46545). National City Bank - PSS.Phishing.nationalcity.com-46545 (Awaiting official AV Signature).
This email targets customers of National City Bank.
Message Details
| Malware Name: | PSS.Phishing.nationalcity.com-46545 (Awaiting official AV Signature). |
| Origin: | |
| Date first seen: | 11/07/2007 05:00:59 |
| From: | "National City" <clientservice.refy04581240227u.cm@nationalcity.com> |
| Subject: | National City corporate customer service: account notification! (mess_id: D60245834775GL) |
Attacker's URLs
The following table shows the details of the URLs used by the attacker. These could either be the fake website of the attack, or a site which redirects to the attackers fake site. Sometimes the attacker will use an additional site for hosting resources such as images.
The table shows the current status of the site: if it is still reachable (
), or if it has been shut down (
). If the site has not been confirmed as a phishing site it is shown with the symbol
. The time when the site was first observed is shown, together with the time that the site was shut down, if applicable. Do not visit the attackers site as it may contain malware. You can get more details on the site by clicking on the
symbol.
| Status | First observed | Shut Down | Internet Address | URL | |
|---|---|---|---|---|---|
| http://session-11396716.nationalcity.com.dll.hk/corporate/onlineservices/TreasuryMgmt/ | |||||
| http://session-11396716.nationalcity.com/corporate/onlineservices/TreasuryMgmt/ |
Message Text
The text below shows the message content, rendered in a safe way. It does not show images or HTML formatting, but the text is the same as that contained in the phishing email. Each clickable link is shown as a reference. You can see the way the URL is presented in the main body of the text, while the actual URL activated by the link is shown below the main body.
Dear National City customer, National City Corporate Customer Service requests you to complete Treasury Management Services Online Confirmation Form. This procedure is obligatory for all business and corporate clients of National City. Please select the hyperlink and visit the address listed to access Treasury Management Services Online Confirmation Form. [1]http://session-11396716.nationalcity.com/corporate/onlineservices/Treasur yMgmt/ Again, thank you for choosing National City for your business needs. We look forward to working with you. Please do not respond to this email. Replies to this mail are not read by National City Corporate Customer Service or technical support. . TKO: 0x240, 0x94, 0x0, 0x01799137, 0x251, 0x69713898, 0x152, 0x0089, 0x4542, 0x6, 0x72517796, 0x9066, 0x1, 0x42, 0x456 start, 1V5X, rcs. 0x3771, 0x87, 0x344, 0x2, 0x50, 0x1030, 0x0918, 0x76, 0x713, 0x09, 0x1272 0x7, 0x647, 0x27479340 Z6Q: 0x52 0x3, 0x20348531 0x83, 0x3649, 0x044, 0x4, 0x7009, 0x410, 0x88, 0x2, 0x2, 0x3067, 0x4, 0x9 start: 0x081, 0x18612365 0x233, 0x4, 0x22183119, 0x6522, 0x20, 0x12, 0x179, 0x659, 0x67107221 0x37642945, 0x366, 0x7455 1FO: 0x5068, 0x89532268, 0x92, 0x90, 0x1 0x8, 0x3846, 0x0429, 0x6413, 0x4068, 0x9, 0x08, 0x3, 0x078, 0x50265959, 0x3, 0x6, 0x9 XFEG, Y8JN QMM, exe H5GX: 0x7, 0x3, 0x22, 0x42, 0x91, 0x103, 0x046, 0x65, 0x240 0x711, 0x07366041, 0x7786, 0x9972, 0x74627710, 0x32, 0x4, 0x80853758, 0x2050, 0x0, 0x80, 0x4391 O3KS common function include GWL NF4P 0HFP. update: 0x52570334, 0x6286 0x1 define: 0x8, 0x70, 0x8, 0x4, 0x2, 0x2249, 0x935, 0x8065, 0x888, 0x112, 0x6258, 0x11703610 RHGB: 0x30544876, 0x065 0x49622445, 0x49985367, 0x9651, 0x1, 0x07879758, 0x15592342, 0x83585943, 0x0, 0x01653791, 0x53, 0x86668166, 0x50, 0x20903061, 0x7060, 0x0798 file: 0x8543, 0x19, 0x920, 0x39, 0x861, 0x4250, 0x9, 0x7, 0x345, 0x8656 0x223, 0x63, 0x9263, 0x350, 0x838, 0x7, 0x6015, 0x304, 0x621, 0x4, 0x52877810 REBX stack NP00x0712, 0x2, 0x07, 0x5188, 0x334, 0x9, 0x05807008 0x419, 0x5, 0x034, 0x2178, 0x7244, 0x68418775, 0x104, 0x679, 0x21, 0x37778563 0x84152563, 0x4, 0x8925, 0x0, 0x86, 0x51802907, 0x57, 0x5711, 0x48, 0x752, 0x71376629, 0x383, 0x2242, 0x728 common, XUIE, interface, SJI, EKW9, OBLK 0x2, 0x04, 0x56267224, 0x4398, 0x80434077, 0x447, 0x05643113, 0x054, 0x72314942, 0x361, 0x21, 0x6519, 0x31921994 References 1. http://session-11396716.nationalcity.com.dll.hk/corporate/onlineservices/TreasuryMgmt/