ThreatFire Research Blog Home
 
 
« Whatever happened to Pacman?
Virus Bulletin 2007 a success »

Phishing weekend!

More phishing this weekend, as always. Apparently, the arrests of a suspected phishing group this past week in Germany didn’t net much of the phishing crime scene. This email bait arrived on Saturday, and appears to be much better designed than past emails. Little misspellings and giveaways can clue a reader in to fraud, however.

Let’s give this one a closer look, and pick out a few of the giveaways. The return addresses at “bankofamerica.com” usually are spelled correctly (outlined in red below), instead of the “bankoffamerica.com” below. Banks don’t use hyperlinks that include funny little ip addresses in the URL, or convuluted or misspelled words (unfortunately, the bank targeted in this example may send emails to their customers with hyperlinks to bankofamerica.com). Also, I believe the bank never contacts their customers with these sorts of security issues in this manner over email.

If you are using gmail and receive this kind of fraudulent mail, you can report it to have the site investigated. Click on the little blue arrow in the upper right hand corner of the message. A drop down menu appears, with the “Report phishing” option (outlined in red below). You can select this option to report the site to the appropriate handlers. Click on the image below to enlarge it:

This entry was posted on Sunday, September 16th, 2007 at 10:03 am and is filed under Password stealing, Social Engineering, Spam. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

3 Responses to “Phishing weekend!”

  1. Wao says:
    October 1, 2007 at 7:58 pm

    Treatfire is very cool.

    I use it with Dr.Web antivirus on my Vista.

    Do U think it is enough ?

    Can I need a firewall ?

    Can TreahFire monitor my system’s network activities ?

    Thanks!

  2. ThreatFire Blogger says:
    October 2, 2007 at 11:01 am

    Hi Wao,

    Thanks so much for the comments.

    Threatfire, when combined with a good av solution, will help provide effective layered security. While you may be using Dr Web, you also could check out PCTools AV for free here:
    http://www.pctools.com/free-antivirus. We like it when you use PC Tools products!

    Yes, using a firewall is always recommended. You are using Vista, so your system has one by default, but you can find one here with a different set of functionality and additional features at http://www.pctools.com/firewall.

    Your question is an interesting one. Attacks on windows network-aware system services have been trending downward (partly because users have been installing firewalls, like the free one at the pctools site), but it’s very important to continue using them to prevent these sorts of attacks. We still see packets arriving at our servers from years-old worms like codered because some administrators still fail to patch their windows systems and use firewalls.

    Finally, yes, Threatfire can monitor network activities, but it currently does so in a limited manner. For example, if your system suddenly starts sending email (or spam), Threatfire will attempt to identify if the behavior is malicious or something that you really meant to perform.

  3. Wao says:
    October 2, 2007 at 11:49 am

    Ok

    Just try …

    Thanks!

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).