Need help? Ask the community or hire an expert.
Go to Avira Answers
Target:Citibank
Date discovered:25/06/2007

 General The goal is to get the following information:
    • Bank account


Phishing method:
    • 'text' link

 Email Details From: cardpayments@citibank.com
Subject: Your card payment is overdue

Visible link: Check your online account
Actual link: http://www.versaway.com/web.da-us.citibank.com/cgi-bin/citifi/scripts/...
IP address: 218.17.76.198


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://www.versaway.com/web.da-us.citibank.com/cgi-bin/citifi/scripts/...
Actual URL: http://www.versaway.com/web.da-us.citibank.com/cgi-bin/citifi/scripts/...
IP address: 218.17.76.198


The phishing page will look like the following:


Description inserted by Dominik Auerbach on Monday, June 25, 2007

Back . . . .