[Dshield] A well crafted PayPal forgery...

The scammers are getting better and better!

Looking at the message, the first thing that raised any suspicion was that the email originated from AOL. But if you trace back the Received: headers, they trace 'properly' back to PayPal. It could easily fool anyone that didn't have a lot of experience looking at such data.

The only give-away that it was a forgery was the fact the 'verify' link took you to a site in Japan.

Apologies for the HTML attachment, but you REALLY have to see this one... it is INCREDIBLE!

