需要修复电脑?
聘请专家
Target:Internal Revenue Service
Date discovered:16/06/2006

 General The goal is to get the following information:
    • Bank account
    • Personal data


Phishing method:
    • 'Click here' link

 Email Details From: service@IRS.gov
Subject: refund of $63.80

Visible link: click here
Actual link: http://221.137.136.154/.../IRS/refund/caseid886432/index.html
IP address: 221.137.136.154


The email is designed to avoid detection from Antispam and Antiphishing. Such techniques are:
    • The Body of the email contains HTML content.
    • The Email contains Java content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://221.137.136.154/.../IRS/refund/caseid886432/pas.php?certegy_...
Actual URL: http://221.137.136.154/.../IRS/refund/caseid886432/pas.php?certegy_...
IP address: 221.137.136.154


The phishing page will look like the following:


说明添加者: Dominik Auerbach 打开 2006年6月17日星期六
说明更新者: Dominik Auerbach 打开 2007年11月28日星期三

反馈 . . . .
https:// 为了你的安全,此窗口已加密。