A new phishing targets HM Revenue & Customs clients. HM Revenue & Customs is an institution tied with the UK government responsible for UK's tax.
The phishing email contains these:
With a zip archive attachment that contains an HTML file named HM Revenue & Customs - Details.html.
Once the html file is opened, it shows this form:
The form looks legit since it uses images directly from the HMRC website.
When submitted, every information entered are sent to
At the time of this writing, directing to the site where the information is sent to was probably shot down and now returns a 404.
A simple whois query about the server shows:
Located in Cambodia.
Nothing malware file was downloaded. Everything was plain and simple phishing and stealing.
The phishing email contains these:
With a zip archive attachment that contains an HTML file named HM Revenue & Customs - Details.html.
Once the html file is opened, it shows this form:
The form looks legit since it uses images directly from the HMRC website.
When submitted, every information entered are sent to
h00p://nagios.net1.com.kh/nagiosweb/Lang.php
At the time of this writing, directing to the site where the information is sent to was probably shot down and now returns a 404.
A simple whois query about the server shows:
domain: nagios.net1.com.kh current ip: 202.131.87.67 nameserver: ns1.cambotech.com nameserver: ns2.cambotech.com reverse lookup domains based on ip: nagios.net1.com.kh crm.netone.com.kh
Located in Cambodia.
Nothing malware file was downloaded. Everything was plain and simple phishing and stealing.