register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

MSN- 'Warning Message'
27-Jan-2005

Summary
Email title: 'Banking Online customer Report'
Scam target: MSN users
Sender:

"MSNSuspending Updating" <access@msn.net>

Sender spoofed/hidden? Spoofed
Phish 'punch line' : 'During one of our regular automated verification procedures we've encountered a some problem caused by the fact that we could not verify the info that you provided to us. Please, give us the following information so that we could fully verify your identity. Otherwise your access to MSN services will be closed'
Scam goal: Getting victim's credit/debit card information, MSN username/password, various other personal data
Phish link method URL link
Link 'masked'? No
Visible link: http://www.msnassistance.com/index.php
Actual link to: http://www.msnassistance.com/index.php
Phish website IP:

68.142.234.41

 
E-mail
 

This phish marks a comeback of a particularly dangerous and convincing deception strategy.

The email in this instance is not the most legitimately looking piece:

 
 
It is way too brief and lacking in legitimate attributes. Nonetheless, the sender is spoofed and the link looks affiliated with msn.com, though it is not.
 
Web Site
Visible link: http://www.msnassistance.com/index.php
Actual link to: http://www.msnassistance.com/index.php
Phish website IP:

68.142.234.41

 
When the link in the email is clicked, the legitimate MSN site opens in the background. But in the foreground, as a pop-up window, the phish page opens:
 
 

This approach is very dangerous for two reasons:

  • The use of very similar design in the two pages creates a sense of link between them, and the victim can easily be misled into trusting the phish page.
  • The pop-up window has no address bar, so no suspicious URL will be displayed by the fraudulent page. Yet, the URL is visible in the 'propertiesp page (accessible via the context menu).

The scam page leads the potential victim through several pages, mimicking a legitimate practice:

 
 
Then the next one:
 
 

The site will check whether the fields contain the required number of symbols, but no further checking will be done. An error page will be shown if the form 'dislikes' the amount of symbols in the 'credit card number' field, for example.

At the end, a logout page is displayed:

 
 
The other major clue of phishing comes from the lack of indication of a secure HTTPS session in the transfer of information.
 
WHOIS information (for IP 68.142.234.41):

Current Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
IP Address: 68.142.234.41 (ARIN & RIPE IP search)
IP Location: US(UNITED STATES)-CALIFORNIA-FOSTER CITY
Lock Status: ACTIVE
Data as of: 08-Jun-2004

Domain Name.......... msnassistance.com
Creation Date........ 2005-01-25
Registration Date.... 2005-01-25
Expiry Date.......... 2006-01-25
Organisation Name.... David Wright
Organisation Address. 5325 Heritage Pl
Organisation Address.
Organisation Address. Culver City
Organisation Address. 90230
Organisation Address. CA
Organisation Address. UNITED STATES

Admin Name........... David Wright
Admin Address........ 5325 Heritage Pl
Admin Address........
Admin Address........ Culver City
Admin Address........ 90230
Admin Address........ CA
Admin Address........ UNITED STATES
Admin Email.......... davidwright777@yahoo.com
Admin Phone.......... +1.7277717203
Admin Fax............

Tech Name............ YahooDomains TechContact
Tech Address......... 701 First Ave.
Tech Address.........
Tech Address......... Sunnyvale
Tech Address......... 94089
Tech Address......... CA
Tech Address......... UNITED STATES
Tech Email........... domain.tech@YAHOO-INC.COM
Tech Phone........... +1.6198813096
Tech Fax............. +1.6198813010
Name Server.......... yns1.yahoo.com
Name Server.......... yns2.yahoo.com