Target:Co-op Services Credit Union
Date discovered:04/02/2007

 General The goal is to get the following information:
    • Bank account
    • Credit card


Phishing method:
    • 'Click here' link

 Email Details From: asdtytr@customersprive.com
Subject: Co-op Services Credit Union - Security Measures

Visible link: click here.
Actual link: http://by.optimost.com/post/110-1461/a00901f0al22bmj04325t222bsj09...
IP address: 194.25.136.14


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://www.sjmanhole.com/.secureserver.cscu.org/login.htm
Actual URL: http://www.sjmanhole.com/.secureserver.cscu.org/login.htm
IP address: 221.139.3.165


The phishing page will look like the following:




Description inserted by Dominik Auerbach on Sunday, February 4, 2007

Back . . . .