Rock Phish
Rock Phish refers to both a phishing toolkit/technique and the group behind it.[1][2]
Rock Phish gang and techniques
At one time the Rock Phish group was stated to be behind "one-half of the phishing attacks being carried out.[2] VeriSign reports them as a group of Romanian origin,[1] but others have claimed that the group is Russian.[3] They were first identified in 2004.[4]
Their techniques were sophisticated and distinctive, as outlined in a presentation at APWG eCrime '07.[5]
History
In 2004 the first rock phishing attacks contained the folder path “/rock”, which led to the name of the attack, and group.
Attackers employed wild card DNS (domain name server) entries to create addresses that included the target's actual address as a sub-domain. For example, in the case of a site appearing as www.thebank.com.1.cn/thebank.html, ”thebank.com” portion of the domain name is the “wild card”, meaning its presence is purely superficial – it is not required in order for the phishing page to be displayed. “1.cn” is the registered domain name, “/thebank.html” is the phishing page, and the combination of “1.cn/thebank” will display the phishing page. This allows the perpetrators to make the wild card portion the legitimate domain name, so that it appears at first glance to be a valid folder path.[6]
References
- ^ a b Compliance and Privacy (2006-12-15). "What is Rock Phish? And why is it important to know?". Compliance and Privacy. Retrieved 2006-12-15.
Rock Phish is an individual or group of actors likely working out of Romania and nearby countries in the region. This group has been in operation since 2004 and is responsible for innovation in both spam and phishing attacks to date, such as pioneering image-spam (Ken Dunham, VeriSign)
{{cite web}}
:|author=
has generic name (help) - ^ a b Robert McMillan (2006-12-12). "'Rock Phish' blamed for surge in phishing". InfoWorld. p. 2. Archived from the original on 2007-01-08. Retrieved 2006-12-13.
The first thing you need to know about Rock Phish is that nobody knows exactly who, or what, they are.
- ^ Dignan, Larry. "RSA finds new malware enhanced phishing technique". ZDNet. Retrieved 8 September 2018.
- ^ Howard, Rick (2009-04-23). Cyber Fraud: Tactics, Techniques and Procedures. CRC Press. p. 264. ISBN 9781420091281.
Rock Phish gang.
- ^ Tyler Moore and Richard Clayton. "Examining the Impact of Website Take-down on Phishing" (PDF). APWG eCrime Researcher's Summit, ACM Press, pp. 1-13. Retrieved October 28, 2007.
- ^ Goodin, Dan. "FBI logs its millionth zombie address". The Register. Retrieved 8 September 2018.
- v
- t
- e
- Scam
- Error account
- Shill
- Shyster
- Sucker list
confidence tricks
- 1992 Indian stock market scam
- 2G spectrum case
- Advance-fee scam
- Art student scam
- Badger game
- Bait-and-switch
- Black money scam
- Blessing scam
- Bogus escrow
- Boiler room
- Bride scam
- Charity fraud
- Clip joint
- Coin-matching game
- Coin rolling scams
- Drop swindle
- Embarrassing cheque
- Exit scam
- Extraterrestrial real estate
- Fiddle game
- Fine print
- Foreclosure rescue scheme
- Foreign exchange fraud
- Fortune telling fraud
- Gem scam
- Get-rich-quick scheme
- Green goods scam
- Hustling
- Indian coal allocation scam
- IRS impersonation scam
- Intellectual property scams
- Kansas City Shuffle
- Locksmith scam
- Long firm
- Miracle cars scam
- Mismarking
- Mock auction
- Moving scam
- Overpayment scam
- Patent safe
- Pig in a poke
- Pigeon drop
- Pork barrel
- Pump and dump
- Redemption/A4V schemes
- Reloading scam
- Return fraud
- Salting
- Shell game
- Sick baby hoax
- SIM swap scam
- Slavery reparations scam
- Spanish Prisoner
- SSA impersonation scam
- SSC Scam
- Strip search phone call scam
- Swampland in Florida
- Tarmac scam
- Technical support scam
- Telemarketing fraud
- Thai tailor scam
- Thai zig zag scam
- Three-card monte
- Trojan horse
- Wash trading
- White van speaker scam
- Work-at-home scheme
countermeasures
- Avalanche
- Pig Butchering
- Carding
- Catfishing
- Click fraud
- Clickjacking
- Cramming
- Cryptocurrency scams
- Cybercrime
- CyberThrill
- DarkMarket
- Domain name scams
- Email authentication
- Email fraud
- Internet vigilantism
- Lenny anti-scam bot
- Lottery scam
- PayPai
- Phishing
- Referer spoofing
- Ripoff Report
- Rock Phish
- Romance scam
- Russian Business Network
- SaferNet
- Scam baiting
- 419eater.com
- Jim Browning
- Kitboga
- Scammer Payback
- ShadowCrew
- Spoofed URL
- Spoofing attack
- Stock Generation
- Voice phishing
- Website reputation ratings
Ponzi schemes
- Aman Futures Group
- Bernard Cornfeld
- Caritas
- Dona Branca
- Earl Jones
- Ezubao
- Foundation for New Era Philanthropy
- Franchise fraud
- High-yield investment program (HYIP)
- Investors Overseas Service
- Kapa investment scam
- Kubus scheme
- Madoff investment scandal
- Make Money Fast
- Matrix scheme
- MMM
- Petters Group Worldwide
- Pyramid schemes in Albania
- Reed Slatkin
- Saradha Group financial scandal
- Secret Sister
- Scott W. Rothstein
- Stanford Financial Group
- Welsh Thrasher faith scam