Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Phishing] McAfee Phish ?
Uniqs:
1047
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Trouble Bubble LLC Collegeville? »
« How to get an infected PC shut down.  
crypto1969

join:2004-02-23
Jacksonville, FL

[Phishing] McAfee Phish ?

Recived a seemingly legitimate E-Mail from MCAfee this evening with the text below:

Customer Note: This service notification is being sent to McAfee customers who are using an expired or unsupported VirusScan product that no longer receives anti-virus updates.

Recommended Action: Renew or upgrade your anti-virus protection today.

Dozens of new Internet threats come online every day. That's why uninterrupted PC protection is essential to keep your computer, email, downloads and attachments safe from new viruses, mass mailing worms, Trojans and spyware or unknown variants.

Remember, McAfee's proven security protects over 100 million computers worldwide. By renewing or upgrading, you'll enjoy the confidence of always-on, always up-to-date protection.

Sincerely,
McAfee, Inc.

The link the E-Mail contains takes you to this URL:
»us.mcafee.com/root/ar.asp?id=vs&···id=18018

The E-Mail looks very geuine and has all the right mCAfee logos but firstly the URL alerted me plus the fact that I only just took out a 1 year subscription to the product less than 2 months ago.

Has anyone else seen this Phishing E-Mail?
MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL

Re: [Phishing] McAfee Phish ?

The link you posted goes to the mcafee.com domain and will take you to an IP addess registered to mcafee. Unless I am missing something, it does not appear to be a phish. Have you examined the html mail code for other links?

MGD
crypto1969

join:2004-02-23
Jacksonville, FL

Re: [Phishing] McAfee Phish ?

Well, my suspicions were aroused by the fact that several of my family members and friends recived this same E-Mail today and none of them use McAfee products whatsoever. Plus the fact that I bought a subscription just 2 months ago.
crypto1969

join:2004-02-23
Jacksonville, FL

Re: [Phishing] McAfee Phish ?

in addition, the E-Mail I received was sent to a different E-Mail to the one I used for my McAfee subscription. McAfee has never been given the address that I received that notification to.
MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL


1 edit
Absolutely, being suspicious is always good practice. Especially since you and the others do not "qualify" for that mail.

My observation was only in regards to the link. I have ran across phishes that had malformed code that took you to the legitimate site and not the phish. If you look at the property/deatils/message source of the mail, you should be able to see if there are hidden re directs.

If you could post the header info from the email, XXX out your personal info, leaving the path and originating IP, then we may be able to establish if McAffe was the sender. They may also work through affiliates.

Based on what you have said, it is at least UCE.

MGD
Edit=added text
crypto1969

join:2004-02-23
Jacksonville, FL

Re: [Phishing] McAfee Phish ?

unfortunately I deleted the E-Mail soon after looking at it!

I will contact my family and friends and see if anyone saved their E-Maal and will then post the information here.
MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL

Re: [Phishing] McAfee Phish ?

Yes, if they can forward it to you as an attachment it will preserve the original headers.

A quick search indicates that there are current McAfee phishes our there;
quote:
Fake McAfee "Anti Kingo31.XRW Patch"
Thanks to the good folks at F-Secure for warning us (and McAfee) about a fake McAfee site that downloads an alleged patch for an alleged virus called "Kongo31.XRW" (which doesn't exist). The site uses the domain name "mcafee-center.net" and is hosted in Canada. The patch is actually infected with Trojan-Downloader.Win32.Hanlo.h.

source: »blog.ziffdavis.com/seltzer/archi···467.aspx

MGD
Forums » Up and Running » Security » Spam, Scam and PhishbustersTrouble Bubble LLC Collegeville? »
« How to get an infected PC shut down.  


Friday, 11-Dec 00:19:10 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [138] AT&T Launching New 24 Mbps U-Verse Tier
· [87] AT&T Hints At Usage-Based iPhone Data Pricing
· [82] 3G Network Test Says AT&T Is Tops
· [76] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [58] Average American Consumes 34 Gigabytes Daily
· [58] AT&T: iPhone Data Pricing Comments 'Taken Out Of Context'
· [52] Sprint, T-Mobile Merger Rumor Lives
Most people now reading
· New Mediacom Email [Mediacom]
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· What frequency is better for a 25+ mile link [Wireless Service Providers]
· Windows 7 boot manager editing questions [Microsoft Help]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Internet access from TV [Verizon FIOS TV]
· New 5 mans full walk through [World of Warcraft]