I’m pretty confused: I just got what looks like an email from MySpace that says “Jason” has sent me a song, but it points me to a completely different Web site. I attach the message: is it legit or are they phishing for my MySpace account information?
Here’s the message you sent me (in part):
From: “New MySpace Message” <monosporous@earthlinkbizdsl.com>
Subject: New message from Jason on MySpace sent on Oct 06 03:20:01 -4 2006
Date: Fri, 06 Oct 2006 08:29:42 +0100
You’ve got a new song from Jason on MySpace!
Click here to hear your MySpace music:
http://myspace.mp3shest.com/?reloc.cfm=6&id=3168
Click here to get 5-free songs downloaded to Your Space:
http://myspace.mp3shest.com/?reloc.cfm=6&id=316890419_5free
————————-
At MySpace we care about your privacy. We have sent you this
notification to facilitate your use as a member of the MySpace service. If
you don’t want to receive emails like this to your external email account
in the future, change your Account Settings to “Do not send me
notification emails”
Click here to change your Account Settings:
http://myspace.mp3shest.com/?account.settings=update=6&id=3168
MySpace Inc. – 1900 Wilshire Blvd. 2109, Los Angeles, CA 90403-5400 USA
©2006 MySpace Inc. All Rights Reserved
It certainly looks like a message that MySpace would send out. In fact, when I have a new message on MySpace, the subject line indeed is identical, but a bit of digging reveals what’s really going on…
Surprisingly, it’s not a phishing attempt, though, it’s just a sneaky way for a illegal music download archive site called Your MP3 Song to generate traffic.
I drew this conclusion by first recognizing that any site that would use a fake MySpace message to draw traffic, then digging around in the domain name records. After all, on first glance, it’s not impossible that MySpace could own a music download service.
A quick visit to a DNS and whois server reveals, however, that the registrant for uxmp3.com is a chap out of Finland called Alex Rodrigez. I then plugged his phone number into Google and found this: phone search results.
If you check it out, you’ll see that he’s associated with reported phishing attempts on the German site phished.de and resellerratings.com.
Going back to the MP3 song site, there are a variety of things that set off alarms in my head, including no indication that there’s a partnership with any record labels (which makes it hard to believe these are legal music copies), the surprisingly low pricing model ($0.10/song, which is less than the royalty on a given song according to Apple’s breakdown of its $0.99/[legal!] song pricing model). The kicker, though? In the Terms of Service is this gem:
“All materials presented on this site are avaliable for the distribtution over the Internet in accordance with the license of the Russian Organization for multimedia and Digital Systems (ROMS) and intended for personal use only. Further distribution, resale or broadcasting is strictly prohibited.”
and, my favorite part:
“The Client has no right to download Files from the archive of audio recordings of YourMp3Songs if this violates the law of his country. The Site Administration is not controling the Client’s actions therefore the Client is reponsibile for any illegitimate use of the Site’s materials.”
Ah, well, I don’t think that’s quite accepted by the World Intellectual Property Organization or any other legal body. Indeed, it’s the same problematic agreement that’s behind the controversial AllofMP3.com, as you can read about on Google News.
Needless to say, it’s not a phishing attempt and they’re not trying to glom onto any of your MySpace information, but they are inappropriately using MySpace material to make you think it’s a legit invitation and sign up for this doubtless illegal music download site.
My advice: just delete this sort of message and good job being vigilant enough to notice that the URLs were pointing to somewhere other than myspace.com before you clicked on them!
i forgot my yahoo and myspace password can u help me get it send me any info to this email
I recieved an email titled “Win a Ford Model Contract”. Is this email legit, I researched it, found out something is going on like that, but it’s not in my interest. I tried researching anything about a new Ford Model spyware/fishing email, but couldn’t find anything. I never opened it, but deleted it from my inbox, then from my trash can. While I was researching it I did get involuntarily redirected to a site 3 times. I looked up Ford Model Contract on Myspace & it seems different than last night. Maybe it’s just paranoia from recent events & insomnia. My guy is having current problems with some people that hacked into his myspace & then their’s my ex-brother-in-law who’s phishing around looking for my sister (who gave up & erased her account, but he’ll probably keep phishing & try to find her again.)
i can’t sign in myspace.how can i sign in,i’m a member since 2008,and now that i want to sign in i can’t.can you help me?
hey! my account got phished! i can’t get my password even though they saty they will send it trough via email, or anything…..and i forgot my password! what in the heck do i do????? thank you! muuch appreciateed! mycah
i just wanted to know what do you do when the activation code doesn’t show when your myspace has been hacked and your trying to change your password.
Please help all the sudden i cant reply to my messages or accept friends
redfgfdg
try thay
hi whenever someone tries to comment me it says that my membership has been cancelled or my friendshipid is invalid what can i do?
Hi,
if your myspace has been phished, what do you do to restore your myspace back to how it originally was?