register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Bank Of Oklahoma - 'Update your Online Banking Records'
16-Mar-2005

Summary
Email title: 'Update your Online Banking Records'
Scam target: Bank Of Oklahoma customers
Sender:

Bank of Oklahoma Security Service <service@bok.com>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's credit card and other personal information
Phish link method URL link
Link 'masked'? Yes
Visible link: 'https://onlinebanking.bankofoklahoma.com/OnlineBanking/login.aspx?ReturnUrl=%2fOnlineBanking%2fDefault.aspx'
Actual link to: http://www.zglobia.com/OKLAHOMA/index.php
Phish website IP: 217.76.130.42
 
Overview
 
An unsophisticated phish, trying to catch the customers of a bank that hasn't been targeted before, by surprise.
 
E-mail
 
The email message is quite simple:
 
 
The link is 'hidden' and the sender is spoofed, but otherwise the message is not very brightly designed. Yet, it could be convincing. This case is another example of how crude phish messages are targeted at institutions new to the fenomenon, while the more sophisticated are directed at the more 'scam-hardened' ones.
 
Web Site
Visible link: 'https://onlinebanking.bankofoklahoma.com/OnlineBanking/login.aspx?ReturnUrl=%2fOnlineBanking%2fDefault.aspx'
Actual link to: http://www.zglobia.com/OKLAHOMA/index.php
Phish website IP: 217.76.130.42
 
The site, like the message, is pretty simple. The usual address bar spoof is not applied, and the phish URL is visible:
 
 
The next page asks for credit card information:
 
 
The site wil perform a sanity check of the information, but nothing more. Some random stuff will easily pass:
 
 
Afterwards, The browser will be redirected to the legitimate bank page.
 
WHOIS data (for IP 217.76.130.42) :

Registrant:
Jerri Jo Idarius (SROW-188738)

40 East San Francisco
Willits CA
95490 US
+1 3107653310

Administrative contact:
Jerri Jo Idarius (SRCO-278208)

40 East San Francisco
Willits CA
95490 US
+1 3107653310

Technical contact:
Jerri Jo Idarius (SRCO-278209)

40 East San Francisco
Willits CA
95490 US
+1 3107653310

Domain servers in listed order:
dns5.servidoresdns.net 217.76.128.130
DNS6.SERVIDORESDNS.NET 217.76.129.130

Created: 14 Mar 2005 18:30:10 UTC
Expires: 14 Mar 2006 18:30:10 UTC
Last updated: 14 Mar 2005 18:30:10 UTC