Home / malware PWS:HTML/Payphish.BG
First posted on 02 October 2012.
Source: MicrosoftAliases :
There are no other names known for PWS:HTML/Payphish.BG.
Explanation :
PWS:HTML/Payphish.BG is a password-stealing malicious webpage, known as a phishing page, that disguises itself as a legitimate PayPal webpage.
The webpage attempts to steal your online banking and PayPal account information by tricking you into filling out your details in a form on a fake page, and then sending that information to a remote attacker.
It may use images, logos and layouts that the authors of PWS:HTML/Payphish.BG have copied from an authentic PayPal website.
The phishing page is an HTML page that is usually hosted on compromised or malicious websites, which an attacker may attempt to lure you to by opening an attachment named "VerifyAccount.zip".
Alternatively, a visit to a compromised or malicious website can be used to redirect you to a website that hosts phishing pages that are then detected as PWS:HTML/Payphish.BG.
In the wild, we have observed the following example webpage:
We have observed these phishing pages using the page name "Account Verification.html" to steal your information.
PWS:HTML/Payphish.BG attempts to obtain personal, banking-related data from you, by tricking you into filling out a form for a particular reason, such as updating your profile.
The information that PWS:HTML/Payphish.BG attempts to gain from you includes the following:
- Your personal information:
- Full name
- Date of birth
- Personal identification phrases, such as your mother's maiden name
- Social security number, if you reside in the US
- Address
- Credit or debit card information, including:
- Credit/debit card number
- Card expiry date
- Card verification number/security code
If you click "save profile" or "update" or a similar button after filling out the form, the information is sent to a remote server. We have observed the information being sent to the following URL using HTTP POST, which is a type of basic Internet data communication:
hxxp://www.tradecars1.com/ssl.php
Analysis by Horea Coroiu
Last update 02 October 2012