Aggressive phishing against Strato.de customers

Strato.de (now belonging to 1&1) is one of the biggests hosters in Germany.

Since a few weeks we see a lot of emails containing various texts that try to convince the user

to login to his strato.de account and perform some actions.

Strato published on their blog also a post about these fake emails: https://strato.de/blog/achtung-aktuell-wieder-phishing-mails-im-namen-von-strato-im-umlauf/

 

Fortunately, the phishing email is very simple and it just hides the target URL with the official strato.de URL.

Pretty much all phishing filters detect it and block it.

 

The subject of the email is very aggressive: Last notification before judicial recovery

The email says that the customer has one more day to pay. But now comes the funny part.

The email says that the payment should be done via credit card, in order to make it “easy” for the customer. 🙂

To may this even more credible, they write that the introduction of a new payment method costs 1€.

After that, they even communicate the name of the company that will try to retrieve the money from the customer: Intrum (www.intrum.de)

 

The problem

I can’t stop to wonder how are the phishers obtaining all domains from Strato.
I have all my domains at Strato and I received an email for each of them.

Could they have been hacked and obtained the database with customers?

Or are the phishers just collecting domains, perform a filter on WhoIs information and then select only those hosted on Strato’s ?

 

The phishing takes place in two stages:

1. it redirects to some hacked website using a single file

2. from this site it redirects to a phishing website where the user needs to enter his Strato account and then credit card information.

 

Conclusion:

PROs: A well written email, making use of social engineering.

CONs: very simple method of providing the fake link, detectable by any phish filter in a generic way.

 

 

 


© Copyright 2020 Sorin Mustaca, All rights Reserved. Written For: Sorin Mustaca on Cybersecurity


Check www.endpoint-cybersecurity.com for seeing the consulting services we offer.

Visit www.itsecuritynews.info for latest security news in English
Besuchen Sie de.itsecuritynews.info für IT Sicherheits News auf Deutsch