dslreports logo
    All Forums Hot Topics Gallery
spc
Search Topic:
uniqs
56680
share rss forum feed


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert

Re: [Phish] Telephone phishing thread

Pentagon Federal Credit Union Phish

As before, the only thing changed was the name in the
X-Apparently-To header.

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


removed
Premium,VIP
join:2002-02-08
Houston, TX
kudos:41
reply to nwrickert
VISA - local number to me in Houston. Scary.

quote:
> VISA Security Department temporary disabled your account.

Verified by VISA will never ask you any information via e-mail. Call this number (832)772-7857 - Toll Free

You must reactivate your account immediately, or you won't be able to use your cards again.

> Sorry for any inconvenience this may cause and thank you for your patience.

> To reactivate your account call us: 832-772-7857- Toll Free

© 2001-2008 Visa. All Rights Reserved.

This message was sent to Email Id :

WPTLLOFITJBTPCIRFUNZMICCCONJSFMEEMUDLO
Headers:

--
irc.removed.us - #dslr | DSLR Phishtracker | Email: removed@dslr.net


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse
reply to nwrickert

[Phish] Credit Union 1 vish (ATM card)

Card Deactivation
Message from: Customer Service
Date: 04/02/2008
We detected irregular activity on your ATM/Check Card on 04/02/2008.
For your protection we have had to suspend any future authorizations
being conducted with your card.
For your security we have deactivate your card.
How to activate/re-activate your card ?
You may stop by your branch or call our Activation Center.

Activation Center: (866) 722-3235 (24 Hour Line)
Our automated system allows you to quickly activate your card.
We apologize for any inconvenience this may cause.
Copyright © 2008 Credit Union 1. All Rights Reserved.


--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.13


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert

Re: [Phish] Telephone phishing thread

This one apparently from CUNA regarding the Wal-Mart data
breach seems to be quite suspicious. It had me fooled for
a minute, until I looked more closely at the headers. Nice try.

As before, the only thing changed is the name in the X-
Apparently-To: header:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


DC DSL
There's a reason I'm Command.
Premium
join:2000-07-30
Washington, DC
kudos:2
reply to nwrickert
I got a Franklin. I called the number. There's a semi-realistic TRS on it that asks for the card number, PIN, expiration date.

I put in completely bogus info (like 1234567812345678 for the card number). After a brief pause, it came back with "card, PIN or expiration are not valid, please reenter." So, I made up different info. It took it, said the card is now active and valid worldwide and ended.

I called back a few more times. Sometimes I gave it identical data, others not. It took it all just the same.

It seems that it tries to make it seem legit to get someone to reenter the info to make sure they've got a live one. However, they farkled it and it doesn't catch mismatches.

This would be great rainy-day fun wasting their time and flooding them with bogus data if it wasn't a toll-free number that captures the number you're calling from regardless of caller id blocking. (Anyone near a pay phone wanna give it a go and see if they're stupid enough to not have blocked pay station callers?)

=====

Return-Path:
Received: from mail.im3.com [216.201.16.126] by mail.ultimahosts.com with SMTP;
Fri, 11 Apr 2008 16:25:02 -0400
Received: from User (unverified [72.28.171.9]) by cartman.im3.com
(Vircom SMTPRS 4.4.568.66) with ESMTP id ;
Fri, 11 Apr 2008 15:53:41 -0400
X-Modus-BlackList: bankfranklin@franklinsecurity.com=OK
X-Modus-Audit: FALSE;0;0;0
Reply-To:
From: "Franklin Bank"
Subject: Card Deactivation
Date: Fri, 11 Apr 2008 15:53:36 -0400
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-Rcpt-To:
X-SmarterMail-Spam: SPF_None

Card Deactivation
Message from: Customer Service
Date: 04/10/2008
We detected irregular activity on your ATM/Check Card on 04/10/2008.
For your protection we have had to suspend any future authorizations being
conducted with your card.
For your security we have deactivate your card.
How to activate/re-activate your card ?
You may stop by your branch or call our Activation Center.

Activation Center: (866) 578-0984 (24 Hour Line)

Our automated system allows you to quickly activate your card.
We apologize for any inconvenience this may cause.
Copyright © 2006 Franklin Bank. All Rights Reserved.
--
There is no giant fur-bearing trout.


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
Another Franklin Bank one:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Snowy
Premium
join:2003-04-05
Kailua, HI
kudos:6
Reviews:
·Time Warner Cable
·Clearwire Wireless
reply to nwrickert

Lizz_Vish_Archived

X-Apparently-To: myemail@pacbell.net via 209.191.85.225; Tue, 15 Apr 2008 10:39:54 -0700
X-Originating-IP:[212.85.249.132]
Return-Path:
Authentication-Results:mta121.sbc.mail.mud.yahoo.com from=franklin.com; domainkeys=neutral (no sig)
Received:from 207.115.36.53 (EHLO nlpi024.prodigy.net) (207.115.36.53) by mta121.sbc.mail.mud.yahoo.com with SMTP; Tue, 15 Apr 2008 10:39:52 -0700
X-Header-Overseas:Mail.from.Overseas.source.212.85.249.132
X-Originating-IP:[212.85.249.132]
Received:from node-2.minx.net.uk (node-2.minx.net.uk [212.85.249.132]) by nlpi024.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m3FHdoDY014536 for ; Tue, 15 Apr 2008 12:39:50 -0500
Received:from [195.82.101.89] (helo=mail.QuantumFittedFurniture.co.uk) by node-2.minx.net.uk with esmtp (Exim 4.60) (envelope-from ) id 1JlpIR-0005rN-Og for myemail@pacbell.net; Tue, 15 Apr 2008 18:50:20 +0100
Received:from User ([192.168.0.250] RDNS failed) by mail.QuantumFittedFurniture.co.uk with Microsoft SMTPSVC(6.0.3790.3959); Tue, 15 Apr 2008 18:29:09 +0100
Reply-to:
From:"Franklin Bank" Add to Address BookAdd to Address Book Add Mobile Alert
Subject:Card Deactivation
Date:Tue, 15 Apr 2008 13:39:36 -0400
MIME-Version:1.0
Content-Type:text/plain; charset="Windows-1251"
Content-Transfer-Encoding:7bit
X-Priority:3
X-MSMail-Priority:Normal
X-Mailer:Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE:Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Message-ID:
X-OriginalArrivalTime:15 Apr 2008 17:29:10.0078 (UTC) FILETIME=[37021DE0:01C89F1E]
X-MINX-Orig-IP:195.82.101.89
X-Spam-Score:2.9 (++)
X-Spam-Level:++
Content-Length:563

Card Deactivation
Message from: Customer Service
Date: 04/15/2008

We detected irregular activity on your ATM/Check Card on 04/15/2008.
For your protection we have had to suspend any future authorizations
being conducted with your card.

For your security we have deactivate your card.

How to activate/re-activate your card ?

You may stop by your branch or call our Activation Center:

Activation Center: (866) 797-5640 (24 Hour Line)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert

Re: [Phish] Telephone phishing thread

Yet another Franklin Bank one, trying to look legitimate by
warning recipients of phishing scams. They're not fooling me.

The phone number's likely bogus, and the IP address 72.28.171.9 is likely a botnet zombie (it certainly
isn't one of Franklin's IPs). The Corporate Office
address is real, however.


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
Another Franklin Bank one, same phone number as before:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

3 edits
reply to nwrickert
Click for full size
Amarillo National Bank vish:


URLs for both the forged ANB and Verisign logos in the
body of the phish (posted as JPG as it is all html)

ANB: hxxp://jeannemcallister.com/logo.gif
Verisign: hxxp://jeannemcallister.com/logo-verisign.gif

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Lizz
Premium
join:2002-10-22
Fullerton, CA
reply to nwrickert
A vish AND a phish, all in one! (and with all the spamcatcher info in the header, ATT/Yahoo still left it in my inbox, not the bulk )

From Bank of America Fri May 2 06:59:39 2008
X-Apparently-To: XXX@pacbell.net via 209.191.85.223; Fri, 02 May 2008 07:01:12 -0700
X-Originating-IP: [64.97.155.27]
Return-Path:
Authentication-Results: mta136.sbc.mail.re3.yahoo.com from=alerts.bankofamerica.com; domainkeys=neutral (no sig)
Received: from 207.115.20.65 (EHLO flpi096.prodigy.net) (207.115.20.65) by mta136.sbc.mail.re3.yahoo.com with SMTP; Fri, 02 May 2008 07:01:12 -0700
X-Originating-IP: [64.97.155.27]
Received: from sc2.he.tucows.com (smtpout2027.sc2.he.tucows.com [64.97.155.27]) by flpi096.prodigy.net (8.13.8 inb regex/8.13.8) with ESMTP id m42E1Bpw001455 for ; Fri, 2 May 2008 07:01:11 -0700
Received: from sc2-out04.emaildefenseservice.com (64.97.201.174) by sc2.he.tucows.com (7.3.127) id 48188F54000E71E6; Fri, 2 May 2008 13:59:46 +0000
Message-ID: (added by postmaster@globo.com)
X-SpamScore: 96
X-Spamcatcher-Summary: 96,15,0,9ea1071f6304b62f,0631c5bc6dd70dd7,alert@alerts.bankofamerica.com,-,
X-Spamcatcher-Explanation: (33%) BODY: mail is from Bank of America but doesn't contain any Bank of America URLS;(27%) BODY: likely phishing content;(13%) X-MAILER: mail headers not consistent with User Agent "Outlook";(13%) HTML: HTML code not consistent with User Agent "Outlook";(7%) BODY: text/html email has no html tag;(7%) BODY: content type is strictly "text/html";
Received: from User (unknown [41.223.251.88]) (Authenticated sender: atm05@globo.com) by sc2-out04.emaildefenseservice.com (Postfix) with ESMTP; Fri, 2 May 2008 13:59:19 +0000 (UTC)
From: "Bank of America" Add to Address BookAdd to Address Book Add Mobile Alert
Subject: Online Banking Verification
Date: Fri, 2 May 2008 14:59:39 +0100
MIME-Version: 1.0
Content-Type: text/html; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Content-Length: 2867

Dear Valued Bank of America Online Customer:

IMPORTANT: Your online account information must be confirmed and verified to ensure uninterrupted service.

To enhance the level of service you receive with Bank of America Online Services, we regularly review the online banking accounts. We have issued this warning message to inform you that we have detected a slight error in your account information. This might be due to either of the following reasons:.
bullet A recent change in your personal information ( i.e.change of address).
bullet Submiting invalid information during the initial sign up process.
bullet An inability to accurately verify your selected option of payment due to an internal error within our processors.

As a result, we require you to confirm and verify your account information By Clicking Here and completing the confirmation process.

Note
However, failure to confirm and verify your account information will result in temporarily account suspension. Please understand that this is a security measure intended to help protect you and your account. We apologize for any inconvenience.
If you have any question regarding this, please call us at 888-692-5949, 24 hours a day, seven days a week. or simply Sign In to Online Banking and click on "Help".

Thank you for banking at Bank of America. We look forward to serving your financial needs for many years to come.


Lizz
Premium
join:2002-10-22
Fullerton, CA
So you all don't think I'm nuts, the "simply sign on" is a link to a phishing site which DOES show in phishtracker.


Snowy
Premium
join:2003-04-05
Kailua, HI
kudos:6
Reviews:
·Time Warner Cable
·Clearwire Wireless
reply to nwrickert


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse
reply to nwrickert

EPPIcard vish 772-924-0104

Email message text:

Dear EPPICard member,

We recently reviewed your account, and suspect that your EPPICard account may
have been accessed from an unauthorized computer. This may be due to changes
in your IP address or location. Protecting the security of your account and
the EPPICard network is our primary concern. Therefor, we have temporarily
blocked your banking account.

To unlock your account call our toll free number: 772-924-0104

To protect your account please follow the instructions below:
- NEVER SHARE YOUR PASSWORD with other persons
- ALWAYS LOG OFF after using your online account
- NEVER access EPPICard`s website by clicking on a link provided in an e-mail

We apologize for any inconvenience this may cause, and appreciate your
assistance in helping us maintaining the integrity of the entire EPPICard System.

Thank you,
EPPICard Security Advisor.

Copyright 2008 EPPICard - The safe and secure way to acces your payments.


Headers:

--
AT&T dsl; Westell 327w modem/router; SuSE 10.1; firefox 2.0.0.14


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX

1 edit
reply to nwrickert

Re: [Phish] Telephone phishing thread

Click for full size
AA/Citibank Vish (also submitted to Phishtracker - see below) - posted
here because there's also a telephone number.


Edit: This did not successfully get parsed by Phishtracker. The
link first leads to hxxp://mail.mrfood.com/logo_servis.gif, but then
redirects to hxxp://mail.opt-al.com/www.citicards.com/cards/wv/copy.doscreenID1214.htm

(The second link has already been reported to Google as a
web forgery, and is still active as of the time of this post.)

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
A Point Bank vish that arrived today:


Dear CardHolder,
Your debit card has open issues
Contact us immediately for assistance.
Toll Free Line: 1-(877)- 596-6749

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
One from WAMU:

This part of the message is invisible. I found it by
checking the page source:

"To activate your account please call urgent at 713-481-1635."

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
USA
kudos:24
reply to nwrickert
Ooops. I guess I am a bit late! I just posted a thread about this in the Security Forum. Oh well. The more that hear about it, the better.


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse
Not a problem.

This thread is mainly for reporting specific instances. So discussing the phenomenon in a different thread is fine.

I'll add a link to your other thread:
»Criminals have now gone 'vishing'
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1
Expand your moderator at work


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7

1 recommendation

reply to nwrickert

Farmers State Bank

Submitted phish #31133 is really a voice/telephone vish for phone number (888) 687-5642.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1
Expand your moderator at work


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
reply to nwrickert

Salin Bank

The Salin Bank phish #31431 is really a voice/telephone vish for 1-800-681-2713.
--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1


Lizz
Premium
join:2002-10-22
Fullerton, CA
reply to nwrickert

Re: [Phish] Telephone phishing thread



Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
American National Bank Of Texas:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
Two more from ANB Texas, with a different phone number:


Second message has the same phone number and message body,
but different headers:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert
One from Uniter Heritage Credit Union:


--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)


nwrickert
sand groper
Premium,MVM
join:2004-09-04
Geneva, IL
kudos:7
Reviews:
·AT&T U-Verse
reply to nwrickert
Resource bank. Phone number is 815-981-4765


--
AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.3


DC DSL
There's a reason I'm Command.
Premium
join:2000-07-30
Washington, DC
kudos:2
reply to nwrickert

877-214-0565 - Community Financial Members Federal Credit Union

The message:
ADVISORY: Some members and non-members of Community Financial Members Federal Credit Union have received fraudulent emails. This email was NOT issued by Community Financial Members Federal Credit Union, and should be deleted. Do not follow the instructions in the email. Do not click the link. For security reasons we have deactivated your debit card. Please call our toll-free hotline at (877) 214-0565 to activate your debit card.


Headers:


It's so touching how much they care for "members and non-members" alike, and have deactivated my debit card for me!

Frickin morons...they couldn't even send well-formed HTML!

--
There is no giant fur-bearing trout.


Doctor Four
My other vehicle is a TARDIS
Premium
join:2000-09-05
Dallas, TX
reply to nwrickert

Re: [Phish] Telephone phishing thread

Click for full size
800-523-8103 Capital One

Sent to my mother's Yahoo email. Only thing changed is the first part of the To: address


The attached logo is the one the phisher used. They left off "what's in your wallet?", which normally is positioned beginning right below the 'One' part of the name.

--
"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)