Simply Security - News, Views, and Opinions from Trend Micro

Phishing Attack Uses Fake Donation Website

Posted on March 16th, 2011 in Current News, Cybercrime, Trend Labs, Web Threats by TrendLabs | Be the first to comment | Tags:

Earlier today, we found a phishing site that poses as a donation site to raise money for the victims of the recent earthquake in Japan. The phishing site http://www.japan{BLOCKED}.com is created by using an open-source social networking system Jcow 4.2.1. It is hosted on the IP address 50.61.{BLOCKED}.{BLOCKED}, which is located in the United States. We’ve confirmed that the site is still active as of this writing.

Click for larger view Click for larger view

Aside from hosting a phishing site, the cybercriminals behind this attack also abused the blog function of the website and inserted advertisement-looking posts, possibly to increase the site’s SEO ranking.

Click for larger view

Such attacks are not uncommon as we’ve previously documented instances of attacks that leveraged natural disasters such as Hurricane Katrina in 2005, Hurricane Gustav in 2008, Chinese Sichuan earthquake in 2008, the latest attack used the Haiti earthquake in 2010.

Users should remember to choose trustworthy organizations when it comes to handing over their donations.

The Trend Micro™ Smart Protection Network™, through the Web reputation technology already blocks access to this phishing site even if a user is duped into clicking its link.

Click for larger view

Post from: TrendLabs | Malware Blog – by Trend Micro

Phishing Attack Uses Fake Donation Website



Comments


No comments yet