WOW! I got my refund from SARS today...

Question Tweety, was this near your actual refund or just a blind stab in the dark?

Reason I ask is that if a person is expecting a refund and the figure is close, I smell a fat rat.
 
That is scary to say the least! The average user wont know to check the url. Plus those pages look so very authenic!
 
Question Tweety, was this near your actual refund or just a blind stab in the dark?

Reason I ask is that if a person is expecting a refund and the figure is close, I smell a fat rat.


incidentally I am awaiting my refund but nothing close to this amount...
 
Wow that's scaley! But what can they do with your login details anyway?

I know with Standard Bank that if you need to do any payments to an unknown counterparty, you first need to enter a one time password sent to your cellphone.
 
Love their english:
"24 hours refund can be made to the listed banks below. If your bank is no listed, please contact us."
 
Lol... I clicked the ABSA bank link.
In the first textbox I typed:
F**K
Second Textbox:
YOU
Third:
C*N*S

Then it said Please wait while we verify, you will receive an sms with a pin bla bla bla ... then it says, please type in your one time pin to verify the login.

Very clever!!
People will type their one time pin in there, and then whoever is sitting there can quickly use those details to withdraw whatever they want.

How do we report this site to firefox?
 
P.S. After I typed F YOU in the one time pin, it goes back to the sars thing and says "Error, refund could not be completed, please try again later"
 
yeah this is fkcing scary actually...... alot of ppl dont even look at the site address.

this needs to be reported :eek:
 
I have mailed the hosting providers with the following:

You guys host a domain INSURRECTIONDATH.COM which is trying to defraud South African’s with their banking details, please note the following:

http://www.insurrectiondath.com/forums/language/da/SARS/SARS/index.html
http://www.insurrectiondath.com/forums/language/da/SARS/SARS/Absa/index.html

A traceroute points to the following:

ns1 ~]$ traceroute www.insurrectiondath.com
traceroute to insurrectiondath.com (67.220.196.131), 64 hops max, 40 byte packets
1 196.25.42.233 (196.25.42.233) 2.543 ms 1.779 ms 1.745 ms
2 196.25.165.53 (196.25.165.53) 249.744 ms 229.087 ms 177.575 ms
3 196.43.18.134 (196.43.18.134) 474.440 ms 370.527 ms 421.472 ms
4 pos2-0.cr02.ash01.pccwbtn.net (63.218.94.17) 466.452 ms 362.062 ms 395.194 ms
5 webnx.ge9-27.br01.lax05.pccwbtn.net (63.218.42.194) 470.390 ms 476.780 ms 558.425 ms
6 67-220-192-2.hosted.static.webnx.com (67.220.192.2) 429.244 ms 339.292 ms 307.300 ms
7 us-soho1-nix.xhostsolutions.com (67.220.196.131) 310.584 ms 319.507 ms 320.538 ms


Please take action ASAP!
 
I have reported the first one to OpenDNS as well, so they should start blocking it at some point.

You can go to http://www.phishtank.com/ to verify that it is in fact phishing. I think they need a few people to verify before they include in their lists/check it out..
 
The http://www.insurrectiondath.com/foru...ARS/index.html now has a 404 error.
Not Found

The requested URL /forums/language/da/SARS/SARS/index.html was not found on this server.

Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.
Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Server at www.insurrectiondath.com Port 80

The http://www.tnt.ba/components/com_fps...ARS/index.html gives me a nice warning
Reported Web Forgery!

This web site at www.tnt.ba has been reported as a web forgery and has been blocked based on your security preferences.

Web forgeries are designed to trick you into revealing personal or financial information by imitating sources you may trust.

Entering any information on this web page may result in identity theft or other fraud.
when using firefox.
 
Top
Sign up to the MyBroadband newsletter
X