« April 2010 · October 2010 »

June 2010
MonTueWedThuFriSatSun
 010203040506
07080910111213
14151617181920
21222324252627
282930    
July 2010
MonTueWedThuFriSatSun
   01020304
05060708091011
12131415161718
19202122232425
262728293031 
August 2010
MonTueWedThuFriSatSun
      01
02030405060708
09101112131415
16171819202122
23242526272829
3031     

Calendar:

  • 15.08.2010: Spam using RU domains - Who's your nameserver?
  • 13.08.2010: Binary Whitelisting Service
  • 02.08.2010: Of Opinions and Anti-Virus Testing
  • 05.07.2010: Lies, Damn Lies, and Botnet Size
  • 09.06.2010: Shadowserver Sinkholing domain associated with SQLi attacks on IIS/ASP web servers
Newest first Oldest first

Tuesday, 8 January 2008

Storm goes phishing?

Today Shadowserver picked up a new name being used by the Storm worm: i-barclays.com. Obviously, this site can be (and evidently has been) used for phishing. This is a new twist for whoever is behind Storm, as we've not seen them try the phishing angle. All Storm nodes capable of serving up any of the Holiday ecards can also serve as phishing sites.

It should be pointed out that the registrar, nic.ru, has not pulled any of the original Holiday ecard domains. There is little reason to believe that they will pull new phishing domains with any reasonable speed. The Storm group stands to be the new owners of thousands of accounts, both with Barclays and Halifax (the other domain currently in use is i-halifax.com). Barclays is returning a 403 error from storm nodes at the moment, but the Halifax phish is live.

Others have seen similar behavior:
PhishTank has screenshots of the phish itself
SCMagazineUS.com reported on a finding by Fortinet.

i-barclays.com has shown up before as a known phishing domain, but someone didn't get the memo when the Storm group re-registered it.

=>Posted January 08, 2008, at 09:42 AM by Mike Johnson