« newyorkrangers.cz gets hacked
Weird spam for sex on Twitter »

IE8 #fail

August 14th, 2009

Although IE8 passed the browser security test with flying colours (hmm) (results here), it did not catch that one below.

Also, should you trust your address bar? No!

Start with a hijacked Hosts file (incidentally it came from the malware described in the previous post):

hosts

Browse to www.bancodabrasil.com.br

whole

However, look at what is under the hood:

sourcecode

Yes, it’s a big cover up and the site is in reality hosted on 209.51.152.42. That means if you log in to this ‘banking’ website, you are giving away your information (and possibly money) to criminals.

How does IE8 protect you?

smart

“Check the address to make sure it is a site you trust.”

OK, let’s do that:

addy

Looks pretty legit to me?????

Phishing scams are very sophisticated and the whole thing is fairly simple: You browse to a site that has an exploit, it modifies your hosts file. Then you go to do some banking and all your money is belonged to the bad guys!

Watch what happened behind the scene:

fiddler

Does that make you feel like doing online banking anymore? It certainly gives me cold shivers.

Jerome Segura

    This entry was posted on Friday, August 14th, 2009 at 2:44 pm and is filed under Phishing. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.