« October 2008 · April 2009 · September 2010 »

December 2008
MonTueWedThuFriSatSun
01020304050607
08091011121314
15161718192021
22232425262728
293031    
January 2009
MonTueWedThuFriSatSun
   01020304
05060708091011
12131415161718
19202122232425
262728293031 
February 2009
MonTueWedThuFriSatSun
      01
02030405060708
09101112131415
16171819202122
232425262728 

Calendar:

Newest first Oldest first

Thursday, 29 January 2009

Asprox Goes Phishing Again


The first time around with Asprox, we saw a little bit of phishing. The question with any botnet is "how do they make money off of this?" Phishing is certainly one way. Renting your botnet out to a phishing organization is probably an even better way. Must less risk for you, Mr. Botnet Herder. Today we saw a template update to the drones:

<hls>
/d
/wps
/favicon.ico
/cs70_banking/logon/blank.gif
/cs70_banking/logon/favicon.gif
/cs70_banking/logon/id_logo-outside.gif
/cs70_banking/logon/id_main_sb.css
/cs70_banking/logon/popup.gif
/cs70_banking/logon/sconfirm
/cs70_banking/logon/sdetails.aspx
</hls>

Point a browser at <asprox node>/cs70_banking/logon/sconfirm and you find a phish for Alliance and Leicester Commercial Bank:

I admit I'm not entirely familiar with this bank, but it doesn't look to be your standard consumer type bank. Bigger gains to be had?

Once you fill in some details, your form is submitted to <asprox node>/cs70_banking/logon/sdetails.aspx and then your browser is redirected to the homepage of the real bank site.

With Asprox's template capabilities, I imagine we'll see more of this.

=>Posted January 29, 2009, at 01:28 PM by Mike Johnson