Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > NZ Computing > Headsup!! ANZ phishing spam :-(

Reply
Thread Tools

Headsup!! ANZ phishing spam :-(

 
 
Adam
Guest
Posts: n/a
 
      03-23-2006
I've just been spammed by a not very convincing e-mail that appears to
come from "support_ref_ [daft number here] at anz.com".

The attached gif image tries to send you to:

http _www.anz.com.inetbankmain.isapdl.com_a_.htm

but shows in the gif as:

https://wwwDOTanzDOTcom/inetbank/ban...rmation/do.asp

(DOTS replaced in case someone clicks the link here).

The usual "software upgrade" - we wish you to confirm your bank
details!

Grrrrrrrrrrrrrrrrrrrrrrrr ...

Adam.
 
Reply With Quote
 
 
 
 
Matty F
Guest
Posts: n/a
 
      03-23-2006
Adam wrote:
> I've just been spammed by a not very convincing e-mail that appears to
> come from "support_ref_ [daft number here] at anz.com".
>
> The attached gif image tries to send you to:
>
> http _www.anz.com.inetbankmain.isapdl.com_a_.htm
>
> but shows in the gif as:
>
> https://wwwDOTanzDOTcom/inetbank/ban...rmation/do.asp
>
> (DOTS replaced in case someone clicks the link here).
>
> The usual "software upgrade" - we wish you to confirm your bank
> details!
>
> Grrrrrrrrrrrrrrrrrrrrrrrr ...


Yes I just got five of them. The last 3 were labelled by xtra as
[SPAM]. Why doesn't a Whois work on that URL?

 
Reply With Quote
 
 
 
 
Brendon
Guest
Posts: n/a
 
      03-23-2006
Yeh, got mine this morning - great - nearly clicked on it....considering I
am not a member of ANZ bank....I don't think so!


twats!!

"Matty F" <> wrote in message
news:U3DUf.8192$...
> Adam wrote:
>> I've just been spammed by a not very convincing e-mail that appears to
>> come from "support_ref_ [daft number here] at anz.com".
>>
>> The attached gif image tries to send you to:
>>
>> http _www.anz.com.inetbankmain.isapdl.com_a_.htm
>>
>> but shows in the gif as:
>>
>> https://wwwDOTanzDOTcom/inetbank/ban...rmation/do.asp
>>
>> (DOTS replaced in case someone clicks the link here).
>>
>> The usual "software upgrade" - we wish you to confirm your bank
>> details!
>>
>> Grrrrrrrrrrrrrrrrrrrrrrrr ...

>
> Yes I just got five of them. The last 3 were labelled by xtra as [SPAM].
> Why doesn't a Whois work on that URL?
>



 
Reply With Quote
 
bonspiel@orcon.net.nz
Guest
Posts: n/a
 
      03-23-2006
Received and spamcopped

 
Reply With Quote
 
Mark Robinson
Guest
Posts: n/a
 
      03-23-2006
Matty F wrote:
> Adam wrote:
>> I've just been spammed by a not very convincing e-mail that appears to
>> come from "support_ref_ [daft number here] at anz.com".
>>
>> The attached gif image tries to send you to:
>>
>> http _www.anz.com.inetbankmain.isapdl.com_a_.htm
>>
>> but shows in the gif as:
>>
>> https://wwwDOTanzDOTcom/inetbank/ban...rmation/do.asp
>>
>> (DOTS replaced in case someone clicks the link here).
>>
>> The usual "software upgrade" - we wish you to confirm your bank
>> details!
>>
>> Grrrrrrrrrrrrrrrrrrrrrrrr ...

>
> Yes I just got five of them. The last 3 were labelled by xtra as [SPAM].
> Why doesn't a Whois work on that URL?
>


Interesting question.

ANZ are reported on Radio NZ news as having "shut down the illegal website" so
perhaps they've had it clobbered at the whois level.

However it's still in the DNS via paradise (whois results follow in order) :

> www.anz.com.inetbankmain.isapdlls.net has address 24.11.143.205
> www.anz.com.inetbankmain.isapdlls.net has address 66.65.19.24
> www.anz.com.inetbankmain.isapdlls.net has address 67.189.241.161
> www.anz.com.inetbankmain.isapdlls.net has address 69.76.88.225
> www.anz.com.inetbankmain.isapdlls.net has address 69.245.111.39
> ================================================== ============================
>
> OrgName: Road Runner
> OrgID: RRNY
> Address: 13241 Woodland Park Road
> City: Herndon
> StateProv: VA
> PostalCode: 20171
> Country: US
>
> ReferralServer: rwhois://ipmt.rr.com:4321
>
> NetRange: 66.65.0.0 - 66.65.255.255
> CIDR: 66.65.0.0/16
> NetName: RR-NYC-1BLK
> NetHandle: NET-66-65-0-0-1
> Parent: NET-66-0-0-0-0
> NetType: Direct Allocation
> NameServer: DNS1.RR.COM
> NameServer: DNS2.RR.COM
> NameServer: DNS3.RR.COM
> NameServer: DNS4.RR.COM
> Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
> RegDate: 2001-01-19
> Updated: 2002-11-25
>
> RTechHandle: ZS30-ARIN
> RTechName: ServiceCo LLC
> RTechPhone: +1-703-345-3416
> RTechEmail:
>
> OrgAbuseHandle: ABUSE10-ARIN
> OrgAbuseName: Abuse
> OrgAbusePhone: +1-703-345-3416
> OrgAbuseEmail:
>
> OrgTechHandle: IPTEC-ARIN
> OrgTechName: IP Tech
> OrgTechPhone: +1-703-345-3416
> OrgTechEmail:
>
> # ARIN WHOIS database, last updated 2006-03-22 19:10
> # Enter ? for additional hints on searching ARIN's WHOIS database.
>
>
> Found a referral to ipmt.rr.com:4321.
>
> %rwhois V-1.5:003fff:00 ipmt-01.rr.com (by Network Solutions, Inc. V-1.5.7.3)
> network:Class-Name:network
> network:ID:NETBLK-isrr-66.65.16.0-21
> network:Auth-Area:66.65.16.0/21
> network:Network-Name:isrr-66.65.16.0
> network:IP-Network:66.65.16.0/21
> network:IP-Network-Block:66.65.16.0 - 66.65.23.255
> network:Organization;I:Road Runner
> network:Tech-Contact;I:
> network:Admin-Contact;I:IPADD-ARIN
> network:Created:20060323
> network:Updated:20060323
> network:Updated-By:
>
> network:Class-Name:network
> network:ID:NETBLK-ISRR-66.65.0.0/17
> network:Auth-Area:66.65.0.0/17
> network:Network-Name:ISRR-66.65.0.0
> network:IP-Network:66.65.0.0/17
> network:IP-Network-Block:66.65.0.0 - 66.65.127.255
> network:Organization;I:Road Runner
> network:Tech-Contact;I:
> network:Admin-Contact;I:IPADD-ARIN
> network:Created:20060323
> network:Updated:20060323
> network:Updated-By:
>
> %ok
> ================================================== ============================
> Comcast Cable Communications, IP Services ATT-COMCAST (NET-67-160-0-0-1)
> 67.160.0.0 - 67.191.255.255
> Comcast Cable Communications, Inc. BOSTON-9 (NET-67-189-128-0-1)
> 67.189.128.0 - 67.189.255.255
>
> # ARIN WHOIS database, last updated 2006-03-22 19:10
> # Enter ? for additional hints on searching ARIN's WHOIS database.
> ================================================== ============================
>
> OrgName: Road Runner
> OrgID: RRWE
> Address: 13241 Woodland Park Road
> City: Herndon
> StateProv: VA
> PostalCode: 20171
> Country: US
>
> ReferralServer: rwhois://ipmt.rr.com:4321
>
> NetRange: 69.75.0.0 - 69.76.255.255
> CIDR: 69.75.0.0/16, 69.76.0.0/16
> NetName: RRWE
> NetHandle: NET-69-75-0-0-1
> Parent: NET-69-0-0-0-0
> NetType: Direct Allocation
> NameServer: DNS1.RR.COM
> NameServer: DNS2.RR.COM
> NameServer: DNS3.RR.COM
> NameServer: DNS4.RR.COM
> Comment:
> RegDate: 2003-09-08
> Updated: 2004-05-03
>
> OrgAbuseHandle: ABUSE10-ARIN
> OrgAbuseName: Abuse
> OrgAbusePhone: +1-703-345-3416
> OrgAbuseEmail:
>
> OrgTechHandle: IPTEC-ARIN
> OrgTechName: IP Tech
> OrgTechPhone: +1-703-345-3416
> OrgTechEmail:
>
> # ARIN WHOIS database, last updated 2006-03-22 19:10
> # Enter ? for additional hints on searching ARIN's WHOIS database.
>
>
> Found a referral to ipmt.rr.com:4321.
>
> %rwhois V-1.5:003fff:00 ipmt-01.rr.com (by Network Solutions, Inc. V-1.5.7.3)
> network:Class-Name:network
> network:ID:NETBLK-isrr-69.76.88.0-21
> network:Auth-Area:69.76.88.0/21
> network:Network-Name:isrr-69.76.88.0
> network:IP-Network:69.76.88.0/21
> network:IP-Network-Block:69.76.88.0 - 69.76.95.255
> network:Organization;I:Road Runner
> network:Tech-Contact;I:
> network:Admin-Contact;I:IPADD-ARIN
> network:Created:20060323
> network:Updated:20060323
> network:Updated-By:
>
> network:Class-Name:network
> network:ID:NETBLK-ISRR-69.76.0.0/16
> network:Auth-Area:69.76.0.0/16
> network:Network-Name:ISRR-69.76.0.0
> network:IP-Network:69.76.0.0/16
> network:IP-Network-Block:69.76.0.0 - 69.76.255.255
> network:Organization;I:Road Runner
> network:Tech-Contact;I:
> network:Admin-Contact;I:IPADD-ARIN
> network:Created:20060323
> network:Updated:20060323
> network:Updated-By:
>
> %ok
> ================================================== ============================
> Comcast Cable Communications, Inc. JUMPSTART-4 (NET-69-240-0-0-1)
> 69.240.0.0 - 69.255.255.255
> Comcast Cable Communications, Inc MICHIGAN-17 (NET-69-245-64-0-1)
> 69.245.64.0 - 69.245.127.255
>
> # ARIN WHOIS database, last updated 2006-03-22 19:10
> # Enter ? for additional hints on searching ARIN's WHOIS database.
> ================================================== ============================
> Comcast Cable Communications, IP Services EASTERNSHORE-1 (NET-24-0-0-0-1)
> 24.0.0.0 - 24.15.255.255
> Comcast Cable Communications MICHIGAN-G-5 (NET-24-11-128-0-1)
> 24.11.128.0 - 24.11.143.255
>
> # ARIN WHOIS database, last updated 2006-03-22 19:10
> # Enter ? for additional hints on searching ARIN's WHOIS database.
> ================================================== ============================

 
Reply With Quote
 
k
Guest
Posts: n/a
 
      03-24-2006
wrote:
> Received and spamcopped
>


Thunderbird's built in spam detection managed to catch this one pretty
well for me
 
Reply With Quote
 
Mutlley
Guest
Posts: n/a
 
      03-24-2006
k <> wrote:

> wrote:
>> Received and spamcopped
>>

>
>Thunderbird's built in spam detection managed to catch this one pretty
>well for me


Been getting these things all day. Don't even have an ANZ account.
Fortunately our exchange server puts them in the spam folder.
 
Reply With Quote
 
Adam
Guest
Posts: n/a
 
      03-24-2006
On Fri, 24 Mar 2006 14:48:12 +1200, k wrote:

> wrote:
>> Received and spamcopped
>>

>
>Thunderbird's built in spam detection managed to catch this one pretty
>well for me


Hmmm - my TB seems to let them in ( - I've received them from about
5 different "pseudo" addresses now.

Any general hints as to where/how my spam filter is (mis)configured)?

Adam.
 
Reply With Quote
 
Ross
Guest
Posts: n/a
 
      03-24-2006
On Fri, 24 Mar 2006 01:16:42 +1200, Adam wrote:

>I've just been spammed by a not very convincing e-mail that appears to
>come from "support_ref_ [daft number here] at anz.com".
>
>The attached gif image tries to send you to:
>
>http _www.anz.com.inetbankmain.isapdl.com_a_.htm
>
>but shows in the gif as:
>
>https://wwwDOTanzDOTcom/inetbank/ban...rmation/do.asp
>
>(DOTS replaced in case someone clicks the link here).
>
>The usual "software upgrade" - we wish you to confirm your bank
>details!
>
>Grrrrrrrrrrrrrrrrrrrrrrrr ...
>
>Adam.


Followed the link and put in details for them.
Unfortunately, if they try them they aren't going to get into my
account
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Spam, spam, spam, spam... rickman VHDL 5 02-13-2010 04:52 PM
Best Spam / Phishing Filter blah Computer Security 7 12-22-2006 11:34 PM
ANZ target of phishing scam Who Am I NZ Computing 0 02-16-2006 08:03 PM
Spam! Spam! Spam! Spam! Anon anon_007_35@lostbbs.dyndns.org Computer Information 1 01-30-2005 04:16 AM
Spam! Spam! Spam! Spam! Anon anon_007_35@lostbbs.dyndns.org Computer Support 1 01-30-2005 04:16 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57