Anatomy Of A Phishing Attack

Phishing attacks are the most common form of attack received today. Our communication methods have moved away from voice to on-line, and with more online interactions with companies comes the bigger risk of these messages not always being what they seem.

Phishing e-mails are often branded the same as legitimate messages. They will either talk about financial issues (confirm this payment you have made, you are due a refund etc), or will ask you to confirm your identity or reset your passwords.

It’s easy to get tricked by these e-mails, and if the link you clicked takes you to what looks like the companies website, what could possibly go wrong ?

I recently received a number of e-mails and text messages from “Apple”. The communication stated that they had spotted some suspicious activity on my account and asked me to click a link to validate their ID so that I could continue using my iTunes accounts.

Upon clicking the link, I was presented with this website:

It looks exactly like the Apple website, which is because it has been copied from their legitimate website. HOWEVER, if you look at the address bar, the site isn’t Apple.com, but is on a server called mtc-travel.com.

MTC Travel run a webserver that is missing security patches, and the bad guys have been able to gain access to the server and setup their own website alongside MTC’s. MTC Travel probably don’t even know they are now hosting a second website.

Anything we now enter onto this fake Apple website will be stored on the server for the bad guys to come and collect later on.

So, page 1, and they are asking for our Apple ID and our Password. This gives them access onto your iTunes Store account, where you will probably have a stored payment card to buy songs, apps etc from the Apple Store.

After entering our Apple ID and Password, we click next, and are shown the following:

To confirm who we are, we are being asked for our full postal address, date of birth, phone number and our credit card details, including the CV2 Numbers.

CV2 is the 3 digits on the back of a credit/debit card. Organisations are not allowed to store CV2 numbers, so if being asked for all of this personal data didn’t raises suspicion, being asked for a CV2 to validate who you are should set alarm bells ringing !

When we click confirm, the Verified by Visa screen is displayed.

We are used to seeing this screen when making online purchases. The page is asking for the full Verified by Visa Password. When the legitimate Verified By Visa screen is presented during an on-line purchase, you are only ever asked for 2 characters from your password, not the full password.

At this point we have given the criminals our AppleID logon and Password (a password we probably use elsewhere), our address, date of birth, credit card details, CV2 number and Verified by Visa password. They have everything they need to carry out online fraud, identity theft, card cloning etc – all because the site LOOKED legitimate.

When we hit confirm, the  site displays a message to confirm all of your details are correct and you have been successfully validate (violated?) and our account is active once more.

Once you click ok, you will be taken back to the Apple homepage, but look at the website address this time…

You are now on Apple.com, the legitimate website. All of the previous pages were on MTC-Travel. By returning you to the legitimate website you won’t realise you have just been phished and your data stolen.

Some phising attacks are just after your logon name and password, as we tend to re-use those across multiple sites. These are usually branded with Gmail, Paypal, Amazon, O2, Netflix etc.

These will ask for your logon and password, as the Apple one started with, but once you have entered them they will then transfer you to the legitimate logon screen to re-enter your details. They realise that we will think we have put in a wrong password once without getting suspicious, so when they direct you to the legitimate site and your logon then works, we don’t think anything bad has happened. That first logon, on the compromised website has now given the criminals your logon id and password and you’re none the wiser, until they start to use it.

Comment (165)

  • canadian rx| 12th November 2022

    canadian prescriptions online https://aoc.stamford.edu/profile/upogunem/

    Thanks a lot! Numerous postings.

  • canada medication| 17th November 2022

    online pharmacies canada https://500px.com/p/reisupvertketk/?view=groups

    You said it terrifically.

  • Canadian Pharmacy USA| 19th November 2022

    online canadian pharmacies https://obsusilli.zombeek.cz/

    With thanks. An abundance of postings!

  • pharmacy canada| 22nd November 2022

    canadian pharmacy world https://challonge.com/townsiglutep

    You stated that superbly.

  • drugs for sale| 23rd November 2022

    canadian pharmacy viagra brand https://scisevitrid.estranky.sk/clanky/canada-pharmacies.html

    You reported it superbly!

  • cialis canadian pharmacy| 23rd November 2022

    canadian mail order pharmacies https://brujagflysban.zombeek.cz/

    Wonderful write ups. Cheers.

  • 500px.compstofovinin?view=groups| 27th November 2022

    Viagra lowest price https://500px.com/p/stofovinin/?view=groups

    You’ve made your stand very nicely.!

  • challonge.comafersparun| 28th November 2022

    Tadalafil 20 mg https://challonge.com/afersparun

    Amazing quite a lot of wonderful facts!

  • erectile enhancement pills| 28th November 2022

    buy erectile dysfunction medications online https://plancaticam.estranky.cz/clanky/best-drugs-for-ed.html

    Fantastic postings, Many thanks!

  • wallsawadar.zombeek.cz| 29th November 2022

    Viagra generique https://wallsawadar.zombeek.cz/

    Whoa many of valuable knowledge.

  • canada medication| 1st December 2022

    highest rated canadian pharmacies https://canadianpharmaceuticalsonline.studio.site/

    You explained that very well.

  • canadian pharmacy king| 3rd December 2022

    canadian government approved pharmacies https://canadianpharmaceuticalsonline.blog.jp/archives/19372004.html

    Seriously lots of very good advice.

  • canadian pharmacy viagra| 5th December 2022

    legitimate canadian mail order pharmacies https://canadianpharmaceuticalsonline.weblog.to/archives/19410199.html

    You actually said that terrifically!

  • canadian discount pharmacies| 5th December 2022

    canada pharmacies online prescriptions https://canadianpharmaceuticalsonline.blogism.jp/archives/17866152.html

    Many thanks, An abundance of write ups.

  • trust pharmacy canada| 18th December 2022

    canadian pharmaceuticals https://experiment.com/users/canadiandrugs/

    Terrific knowledge. Thanks a lot.

  • canadian drugs| 9th January 2023

    trust pharmacy canada https://sketchfab.com/canadianpharmaceuticalsonline

    You said that terrifically.

  • https://fliphtml5.com/homepage/fhrha| 9th January 2023

    Viagra generika https://fliphtml5.com/homepage/fhrha

    You revealed this exceptionally well!

  • canadian pharmacycanadian pharmacy| 29th January 2023

    canadian pharmacies that are legit https://haikudeck.com/presentations/cheapprescriptiondrugs

    Incredible loads of great advice.

  • canadian pharmacies that are legit| 1st February 2023

    canadian pharmacycanadian pharmacy https://www.bakespace.com/members/profile/Canadian drugs online pharmacies/1563583/

    Great tips. Thanks.

  • canadian pharcharmy online| 8th February 2023

    canadian pharmacies mail order https://fnote.net/notes/7ce1ce

    Very good stuff. Many thanks!

  • https://www.dibiz.com/gdooc| 2nd March 2023

    Buy generic viagra https://www.dibiz.com/gdooc

    Regards, Plenty of advice.

  • https://www.buymeacoffee.com/pharmacies| 7th March 2023

    Low cost viagra 20mg https://www.buymeacoffee.com/pharmacies

    Appreciate it! Numerous information!

  • list of reputable canadian pharmacies| 27th March 2023

    canadian pharmacies online prescriptions https://www.viki.com/users/canadianpharmaciess/about

    Incredible quite a lot of very good knowledge.

  • canadian viagra| 12th April 2023

    no 1 canadian pharcharmy online https://pinshape.com/users/2612491-medicine-online-order

    Fine information. Regards.

  • canadianpharmacy| 12th April 2023

    prescription drugs without prior prescription https://500px.com/p/arrameru/?view=groups

    You stated that superbly.

  • buy viagra 25mg| 13th April 2023

    no 1 canadian pharcharmy online https://challonge.com/gyoupafefer

    With thanks. A good amount of knowledge.

  • online pharmacy| 14th April 2023

    legitimate canadian mail order pharmacies https://hafbeltminla.zombeek.cz/

    Fantastic content, Appreciate it.