• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

Phishers Phished!

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Phishers Phished!

    The ease of use and availability of tools used for malicious schemes have always been a problem for security companies, since these greatly contribute to the quick proliferation of codes and files that can affect Internet users. Web sites that represent an individual or group of individuals giving away free code and software for the whole community to use as they please are available almost anywhere.

    Netcraft recently reported of a certain “Mr. Brain” — actually a group of Moroccan fraudsters who recently launched a dedicated Web site for free phishing kits that anyone can use for their phishing activities. They lure interested parties by packaging the code as “easy-to-use” and “programmer-friendly,” since only a requirement on basic programming is needed to deploy this kit. Visitors of this site would hardly think twice in going for the bait, but upon closer inspection, it turns out that, though powerfully alluring, most good things are just too good to be true.



    Certain codes were found to reveal the true nature of the email addresses where the phished information are to be sent once they were retrieved from the phishers’ victims: though the phished information are sent to the phishers, a copy of the phished information is also covertly sent back to Mr. Brain. Further analysis reveals what look like Mr. Brain’s email addresses from these code snippets:
    <input type=”hidden” name=”niarB” value=”32970696f6e6565722e627261696e40676d61696c2e 636f6d” />
    and
    <input TXItQnJhaW5ARXZpbC1CcmFpbi5OZXQ=”);?>” name=”Send” type=”hidden” />
    These code segments translate to the email addresses where the stolen information is sent.

    Suffice it to say that the phishers who thought they had their victims didn’t know they had been had by Mr. Brain. This con saves Mr. Brain the more arduous task of hacking and compromising Web sites and deploying the phishing pages by himself: clearly a classic one-uppance the likes of which have never been seen before with regard to online theft.

    Researcher Ivan Macalintal itemized the following banking and other establishments that can be affected by the Mr. Brain phishing scheme:
    • abbey.co.uk
    • bankofamerica.com
    • chase.com
    • e-gold.com
    • ebay.com
    • hsbc.co.uk
    • lloydstsb.com
    • moneybookers.com
    • nationwide.co.uk
    • nbk.com.kw
    • paypal.com
    • regions.com
    • stgeorge.com.au
    • wachovia.com
    • westernunion.com
    Further investigation reveals that these phishing kits are now being actively used. More information will be povided regarding this so stay tuned to this post. Investigation about this operation is currently underway, and the authorities have been contacted for the proper action regarding this.

    Ivan Macalintal and Senior Threat Analyst Robert McArdle provided information

View our Terms and Conditions

LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
Working...
X