republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Phishing] McAfee Phish ?
Search Topic:
Uniqs:
1026
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Trouble Bubble LLC Collegeville? »
« How to get an infected PC shut down.  
AuthorAll Replies

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL

reply to crypto1969
Re: [Phishing] McAfee Phish ?

Yes, if they can forward it to you as an attachment it will preserve the original headers.

A quick search indicates that there are current McAfee phishes our there;
quote:
Fake McAfee "Anti Kingo31.XRW Patch"
Thanks to the good folks at F-Secure for warning us (and McAfee) about a fake McAfee site that downloads an alleged patch for an alleged virus called "Kongo31.XRW" (which doesn't exist). The site uses the domain name "mcafee-center.net" and is hosted in Canada. The patch is actually infected with Trojan-Downloader.Win32.Hanlo.h.

source: »blog.ziffdavis.com/seltzer/archi···467.aspx

MGD

crypto1969

join:2004-02-23
Jacksonville, FL
reply to MGD
unfortunately I deleted the E-Mail soon after looking at it!

I will contact my family and friends and see if anyone saved their E-Maal and will then post the information here.

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL


1 edit
reply to crypto1969
Absolutely, being suspicious is always good practice. Especially since you and the others do not "qualify" for that mail.

My observation was only in regards to the link. I have ran across phishes that had malformed code that took you to the legitimate site and not the phish. If you look at the property/deatils/message source of the mail, you should be able to see if there are hidden re directs.

If you could post the header info from the email, XXX out your personal info, leaving the path and originating IP, then we may be able to establish if McAffe was the sender. They may also work through affiliates.

Based on what you have said, it is at least UCE.

MGD
Edit=added text

crypto1969

join:2004-02-23
Jacksonville, FL
reply to crypto1969
in addition, the E-Mail I received was sent to a different E-Mail to the one I used for my McAfee subscription. McAfee has never been given the address that I received that notification to.

crypto1969

join:2004-02-23
Jacksonville, FL
reply to MGD
Well, my suspicions were aroused by the fact that several of my family members and friends recived this same E-Mail today and none of them use McAfee products whatsoever. Plus the fact that I bought a subscription just 2 months ago.

MGD
Premium,MVM
join:2002-07-31
Fort Lauderdale, FL
reply to crypto1969
The link you posted goes to the mcafee.com domain and will take you to an IP addess registered to mcafee. Unless I am missing something, it does not appear to be a phish. Have you examined the html mail code for other links?

MGD

crypto1969

join:2004-02-23
Jacksonville, FL

Recived a seemingly legitimate E-Mail from MCAfee this evening with the text below:

Customer Note: This service notification is being sent to McAfee customers who are using an expired or unsupported VirusScan product that no longer receives anti-virus updates.

Recommended Action: Renew or upgrade your anti-virus protection today.

Dozens of new Internet threats come online every day. That's why uninterrupted PC protection is essential to keep your computer, email, downloads and attachments safe from new viruses, mass mailing worms, Trojans and spyware or unknown variants.

Remember, McAfee's proven security protects over 100 million computers worldwide. By renewing or upgrading, you'll enjoy the confidence of always-on, always up-to-date protection.

Sincerely,
McAfee, Inc.

The link the E-Mail contains takes you to this URL:
»us.mcafee.com/root/ar.asp?id=vs&···id=18018

The E-Mail looks very geuine and has all the right mCAfee logos but firstly the URL alerted me plus the fact that I only just took out a 1 year subscription to the product less than 2 months ago.

Has anyone else seen this Phishing E-Mail?
Forums » Up and Running » Security » Spam, Scam and PhishbustersTrouble Bubble LLC Collegeville? »
« How to get an infected PC shut down.  


Saturday, 28-Nov 22:13:04 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [71] Weekend Open Thread
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Why would I want an e reader? [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Why does it take so long? Mail question [General Questions]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· [Vista] Why is HD So Full? [Microsoft Help]