register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Bank Of America- 'Online Banking Alert (Change of Email Address)'
19-Apr-2005

Summary
Email title: 'Online Banking Alert (Change of Email Address)'
Scam target: Bank Of America customers
Sender:

Online Banking Notices <5thvtc@alert.bankofamerca.com>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's Bank Of America username/password, ATM card information
Phish link method 'Click here' type link
Link 'masked'? Yes
Visible link: 'Sign in to Online Banking'
Actual link to: http://www.bankofamerica.com/nationsfunds/nf2/leaving.cfm?destination=http://www.bankofamerica.com/nationsfunds/nf2/leaving.cfm?destination=
%22%3e%3c%53...(etc.)
Phish site IP :

216.119.179.191

 
Analysis contributed by: Tumbleweed Communications - Message Protection Lab
 
Overview
 
A very well designed and dangerous scam. Uses a vulnerability in the Bank Of America site.
 
E-mail
 
The email is exceptionally well done. It does not involve any coercive or threating message:
 
 

The only suspicious thing is the sender - it looks like some random letters, but still, it is from the right site (at least it looks like it).

However, the link is the most interesting object here. It uses a weakness in the bankofamerica.com site. There is a page there, that would redirect to a URL passed to it. This enables scammers to form a link, which looks like it points to the legitimate site (and in fact, it does!), but passes the scam URL to the redirect page (practically pasteing the scam link after the legit one). To make the phish URL unrecognizable, the scammers have encoded it. This way, the link is functional, but the scam URL is unreadable to a human inspection.

 
Web Site
Visible link: 'Sign in to Online Banking'
Actual link to: http://www.bankofamerica.com/nationsfunds/nf2/leaving.cfm?destination=http://www.bankofamerica.com/nationsfunds/nf2/leaving.cfm?destination=
%22%3e%3c%53...(etc.)
Phish site IP :

216.119.179.191

 
When the link is clicked, the legitimate site opens on the background. On the foreground, the phish site pops up:
 
 
Here is the entire phish pop-up - notice the lack of coercive (hence suspicious) element:
 
 
Placing the phish site as a pop-up above the legitimate site is a tried and tested technique to create an illusion of a direct link between the two. The true location of the pop-up can be revealed by invoking the properties page from the context menu:
 
 
After the 'continue' button is clicked, and the fields are not empty, the pop-up will close, leaing the browser window with the legitimate site in the foreground.
 
WHOIS data (for IP 216.119.179.191) :

Name Server: NS1.BOFALERT.COM
ICANN Registrar: TUCOWS INC.
Created: 2005-04-17
Expires: 2006-04-17
Status: ACTIVE

Registrant:
BOFA International Ltd
1/2 Harwell Road
Dorset, na SE1 1GB
GB

Domain name: BOFALERT.COM

Administrative Contact:
Roberts, David
1/2 Harwell Road
Dorset, na SE1 1GB
GB
+4.4207015 9370
Technical Contact:
Roberts, David
1/2 Harwell Road
Dorset, na SE1 1GB
GB

Registrar of Record: TUCOWS, INC.
Record last updated on 17-Apr-2005.
Record expires on 17-Apr-2006.
Record created on 17-Apr-2005.

Domain servers in listed order:
NS1.BOFALERT.COM 67.175.95.192
NS2.BOFALERT.COM 24.107.89.35
NS3.BOFALERT.COM 67.161.209.152
NS4.BOFALERT.COM 69.248.60.233
NS5.BOFALERT.COM 24.17.34.169