PhishTrackers.com

Report Phishing Scams Easily & Anonymously


SMITH BARNEY: URGENT SECURITY NOTIFICATION FOR ALL CLIENTS ( Brazil)

Report# A109

Reported on: Friday, 25 January, 2008  01:28
Updated On: Friday, 13 May, 2011  09:25
Reply to: (Use contact form below)
Date Reported 3rd February 2005
Apparent Sender Smith Barney

Return Address SmithBarney < identifdep_ref2289349@smithbarney.com >

Subject SMITH BARNEY: URGENT SECURITY NOTIFICATION FOR ALL CLIENTS
Format HTML
Method Spoof email links to a spoof webpage where victim is prompted to enter their details believing the site is genuine. Details are then forwarded to a local script and captured.


Bogus Web Content? Yes
URL of web content http://200.211.52.11/s/


RISK LEVEL HIGH
WARNINGS 1. Email claims to be from Smith Barney asking you to confirm your account data by clicking on the link. You will be taken to a spoof login page where your details will be captured by the phishers.

2. Smith Barney never send users emails requesting details in this way.

3. URL of spoof website disguised by an image in the body of the email - a technique used to get past spam filters .

4. Spoof website traced to Brazil.

5. Real URL obviously NOT Smith Barney .

6. The spoof website contains a trojan VIRUS! Called Stealus A. See Sophos for more information: http://www.sophos.com/virusinfo/analyses/trojstealusa.html

7. A variation of a scam also targeting Regions.






" Dear Smith Barney customer, Technical services of the Smith Barney are carrying out a planned software upgrade."

If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.