register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Wells Fargo - 'Wells Fargo Customer Support: Transactions security standards update (code ...)'
13-Oct-2004

Summary
Email title: 'Wells Fargo Customer Support: Transactions security standards update (code ...)' , random numbers after 'code'
Scam target: Wells fargo customers
Email format: HTML email
Sender:

Wells Fargo Customer Support <customerservice...@wellsfargo.com> (random numbers before the '@')

Sender spoofed? Yes
Scam call to action: '... our bank is switching to new transactions security standards...We kindly ask you to confirm your ATM card details here...'
Scam goal: Getting victim's ATM card information, e-mail address
Call to action format: URL link
Visible link: https://online.wellsfargo.com/?customersupport=CONFIRMATION
Called link :

http://202.67.159.110:5180/index.php

Phish website hosted on : 218.22.141.202
 
E-mail
 

This attack is similar to another one reviewed here, but it is better made and poses a greater threat.

The e-mail is convincing and believable:

 
 
The sender is spoofed, the URL link too. This adds to the overall effectiveness of the scam.
 
Web Site
Visible link: https://online.wellsfargo.com/?customersupport=CONFIRMATION
Called link :

http://202.67.159.110:5180/index.php

Phish website hosted on : 218.22.141.202
 
The phish site is a very well made one, though there are some obvious clues of phishing. The greatest danger comes from the perfectly 'overwritten' address bar:
 
 

But the lock icon in the lower right corner of the page is missing, which contradicts with the 'https' displayed in the address bar.

Furthermore, the true URL of the page can be seen by opening the 'properties' page (from the main menu of your browser, file/properties):

 
 
After the eventual phishing of the information, a generic-looking logout page is displayed:
 
 
As you see, a serious amount of vigilance is required to avoid being scammed by this phish. The best thing to do when you recieve a message like this is to open up a new browser window and type manually the legitimate address.
 
Phish server WHOIS information:
WHOIS data (for IP 202.67.159.110), 'Asia Pacific Network Information Centre' (apnic.com) database:

IP range : 202.67.128.0 - 202.67.159.255
netname: HKNET-HK
descr: HKNet Company Limited
descr: 32/F., Shun Tak Centre, China Merchants Tower,
descr: 168-200 Connaught Road Central., Hong Kong.
country: HK
admin-c: DA56-AP
tech-c: DA56-AP
mnt-by: APNIC-HM
mnt-lower: MAINT-HKNET-NT
changed: hostmaster@apnic.net 19990914
changed: hostmaster@apnic.net 20010803
status: ALLOCATED PORTABLE
source: APNIC