Need help? Ask the community or hire an expert.
Go to Avira Answers
Target:National Credit Union Administration
Date discovered:18/10/2007

 General The goal is to get the following information:
    • Credit card


Phishing method:
    • 'Click here' link

 Email Details From: f.c.u@ncua.com
Subject: ***Bulk SPAM*** Your Payment is Pending

Visible link: >>> Click here <<<
Actual link: http://80.81.2.14/ncua/activate.html
IP address: 80.81.2.14


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://www.associates-tso.org/users/test/ncua.gov/
Actual URL: https://www.fcu.gov/cgi-bin/webscr?cmd=_activate-run
IP address: 66.49.204.203


The page contains the following trick:
    • Forged address bar


The phishing page will look like the following:




Description inserted by Dominik Auerbach on Saturday, October 20, 2007

Back . . . .