[FSec] Is that URL for real?

Newsfeed

Nachrichtenbote
Here's a fairly standard bank phishing email, targeting a bank in India:

rbi1.png


Nice touch with that "Beware of Phishing" warning...

Let's look at the attached HTML file:

rbi2.png


You got to be kidding me? The page has redirection to
http://amen.fr.softms.com.netwayexchange.com.liberty-textiles.org.v2nmobile.com.manchesteraircooled.com.blackcountrymortgages.com.cardiorenew-europe.com.solhosts.com.giveupthecigs.com.extravite.com.taxrepay.co.uk? That hostname can't possibly work...

Except it does.

rbi5.png


The redirection goes to reserve.bank.minecraftarena.fr. And the front page of minecraftarena.fr shows a fake "account suspended" message. Nice touch.

The phishing page looks like this:

rbi3.png


The ultimate target of the attack is to collect bank logins and credit card numbers:

rbi4.png


Thanks to Ravikiran for help.

On 20/09/11 At 08:23 AM

Weiterlesen...
 
Zurück
Oben