lovingboth: (Default)
Ian ([personal profile] lovingboth) wrote2005-01-17 11:33 am

"Please give us all your banking details, including passwords..."

All the usual 'this is a scam' signs: odd 'from' address, the HTML bit of the email is a single .gif, called aunt.gif! The non-HTML is 'get me through the spam filters' gibberish: "Animated Graphics Firestone Tires I'd like to see you in 1868". The language used is not that of a native English speaker:

Dear client of the Halifax Internet banking,
[..] We earnestly ask you to visit the following link and to confirm your bank data: [..] This instruction has been sent to all bank customers and is obligatory to follow
Please do not answer to this email [..]


Ok, let's see what the purported link of https://www.halifax-online.co.uk/ etc actually is.

Gosh, it really is https://www.halifax-online.co.uk/ etc, none of this 'genuine-looking-address@dodgy-one' or 'IP-address/genuine-looking-rest' stuff.

OK, let's do a whois.

Domain Name: halifax-online.co.uk

Registrant: Halifax plc


Yeah, yeah, that's what they all say.

Administrative Contact's Address: Inca Research Inc, Victoria Chambers, Fir Vale Road, Bournemouth, BH1 2JN.


Ha! Well, there are some companies that let their suppliers manage their domains, but an Inc (rather than Ltd or plc) in the UK?

Relevant Dates: Registered on:  26-Apr-1999


But gosh. If this were a 'let's register a plausible sounding domain name and see who bites' scam, you'd have expected Halifax to have stomped on them years ago.

A check of Nominet's dispute registration scheme does show that Inca are real but have have been naughty in the past.

OK, let's be brave and look at halifax-online.co.uk - hmm, the certificate is valid, the site looks genuine. The IP address is 212.140.245.11 vs 212.140.245.97 for halifax.co.uk, too.

Gosh. Have I been spammed by a dodgy email that actually points to a genuine site?

[personal profile] tempaccount99 2005-01-17 11:35 am (UTC)(link)
Yup, Halifax-online.co.uk is the genuine URL for halifax internet banking. How very strange...
ext_9215: (Default)

[identity profile] hfnuala.livejournal.com 2005-01-17 11:37 am (UTC)(link)
There's probably spyware in there somewhere - they want you to log onto the genuine site so they can collect your login data.

[identity profile] ciphergoth.livejournal.com 2005-01-17 11:39 am (UTC)(link)
Maybe you are looking at the text version of the email, and the HTML one says [a href=dodgy-site]legitimate-link[/a] ?
vampwillow: (Default)

[personal profile] vampwillow 2005-01-17 12:19 pm (UTC)(link)
I've noticed that quite a few spam mails actually include links to the 'real' site. I've assumed it is so that you transfer the trust from one to the link they give you ...

If in doubt...

[identity profile] pavlos.livejournal.com 2005-01-18 02:51 am (UTC)(link)
Using Firefox (or Mozilla) go to Tool->Page Info->Security and look at the company to whom the HTTPS certificate is issued. For https://www.halifax-online.co.uk/ it's Hbos Plc.