Monday, January 30, 2017

Phishing Email - ScotiaBank Online Banking

 For the record, here's a recent phishing email faking it's Scotiabank Online Banking.























The body of this email in text reveals the rogue link on line 15 - fenc.daewonit.com/baoa/index.php is hosted in Seoul, Korea.


The interesting thing is the email is from hogan.com website which is a legitimate site, but clearly its website has been zombified.


 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
From: Message.069.From.S.c.o.t.i.a_B.a.n.k.ID.0764676654@hogan.com <Message.069.From.S.c.o.t.i.a_B.a.n.k.ID.676767676@hogan.com>
Sent: January 30, 2017 5:37 PM
To: xxxxxxxxxxxxx@hotmail.com
Subject: Reminder: Last Notification! (0697)

//click.mail.onedrive.com/?qs=xxxxx
xxxxxxxxxxxx@hotmail.com.
[img]


You are no longer allowed to access your ScotiaBank Online Banking. We had to disable your online access for your security.

This can be because of a recent change in your address or submitting incorrect information during the initial registration process.
Please verify your account within the next 24 hours in order to avoid full online suspension. //click.mail.onedrive.com/?qs=32b26e68be826244f798f60445dfd85de29d309e84058c43d950e053e97cfedf416cf5597446254a50fb196c75dd980151f2da54664bc0a5
Click here <http://fenc.daewonit.com/baoa/index.php> to verify your information and remove the suspension on your account or follow this secure link:
//www2.scotiaonline.scotiabanking.com/online/unsuspend-xxxxxxxxxxxx@hotmail.com-0697837489/auth.bns<http://fenc.daewonit.com/baoa/index.php>

After the secure online verification you will be able to use your account as usual.

2017 (30th of January) Scotiabank Canada

click.mail.onedrive.com/?qs=xxxxxxxxxxxxxxxxx



Whois Record lookup for fence.faewonit.com
Email
RegistrarDOTNAME KOREA CORP
Registrar Statusok
DatesCreated on 2011-03-07 - Expires on 2017-03-07 - Updated on 2016-03-06
Name Server(s)DNS.MIREENE.COM (has 5,979 domains)
IP Address112.217.208.42 - 1 other site is hosted on this server
IP LocationSeoul - Seoul - Lg Dacom Corporation
ASNAS3786 LGDACOM LG DACOM Corporation, KR (registered Aug 01, 2002)
Domain StatusRegistered And Active Website
Whois History40 records have been archived since 2008-11-11
IP History5 changes on 5 unique IP addresses over 13 years
Registrar History2 registrars with 2 drops
Hosting History9 changes on 6 unique name servers over 12 years
Whois Serverwhois.dotname.co.kr
Website Title대원정보기술입니다.
Server TypeApache/2.2.21 (Unix) mod_ssl/2.2.21 OpenSSL/0.9.8e-fips-rhel5 PHP/5.3.8
Response Code200
SEO Score44%
Terms81 (Unique: 74, Linked: 59)
Images39 (Alt tags missing: 39)
Links50   (Internal: 50, Outbound: 0)
Whois Record ( last updated on 2016-12-21 )


How to tell this is a Phishing email?

  1. Check email address in full, if it's not from originating company then it's phishing.
  2. Hover over all links in email, if it's not from the company's website then forget it.
  3. The best way is to look at message source, see below.

How to examine Email Message Source?

Now let's look at message source
  1. Outlook.com->Actions->View Message Source. 
  2. Gmail.com->More (down arrow to top right)->Show original.
Check for suspicious links, anything that does not originate from source domain, like apple.com.

-------------------------------------------------------------------------------------------------------------


Report Phishing Email (not as Spam)

  1. Outlook.com->Junk (at Top)->Phishing Scam
  2. Gmail.com->More (down-arrow to top right)->Report Phishing 

Report Phishing to Google

    If you have received this email, take further action by

    1. https://www.google.com/safebrowsing/report_phish/

    Report phishing at Microsoft and government agencies

    1. http://www.microsoft.com/security/online-privacy/phishing-faq.aspx

    Report phishing for Web hosting companies (e.g., GoDaddy, Cloudflare, DigitalOcean) and ISPs

    Anti‑Phishing Working Group (APWG) — forward to reportphishing@apwg.org

    -------------------------------------------------------------------------------------------------------------

    💣 📧 Check if your username or email has been hacked



    No comments:

    Post a Comment

    Use at your own risk.