<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>javadis.com &#187; phishing expedition</title>
	<atom:link href="http://javadis.com/tag/phishing-expedition/feed/" rel="self" type="application/rss+xml" />
	<link>http://javadis.com</link>
	<description>Javadi Present Some More Controversial Ideas</description>
	<lastBuildDate>Tue, 24 Nov 2009 17:10:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>A phishing expedition</title>
		<link>http://javadis.com/a-phishing-expedition/</link>
		<comments>http://javadis.com/a-phishing-expedition/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 18:44:45 +0000</pubDate>
		<dc:creator>Javadi</dc:creator>
				<category><![CDATA[safe internet]]></category>
		<category><![CDATA[phishing expedition]]></category>

		<guid isPermaLink="false">http://javadis.com/?p=106</guid>
		<description><![CDATA[I just got this email:
&#60;&#60;beginning of email&#62;&#62;
FEDERAL RESERVE BANK
Important:
You&#8217;re getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.
On January 26, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this [...]]]></description>
			<content:encoded><![CDATA[<p>I just got this email:<br />
&lt;&lt;beginning of email&gt;&gt;<br />
FEDERAL RESERVE BANK</p>
<p>Important:<br />
You&#8217;re getting this letter in connection with new directions issued by U.S. Treasury Department. The directions concern U.S. Federal Wire online payments.</p>
<p>On January 26, 2009 a large-scaled phishing attack started and has been still lasting. A great number of banks and credit unions is affected by this attack and quantity of illegal wire transfers has reached an extremely high level.</p>
<p>U.S. Treasury Department, Federal Reserve and Federal Deposit Insurance Corporation (FDIC) in common worked out a complex of immediate actions for the highest possible reduction of fraudulent operations. We regret to inform you that definite restrictions will be applied to all Federal Wire transfers from February 6 till February 13.</p>
<p>Here you can get more detailed information regarding the affected banks and U.S. Treasury Department restrictions:</p>
<p>http://ach-frs.e-bankserver.us/37575142/secur~12432/wire/</p>
<p>Federal Reserve Bank System Administration<br />
&lt;&lt;end of email&gt;&gt;</p>
<p>So how do we know it is a phising email:</p>
<ol>
<li>The English is atrocious: eg has been still lasting&#8230;.</li>
<li>The spaces are in the wrong places.</li>
<li>The URL they want to send you is not www.ustreas.gov which is the URL of the<br />
U.S. Department of the Treasury.</li>
<li>It is not U.S. Treasury Department but U.S. Department of the Treasury. Subtle things like this can give you clues about what is going on.</li>
<li>Remember all US government agencies are dot GOV never dot COM dot US or anything else.</li>
</ol>
<p>When in doubt run a WHOIS on the offending site. This is what I got:</p>
<div id="serverDataContainer">
<div class="ajax" style="width: 100%;">
<h3>Server Data</h3>
<table class="whois" border="0" cellspacing="1">
<tbody>
<tr class="odd">
<td class="t">IP Address:</td>
<td>61.235.117.73		         		            Whois 		         | 		         		            Reverse-IP 		         | 		         		            Ping 		         | 		         		            DNS Lookup 		         | 		         		            Traceroute</td>
</tr>
<tr>
<td class="t">IP Location</td>
<td><img src="http://img.domaintools.com/flags/cn.gif" alt="China" width="18" height="12" /> &#8211; Beijing			        &#8211; Beijing			        &#8211; China Railcom Guangdong Shenzhen Subbranch</td>
</tr>
<tr class="odd">
<td class="t">Response Code:</td>
<td>200</td>
</tr>
<tr>
<td class="t">Domain Status:</td>
<td>Registered And Active Website</td>
</tr>
</tbody>
</table>
<p><script type="text/javascript"><!--
jQuery('#serverDataContainer').show();
// --></script></div>
</div>
<div id="exclusiveContainer">
<div class="ajax" style="width: 100%;">
<h3>DomainTools Exclusive</h3>
<table class="whois exclusive" border="0" cellspacing="1">
<tbody>
<tr class="odd">
<td class="t">Registrant Search:</td>
<td style="color: #008800; font-weight: bold;">&#8220;Evgeniy Kotsarev&#8221;  								 				owns about 5 other domains</td>
</tr>
<tr>
<td class="t">NS History:</td>
<td>3 changes				 				on 				3					 unique name  					servers					 over 3					 years.</td>
</tr>
<tr class="odd">
<td class="t"></td>
<td></td>
</tr>
<tr>
<td class="t"></td>
<td></td>
</tr>
</tbody>
</table>
</div>
</div>
<h3>Whois Record</h3>
<p>Domain Name:                                 E-BANKSERVER.US<br />
Domain ID:                                   D18514989-US<br />
Sponsoring Registrar:                        WEB COMMERCE COMMUNICATIONS, LTD.<br />
Registrar URL (registration services):       whois.web.cc<br />
Domain Status:                               clientDeleteProhibited<br />
Domain Status:                               clientTransferProhibited<br />
Domain Status:                               clientUpdateProhibited<br />
Registrant ID:                               WN8837600T<br />
Registrant Name:                             Evgeniy Kotsarev<br />
Registrant Organization:                     Evgeniy Kotsarev<br />
Registrant Address1:                         Sovetskaya str. d.11 kv.1<br />
Registrant City:                             Kachalino<br />
Registrant State/Province:                   Volgogradskaya<br />
Registrant Postal Code:                      403080<br />
Registrant Country:                          Russian Federation<br />
Registrant Country Code:                     RU<br />
Registrant Phone Number:                     +7.8442531113<br />
Registrant Facsimile Number:                 +0.0<br />
Registrant Email:                            <span style="position: relative; top: -5px;"><img src="http://source.domaintools.com/email.pgif?md5=759433a17292d73f4c6ce880b7bab53d&amp;face=Atomic_Clock_Radio&amp;size=7&amp;color=000000&amp;bgcolor=FFFFFF&amp;format%5B%5D=transparent&amp;face=Trebuchet&amp;size=9&amp;color=0000FF&amp;bgcolor=FFFFFF&amp;format%5B%5D=underline&amp;format%5B%5D=transparent" border="0" alt="" align="middle" /></span></p>
<p>And:</p>
<p>Domain Registration Date:                    Mon Feb 02 14:32:20 GMT 2009<br />
Domain Expiration Date:                      Mon Feb 01 23:59:59 GMT 2010<br />
Domain Last Updated Date:                    Mon Feb 02 19:33:51 GMT 2009</p>
<p>To get more information on this or any site go to <a href="http://whois.domaintools.com/" title="Run a WHOIS and find the website owner"  target="_blank">WHOIS</a>.</p>
<p>The point is that the phishing site was registered today and no doubt they&#8217;ll send out milions of emails and unfortunately there are enough people who don&#8217;t know what they are doing and are caught hook line and sinker.</p>
<p>To protect yourself: never go to directly to a website from an email when they scare you. Type in the website address yourself. So if an email comes from paypal go to paypal.com by typing it in you browser yourself and remember never give your password, SSN, user ID to anyone who asks from an email but it is much safer never to click on an unsolicited email&#8217;s links.
<div id="apf_post_footer">
<h4>Related Articles</h4>
<ul>
<li class="apf_footer"><a href="http://javadis.com/step-by-step/" >Step by step</a></li>
</ul>
</div>
<p><a href="http://www.dpbolvw.net/click-2894626-10510159"  target="_blank" onmouseover="window.status='http://www.vistaprint.com/vp/gateway.asp?S=3423758781';return true;" onmouseout="window.status=' ';return true;">Winter Clearance Sale at VistaPrint! Save up to 90%</a><br />
<img src="http://www.ftjcfx.com/image-2894626-10510159" width="1" height="1" border="0"/></p>
<p><a href="http://www.kqzyfj.com/click-2894626-10555495"  target="_blank" onmouseover="window.status='http://www.ivlproducts.com';return true;" onmouseout="window.status=' ';return true;">Take $50 off your supplement order of $200 or more at the Institute For Vibrant Living.  Use Code ST010</a><br />
<img src="http://www.tqlkg.com/image-2894626-10555495" width="1" height="1" border="0"/>
<p><font color="#B4B4B4" size="-2">Post Footer automatically generated by <a href="http://www.freetimefoto.com/add_post_footer_plugin_wordpress"  style="color: #B4B4B4; text-decoration:underline;">Add Post Footer Plugin</a> for wordpress.</font></p>
<p><map name='google_ad_map_106_d288fba63412af5d'>
<area shape='rect' href='http://imageads.googleadservices.com/pagead/imgclick/106?pos=0' coords='1,2,367,28' />
<area shape='rect' href='http://services.google.com/feedback/abg' coords='384,10,453,23'/></map>
<img usemap='#google_ad_map_106_d288fba63412af5d' border='0' src='http://imageads.googleadservices.com/pagead/ads?format=468x30_aff_img&amp;client=&amp;channel=&amp;output=png&amp;cuid=106&amp;url= http%3A%2F%2Fjavadis.com%2Fa-phishing-expedition%2F' /></p>]]></content:encoded>
			<wfw:commentRss>http://javadis.com/a-phishing-expedition/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
