boots womens at January 08, 2013 05:32 PM (5CkuR)
Posted by: north face shoes mens at January 08, 2013 05:32 PM (5CkuR)
Posted by: the north face 2013 at January 08, 2013 05:33 PM (5CkuR)
Posted by: north face 2 in 1 at January 08, 2013 05:33 PM (5CkuR)
Posted by: north face gloves at January 08, 2013 05:33 PM (5CkuR)
Posted by: sinhalaunicode.learnenglishinsrilanka.com/activity/p/43318/ at January 09, 2013 12:34 PM (+0Ycx)
Posted by: Jewel at January 13, 2013 10:19 AM (Fpva1)
Posted by: vuelos baratos desde Madrid A valencia at January 13, 2013 12:32 PM (Fpva1)
Posted by: アグ ブーツ at January 14, 2013 07:31 AM (P8mfl)
Posted by: kaunbanegacrorpati.com at January 15, 2013 01:41 AM (RHKhg)
Posted by: Health e cigarette at January 17, 2013 01:10 AM (glRi1)
Posted by: prada éž„ at January 18, 2013 06:11 PM (ClAQW)
Posted by: maillot de foot 2013 2014 at January 20, 2013 06:50 AM (tIpXM)
<a href="http://hqview-wallpapers.blogspot.com/">Wallpapers</a> <a href="http://hqview-wallpapers.blogspot.com/">Computer wallpaper</a> <a href="http://hqview-wallpapers.blogspot.com/">Desktop wallpaper</a> <a href="http://hqview-wallpapers.blogspot.com/">Background wallpaper</a>
Posted by: Syed Qamer at February 06, 2013 09:39 AM (SPe9O)
<a href="http://hackingsoftwaresfreedownload.blogspot.com/">Hacking Softwares</a></div> <a href="http://hackingsoftwaresfreedownload.blogspot.com/">Facebook Hacking</a></div> <a href="http://hackingsoftwaresfreedownload.blogspot.com/">Password Hacker</a></div> <a href="http://hackingsoftwaresfreedownload.blogspot.com/">Facebook Hack Password</a></div>
Posted by: Syed Qamer at February 06, 2013 09:41 AM (SPe9O)
Posted by: windows 7 product key at February 08, 2013 03:55 AM (JrXYi)
Posted by: windows 7 product key at February 08, 2013 03:55 AM (e0/th)
95 queries taking 0.126 seconds, 281 records returned.
Powered by Minx 1.1.6c-pink.