register
-- Home
-- Phishing Archive
-- Report Phishing
-- Events
-- APWG News
-- Resources
-- Membership
-- APWG Member Site
-- Contact Us
-- JOIN THE APWG
 
LATEST NEWS IN THE FIGHT AGAINST PHISHING:
 
 
 
     
     
     
     
 

MSN - 'Microsoft Network customer data verification'
15-Feb-2005

Summary
Email title: Subjects vary widely within the spam wave
Scam target: MSN users
Sender:

various addressesat 'msn.net' or 'msn-network.com'

Sender spoofed/hidden? Spoofed
Scam goal: Getting victim's credit/debit card information
Phish link method a 'Click here' type link
Link 'masked'? Yes
Visible link: an 'Apply here' link
Actual link to: various domains. The names are constructed upon a word-slash-'msn.com', or 'msn'-slash-word'.com' scheme, i.e. 'explore-msn.com' or 'msn-site.com'.
Phish websites IP: 68.142.234.35
 
E-mail
 

This scam is a variation of another one, recently reviewed (the review can be found here), with an additional trick. It is being mass-mailed widely, and is one of the most frequently reported ones.

The email looks quite nice:

 
 
Yet this is where the trick lies. Seen in a normal HTML email, the text looks untampered. But it is in fact arranged in a HTML table, in which every symbol lies in a different cell, and the space between the visible lines is (i.e. every other row of the table) is filled with background-coloured dots. This trick can be exposed if the HTML of the message is opened in a HTML editor:
 
 
 
This trick makes it quite hard for the spam filters to block the message.
 
Web Site
Visible link: an 'Apply here' link
Actual link to: various domains. The names are constructed upon a word-slash-'msn.com', or 'msn'-slash-word'.com' scheme, i.e. 'explore-msn.com' or 'msn-site.com'.
Phish websites IP: 68.142.234.35
 

As mentioned, the phish site itself is designed just like the one reviewed here.

And as far as the server is concerned - it is obvoiously the hub of large spam/scam operations - 215 933 domains are registered on this IP!

 
WHOIS data (for IP 68.142.234.35):

Website Status: Active
IP Address: 68.142.234.35
IP Location: - California - Foster City - Inktomi Corporation
Blacklist Status: Clear
Record Type: Domain Name
Name Server: YNS1.YAHOO.COM YNS2.YAHOO.COM
ICANN Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Created: 02-feb-2005
Expires: 02-feb-2006
Status: ACTIVE

OrgName: Inktomi Corporation
OrgID: INKT
Address: 4100 East Third Avenue
City: Foster City
StateProv: CA
PostalCode: 94404
Country: US

NetRange: 68.142.192.0 - 68.142.255.255
CIDR: 68.142.192.0/18
NetName: INKTOMI-BLK-4
NetHandle: NET-68-142-192-0-1
Parent: NET-68-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.YAHOO.COM
NameServer: NS2.YAHOO.COM
NameServer: NS3.YAHOO.COM
NameServer: NS4.YAHOO.COM
NameServer: NS5.YAHOO.COM
RegDate: 2004-03-24
Updated: 2005-02-03

AbuseHandle: NA258-ARIN
AbuseName: Netblock Admin
AbusePhone: +1-408-349-3300

OrgTechHandle: ZI35-ARIN
OrgTechName: Inktomi Corporation
OrgTechPhone: +1-650-653-2800