adwords scam email (new?)

Do you have a question? Post it now! No Registration Necessary.  Now with pictures!

Threaded View
Showed up in Inbox today:

Dear Advertiser,

We were unable to process your payment. Your ads will be suspended soon
unless we can process your payment. To prevent your ads from being
suspended, please update your payment information.

Please sign in
to your account at , and update your
payment information.

We look forward to providing you with the most effective advertising
available. Thank you for advertising with Google AdWords.
------------------------------------------------------- The Google AdWords
Team --

The url actually goes to ./

That url with the dot at the end loads a page that looks like AdWords, but
Opera protests the server's certificate doesn't match its hostname. Some
interesting headers:

Your ads are not running.
Microsoft Outlook, Build 10.0.2616

Oh, and BTW I have never used AdWords.

"Because all you of Earth are idiots!"
¯`·.¸¸.·´¯`·-> freemont© <-·´¯`·.¸¸.·´¯

Re: adwords scam email (new?)

On Tue, 24 Jun 2008 18:57:43 +0000, freemont put finger to keyboard
and typed:

Quoted text here. Click to load it

It looks like an example of Rule #3. My guess is that the attempted
phish was generated by a script which is supposed to add the actual
compromised site after the dot, thus generating a URL like this: /

(Except that it would probably have been obfuscated more than that)

This sort of bodged spam or phish is actually quite common. I see a
fair amount of spam addressed to "Dear %firstname %lastname", or
variants thereof, as well as broken phishing URLs. The real clues, as
always, are in the headers which mark it as non-genuine.

Stuff, some of it good, at
"Let's see colours that have never been seen"

Re: adwords scam email (new?)

Quoted text here. Click to load it

I've got it several times over last few weeks and as I, like you, have never
used adwords, it was easy enough to identify as a scam.

Site Timeline