 Reviews:
·Charter
| Good Bank of America Phish Looks real |  notice the address bar |
Just wanted to post some pictures of what seems to be a very good phish attempt. -- There's so much to be thankful for...How can anyone be sad? |
|
|
|
 nwrickertsand groperPremium,MVM join:2004-09-04 Geneva, IL kudos:7 | This seems to be the phish you submitted to »/phishtrack and appears as phish #37948. Thanks for submitting. -- AT&T dsl; Speedstream 5100b modem; openSuSE 11.0; firefox 3.0.11 |
|
 antiphishingPhishing Scam TerminatorPremium join:2004-06-09 Wilkes Barre, PA kudos:2 Reviews:
·PenTeleData
·ProLog
| said by nwrickert:This seems to be the phish you submitted to » /phishtrack and appears as phish #37948. Thanks for submitting. Was the phishing site: httx://70.90.182.---/Onlineid/Onlineid.bankofamerica/bankofamerica.com/Online_Banking/security.update/update.bankofamerica.com/
I am trying to get that site terminated off the internet.  --
Specializing in "takes downs" of phishing and advance fee scams Send your Phishing/Advance fee scams to: phish@antihotmail.com »www.phishtank.com »www.fraudwatchers.org »mozilla.com
|
|
 nwrickertsand groperPremium,MVM join:2004-09-04 Geneva, IL kudos:7 | No it wasn't. But you can see for yourself at »/phishtrack?pi···8&urls=1 -- AT&T dsl; Speedstream 5100b modem; openSuSE 11.0; firefox 3.0.11 |
|
 Doctor FourMy other vehicle is a TARDISPremium join:2000-09-05 Dallas, TX | reply to nirvansk815 Has anyone reporting this phish to Google so that it shows up as a reported web forgery for Firefox users? |
|
 MGDPremium,MVM join:2002-07-31 kudos:9 | I am not sure about that, however, SURBL picks up phishtrack submits in real time, and others may as well. MSIE currently flags the culturalclassics.com domain as a phishing site. Tinyurl has disabled the tinyurl.com initial redirect.
MGD |
|
 garys_2kPremium join:2004-05-07 Farmington, MI Reviews:
·Callcentric
·Future Nine Corp..
| reply to Doctor Four said by Doctor Four:Has anyone reporting this phish to Google so that it shows up as a reported web forgery for Firefox users? Yes, I did as soon as I saw it. It still shows without the warning so I did it again, just now. Hopefully it will get their attention. |
|
 madylarianThe curmudgeonlyPremium join:2002-01-03 Parkville, MD | reply to nirvansk815 Rather, it's a not-very-good phish. Dead giveaways:
1. Bank Of American Bill Pays Notification Services
2. Dear Customer instead of Dear *Your Name*
mady -- Honi soit qui mal y pense |
|
 MGDPremium,MVM join:2002-07-31 kudos:9 | Yes, it has errors that belies its Eastern European non native English origin. However, the presentation is rather unique, so is the the drop down javascripted box format, that will request both online bank log in, and card data. Plus site key answers and victim's Drivers License, DOB, SSN, & MMN.
Even though the files are dated from May of 2008,
I don't recall seeing the exact phish format before. Maybe nwrickert has.
MGD |
|
 MGDPremium,MVM join:2002-07-31 kudos:9 1 edit | reply to nirvansk815 said by nirvansk815:Just wanted to post some pictures of what seems to be a very good phish attempt. You don't by chance have the originating IP of that phishmail.?
MGD |
|
 Reviews:
·Charter
| said by MGD:said by nirvansk815:Just wanted to post some pictures of what seems to be a very good phish attempt. You don't by chance have the originating IP of that phishmail.? MGD Hopefully what you need is inside this header. If not, let me know where to look.
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MjtTQ0w9NA==
X-Message-Status: s3:0
X-SID-PRA: billpay-alert@bankofamerica <e-alert-update@bankofamerica.com>
X-SID-Result: SoftFail
X-Message-Info: dpeAAki3kMS5MfdIIv4qnXWmWRVCOXEotpHEqZVh/uQdqaxlz5hlwhPg/dc4fC5y0BJ0b5W34GTaFeUlTy1DdMCt8mAw/+AT
Received: from mxi1.callplus.net.nz ([202.180.66.203]) by col0-mc3-f30.Col0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);
Tue, 30 Jun 2009 07:32:07 -0700
Message-Id: <7mumo6$7kdksd@ismtp01.callplus.net.nz>
Received: from 8.159.86-79.rev.gaoland.net (HELO User) ([79.86.159.8])
by ismtp01.callplus.net.nz with ESMTP; 01 Jul 2009 02:31:24 +1200
From: "billpay-alert@bankofamerica"<e-alert-update@bankofamerica.com>
Subject: Bank Of America Alert : Important Customer Service Message
Date: Tue, 30 Jun 2009 07:32:02 -0700
MIME-Version: 1.0
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 1
X-MSMail-Priority: High
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Bcc:
Return-Path: e-alert-update@bankofamerica.com
X-OriginalArrivalTime: 30 Jun 2009 14:32:07.0490 (UTC) FILETIME=[8B9F9220:01C9F98F]
-- There's so much to be thankful for...How can anyone be sad? |
|
 MGDPremium,MVM join:2002-07-31 kudos:9 | said by nirvansk815: Hopefully what you need is inside this header. If not, let me know where to look. Excellent, thank you. Originated in France then relayed via a server in New Zealand.
MGD |
|