paypal or AV going nuts?

Forum for getting help with Project Gamera, Spamassassin, Clamav, qmail-scanner and other anti-spam tools.
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

paypal or AV going nuts?

Unread post by faris »

I received an email today, supposedly from PayPal. Although the content was legit, with no fake/spoofed domains and no instructions to do anything silly, when I examined the header I was convinced it was a phish. Take a look:

Code: Select all

Received: from mx0.slc.paypal.com (mx0.slc.paypal.com [173.0.84.225])
	by redacted (Postfix) with ESMTP id 6120840E15
	for <redacted>; Thu, 21 Feb 2013 11:09:29 +0000 (GMT)
MaxCode-Template: appeals-request-more-info
content-type: text/plain; charset=utf-8
X-XPT-XSL-Name: email_attack/default/en_GB/account/security/AppealsRequestMoreInfo.xsl
X-Email-Type-Id: PP821
X-managedapps-av01-MailScanner-SpamCheck: not spam, SpamAssassin (not cached,
	score=-4.585, required 6, FILL_THIS_FORM_FRAUD_PHISH 0.40,
	RCVD_IN_DNSWL_HI -5.00, SPF_PASS -0.00, T_DKIM_INVALID 0.01,
	T_FILL_THIS_FORM_SHORT 0.01)
Received-SPF: pass(paypal.co.uk: domain of
	pp._spf.paypal.com designates 173.0.84.225 as permitted sender)
The key thing that rang all my alarm bells was this line:

Code: Select all

X-XPT-XSL-Name: email_attack/default/en_GB/account/security/AppealsRequestMoreInfo.xsl
But as a precaution, I logged in to PayPal (using normal methods -- no files were opened, no links clicked, even the email I'm quoting wasn't actually opened -- I was examining the raw text form of it while it was still in the mailbox) and what do you know -- I get a message saying they want more information, with the same reference as in the email. Eveything about the site was legit -- it had all my account history, my details, EV cert in place, etc etc. I then checked on my mobile (mobile network, different DNS etc etc, has different AV) and got the same message on login. So for this to be a spoof then ... boy oh boy am I in trouble, because I'm absolutely fooled and they have managed to get malware on two PCs and on my mobile, all just to get photo ID from me.

Even so, I just can't see any way to explain away the email_attack/default/en_GB/account/security/AppealsRequestMoreInfo.xsl

Any suggestions?
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
prupert
Forum Regular
Forum Regular
Posts: 573
Joined: Tue Aug 01, 2006 2:45 pm
Location: Netherlands

Re: paypal or AV going nuts?

Unread post by prupert »

A little while ago we got a similar message from PayPal, asking for additional proof of identification.

I have found that they used the exact same header rules. I actually contacted PayPal by phone at that time because it worried me as well.

Code: Select all

X-XPT-XSL-Name: email_attack/default/nl_NL/account/security/AppealsRequestMoreInfo.xsl
X-Email-Type-Id: PP821
So, it's legit.
Lemonbit Internet Dedicated Server Management
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Re: paypal or AV going nuts?

Unread post by faris »

That's good to know. Thanks. But darned strange!
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
Post Reply