May 18, 2012

Anatomy of a Phishing Email

I encountered a great opportunity this evening, the opportunity to share an inside look of a Phishing Email. What is Phishing?

“In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication.” – Wikipedia

What I noticed was an Email purportedly from Bank of America telling me that there was an “Account Resolution Required”:

Phishing Message Bank of America

Message in Outlook Allegedly from Bank of America

I scanned over to the preview pane and noticed that it had a link that appeared to be correct, so I hovered over the link to see if the link was spoofed and to no big surprise, it was. Here is how the message looked in my preview pane, I did not download pictures because that is a popular way for spammers/crooks to confirm Email addresses of their targets/victims:

Full Phishing Email Screenshot

Full Phishing Email Screenshot

Let me further clarify in lay terms, the link that reads:

https://www.bankofamerica.com/home/1244618/ddjdfdkfi126.aspx?screenid=Update_Acct

is actually:

http://prostyle-esports.nl/index.php

and this is evident when I hover over, or place my mouse cursor on the “alleged” link. This is a tactic you can use to check links you are unsure of. However I should clarify that it doesn’t always work. There have been occasions where this has been spoofed effectively typically it has to do with the Email client or Browser and security patches on your computer.

Testing the Link

Using a test environment I pasted the link to see what the target site looked like:

Blocked - Forgery

Blocked - Forgery

I was pleased to see it had been blocked, this saved me the time of researching and Emailing the Internet Provider involved. After confirming this I used “properties” on Outlook to get the header information, there is a lot of information but plenty of clues to let me know that this message was not authentic (had everything else appeared right, which most certainly the SSL certificate warning would have popped up unless it was an unprecedented forgery!). Here are a few of the more obvious lines I parsed from the headers:


Received: from User ([82.128.0.69]) by post.strato.de (mrclete mo25) (RZmta
23.3) with ESMTP id 20016am5E507CT ; Mon, 14 Jun 2010 07:43:29 +0200 (MEST)
Reply-To:
From: Bank of America


In the above examples, you can see that the message replay and from don’t match and that the mail server is post.strato.de not a likely mail server for Bank of America (perhaps for Deutsche Bank next time guys?). Also after running the IP address of the sender 82.128.0.69 on Arin.net I was able to determine that it was a European Address (which I had already figured due to the .de domain on the mail server, but it was further validation):

Output of Arin.net Whois - RIPE

Output of Arin.net Whois - RIPE

There are a lot of ways to spot fraudulent/Phishing Emails. Our advice to our clients is if they are not 100% certain we recommend they forward the messages to us for analysis. Most of these kinds of messages are blocked and we don’t see them, but if something doesn’t look quite right it probably isn’t.

Enhanced by Zemanta

Popularity: 8% [?]

Update Microsoft Office Products – Joe Reviews SB10-074 Cert Report (Video)

Here is a review of this weeks Cert Advisory. This update contains the infamous Arucer.dll that came with the charging software on the Energizer Duo USB. Also definitely recommend updating your Microsoft Office products if you haven’t recently. This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook Fan Page.

Reblog this post [with Zemanta]

Popularity: 5% [?]

Update Adobe Acrobat, Again – Joe Reviews SB10-060 Cert Report (Video)

Here is a review of this weeks Cert Advisory. Adobe Acrobat has returned, please be sure to update! This is a weekly feature here at Managed Solutions. If you have questions about this video post a comment here or ask on our Facebook Fan Page.

Reblog this post [with Zemanta]

Popularity: 3% [?]

Google Chrome Vulnerabilities – Joe Reviews SB10-053 Cert Report (Video)

Here is a review of this weeks Cert Advisory. Surprising number of Google Chrome issues this week, luckily Chrome is updated constantly and quietly without prompting. This is a weekly feature here at Managed Solutions.

    Popularity: 2% [?]

    Run Windows Updates – Joe Reviews SB10-046 Cert Report (Video)

    Here is a review of this weeks Cert Advisory. This week is Microsoft triage week, there are a ton of 9.3 severity and above (out of 10) vulnerabilities. This is a weekly feature here at Managed Solutions. What can you do to protect yourself:

    1. Perform Windows updates when prompted or visit http://update.microsoft.com/windowsupdate
    2. Perform Office Updates if you use any of the Micrososft Office family products at http://office.microsoft.com
    3. Be cautious with file attachments and links in Email and practice more careful browsing habits.

    Popularity: 2% [?]

    Solving the problem with large attachments (Video) Drop.io

    Our partner Drop.io has recently created a functional beta of a plugin that allows you to share file(s) up to 100mb (for free) or greater (with paid subscription) simply via Microsoft Outlook. In this video we demonstrate where to get the plugin and how to use it. We are an affiliate of drop.io and if you would like a paid subscription you can use the featured product links in the right hand navigation menu on our website or by clicking here.

    Popularity: 5% [?]

    Joe Reviews SB10-040 Cert Report (Video)

    Here is a review of this weeks Cert Advisory. The main highlight are the vulnerabilities in Internet Explorer version 5, which is not broadly used. This is a weekly feature here at Managed Solutions.

    Popularity: 2% [?]

    Joe Reviews SB10-32 Cert Report (Video)

    These are weekly reviews of the reports from CERT. The main highlights are some Realplayer vulnerabilities and the Cisco Unified Meeting Place. This is a weekly feature here at Managed Solutions.

    Cisco Unified Meeting Place Bulletins

    Popularity: 2% [?]

    ADP Warns of Phishing Emails to Payroll Clients

    We were made aware of an issue that ADP is reporting with some of their Payroll customers. Here is the text of the warning message they are sending their clients:

    “ADP is receiving reports of a phishing email scam targeting ADP EasyPayNet clients who perform their payroll via the Internet.  Phishing email scams are designed to mimic legitimate websites and are intended to compromise your login credentials.  The email is fraudulent and did not come from ADP.  Please immediately delete the email and do not click on any links in the email or enter any login information.  Please be aware that ADP would never send an email asking you to provide or enter your login credentials for any reason.”

    Here is a screenshot of the Phishing Email:

    Sample of ADP Phishing Email

    Sample of ADP Phishing Email

    Popularity: 24% [?]

    Joe Reviews SB10-25 Cert Report (Video)

    These are weekly reviews of the reports from CERT. Nothing too horrible this week, but I provide more insights into what to look for and why. I did review the Shockwave Player vulnerability after recording the video and determined that since it is not a common component for most of our audience it did not merit a separate bulletin and notice. This is a weekly feature here at Managed Solutions.

    Related Posts Plugin for WordPress, Blogger...

    Popularity: 2% [?]