Need help? Ask the community or hire an expert.
Go to Avira Answers
Target:National Association of Federal Credit Unions
Date discovered:07/06/2006

 General The goal is to get the following information:
    • Credit card
    • Personal data


Phishing method:
    • URL link

 Email Details From: accounts@nafcu.org
Subject: Update your NAFCU account

Visible link: http://www.nafcunet.org/profile_verification/index.htm
Actual link: http://72.9.252.18/~bernardo/cgi-bin/NAFCU/www.nafcunet.org/
IP address: 72.9.252.18


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://72.9.252.18/~bernardo/cgi-bin/NAFCU/www.nafcunet.org/
Actual URL: http://72.9.252.18/~bernardo/cgi-bin/NAFCU/www.nafcunet.org/
IP address: 72.9.252.18


The phishing page will look like the following:



Description inserted by Dominik Auerbach on Wednesday, June 7, 2006
Description updated by Dominik Auerbach on Wednesday, June 7, 2006

Back . . . .