register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
  U.S. Bank - 'U.S. Bank Online Access Blocked User Compromised'
15-Jul-2004

Summary
Email subject: 'U.S. Bank Online Access Blocked User Compromised'
Scam target: U.S. Bank customers
Email format: HTML email
Sender:

'service@usbank.com'

Sender spoofed? Yes
Scam call to action: 'We regret to inform you, that we had to lock your U.S. Bank, Online Access...To reactivate your account, click on the link below and confirm your identity...'
Scam goal: US Bank websete username/password, credit/debit card PIN and expiration date.
Call to action format: URL link
Visible link:

https://www4.usbank.com/internetBanking/RequestRouter?requestCmdId=DisplayLoginPage

Called link: http://www.infoeskilsen.com/internetBanking/RequestRouter/DisplayLoginPage/index.html
Phish site on : infoeskilsen.com
 
E-mail
 
Another phish that relies on simple and casual looking design and low profile to slip by unnoticed. The phish message is simple and to the point. The sender looks OK (the phishers usually spoof the senders), and the link looks fine too (it is, in fact, a text, looking like the usbank.com login page, associated with another URL).
 
 
Web Site
Visible link:

https://www4.usbank.com/internetBanking/RequestRouter?requestCmdId=DisplayLoginPage

Called link: http://www.infoeskilsen.com/internetBanking/RequestRouter/DisplayLoginPage/index.html
Phish site on : infoeskilsen.com
 
The site is an almost perfect replica of the legitimate US Bank site. The path in the URL looks nice, but the domain is NOT usbank.com :
 
 

However, the site does look nice, and could fool inexperienced users - many people don't take time to decipher the URL they see.
The next page keeps a low profile, too. It does not require a lot of information, and therefore is not too suspicious:

 
 
A nice looking login screen follows. Notice, again the phishy URL. Another clue of phishing - you don't get the usual 'entering a secure zone' type notification from your browser. Using secure sites is a standard with established companies.
 
 
WHOIS data:

Domain Name: INFOESKILSEN.COM
Registrar: ARSYS INTERNET, S.L. D/B/A NICLINE.COM
Whois Server: whois.nicline.com
Referral URL: http://www.nicline.com
Name Server: DNS2.SERVIDORESDNS.NET
Status: ACTIVE
Updated Date: 23-jun-2004
Creation Date: 23-jun-2004
Expiration Date: 23-jun-2005

Registrant: Joan Mortensen (SROW-112141)
eskilsen@pcpostal.com
26465 Carmel Rancho Bl
Carmel Valley SIN PROVINCIA