Archive for the ‘Phishing’ Category

Sep16
by Abigail Villarin (Fraud Analyst)

We have encountered a new phishing scam that targets ClickandBuy. The London-based competitor to eBay offers both billing ang payment solutions, so it's no surprise cybercriminals would be interested in stealing the login information of ClickandBuy users. Phishers have created a duplicate of a legitimate German-language ClickandBuy login page on at least one malicious website. The fake site can be seen below: Figure 1. Phishing website After entering their credentials, users would be redirected to the legitimate ClickandBuy site. Users would then ...


Sep14
by Merianne Polintan (Anti-spam Research Engineer)

We have received samples of a new phishing mail targeting users of MSN Messenger inviting them to see who deleted or blocked them from their contact list. Users would be interested to know who among their friends have deleted them from their lists. Figure 1. Phishing email Clicking on the link displays the following fake login page asking the user to input his or her password: Figure 2. Phishing website It is obvious that the intention of the cybercriminals is to harvest the user's ...


Aug19
by Jonathan Leopando (Technical Communications)

It would be easy to think that once someone has logged in successfully to Facebook—and not a phishing site—that the security threat is largely gone. However, that's not quite the case, as we've seen before. Earlier this week, however, Trend Micro researcher Rik Ferguson found at least two—if not more—malicious applications on Facebook. (These were the Posts and Stream applications.) They were used for a phishing attack that sent users to a known phishing domain, with a page claiming that users ...


Aug11
by Fatima Bancod (Fraud Analyst)

It's about time this technique comes in.. Content Security's forecast that phishing with captcha would be an emerging fraudulent techniques. CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) used to protect web sites against abusive automated softwares that can register, spam, login, or even splog. However, now a days that isn't the case anymore. Just like the traditional PayPal phish, the web page http://{BLOCKED}www.security-paypal.citymax.com/paypal_security.htmlasks the user to provide feedback from their Shopping by asking for their Name, E-mail ...


Jun25

We have recently discovered a version, of online fraud that takes the guise of a legitimate-lookng news website. At first glance, the content of the purported news page appears real but after conducting further analysis, one will realize that the news page is actually a spammy site. What's supposed to be a news article is actually an writeup that explains how Google can supposedly provide online users the opportunity to earn easy money. To make it more convincing, the page also ...



© Copyright 2009 Trend Micro Inc. All rights reserved. Legal Notice