Analyst Journal; work and IT @ 08 Mar 2010 08:08 pm by ayoi
My email used to be bombarded with spam or phising emails either for Paypal, Maybank or CIMB and sometimes Amazon as well. Usually these emails are in the same format (sometimes even same wordings), same email subject and lil bit different header images and of cause different sender address. But today (the email actually received yesterday but I only open my trusted Thunderbird today) the content is lil bit different, convincing enough and yeah even the sender address seems like from legitimate source for the unsuspecting users.
As usual my Thunderbird categorized this email as probable Scam Email (as for some of my unfortunate friends email as well haha). Anyway for the first time I just remove the Scam tag and let the image load (after checking the email content source of cause).
As you can see the link stated in this email SEEMS to point to actual maybank2u website. But wait.. do not click it yet. Just move your mouse over the link and you can see the exact place where this link will lead you..
Yup.. Instead of going to maybank2u website, the link actually will lead (or mislead in this case) you to http://foto.asmul.com/gallery2/modules/icons/iconpacks/KSIcons/M2ULogin.doaction=Login.htm
. So what if you really click on that link? For a start Firefox will not publish the site immediately but will give you an ample warning about that site instead.
And if you superbly ignorant or stubborn and choose to ignore the warning instead, you will be presented with this page
Ok even though the page bear resemblance with the actual maybank2u login page (refer image below) but IF you compare with these two, there are few glaring items that HOPEFULLY will make you aware that you are in a wrong/spoof/phising/tipu/kencing site.
The most obvious one is the address of the link. IF you are presented with maybank2u login page but the url shows address others BUT maybank2u’s, close your browser/tab and for precautionary move, run your antivirus or whatever anti spyware/bot/adware that you have in order to detect any possible unwanted malware (malicious software) downloaded unwittingly into your precious computer.
Like in this case, instead of having this address on the url field: https://www.maybank2u.com.my/mbb/m2u/common/M2ULogin.do?action=Login; you can see the address actually is http://foto.asmul.com/gallery2/modules/icons/iconpacks/KSIcons/M2ULogin.doaction=Login.htm with maybank2u login page.
Besides there’s a date on actual maybank2u’s login page, there are other differences that you should notice. Be my guest to download the images and play the “spot the different” between those images yourself as I’ve had enough of this game during my school years
Well what will happen if you login or inserting your credential at this page..
Unless your username is testing and the password is 12345678abcd, you have nothing to worry about. And even with this false information, the page will “process” and lead you to another page..
Yup.. the infamous “update your Profile” page. Again unless your email is spongebob@krustykrab.com (is it yours?? sorry but I think you do not have maybank2u account rite? You do?…)
And the rest of the process is similar with the old phising scam.. Get TAC number, enter your TAC number, and the usual do not login to your account within 24 hours..
That’s for now. it seems there’s something interesting from the traffic generated by these activities. Will update on later post.
Oh yeah, it seems the site has been taken down











lots of scammer nowadays. need to be careful. thanks for tips ah yoi.
yang tak literate IT le yang naya… mana paham menda2 gini… alaaa yang terrer pon kena ape kakakkka
Nice writeup. As security professionals such as yourself continue to spread awareness and as better safety tools like the Firefox warning are developed, it is eventually going to get harder for the scammers.
Been thinking this is likely to lead to a situation where the attackers have to become more active, instead of send email or email with attachments. So I guess we will start to see worms again, I rather preferred the emails – they were easier.
bro, plz help promote i-hack2010..
thnx in advance
http://www.facebook.com/nizmy?ref=profile#!/pages/i-Hack-2010/116310938389693
https://addons.mozilla.org/en-US/firefox/addon/142878/
thanks for sharing this information to the general public, continue to write more of this stuffs, coz its useful to prevent ppl from falling into the traps of phishers and scammers
thanks for sharing this information to the general public, continue to write more of this stuffs, coz its useful to prevent ppl from falling into the traps of phishers and scammers