2 min read

Bank of America sends electronic Customer Forms?

Răzvan LIVINTZ

July 13, 2009

Promo Protect all your devices, without slowing them down.
Free 30-day trial
Bank of America sends electronic Customer Forms?

Normal
0

false
false
false

EN-US
X-NONE
X-NONE

MicrosoftInternetExplorer4

/* Style Definitions */
table.MsoNormalTable
{mso-style-name:”Table Normal”;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:””;
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:”Calibri”,”sans-serif”;
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:”Times New Roman”;
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;
mso-bidi-font-family:”Times New Roman”;
mso-bidi-theme-font:minor-bidi;}

Bank of America, the number one spoofed bank identity in the
world according to our latest E-Threats
Landscape Report
, continues to be exploited by phishers around the globe.
This time, the unsolicited message requires credulous users to fill in the new
on-line Customer Form.

Bank of America Phishing

The link does not lead to the e-banking portal, but to a .co.uk
registered Web page that mimics the appearance of the original Web site.

Bank of America Phishing

E-criminals seek to get the financial information from the
unsuspicious bank customers by using the bank logo and the general formatting
elements onto an alleged on-line banking enrollment routine. The sensitive data
– card number, expiration date, card ID number, PIN, first and last name and
e-mail address – is stolen using done1.php
script.

Unlike other phishers, these e-thieves seemed more
preoccupied about the credibility of their conning scheme and spent some
additional time into creating a pop-up window that informs the duped users
about their automatic log out and redirection towards the (real) homepage of
the bank.

Bank of America Phishing

If one seeks for specific security elements, namely SSL
encryption (Secure Socket Layer) and security authentication methods (“https”
prefix and locked padlock), one will see none of them.

tags


Author


Răzvan LIVINTZ

I rediscovered "all that technical jazz" with the E-Threat Analysis Team at Bitdefender, the creator of one of the industry's most effective lines of internationally certified security software.

View all posts

You might also like

Bookmarks


loader