New (to me) phishing scheme

Got a typical phishing email today with a slightly new (to me) twist, and thought I'd share.

Date: Mon, 06 Jun 2005 18:05:13 -0500
From: administrator@stny.rr.com
Subject: *IMPORTANT* Please Validate Your Account
To: <myaddress>@stny.rr.com

Dear Valued Member,

According to our site policy you will have to confirm your account by the following link or else your account will be suspended within 24 hours for security reasons.

http://www.stny.rr.com/confirm.php?email=<myaddress>@stny.rr.com

Thank you for your attention to this question. We apologize for any inconvenience.

Sincerely,Stny Security Department Assistant.
The site it linked to was an IP, and on visiting the raw IP, I got a Plesk default page. Add the "confirm.php" and it tried to load a Windows COM object, which I assume was a trojan or virus loader.

I hadn't seen this ISP twist on this old issue, so I thought I'd pass it on here.

 

 

 

 

Top