
Caught an email for a new victim - SouthTrust bank.
Pretty standard, good English. No attempt to obfuscate the URL, it's just an IP address.
Website was still up on port 80.

Just for grins, I figure I'll click on the Verisign seal. Noone ever actually checks, so I figured it wouldn't go anywhere.
Surprise!

Verisign tells me that this site is to be trusted, and I can go ahead and put my private information in.
I don't know quite how they did that. I'll be looking into it, meantime, don't trust it just because it has the seal.
UPDATE It's a Korean website - the site is running PHP 4.1.1 and phpbb, so my guess it's the Santy worm that gave the hackers access. We'll be seeing more of this very soon.
$ telnet 210.220.162.130 80
Trying 210.220.162.130...
Connected to 210.220.162.130.
Escape character is '^]'.
HEAD / HTTP/1.0
HTTP/1.1 200 OK
Date: Wed, 29 Dec 2004 19:20:55 GMT
Server: Apache/1.3.22 (Unix) PHP/4.1.1
X-Powered-By: PHP/4.1.1
Set-Cookie: phpbb2mysql_data=a%3A0%3A%7B%7D; expires=Thu, 29-Dec-05 19:20:56 GMT; path=/
Set-Cookie: phpbb2mysql_sid=1e9a41281d6cec764ab42fe18a6470e6; path=/
Connection: close
Content-Type: text/html