excellent phishing attempt

eridanus

Thinks s/he gets paid by the post
Joined
Jan 29, 2004
Messages
2,049
Dear Chase Manhattan Customer,

You have been chosen by the Chase Manhattan online department to take
part in our quick and easy 5 question survey. In return we will
credit $20 to your account - Just for your time!
and Helping us better understand how our customers feel benefits
everyone.
With the information collected we can decide to direct a number of
changes to improve and expand our online service. The information you
provide us is all non-sensitive and anonymous -
No part of it is handed down to any third party groups.
It will be stored in our secure database for maximum of 3 days while
we process the results of this nationwide survey.
We kindly ask you to spare two minutes of your time in taking part
with this unique offer! To Continue click on the link below.

https://chaseonline.chase.com/chaseonline/signup/sso_signup_filter.jsp?LOBRBGLogon

-----------------------------------------

Take a look at that link to see how real it appears. DO NOT ENTER ANY INFORMATION! Unless it's bogus.

Clues that it isn't what it seems: The return address is admin@gmail.com. The actual sending host is 80.96.112.115, which isn't a chase computer and appears to be located in Romania. Finally, I don't have a chase account (and banks never send emails asking for account information anyway.)

I'm not sure the intent. It's either some kind of Denial of Service attempt...or they hacked the chase servers. Scary.
 
They're getting a lot better.

I get a bunch of "Fraud alerts" and "Your credit card has been suspended" warnings from the Bank of Hawaii. Good thing I don't have an account there!
 
The gremlins are getting braver. They had a go at the Federal Thrift Saving Plan. Probably a bad choice, I assume someone will be tracking down those phisers.
 
Hmmm...maybe something got lost in the cut and paste of the url, because that page link above is verisign verified to belong to JP Morgan Chase...
 
Cute 'n' Fuzzy Bunny said:
Hmmm...maybe something got lost in the cut and paste of the url, because that page link above is verisign verified to belong to JP Morgan Chase...

Exactly. It is indeed their server. The site was either hacked or...Chase is sending emails from Romania with a from: address of admin@gmail.com.


From: "Chase Manhattan"<admin@gmail.com>

Received: from [80.96.112.115] (helo=User)
by semnai.site5.com with esmtpa (Exim 4.52)
id 1FLe4m-0005fF-Rw; Tue, 21 Mar 2006 05:26:57 -0500

traceroute 80.96.112.115
9 de-fra01a-rd1-pos-5-0.aorta.net (213.46.179.5) 150.167 ms 151.514 ms 149.271 ms
10 ro-clu01a-ra1-so-0-0-0.aorta.net (213.46.160.74) 171.751 ms 172.480 ms 171.792 ms
11 r1-TenGigabitEthernet-1-1.bucuresti.astralnet.ro (213.46.170.70) 173.097 ms 172.744 ms 172.836 ms
12 r6-ge0-v91-dr.constanta.astralnet.ro (85.186.212.5) 185.768 ms 186.831 ms 185.082 ms
13 ct-tsat-sdr.tnet.ro (193.226.47.146) 188.275 ms 189.067 ms 185.722 ms
14 * *^C
 
How. Strange. Maybe they tried a phish but forgot to use the right link to redirect to their own server...
 
Cute 'n' Fuzzy Bunny said:
How. Strange. Maybe they tried a phish but forgot to use the right link to redirect to their own server...

Good point. That's more likely then a hack of the Chase servers.
 
Back
Top Bottom