Phun Phishing
Tuesday, August 24, 2010 1:59:26 PM
The editor just got an "Outage Message" from "Bank of America". The editor is supposed to log onto the Bank of America server and reset the account, probably to include various items such as SSN and mother's maiden name.
Right.
The editor wasn't born yesterday. The link "www.bankofamerica.com/update" really leads to "http://confirmationudpateserviceonlin.web.fc2.com/i/bofa-usa/security_top/logon.htm". (The editor changed a couple of letters in there in case some one is dumb enough to try it. Think of it as "Nanny Blogging".) The phishers even have the real Bank of America logo directly linked, which seems like a professional touch.
So the editor checks the "fr2.com". It's registered to:
The European Internet Service Providers
Smedjekullsgatan 16 B
Malmoe, Skaane 212 24
SE
Domain Name: FR2.COM
Administrative Contact, Technical Contact, Zone Contact:
The European Internet Service Providers
Anani Voulehttp://en.wikipedia.org/wiki/Phishing
Smedjekullsgatan 16 B
Malmoe, Skaane 212 24
SE
+46 040 933 491
anani@voule.com
Doesn't sound like an American company.
But the editor does think that it is a sign of gentrification, if the phishers think there's money to be made in this neighborhood. Sort of like getting an unsolicited Nordstroms catalog in zip code 20001. Oh, wait. That hasn't happened yet. Maybe after the new Giant and Convention Center Hotel.
Right.
The editor wasn't born yesterday. The link "www.bankofamerica.com/update" really leads to "http://confirmationudpateserviceonlin.web.fc2.com/i/bofa-usa/security_top/logon.htm". (The editor changed a couple of letters in there in case some one is dumb enough to try it. Think of it as "Nanny Blogging".) The phishers even have the real Bank of America logo directly linked, which seems like a professional touch.
So the editor checks the "fr2.com". It's registered to:
The European Internet Service Providers
Smedjekullsgatan 16 B
Malmoe, Skaane 212 24
SE
Domain Name: FR2.COM
Administrative Contact, Technical Contact, Zone Contact:
The European Internet Service Providers
Anani Voulehttp://en.wikipedia.org/wiki/Phishing
Smedjekullsgatan 16 B
Malmoe, Skaane 212 24
SE
+46 040 933 491
anani@voule.com
Doesn't sound like an American company.
But the editor does think that it is a sign of gentrification, if the phishers think there's money to be made in this neighborhood. Sort of like getting an unsolicited Nordstroms catalog in zip code 20001. Oh, wait. That hasn't happened yet. Maybe after the new Giant and Convention Center Hotel.







Unregistered user # Wednesday, August 25, 2010 1:24:40 PM