Date discovered:23/11/2007

 General The goal is to get the following information:
    • Bank account
    • Personal data

Phishing method:
    • URL link

 Email Details From: kundeervice-num03639vr@vr-networld.de
Subject: Softwareupdate (nachrichtenzahl: **************)

Visible link: http://volksbank.de/banking/portal?id=***************************...
Actual link: http://volksbank.de.117.kg/banking/portal?id=*********************...
IP address:

The email is designed to avoid detection from Antispam and Antiphishing. Such techniques are:
    • The Subject of the email contains random characters.
    • The Body contains invisible Text.
    • The Body of the email contains HTML content.

This screenshot is how the phishing email looks like:

 Page Details Visible URL: http://volksbank.de.117.kg/banking/portal/?id=********************...
Actual URL: http://volksbank.de.117.kg/banking/portal/?id=********************...
IP address:

The phishing page will look like the following:

