Target:Teachers Credit Union
Date discovered:25/09/2006

 General The goal is to get the following information:
    • Bank account
    • Credit card


Phishing method:
    • 'text' link

 Email Details From: service@nacu.com
Subject: Important message from Teachers Credit Union Banking !

Visible link: Sign on to Online Banking
Actual link: http://maps.google.com/local_url?q=http://72.10.98.71/~kohtenc/.x/
IP address: 72.10.98.71


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.


The phishing page contains the following trick:
    • Link redirection by means of a well known domain name



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://72.10.98.71/~kohtenc/.x/
Actual URL: http://72.10.98.71/~kohtenc/.x/
IP address: 72.10.98.71


The phishing page will look like the following:



Description inserted by Dominik Auerbach on Tuesday, September 26, 2006

Back . . . .