SecurityIntelligence is another division of MalwareIntelligence that focuses on aspects related to Information Security. The proposed content related to security issues and aspects relating to the management and administration of an information environment.

February 09, 2010

Phishing database I

Phishing responds to a purely criminal activity, part of the circuit that drives the illegal business of crimeware, designed to steal money using the sensitive and private information from users that criminals obtained through non-sacred activities.

Therefore, as a preventive measure, it's important not to allow access to the domains that host usually banks cloned pages, webmail and any other Internet service through a process that requires authentication.

To that end, born Phishing database, a compendium of fraudulent domains for implementing a plunger of phishing, which can be used to create the block lists.

Wachovia Corporation
http://www.stc.lk/it/home/online.wachovia.com/accountupdate/AuthService.php?action=presentLogin&url=https%3a//onlineservices.wachovia.com/NASApp/NavApp/Titanium%3faction%3dreturnHome

PayPal
aurelie-et-arnaud.me/img/paypal/verify/login.php
www.yvescochet.net/.secure.paypal.fr/verified_by_paypal/webscrcmd=_login-run/cgi-bin/_login/
dz-tero.com/paypal/
www.paypal.com.0ytyz0oxg18bu.124nruo3kb3j903ers01.com/cgi-bin/webscr/?login-dispatch&login_email=unnimay@aol.com&ref=pp&login-processing=ok
www.124nruo3kb3j903ers01.com/cgi-bin/webscr/
www.syrianaction.com/data/.confirm/paypal/
www.paypalcomservupdate.intl-paypal1.com/us/cgi-bin/?cmd=_login-run
ukghd.com/images/www.paypal.com/cgi-bin/webscr.htm?cmd=_login-run
203.101.73.204/www.paypal.com.au/security/cgi-bin/webscr.htm?cmd=_login-run
52274548.es.strato-hosting.eu/lol/webscr.php?cmd=LogIn 
www.kules.knows.nl/cgi/
lejournalduthesard.info/help/css/update/online-information/fr/verefication-compte/online-update/webscr.php?cmd=_login-run&dispatch=5885d80a13c0db1f1ff80d546411d7f84f1036d8f209d3d19ebb6f4eeec8bd0e57b2ad7d754c297ea32a3580bcf6dcb357b2ad7d754c297ea32a3580bcf6dcb3
208.101.19.98/~mikorg/
iwww.cz.cc/PayPal.fr/paypal/fr/webscr.php?cmd=_login-run&dispatch=5885d80a13c0db1f998ca054efbdf2c29878a435fe324eec2511727fbf3e9efc0779736997661668caf8ff5d99e81fe40779736997661668caf8ff5d99e81fe4

egg
www.luxor2020.com/about/files/Image/jpg/txt/neweggcom/security/customer/index.html

CUA
www.zoi-creation.com/customers.cua.com.au/webbanker/CUA/2/notice.htm
www.zoi-creation.com/customers.cua.com.au/webbanker/CUA/ 

HSBC
cmodz-hosting.com/upload/cache/IBlogin.html
www.w650-france.com//forum/modules/index.html
www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/HSBC/index.html
dodongminhhien.com/modules/pib-home/2/1/personal/hsbc.co.uk/IBlogin.html

eBay
rahasiabisnis21.com/_space/apache_module.php
www.ebay.motors-cgi-items.com/cars-trucks_2003-BMW330I_W0QQitemZ15982632345413QQihZ012QQcategory-cars-trucksZ21983317QQssPageNameZWDVWQQrdZ1QQcmdZViewItems/index2.php
190-13-160-211.bk14-ipfija.surnet.cl/.ws-cgi/index.php
7beginnings.com/~sothebys/assets/profile/ws/login.html 

JPMorgan Chase Bank
7beginnings.com/~sothebys/assets/profile/auth/secure/chase-sec/onlinebanking.chase.com=logon_confirm/

In this case, in the same living space there is a breach against eBay phishing and another against JPMorgan Chase Bank in the IP address 203.211.129.222. The site is controlled by a shell in php call !islamicshell v. edition ADVANCED!.

The truth is that in addition to web upload cloned, the attacker can quietly, such as spreading malware of any type hosted on the server which hosts the site, including (a very common and which tend to be used the shell php) defacing.

Lloyds TSB Bank
www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/Lloyds/customer.php

Barclays
www.ifsb.co.kr/bbs/data/guest/gold/folder/folder/New%20Folder/United2/Folder/Folder/Folder/Folder/Folder/Folder/Folder/empty/empty/empty/United2/United/United/United/Barclays/LoginMember.login.htm

Canada Revenue Agency
221.134.144.147/cra-arc.gc.ca/esrvc-srvce/tx/ndvdls/myrefund/getStatus_en.htm

Poste italiane
fgewfgewdfsa.pochta.ru/posste.html
mesagio-postepay.xaker.ru/postpayleg-clientesdasdhit.html

Abbey
www.velositas.com/update/myonlineacounts2.abbeynational.co.uk/Logonaction=prepared/Logonaction=prepare/

Jorge Mieres

0 comentarios:

Post a Comment