Another Fifth Third Bank Phising Email

12/27/06

Permalink 07:40:17 am, by dave Email , 637 words, 196 views   English (US)
Categories: Security, Phishing

Another Fifth Third Bank Phising Email

Another Fifth Third Bank Phising Email

I just received another Fifth Third Bank phising email. The subject line was Dear Fifth Third Bank Cusotmer. This email contained an image that showed a message supposedly from Fifth Third Bank. The entire image is a link to the site that would perform the phishing. When I tried to access the link that the image points to, I recieved the following error.

Server Error
The following error occurred:
[code=SERVER_RESPONSE_RESET] The server response could not be read because of an error. Contact your system administrator.

--------------------------------------------------------------------------------
Please contact the administrator

The text of the email is:

Dear Fifth Third bank business/commercial customer,

Fifth Third Protection Department requests you start the client details confirmation procedure. By clicking on the link at the bottom of this letter you will get all necessary instructions how to start and complete the confirmation procedure. The following steps are to be taken by all business and commercial customers of the Fifth Third bank.

Fifth Third Protection Department apologizes for the inconveninces caused to you, and is very grateful for your cooperation.

To start the confirmation procedure, click the following link:

[a picture of a valid link is shown here]

Here is what the actual message looks like:


Phishing Test Image

[More:]

Here is the message source for the email I received. My email info has been changed prior to this posting, but otherwise it is exactly as I received it. The two links in the message section below will take you to two different IP address lookup utilities that will allow you to see who owns these IP addresses.

Return-path: <manager-id6609459634ver@security.53.com>
Envelope-to: xxxxxxxxxx @ davemoats.com
Delivery-date: Mon, 25 Dec 2006 05:56:20 -0700
Received: from [86.75.171.230] (helo=230.171.75-86.rev.gaoland.net)
by [ My Email Server ]
id 1GypNH-0000Eb-Vx
for xxxxxxxxxx @ davemoats.com; Mon, 25 Dec 2006 05:56:19 -0700
Received: from grungecafe.com (grungecafe.com.dizinc.com [102.162.206.16])
by outblaze.com with SMTP id 8OFCCIH7X5
for <xxxxxxxxxx @ davemoats.com>; Mon, 25 Dec 2006 07:56:06 -0500
Sender: "Fifth Third Bank" <manager_id2257901243ver@security.53.com>
From: "Fifth Third Bank" <manager-id6609459634ver@security.53.com>
To: "Xxxxxxxxxx" <xxxxxxxxxx @ davemoats.com>
Subject: Dear Fifth Third Bank Customer!
Sender: "Fifth Third Bank" <manager_id2257901243ver@security.53.com>
User-Agent: Internet Mail Service (5.5.2650.21)
X-Mailer: Internet Mail Service (5.5.2650.21)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/related;
boundary="002Z_KG1F4SQ4WD588FY"

--002Z_KG1F4SQ4WD588FY
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=utf-8">
<META content="MSHTML 6.00.2800.1522" name=GENERATOR></HEAD>
<BODY bgcolor="#FFFFFC" text="#D89D6A">
<a hREf=http: //www .53.com.bankingportal.id74557407256773.missch.biz/sbcbconfirm>
<img src="cid:RY4PEFSH2I" border=0></a>
</p><p><font color="#FFFFF6">"Get the hell out of here! comport bestow He tried not to but couldn't help it.</font></p><p><font color="#FFFFFD">Cat then crawls as close to his mistresses as possible before expiring — and killing one of said mistresses. Oh boy. "Let me offer again, Paul. Paul heard the screen's hinges squeak, and then they were in. At that she had not scrupled. There was another that seemed to exist mostly in his mind, but which was no less real for that. "That was when I started to realize I could have a problem with you even if no one from the outside suspected a thing. angelfish</font></p>
</BODY>
</HTML>

--002Z_KG1F4SQ4WD588FY
Content-Type: image/gif; name="consequent.gif"
Content-Transfer-Encoding: base64
Content-ID: <RY4PEFSH2I>
--002Z_KG1F4SQ4WD588FY--

If you receive an email like this DELETE IT.



Did you like this post? If so, Share it!  del.icio.us digg reddit slashdot this article Facebook Twitter MySpace Email



Pingbacks:

No Pingbacks for this post yet...

IS Security

Thoughts, ideas, and concerns about Information security.

Search

Follow Me:

Misc

Who's Online?

  • Guest Users: 1

powered by b2evolution free blog software