maybank2u的釣魚詐騙網站 趴1

今午同事tohps收到一封號稱來自maybank2u的信件
信件內容是講述(附帶一個html)
你的銀行戶口出現問題要做些"動作"
然後跟他們回報
這肯定是騙人的
千萬不要上當~~~~!!!!!!!

我們來拆招下:
1.他給的網址是沒錯的
但是接下來做的動作根本就是廢的,可疑的,假的
2.銀行是不會跟客戶要密碼的
3.TAC據tohps說要轉帳是需要的識別碼,沒有就不行,
還有有效性是在48小時內(??),除了這用途他能拿來做麼?
4.他的附帶檔案去的網站是一個跳板(看圖1)
是一個連去中國的網站,
而且這個網站被偉大的firefox認定為危險的,不安全的(圖2)
所以如果你把你的資料統統給他
他就會登入你戶口然後把錢轉進他自己的戶口
你的餘額就是只剩下 RM1或RM0
5.Risk Management Department從來沒聽過這銀行有這部門

所以大家要小心警惕,也告訴朋友家人不要受騙了

故事還沒完
請看趴2

圖1:

圖2:


信件內容:
> Dear maybank2u Account Holder,
>
> Maybank2u would like to inform you that an increased number of
> merchants and ATMs in your country have experienced data compromises of
> payment cards used in their stores and at their ATMs, and that your funds
> may be at risk. To protect yourself, please follow the next steps :
>
> * Log in into maybank2u online account
> https://www.maybank2u.com.my/mbb/m2u/common/M2ULogin.do?action=Login
> * You must request for TAC online via maybank2u - your TAC will be sent
> via SMS to the mobile phone number you registered at the ATM.
> ( you can find the "request a TAC" button in the right menu of your
> account "Utilities" )
> * Logout from your maybank2u account and close the browser.
> * When you have received the TAC (Transaction Authorization Code) on
> your mobile phone, open the secured form attached to email and submit the
> requested information
> ( Account user ID, password and TAC )
>
> Please allow 48 hours for processing
>
> Thank you,
> maybank2u Risk Management Department
>

0 意見:

Related Posts Plugin for WordPress, Blogger...