Offshore banking

Mar 18, 2009 13 Replies

I got my first (solicited) email from an offshore bank relationship manager, which I intend to set up. As I've received so many scam emails before, can anyone who uses Natwest International Personal Banking confirm if the following IP address belongs to them so I can start transferring funds?



I get the results of a network lookup below but it would be great if someone can confirm it is legit as I will be transferring my life savings out of the UK.



Thanks.


213.167.72.29 is from United Kingdom(UK) in region Western Europe


Whois query for 213.167.72.29...



Results returned from whois.arin.net:


OrgName: RIPE Network Coordination Centre OrgID: RIPE Address: P.O. Box 10096 City: Amsterdam StateProv: PostalCode: 1001EB Country: NL



ReferralServer: whois://whois.ripe.net:43



NetRange: 213.0.0.0 - 213.255.255.255 CIDR: 213.0.0.0/8 NetName: RIPE-213 NetHandle: NET-213-0-0-0-1 Parent: NetType: Allocated to RIPE NCC NameServer: NS-PRI.RIPE.NET NameServer: NS3.NIC.FR NameServer: SUNIC.SUNET.SE NameServer: NS-EXT.ISC.ORG NameServer: SEC1.APNIC.NET NameServer: SEC3.APNIC.NET NameServer: TINNIE.ARIN.NET Comment: These addresses have been further assigned to users in Comment: the RIPE NCC region. Contact information can be found in Comment: the RIPE database at

formatting link
RegDate: Updated: 2005-07-27



# ARIN WHOIS database, last updated 2009-03-17 19:10 # Enter ? for additional hints on searching ARIN's WHOIS database.


Results returned from whois.ripe.net:



% This is the RIPE Whois query server #1. % The objects are in RPSL format. % % Rights restricted by copyright. % See

formatting link
% Information related to '213.167.72.0 - 213.167.72.31'



inetnum: 213.167.72.0 - 213.167.72.31 netname: RBSI descr: Royal Bank Of Scotland International country: GB admin-c: AW482-RIPE admin-c: FS13206-RIPE tech-c: FS13206-RIPE status: ASSIGNED PA notify: snipped-for-privacy@foreshore.net mnt-by: FORESHORE-MNT changed: snipped-for-privacy@foreshore.net 20021017 source: RIPE



role: FS ADMIN address: Foreshore Ltd address: The Powerhouse address: Queens Road address: St.Helier address: Jersey address: JE2 3AP, UK phone: +44 1534 752 300 fax-no: +44 1534 752 301 e-mail: snipped-for-privacy@foreshore.net remarks: trouble: Please email trouble reports to snipped-for-privacy@foreshore.net admin-c: CC530-RIPE admin-c: RO613-RIPE tech-c: DF2309-RIPE tech-c: SV1415-RIPE tech-c: DW789-RIPE nic-hdl: FS13206-RIPE remarks: This role is used for Admin and Technical Contacts notify: snipped-for-privacy@foreshore.net mnt-by: FORESHORE-MNT changed: snipped-for-privacy@foreshore.net 20050920 source: RIPE abuse-mailbox: snipped-for-privacy@foreshore.net



person: Andew Winup address: Royal Bank of Scotland International address: St.Helier address: Jersey address: Channel Islands address: GB phone: +44 1534 205290 e-mail: snipped-for-privacy@rbsint.com nic-hdl: AW482-RIPE mnt-by: FORESHORE-MNT changed: snipped-for-privacy@foreshore.net 20020306 source: RIPE



% Information related to '213.167.64.0/19AS13173'



route: 213.167.64.0/19 descr: Foreshore - Primary CIDR origin: AS13173 notify: snipped-for-privacy@foreshore.com mnt-by: FORESHORE-MNT changed: snipped-for-privacy@foreshore.com 20000419 source: RIPE



% Information related to '213.167.64.0/20AS13173'



route: 213.167.64.0/20 descr: Foreshore - traffic engineering routes origin: AS13173 notify: snipped-for-privacy@foreshore.com mnt-by: FORESHORE-MNT changed: snipped-for-privacy@foreshore.com 20041126 source: RIPE


Of course it's genuine. Banks are always sending out spam mails to attract customers.

Email headers can be forged, so the result would prove nothing.

If the email is solicited, addresses you by name and contains references to matters you have discussed with the bank by letter or telephone, it is unlikely to be bogus.

Why not telephone the bank (using a number you got from a directory lookup rather than from the email), ask to speak to the person who apparently sent the email, and ask him/her to verify that s/he did indeed send you an email on the date & time in question.

The OP stated that it was a solicited email - IOW *not* a spam.

A whois look up on RIPE resolves it to Royal Bank of Scotland International, Jersey CI.

The telephone number that the OP gives draws a blank.

It is true that (some) email headers can be forged. But you can also be sure about some of the headers because they will have been inserted by an MTA that you trust (for some definition of trust if you use someone elses MTA to receive your email and then collect it via pop3 or imap). This will include at least the last(top) Received: header.

Received: from 125310-batch1.tfl.deloitte.co.uk (125310-batch1.tfl.deloitte.co.uk [78.136.2.116] (may be forged)) by einstein.home.woodall.me.uk (8.14.3/8.14.3/Debian-5) with ESMTP id n2G29e5k002384 for ; Mon, 16 Mar 2009 02:09:41 GMT Received: from 125310-batch1.tfl.deloitte.co.uk (localhost [127.0.0.1]) by 125310-batch1.tfl.deloitte.co.uk (Postfix) with ESMTP id 17BB1710194 for ; Mon, 16 Mar 2009 02:09:35 +0000 (GMT) Date: Mon, 16 Mar 2009 02:09:35 +0000 (GMT)

I can be sure that this email came from 78.136.2.116 because my mailserver added that header. (That "(may be forged)" is because

125310-batch1.tfl.deloitte.co.uk does not resolve, not because the IP might be forged)

Tim.

So it is a *bit* dodgy then...?

Of course, if the tax lot can sell all their buildings to a tax dodge company and rent them back to save money, all that sort of thing must be OK for us mere mortals as well. No?

(125310-batch1.tfl.deloitte.co.uk [78.136.2.116] (may be forged))

The only mailserver that knows the originating (sender's) IP address is the first (outgoing) server that was chosen by the *sender*. If that server is compromised and substitutes a different IP address, none of the servers further down the line will know any different.

So the "trusted" server must be the outgoing server that the email sender has used, not the email server that *you* use to receive mail.

If the sender is bogus, then of course he will deliberately use a compromised outgoing mailserver!

(125310-batch1.tfl.deloitte.co.uk [78.136.2.116] (may be forged))

n2G29e5k002384

Yes. But RBS etc don't relay via random servers on the web, they send from their own servers. So you will see something like:

Received from ISP-INCOMING by ISP-POP Received from RBS-OUTGOING by ISP-INCOMING Received from RBS-USER-1234 by RBS-OUTGOING

If you trust your ISP then you can trust the first two headers. That means you know it came from RBS. (I'm assuming you've verified that RBS-OUTGOING has an IP address owned by RBS which is where this thread started)

Someone trying to forge an email could forge headers:

Received from RBS-OUTGOING by ISP-INCOMING Received from RBS-USER-1234 by RBS-OUTGOING

but now when they try and send it to your ISP your ISP will add another header:

Received from ISP-INCOMING by ISP-POP Received from FRAUDULENT by ISP-INCOMING Received from RBS-OUTGOING by ISP-INCOMING Received from RBS-USER-1234 by RBS-OUTGOING

The chain is broken

Or they could try:

Received from ISP-INCOMING by ISP-POP Received from FRAUDULENT by ISP-INCOMING Received from RBS-OUTGOING by FRAUDULENT Received from RBS-USER-1234 by RBS-OUTGOING

Now this time the chain looks good. You trust your ISP so you can be confident it came via FRAUDLENT. But as you don't trust FRAUDULENT you are suspicious that it didn't originally come from RBS.

(The first example of trying to forge headers is seen in spam. I doubt that they ever go to the trouble of trying to make the chain look good, they just try sticking an apparently good Received header at the bottom to try and throw off complaints to the wrong ISP. Maybe next time I get a phishing email I'll take a look and see what they're currently trying)

Tim.

Why not use the bank's secure online banking site, verified phone number or go to a branch?

What's the advantage of an off-shore account anyway? If you live in the UK, you still need need to pay tax.

It is impossible to say what possible advantage an offshore account may or may not have without knowing the OP's situation. For starters, perhaps he *doesn't* reside in the UK for tax purposes.

Well Nat West is a subsidiary of RBS.

If you have money in RBS or HBOS you might be advised to move to another dodgy foreign* bank...

  • as in not English

You've received a message without a digital signature, let alone one signed with a high trust certificate, and checked by a browser with known provenance. You are not an expert in internet security. I would suggest you can have low to medium confidence.

The realistic risk depends on to what extent someone thinks it worth targeting you, or the bank.

If you have any doubt at all, go to a major reference library and look up the phone number of the bank in a paper or microfiche phone directory, then call them and check. If you are feeling paranoid, make the call from a random phone, not near to your home or office.

You might want to note that, in my experience, banks do not trust emailed instructions and will only trust faxed ones by prior arrangement.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required