Determining Phishing Email

Received an Amazon email about a survey. Asked Amazon about the survey, rep said they have no record of sending me an email. For my own curiosity I copied some of the amazon hypertext links in the email and checked them out with virus total. Here’s the info for the hypertext link “Amazon Customer Service Help page”

https://www.virustotaldotcom/en/url/9873b5038eb51b533fa81d9b42e099cafc4baf265cb8d947514c381317b94d26/analysis/1479328282/

with the Final URL After Redirects:

https://www.amazondotcom/gp/help/customer/display.html/?nodeId=200896290&ref_=pe_2619750_215246050

and here’s the info for the Amazon Customer Service page URL at Amazon that I went to and copied myself:

https://www.virustotaldotcom/en/url/a9b9c09156797581093950890281d1ddfa96fae034fe3b5af7a0a22fa2a70eb9/analysis/1479328418/

with the Final URL After Redirects:

https://www.amazondotcom/gp/help/customer/display.html

What does the added URL text in the first/email link (?nodeId=200896290&ref_=pe_2619750_215246050) mean and do?

And why do both links have the same IP address resolution and HTTP response code but different HTTP Response Headers and Response content SHA256?

Finally the Survey link info at Virus Total is here:

https://www.virustotaldotcom/en/url/51d55fe6cb8f66f02372175a07b1f64120ee12a9a1053ad6bed8683edecaf33d/analysis/

And the Final URL After Redirects is:

http://www31.absolutdatadotcom/cgi-bin/ssiweb824/ciwweb.pl?hid_studyname=FF1&username=v2&hid_pagenum=1&hid_link=1&hid_javascript=1&r=F90D911C9C6BC977C70D798F9205A185&w=45&group=2

Does the 31 after WWW mean anything? Is there anyway to know from the URL what this web page is really about?

No viruses found by VirusTotal for any of these links.

Thanks

N

Does the 31 after WWW mean anything? Is there anyway to know from the URL what this web page is really about?
It is a survey
No viruses found by VirusTotal for any of these links.
And it will not as it is a blacklist check

See picture in top right corner, click to enlarge
http://urlquery.net/report.php?id=1479333254734
http://urlquery.net/report.php?id=1479333379503
http://urlquery.net/report.php?id=1479333537712

So you checked it out? Is it an Amazon survey? Can one be sure the survey isn’t some kind of phishing scheme itself?

Thanks.

N

I wanted to add that the email says it comes from Amazon.com store-news@amazondtcom which apparently is a legit email and when I hover over the Amazon.com it also says the email address is store-news@amazondotcom. Can a phisher forge a real email address like this?

see attached pic

You’re saying that URL and thus the survey is legit?

If you are in any doubt about its authenticity, save yourself a lot of time and delete it. I never respond to unsolicited email and this includes any surveys even if legit as I didn’t ask for it.

As far as Phishing emails go, are generally going to try and trick/scare you into giving out personal/security information. They usually have a link that whilst it appears to be for the site (in the subject of the email), but the underlying url will be for somewhere else.

Most likely they are going to try to get your banking details user and password, etc. No bank is going to ask you for that. Fear is what phishing email rely on, so you aren’t acting rationally.

I had one only a few days ago purporting to come from a bank that I use, it said that my account was restricted because of unusual activity, etc. etc. They wanted me to logon (via their link) to my account and because of the scare tactic many will do as is asked. I picked it up in my anti-spam software and it didn’t take long to see it wasn’t legit and was deleted at server level and never downloaded to my system.

Thanks. I was curious about this one and am trying to see if I can determine its true nature.

You’re welcome.

For me I never spend much time trying determine its nature, if it is unsolicited email its flagged as spam (to train the anti-spam application) and then it is gone.

Something else to be ware of in unsolicited emails, they may have images, etc. and these have to be imported (they aren’t embedded in the email). The act of being imported gives them information, a) that the email address is active and b) the recipient opened it.

These show they have a live person that is prepared to open the email, so your email will be sold on to other lists, more spam and or possible phishing attempts.

Okay, so I emailed an Amazon rep and she wrote back telling me they have no record of sending me such an email. I emailed absolutdata and we’ll see what they have to say.

My last question that maybe someone can answer is why the URL in the email link for the “About Amazon Customer Email Surveys” page has &ref_=pe_2619750_215246050 added to its tail as opposed to that page’s URL when arrived at by a Google search/hit:

URL from email link:

https://www.amazondotcom/gp/help/customer/display.html/?nodeId=200896290&ref_=pe_2619750_215246050

URL arrived at through Google search/hit:

https://www.amazondotcom/gp/help/customer/display.html?nodeId=200896290

Thanks.

So now you’ve confirmed to a whole bunch of folks that you’re a real person and you respond to email that’s basically crap.
Unsolicited email should never be answered. It’s trash. It’s hoping to find a victim. Don’t become one.
If it wasn’t something you asked for, throw it out.
One of the great things about Gmail is it’s ability to filter out almost all of this crap. It winds up in the Spam folder where it belongs.

When did I respond to the email in question? I said I emailed a rep at Amazon.

I use Gmail.

  1. This is an awful lot of time wasted on what is essentially unsolicited email - just get rid of unsolicited email - but it is your time to waste.

  2. Generally this will be some sort tracking.

Okay, so both of those pages are the same, not like a spoof page?

And I hear you. I always just toss a suspicious email but this one was so well done it caught my curiosity. Many times you can see the email is not from who is claimed or the text has simple grammatical errors but not here.

The “from” in a email doesn’t say a thing.
I can send you a email that appears to be coming from your own email address (if I wanted to do so ofcourse)
If you want to check where a email comes from, check the headers.

How would I do that with Gmail?

Gmail does allow me to “show original” where I can see data like Message ID, IP, received from, etc. although I suspect someone could fake some of that?

Email spoofing >> https://en.wikipedia.org/wiki/Email_spoofing

https://www.google.no/webhp?sourceid=chrome-instant&rlz=1C1JZAP_noNO713NO713&ion=1&espv=2&ie=UTF-8#q=how%20mail%20spoof%20work

https://www.lifewire.com/what-is-email-spoofing-2483501

Subtract the “Fire TV” and this is same email I received:

http://email-fakedotcom/get.pp.ua/smail/33f9a3c90e05a9a34b41e582c0a32890

Site was clean on virustotal:

https://www.virustotaldotcom/en/url/471359942b9fc5003b88723b458b66a27e742e3753c8f316610a7eee5c458a6f/analysis/

The virustotal site doesn’t actually scan sites for viruses in real-time (but checks various blacklists), so that isn’t a guarantee that it is ‘clean.’

That said your VT link is currently inaccessible.

Even if you replace “dot” with “.”? It’s working for me.