phishing filter thwarted by unique subdomains
http://onlinesession-518260672.natwest.com/updatemode/userdatadirectory/start.aspx
Leads to…
http://onlinesession-518260672.natwest.com.mofer1.yn.cn/updatemode/userdatadirectory/start.aspx/
I just got one of these wonderful phishing emails. And noticed the onlinesession-xxxxxx ID.
Guess M$s wonderful, slow, phishing filter can’t make any use of this..
|