register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Barclays- 'Barclays Verification Service'
20-Apr-2005

Summary
Email title: 'Barclays Verification Service'
Scam target: Barclays banking customers
Sender:

Barclays Verification Team <verification@barclays.co.uk>

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's Barclays account information
Phish link method HTML form in the email
Phished data sent to: http://personalhsbc.co.uk:54867
Phish site IP :

202.60.230.77

 
Analysis contributed by: Tumbleweed Communications - Message Protection Lab
 
Overview
 
A simple form of phishing - one of the first to emerge, but still being used.
 
E-mail
 
This kind of phishing scheme demands personal information to be entered in a form in an email. The email itself is, of course, fashioned to look like it comes from a legitimate source:
 
 

Given the fact that the sender is also spoofed, this could be convincing, especially to somebody new to phishing.

What should be remembered is that a legitimate company will never ask you for such sensitive information in an email.

 
Web Site
Phished data sent to: http://personalhsbc.co.uk:54867
Phish site IP :

202.60.230.77

 
In this case, the phish website is just a mailbox, where the phished information is delivered to.
 
WHOIS data (for IP 202.60.230.77) :

Domain Name:
personalhsbc.co.uk

Registrant:
HSBC(faked)

Registrant's Address:
11 Moran Drive
Columbus
NJ
08022
US

Registrant's Agent:
TUCOWS INC [Tag = TUCOWS-CA]
URL: http://www.opensrs.org

Relevant Dates:
Registered on: 10-Apr-2005
Renewal Date: 10-Apr-2007
Last updated: 19-Apr-2005

Registration Status:
Registration request being processed

Name servers listed in order:
ns1.goltrest.com 72.9.244.66
ns2.goltrest.com 72.9.244.67