Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: ALERTS

UK and US customers of PayPal™, Abbey and Halifax beware

Date: 06/09/2009
Author: Razvan Livintz

UK and US customers of PayPal™, Abbey and Halifax beware

The latest phishing campaign targeting e-banking and e-payment customers features several malicious components. First, the unsolicited message that disseminates the malware purports to deliver the ultimate Open Source Antivirus Solution, asking the users to visit a Web page where they can download the product.

Rogue

However, upon clicking the link, the user does not receive the promised security suite, but a fake executable - setup.exe - which is, in effect, a self-extracting archive. Its purpose is to replace the content of C:\WINDOWS\System32\drivers\etc and to alter the Web browser's behavior, by automatically loading maliciously crafted pages for phishing purposes of PayPal, Abbey and Halifax.

Each time the user types in his or her browser the address belonging to one of these financial institutions, he or she is automatically redirected towards the fake pages. Here, the log in credentials (user name, password, security code) and other sensitive data (first and last name, complete home and e-mail address, credit card number, expiration date, Card Verification Code, and even PIN) are pilfered using PHP scripts. All other menu options available on each page redirect the user towards the appropriate sections of the genuine Web site. The analysis revealed that the bogus Web pages load from domains registered in China and Korea.

 

Rogue 2

 

Rogue 3

 

Rogue 4

Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
February 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
       
« Jan February Mar »
Tag Claud
bitdefender system antivirus exploit omelette malware rogue virus conficker data pharmacy infected message security spam botnet downadup canadian windows software word computer messages twitter worm file files review trojan microsoft