MEDIUM SEVERITYRESOLVEDVerified ReportPhishing

Phishing Email: PayPal Account Suspension

SecurityPro(Trust: 92%)
2024-01-12
Email
89
Upvotes
24
Comments
1,870
Views
45
Shares

Report Summary

Received email claiming PayPal account suspended. Link led to fake login page.

⚠️ Warning Signs Identified:

  • • Pressure to act quickly without time for consideration
  • • Requests for payment via unusual methods (gift cards, cryptocurrency)
  • • Poor grammar and spelling in communications
  • • Email addresses that don't match company domain

Full Report Details

PayPal Phishing Email Investigation

Email Details

Sender: security@paypal-support.com (spoofed) Subject: URGENT: Your PayPal Account Has Been Suspended Received: January 12, 2024, 9:15 AM

Phishing Analysis

Email Content

  • Professional-looking PayPal branding
  • Claimed "suspicious activity detected"
  • Urgent call to action: "Verify your account within 24 hours"
  • Fake customer service number included

Malicious Elements

  1. Link Analysis: Hover showed "paypa1-verification.com" (note digit '1' instead of 'l')
  2. Fake Login Page: Perfect replica of PayPal login
  3. Data Collection: Requested full credentials + credit card information
  4. 2FA Bypass: Fake page also asked for SMS verification codes

Technical Investigation

  • Domain Age: Registered 3 days before attack
  • SSL Certificate: Self-signed, browser warnings ignored by design
  • Hosting: Bulletproof hosting in uncooperative jurisdiction
  • Pattern: Similar to 15 other reports this month

Protective Actions Taken

  1. Immediate:
    • Did not click any links
    • Forwarded email to PayPal's fraud department
    • Reported to Quiet-Report platform
  2. Follow-up:
    • Enabled PayPal's security key feature
    • Set up transaction notifications
    • Educated family and colleagues

Impact

Users Protected: 47 (based on email sharing) Accounts Secured: Verified no unauthorized access Awareness Created: Shared in company security training

Technical Indicators of Compromise

  • IP: 185.162.131.104
  • ASN: 202425
  • Country: Netherlands
  • TTPs: Similar to "Silent Librarian" phishing group

Evidence Provided

📄
email-headers.txt
Click to view
🖼️
screenshot-1.png
Click to view
🖼️
screenshot-2.png
Click to view

Resolution

Type:

WARNING

Description:

Domain taken down, PayPal security team notified

Outcome:

Phishing kit disabled, warnings issued to affected users

Tags

#Phishing#Email#PayPal#Credential Theft#2FA Bypass

Reporter Information

Status:Verified User
Username:SecurityPro
Trust Score:92%
Reports Filed:12
Success Rate:85%

⚠️ Safety Tips

  • Never share personal information with unknown parties
  • Verify company credentials before making payments
  • Use secure payment methods with buyer protection
  • Report suspicious activity immediately

Experienced Similar?

Help protect others by reporting your experience