My next class:

Trustwave Trustkeeper Phish

Published: 2013-02-25. Last Updated: 2013-02-25 17:41:36 UTC
by Johannes Ullrich (Version: 1)
3 comment(s)

Just got another interesting phishing e-mail. This time around it is security company Trustwave that is being phished. I am not a customer, so I am not sure how well these e-mails reflect the real thing, but they confused me for a while. The give away that this is a fake is the from e-mail address as well as the link leading to a different site then advertised.

Click on the image for a full size example.

trustwave phishing email

[Update:] An analysis of this phish by Trustwave's own Spiderlabs can be found here: http://blog.spiderlabs.com/2013/02/more-on-the-trustkeeper-phish.html 

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

3 comment(s)
My next class:

Comments

Our Barracuda appliance shows a LOT of incoming "scan warning" spam starting at about 2/21 1100 EST.

Thankfully all either blocked or quarantined.

- http://blog.dynamoo.com/2013/02/trustkeeper-vulnerabilities-scan.html
25 Feb 2013 - "... this "TrustKeeper Vulnerabilities Scan Information" -spam- leads to an exploit kit on saberdelvino .net...The malicious payload is at [donotclick]saberdelvino .net/detects/random-ship-members-daily.php (report here*) hosted on the following IPs:
118.97.77.122 (PT Telekon, Indonesia)
176.120.38.238 (Langate, Ukraine)..."
* http://www.urlquery.net/report.php?id=1120754
... Blackhole 2
.
One of these madeit thruclamav and spamassassin and into my INBOX today. :-(

Diary Archives