Morning
If anyone from Westpac Security monitors NZNOG, and for those that want
to update their mail rulesets appropriately, there appears to be a new
phish this morning for Westpac. I've received 6 in the last 10 minutes.
All originate from 219.128.152.213, a Chinanet host or 82.229.209.178.
The body refers people to http://secwestpac.com/IOLB/newSession .
The hostname is similar to their correct "sec.westpac.co.nz". The
domain hasn't yet been pushed into WHOIS, but is in the GTLD servers.
The body of the message is HTML, with Westpac graphics. The text is:
Processing error
We were unable to process your recent transactions on your account. To
ensure that your account is not suspended, please update your information
Headers below.
aj
From - Mon Sep 19 10:28:31 2005
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-Path:
At 10:31 19/09/2005, Alastair Johnson wrote:
Morning
If anyone from Westpac Security monitors NZNOG, and for those that want to update their mail rulesets appropriately, there appears to be a new phish this morning for Westpac. I've received 6 in the last 10 minutes.
All originate from 219.128.152.213, a Chinanet host or 82.229.209.178.
The body refers people to http://secwestpac.com/IOLB/newSession .
I think you'll find that they're not originating from only two ip addresses, but rather from random zombied machines. My copy of this phishing email came from 84.105.36.75 which is a cable connection in Holland... Regards, Simon Byrnand iGRIN Internet
participants (2)
-
Alastair Johnson
-
Simon Byrnand