its some kind of worm or virus and we tracked it to the source.
this is the phish mail exactly word for word. still digging deeper.
http://www.millersmiles.co.uk/report/1294
Please send us any scam/phishing emails you have received by clicking here.
If you have received the email below, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content, such as a different subject or return address, or with the fake webpage(s) hosted on a different webserver.
We aim to report every variant of the scams we receive, so even if it appears that a scam you receive has already been reported, please submit it to us anyway.
ACCOUNT ALERT
Date Reported: 26th September 2005 Whats this? Risk Level: MEDIUM Whats this?
Details
Apparent Sender:
Aol - See all Aol phishing scams Whats this?
Return Address:
<
[email protected] > Whats this?
Email Format: HTML Whats this?
URL of Web Content:
http://199.74.94.110:90/Confirmation_Sheet.pif Whats this?
Location:
US Whats this?
Comments:
* Email asks you to confirm/update/verify your account data at Aol by visiting the given link. You will be taken to a spoof website where your details will be captured for the phishers.
* Aol never send their users emails requesting personal details in this way.
* The REAL URL of the spoof website is disguised as "http://
[email protected]/confirm. php?email=aol.com".
* The spoof website this email links to was not online at time of this report, but variations of the scam which link to working websites are bound to exist, so be wary! The website may have been taken down or disabled by the hosts, but quite often these websites are hosted on the personal computer of the phishers, so may only be online at certain times.
* The REAL URL of the spoof website looks nothing like the actual Aol URL.
Content
Email:
"According to our terms of services, you will have to confirm your e-mail by the following link or your account will be suspended within 24 hours for security reasons."
Dear Valued Member,
According to our terms of services, you will have to confirm your e-mail by the following link or your account will be suspended within 24 hours for security reasons.
http://[email protected]/confirm. php?email=aol.com
After following the instructions in the sheet, your account will not be interrupted and will continue as normal.
Thanks for your attention to this request. We apologize for any inconvenience.
Sincerely,Aol Security Department
Website:
Spoof website not online at time of report...
started as an aol problem, but looks as if people are adopting the work/virus from this aol phish campaign.