Phishing is a social engineering attack on the endusers. Especially bank customers are targeted a lot. I found a blog investigating a phishing attempt on Argenta, a Belgian bank. Here is the full analysis (in Dutch from Knudde.be)
I tried Babelfish but the translation was horrible. You can try it for a good laugh. So here is a translation from myself. I take no responsibility for the correctness of the translation. ;-)
Argenta for example has a notification for the moment on their website warning about "Argenta Finance Bank". Unfortunately it stops with the display of this warning.
So, let's Rock and Roll
From the real Argenta Site:
Argenta wil haar cliƫnteel waarschuwen voor de activiteiten van Argenta Finance Bank
die beweert vanuit de Rodestraat te Antwerpen bankdiensten aan te bieden.
Deze organisatie opereert illegaal en zonder vereiste vergunningen en maakt
onrechtmatig gebruik van de merknaam Argenta. Er bestaat geen enkele band tussen
Argenta Spaarbank N.V. en deze organisatie en wij raden dan ook aan op geen enkel
aanbod van deze organisatie in te gaan.
"Argenta Finance Bank" == http://www.onlineargenta.com/
The site is not bad looking but neither is it professional.
The first noticable element is the mention of "Western Union" on their first page.Maybe you should read this:
http://www.westernunion.com/info/fraudIndex.asp
Information gathering
Ok, what's not right in this picture:
Hosting
The site opens a frame and alle the linkscontain a URL beginning with "xyueyhwhhayya000001jskanyuw.50webs.com".
So the site is hosted at 50webs.com
Very strange for a bank but it's only indirect evidence.
Domain
The domein is registred by:
jerry thombson (annabel.march3@googlemail.com)
+1.5204326000
Fax:
8 Arizona St. ,
Bisbee, 85603
US
There is already an inconsistency between the name and the emailaddress, and probably isn't even the real person who registered the domain.
The domain is also very recent. Creation date: 20 May 2007 11:02:42
Also very strance. since Argenta exists for a much longer period. In any case, it's obvious that something fishy is going on.
Contact data
The foto's of the people on the website have strange names. Some pictures contain names while the displayed name is different.
The address seems to be in Antwerp but the phonenumbers are from Brussels. Another inconsistency.
Argenta doesn't have an office on the mentioned address. Probably there is nothing to find there but I didn't check.
OK, numbertracing 101: +32-2-747-0975, +32-2-747-0974, +32-2-791-9303
3 numbers in 2 different series, and no info about it from the local telco provider.
A simple trick teaches us that the "normal" phonenumbers are hosted with Realroot", a Belgian firm who is, let's say, not very selective with their business partners.
RealROOT
Drakenhoflaan 54
B-2100 Deurne
Tel. +32 3 747 00 00
Fax. +32 3 747 99 99
The trace of the Faxnumber leads me through "Colt Telecom" to "J2 Global Ireland ltd".
j2 Global Ireland Ltd
Woodford Business Park, Unit-3
Santry, Dublin 9
Ireland
Both are "transfer" firms where you can rent local numbers to forward to other numbers. Both enterprises have no information about the customer behind these numbers.
Login page
The login page from the site goes somewhere totally different: ebancargentanet.cogia.net.
The page is hosted by 100WebSpace.com, which is a free webhosting service. (Very strange for a bank.)
During the "so called login" and the registration nothing visable happens. But you can be sure that the login information is stored. The connection isn't encrypted either
Apperently there is a MySQL DB behind it which suggest the following error:
Warning: mysql_pconnect(): Too many connections in
/home/www/ebancargentanet.cogia.net/argenta/adodb/drivers/adodb-mysql.inc.php on line 354
Too many connections
The error and the URL teaches us something in addition: "ebancargentanet"
"ebanc" -> e-bank. Which language do the "culprits" speak.
"argentanet" -> Argenta.net also exists.
Probably an old version of argenta.net pointing to the loginpage from cogia.net.
argenta.net:
Nova
111 State and Broadway
Lovington, IL 61937
US
Record created on 04-Nov-1998.
Database last updated on 6-Jun-2007 10:40:31 EDT.
Hmmm, recent activity.
http://ebancargentanet.cogia.net/argenta/ is an open directory.
The players
Contactdata:
-Realroot for the telephonenumbers (+32 3 747 00 00)
-J2 Global for the faxnumber (+35 3 1 656 4909)
-50webs.com, for the mainwebsite (abuse@50webs.com)
-cogia.net (100WebSpace.com), for the login page (http://www.100webspace.com/about_us/report_abuse.html)
So it's trivial to get the website offline which is the case at this moment.
Very nice. This also satisfies my curiosity about Belgian companies being under attack. At last some examples. If you notice Belgian phishing attempts yourself, please report them to
(FCCU).