Saturday, December 15, 2007

Phisherman Spoofs Athenet

Today's latest phishing attempt is attempting to spoof Athenet and I finally receive a phishing scam that targets appropriately.

It is a very poor attempt, I am not going to go into the specifics of why this phishing attempt despite accurate targeting fails so poorly. I do not want to provide feedback on the attempt to the perpetrators.

In any event I will forward the note to NTD/Athenet and they can deal with it.

Labels:

Monday, September 03, 2007

A Phishy Note

I absolutely love the phishing note I received this morning! They start off by warning us of – yes you guessed it – phishing scams!

I love the line Failure to authenticate, your account may result in account malfunction, slow online expericence or even exposeure of sensible data. Think it a legitimate message, of course not! People pulling these attempts off really should troll around for starving writers to help with the editing.

Dear JPEFCU member,
Due to the recent pishing attacks targeting Jefferson Parish Employees Federal Credit Union,
we are currently launching a new security system that will improve the level of
member service we can provide to you.

In order to update your account and benefit from new facilities, click here to login.
To enhance the security when accessing your online accounts, we implemented
an additional layer to our system called Secure4U.

You may be requested to answer a few security questions in order to complete your login
to our Online Banking.

Failure to authenticate, your account may result in account malfunction, slow online expericence or even exposeure of sensible data.

Labels:

Monday, June 04, 2007

Slick Phishing Attempt

Another day another phishing note.

Activate your card now

You may activate now by entering your card number over our secure server. If your card issuer is participating in Verified by Visa (most issuers are) you’ll complete a brief activation process. You’ll verify your identity, create your Verified by Visa password and you’re done Start using verified by Visa

Visa’s multiple layers of security provide cardholders with an extraordinary level of protection so they can feel confident no matter how they use their Visa card. Verified by Visa plays an important role in this strategy in the following ways:
a) Improving the security of online payment transactions
b) Increasing both cardholder and merchant confidence in Internet purchases
c) Reducing disputes and fraudulent activity related to Visa payment cards

Simply activate your existing card at First National Bank in Manitowoc 4727-86XX-XXXX-XXXX with the Verified by Visa service and create your personal password.

The service is free to Visa cardholders.
You’ll have the added assurance that your Visa card is safer when you shop at participating online stores
Source: Phishing Attempt E-Mail
The First National Bank of Manitowoc once again serves as a bait, however it is not the hook. The link provided (not included above) first off does not work as intended but when you type in the URL yourself it sends you to a very slick looking & convincing (at least by the superficial appearance) site to register your visa card.

Again, there are many hints in the note pointing out the true nature of the note. I did some searching on the address provided in the link and it shows up in some scam databases out there.

I do not know how Outlook handles web links embedded in e-mail but below is a screen shot of my client with the mouse over the link provided:

Notice, in the lower left corner? That site does not appear to have anything to do with banking or finances.

Updates:
  • 8:44 pm June 4, 2007

  • One phishing site shut down:

    Thank you Marcus.
    Site has been shut down per Yahoo!

    Kelly
    Source: E-mail from First National Bank of Manitowoc

    Labels:

    Thursday, May 24, 2007

    Today's Phishing Attempt

    Starts off:
    > Dear Customer,

    > The First National Bank of Manitowoc Online department temporary disabled your account.

    After three unsuccessful login attempts your account was temporary disabled until further investigations.

    All cards from this account are suspended.

    You must reactivate your account at First National Bank of Manitowoc immediately, or you won't be able to use your cards again.
    Source: From phishing attempt e-mail received on Thursday May 24, 2007


    The URL the phishing attempt tries to get you to click on is http://www.bankfirstnational.com/banking/unsuspend.shtml but is anchored to a site at: firstmanitowoc.com which is registered to:
    Domain Name.......... firstmanitowoc.com
    Creation Date........ 2007-05-24
    Registration Date.... 2007-05-24
    Expiry Date.......... 2008-05-24
    Organisation Name.... OWEN TAYLOR
    Organisation Address. 136 FM 1746
    Organisation Address.
    Organisation Address. WOODVILLE
    Organisation Address. 75979
    Organisation Address. TX
    Organisation Address. UNITED STATES

    Admin Name........... OWEN TAYLOR
    Admin Address........ 136 FM 1746
    Admin Address........
    Admin Address........ WOODVILLE
    Admin Address........ 75979
    Admin Address........ TX
    Admin Address........ UNITED STATES
    Admin Email.......... firstmanitowoc@yahoo.com
    Admin Phone.......... +1.4092837981
    Admin Fax............

    Tech Name............ YahooDomains TechContact
    Tech Address......... 701 First Ave.
    Tech Address.........
    Tech Address......... Sunnyvale
    Tech Address......... 94089
    Tech Address......... CA
    Tech Address......... UNITED STATES
    Tech Email........... domain.tech@YAHOO-INC.COM
    Tech Phone........... +1.6198813096
    Tech Fax.............
    Name Server.......... yns1.yahoo.com
    Name Server.......... yns2.yahoo.com
    Source: Whois.net whois lookup of firstmanitowoc.com
    I have found most of these attempts come from overseass, I am shocked to find a phishing scam arising from the USA.

    Updates:
    Looking at the e-mail headers I see this note coming to me from 213.193.223.109 (Link takes you to Project Honey Pot) reportedly from The Netherlands via system in Australia – 210.8.99.128 (again this link takes you to Project Honey Pot's entry on the IP).

    FYI, whois information is easy to fake up. The phishermen probably got a hold of some poor sap's information and used that. This is the second spoof of the First National Bank I have received.

    Labels:

    Friday, May 04, 2007

    Flagstar Bank Customers Targeted for Phishing

    I just received multiple attempts to scam personal financial information. The scam spoofs Flagstar bank (which does have the reported contest going on) and tries to make you click on a link which directs you to www.zakerin.biz ( an Arabic website) site that spoofs the Flagstar survey.

    Being I am not a Flagstar Bank customer and have never heard of the bank I immediately suspected the scam and doing the mouse float over the links the classic signs of phishing were apparent.

    I have alerted Flagstar Bank of this situation.

    Labels: