<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>mxlab - all about anti virus and anti spam &#187; fraud</title>
	<atom:link href="http://blog.mxlab.eu/tag/fraud/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mxlab.eu</link>
	<description>mx lab blog - all about anti virus and anti spam</description>
	<lastBuildDate>Wed, 28 Jul 2010 23:26:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.mxlab.eu' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8be3c09044ac5968d17dadf3224891c4?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>mxlab - all about anti virus and anti spam &#187; fraud</title>
		<link>http://blog.mxlab.eu</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.mxlab.eu/osd.xml" title="mxlab - all about anti virus and anti spam" />
	<atom:link rel='hub' href='http://blog.mxlab.eu/?pushpress=hub'/>
		<item>
		<title>Nice Citibank phishing attempt example</title>
		<link>http://blog.mxlab.eu/2008/10/07/nice-citibank-phishing-attempt-example/</link>
		<comments>http://blog.mxlab.eu/2008/10/07/nice-citibank-phishing-attempt-example/#comments</comments>
		<pubDate>Tue, 07 Oct 2008 22:53:57 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[citibank]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=230</guid>
		<description><![CDATA[We intercepted a nice Citibank phishing attempt. The email contains the notification that 1 message is waiting for you in the mail section so you will need to login. Dear Customer, You have one new message at .Citibank (South Dakota). INBOX From: Customer Service Date: 10/07/2008 Subject: Official service renewal notification. In order to read [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=230&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>We intercepted a nice Citibank phishing attempt. The email contains the notification that 1 message is waiting for you in the mail section so you will need to login.</p>
<blockquote><p><!--StartFragment--><span style="font-family:Arial;"><span><strong><em>Dear Customer,<br />
</em></strong><br />
</span></span><span><span style="font-family:Verdana, Helvetica, Arial;"><strong>You have one new message at .Citibank (South Dakota).<br />
</strong><br />
<strong>INBOX </strong></span></span></p>
<p><strong>From:</strong> Customer Service<br />
<strong>Date: </strong>10/07/2008<br />
<strong>Subject:</strong> Official service renewal notification.</p>
<p>In order to read the message<strong>  <em>click here</em> &lt;<span style="color:#0000ff;"><span style="text-decoration:underline;">http://www.***********.com/uploads/z/***/citibank/index.html</span></span>&gt;  </strong>to login at<br />
 Citibank (South Dakota) and access your MAIL section. </p></blockquote>
<p>This link brings us to the first step in the whole process, the login page. Notice that there is no secure HTTPS in use. The whole phishing web site is hosted on a blog server.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081008_citibank_phish_1.jpg" alt="" width="340" height="241" /></p>
<p>After a succesfull login (with a non real login and password of course) we get the security notification message to see.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081008_citibank_phish_2.jpg" alt="" width="340" height="414" /></p>
<p>This message explains that our account is temporary locked for security reasons after detection login attempts of foreign IP addresses. So, we need to update our account. When clicking in Continue we can fill in all our private details such as our address and more important our credit card details.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081008_citibank_phish_3.jpg" alt="" width="340" height="407" /></p>
<p>Again, we continue with dummy data and get a response page that the submitted details will be verified.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081008_citibank_phish_4.jpg" alt="" width="340" height="364" /></p>
<p>The green button at the end of the page contains a link to an external web site and leads us to a log out confirmation page. This domain appears to be registered by Citibank and contains a secured HTTP connection.</p>
<p><img class="alignnone" src="http://www.mxlab.eu/img_news/20081008_citibank_phish_5.jpg" alt="" width="340" height="229" /></p>
<p>As you can see, it&#8217;s that easy to steal your information if you don&#8217;t pay any attention at all. Phishing attempts can be detected by following some simple rules:</p>
<ul>
<li>do not trust the email from address at all times</li>
<li>banks do not send you an email to ask to re-activate or confirm your account, even if they include their logo and if it looks legit</li>
<li>banks also do not ask you to send private and critical data over the internet like your credit card details</li>
<li>always keep an eye on the address in the URL locator of your browser</li>
<li>don&#8217;t send any details over an unsecured HTTP, always look for HTTPS and make sure your browser is showing a HTTPS security icon in the status bar</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/230/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/230/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/230/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=230&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/10/07/nice-citibank-phishing-attempt-example/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.eu/img_news/20081008_citibank_phish_1.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081008_citibank_phish_2.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081008_citibank_phish_3.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081008_citibank_phish_4.jpg" medium="image" />

		<media:content url="http://www.mxlab.eu/img_news/20081008_citibank_phish_5.jpg" medium="image" />
	</item>
		<item>
		<title>Phishing levels peak</title>
		<link>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/</link>
		<comments>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 00:35:00 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=62</guid>
		<description><![CDATA[MX Lab detects in increase in phishing emails between 09/04/2008 and 13/04/2008, bringing the phishing level up to 0,28% of all blocked messages where in the past this level was 0,03%. These phishing emails are mostly regarding a &#8220;locked bank account&#8221; or &#8220;verify your details&#8221; but we see other phishing attempts targeting Google Adwords customers [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=62&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>MX Lab detects in increase in phishing emails between 09/04/2008 and 13/04/2008, bringing the phishing level up to 0,28% of all blocked messages where in the past this level was 0,03%.</p>
<p>These phishing emails are mostly regarding a &#8220;locked bank account&#8221; or &#8220;verify your details&#8221; but we see other phishing attempts targeting Google Adwords customers stating that their account is locked.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/62/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/62/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/62/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/62/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/62/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=62&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/14/phishing-levels-peak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>
	</item>
		<item>
		<title>Very good PayPal phishing email</title>
		<link>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/</link>
		<comments>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 11:12:53 +0000</pubDate>
		<dc:creator>mxlab</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[MX Lab]]></category>
		<category><![CDATA[paypal]]></category>

		<guid isPermaLink="false">http://mxlab.wordpress.com/?p=58</guid>
		<description><![CDATA[A certain phishing email from &#8216;PayPal&#8217; caught our attention. When investigating the phishing email we could find that this is a very professional one. The email in fact confirms your payment to a company, in this case Plimus, for an amout of$55,89 USD. The email provides a link to dispute the transaction and this is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=58&subd=mxlab&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>A certain phishing email from &#8216;PayPal&#8217; caught our attention. When investigating the phishing email we could find that this is a very professional one. The email in fact confirms your payment to a company, in this case Plimus, for an amout of$55,89 USD. The email provides a link to dispute the transaction and this is where the phishing starts.
<p><img src="http://www.mxlab.be/img_news/20080402_phishing_paypal_1s.gif" width="340" height="365" /></p>
<p>Following the link to report a dispute results in being directed to http://**-***-**-***.fld-bsr1.chi-fld.il.******.cable.rcn.com:90/www.paypal.com/cgi-bin/ and it brings you to the &#8220;PayPal login screen&#8221;.</p>
<p>Typical to phishing sites is that you can type in whatever you want as login or password, you will always be directed to a webform.</p>
<p>These guys have even included the animated screen &#8216;Logging in&#8217; that you have when logging in to the real PayPal web site. After this screen you get a full webform which will try to get your full details. <img src="http://www.mxlab.be/img_news/20080402_phishing_paypal_3s.gif" width="340" height="347" />  </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/mxlab.wordpress.com/58/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/mxlab.wordpress.com/58/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/mxlab.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/mxlab.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/mxlab.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.mxlab.eu&blog=574486&post=58&subd=mxlab&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.mxlab.eu/2008/04/02/very-good-paypal-phishing-email/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6751de05c9679f2f58d63d33207ef4f7?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mxlab</media:title>
		</media:content>

		<media:content url="http://www.mxlab.be/img_news/20080402_phishing_paypal_1s.gif" medium="image" />

		<media:content url="http://www.mxlab.be/img_news/20080402_phishing_paypal_3s.gif" medium="image" />
	</item>
	</channel>
</rss>