A very interesting phishing email was sent to me today. The body from the email was:
Northern Trust Corporation Warning:
Beginning March 17, 2009, the Northern Trust Business Passport Center will use a new Certification Authority (CA) to issue end-user certificates.
If no one in your organization has a digital certificate, you will need to download your primary digital certificate file.
Installation is quick and simple.
Proceed for further information:
http://northerntrust.updateserver.initiated.landing-82z121sin.4565singin.com/signin.htm?/Management/login=an7v77b1qxyrty9
Sincerely, Refugio Johnson. Customer Service Department.
2009 Northern Trust Corporation. All rights reserved.
I’m calling this email interesting, because it’s kind of an odd method to get recipients to click on the link, and interact with the resulting site. After all, how many everyday computer users (Joe plumbers) have a clue what the terms Certificate Authority or end-user certificates refer too? Heck, considering that I know a fair number of IT professionals that are still coming to grips with these terms. I’m going to guess that most end-users would react with blank stares upon receiving this email.
Hey bad guys, when dealing with the masses which are more inclined to react positively to emails slanted Nude Britney Spears, or Your Password has Expired, or I have millions to share with you (for a nominal small fee). This is a really lame phishing scam.
Anyhow, because I’m a security geek, I took a little closer look. Here are some analysis details:
- Northern Trust is a valid US Bank.
- The link in the email is not related to Northern Trust.
- The link in the email resolves to a site that is branded to look like a Northern Trust site.
- On the site, there is a file download named NTrustdigicert.exe.
- This file is not currently recognized as malware by must AV software packages.
- This file, if executed appears to install a generic Win32 Trojan.
- The IP Address that the link resolves to is hosted by Comcast Cable address in the US. Most likely some poor sap that got infected.
- The DNS name 4565singin.com is owned by BIZCN.COM (XiaMenBizcn.com, Inc).
- That is a Chinese company, which appears to be part of the China’s anti-phishing alliance.
Honestly, that last bullet was a bit of surprise. Unless I read something wrong, members of China’s anti-phishing alliance are themselves either phishing, or have been hacked. Just sad.
If you like this, check out some other posts from Tyson:
- Would I trust you, if everyone else trusted you?
- Here is a good question: Is scripting programming or just systems administration?
- PowerShell boy and the case of the missing cmdlets!
- Fun with PowerShell 2.0 Eventing!
- Microsoft Discontinues Support for Windows 3.X (as an embedded system)
- My quest for SSH within PowerShell revisited!




