Tuesday, June 10, 2008

The Famed ICICI phishing attack

I have attached this mail with headers.
I guess this is one of those famous mails,
used for hacking ICICI customers accounts.
-----------------------------------------------

Delivered-To: --my email address here--
Received: by 10.110.93.18 with SMTP id q18cs103450tib;
Mon, 9 Jun 2008 09:01:28 -0700 (PDT)
Received: by 10.100.178.13 with SMTP id a13mr3889104anf.29.1213027286181;
Mon, 09 Jun 2008 09:01:26 -0700 (PDT)
Return-Path:
Received: from corvette.speedlimithosting.com (3a.dc.5d45.static.theplanet.com [69.93.220.58])
by mx.google.com with ESMTP id c13si20539843anc.32.2008.06.09.09.01.25;
Mon, 09 Jun 2008 09:01:26 -0700 (PDT)
Received-SPF: neutral (google.com: 69.93.220.58 is neither permitted nor denied by best guess record for domain of radioone@corvette.speedlimithosting.com) client-ip=69.93.220.58;
Authentication-Results: mx.google.com; spf=neutral (google.com: 69.93.220.58 is neither permitted nor denied by best guess record for domain of radioone@corvette.speedlimithosting.com) smtp.mail=radioone@corvette.speedlimithosting.com
Received: from radioone by corvette.speedlimithosting.com with local (Exim 4.68)
(envelope-from )
id 1K5joB-0007Dx-7E
for --my email address here--; Mon, 09 Jun 2008 11:01:23 -0500
To: --my email address here--
Subject: Secure Your NetBanking Account
From: ICICI Bank
Reply-To:
MIME-Version: 1.0
Content-Type: text/html
Content-Transfer-Encoding: 8bit
Message-Id:
Date: Mon, 09 Jun 2008 11:01:23 -0500
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - corvette.speedlimithosting.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [32023 32002] / [47 12]
X-AntiAbuse: Sender Address Domain - corvette.speedlimithosting.com
X-Source: /usr/bin/php
X-Source-Args: /usr/bin/php /home/radioone/public_html/calendar/tasks/settings.inc.php
X-Source-Dir: radiooneindiana.com:/public_html/calendar/tasks












ICICI Online Banking Mail Box Notification






























Security Alert



ICICI Bank has been
receiving complaints from our customers of unauthorized access of the NetBanking
accounts. As a result we have started reviewing our

NetBanking Accounts periodically and temporarily restrict access of those
accounts which we think are vulnerable.It has come to our attention that your
account

information needs to be updated as part of our continuing commitment to protect
your account in this year 2008 and to reduce the instance of fraud on our
website.

If you could please take 5-10 minutes out of your online experience and update
your personal records, you will not run into any future problems with our online
service.

Once you have updated your account records your online banking account service
will not be interrupted and will continue as normal.


To update your records click
the following link(s) and fill in the necessary requirements :


Personal
Account Holders -

https://infinity.icicibank.co.in/BANKAWAY?Action.RetUser.Init.001=Y&AppSignonBankId=ICI&AppType=retail&abrdPrf=N


Business Account Holders -

https://cib.icicibank.co.incorp/BANKAWAY?Action.CorpUser.Init.001=Y&AppSignonBankId=ICI&AppType=corporate




Please sign in to Online Banking after you have
verified your account to ensure your account security. It is all about your
security.

We seek your cooperation for serving you better.

Sincerely,



Benoy Dasgupta

Security Department

ICICI Bank









No comments: