register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Washington Mutual Bank- 'Unauthorized Access To Your Washington Mutual Account'
24-Feb-2005

Summary
Email title: 'Unauthorized Access To Your Washington Mutual Account'
Scam target: Washington Mutual Bank clients
Sender:

Washington Mutual <customerservice@wamu.com>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's credit/debit card information, personal information
Phish link method a 'Click here' type link
Link 'masked'? Yes
Visible link: 'Log On for Online Services'
Actual link to: http://login.personal.wamuin.com/logon/logon2.asp/login.php
Phish website IP: 68.142.234.35
 
Overview
 
A rather believable email and a clever chosen domain name make this scam a dangerous one.
 
E-mail
 
The email looks quite convinincing, and it manages to disguise some random text believably:
 
 
The spoofed sender and the hidden link add to the appeal.
 
Web Site
Visible link: 'Log On for Online Services'
Actual link to: http://login.personal.wamuin.com/logon/logon2.asp/login.php
Phish website IP: 68.142.234.35
 
After the site opens up, it looks very much like the original, legitimate one:
 
 

As you see, the difference in the domain name is quite slight, and could easily slip by a lot of the ordinary users. The main paint to be looked for here is the http (not https, as in the legitimate site) session.

The same is valid for the second phish page:

 
 

The relatively modest amount of information increases the chances of the scam getting away, and underlines, again, the importance of vigilance when entering such sensitive information in a web site.

The phishing server is hosted in a Yahoo! IP range, and is found out to be the source of other spam and scam activities, too:

 
WHOIS data (for IP 68.142.234.35):

IP Location: United States - California - Foster City - Inktomi Corporation
OrgName: Inktomi Corporation
OrgID: INKT
Address: 4100 East Third Avenue
City: Foster City
StateProv: CA
PostalCode: 94404
Country: US

NetRange: 68.142.192.0 - 68.142.255.255
CIDR: 68.142.192.0/18
NetName: INKTOMI-BLK-4
NetHandle: NET-68-142-192-0-1
Parent: NET-68-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.YAHOO.COM
NameServer: NS2.YAHOO.COM
NameServer: NS3.YAHOO.COM
NameServer: NS4.YAHOO.COM
NameServer: NS5.YAHOO.COM
Comment: For general abuse contact netblockadmin@yahoo-inc.com.
Comment: For Web Crawler questions please visit
Comment: http://help.yahoo.com/help/us/ysearch/slurp/
RegDate: 2004-03-24
Updated: 2005-02-18

AbuseHandle: NA258-ARIN
AbuseName: Netblock Admin
AbusePhone: +1-408-349-3300

OrgTechHandle: ZI35-ARIN
OrgTechName: Inktomi Corporation
OrgTechPhone: +1-650-653-2800