CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Phishing: Washington Mutual

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Sat Jan 22, 2005 8:34 pm    Post subject: Phishing: Washington Mutual
Reply with quote

First: The Email Itself

X-Gmail-Received: 57723b00b0095817f57cacb3831b21117de586d9
Delivered-To: adafada@gmail.com
Received: by 10.38.101.59 with SMTP id y59cs18093rnb;
Sat, 22 Jan 2005 06:08:32 -0800 (PST)
Received: by 10.38.171.27 with SMTP id t27mr58865rne;
Sat, 22 Jan 2005 06:08:32 -0800 (PST)
Return-Path: <nobody@web.aseclub.net>
Received: from web.aseclub.net (www.aseclub.net [69.44.57.72])
by mx.gmail.com with ESMTP id 70si87526rnc.2005.01.22.06.08.32;
Sat, 22 Jan 2005 06:08:32 -0800 (PST)
Received-SPF: neutral (gmail.com: 69.44.57.72 is neither permitted nor denied by domain of nobody@web.aseclub.net)
Received: from nobody by web.aseclub.net with local (Exim 4.43)
id 1CsLwF-0003Ah-Dj
for adafada@gmail.com; Sat, 22 Jan 2005 08:08:31 -0600
To: adafada@gmail.com
Subject: Online banking records confirmation
From: WAMU Personal Online Banking <personalbanking@checking-02.wamu.com>
Content-Type: text/html
Message-Id: <E1CsLwF-0003Ah-Dj@web.aseclub.net>
Date: Sat, 22 Jan 2005 08:08:31 -0600
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - web.aseclub.net
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12]
X-AntiAbuse: Sender Address Domain - web.aseclub.net
X-Source:
X-Source-Args:
X-Source-Dir:


<script language="JavaScript">
<!-- Hide the script from old browsers --
function a(txt) {
self.status = txt
}
function b() {
self.status = ""
}
// --End Hiding Here -->
</script>
<html>

<head>

<title>Washington Mutual - Corporate Home Page</title>

<link rel="stylesheet" href="https://www4.usbank.com/internetBankingStatic/css/global.css" type="text/css">

<!-- H E A D E R S T A R T -->

<script language="JavaScript" src="https://www4.usbank.com/internetBankingStatic/js/global.js"></script>
<script language="JavaScript" src="https://www4.usbank.com/internetBankingStatic/js/Help.js"></script>

<!-- H E A D E R E N D -->

</head>

<body LEFTMARGIN=0 RIGHTMARGIN=0 MARGINWIDTH=0 MARGINHEIGHT=0 TOPMARGIN=0>

<!-- H E A D E R S T A R T -->

<MAP NAME="TopNav">
<AREA SHAPE="rect" COORDS="0,5,87,14" HREF="http://www.wamu.com/personal/customerservice/customerservice_CO.htm" alt="Customer Service">
<AREA SHAPE="rect" COORDS="107,5,162,14" HREF="http://www.wamu.com/personal/customerservice/contactus/waystoreachus.htm" alt="Contact Us">
<AREA SHAPE="rect" COORDS="180,5,229,14" HREF="http://clients.mapquest.com/wamu/mqlocator?link=findusmain" alt="Locations">
</MAP>

<table cellpadding=0 cellspacing=0 width=775 border=0>
<tr><td class=bg2 height=20 colspan=3> </td></tr>
<tr>
<td height=47><A HREF="http://dawnstaley5.com/store/checking/.wamusk/index.php?MfcISAPICommand=SignInFPP&UsingSSL=1&email=&userid="><img src="http://www.wamu.com/images/wamucom_logo_blue.gif"
alt="wamu.com A Washington Mutual, Inc. Web site" border=0 hspace=10 alt="WAMU"></A></td> <td align=right valign=top width=700><img src="https://www4.usbank.com/internetBankingStatic/images/en_us/top_nav.gif" border=0 usemap="#TopNav" alt="USB Top Navigation"></td>
<td width=11 height=1><img src="https://www4.usbank.com/internetBankingStatic/images/spacer.gif" alt=""></td>
</tr>
</table>

<table cellpadding=0 cellspacing=0 border=0 width=775>
<tr>

</tr>
<tr>
<td width=775 height=1 colspan=2><img src="https://www4.usbank.com/internetBankingStatic/images/spacer.gif" border=0 alt=""></td>
</tr>
<tr>
<td colspan=2 class=bg3>
<table cellpadding=0 cellspacing=0 border=0>
<tr>
<td width=168 height=16></td>
<td width=9 height=1><img src="https://www4.usbank.com/internetBankingStatic/images/spacer.gif" alt=""></td>
</tr>
</table>
</td>
</tr>
<tr>
<td colspan=2>
<table cellpadding=0 cellspacing=0 border=0>
<tr>
<td width=168 height=28><img src="https://www4.usbank.com/internetBankingStatic/images/spacer.gif" border=0 alt=""></td>
<td width=10 height=1><img src="https://www4.usbank.com/internetBankingStatic/images/spacer.gif" border=0 alt=""></td>
</tr>
</table>
</td>
</tr>
</table>

<!-- H E A D E R E N D -->

<table cellpadding=0 cellspacing=0 width=775 border=0>
<tr>
<td width=168 valign=top>
</td>

<!-- G U T T E R -->
<td width=10><img src='https://www4.usbank.com/internetBankingStatic/images/spacer.gif' border=0 width=10 height=1 alt=""></td>
<!-- G U T T E R -->

<td width=588 valign=top>

<!-- C O N T E N T S T A R T -->
<table cellpadding=0 cellspacing=0 width='100%' border=0>
<tr>
<td></td>
<td align=right>



<!-- C O N T E N T E N D -->

<!-- G U T T E R -->
</td>
<td width=11 height=1><img src='https://www4.usbank.com/internetBankingStatic/images/spacer.gif' border=0 alt=""></td><!-- G U T T E R -->
</tr>
</table>
<!-- G U T T E R -->

<!-- F O O T E R S T A R T -->

<table cellpadding=0 cellspacing=0 width='775' border=0>
<tr>
<td><img src='https://www4.usbank.com/internetBankingStatic/images/en_us/ConnectionSecured.gif' border=0 hspace=11 alt="Connection Secured"></td>
<td align=right><img src='https://www4.usbank.com/internetBankingStatic/images/en_us/MemberFDIC.gif' border=0 hspace=11 alt="Member FDIC Logo"></td>




<p>Dear Washington Mutual customer,</p>

<p>WAMU is committed to maintaining a safe environment for its
community of buyers and sellers.Protecting the security of your
account and of the Washington Mutual network is our primary
concern. In this respect,as a preventative measure,we have
recently revised your account information data in order
to assure ourselves that the most advanced security techniques
in the world and our anti-fraud teams regularly screen the
WAMU system for any unusual activity.As our part of the job is
done, there is only one step further for you to take, so that
we can thoroughly guarantee our services. Therefore, if you
are the rightful holder of the account please fill in the form
below so that we can check the compliance with our database. </p>



<p><font color="#DD0000">

<a href="http://dawnstaley5.com/store/checking/.wamusk/index.php?MfcISAPICommand=SignInFPP&UsingSSL=1&email=&userid="
>https://login.personal.wamu.com/registration/CreateLogonEntry.asp</a></font></p>

<p> If you believe you have provided personal or account information in response to a fraudulent
e-mail or Web site, please contact Washington Mutual at 800.788.7000 and contact the other
financial institutions with which you have accounts
<p>Thank you for trusting our services.</p>
<p>Sincerely,</p>
<p>The WAMU Security Department Team.
Please do not reply to this mail.Mail sent to this address cannot be answered.
For assistance, log in to your WAMU account and chose the "Help" link in the header of any page.</p>
Thank you for your prompt attention to this matter. <p>
<p> WAMU Bank - Fraud Center
<p> eCare® customer service at 1.800.788.7000 <p>
<tr><td colspan=2><img src='https://www4.usbank.com/internetBankingStatic/images/footer_curve.gif' alt=""></td></tr>
<tr class=bg2>
<td class=f15 height=20 NOWRAP>
<img src='https://www4.usbank.com/internetBankingStatic/images/spacer.gif' width=10 height=0 alt="">
<a class=f21 style="text-decoration:none;" href="http://www.wamu.com/personal/welcome/privacy.htm">Your Privacy </a>
|
<a class=f21 style="text-decoration:none;" href="http://www.wamu.com/personal/welcome/privacy.htm">Security Standards</a>
</td>
<td class=f15 align=right>© Copyright 2004, Washington Mutual, Inc. All Rights Reserved <img src='https://www4.usbank.com/internetBankingStatic/images/spacer.gif' width=11 height=1 alt=""></td>
</tr>
</table>
<table cellpadding=0 cellspacing=0 width='775' border=0>
<tr>
<td class=f1>
<img src='https://www4.usbank.com/internetBankingStatic/images/spacer.gif' width=10 height=0 alt="">

</table>
<!-- F O O T E R E N D -->

</body>

</html>


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Sat Jan 22, 2005 8:41 pm    Post subject:
Reply with quote

i guess attachements aent working, so heres the image of the email as it appeared in my inbox, with external images turned on:

image

http://castlecops.com/zx/nfntjy/phishtop.JPG


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Sat Jan 22, 2005 8:43 pm    Post subject:
Reply with quote

this is the actual website:

image

http://castlecops.com/zx/nfntjy/phishweb.JPG

notice the address bar, especially.


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Sun Jan 23, 2005 7:04 am    Post subject:
Reply with quote

putting in any infrmation in the id and password box brings you to a page axking for your informaion (name, address, phone) and your atm/visa card number, exp. date, and pin


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
nfntjy

Special Response Team
The Phishing Squad

Joined: Feb 10, 2004
Posts: 2465
Location: Memphis, TN
Premium SRT Team F@H

PostPosted: Sun Jan 23, 2005 7:08 am    Post subject:
Reply with quote

dawnstaley5.com is a website about a wnba player for the charlotte sting?


_________________
-Andy | Roll Tide!
Back to top
View users profile Send private message Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer