Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Phishing Attack Uses Fake Donation Website

    Earlier today, we found a phishing site that poses as a donation site to raise money for the victims of the recent earthquake in Japan. The phishing site http://www.japan{BLOCKED}.com is created by using an open-source social networking system Jcow 4.2.1. It is hosted on the IP address 50.61.{BLOCKED}.{BLOCKED}, which is located in the United States. We’ve confirmed that the site is still active as of this writing.

    Click for larger view Click for larger view

    Aside from hosting a phishing site, the cybercriminals behind this attack also abused the blog function of the website and inserted advertisement-looking posts, possibly to increase the site’s SEO ranking.

    Click for larger view

    Such attacks are not uncommon as we’ve previously documented instances of attacks that leveraged natural disasters such as Hurricane Katrina in 2005, Hurricane Gustav in 2008, Chinese Sichuan earthquake in 2008, the latest attack used the Haiti earthquake in 2010.

    Users should remember to choose trustworthy organizations when it comes to handing over their donations.

    The Trend Micro™ Smart Protection Network™, through the Web reputation technology already blocks access to this phishing site even if a user is duped into clicking its link.

    Click for larger view

    Update as of March 17, 2011, 10:44 PM Pacific Time

    We’ve received report from the Council of Anti-Phishing Japan that they’ve seen a similiar phishing site also leveraging on this tragic event. The phishing page poses as the organization Japan Red Cross Society and asks users to send their donations through PayPal.

    Click for larger view

    The said phishing site is now blocked through the Web Reputation Service. Users are strongly advised to steer clear of such sites, and make sure that they go directly to the websites of their organization of choice when sending donations. The real URL for the Japanese Red Cross Society website is http://www.jrc.or.jp.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    13 Responses to “Phishing Attack Uses Fake Donation Website”

    1. EKI Says:

      Hi, I recently received e-mail from someone who I trust saying that a good friend of her who lives in Japan has suggested this website as one of the plausible real ones:
      "http://www.google.co.jp/intl/en/crisisresponse/japanquake2011.html"
      and who also linked in here to check for information of phishing on this subject.

      Could you report if this site is legit, or at least if it has not yet been flagged as a phishing site?

      Thanks,

    2. Jonathan Leopando (Technical Communications) Says:

      Hi Eki,

      Yes, that site is maintained by Google and is 100% legitimate.

    Trackbacks

    1. TrendLabs (TrendLabs)
    2. jhaggett (Jamie Haggett)
    3. TrendMicro (TrendMicro)
    4. luizsrabelo (Luiz Rabelo)
    5. msaitotypeR (M Saito)
    6. rockontom (Tom Morris)
    7. 2020plus1 (Alan Potts)
    8. Hoax BBC Fukushima radiation SMS texts | Vishnu Valentino Hacking Tutorial, Tips and Trick
    9. Trend Micro Asia Pacific News Library - Phishing Attack Uses Fake Donation Website
    10. Disasters Present Cybercriminals Multiple Points to Leverage | Simply Security
    11. Phishing Attack Uses Fake Donation Website | Simply Security


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice