Industry guru Dave Taylor offers tech support on technical and business topics, including iPhone, iPod, Microsoft Windows, Sony PSP, cellphones, online advertising, CSS, Web design, business, Unix, Linux, SEO, Mac OS X, and shell script programming.     


Did I just get a MySpace phishing attempt?

I'm pretty confused: I just got what looks like an email from MySpace that says "Jason" has sent me a song, but it points me to a completely different Web site. I attach the message: is it legit or are they phishing for my MySpace account information?


Dave's Answer:

Here's the message you sent me (in part):


From: "New MySpace Message" <monosporous@earthlinkbizdsl.com>
Subject: New message from Jason on MySpace sent on Oct 06 03:20:01 -4 2006
Date: Fri, 06 Oct 2006 08:29:42 +0100

You've got a new song from Jason on MySpace!

Click here to hear your MySpace music:
http://myspace.mp3shest.com/?reloc.cfm=6&id=3168

Click here to get 5-free songs downloaded to Your Space:
http://myspace.mp3shest.com/?reloc.cfm=6&id=316890419_5free

-------------------------

At MySpace we care about your privacy. We have sent you this
notification to facilitate your use as a member of the MySpace service. If
you don't want to receive emails like this to your external email account
in the future, change your Account Settings to "Do not send me
notification emails"

Click here to change your Account Settings:
http://myspace.mp3shest.com/?account.settings=update=6&id=3168

MySpace Inc. - 1900 Wilshire Blvd. 2109, Los Angeles, CA 90403-5400 USA

©2006 MySpace Inc. All Rights Reserved


It certainly looks like a message that MySpace would send out. In fact, when I have a new message on MySpace, the subject line indeed is identical, but a bit of digging reveals what's really going on...

Surprisingly, it's not a phishing attempt, though, it's just a sneaky way for a illegal music download archive site called Your MP3 Song to generate traffic.

I drew this conclusion by first recognizing that any site that would use a fake MySpace message to draw traffic, then digging around in the domain name records. After all, on first glance, it's not impossible that MySpace could own a music download service.

A quick visit to a DNS and whois server reveals, however, that the registrant for uxmp3.com is a chap out of Finland called Alex Rodrigez. I then plugged his phone number into Google and found this: phone search results.

If you check it out, you'll see that he's associated with reported phishing attempts on the German site phished.de and resellerratings.com.

Going back to the MP3 song site, there are a variety of things that set off alarms in my head, including no indication that there's a partnership with any record labels (which makes it hard to believe these are legal music copies), the surprisingly low pricing model ($0.10/song, which is less than the royalty on a given song according to Apple's breakdown of its $0.99/[legal!] song pricing model). The kicker, though? In the Terms of Service is this gem:

"All materials presented on this site are avaliable for the distribtution over the Internet in accordance with the license of the Russian Organization for multimedia and Digital Systems (ROMS) and intended for personal use only. Further distribution, resale or broadcasting is strictly prohibited."

and, my favorite part:

"The Client has no right to download Files from the archive of audio recordings of YourMp3Songs if this violates the law of his country. The Site Administration is not controling the Client's actions therefore the Client is reponsibile for any illegitimate use of the Site's materials."

Ah, well, I don't think that's quite accepted by the World Intellectual Property Organization or any other legal body. Indeed, it's the same problematic agreement that's behind the controversial AllofMP3.com, as you can read about on Google News.

Needless to say, it's not a phishing attempt and they're not trying to glom onto any of your MySpace information, but they are inappropriately using MySpace material to make you think it's a legit invitation and sign up for this doubtless illegal music download site.

My advice: just delete this sort of message and good job being vigilant enough to notice that the URLs were pointing to somewhere other than myspace.com before you clicked on them!


More Useful Twitter, LinkedIn and Social Network Help Articles:
✔   How do I search for a job on LinkedIn?
This may be a bit obvious, but I'm looking for work and am unclear how I can use LinkedIn to find positions other...
✔   Add a header graphic to my Twitter profile?
I heard from a colleague that Twitter's added profile pictures a la Facebook's timeline photo on the top. Nice, but how do I...
✔   Export LinkedIn Profile as a PDF Resume?
I've spent the last year or two updating and adding to my LinkedIn profile and it has a ton of information about me....
✔   How do I block an iPad app from accessing Twitter?
My son installed an app on my iPad and now it's posting updates on my Twitter account when he plays. What the deuce?...
✔   Repost a Facebook photo on Instagram?
I post a lot of photos on Facebook and sometimes want to share them with my Instagram followers. You can automatically mirror an...

Let's stay in touch!
Sign up for my weekly AskDaveTaylor Newsletter and you'll receive even more tech and gadget help right to your inbox, along with exclusive news and industry updates. It's good stuff. I promise!
    Enter your name: and your email addr:  




Categorized: Twitter, LinkedIn and Social Network Help   (Article 6908, Written by )
Tagged: allofmp3.com, illegal music downloads, myspace, phishing, wipo
Previous: How do I fix my Apple iPod: It's busted?
Next: Can I shrink the nav buttons in Microsoft Entourage?




Reader Comments To Date: 11

morgan said, on March 2, 2007 9:48 PM:

Hi,
if your myspace has been phished, what do you do to restore your myspace back to how it originally was?

morgan said, on March 2, 2007 9:48 PM:

Hi,
if your myspace has been phished, what do you do to restore your myspace back to how it originally was?

morgan said, on March 2, 2007 9:48 PM:

Hi,
if your myspace has been phished, what do you do to restore your myspace back to how it originally was?

nicole said, on April 2, 2007 3:13 AM:

hi whenever someone tries to comment me it says that my membership has been cancelled or my friendshipid is invalid what can i do?

grefdgfd said, on May 4, 2007 11:37 AM:

redfgfdg

try thay

tammy said, on May 26, 2007 4:32 AM:

Please help all the sudden i cant reply to my messages or accept friends

kassandra said, on July 2, 2007 9:14 PM:

i just wanted to know what do you do when the activation code doesn't show when your myspace has been hacked and your trying to change your password.

mycah said, on January 29, 2008 1:50 PM:

hey! my account got phished! i can't get my password even though they saty they will send it trough via email, or anything.....and i forgot my password! what in the heck do i do????? thank you! muuch appreciateed! mycah

lus duarte said, on February 19, 2009 3:52 PM:

i can't sign in myspace.how can i sign in,i'm a member since 2008,and now that i want to sign in i can't.can you help me?

shhhh said, on May 16, 2009 12:54 AM:

I recieved an email titled "Win a Ford Model Contract". Is this email legit, I researched it, found out something is going on like that, but it's not in my interest. I tried researching anything about a new Ford Model spyware/fishing email, but couldn't find anything. I never opened it, but deleted it from my inbox, then from my trash can. While I was researching it I did get involuntarily redirected to a site 3 times. I looked up Ford Model Contract on Myspace & it seems different than last night. Maybe it's just paranoia from recent events & insomnia. My guy is having current problems with some people that hacked into his myspace & then their's my ex-brother-in-law who's phishing around looking for my sister (who gave up & erased her account, but he'll probably keep phishing & try to find her again.)

enedina said, on May 26, 2009 11:57 AM:

i forgot my yahoo and myspace password can u help me get it send me any info to this email

Starbucks coffee cup I do have a lot to say, and questions of my own for that matter, but first I'd like to say thank you, Dave, for all your helpful information by buying you a cup of coffee!

I do have a comment, now that you mention it!











I will never send you any unsolicited email. Ever.






Check This Out Too...

 
Look for Answers
Need Help? Ask Dave Taylor!


Follow Me on Pinterest

Find Me on Google+
ADT on G+
© 2002 - 2013 by Dave Taylor. All Rights Reserved.

Note: This web site is for the purpose of disseminating information for educational purposes, free of charge, for the benefit of all visitors. We take great care to provide quality information. However, we do not guarantee, and accept no legal liability whatsoever arising from or connected to, the accuracy, reliability, currency or completeness of any material contained on this web site or on any linked site. Further, please note that by submitting a question or comment you're agreeing to my terms of service, which are: you relinquish any subsequent rights of ownership to your material by submitting it on this site. My lawyer says "Thanks".
"Ask Dave Taylor®" is a registered trademark of Intuitive Systems, LLC.