register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

Amazon.com- 'Account Verification Notice'
31-Jan-2005

Summary
Email title: 'Account Verification Notice'
Scam target: Amazon.com users
Sender:

service@amazon.com

Sender spoofed/hidden? Spoofed
Phish 'punch line' : 'During our regular update and verification of the accounts, we couldn't verify your account information...Please update and verify your information below'
Scam goal: Getting victim's credit/debit card information, email address and amazon.com password
Phish link method A 'click here' type link
Link 'masked'? Yes
Visible link: 'Sign in using our secure server' button
Actual link to: http://www.amazon-department.com/exec/obidos/flex-sign-in/ref-ya_hp_pi_5/1-click-settings/104-0220521-9331958
Phish website IP:

68.142.234.35

 
E-mail
 
This attack against Amazon.com is particularly nice-looking. Here is a screenshot of the HTML email it is being sent as:
 
 
All the links in the email lead to the same phish page. But the effect of the nice design is convincing on the potential victim. The sender is spoofed, adding to the effect.
 
Web Site
Visible link: 'Sign in using our secure server' button
Actual link to: http://www.amazon-department.com/exec/obidos/flex-sign-in/ref-ya_hp_pi_5/1-click-settings/104-0220521-9331958
Phish website IP:

68.142.234.35

 
The site continues the nice design trend. The domain name is also carefully chosen to match amazon.com in a realistic manner:
 
 
The session is unsecured (no https) which is the main phish clue here. After the 'login' page, another one is displayed:
 
 
Notice that the phish will not try to get too much information, in order not to instill too much suspicion. But the information entered will not be checked - the site will immediately redirect to the legitimate amazon.com page:
 
 
As far as the server, hosing the phish is concerned - there have been some other phishing attacks from the same location before. This indicates possibly repeating perpetrators.
 
WHOIS information (for IP 68.142.234.35):

IP Address: 68.142.234.35
IP Location: - California - Foster City - Inktomi Corporation

Domain Name.......... amazon-department.com
Creation Date........ 2005-01-17
Registration Date.... 2005-01-17
Expiry Date.......... 2006-01-17
Organisation Name.... Mary Kerznere
Organisation Address. 40 Massasoit Rd.
Organisation Address. Duxbury
Organisation Address. 02332
Organisation Address. MA
Organisation Address. UNITED STATES

Admin Name........... Mary Kerznere
Admin Address........ 40 Massasoit Rd.
Admin Address........ Duxbury
Admin Address........ 02332
Admin Address........ MA
Admin Address........ UNITED STATES
Admin Phone.......... +1.7819344460

Tech Name............ YahooDomains TechContact
Tech Address......... 701 First Ave.
Tech Address......... Sunnyvale
Tech Address......... 94089
Tech Address......... CA
Tech Address......... UNITED STATES
Tech Phone........... +1.6198813096
Tech Fax............. +1.6198813010
Name Server.......... yns1.yahoo.com
Name Server.......... yns2.yahoo.com