MacInTouch reader Douglas Broussard warns of a phishing scam that purports to be from Apple:

I just received a deceptively well-crafted e-mail from a sender purporting to be Apple, claiming that I have billing problems. The link in the e-mail goes to http://www.satc.net/https/.store.apple.com/us/, which does not appear to be a valid Apple URL.
The e-mail is well laid-out, and uses Apple’s graphics from the .Mac/.Me service. The title of the e-mail is: “IMPORTANT: Billing Problems”.
I received the e-mail just after buying a song from iTunes, so I was worried my account info may have been compromised, but after doing a little detective work, this appears to be a coincidence.
The long headers in the e-mails seems to indicate that “User (unknown [92.55.82.185]) by mail.decitre.fr ” is the sender. I requested that Apple add that IP/domain to its blacklist, since the headers opf the e-mail are forged and look as though the mail is coming from Apple.
Here are the headers. One easy tip off is the X-Mailer header; Apple doesn’t send e-mails using OUtlook Express 6 for Windows.
To see this information when you suspect an e-mail isn’t genuine, Click the View Menu, select Message, and choose Long Headers. Look for the “Received:” section, and see if it matches the purported sender in the “From:” field of the e-mail.

From: Apple
Date: July 9, 2008 11:05:39 AM PDT
To: undisclosed-recipients: ;
Subject: IMPORTANT : Billing Problem
Reply-To: no_reply@apple.com
Return-Path:

Received: from smtpin132.mac.com ([10.150.68.132]) by ms232.mac.com (Sun Java(tm) System Messaging Server 6.3-6.03 (built Mar 14 2008; 64bit)) with ESMTP id <0K3R00JIR3LAB8I0@ms232.mac.com>; Wed, 09 Jul 2008 11:05:34 -0700 (PDT)
Received: from mail.decitre.fr ([195.28.201.9]) by smtpin132.mac.com (Sun Java(tm) System Messaging Server 6.3-6.03 (built Mar 14 2008; 32bit)) with ESMTP id <0K3R008M63L7OO00@smtpin132.mac.com>; Wed, 09 Jul 2008 11:05:34 -0700 (PDT)
Received: from User (unknown [92.55.82.185]) by mail.decitre.fr (Postfix) with ESMTP id 0390E1B008CB; Wed, 09 Jul 2008 20:05:24 +0200 (CEST)
Mime-Version: 1.0
Content-Type: text/html; charset=Windows-1251
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-Msmail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-Mimeole: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <20080709180525.0390E1B008CB@mail.decitre.fr>

#No Responses to 'Warning of a phishing scam purportedly from Apple, Not'

There are no comments yet, why don't you leave one.

Leave a Reply