| Summary |
| Email title: |
'Found error! Please resubmit UsBank.com urgenqf' |
| Scam target: |
US Bank clients |
| Email format: |
Plain text e-mail |
| Sender: |
Important-UsBadr@UsBank.com
|
| Sender spoofed? |
No |
| Scam call to action: |
'During our regular update and verification of
the Internet Banking Accounts, we could not verify
your current information...as a result your access
to use our services has been limited...To update
your account information and start using our services
please click on the link below'
|
| Scam goal: |
Getting victim's US Bank account, credit card, phone/email/address
and SSN information |
| Call to action format: |
URL link |
| Visible link: |
http://www.usbank.com/internetBanking/RequestRouter?requestCmdId=DisplayLoginPage |
| Called link : |
http://validation-required.info/
|
|
| |
| E-mail |
This message could be quite convincing, although it
carries no US Bank logo. The subject is messed up at
the end (a typical spam technique), but the link seems
OK, and it is familiar to the US Bank customers. The
sender also looks nice. Given this, the unaware user
could easily be tricked into clicking the link.
|
_email.jpg)
|
| |
| Web Site |
| Visible link: |
http://www.usbank.com/internetBanking/RequestRouter?requestCmdId=DisplayLoginPage |
| Called link : |
http://validation-required.info/
|
|
Once the link is clicked, the phish comes into motion.
The site that opens uses US Bank's own website style/fonts/pictures
(they are even loaded from the official site itself),
and looks flawless.
|
_site.jpg) |
To cover the most obvious sign of phishing - the URL
that does not match the original, a special trick is
used. The phish draws a window above the victim's Internet
Explorer address bar (note that this technique is browser
specific), using a Java applet.
This is a close-up of the faked address bar:
|
_adrbar.jpg) |
Note that this 'replacement' of the address bar is not
perfect. This gives a chance to reckognize the phish,
before it is too late. Noticing this, however, requires
a level of attention to detail, that is not common among
the ordinary internet users.
After the victim clicks 'next' on the first page, the
second phish page loads. It is here that the phish demands
the personal information from the victim.
Note : although the address bar is covered, the status
bar remains correct. When clicking 'next' on the first
page, one could notice the 'loading http://validation-required.info/...'
message in the status bar.
|
_site2.jpg) |
This is the second phish attack that uses this technique.
Besides being a very dangerous phish, it comes with even
greater danger - it exploits security holes, allowing
the phisher to execute code on the victim's machine.
This could be used to install other malware (trojans,
keyloggers, etc.).
|
| WHOIS Data: |
[ ISP Organization Information ]
Org Name : Enterprise Networks
Service Name : ENTERPRISENET
Org Address : GNG IDC B/D, 343-1 Yhatap-dong, Pundang-gu, Seongnam
[ ISP IP Admin Contact Information ]
Name : Hyo-Sun, Chang
Phone : +82-2-2105-6082
Fax : +82-2-2105-6100
E-Mail : ip@epnetworks.co.kr
|