Date Reported 17th February 2005
Apparent Sender Southtrust
Return Address SouthTrust Bank Support < customer@southtrustonlinebanking.com >
Subject Online Banking Unusual Activity
Format HTML
Method Spoof email links to a spoof webpage where victim is prompted to enter their details believing the site is genuine. Details are then forwarded to a local script and captured.
Bogus Web Content? Yes
URL of web content http://210.102.16.110/retail/
RISK LEVEL MEDIUM
WARNINGS 1. Email claims to be from Southtrust asking you to confirm your account data by clicking on the link. You will be taken to a spoof login page where your details will be captured by the phishers.
2. Southtrust never send users emails requesting details in this way.
3. URL of spoof website disguised as "Log In to Online Account Page".
4. Real URL looks nothing like Southtrust.
5. Website traced to Korea.
"Online Support are remind you that on Feb. 12, 2005 our Banking Review Team..."
If you have received this email, please remember that it is very common for these email scams to be redistributed at a later date with only slightly different content or the same but with the fake page(s) hosted by a different provider. Also, once you have received one of these hoaxes, it is also common place to receive at least another one and usually a day or two after the first, although not necessarily from the same apparent sender.
The Spoof Email ...
Dear Customer x,
Online Support are remind you that on Feb. 12, 2005 our Banking Review Team identified some uncommon activity in your online account. In accordance with SouthTrust Financial Corp.'s Consumer Agreement and to guarantee that your account has not been compromised, internet access to your account was limited. Your online access will remain blocked until this issue has been decided. We encourage you to log in and perform the steps requisite to give back your account access immediatelly. Allowing your online access to remain blocked for a long period of time may result in further restrictions on the use of your account and possible account closure. Log In to Online Account Page
To protect the confidence of your account access, employs some of the most leading Bank security systems in the world and our anti-fraud groups hourly screen the Bank system for fraud activity.
Thank you for your prompt attention to this question. We apologize for any inconvenience.This is a security procedure meant to help protect you and your account.
Sincerely,
SouthTrust Bank, Online Service
|