The Developer Stash

Arbitrary Contemplations
posts - 20, comments - 29, trackbacks - 0

My Links

News




Locations of visitors to this page

 





Elroy D'silva's Blog

Twitter












Archives

Post Categories

Blogs I read

Phishing in the name of Midwest Airlines

   What happens when you receive a very polite email from an airline company which tells you that you have booked a ticket somewhere across the globe and your credit card has been charged with $690? This doesn't sound strange if you've really bought the ticket on your credit card. What happens when you know that you haven't?

   This happened to my colleague recently. She received a mail from the phisher pretending to be the Midwest Airlines web service which thanked her for purchasing the ticket and informed her that her credit card account was charged with $690. Gosh! You should have seen the look on her face. I definitely can't describe it. It was a mixture of fear (the fear of losing $690, which is quite a large amount), confusion (the confusion of what should be done next) and curiosity (all said and done, she too is a techie, knows and is curious about this stuff). But it's kind of cool to study the behavior of people becoming  victims (or in this case, potential victims) of phishing.

   She gave me a shout across the desk and asked what she should do next. I informed her not to delete the mail (as I needed it as a real phishing example for posting on my blog, cruel thinking!) and inform the information security folks about this problem. And, I shouldn't have believed her on that. She deleted the mail and dreams of including snapshots of that mail and the attachments were destroyed. Anyways, you can find the pattern of the mail and the attachment in this article on CyberInsecure.com.

   The best part of it was when I asked her to forward the mail to me. She looked at me as if I was planning to learn phishing by using that trojan as my tool. But, by the time I asked for it, the mail was long gone (the mail was a victim of the Shilt+Del disaster).

   The attachent contains contains an exe file named E-ticket_[number].doc.exe which is a Trojan horse that steals information, including keystrokes, from the infected Windows PC and transmits that data to a server hosted in Russia. Now, that is something to take note of. Almost a year ago, this trojan ripped off more than 1.6 million customer records from Monster Worldwide Inc., the company that operates the popular Monster.com recruiting Web site.

   Have you ever been phished?

Print | posted on Sunday, August 31, 2008 9:34 AM | Filed Under [ Viruses and Trojans ]

Feedback

Gravatar

# re: Phishing in the name of Midwest Airlines

Sitting in my junkmail folder last night was no less than 4 phishing emails 3 or them for Banks I have never banked with and 1 from a bank where I had closed the account.

To be honest I have removed the preview option from my Inbox and use Outlooks rules engine to move emails from known domains into their own folder.

This way I get to avoid the preview pane running any trojans as well.

As a general rule of thumb no credit card information is put into a website/window displayed unsolicited. One of my clients got hit by something calling itself 'Microsoft Security'. It also stopped Norton from running. He did however put his credit card in when requested to buy an anti-virus program :(

Needless to say, even though the transaction was cancelled his card was charged and he has just had to get a new account set up.

9/4/2008 5:38 PM | Paul
Gravatar

# re: Phishing in the name of Midwest Airlines

Forgot to mention in the post that no damages occurred to my colleague’s financial status.
:-)
9/4/2008 5:47 PM | Elroy
Post A Comment
Title:
Name:
Email:
Website:
Comment:
Verification:
 
 

Powered by: