register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Charter One - 'Client's Details Confirmation'
24-Mar-2005

Summary
Email title: 'Charter One - 'Client's Details Confirmation'
Scam target: Charter One bank customers
Sender:

Staff_ID9955@banksecurity.com

Sender spoofed/hidden? No
Scam goal: Getting victim's credit card information , Charter One username/password
Phish link method A 'click here' type link
Link 'masked'? Yes
Visible link: 'Click Here'
Actual link to: http://www.lbgirls.net/galleries/001/galler.htm
Resolved site : http://67.18.75.101/buttcam/resources/logon/SecurityMeasures.php
 
Analysis contributed by: Tumbleweed Communications - Message Protection Lab
 
Overview
 
The good site design and the address bar forgery make this phish dangerous. The email, however, contains obvious indications of phishing.
 
E-mail
 

The email is well designed, but there are some obviously peculiar eBay mentions:

 
 
This is the first clue of phishing. The second one is the email sender - not coming from the legit Charter One site.
 
Web Site
Visible link: 'Click Here'
Actual link to: http://www.lbgirls.net/galleries/001/galler.htm
Resolved site : http://67.18.75.101/buttcam/resources/logon/SecurityMeasures.php
 
After 'hopping' throug the first destionation of the link, the browser is redirected to the real phish site. At this point, an address bar forgery loads up. It draws a window above the browser's address bar, and makes it look as it points to the legitimate site:
 
 
On the surface, the only phishing clue here is the 'insecure' login - the page is not HTTPS secured. Still the address bar forgery can be defeated by invoking the 'Properties' screen (File/Properties), where the real URL shows up:
 
 
After 'logging in', the main phish page shows up. The address bar forgery remains active:
 
 
The site is hosted in the US:
 
WHOIS data (for IP 67.18.75.101) :

IP Location: United States - California - Visalia - Theplanet.com Internet Services Inc
Reverse DNS: 101.67-18-75.reverse.theplanet.com

OrgName: ThePlanet.com Internet Services, Inc.
OrgID: TPCM
Address: 1333 North Stemmons Freeway
Address: Suite 110
City: Dallas
StateProv: TX
PostalCode: 75207
Country: US

ReferralServer: rwhois://rwhois.theplanet.com:4321

NetRange: 67.18.0.0 - 67.19.255.255
CIDR: 67.18.0.0/15
NetName: NETBLK-THEPLANET-BLK-11
NetHandle: NET-67-18-0-0-1
Parent: NET-67-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.THEPLANET.COM
NameServer: NS2.THEPLANET.COM
RegDate: 2004-03-15
Updated: 2004-07-29

TechHandle: PP46-ARIN
TechName: Pathos, Peter
TechPhone: +1-214-782-7800

OrgAbuseHandle: ABUSE271-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-214-782-7802

OrgNOCHandle: TECHN33-ARIN
OrgNOCName: Technical Support
OrgNOCPhone: +1-214-782-7800

OrgTechHandle: TECHN33-ARIN
OrgTechName: Technical Support
OrgTechPhone: +1-214-782-7800