Target:TD Canada Trust
Date discovered:12/07/2006

 General The goal is to get the following information:
    • Bank account
    • Credit card
    • Personal data


Phishing method:
    • URL link

 Email Details From: security@easyweb.tdcanadatrust.com
Subject: TD Online Banking

Visible link: https://easyweb.tdcanadatrust.com/
Actual link: http://verifyserveraus.com/easyweb/easyweb.tdcanadatrust.com/EasyWeb.htm
IP address: 82.227.128.20


The email is designed to avoid detection from Antispam and Antiphishing. Such techniques are:
    • The Body of the email contains HTML content.
    • The Email contains Java content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://verifyserveraus.com/easyweb/easyweb.tdcanadatrust.com/EasyWeb.htm
Actual URL: http://verifyserveraus.com/easyweb/easyweb.tdcanadatrust.com/EasyWeb.htm
IP address: 82.227.128.20


The phishing page will look like the following:



Description inserted by Dominik Auerbach on Wednesday, July 12, 2006
Description updated by Dominik Auerbach on Wednesday, July 12, 2006

Back . . . .