  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert Re: [Phish] Telephone phishing thread
Pentagon Federal Credit Union Phish
As before, the only thing changed was the name in the X-Apparently-To header.
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  removed Crisis Management Squad Premium,VIP join:2002-02-08 Houston, TX clubs:
| reply to nwrickert VISA - local number to me in Houston. Scary.
quote: > VISA Security Department temporary disabled your account.
Verified by VISA will never ask you any information via e-mail. Call this number (832)772-7857 - Toll Free
You must reactivate your account immediately, or you won't be able to use your cards again.
> Sorry for any inconvenience this may cause and thank you for your patience.
> To reactivate your account call us: 832-772-7857- Toll Free
© 2001-2008 Visa. All Rights Reserved.
This message was sent to Email Id :
WPTLLOFITJBTPCIRFUNZMICCCONJSFMEEMUDLO
Headers:
-- irc.removed.us - #dslr | DSLR Phishtracker | Email: removed@dslr.net |
|
  nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
| reply to nwrickert [Phish] Credit Union 1 vish (ATM card)
Card Deactivation Message from: Customer Service Date: 04/02/2008 We detected irregular activity on your ATM/Check Card on 04/02/2008. For your protection we have had to suspend any future authorizations being conducted with your card. For your security we have deactivate your card. How to activate/re-activate your card ? You may stop by your branch or call our Activation Center.
Activation Center: (866) 722-3235 (24 Hour Line) Our automated system allows you to quickly activate your card. We apologize for any inconvenience this may cause. Copyright © 2008 Credit Union 1. All Rights Reserved.
-- AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13 |
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert Re: [Phish] Telephone phishing thread
This one apparently from CUNA regarding the Wal-Mart data breach seems to be quite suspicious. It had me fooled for a minute, until I looked more closely at the headers. Nice try.
As before, the only thing changed is the name in the X- Apparently-To: header:
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  DC DSL Stays crunchy even in milk Premium join:2000-07-30 Washington, DC
·Covad Communications
·Verizon Online DSL
| reply to nwrickert I got a Franklin. I called the number. There's a semi-realistic TRS on it that asks for the card number, PIN, expiration date.
I put in completely bogus info (like 1234567812345678 for the card number). After a brief pause, it came back with "card, PIN or expiration are not valid, please reenter." So, I made up different info. It took it, said the card is now active and valid worldwide and ended.
I called back a few more times. Sometimes I gave it identical data, others not. It took it all just the same.
It seems that it tries to make it seem legit to get someone to reenter the info to make sure they've got a live one. However, they farkled it and it doesn't catch mismatches.
This would be great rainy-day fun wasting their time and flooding them with bogus data if it wasn't a toll-free number that captures the number you're calling from regardless of caller id blocking. (Anyone near a pay phone wanna give it a go and see if they're stupid enough to not have blocked pay station callers?)
=====
Return-Path: Received: from mail.im3.com [216.201.16.126] by mail.ultimahosts.com with SMTP; Fri, 11 Apr 2008 16:25:02 -0400 Received: from User (unverified [72.28.171.9]) by cartman.im3.com (Vircom SMTPRS 4.4.568.66) with ESMTP id ; Fri, 11 Apr 2008 15:53:41 -0400 X-Modus-BlackList: bankfranklin@franklinsecurity.com=OK X-Modus-Audit: FALSE;0;0;0 Reply-To: From: "Franklin Bank" Subject: Card Deactivation Date: Fri, 11 Apr 2008 15:53:36 -0400 MIME-Version: 1.0 Content-Type: text/html; charset="Windows-1251" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 X-Rcpt-To: X-SmarterMail-Spam: SPF_None
Card Deactivation Message from: Customer Service Date: 04/10/2008 We detected irregular activity on your ATM/Check Card on 04/10/2008. For your protection we have had to suspend any future authorizations being conducted with your card. For your security we have deactivate your card. How to activate/re-activate your card ? You may stop by your branch or call our Activation Center.
Activation Center: (866) 578-0984 (24 Hour Line)
Our automated system allows you to quickly activate your card. We apologize for any inconvenience this may cause. Copyright © 2006 Franklin Bank. All Rights Reserved. -- There is no giant fur-bearing trout. |
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert Another Franklin Bank one:
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  SnowyOne Premium join:2003-04-05 Kailua, HI
·RoadRunner Cable
·Clearwire Wireless
| reply to nwrickert Lizz_Vish_Archived
X-Apparently-To: myemail@pacbell.net via 209.191.85.225; Tue, 15 Apr 2008 10:39:54 -0700 X-Originating-IP:[212.85.249.132] Return-Path: Authentication-Results:mta121.sbc.mail.mud.yahoo.com from=franklin.com; domainkeys=neutral (no sig) Received:from 207.115.36.53 (EHLO nlpi024.prodigy.net) (207.115.36.53) by mta121.sbc.mail.mud.yahoo.com with SMTP; Tue, 15 Apr 2008 10:39:52 -0700 X-Header-Overseas:Mail.from.Overseas.source.212.85.249.132 X-Originating-IP:[212.85.249.132] Received:from node-2.minx.net.uk (node-2.minx.net.uk [212.85.249.132]) by nlpi024.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m3FHdoDY014536 for ; Tue, 15 Apr 2008 12:39:50 -0500 Received:from [195.82.101.89] (helo=mail.QuantumFittedFurniture.co.uk) by node-2.minx.net.uk with esmtp (Exim 4.60) (envelope-from ) id 1JlpIR-0005rN-Og for myemail@pacbell.net; Tue, 15 Apr 2008 18:50:20 +0100 Received:from User ([192.168.0.250] RDNS failed) by mail.QuantumFittedFurniture.co.uk with Microsoft SMTPSVC(6.0.3790.3959); Tue, 15 Apr 2008 18:29:09 +0100 Reply-to: From:"Franklin Bank" Add to Address BookAdd to Address Book Add Mobile Alert Subject:Card Deactivation Date:Tue, 15 Apr 2008 13:39:36 -0400 MIME-Version:1.0 Content-Type:text/plain; charset="Windows-1251" Content-Transfer-Encoding:7bit X-Priority:3 X-MSMail-Priority:Normal X-Mailer:Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000 Bcc: Message-ID: X-OriginalArrivalTime:15 Apr 2008 17:29:10.0078 (UTC) FILETIME=[37021DE0:01C89F1E] X-MINX-Orig-IP:195.82.101.89 X-Spam-Score:2.9 (++) X-Spam-Level:++ Content-Length:563
Card Deactivation Message from: Customer Service Date: 04/15/2008
We detected irregular activity on your ATM/Check Card on 04/15/2008. For your protection we have had to suspend any future authorizations being conducted with your card.
For your security we have deactivate your card.
How to activate/re-activate your card ?
You may stop by your branch or call our Activation Center:
Activation Center: (866) 797-5640 (24 Hour Line) |
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert Re: [Phish] Telephone phishing thread
Yet another Franklin Bank one, trying to look legitimate by warning recipients of phishing scams. They're not fooling me.
The phone number's likely bogus, and the IP address 72.28.171.9 is likely a botnet zombie (it certainly isn't one of Franklin's IPs). The Corporate Office address is real, however.
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert Another Franklin Bank one, same phone number as before:
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
3 edits | reply to nwrickert Amarillo National Bank vish:
URLs for both the forged ANB and Verisign logos in the body of the phish (posted as JPG as it is all html)
ANB: hxxp://jeannemcallister.com/logo.gif Verisign: hxxp://jeannemcallister.com/logo-verisign.gif
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  Lizz Premium join:2002-10-22 Fullerton, CA
| reply to nwrickert A vish AND a phish, all in one! (and with all the spamcatcher info in the header, ATT/Yahoo still left it in my inbox, not the bulk )
From Bank of America Fri May 2 06:59:39 2008 X-Apparently-To: XXX@pacbell.net via 209.191.85.223; Fri, 02 May 2008 07:01:12 -0700 X-Originating-IP: [64.97.155.27] Return-Path: Authentication-Results: mta136.sbc.mail.re3.yahoo.com from=alerts.bankofamerica.com; domainkeys=neutral (no sig) Received: from 207.115.20.65 (EHLO flpi096.prodigy.net) (207.115.20.65) by mta136.sbc.mail.re3.yahoo.com with SMTP; Fri, 02 May 2008 07:01:12 -0700 X-Originating-IP: [64.97.155.27] Received: from sc2.he.tucows.com (smtpout2027.sc2.he.tucows.com [64.97.155.27]) by flpi096.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m42E1Bpw001455 for ; Fri, 2 May 2008 07:01:11 -0700 Received: from sc2-out04.emaildefenseservice.com (64.97.201.174) by sc2.he.tucows.com (7.3.127) id 48188F54000E71E6; Fri, 2 May 2008 13:59:46 +0000 Message-ID: (added by postmaster@globo.com) X-SpamScore: 96 X-Spamcatcher-Summary: 96,15,0,9ea1071f6304b62f,0631c5bc6dd70dd7,alert@alerts.bankofamerica.com,-, X-Spamcatcher-Explanation: (33%) BODY: mail is from Bank of America but doesn't contain any Bank of America URLS;(27%) BODY: likely phishing content;(13%) X-MAILER: mail headers not consistent with User Agent "Outlook";(13%) HTML: HTML code not consistent with User Agent "Outlook";(7%) BODY: text/html email has no html tag;(7%) BODY: content type is strictly "text/html"; Received: from User (unknown [41.223.251.88]) (Authenticated sender: atm05@globo.com) by sc2-out04.emaildefenseservice.com (Postfix) with ESMTP; Fri, 2 May 2008 13:59:19 +0000 (UTC) From: "Bank of America" Add to Address BookAdd to Address Book Add Mobile Alert Subject: Online Banking Verification Date: Fri, 2 May 2008 14:59:39 +0100 MIME-Version: 1.0 Content-Type: text/html; charset="Windows-1251" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Content-Length: 2867
Dear Valued Bank of America Online Customer:
IMPORTANT: Your online account information must be confirmed and verified to ensure uninterrupted service.
To enhance the level of service you receive with Bank of America Online Services, we regularly review the online banking accounts. We have issued this warning message to inform you that we have detected a slight error in your account information. This might be due to either of the following reasons:. bullet A recent change in your personal information ( i.e.change of address). bullet Submiting invalid information during the initial sign up process. bullet An inability to accurately verify your selected option of payment due to an internal error within our processors.
As a result, we require you to confirm and verify your account information By Clicking Here and completing the confirmation process.
Note However, failure to confirm and verify your account information will result in temporarily account suspension. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience. If you have any question regarding this, please call us at 888-692-5949, 24 hours a day, seven days a week. or simply Sign In to Online Banking and click on "Help".
Thank you for banking at Bank of America. We look forward to serving your financial needs for many years to come. |
|
  Lizz Premium join:2002-10-22 Fullerton, CA | So you all don't think I'm nuts, the "simply sign on" is a link to a phishing site which DOES show in phishtracker. |
|
  SnowyOne Premium join:2003-04-05 Kailua, HI
·RoadRunner Cable
·Clearwire Wireless
| reply to nwrickert
|
|
  nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
| reply to nwrickert EPPIcard vish 772-924-0104
Email message text:
Dear EPPICard member,
We recently reviewed your account, and suspect that your EPPICard account may have been accessed from an unauthorized computer. This may be due to changes in your IP address or location. Protecting the security of your account and the EPPICard network is our primary concern. Therefor, we have temporarily blocked your banking account.
To unlock your account call our toll free number: 772-924-0104
To protect your account please follow the instructions below: - NEVER SHARE YOUR PASSWORD with other persons - ALWAYS LOG OFF after using your online account - NEVER access EPPICard`s website by clicking on a link provided in an e-mail
We apologize for any inconvenience this may cause, and appreciate your assistance in helping us maintaining the integrity of the entire EPPICard System.
Thank you, EPPICard Security Advisor.
Copyright 2008 EPPICard - The safe and secure way to acces your payments.
Headers:
-- AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14 |
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
1 edit | reply to nwrickert Re: [Phish] Telephone phishing thread
AA/Citibank Vish (also submitted to Phishtracker - see below) - posted here because there's also a telephone number.
Edit: This did not successfully get parsed by Phishtracker. The link first leads to hxxp://mail.mrfood.com/logo_servis.gif, but then redirects to hxxp://mail.opt-al.com/www.citicards.com/cards/wv/copy.doscreenID1214.htm
(The second link has already been reported to Google as a web forgery, and is still active as of the time of this post.)
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert A Point Bank vish that arrived today:
Dear CardHolder, Your debit card has open issues Contact us immediately for assistance. Toll Free Line: 1-(877)- 596-6749
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  Doctor Four My other vehicle is a TARDIS Premium join:2000-09-05 Dallas, TX
·AT&T U-Verse
| reply to nwrickert One from WAMU:
This part of the message is invisible. I found it by checking the page source:
"To activate your account please call urgent at 713-481-1635."
-- "The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)
|
|
  jaykaykay 4 Ever Young Premium,MVM join:2000-04-13 Scottsdale, AZ | reply to nwrickert Ooops. I guess I am a bit late! I just posted a thread about this in the Security Forum. Oh well. The more that hear about it, the better. |
|
  nwrickert sand groper Premium,MVM join:2004-09-04 Geneva, IL
·AT&T U-Verse
·AT&T Midwest
| Not a problem.
This thread is mainly for reporting specific instances. So discussing the phenomenon in a different thread is fine.
I'll add a link to your other thread: »Criminals have now gone 'vishing' -- AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1 |
|