
Phishing in a Greek Bank and how quickly do we react? Last Friday, November 11, 2016, the above “optimistic” email from… Alpha e-Banking Holdings Inc. arrived at our offices. “Please synchronize your Additional Security Code” it urged us with a lot of misspellings and a… hidden link: “Click here”. Listen… “Click here”; lol!!
The first thing we do in these cases is to look at the Header of the specific email. Through Outlook, we open the email and click File | Properties:

It clearly looks like a different address than the one the email wanted to show us: zbang.com from IP 92.243.24.96. Not at all convincing, don't you agree?
The second thing we did was to check the completely invalid “Click here” and we saw that it led to the address: https://microcourse.info/files/tel/ However, when you clicked on it, it redirected to the real phishing site: https://prostarwiki.com/cp/alpha.web.gr/ which, as we can see in the next image, is a fake ALPHA BANK web banking site:

What the site asked for was to enter the Subscriber Code, the password and the Additional Security Code. If someone fell into the trap and provided these details, they would see the following form:

Here the scammers simply ask us to provide the Security Code from the device (2-factor-authentication) provided by the Bank or from the corresponding mobile application. We believe this is an additional step that the thieves took, in case we did not provide it on the previous screen, so that they can make sure that we will provide it here!
Immediately after that, our "application" goes to the following form:

The program asks us for a security code once again and to be precise, when we give it, it asks us for it one more time, perhaps not so much to make sure we give the correct one, but perhaps to... collect valid security codes!!
Finally, after we have sent 3 security codes (or 4 with the one we gave in the credentials entry form), they "reassure" us with this last screen:

“Your account has been successfully synchronized. Online access will be activated in 2 hours. thank you” or else, within 2 hours you will have lost all your money… as the above screen suggests!! Regardless of the result, we must admit that (compared to the original email) their spelling has improved significantly… (coincidental???)!
So after seeing all of the above, the first thing I did was to put out an alert at the same time, on my personal Facebook & Twitter pages. This happened on the same day, Friday, November 11, 2016 at 16:04, as the image below shows.

How quickly it became known..
We must say that Firefox was already aware of this specific address and had already blocked it:

Chrome was updated a few hours after our post and the next morning the page had already been blocked by some Antiviruses such as ESET NOD32:

It would also not be a bad idea to mention that Microsoft's famous Edge has not been "stunned", displaying this site normally.
Does the phishing site exist now?
It is interesting to mention that a few hours after the report, some people changed the directory hosting the phishing site, thinking perhaps that we would click on it and (1) we would think it was closed and (2) they could fool serious (with security) Web Browsers!
The site that the thieves had put their site on was that of some (most likely) simple and innocent person who maintains a personal site. However, they did not know that (in addition to other security problems) it also had Directory Listing. In this way, we saw that immediately after our report, the directory changed from https://prostarwiki.com/cp/alpha.web.gr/ to https://prostarwiki.com/cp/alpha/ as shown in the following (before/after) image:

Also consider the date and time the phishing site was created! Several months ago…
Otherwise, the Phishing Site now that these lines are being written exists at the address https://prostarwiki.com/cp/alpha/ibank/index2.html?netKpoZxJf5FscjPWiCqShTgaIG1d07Bv6OYRXM9wHrmzQNVbD8AlUykE2Lu43jVbCc84g6qHdAkO3NzauwWt0Fe5rML7T9KnZB2SUhQXEsDxYPmilRpIyJoG1vf51584251573?EsetProtoscanCtx=1aefd240290
However, only the first page is working. The rest seem to be inaccessible, and the directory listing is also inaccessible, as it appears to have been blocked by the hosting provider.
Conclusions
In general, we are pleased with the feedback and response time of the main Internet players after a simple post on fb / twitter. A thumbs up to Firefox, Chrome and ESET and a thumbs-down to Microsoft Edge.
But as we do and will do every time, we will present the events exactly as they happened and leave the main conclusions to you..
Stay tuned… 😉
