The Phishing email with the subject “Summit Bank Account Locked” pretends to be coming from the legitimate bank, using the email address ibsupport[@]summitbank[.]pk and targets employees of other banks. It contains a fake URL leading to a login page. While the legitimate URL of Summit Bank’s internet banking log-in page is https://ib.summitbank.com.pk/ib.login.do, the URL received through email was https://latamvapea[.]com/mails/nl/summit/summit[.]html/. The page latamvapea itself is a legitimate but compromised vapeselling site.
The email looks like this:
Moreover, while only port 443 is open on the legitimate site, the fake site has port 80, 443 and 81 open as well. 81 can be used for web services but if it’s idle it can be widely used as a RAT (remote access Trojan).
INDICATORS OF COMPROMISE
Summit Bank Account Locked
If you think you’re a victim of a cyber-attack, immediately send an email to firstname.lastname@example.org for a quick response.