需要修复电脑?
聘请专家
Target:Commerce Bank
Date discovered:24/01/2008

 General The goal is to get the following information:
    • Bank account
    • Personal data


Phishing method:
    • URL link

 Email Details From: mail.serverA02076482.cb@commercebank.com
Subject: Confirm Your Information! (Wed, *********************)

Visible link: http://commerceconnections.commercebank.com/cmserver/ccf.cfm?...
Actual link: http://commerceconnections.commercebank.com.technfo.com.ua/...
IP address: 220.90.230.71


The email is designed to avoid detection from Antispam and Antiphishing. Such techniques are:
    • The Body contains invisible Text.
    • The Body of the email contains HTML content.



This screenshot is how the phishing email looks like:


 Page Details Visible URL: http://commerceconnections.commercebank.com.technfo.com.ua/...
Actual URL: http://commerceconnections.commercebank.com.technfo.com.ua/...
IP address: 220.90.230.71


The phishing page will look like the following:


说明添加者: Dominik Auerbach 打开 2008年1月24日星期四
说明更新者: Dominik Auerbach 打开 2008年1月24日星期四

反馈 . . . .
https:// 为了你的安全,此窗口已加密。