Phishing Attack Uses Fake Donation Website

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Forum Veteran
Jan 24, 2011
9,380
1
24,874
8,379
malwaretips.com
Earlier today, Trend Micro found a phishing site which poses as a donation site to raise money for victims of the recent earthquake in Japan. The phishing site, http://www.japan{BLOCKED}.com, is created by using an open-source social network system Jcow 4.2.1. It is hosted on the IP address 50.61.{BLOCKED}.{BLOCKED}, which has been found to be located to be in the US. Tred Micro confirmed that the site is still active right now.

[attachment=32]
[attachment=33]

Aside from hosting a phishing site, the cybercriminal behind this attack also abused the blog function of the website and inserted advertisement-looking posts, possibly to increase SEO ranking.

[attachment=34]

More details - link
 

Attachments

  • japandonate1.jpg
    japandonate1.jpg
    130.6 KB · Views: 499
  • japandonate2.jpg
    japandonate2.jpg
    188.4 KB · Views: 467
  • japandonate3.jpg
    japandonate3.jpg
    217.9 KB · Views: 481
Status
Not open for further replies.