Welcome
Welcome to Paetechie, the pathetic technology oriented and information security blog of a techie traveler from the Philippines




Paetechie's Wanderlust:
  • Hong Kong Disneyland
  • Madame Tussauds Hong Kong
  • Victoria Harbour Cruise
  • A Symphony of Lights
  • Hong Kong Shopping Tips

  • Singapore Travel Tips
  • The Merlion
  • DIY Tour of Singapore
  • Singapore Free City Tour
  • India in Singapore

  • Bangkok, Thailand Travel Tips
  • The Grand Palace Bangkok, Thailand
  • Ancient City Ruins
  • Bridge on the River Kwai

  • Mumbai,India Travel

  • Backpacking Malaysia
  • Genting Highlands

  • Philippine Travel Guide
  • Island-Hopping
  • Backpacking Cebu

  • Mayon Volcano
  • Capones Island Lighthouse
  • Mount Pinatubo Crater Trek
  • Taal Volcano Trek
  • Vigan, Ilocos Sur
  • Angono Petroglyphs
  • Corregidor Tour
  • Subic Ocean Adventure
  • Hundred Islands
  • Coron, Palawan
  • Chocolate Hills
  • Puerto Galera
  • Lago de Oro Wakeboarding
  • Lake Caliraya
  • Pagsanjan Falls
  • Whale Sharks Donsol
  • Laiya, San Juan
  • Budget Travel Boracay
  • Antipolo Church
  • Our Lady of Manaoag
  • Camiguin Island Tour
  • Monastery of Transfiguration
  • Potipot Island
  • Caramoan
  • Tour of Intramuros
  • Escolta
  • Manila Ocean Park
  • Golf Courses
  • Bagasbas Beach
  • Calaguas Island
  • Munting Buhangin Beach Camp
  • Davao Zipline

  • Panagbenga Flower Festival
  • Pahiyas Festival
  • Sagada Festival of Lights
  • Ati-atihan Festival

  • Halal Food Restaurants
  • Kopi Luwak

  • Manila Shopping Guide
  • Pasig Ferry
  • Metrostar Ferry
  • Unaccompanied Minors
  • Philippine Airlines Excess Baggage
  • Cebu Pacific Excess Baggage
  • PAL Express
  • NAIA Terminal 3

  • Balikbayan visa
  • Cheap Resorts in Boracay
  • Bataan Beach Resorts
  • Donsol Beach Resorts
  • Batangas Calatagan Beach Resorts
  • Laiya San Juan Beach Resorts
  • Malapascua Beach Resorts
  • Moalboal Beach Resorts
  • Bolinao Beach Resorts
  • Pangasinan Beach Resorts
  • La Union Beach Resorts
  • Bantayan Beach Resorts
  • Quezon Beach Resorts
  • Pansol Resorts
  • Sydney Opera House History
  • Sydney Harbour Bridge
  • Colour Orange
  • Pacquiao vs Hatton
  • Pacquiao Cotto Fight
  • Wedding Glitters

  • Withdraw Paypal Funds

  • Equitable PCI Bank Phishing

    I received this email toady purportedly from Equitable-PCI Bank informing me of unsuccesful login attempts on my online banking account and thus requiring me to review my account activity for any anomaly

    the email is not directly addressed to me but to a resigned co-employees. I was only BCCed. The link to the FastNet site will take you not to the legitimate site i.e. http://www.fastnet.com.ph but rather to this phishing site.



    Note that entering my account number and PIN, the miscreant will then be able to get and use my account information for whatever evil purposes-- that is if I have an Equitable PCI Bank account!

    Digging deeper into the email headers and page source, I found these details:

    1. Phishing website copied from Fastnet using HTTRACK available here
    2. Used FROM email address: "Equitable PCI BANK"
    3. Sent to a random email typical of phishers
    4. Return Path: kingm@noronet.cz
    5. SMTP server used: mail.noronet.cz
    6. IP address of email sender: 194.212.224.152 traced to the Czech Republic
    netname: GBCOMP-NET
    descr: NoRoNet
    descr: Municipal Network
    descr: GB-COMP v.o.s.
    descr: Nova Role
    country: CZ

    7. Note both IP address may be routed through Czech Republic IP address and does not necessarily come from there.
    8. Phishing site is using fastnet.hk domain name HKDNR WHOIS site.
    Registered on February 6, 2007 up to February 6, 2008
    Registrant Name: SADA LOPA
    Email: Dave2Cruz@hotmail.com
    Country: US
    Account Name: HK1806283T

    9. Server hosted in using there IP addresses taken from authoritative DNS server
    Name: www.fastnet.hk
    Address: 62.43.146.9
    Name: www.fastnet.hk
    Address: 83.61.105.204
    Name: www.fastnet.hk
    Address: 84.102.8.73
    Name: www.fastnet.hk
    Address: 84.202.139.205
    Name: www.fastnet.hk
    Address: 142.161.199.111

    I could have dug deeper into this one but I know I'll be facing a blank wall. I'm sure the guys at Equitable PCI Bank are already aware of this.

    Note that phishing is an attack against the account holder and not directly at the bank itself. The only way to combat this is to educate users on how to discern legitimate sites from fake ones. There are, however, various ways to guard against phishing, one of which is strong 2nd factor authentication already being studied by various local banks.

    Labels:

    posted by backpacking philippines @ 11:47 AM,

    4 Comments:

    At 11:34 AM, Blogger Senor Enrique said...

    Thanks for the warning!

     
    At 4:26 PM, Blogger zedd said...

    hi,

    got your email thru phphoto, i also got these emails from ebay, citibank... but when you click thre link, the status bar shows the link address of the link you're clicking, meaning to say that this site is not the actual site you're going to... im using thunderbird email program and when you get to read the message, the title has a notification that something "this is a clone or spam..."
    thunderbird is free anyway

     
    At 4:28 PM, Blogger zedd said...

    oh great!
    i was just checking my emails and i got one too! :)
    i dont have any account with epci

     
    At 5:40 PM, Blogger dodongflores said...

    PCIB, Ebay, Amazon, Paypal. You name it, these scammers have all of these. I think a massive campaign like in bigger print ads and TV ads is needed to educate ordinary consumers. As far as I know, only "computer techie" like us can easily detect all of these scam things. those plain email users are susceptible to this attack and prone to be easily deceived...
    Well, thanx for sharing. That surely helps...

     

    Post a Comment

    Links to this post:

    Create a Link

    << Home


    Categories
  • Adsense
  • Anonymity and Privacy
  • ATM Banking
  • Banking
  • Banking News
  • Blogging
  • Computers
  • Credit Cards
  • Driving
  • eGovernment
  • Electronics
  • Floobydust
  • Google Stuff
  • GPS
  • Hoax
  • Information Security
  • Legal Stuff
  • Linux
  • m-commerce
  • Mathematics
  • Mobile Phones
  • Modus Operandi
  • Paete
  • Paypal
  • Personal
  • Personal Finance
  • Phishing
  • Photography
  • Physical Security
  • Rants
  • Renewable Energy
  • Scams
  • SEO
  • Software
  • Spam
  • Sports
  • Technology
  • Telecom News
  • Tips and Tricks
  • Wireless World
  • previous posts
    Ads

    Counters

    Get listed at www.millionbloglist.com