Paypal Phishing attempts via and and from –

  1. they are changing the final destination url several times a day: When I posted this comment the destination was “” Not the different folder that holds the phish. previously it was ” /upg/ ”

    this is being done to try to stop Microsoft, Mozilla & Google chrome blocking the phishing site. These browsers and the underlying technology will only block the full URL not the base domain. This is because often the sites or the servers hosting the sites have been hacked or compromised

  2. This has been updated yet again to use as the eventual landing site and the link in the email will be to ( the img folder changes frequently to another folder name)

