register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Huntington Bank - 'Huntington Bank EmaiI Verification'
30-Mar-2005

Summary
Email title: 'Huntington Bank EmaiI - [recipient address] - Verification'
Scam target: Huntington bank customers
Sender:

support_refnum_6@huntington.com

Sender spoofed/hidden? Yes
Scam goal: Getting victim's credit card information
Phish link method Image link
Link 'masked'? Yes
Visible link: https://onlinebanking.huntington.com/index.asp?confirm=yes
Actual link to: http://dllconf.com:280
Phish site IP : 218.94.38.126
 
Analysis contributed by: Tumbleweed Communications - Message Protection Lab
 
Overview
 
This scam uses a dangerous combination of several phishing techniques. Serious damage potential.
 
E-mail
 
The HTML email contains a single image, linking to the phish site. Using a tried and tested phishing technique, the HTML is formed so
the real destination of the link is not visible - the tooltip/status bar indications are tampered:
 
 
There are two more suspicious elements - the misspelled character in the subject line and the strange sender - despite it is in the legitimate domain.
 
Web Site
Visible link: https://onlinebanking.huntington.com/index.asp?confirm=yes
Actual link to: http://dllconf.com:280
Phish site IP : 218.94.38.126
 
Immediately after the site opens, a Java program loads up, that 'overwtites' the address bar. The result is pretty convincing:
 
 

Also, the browser window won't minimize or close, and the context (right click) menu is inaccessible.

Still, phishing clues can be seen:

  • there is no login screen ;
  • the session is not a HTTPS secured one. There is no browser indication for a secure session (the lock incon in the lower right part of the status bar in IE, for example),
    despite the URL starting with 'https' in the address bar.

The real URL can be seen in the proerties page: (File/Properties):

 
 
The next page is simply an acknowledgement:
 
 
The site is hosted in China, but the registrant is in the US:
 
WHOIS data (for IP 218.94.38.126) :

IP Location: - Chinanet Jiangsu Province Network
Name Server: NSA1.SPX2K.NET
ICANN Registrar: YESNIC CO. LTD.
Created: 12-feb-2005
Expires: 12-feb-2006
Status: ACTIVE

Domain Name : dllconf.com

::Registrant::
Name : Constance Edwards
Address : 1094 SE St Patricks Court, Port Orchard, WA
Zipcode : 98367
Nation : US
Tel : +1.302-338-7956
Fax : +1.302-338-7956

::Administrative Contact::
Name : Constance Edwards
Address : 1094 SE St Patricks Court, Port Orchard, WA
Zipcode : 98367
Nation : US
Tel : +1.302-338-7956
Fax : +1.302-338-7956

::Technical Contact::
Name : Constance Edwards
Address : 1094 SE St Patricks Court, Port Orchard, WA
Zipcode : 98367
Nation : US
Tel : +1.302-338-7956
Fax : +1.302-338-7956

::Name Servers::
nsa1.spx2k.net

::Dates & Status::
Created Date 2005-02-12 19:01:37 EST
Updated Date 2005-02-12 19:01:37 EST
Valid Date 2006-02-12 19:01:37 EST
Status ACTIVE