02 December 2008
heres a new style phish we just received. it pretends to be a message alert to 1 unread message in the inbox folder of an abbey national plc account holder. this phish uses a different variation on a social engineering technique from past phishes we've seen.
the usual phish attempts to trick you into signing directly into your account usually by feigning an account emergency. this phish has no sense of urgency. it's innocuous. it comes across as just an alert sent to let an account holder know of a new abbey national message. if the spammer is lucky enough to reach a few new abbey national account holders it could trick them. in 2004 some 28% of internet users were tricked by phishing schemes...
What is Phishing and Pharming?
Phishing attacks use both social engineering and technical subterfuge to steal consumers' personal identity data and financial account credentials.
Social-engineering schemes use 'spoofed' e-mails to lead consumers to counterfeit websites designed to trick recipients into divulging financial data such as credit card numbers, account usernames, passwords and social security numbers.
Hijacking brand names of banks, e-retailers and credit card companies, phishers often convince recipients to respond. Technical subterfuge schemes plant crimeware onto PCs to steal credentials directly, often using Trojan keylogger spyware. Pharming crimeware misdirects users to fraudulent sites or proxy servers, typically through DNS hijacking or poisoning.~ source anti-phishing working group
To: email@example.com, firstname.lastname@example.org
Subject: Fw: Message Alert - You Have 1 Unread Message
EVERESTKC.NET: this spam was sent to advertise a phishing website that you host please would you terminate service to:
X-SID-PRA: Abbey National plc email@example.com
Received: from ensim.repairit.dk ([220.127.116.11]) by bay0-mc12-f14.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2668);
Mon, 1 Dec 2008 20:26:49 -0800
Received: from VPS368386 (wvps212-241-220-200.vps.webfusion.co.uk [18.104.22.168])
by ensim.repairit.dk (8.12.10/8.12.10) with ESMTP id mB24NOO4016667;
Tue, 2 Dec 2008 05:23:24 +0100
Reply-To: "Abbey National plc" firstname.lastname@example.org
From: "Abbey National plc" email@example.com
To: @yahoo.co.uk, @btinternet.com,@yahoo.co.uk, @hotmail.co.uk,@hotmail.com, @hotmail.co.uk, @hotmail.com, @hotmail.co.uk,@hotmail.com, @hotmail.co.uk,@hotmail.com, @telia.co.uk, @telia.com, @hotmail.co.uk, @hotmail.com, @spray.se,@msn.co.uk, @msn.com, @yahoo.fr,@msn.co.uk, @msn.com, @hotmail.co.uk,@hotmail.com, @hotmail.co.uk,@hotmail.com
Subject: Message Alert - You Have 1 Unread Message
Date: Tue, 2 Dec 2008 05:26:28 +0100
Organization: Abbey National plc
X-Mailer: Microsoft Windows Mail 6.0.6001.18000
X-MimeOLE: Produced By Microsoft MimeOLE V6.0.6001.18000
X-OriginalArrivalTime: 02 Dec 2008 04:26:49.0775 (UTC) FILETIME=[31D48BF0:01C95436]
PART OF THE SANTANDER GROUP
Dear Valued Customer,
You have a new message waiting in your Inbox Folder.
Click here to read.
Abbey National plc Security Department Team.
* Please do not reply to this email as your reply will not be received.
Abbey National plc. Registered Office: Abbey National House, 2 Triton Square, Regent's Place, London, NW1 3AN, United Kingdom. Registered Number 2294747. Registered in England. Telephone 0870 607 6000. Calls may be recorded or monitored. Calls may be recorded or monitored. Authorised and regulated by the Financial Services Authority. FSA registration number 106054. For more information visit www.fsa.gov.uk/register. Abbey and the flame logo are registered trademarks
Posted by wst... at 00:41