CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Charter One Phishing Scam

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Sat Mar 26, 2005 4:46 am    Post subject: Charter One Phishing Scam
Reply with quote

Date: Fri, 25 Mar 2005 21:13:35 -0500
From: Charter One Online Banking <jmdavis@charteronesecurities.com>
To: email removed
Subject: Online Customer Service

Charter One Bank Home Page

Dear Charter One Bank customer,

We recently reviewed your account, and suspect that your Charter One Bank Internet Banking accountmay have been
accessed by an unauthorized third party.
Protecting the security of your account and of the Charter One Bank network is our primary concern. Therefore, as a
preventative measure, we have temporarily limited access to sensitive account features.

To restore your account access, please take the following steps to ensure that your account has not been compromised:

1. Login to your Charter One Bank Internet Banking account. In case you are not enrolled for Internet Banking, you will
have to fill in all the required information, including your name and you account number.

2. Review your recent account history for any unauthorized withdrawals or deposits, and check you account profile to
make sure not changes have been made. If any unauthorized activity has taken place on your account, report this to
Charter One Bank staff immediately.

To get started, please click the link below:

http://www.charterone.com/home/

We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintain the integrity of
the entire Charter One Bank system. Thank you for attention to this matter.



Sincerely,

Charter One Bank Team

Please do not reply to this e-mail. Mail sent to this address cannot be answered. For assistance, log in to your
Charter One Bank account and choose the "Help" link in the header of any page.


| Member FDIC | Equal Housing Lender Charter One is an Equal Housing Lender | © 2005 Charter One Bank

_________________________

Above link directs to http://210.0.213.115/~chuihf/Secure/CHARTERONE/
_________________________

Headers from email:

Return-Path: <nobody@server145.6host.com>
Received: from server145.6host.com (ns1.6host.com [69.72.196.210])
by bugsbunny.castlecops.com (8.13.2/8.13.2) with ESMTP id j2Q2DOOe018361
for <email removed>; Fri, 25 Mar 2005 21:13:24 -0500
Received: from nobody by server145.6host.com with local (Exim 4.44)
id 1DF0nv-0005K9-27
for email removed; Fri, 25 Mar 2005 21:13:35 -0500
To: email removed
Subject: Online Customer Service
From: Charter One Online Banking <jmdavis@charteronesecurities.com>
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id: <E1DF0nv-0005K9-27@server145.6host.com>
Date: Fri, 25 Mar 2005 21:13:35 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - server145.6host.com
X-AntiAbuse: Original Domain - computercops.biz
X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]
X-AntiAbuse: Sender Address Domain - server145.6host.com
X-Source:
X-Source-Args:
X-Source-Dir:
X-NOD32Result: clean
X-Spam-Checker-Version: SpamAssassin 3.0.2 (2004-11-16) on
bugsbunny.castlecops.com
X-Spam-Level: **
X-Spam-Status: No, score=2.5 required=5.6 tests=BAYES_50,HTML_50_60,
HTML_EVENT_UNSAFE,HTML_MESSAGE,MIME_HTML_ONLY,NORMAL_HTTP_TO_IP,
REPLY_TO_EMPTY autolearn=no version=3.0.2
X-Spam-DCCB: SIHOPE-DCC-3
X-Spam-DCCR: bugsbunny.castlecops.com 1085; Body=1 Fuz1=1 Fuz2=1

Back to top
View users profile Send private message
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Mar 26, 2005 11:41 am    Post subject:
Reply with quote

This looks like the same one I received at work about two weeks ago.

Oldfrog said

Quote:
It looks from here like that site has already been shut down. Incidentally, while that address does belong to APNIC (Asia Pacific Network Information Centre) they have allocated it to KRNIC (Korea Network Information Center) which shows is to belong to

Quote:
Organization ID : ORG236154
Org Name : Oofbird
State : KYONGGI
Address : 447-28, Sinjang-dong, Hanam
Zip Code : 465-010

CastleCops Link/t111328-Charter_One_email_warning_unauthorized_bank_account_access.html

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Sat Mar 26, 2005 12:42 pm    Post subject:
Reply with quote

It may be the same email, but the URL must be different. This one is still live at the moment although Netcraft is blocking it and it has been reported elsewhere as well.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
quietman7

1st Responder Mentor
1st Responder Mentor

Joined: Sep 30, 2004
Posts: 3566
Location: Virginia, USA
1st Responder Mentors 1st Responders MVP Premium Rootkit Experts Security Experts

PostPosted: Sat Mar 26, 2005 12:51 pm    Post subject:
Reply with quote

Yea, the one I received came from Korea. The IP in the link in this one appears to be coming from Hong Kong.

Alas, why don't they target the Russians for a change?

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer