Westpac "security change" hoax email circulating..

Phishing scams, hijacking of TM accounts, keyloggers and all manner of other nasties. This is the place to report them and get help if you've been hit.
Post Reply
User avatar
CliveHill
Scambuster
Posts: 3944
Joined: Thu May 06, 2004 8:51 am
Location: Christchurch NZ

Westpac "security change" hoax email circulating..

Post by CliveHill » Tue Sep 26, 2006 7:14 pm

Image A spam email claiming to be from Westpac Security has been widely circulated. This email targets Westpac Online Banking customers by informing them of a security change and requesting them to login to a hoax Westpac website. Please do not follow the link or login to this website. If you have logged onto this site please call us immediately on 0800 400 600.

:?
Honesty and Integrity are always the best Policies !

sir1963nz
Members
Posts: 368
Joined: Mon Jun 28, 2004 3:29 am
Location: Palmerston North
Contact:

Post by sir1963nz » Mon Oct 02, 2006 3:42 am

Dear Online Customer:

There is a recent online banking security server update
To update your record, just click on the link below and follow instruction.
You will be able update to your online banking service
https://sec.westpac.co.nz/IOLB/newSession?update_Act

Thank you,

Westpac Banking Corporation
Online Banking Customer Service

Please do not reply to this message.
To speak with a representative about your Online Banking account,
or if you need help about Internet Banking,call 0800 400 601
traceroute to battarel.com (213.186.33.19)

% Information related to '213.186.33.0 - 213.186.33.255'

inetnum: 213.186.33.0 - 213.186.33.255
netname: OVH
descr: OVH SAS
descr: Shared Hosting Servers
descr: http://www.ovh.com
country: FR
admin-c: OK217-RIPE
tech-c: OTC2-RIPE
status: ASSIGNED PA
mnt-by: OVH-MNT
source: RIPE # Filtered

role: OVH Technical Contact
address: OVH SAS
address: 140, Quai du Sartel
address: 59100 Roubaix
address: France
admin-c: OK217-RIPE
tech-c: GM84-RIPE
nic-hdl: OTC2-RIPE
remarks: ========================================
remarks: support : support@ovh.com
remarks: 0 899 701 761 (france only)
remarks: ========================================
remarks: troubles:
remarks: + network : abuse@ovh.net
remarks: + spam : http://www.spam-rbl.com
remarks: ========================================
remarks: peering : noc@ovh.net
remarks: prefix 213.186.32.0/19
remarks: prefix 213.251.128.0/18
remarks: - FreeIX (1Gbs) 213.228.3.244
remarks: - PariX (1Gbs) 198.32.247.104
remarks: - SfinX (1Gbs) 194.68.129.144
remarks: ========================================
abuse-mailbox: abuse@ovh.net
mnt-by: OVH-MNT
source: RIPE # Filtered

User avatar
CliveHill
Scambuster
Posts: 3944
Joined: Thu May 06, 2004 8:51 am
Location: Christchurch NZ

Another Warning.........

Post by CliveHill » Mon Oct 02, 2006 5:56 pm

ImageOctober 02 2006 - A spam email claiming to be from Westpac Security has been widely circulated. This email targets Westpac Online Banking customers by informing them of a security server update and requesting them to login to a hoax Westpac website. Please do not follow the link or login to this website. If you have logged onto this site please call us immediately on 0800 400 600.
:?
Honesty and Integrity are always the best Policies !

User avatar
CliveHill
Scambuster
Posts: 3944
Joined: Thu May 06, 2004 8:51 am
Location: Christchurch NZ

Post by CliveHill » Wed Oct 11, 2006 6:03 pm

ImageOctober 11 2006 - A spam email claiming to be from Westpac has been widely circulated. This email targets Westpac Online Banking customers by informing them of a security server update and requesting them to login to a hoax Westpac website. Please do not follow the link or login to this website. If you have logged onto this site please call us immediately on 0800 400 600.
Honesty and Integrity are always the best Policies !

User avatar
digidog
Site Admin
Posts: 15014
Joined: Wed May 05, 2004 2:25 am
First Name: Alfie
Location: Otago
Contact:

Re: Westpac "security change" hoax email circulating..

Post by digidog » Sun Aug 25, 2013 10:22 pm

Here's a tricky variation on phishing scams.
From: Westpac Group

Westpac Bank will add $150 AUD credit to your account just for taking part in our quick 4 question survey.
Only one suvery per card is allowed, if you own multiple cards you can run the survey again for each.
Careful: Live phishing sites
http://prosport-ferrari.com//includes/p ... ex.php?id=****" onclick="window.open(this.href);return false; (removed)

Redirects to:
https://cleeng.com/blog/wp-content/uplo ... /08/bonus/" onclick="window.open(this.href);return false;

The first page gets punters started filling in a survey and it's not until the second page that you're asked to enter credit card details and all manner of other personal info. Clever!

User avatar
Foggyone
Site Admin
Posts: 9880
Joined: Sat May 22, 2004 8:16 pm
First Name: Peter
Location: Lower Hutt
Contact:

Re: Westpac "security change" hoax email circulating..

Post by Foggyone » Mon Aug 26, 2013 1:37 am

And its running under an https secure site which could easily persude the gullible that it's OK.

Also, in the first page re survey
Only one suvery per card is allowed, if you own multiple cards you can run the survey again for each.
In other words, let us phish each of your credit cards. Nasty

The site hacked hold themselves out as experts in supplying internet services.
Google, the answer to so many questions!
-----------------------------------------------------

User avatar
digidog
Site Admin
Posts: 15014
Joined: Wed May 05, 2004 2:25 am
First Name: Alfie
Location: Otago
Contact:

Re: Westpac "security change" hoax email circulating..

Post by digidog » Mon Aug 26, 2013 2:42 am

The site owners have taken down the phishing page but they forgot to secure their server. So the bad guys have set up another copy at a slightly different location...

Careful: Live phishing site
https://cleeng.com/blog/wp-content/uplo ... westle.au/" onclick="window.open(this.href);return false;

User avatar
Foggyone
Site Admin
Posts: 9880
Joined: Sat May 22, 2004 8:16 pm
First Name: Peter
Location: Lower Hutt
Contact:

Re: Westpac "security change" hoax email circulating..

Post by Foggyone » Mon Aug 26, 2013 4:11 am

And there is another waiting at https://cleeng.com/blog/wp-content/uplo ... 8/westham/" onclick="window.open(this.href);return false;

Input is handled by dataz.php
Google, the answer to so many questions!
-----------------------------------------------------

Post Reply

Who is online

Users browsing this forum: No registered users and 4 guests