Emails Disguised as ‘Emirates Post’ Being Distributed During the Overseas Direct Purchase Season

Emails Disguised as ‘Emirates Post’ Being Distributed During the Overseas Direct Purchase Season

The ASEC analysis team has introduced numerous phishing websites disguised as various companies. The team has recently discovered a malicious email disguised as Emirates Post, a transport company, during the overseas direct purchase season.

As shown in the figure below, the malicious email states that there is a problem with the shipping address, requesting the purchaser to check and return. The texts “Tracking Number” and “Click Here” contain a malicious URL that redirects the clicker to the phishing website. It also prompts the user to click the link by stating that the link expires after 24 hours.

Figure 1. Email disguised as Emirates Post

 

As shown in the address of the link in the email below, the address of the malicious website was created similarly to the normal Emirates Post website, therefore, the users must take great caution as it can be mistaken for the normal website.

Upon accessing the phishing website, the user is flashed with the page disguised as the Emirates Post website, which prompts the user to enter their phone number to check the shipping status.

Figure 2. Prompting the user to enter their phone number

 

Upon entering the phone number and clicking Continue on the page, the user is redirected to the URL below. The redirected page prompts the user to enter the 4-digit number sent to the entered phone number. The team has confirmed that entering any numbers will redirect the user to the next page.

  • hxxps://emirates-ae-post-shipping.com/smsphone2.php

Figure 3. Redirected page after entering the phone number

 

Upon entering the data and clicking Confirm, the user is redirected to a page to enter additional user credentials. The figures and the URLs below are the redirected pages the users get upon entering the data and clicking the button. As shown in the figures, they prompt the user to enter their home address and credit card information in order.

  • hxxps://emirates-ae-post-shipping.com/index4.php

Figure 4. Prompting the user to enter their home address

 

  • hxxps://emirates-ae-post-shipping.com/index2.php

Figure 5. Prompting the user to enter their credit card information

 

The figure below shows the final redirected page, and it prompts the user to enter the code sent to the user’s phone number.

  • hxxps://emirates-ae-post-shipping.com/sms.php

Figure 6. Last page

 

During the overseas direct purchase season, the distribution of malicious emails containing shipping-related texts has recently been increasing, and it can cause financial damage due to the leakage of user’s credit card information. Users should refrain from opening the URL attached or included in emails from unknown sources.

URL

https[:]//emirates-ae-post-shipping[.]com/
https[:]//emirates-ae-post-shipping[.]com/index2[.]php
https[:]//emirates-ae-post-shipping[.]com/index4[.]php
https[:]//emirates-ae-post-shipping[.]com/sms[.]php
https[:]//emirates-ae-post-shipping[.]com/smsphone2[.]php

Gain access to related IOCs and detailed analysis by subscribing to AhnLab TIP. For subscription details, click the banner below.