About Me

Geok Meng Ong

Geok Meng Ong
Senior Research Manager

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Latest, Coolest Gizmos at a Malware Near You

Monday, July 2, 2007 at 8:31am by Geok Meng Ong
Geok Meng Ong

Over this weekend, McAfee Avert Labs tracked down a phishing website that claims to be selling the first 25,000 exclusive sets of Apple iPhones. This turns out to be the works of Phish-BuyPhony, a trojan designed to redirect and masquerade legitimate websites to a malicious phishing website on the victim’s browser. The evil plan is to entice victims into buying limited iPhones that never gets delivered from the fake website, and making payment through Western Union or MoneyGram to a guy in Latvia.

To improve its chances, the malware tracks the victim’s web activity and spawns a popup advertisement when the victim browses upon Apple’s official website, or popular search engines such as Google or Yahoo.

When clicked, the victim is brought to www.iphone.com, a normally legitimate webpage that is redirected to www.apple.com/iphone/. In an infected scenartio, the webpage loads a phishing website instead, from the iesecurityupdates.com domain.

The phishing website even displays a TRUSTe icon. When the victim clicks on the TRUSTe icon, it displays a fake validation page for www.iphone.com as a certified participant in the TRUSTe privacy program. This webpage does not come from truste.org, but is hosted on the malicious iesecurityupdates.com domain.

 Normally, this website displays the following data:

This phishing website is hosted on a server that was last known to be associated with several HTool-MPack exploits. We’ve just discussed loosely managed web domains repeatedly used to host new malware in a recent blog, and Phish-BuyPhony simply adds to the list.

More screen shots and details of Phish-BuyPhony at:

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)