<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NoVirusThanks Blog &#187; Phishing</title>
	<atom:link href="http://blog.novirusthanks.org/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.novirusthanks.org</link>
	<description>Security News and Malware Analysis</description>
	<lastBuildDate>Wed, 01 Feb 2012 13:34:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Phishing: Update your PayPal account Information</title>
		<link>http://blog.novirusthanks.org/2012/01/phishing-update-your-paypal-account-information/</link>
		<comments>http://blog.novirusthanks.org/2012/01/phishing-update-your-paypal-account-information/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 02:01:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security News]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=3121</guid>
		<description><![CDATA[We have detected new phishing emails with subject &#8220;Update your PayPal account Information&#8221; that contain fake PayPal link that redirects to a phishing page used to steal PayPal account details of users that type their credentials. Email header: Subject: Update your PayPal account Information Date: Mon, 16 Jan 2012 00:43:26 +0100 Received: from WIN-QJ6LOAE77N1 (unknown [...]]]></description>
			<content:encoded><![CDATA[<p>We have detected new phishing emails with subject &#8220;Update your PayPal account Information&#8221; that contain fake PayPal link that redirects to a phishing page used to steal PayPal account details of users that type their credentials.</p>
<p>Email header:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Subject: Update your PayPal account Information
Date: Mon, 16 Jan 2012 00:43:26 +0100
Received: from WIN-QJ6LOAE77N1 (unknown [109.169.70.227])</pre></div></div>

<p>The malicious link is:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">hxxp://technologyprojects. org/wp-rss.php</pre></div></div>

<p>That redirects to:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">HTTP/1.1 302 Moved Temporarily
Date: Mon, 16 Jan 2012 01:08:28 GMT
Server: Apache
X-Powered-By: PHP/5.2.14
Location: hxxp://paypal.com-us.cgi-bin-webscr-cmd.login-submit-dispatch.74fghghs68g484iky4mn86we8r46d4h38df4b83m48hg3ui4ty84s83f4xcb78.norenterprises .com/us/webser/us
Content-Length: 0
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Type: text/html</pre></div></div>

<p>Note the long subdomain name that begins with &#8220;paypal.com&#8221;:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">paypal.com-us.cgi-bin-webscr-cmd.login-submit-dispatch.74fghghs68g484iky4mn86we8r46d4h38df4b83m48hg3ui4ty84s83f4xcb78.norenterprises. com</pre></div></div>

<p>The ip address of the malicious domain is:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">67.220.209.21 / server23.verygoodserver.com</pre></div></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2012/01/phishing-update-your-paypal-account-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PayPal Phishing &#8211; HTML Attachment</title>
		<link>http://blog.novirusthanks.org/2010/08/paypal-phishing-html-attachment/</link>
		<comments>http://blog.novirusthanks.org/2010/08/paypal-phishing-html-attachment/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 13:02:58 +0000</pubDate>
		<dc:creator></dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=2921</guid>
		<description><![CDATA[Got a another phishing email today. The email came to an email I have registered to a PayPal account so it instantly caught my eye. I logged into my PayPal account using the correct URL, all is well. So this is obviously another phishing attempt, but not the typical kind. &#160; &#160; Typical message content, [...]]]></description>
			<content:encoded><![CDATA[<p>Got a another phishing email today.  The email came to an email I have registered to a PayPal account so it instantly caught my eye.  I logged into my PayPal account using the correct URL, all is well.  So this is obviously another phishing attempt, but not the typical kind.</p>
<p>&nbsp;</p>
<p><a href="http://i36.tinypic.com/2nkhuld.png" target="blank"><img src="http://i36.tinypic.com/2nkhuld.png" alt="Image" width="530" height="250" /></a></p>
<p>&nbsp;</p>
<p>Typical message content, but they usually give you a (fraudulent) link to follow.  Not this time, they attach an HTML file which will open in any browser.  I opened the file in a safe environment, all looks very convincing.</p>
<p>&nbsp;</p>
<p><a href="http://i36.tinypic.com/2ev88y0.png" target="blank"><img src="http://i36.tinypic.com/2ev88y0.png" alt="Image" width="530" height="250" /></a></p>
<p>&nbsp;</p>
<p>Now, not only would PayPal never ask you to reactivate your account in this manner, they would never ask for your credit card &amp; personal details.</p>
<p>&nbsp;</p>
<p><a href="http://i37.tinypic.com/33y4d2o.png" target="blank"><img src="http://i37.tinypic.com/33y4d2o.png" alt="Image" width="530" height="250" /></a></p>
<p>&nbsp;</p>
<p>When you click the Submit button it will send all the details you entered to this script.</p>
<p>&nbsp;</p>
<pre>hxxp://202.181.105.217/~info/AccountVerification/cf.php</pre>
<p>&nbsp;</p>
<p>Which displays this output.</p>
<p>&nbsp;</p>
<p><a href="http://i34.tinypic.com/2dhwe3n.png" target="blank"><img src="http://i34.tinypic.com/2dhwe3n.png" alt="Image" width="530" height="250" /></a></p>
<p>&nbsp;</p>
<p>So in conclusion, if you ever are worried your PayPal account has been accessed by a third party and needs reactivating, phone them.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2010/08/paypal-phishing-html-attachment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive phishing scam emails against Maybank Malaysia</title>
		<link>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/</link>
		<comments>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/#comments</comments>
		<pubDate>Sat, 23 Jan 2010 01:54:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[maybank]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.novirusthanks.org/?p=2229</guid>
		<description><![CDATA[We have recently counted more than 50 scam emails that contain very dangerous links used for phishing attacks against the Maybank of Malaysia. &#160; &#160; Below there are some examples of subjects used in the scam emails: Subject: Important Update Subject: Security Check Subject: Update your profile Subject: Urgent Notice Subject: Profile update Subject: Security [...]]]></description>
			<content:encoded><![CDATA[<p>We have recently counted more than 50 scam emails that contain very dangerous links used for phishing attacks against the Maybank of Malaysia.</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/maybank-phishing.jpg" alt="Maybank phishing emails" title="Maybank phishing emails" width="530" /></p>
<p>&nbsp;</p>
<p>Below there are some examples of subjects used in the scam emails:</p>
<blockquote><p>
Subject:  	Important Update<br />
Subject:  	Security Check<br />
Subject:  	Update your profile<br />
Subject:  	Urgent Notice<br />
Subject:  	Profile update<br />
Subject:  	Security Warning<br />
Subject:  	Update your Account<br />
Subject:  	Update your Password
</p></blockquote>
<p>While I was checking the headers of the emails, I noticed that most of the IP addresses of the senders come from Chinese (.CN) domains:</p>
<blockquote><p>
mail.bnu.edu.cn (mail.bnu.edu.cn [219.142.99.2])<br />
58.185.112.164 (HELO user) (58.185.112.164) by 219.142.99.2<br />
mailqd.cmr.com.cn (unknown [211.100.42.132])<br />
User ([212.62.45.71]) by mailqd.cmr.com.cn<br />
mail0.shift.edu.cn (unknown [61.152.219.51])<br />
User ([58.185.112.164]) by mail0.shift.edu.cn<br />
mail.smu.ac.kr (smu.ac.kr [203.237.168.13])<br />
User ([58.185.112.164]) (authenticated (0 bits)) by mail.smu.ac.kr<br />
idrgroup-nx0i3d.idrgroup.local (servera210.opencom.com [121.78.88.210])<br />
User ([58.185.112.164]) by idrgroup-nx0i3d.idrgroup.local<br />
mail.fudan.edu.cn (unknown [61.129.42.10])<br />
User ([212.62.45.71]) by mail.fudan.edu.cn
</p></blockquote>
<p>Some of the malicious links used for phishing attacks are the following:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
3
4
5
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">hxxp://zoahaza.isfreeweb.com/tt/style/setup/image/m2u.htm
hxxp://www.dobongn.kr/gnuboard4/bbs/m2u.htm
hxxp://central-groove.co.uk/images/M_images/www.maybank2u.com.my/m2u.htm
hxxp://zoahaza.isfreeweb.com/tt/components/m2u.htm
hxxp://womabkr.com.tw/Ch/img/main.htm</pre></td></tr></table></div>

<p>Not all the links are still active and fortunately there are also links that are detected and blocked by Mozilla Firefox but keep in mind that there are always links that are not blocked or that are not detected by any antispam filter!</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/maybank-phishing2.jpg" alt="Reported web forgery" title="Reported web forgery" /></p>
<p>&nbsp;</p>
<p>Remember always to NOT insert sensitive data in unknown websites and to never click in links contained in unknown emails. When you receive this kind of emails, example from your Bank, and you are requested to insert sensitive data make sure to give a call to your bank before insert any kind of data in the suspicious website.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2010/01/massive-phishing-scam-emails-against-maybank-malaysia/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Massive phishing scam emails against Poste Italiane</title>
		<link>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/</link>
		<comments>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/#comments</comments>
		<pubDate>Tue, 17 Mar 2009 22:32:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=1358</guid>
		<description><![CDATA[We recently received a lot of phishing emails used by attackers to steal Poste Italiane accounts by redirecting victims to a malicious website that looks as the Poste Italiane homepage. Despite this, the user who will insert its details will be victim of a phishing attack and is highly suggested to change its username and [...]]]></description>
			<content:encoded><![CDATA[<p>We recently received a lot of phishing emails used by attackers to steal Poste Italiane accounts by redirecting victims to a malicious website that looks as the Poste Italiane homepage. Despite this, the user who will insert its details will be victim of a phishing attack and is highly suggested to change its username and password of its account.</p>
<p>&nbsp;</p>
<p><img src="http://blog.novirusthanks.org/wp-content/uploads/mass-phishing-emails.gif" alt="Screenshot of the phishing email" title="Screenshot of the phishing email" width="530" /></p>
<p>&nbsp;</p>
<p>Malicious links used for phishing attacks:</p>

<div class="wp_syntax"><table><tr><td class="line_numbers"><pre>1
2
</pre></td><td class="code"><pre class="text" style="font-family:monospace;">hxxp://217.24.231.33/login.html
hxxp://79.39.132.165/poste/index.htm</pre></td></tr></table></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/03/massive-poste-italiane-phishing-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Promemoria eBay per oggetto non pagato numero</title>
		<link>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/</link>
		<comments>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 22:59:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[ebay spam]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=818</guid>
		<description><![CDATA[We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker. &#160; Message Promemoria eBay [...]]]></description>
			<content:encoded><![CDATA[<p>We received again new false eBay emails that redirects the user to visit a webpage that is used to steals the user&#8217;s eBay account with a false webpage, similar to the original eBay homepage, that save the logi account typed by the user and send the sensitive data to the attacker.</p>
<p>&nbsp;</p>
<p><u>Message</u></p>
<blockquote><p>
Promemoria eBay per oggetto non pagato numero 3104678753291</p>
<p>Gentile member,<br />
alenf ha segnalato di non avere ancora ricevuto il pagamento per il seguente<br />
oggetto: numero 3104678753291</p>
<p>Al momento non viene intrapresa alcuna azione nei confronti del tuo account.<br />
Tuttavia, ti ricordiamo che quando fai un&#8217;offerta o acquisti un oggetto su eBay,<br />
prendi un impegno vincolante con il venditore. Se la situazione non verr? risolta<br />
entro 7 giorni dalla ricezione di questo promemoria, riceverai un ammonimento per<br />
oggetto non pagato&#8230;
</p></blockquote>
<p><u>Header</u></p>
<blockquote><p>
<strong>Received</strong>: from hsenc.co.kr (unknown [211.215.20.40])<br />
<strong>Received</strong>: from User (80.229.253.105)<br />
by hsenc.co.kr (211.215.20.40) with [Nmail V3.6]<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 3104678753291<br />
<strong>Date</strong>: Thu, 29 Jan 2009 15:25:31 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from 419revolution.org (unknown [211.106.23.71])<br />
<strong>Received</strong>: from User ([])<br />
by 419revolution.org (Merak 6.1.0)<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 292567831524<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p><strong>Received</strong>: from mail.quike.com.cn (unknown [202.75.222.151])<br />
<strong>Received</strong>: from User ([80.229.253.105])<br />
by 211.155.233.151 with ESMTP<br />
<strong>Subject</strong>: Hai ricevuto un ammonimento per Oggetto non pagato 260300220759<br />
<strong>Date</strong>: Mon, 28 Jan 2009 14:38:18 -0000
</p></blockquote>
<blockquote><p>
<strong>Received</strong>: from topinfo.com.cn (unknown [211.157.2.61])<br />
<strong>Received</strong>: from User [80.229.253.105] by topinfo.com.cn<br />
<strong>Subject</strong>: Promemoria eBay per oggetto non pagato numero 299010852347<br />
<strong>Date</strong>: Mon, 17 Nov 2008 10:51:59 -0000
</p></blockquote>
<p>Make sure to not fall in this scam, check always the address of the site before write sensitive data in web forms and analyze always the header of the emails.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2009/01/phishing-promemoria-ebay-per-oggetto-non-pagato-numero/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What to do in case of a suspected email or phishing ?</title>
		<link>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/</link>
		<comments>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 15:48:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[what to do]]></category>

		<guid isPermaLink="false">http://novirusthanks.org/blog/?p=75</guid>
		<description><![CDATA[Some basic info on what to do in case of a suspected email or phishing: &#160; Use always maximum attenction when reading the email Never click on http links or images Never download attachments Analyze the header of the email Check the email of the sender on google to see if you find bad info [...]]]></description>
			<content:encoded><![CDATA[<p>Some basic info on what to do in case of a suspected email or phishing:</p>
<p>&nbsp;</p>
<ul>
<li>Use always maximum attenction when reading the email</li>
<li>Never click on http links or images</li>
<li>Never download attachments</li>
<li>Analyze the header of the email</li>
<li>Check the email of the sender on google to see if you find bad info</li>
<li>Check the info of the sender&#8217;s site on google</li>
<li>Report the email to your local authorities</li>
<li>Report the email to <a href="http://www.phishtank.com/" target="_blank" rel="nofollow">PhishTank</a></li>
<li>Delete the email</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.novirusthanks.org/2008/10/what-to-do-in-case-of-a-suspected-email-or-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

