Phishing Attempt - [Invitation] Attn: Beneficiary

| | Comments (0) | TrackBacks (0)

I've seen a number of Phishing attempts in my time, never one that had an attached 'invite.ics' file from Google Calendar. Since it came through as an Invitation, there were no full Internet Headers to trace the path.

I did save the 'invite.ics' file and opened it in Notepad. Here is that text.

BEGIN:VCALENDAR
PRODID:-//Google Inc//Google Calendar 70.9054//EN
VERSION:2.0
CALSCALE:GREGORIAN
METHOD:REQUEST
BEGIN:VEVENT
DTSTART:20080305T050000Z
DTEND:20080305T060000Z
DTSTAMP:20080304T174202Z
ORGANIZER;CN=patrick moore:MAILTO:patrickmoor2004 @ [removed].com
UID:ik2fh7vpcee0t4p13o347oho1c@google.com
ATTENDEE;CUTYPE=INDIVIDUAL;ROLE=REQ-PARTICIPANT;PARTSTAT=NEEDS-ACTION;RSVP=
 TRUE;X-NUM-GUESTS=0:MAILTO:keeper@psu.edu (this is my email)
CLASS:PRIVATE
CREATED:20080304T174158Z
DESCRIPTION:[removed]
LAST-MODIFIED:20080304T174158Z
LOCATION:
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:Attn: Beneficiary
TRANSP:OPAQUE
END:VEVENT
END:VCALENDAR

 

There were links that asked

Will you attend?

Yes |No |Maybe

 

In breaking down the links, they all went to the same address. Here they are in four parts.

 

http ://www.google.com/calendar/event?action=RESPOND&eid=

http: //www.google.com/calendar/event?action=RESPOND&eid=

http: //www.google.com/calendar/event?action=RESPOND&eid=

 

aWsyZmg3dnBjZWUwdDRwMTNvMzQ3b2hvMWMga2VlcGVyQHBzdS5lZHU

aWsyZmg3dnBjZWUwdDRwMTNvMzQ3b2hvMWMga2VlcGVyQHBzdS5lZHU

aWsyZmg3dnBjZWUwdDRwMTNvMzQ3b2hvMWMga2VlcGVyQHBzdS5lZHU

 

&rst=1&tok=MjUjcGF0cmlja21vb3IyMDA0QGdtYWlsLmNvbTRlOGM0ZWM1MTZlYT

&rst=2&tok=MjUjcGF0cmlja21vb3IyMDA0QGdtYWlsLmNvbTRlOGM0ZWM1MTZlYT

&rst=3&tok=MjUjcGF0cmlja21vb3IyMDA0QGdtYWlsLmNvbTRlOGM0ZWM1MTZlYT

 

g2YTRlOGZkZGEwYzZhMjY2OGRkZDQyNWExODA&ctz

g2YTRlOGZkZGEwYzZhMjY2OGRkZDQyNWExODA&ctz

g2YTRlOGZkZGEwYzZhMjY2OGRkZDQyNWExODA&ctz

 

=Pacific%2FHonolulu&hl=en

=Pacific%2FHonolulu&hl=en

=Pacific%2FHonolulu&hl=en

 

 

So in the classic shell game, any answer would have confirmed my email address as being "live" and could have been used for more Spam.

 

As further indication of human engineering, the Phisher is on Honolulu time. Lucky them.

 

Never seen one of these attempts. Interesting.  

 

 

 

0 TrackBacks

Listed below are links to blogs that reference this entry: Phishing Attempt - [Invitation] Attn: Beneficiary .

TrackBack URL for this entry: https://blogs.psu.edu/mt4/mt-tb.cgi/5218

Leave a comment

August 2009

Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          

Sign In