Target:Affinity Plus Federal Credit Union
Date discovered:07/07/2006

 General The goal is to get the following information:
    • Bank account
    • Credit card
    • Personal data


Phishing method:
    • URL link

 Email Details From: upgrade@affinityplus.org
Subject: Message from AffinityPlus Resolution Center ###############

Visible link: https://hb.affinityplus.org/authenticate/unlock/
Actual link: http://60.176.86.92/hb.affinityplus.org/signon.htm
IP address: 60.176.86.92


The email is designed to avoid detection from Antispam and Antiphishing. Such techniques are:
    • The Subject of the email contains random characters.
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://60.176.86.92/hb.affinityplus.org/signon.htm
Actual URL: http://60.176.86.92/hb.affinityplus.org/signon.htm
IP address: 60.176.86.92


The phishing page will look like the following:



Description inserted by Dominik Auerbach on Friday, July 7, 2006
Description updated by Dominik Auerbach on Friday, July 7, 2006

Back . . . .