Home Malware Programs Trojans PWS:HTML/Phish.DD

PWS:HTML/Phish.DD

Posted: November 8, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 337
First Seen: November 8, 2012
Last Seen: August 24, 2021
OS(es) Affected: Windows

PWS:HTML/Phish.DD is a password-stealing Trojan that spreads via a malicious website. A phishing website hides itself as a genuine PayPal website. The fake PayPal website strives to steal a victim's online banking and PayPal account information (credit card details) by tricking a PC user into filling out his/her details in a form on a bogus website for a certain reason, such as updating a PayPal profile, and then, sends that information to remote attackers. The fraudulent website that contains PWS:HTML/Phish.DD may use logos, layouts and images copied from a legal PayPal website. The phishing website that is used to distribute PWS:HTML/Phish.DD is an HTML page that is usually hosted on hijacked or malicious websites, or added as an attachment to an unsolicited email message. Computer users, who visit a hijacked or malicious website get redirected to a website that hosts phishing pages that are then identified as PWS:HTML/Phish.DD. If a computer users clicks 'Save Profile' or 'update' or a similar button after filling out the form, the information is transmitted to a remote server.

Loading...