CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

A Trend?

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sat Jan 22, 2005 10:40 pm    Post subject: A Trend?
Reply with quote

Over the last 2 months or so I have seen more and more of the "financial institution" phishing emails arriving with several things in common.

1) The visible portion of the email is not HTML but one large .gif image. The image itself is sent using 64bit encoding. Viewing the entire source of the email reveals that the image is mapped and is essentially a giant clickable link leading to the bogus website. The image portrays a legitimate URL for the financial institution in question and a right click and copy of the link location also yields the legitimate URL. Clicking anywhere on the image, however, takes one to a bogus site.

2) The bogus URL's all follow the same general pattern of http://xxx.xxx.xxx.xxx:87/(code)/(page)
where:
xxx.xxx.xxx.xxx is an IP address
87 is the port number being used (all so far are using 87)
(code) is a one or two letter code denoting the financial institution, and
(page) is the target page with seems to vary between index.htm and login.htm

It strikes me that this makes for a very streamlined and flexible package.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sun Jan 23, 2005 8:03 am    Post subject:
Reply with quote

It makes me think that these are all originating from the same sleazebag.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sun Jan 23, 2005 2:17 pm    Post subject:
Reply with quote

Quote:
It makes me think that these are all originating from the same sleazebag

I was thinking more "sleazebags".


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Mon Jan 24, 2005 1:20 am    Post subject:
Reply with quote

just like i can go download phpbb and phpnuke packages for my website, there may be packages with easy-to-follow intructions on how to set up a site like this.i bet you could find them if you had kazaa or something on your computer. scary.


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer