Similar Searches

Related Posts

  • Phishing School Teaches Lessons on Secure Practices (March 11, 2009)

    The Trend Micro Content Security team discovered a phishing attack that used a software company’s website to lure victims into divulging personal information. The compromised site was that of School Website Solutions, which looks like this:Figure 1. Clean page. Phishers were able to hack the site however. Users who ...

  • RapidShare Users Get Phished (February 13, 2009)

    The Trend Micro Content Security team has discovered a phishing attack targeting users of the German-owned file-hosting website, RapidShare. Aside from their free hosting service, the website also offers a benefit for premium members who opt to pay a certain fee through PayPal, or by means of RapidShare authorized resellers. ...

  • Two Credit Unions Phished (December 22, 2008)

    The Trend Micro Content Security Team discovered two phishing URLs just within hours of each other that use legitimate credit unions to trick unknowing users into giving out confidential information. Here’s a screenshot of a page that spoofs the O Bee Credit Union:Figure 1. Sample phishing page. The ...

  • Phishing Made “Super” (March 1, 2010)

    Phishing and its effects, namely, identity fraud, continue to grow. Unfortunately, it is now easier than ever to carry out these kinds of attacks. Cybercriminals are now using a new tool known as “Super Phisher” (detected by Trend Micro as HKTL_SUPERPHISER) has been released, which creates a phishing page ...

  • Phishing in the Guise of Enhancing Security (January 20, 2010)

    Trend Micro fraud analysts recently came across spammed messages targeting customers of the Fifth Third Bank. The messages urged recipients to log in to a temporary link, http://www.53.com.{BLOCKED}.com.pl/wpserver/cmportal/cblogin.php?session=667882698791972326077742654898739&email=p2t2all@tacobell.com, in order to download and install a digital certificate that would supposedly reinforce the bank’s security. Clicking the link, however, led users ...

Related News

Related Posts

  • Phishing School Teaches Lessons on Secure Practices (March 11, 2009)

    The Trend Micro Content Security team discovered a phishing attack that used a software company’s website to lure victims into divulging personal information. The compromised site was that of School Website Solutions, which looks like this:Figure 1. Clean page. Phishers were able to hack the site however. Users who ...

  • RapidShare Users Get Phished (February 13, 2009)

    The Trend Micro Content Security team has discovered a phishing attack targeting users of the German-owned file-hosting website, RapidShare. Aside from their free hosting service, the website also offers a benefit for premium members who opt to pay a certain fee through PayPal, or by means of RapidShare authorized resellers. ...

  • Two Credit Unions Phished (December 22, 2008)

    The Trend Micro Content Security Team discovered two phishing URLs just within hours of each other that use legitimate credit unions to trick unknowing users into giving out confidential information. Here’s a screenshot of a page that spoofs the O Bee Credit Union:Figure 1. Sample phishing page. The ...

  • Phishing Made “Super” (March 1, 2010)

    Phishing and its effects, namely, identity fraud, continue to grow. Unfortunately, it is now easier than ever to carry out these kinds of attacks. Cybercriminals are now using a new tool known as “Super Phisher” (detected by Trend Micro as HKTL_SUPERPHISER) has been released, which creates a phishing page ...

  • Phishing in the Guise of Enhancing Security (January 20, 2010)

    Trend Micro fraud analysts recently came across spammed messages targeting customers of the Fifth Third Bank. The messages urged recipients to log in to a temporary link, http://www.53.com.{BLOCKED}.com.pl/wpserver/cmportal/cblogin.php?session=667882698791972326077742654898739&email=p2t2all@tacobell.com, in order to download and install a digital certificate that would supposedly reinforce the bank’s security. Clicking the link, however, led users ...

Phishing Pages Pose as Secure Login Pages

TrendLabs recently spotted a new phishing site spoofing CenturyLink’s secure login page from one of its anti-phishing resources.

CenturyLink, created by the merger of CenturyTel and Embarq on July 1, 2009, is a leading provider of high-quality voice, broadband, and video services through its advanced communication networks to consumers and businesses in 33 states in the United States. It is the currently the fourth largest local exchange telephone company in the United States in terms of access lines. It has more than 7 million access lines in service and more than 2 million high-speed Internet connections as well as its own 100 percent digital network, Centrex, ISDN, and advanced intelligent network.

Even though CyberLink’s real secure login page looks very similar to the spoofed one, there are still at least three major differences. First, the URL of the real login page is https://secure.centurylink.net/login.php begins with one of the first marks of a secure login page (https), followed by the company name, unlike the spoofed one, http://www.{BLOCKED}gsoo.com/g4/data/file/news/CenturyLink.net.html, which begins with http, followed by a suspicious-looking domain name before the company’s own name.

Next, a secure login page always has a padlock icon on the lower-right portion of the page while the fake page only has an exclamation point, indicating that something is wrong.

Finally, look at the lower-left portion of the spoofed page, though it is marked as “Done,” it clearly contains errors,

...
Read the original story


Source: Abigail Villarin (Fraud Analyst) @ TrendLabs | Malware Blog - by Trend Micro

Write a Comment

Copyright © 2010 The Security Blog. All rights reserved.
Web Statistics Homeland Security blogs & blog posts