Need help? Ask the community or hire an expert.
Go to Avira Answers
Target:First Federal Bank of California
Date discovered:12/12/2007

 General The goal is to get the following information:
    • Bank account
    • Personal data


Phishing method:
    • URL link

 Email Details From: survey@firstfedca.com
Subject: $80.00 to your account - Just for your time!

Visible link: http://exibank-10.ip.peterstar.net:84/firstfedca/survey/Online.php
Actual link: http://exibank-10.ip.peterstar.net:84/firstfedca/survey/Online.php
IP address: 217.195.71.106


The email is designed to avoid detection from Antispam and Antiphishing. The technique is:
    • The Body of the email contains random characters.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://exibank-10.ip.peterstar.net:84/firstfedca/survey/index.html?...
Actual URL: http://exibank-10.ip.peterstar.net:84/firstfedca/survey/index.html?...
IP address: 217.195.71.106


The phishing page will look like the following:




Description inserted by Dominik Auerbach on Wednesday, December 12, 2007

Back . . . .