# Is this another e-mail scam?  And what should I do about it?

**URL:** <https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135>\
**Category:** Factual Questions\
**Created:** [October 19, 2004, 11:57pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135 "2004-10-19T23:57:10Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![BrainGlutton](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@BrainGlutton](https://boards.straightdope.com/u/BrainGlutton)\
**Post date:** [October 19, 2004, 11:57pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/1 "2004-10-19T23:57:10Z")

</div>

I just got this e-mail:

> [@](#):
>
> Dear SunTrust Bank client:
> 
> Recently there have been a large number of identity theft attempts regarding SunTrust customers. In order to safeguard your account, we require that you confirm your banking details (credit card information and login/password for online banking, if you have).
> 
> This process is mandatory, and if not completed within the nearest time your account or credit card may be subject to immediate suspension.
> 
> To securely confirm you SunTrust bank details please follow the link:
> 
> [http://www.suntrust.com/personal/Checking/OnlineBanking/Internet\_Banking/security.asp](http://www.suntrust.com/personal/Checking/OnlineBanking/Internet_Banking/security.asp)
> 
> Thank you for your prompt attention to this matter and thank you for using SunTrust Bank!
> 
> Do not reply to this e-mail as it is an unmonitored alias.

I tried to copy-and-paste the above text but for some reason it’s impossible. Not only that, but even putting the mouse pointer in the text block opens the Internet link (which I closed before it could be finished).

I am not a customer of SunTrust Bank, by the way. Either this is a mistake, or it’s an attempt at identity theft.

Is there some law enforcement agency to which I can report this kind of thing?

---

<div class="post-metadata">

**Author:** ![percypercy](https://avatars.discourse-cdn.com/v4/letter/p/8baadc/32.png) [@percypercy](https://boards.straightdope.com/u/percypercy)\
**Post date:** [October 20, 2004, 12:03am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/2 "2004-10-20T00:03:32Z")

</div>

Yeah, it’s a hoax, a version of the Citibank one that’s been floating around for a while I guess. Here’s Suntrust’s page on it.

[http://www.suntrust.com/alert/index.asp](http://www.suntrust.com/alert/index.asp)

And a page with a copy of the email you received.

[http://www.doshelp.com/Scams-fraud/SunTrust-Scams.htm](http://www.doshelp.com/Scams-fraud/SunTrust-Scams.htm)

-Lil

---

<div class="post-metadata">

**Author:** ![GorillaMan](https://avatars.discourse-cdn.com/v4/letter/g/50afbb/32.png) [@GorillaMan](https://boards.straightdope.com/u/GorillaMan)\
**Post date:** [October 20, 2004, 12:03am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/3 "2004-10-20T00:03:53Z")

</div>

Unquestionably a scam.

What you’ve ended up posting here is the real link to the Suntrust page, which is what the scammer wants you to think you’re going to when you click on the link they provided. What will actually happen on following the link from the original email is you’ll be taken to a clone of the Suntrust page, run by the banker.

Here’s Suntrust’s page explaining what to do: [http://www.suntrust.com/alert/index.asp](http://www.suntrust.com/alert/index.asp)

---

<div class="post-metadata">

**Author:** ![Oat1957](https://avatars.discourse-cdn.com/v4/letter/o/bbe5ce/32.png) [@Oat1957](https://boards.straightdope.com/u/Oat1957)\
**Post date:** [October 20, 2004, 12:19am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/4 "2004-10-20T00:19:32Z")

</div>

There is Wells Fargo version as well.

[Wells Fargo](http://www.wellsfargo.com/privacy_security/email_fraud/report.jhtml)

---

<div class="post-metadata">

**Author:** ![Mr.Blue\_Sky](https://avatars.discourse-cdn.com/v4/letter/m/d26b3c/32.png) [@Mr.Blue\_Sky](https://boards.straightdope.com/u/Mr.Blue_Sky)\
**Post date:** [October 20, 2004, 12:21am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/5 "2004-10-20T00:21:45Z")

</div>

I got from Commerce Bank.

Never heard of them. The email spelled Commerce three different ways (all wrong).

---

<div class="post-metadata">

**Author:** ![ccwaterback](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@ccwaterback](https://boards.straightdope.com/u/ccwaterback)\
**Post date:** [October 20, 2004, 3:48am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/6 "2004-10-20T03:48:12Z")

</div>

Usually you can tell from the WWW address, but in this case they use [www.suntrust.com](http://www.suntrust.com). How can they do that? Have they hacked the Suntrust website and installed their “asp” file there?

---

<div class="post-metadata">

**Author:** ![Baraqiyal](https://avatars.discourse-cdn.com/v4/letter/b/ecccb3/32.png) [@Baraqiyal](https://boards.straightdope.com/u/Baraqiyal)\
**Post date:** [October 20, 2004, 4:00am UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/7 "2004-10-20T04:00:43Z")

</div>

It’s probably an embedded hyperlink. Instead of saying “Click Here”, it says [www.suntrust.com/whatever](http://www.suntrust.com/whatever). Just like how the following link doesn’t take you to the Straight Dope, but to Fark: www.straightdope.com.

---

<div class="post-metadata">

**Author:** ![The\_world\_s\_most\_deadliest](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@The\_world\_s\_most\_deadliest](https://boards.straightdope.com/u/The_world_s_most_deadliest)\
**Post date:** [October 20, 2004, 12:47pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/8 "2004-10-20T12:47:24Z")

</div>

> [@Baraqiyal](#):
>
> It’s probably an embedded hyperlink. Instead of saying “Click Here”, it says [www.suntrust.com/whatever](http://www.suntrust.com/whatever). Just like how the following link doesn’t take you to the Straight Dope, but to Fark: www.straightdope.com.

That’s exactly what it is. The entire message is a graphic (when I got my version, it was a .gif) and according to CitiBank’s website [http://www.citibank.com/domain/spoof/learn.htm](http://www.citibank.com/domain/spoof/learn.htm) clicking the “link” can begin a background installation of viruses or keylogging programs. I’d run a thorough scan of your computer just to be safe.

Here’s a fun activity: there should be a way to view all the headers on the email. Check out the **Received:** lines. There should be at least 2 seperate instances. The second one listed will probably have an IP address, like so:

> [@](#):
>
> Received: from [218.49.76.172] (helo=64.235.243.132)  
> by [cadillac.elinuxservers.com](http://cadillac.elinuxservers.com) with smtp (Exim 4.43)  
> id 1CJvlS-0005Dk-3N  
> for [myname@website.com](mailto:myname@website.com); Tue, 19 Oct 2004 08:19:07 -0700

That number that starts 218 is the IP address for the computer (or network) that originally sent the email. The From: line and the supposed email address it was sent from are spoofed. In this case, the IP address is associated with [hanero.com](http://hanero.com) (according to  
[spambag.org](http://www.spambag.org)), a known spammer. In any case, its obviously not affiliated in any way with CitiBank.

The same day, I got the same exact email, except it was supposedly from Sun Trust bank. This time, a search through [spambag.org](http://spambag.org) revealed the IP address was a Comcast IP address, meaning that one of Comcast’s internet subscribers was sending the email. Again, obviously not Sun Trust bank.

Also check out this link: [http://vil.mcafeesecurity.com/vil/content/v\_127728.htm](http://vil.mcafeesecurity.com/vil/content/v_127728.htm)  
(Explaination of the .eml attachment you often find on these kind of emails - I only knew it was attached to my CitiBank email when it bounced back from the CitiBack email address that I forwarded it to in order to report it.)

And finally, you can also forward the email to [spam@uce.gov](mailto:spam@uce.gov).  
Internet sleuthing can be fun! 😃

---

<div class="post-metadata">

**Author:** ![Colophon](https://avatars.discourse-cdn.com/v4/letter/c/f05b48/32.png) [@Colophon](https://boards.straightdope.com/u/Colophon)\
**Post date:** [October 20, 2004, 1:01pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/9 "2004-10-20T13:01:15Z")

</div>

> [@](#):
>
> Not only that, but \*\*even putting the mouse pointer in the text block opens the Internet link \*\* (which I closed before it could be finished).

I’m intrigued to know how this works - seems like very weird behaviour :dubious:

---

<div class="post-metadata">

**Author:** ![Colophon](https://avatars.discourse-cdn.com/v4/letter/c/f05b48/32.png) [@Colophon](https://boards.straightdope.com/u/Colophon)\
**Post date:** [October 20, 2004, 1:02pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/10 "2004-10-20T13:02:31Z")

</div>

Hmm, on second thoughts, do you mean **clicking** anywhere inside the “text block” (which is actually an image)? If so, that makes sense as the whole image is hyperlinked. I thought you meant that just moving the pointer into the area opened a link, which would be very odd indeed.

---

<div class="post-metadata">

**Author:** ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)\
**Post date:** [October 20, 2004, 2:09pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/11 "2004-10-20T14:09:01Z")

</div>

If you set your mail client to view all messages as plain text (which is what I do), then you can see right away if they have a hyperlink that takes you to a different server from the link’s text. Hyperlinks in these email scams typically point to a server with a numeric IP address.

---

<div class="post-metadata">

**Author:** ![CurtC](https://avatars.discourse-cdn.com/v4/letter/c/ce73a5/32.png) [@CurtC](https://boards.straightdope.com/u/CurtC)\
**Post date:** [October 20, 2004, 2:12pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/12 "2004-10-20T14:12:53Z")

</div>

Also, could a Javascript in an HTML email cause it to open the web page by hovering the mouse over the link? You should definitely set your email client up so that it doesn’t run Javascript in email messages. Also, if you do view messages as HTML, tell it not to load remote images, as sometimes images are used by the spammers for tracking who reads the messages. But IMHO, the best answer is just to view all messages as plain text. There are surprisingly few non-spam emails that can’t be read as plain text.

---

<div class="post-metadata">

**Author:** ![The\_world\_s\_most\_deadliest](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@The\_world\_s\_most\_deadliest](https://boards.straightdope.com/u/The_world_s_most_deadliest)\
**Post date:** [October 20, 2004, 2:15pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/13 "2004-10-20T14:15:21Z")

</div>

> [@Colophon](#):
>
> Hmm, on second thoughts, do you mean **clicking** anywhere inside the “text block” (which is actually an image)? If so, that makes sense as the whole image is hyperlinked. I thought you meant that just moving the pointer into the area opened a link, which would be very odd indeed.

You are correct - the entire image is hyperlinked. They just did a really good job at putting the text in the graphic so that it _looks_ like regular text.

---

<div class="post-metadata">

**Author:** ![jjimm](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jjimm](https://boards.straightdope.com/u/jjimm)\
**Post date:** [October 20, 2004, 2:17pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/14 "2004-10-20T14:17:43Z")

</div>

> [@Colophon](#):
>
> I’m intrigued to know how this works - seems like very weird behaviour :dubious:

JavaScript:

```auto

<A HREF="nasty.url" OnMouseOver="document.location='nasty.url';">www.suntrust.com</A>

```

---

<div class="post-metadata">

**Author:** ![The\_world\_s\_most\_deadliest](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@The\_world\_s\_most\_deadliest](https://boards.straightdope.com/u/The_world_s_most_deadliest)\
**Post date:** [October 20, 2004, 2:19pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/15 "2004-10-20T14:19:57Z")

</div>

> [@CurtC](#):
>
> Also, could a Javascript in an HTML email cause it to open the web page by hovering the mouse over the link? You should definitely set your email client up so that it doesn’t run Javascript in email messages. Also, if you do view messages as HTML, tell it not to load remote images, as sometimes images are used by the spammers for tracking who reads the messages. But IMHO, the best answer is just to view all messages as plain text. There are surprisingly few non-spam emails that can’t be read as plain text.

Yes, there is JavaScript that will open up a window when you mouse over the link.  
[http://www.as400pro.com/TipsHTML2.htm#4](http://www.as400pro.com/TipsHTML2.htm#4)

However, I’d imagine the only real use for it would be in the hands of spammers - code like that would be a nightmare if you try to use it in legitimate site design.

Your recommendations - shut off JavaScript, read email as plain text - are very good ones.

---

<div class="post-metadata">

**Author:** ![Mama\_Zappa](https://avatars.discourse-cdn.com/v4/letter/m/71e660/32.png) [@Mama\_Zappa](https://boards.straightdope.com/u/Mama_Zappa)\
**Post date:** [October 20, 2004, 2:38pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/16 "2004-10-20T14:38:15Z")

</div>

> [@ccwaterback](#):
>
> Usually you can tell from the WWW address, but in this case they use [www.suntrust.com](http://www.suntrust.com). How can they do that? Have they hacked the Suntrust website and installed their “asp” file there?

No - like the others have said, they’ve got the link displaying something other than the real destination of the link. I displayed the real URL one time to see where it led, and it led to “[www-suntrust.com](http://www-suntrust.com)”, so they’re getting cleverer (usually when I display the real URLs, it’s to something obviously fake like www dot stealyourmoney dot ru or 123 dot 345 dot 567 dot 89).

---

<div class="post-metadata">

**Author:** ![BrainGlutton](https://avatars.discourse-cdn.com/v4/letter/b/82dd89/32.png) [@BrainGlutton](https://boards.straightdope.com/u/BrainGlutton)\
**Post date:** [October 20, 2004, 2:40pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/17 "2004-10-20T14:40:44Z")

</div>

> [@Colophon](#):
>
> Hmm, on second thoughts, do you mean **clicking** anywhere inside the “text block” (which is actually an image)? If so, that makes sense as the whole image is hyperlinked. I thought you meant that just moving the pointer into the area opened a link, which would be very odd indeed.

The latter. I moved the mouse pointer over the text – and without my even clicking it, the pointer turned into a hand with index finger extended and the link-opening process began. They’re getting clever, aren’t they? :mad:

---

<div class="post-metadata">

**Author:** ![Colophon](https://avatars.discourse-cdn.com/v4/letter/c/f05b48/32.png) [@Colophon](https://boards.straightdope.com/u/Colophon)\
**Post date:** [October 20, 2004, 5:11pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/18 "2004-10-20T17:11:23Z")

</div>

> [@The world's most deadliest...](#):
>
> Yes, there is JavaScript that will open up a window when you mouse over the link.

This is too weird. I always get these SDMB coincidences, where I read of or hear of something hitherto unknow to me, and then _bam!_ I run straight into it again. I just came across this mouse-over trick for the first time ever, on a French hotel website I was checking for work: [http://www.jardinssecrets.net/](http://www.jardinssecrets.net/).

This within about 3 hours of first reading about it on here. Too weird.

---

<div class="post-metadata">

**Author:** ![Boldface\_Type](https://avatars.discourse-cdn.com/v4/letter/b/b5e925/32.png) [@Boldface\_Type](https://boards.straightdope.com/u/Boldface_Type)\
**Post date:** [October 20, 2004, 6:54pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/19 "2004-10-20T18:54:32Z")

</div>

> [@The world's most deadliest...](#):
>
> Your recommendations - shut off JavaScript, read email as plain text - are very good ones.

To do this is Outlook 2002, see the [Microsoft knowlege base](http://support.microsoft.com/default.aspx?scid=kb;en-us;307594).

---

<div class="post-metadata">

**Author:** ![Dragwyr](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dragwyr/32/2855_2.png) [@Dragwyr](https://boards.straightdope.com/u/Dragwyr)\
**Post date:** [October 20, 2004, 7:27pm UTC](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135/20 "2004-10-20T19:27:59Z")

</div>

On a related note, I read today in a security e-zine I get that [most phishing scams are from just a handful of people.](http://www.eweek.com/article2/0,1759,1679953,00.asp)

[Next page](https://boards.straightdope.com/t/is-this-another-e-mail-scam-and-what-should-i-do-about-it/270135.md?page=2)
