Normal
0
false
false
false
EN-US
X-NONE
X-NONE
MicrosoftInternetExplorer4
st1:*{behavior:url(#ieooui) }
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:”Table Normal”;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:””;
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:”Calibri”,”sans-serif”;
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:”Times New Roman”;
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;
mso-bidi-font-family:”Times New Roman”;
mso-bidi-theme-font:minor-bidi;}
The latest phishing campaign targeting e-banking and
e-payment customers features several malicious components. First, the
unsolicited message that disseminates the malware purports to deliver the
ultimate Open Source Antivirus Solution, asking the users to visit a Web page
where they can download the product.
However, upon clicking the link, the user does not receive
the promised security suite, but a fake executable – setup.exe – which is, in effect, a self-extracting archive. Its
purpose is to replace the content of C:WINDOWSSystem32driversetc
and to alter the Web browser’s behavior, by automatically loading maliciously
crafted pages for phishing purposes of PayPal, Abbey and Halifax.
Each time the user types in his or her browser the address
belonging to one of these financial institutions, he or she is automatically
redirected towards the fake pages. Here, the log in credentials (user name,
password, security code) and other sensitive data (first and last name,
complete home and e-mail address, credit card number, expiration date, Card
Verification Code, and even PIN) are pilfered using PHP scripts. All other menu
options available on each page redirect the user towards the appropriate sections
of the genuine Web site. The analysis revealed that the bogus Web pages load
from domains registered in China
and Korea.
tags
I rediscovered "all that technical jazz" with the E-Threat Analysis Team at Bitdefender, the creator of one of the industry's most effective lines of internationally certified security software.
View all postsSeptember 06, 2024
September 02, 2024